1) I have no firewall software.Only
McAfee Software installed.
no updates due to no internet.
2) Proxy settings.....where ?
3) virus was removed by McAfee. first i removed hard disk(from virus system1 ), placed at another system2(this system has updated McAfee) and scaned all drives. virus was removed and I fixed the hard disk at original place.
Ping OK, Shares Ok but No internet browsing and also virus list was not removed from
MSCONFIG.MSC Tool.
*) dc c:\windows\dc.exe
*) SVIQ c:\windows\SVIQ.EXE
*) Fun c:\windows\system\Fun.exe
*) Other c:\windows\inf\Other.exe
*) lphcesbj0ej0l c:\windows\system32\lphcesbj0ej0l.exe
*) win c:\windows\system32\config\win.exe
*) SHSTAT c:\Program Files\Network Associates\VirusScan\SHSTAT.EXE*/
*) rhcasbj0ej0l c:\Program Files\rhcasbj0ej0l\rhcasbj0ej0l.exe
But virus files were removed completely. I saw all drives and folders in "Show all files and folders" mode.
I modified some more regestry paths...see them
a)
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1
*) string value
FriendlyName
http://antivirus-2008pro.com/scanner.php?aff=DB
http://antivirus-2008pro.com/scanner.php?aff=DB
Antivirus 2008 PRO
b)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Antivirus 2008 PRO
c)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Antispyware 2008
d)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
C:\Program Files\Antivirus 2008 PRO\antivirus-2008pro.exe
C:\WINDOWS\dc.exe
C:\WINDOWS\system\Fun.exe
e)
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache
f)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Webcheck\Store.1\{D322370E-E6BE-01C8-0000-0000681B8206}
*)default
http://antivirus-2008pro.com/scanner.php?aff=DB
g)
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
*)string value
load
C:\WINDOWS\inf\Other.exe
run
C:\WINDOWS\system32\config\Win.exe
h)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Load
*)string value
command
C:\WINDOWS\inf\Other.exe
item
Other
i)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Run
*)string value
command
C:\WINDOWS\system32\config\Win.exe
item
Win
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
*)string value
dc
C:\WINDOWS\dc.exe
dc2k5
C:\WINDOWS\SVIQ.EXE
Fun
C:\WINDOWS\system\Fun.exe
MSMSGS
"C:\Program Files\Messenger\msmsgs.exe" /background
j)
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache
*)string value
C:\WINDOWS\SVIQ.EXE
SVIQ
C:\WINDOWS\dc.exe
dc
C:\WINDOWS\system\Fun.exe
Fun
4) I set all values default.
5) my system have two lan cards. One is on board lan and second is additional card.
D-Link DFE-520TX PCI Faxt Ethernet Adapter
Realtek RTL8139/810x Family Fast Ethernet NIC
Physical Address Transport Name
=================================================
00-16-76-70-1D-1B \Device\Tcpip_{7B6E5E29-4DD1-490A-B85C-C86399046485}
00-1C-F0-15-39-47 Media disconnected
pls give solution.