Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Internet connection problems after removing windows 7 2012 rogue antivirus  (Read 6405 times)

0 Members and 1 Guest are viewing this topic.

giardmi09

    Topic Starter


    Beginner

    Thanked: 6
    • Yes
  • Experience: Experienced
  • OS: Windows 7
A few weeks ago my computer was infected with the Windows 7 2012 security rogue antivirus. I found the removal instruction on Microsoft's support site and followed them. The virus is gone now and everything is fine except now I'm getting intermittent internet connection drops which seem to have started after removing the virus. The drops are completely random and last about 5 to 10 seconds. During this time, the connection monitor in the notification area still remains normal as if I am still connected to the internet. Usually I'll be browsing the web and will browse to a site and it gives me the "web site not found" error. This is quickly resolved by clicking refresh, but it's rather annoying. Also, programs like Skype have the same issues. If I'm talking on Skype I'll get random drops, but it won't end the call or log me out; it simply loses connection for about 5 seconds during which I can't be heard and I can't hear the other person but then it comes right back as if nothing happened. The only thing I can think of is that the virus crippled my firewall or changed network settings. Any suggestions would be greatly appreciated! :)

I'm running windows 7 home premium x64, my connection is wired to a router. and I use Avast antivirus and Malwarebytes

Thanks!

Mike

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
Did you try re-setting your modem?

Please download MiniToolBox to Desktop and run it.



Checkmark the following boxes:

    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • List content of Hosts
    • List IP Configuration
    • Lst Last 10 Event Viewer Errors
    • List Users, Partitions and Memory Size
    • [/b]
    Click Go and copy/paste the log (Result.txt) into your next post. .
    Windows 8 and Windows 10 dual boot with two SSD's

    giardmi09

      Topic Starter


      Beginner

      Thanked: 6
      • Yes
    • Experience: Experienced
    • OS: Windows 7
    Thanks for the response Dave, I'm at school right now but as soon as I get home and have the chance I will follow your steps. I'll report back here and let you know how it goes.

    Mike

    giardmi09

      Topic Starter


      Beginner

      Thanked: 6
      • Yes
    • Experience: Experienced
    • OS: Windows 7

    Dave, here is the resulting log from MiniToolBox and again thanks so much for your help. It's very very much appreciated.

    MiniToolBox by Farbar  Version: 18-01-2012
    Ran by Mike (administrator) on 25-01-2012 at 17:28:57
    Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
    Boot Mode: Normal
    ***************************************************************************

    ========================= Flush DNS: ===================================

    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========================= IE Proxy Settings: ==============================

    Proxy is not enabled.
    No Proxy Server is set.

    "Reset IE Proxy Settings": IE Proxy Settings were reset.
    Hosts file not detected in the default directory
    ========================= IP Configuration: ================================

    NVIDIA nForce 10/100/1000 Mbps Ethernet  = Local Area Connection (Connected)
    Hamachi Network Interface = Local Area Connection 3 (Connected)
    VirtualBox Host-Only Ethernet Adapter = VirtualBox Host-Only Network (Hardware not present)
    Linksys Wireless-G PCI Adapter = Wireless Network Connection 3 (Media disconnected)


    # ----------------------------------
    # IPv4 Configuration
    # ----------------------------------
    pushd interface ipv4

    reset
    set global icmpredirects=enabled
    add route prefix=0.0.0.0/0 interface="Local Area Connection 3" nexthop=5.0.0.1 publish=Yes
    set interface interface="Local Area Connection 3" forwarding=disabled advertise=disabled metric=9000 siteprefixlength=0 nud=disabled routerdiscovery=disabled managedaddress=disabled otherstateful=disabled weakhostsend=disabled weakhostreceive=disabled ignoredefaultroutes=disabled advertisedrouterlifetime=0 advertisedefaultroute=disabled currenthoplimit=0 forcearpndwolpattern=disabled enabledirectedmacwolpattern=disabled
    add address name="VirtualBox Host-Only Network" address=192.168.56.1 mask=255.255.255.0
    add address name="Wireless Network Connection" address=192.168.1.239 mask=255.255.255.0


    popd
    # End of IPv4 configuration



    Windows IP Configuration

       Host Name . . . . . . . . . . . . : Mike-PC
       Primary Dns Suffix  . . . . . . . :
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : No
       WINS Proxy Enabled. . . . . . . . : No

    Wireless LAN adapter Wireless Network Connection 3:

       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Linksys Wireless-G PCI Adapter
       Physical Address. . . . . . . . . : 00-18-39-06-70-CD
       DHCP Enabled. . . . . . . . . . . : Yes
       Autoconfiguration Enabled . . . . : Yes

    Ethernet adapter Local Area Connection:

       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : NVIDIA nForce 10/100/1000 Mbps Ethernet
       Physical Address. . . . . . . . . : 00-1F-BC-08-1A-F7
       DHCP Enabled. . . . . . . . . . . : Yes
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 192.168.5.100(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Lease Obtained. . . . . . . . . . : Friday, January 20, 2012 1:25:55 AM
       Lease Expires . . . . . . . . . . : Thursday, January 26, 2012 3:10:48 PM
       Default Gateway . . . . . . . . . : 192.168.5.1
       DHCP Server . . . . . . . . . . . : 192.168.5.1
       DNS Servers . . . . . . . . . . . : 192.168.5.1
       NetBIOS over Tcpip. . . . . . . . : Enabled

    Ethernet adapter Local Area Connection 3:

       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Hamachi Network Interface
       Physical Address. . . . . . . . . : 7A-79-05-3C-D9-CE
       DHCP Enabled. . . . . . . . . . . : Yes
       Autoconfiguration Enabled . . . . : Yes
       Link-local IPv6 Address . . . . . : fe80::e57c:dfd2:8b15:694d%27(Preferred)
       IPv4 Address. . . . . . . . . . . : 5.60.217.206(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.0.0.0
       Lease Obtained. . . . . . . . . . : Friday, January 20, 2012 1:25:55 AM
       Lease Expires . . . . . . . . . . : Saturday, January 19, 2013 1:28:02 AM
       Default Gateway . . . . . . . . . : 5.0.0.1
       DHCP Server . . . . . . . . . . . : 5.0.0.1
       DHCPv6 IAID . . . . . . . . . . . : 595228951
       DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-14-93-3F-BB-00-1F-BC-08-1A-F7
       DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
                                           fec0:0:0:ffff::2%1
                                           fec0:0:0:ffff::3%1
       NetBIOS over Tcpip. . . . . . . . : Enabled

    Tunnel adapter isatap.{0B6CBA9E-01B5-4664-9E2C-565FED6190A8}:

       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes

    Tunnel adapter Local Area Connection* 11:

       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Server:  master
    Address:  192.168.5.1

    Name:    google.com
    Addresses:  74.125.113.105
         74.125.113.104
         74.125.113.103
         74.125.113.106
         74.125.113.99
         74.125.113.147


    Pinging google.com [74.125.113.147] with 32 bytes of data:
    Reply from 74.125.113.147: bytes=32 time=36ms TTL=50
    Reply from 74.125.113.147: bytes=32 time=40ms TTL=50

    Ping statistics for 74.125.113.147:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 36ms, Maximum = 40ms, Average = 38ms
    Server:  master
    Address:  192.168.5.1

    Name:    yahoo.com
    Addresses:  98.137.149.56
         98.139.180.149
         209.191.122.70
         72.30.2.43


    Pinging yahoo.com [72.30.2.43] with 32 bytes of data:
    Reply from 72.30.2.43: bytes=32 time=94ms TTL=46
    Reply from 72.30.2.43: bytes=32 time=94ms TTL=46

    Ping statistics for 72.30.2.43:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 94ms, Maximum = 94ms, Average = 94ms
    Server:  master
    Address:  192.168.5.1

    Name:    bleepingcomputer.com
    Address:  208.43.87.2


    Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
    Reply from 208.43.87.2: Destination host unreachable.
    Reply from 208.43.87.2: Destination host unreachable.

    Ping statistics for 208.43.87.2:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

    Pinging 127.0.0.1 with 32 bytes of data:
    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

    Ping statistics for 127.0.0.1:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 0ms, Maximum = 0ms, Average = 0ms
    ===========================================================================
    Interface List
     25...00 18 39 06 70 cd ......Linksys Wireless-G PCI Adapter
     10...00 1f bc 08 1a f7 ......NVIDIA nForce 10/100/1000 Mbps Ethernet
     27...7a 79 05 3c d9 ce ......Hamachi Network Interface
      1...........................Software Loopback Interface 1
     11...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
     12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
    ===========================================================================

    IPv4 Route Table
    ===========================================================================
    Active Routes:
    Network Destination        Netmask          Gateway       Interface  Metric
              0.0.0.0          0.0.0.0          5.0.0.1     5.60.217.206   9256
              0.0.0.0          0.0.0.0      192.168.5.1    192.168.5.100     20
              5.0.0.0        255.0.0.0         On-link      5.60.217.206   9256
         5.60.217.206  255.255.255.255         On-link      5.60.217.206   9256
        5.255.255.255  255.255.255.255         On-link      5.60.217.206   9256
            127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
            127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
      127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
          192.168.5.0    255.255.255.0         On-link     192.168.5.100    276
        192.168.5.100  255.255.255.255         On-link     192.168.5.100    276
        192.168.5.255  255.255.255.255         On-link     192.168.5.100    276
            224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
            224.0.0.0        240.0.0.0         On-link     192.168.5.100    276
            224.0.0.0        240.0.0.0         On-link      5.60.217.206   9256
      255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      255.255.255.255  255.255.255.255         On-link     192.168.5.100    276
      255.255.255.255  255.255.255.255         On-link      5.60.217.206   9256
    ===========================================================================
    Persistent Routes:
      Network Address          Netmask  Gateway Address  Metric
              0.0.0.0          0.0.0.0          5.0.0.1  Default
    ===========================================================================

    IPv6 Route Table
    ===========================================================================
    Active Routes:
     If Metric Network Destination      Gateway
      1    306 ::1/128                  On-link
     27    276 fe80::/64                On-link
     27    276 fe80::e57c:dfd2:8b15:694d/128
                                        On-link
      1    306 ff00::/8                 On-link
     27    276 ff00::/8                 On-link
    ===========================================================================
    Persistent Routes:
      None

    ========================= Event log errors: ===============================

    Application errors:
    ==================
    Error: (01/25/2012 00:30:27 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "1".Error in manifest or policy file "2" on line 3.
    Multiple requestedPrivileges elements are not allowed in manifest.

    Error: (01/25/2012 00:00:01 AM) (Source: System Restore) (User: )
    Description: Failed to create restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint; Error = 0x80070422).

    Error: (01/24/2012 06:02:59 AM) (Source: System Restore) (User: )
    Description: Failed to create restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint; Error = 0x80070422).

    Error: (01/24/2012 05:56:23 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "1".Error in manifest or policy file "2" on line 3.
    Multiple requestedPrivileges elements are not allowed in manifest.

    Error: (01/23/2012 01:35:44 AM) (Source: System Restore) (User: )
    Description: Failed to create restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint; Error = 0x80070422).

    Error: (01/23/2012 01:29:16 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "1".Error in manifest or policy file "2" on line 3.
    Multiple requestedPrivileges elements are not allowed in manifest.

    Error: (01/22/2012 00:30:30 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "1".Error in manifest or policy file "2" on line 3.
    Multiple requestedPrivileges elements are not allowed in manifest.

    Error: (01/22/2012 00:00:01 AM) (Source: System Restore) (User: )
    Description: Failed to create restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint; Error = 0x80070422).

    Error: (01/21/2012 00:30:30 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "1".Error in manifest or policy file "2" on line 3.
    Multiple requestedPrivileges elements are not allowed in manifest.

    Error: (01/21/2012 00:00:01 AM) (Source: System Restore) (User: )
    Description: Failed to create restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint; Error = 0x80070422).


    System errors:
    =============
    Error: (01/25/2012 03:27:24 PM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
    Description: There was an error while attempting to read the local hosts file.

    Error: (01/25/2012 04:28:02 AM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
    Description: There was an error while attempting to read the local hosts file.

    Error: (01/24/2012 05:38:10 PM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
    Description: There was an error while attempting to read the local hosts file.

    Error: (01/24/2012 06:53:00 AM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
    Description: There was an error while attempting to read the local hosts file.

    Error: (01/23/2012 06:58:47 PM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
    Description: There was an error while attempting to read the local hosts file.

    Error: (01/23/2012 08:28:02 AM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
    Description: There was an error while attempting to read the local hosts file.

    Error: (01/22/2012 09:08:14 PM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
    Description: There was an error while attempting to read the local hosts file.

    Error: (01/22/2012 10:27:23 AM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
    Description: There was an error while attempting to read the local hosts file.

    Error: (01/21/2012 11:26:00 PM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
    Description: There was an error while attempting to read the local hosts file.

    Error: (01/21/2012 00:52:21 PM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
    Description: There was an error while attempting to read the local hosts file.


    Microsoft Office Sessions:
    =========================
    Error: (01/25/2012 00:30:27 AM) (Source: SideBySide)(User: )
    Description: C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exeC:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe2

    Error: (01/25/2012 00:00:01 AM) (Source: System Restore)(User: )
    Description: C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreationScheduled Checkpoint0x80070422

    Error: (01/24/2012 06:02:59 AM) (Source: System Restore)(User: )
    Description: C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreationScheduled Checkpoint0x80070422

    Error: (01/24/2012 05:56:23 AM) (Source: SideBySide)(User: )
    Description: C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exeC:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe2

    Error: (01/23/2012 01:35:44 AM) (Source: System Restore)(User: )
    Description: C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreationScheduled Checkpoint0x80070422

    Error: (01/23/2012 01:29:16 AM) (Source: SideBySide)(User: )
    Description: C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exeC:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe2

    Error: (01/22/2012 00:30:30 AM) (Source: SideBySide)(User: )
    Description: C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exeC:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe2

    Error: (01/22/2012 00:00:01 AM) (Source: System Restore)(User: )
    Description: C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreationScheduled Checkpoint0x80070422

    Error: (01/21/2012 00:30:30 AM) (Source: SideBySide)(User: )
    Description: C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exeC:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe2

    Error: (01/21/2012 00:00:01 AM) (Source: System Restore)(User: )
    Description: C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreationScheduled Checkpoint0x80070422


    ========================= Memory info: ===================================

    Percentage of memory in use: 50%
    Total physical RAM: 4094.49 MB
    Available physical RAM: 2041.27 MB
    Total Pagefile: 8187.18 MB
    Available Pagefile: 5804.79 MB
    Total Virtual: 4095.88 MB
    Available Virtual: 3960.55 MB

    ========================= Partitions: =====================================

    1 Drive c: () (Fixed) (Total:931.41 GB) (Free:495.84 GB) NTFS

    ========================= Users: ========================================

    User accounts for \\MIKE-PC

    Administrator            Guest                    Mike                     
    UpdatusUser             


    **** End of log ****

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Have you tried re-setting your modem? Unplug the power supply for 30 secs.
    Are you still having problems with the connection?


    SUPERAntiSpyware

    If you already have SUPERAntiSpyware be sure to check for updates before scanning!


    Download SuperAntispyware Free Edition (SAS)
    * Double-click the icon on your desktop to run the installer.
    * When asked to Update the program definitions, click Yes
    * If you encounter any problems while downloading the updates, manually download and unzip them from here
    * Next click the Preferences button.

    •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
    * Click the Scanning Control tab.
    * Under Scanner Options make sure only the following are checked:

    •Close browsers before scanning
    •Scan for tracking cookies
    •Terminate memory threats before quarantining
    Please leave the others unchecked

    •Click the Close button to leave the control center screen.

    * On the main screen click Scan your computer
    * On the left check the box for the drive you are scanning.
    * On the right choose Perform Complete Scan
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete a summary box will appear. Click OK
    * Make sure everything in the white box has a check next to it, then click Next
    * It will quarantine what it found and if it asks if you want to reboot, click Yes

    •To retrieve the removal information please do the following:
    •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
    •Click Preferences. Click the Statistics/Logs tab.

    •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

    •It will open in your default text editor (preferably Notepad).
    •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

    * Save the log somewhere you can easily find it. (normally the desktop)
    * Click close and close again to exit the program.
    *Copy and Paste the log in your post.
    ***************************************************
    Please download Malwarebytes Anti-Malware from here.
    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Full Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
    • Please save the log to a location you will remember.
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the entire report in your next reply.
    Extra Note:

    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
    ******************************************************
    Download DDS from HERE or HERE and save it to your desktop.

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.
    * Save both reports to your desktop.
    * The instructions here ask you to attach the Attach.txt.



    1) DDS.txt
    2) Attach.txt
    Instead of attaching, please copy/past both logs into your Thread

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copying and pasting it into the reply.

    •Close the program window, and delete the program from your desktop.

    Please note: You may have to disable any script protection running if the scan fails to run.
    After downloading the tool, disconnect from the internet and disable all antivirus protection.
    Run the scan, enable your A/V and reconnect to the internet.
    Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt )
    Windows 8 and Windows 10 dual boot with two SSD's

    giardmi09

      Topic Starter


      Beginner

      Thanked: 6
      • Yes
    • Experience: Experienced
    • OS: Windows 7
    Re: Internet connection problems after removing windows 7 2012 rogue antivirus
    « Reply #5 on: February 08, 2012, 07:29:18 AM »
    Sorry I haven't posted for a while I've been very busy with work and school. I'm beginning to think its a problem with the router's settings because this happens on all of our computers. It doesn't make much sense though because the router has the same settings as it has for over a year.  ???

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Internet connection problems after removing windows 7 2012 rogue antivirus
    « Reply #6 on: February 08, 2012, 11:53:18 AM »
    Please download Farbar Service Scanner and run it on the computer with the issue.
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.
    Windows 8 and Windows 10 dual boot with two SSD's