Thank you for reporting back Jroffman ![]()
Certainly looks like some progress, especially now that tdx.sys, bfe.dll, etc. are now showing
as legit and present. ![]()
Yes, often some reg files cannot be merged do to certain types of keys. Sometimes, it may be possible
to merge them while in safe mode, but not always. One thing, after seeing your log…it pertains to windows firewall.
I hope the reg files you were able to merge were the BFE and MPSsvc related files at the very least.
BFE is “Base filtering engine” and “Mpssvc” are both windows firewall related. Have you taken a look at your services?
You can access it either by going to “Administrative tools” and clicking “Services”…or you can click start, “Run” and type in services.msc
to bring up the window. Take a look at two services, “Base engine filtering” (BFE) and also scroll down and look at the entry Windows Firewall.
I assume they are not running…but you can try to start them by clicking at the top of the window, the green arrow, or simply right click the entries and choose “Start” from the context menu. Just make sure each service line is highlighted first Base filtering, then Windows Firewall entry as you try to start them one at a time.
The log you posted still shows Localhost is blocked. This I assume is due in part or fully to the fact windows firewall will not run, which may be the reason for the block report, while the BFE and MPSsvc related files are legit, there is still a problem with getting that firewall started. Also while you are checking within
the services.msc window, make sure both “Base Filtering Engine” and Windows Firewall are set to “Automatic” for start up type.
Obviously still something disallowing the firewall service. I am wondering if since “SFC” check fixed the corrupted files, if it would be worth trying to reset the winsock again with the following:
Click Start, then click “All programs”, then click “Accessories” folder…then Right Click “Command Prompt” and choose “Run as Administrator”, answer “Yes” to the prompt to allow this action.
Now within the command prompt window at the prompt, Type the following: “netsh winsock reset” (without the quotes) and then press ENTER.
My thought is after files were replaced, this may be of more assistance, also pay special attention to any errors reported after checking the above in services.msc and after going through the reset of the winsock as instructed. After resetting the winsock after checking the services, please reboot your computer and report back. It appears we are closer than before in getting to the bottom of this problem, but it is fairly clear either some form of infection began the problem, or the uninstall of Mcafee may have wiped out necessary data or a bit of both. At last the tdx.sys, BFE, etc. are showing legit. After reboot, run Farbar again and post report so we can see if anything at all has changed or improved.
Doing my best to figure out how to proceed, so please carefully review the above and report back any reported errors. I suspect if you can get that firewall up and running, it may get you your connectivity back in place…at least I am hoping.