Open a Commnad Prompt and execute...
netsh winsock reset
Then reboot the PC.
--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
| Dave - Sorry, it didn't fix the problem. I opened the Comm.Prompt from Start
| menu and wrote exactly what you said. It said I had to restart, which I did,
| but problems still persist. On Sunday, when I ran SpyBot (not updated),
| one of the errors that got "fixed" was under NewDotNet <$winsock>. C:\Prog
| Files\NewDotNet\ was not fixed - needed to run again at next startup. Could
| this be of importance?? Anu ideas out there?? Also, I installed sysclean,
| but when I click on it in Safe Mode, the DOS window flashes quickly and
| disappears.
New Dot Net does indeed a LSP plug-in that must be removed if you remove New Dot Net and if
you don't it breaks the TCP/IP stack.
Download both a copy of LSP Fix -- http://www.cexx.org/LSPFix.exe
and remove and non-OS LSP plug-ins.
http://www.cexx.org/lspfix.txt
| Sorry Dave that I "jumped" over to another group. I thought I could get more
| ideas to try.
| LSPFix doesn't seem to be doing it. The Keep list contains: mswsock.dll
| (Tcpip), winrnr.dll (NTDS), and rsvpsp.dll (Protocol handler). The Remove
| list has nothing in it. After I hit Finish, the report has all 0's.
| I am going to try to do these updates through dial-up later tonight, 'cuz
| maybe the problem is just with some erroneous setting on the network stuff.
| These people use dial-up, anyway. I'll advise.
| Also, I can try the manual updates PaBear mentioned - I just go to the
| actual website?? Talk to you later - prob. tom'w.
The Remove list has to be populated.
You have to check the box "I know what I am doing"
Then you have to select an item on the left. Click on the ">>" so the file shows on the
right side and then click "Finish".
However, the list you provided are legitimate and are not malware Layered Service Provider
(LSP) plug-ins.
We are goin to have to spend some time together running diagnostics...
To start off, execute; %windir%\system32\drivers\etc
Delete a file named; hosts (no extension to the name) if you see it.
Then open a command prompt and type...
ipconfig /flushdns
Then type...
ping yahoo.com
What are the results ?
Then...
ping 216.109.112.135
What are the results ?
| Dave -
| I went through Search to find that "etc" folder. It did have the hosts (no
| ext) file, which I sent to Recycle. Then I did the ipconfig, then pinged
| yahoo.
| Results: Pckts: Sent=4, Rec'd=4, Lost=0. Rd trip (ms): Min=674, Max=732,
| Avg=698.
| Ping the other address: Pckts: Sent=4, Rec'd=4. Rd trip: Mn 717ms, Mx 887ms,
| Avg 774ms.
| What can I do next? I am home most of today, so I'll try to watch carefully
| for your reply. Thanks. Barb
So it looks like you can ping and get resoltion via DNS. It looks like the TCP/IP stack is
OK.
Please try the update of; Ad-aware SE, SpyBot S&D and AVG again.
| Hi Dave - Had to run out for 20+ mins.
| Sorry, no go on the updates.
| One thing - they have NAV which comes up saying the Auto-Protect drivers are
| not working. When I first checked status, I saw that the definitions were
| outdated (5/27/05) and need to be renewed. That is why I installed AVG; the
| red X is thru the NAV tray icon, and I figured I'm OK. I did get in touch w/
| these people last night - they said thay bought a new NSW, so it's OK to go
| ahead and uninstall the NAV04. Do you think that might help??
| I'm doublechecking msconfig now. Before when I went thru it, I didn't
| uncheck any Symantec items. I just did now, and it's restarting........still
| no go on updates. Any more ideas?? Should I go ahead and uninstall NAV??
Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe
To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close
Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }
NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.
C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.
You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm
* * * Please report back your results * * *
--
Barb Zakrzewski
| Hi Dave -
| I made a folder C:\AC-CLS and D/L the Multi_AV.exe to it, then unzipped it
| there also. I disabled the Windows Firewall, and went thru the steps. Sophos
| (1) and Kaspersky (4) seemed to download, but Trend (2) and McAfee (3) had
| errors: ....read error code [0]. I tried again, and I also did the scans for
| (1) and (4). They seemed to go very fast (secs). When I went to Safe Mode, I
| tried (1), but it went to System Shutdown, 'cuz it said there was no info in
| Sophos, and I had to D/L again in Normal Mode. (I did notice that the folders
| for the four AVs were all empty 'cept Kas.) So on restart, I tried again,
| went back to Safe Mode, and tried (4). This time it went to System Shutdown
| 'cuz something was wrong w/ Kas files (?? forgot to jot it down). Right now,
| I think I am going to delete the whole \AV-CLS folder and start again.
| Should I have put the original zip file in that folder, or is that
| irrelevant?? Please advise. It is now 6:08PM my time and I'm tired!!
| I will definitely try this again, tho' tonight. The next 2 days I
| substitute teach, so my time will be more limited. Please be patient with my
| response time. Thanks. Barb
|
Yes !
But first open a command prompt. In the command prompt type...
ping ftp.nai.speedera.net
Please Copy & Paste the EXACT results into your reply.
Start again.
Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe
To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close
So just execute Multi_AV.exe it will create the folder, just don't change the default.
Then execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }
Then choose a module like Mcafee. You will see it download the file which is close to 8MB.
Pinging ftp.nai.speedera.net [63.209.221.236] with 32 bytes of data:
Reply from 63.209.221.236: bytes=32 time=781ms TTL=54
Reply from 63.209.221.236: bytes=32 time=829ms TTL=54
Reply from 63.209.221.236: bytes=32 time=759ms TTL=54
Reply from 63.209.221.236: bytes=32 time=789ms TTL=54
Ping statistics for 63.209.221.236:
Packets: Sent = 4, Received = 4, Lost = 0 <0% loss>,
Approximate round trip times in milli-seconds:
Minimum = 759ms, Maximum = 829ms, Average = 789ms
That's all for now; I don't know if I'll get to retry it tonight. Will post
as soon as I do. Thanks again.
--
Barb Zakrzewski
This is an HP computer that the guy said he did not have an OS CD; do you
think it might be time for some kind of restore?? I did at beginning of my
work disable System Restore, as I was doing all kinds of maintenance. This
comp is past warranty, but would company send a CD for Windows XP??
--
Barb Zakrzewski
| Dave - It's Wed almost 9AM (2 hr school delay for me)
| I retried the Multi_AV - SAME exact problem!
| Trying download Trend, get: \trend\pattern.txt not opened for READ, error
| code: [0]. When I checked the folders, KAV was 28kB, and the other three
| were empty.
| Any other ideas??
| This seems to be the trickiest one I've done yet.
|
| This is an HP computer that the guy said he did not have an OS CD; do you
| think it might be time for some kind of restore?? I did at beginning of my
| work disable System Restore, as I was doing all kinds of maintenance. This
| comp is past warranty, but would company send a CD for Windows XP??
Nope. No ideas. You can access the Internet but you can't download files at all and I
don't know why.
I suggest bringing the PC to a local, reputable, computer service center.
>Working on someone's computer at my home. I was able to d/l and run AVG
>Free, AdAware, and SpyBot, but several problems were encountered.
>When I try to update AVG, I get: "Update server connection failed. ..."
>With AdAware, just "Error retrieving update", and with SpyBot, "Error
>retrieving update information file. Socket Error #10061 Connection
>refused." I seem to be able to get to all web pages OK, just not the updates.
I remember this exact thing happen to a Windows ME two year ago. He
never told me the truth, but I believe he opened an email attachment.
I downloaded the latest versions from my PC to a thumb drive, then
to his desktop. It found various trojans, spy ware and a virus.
After deleting and cleaning they all crashed again when trying to
update. (NOTE* they all crashed the first time I installed them during
the first update. After uninstalling them and trying again WITHOUT
trying to update anything I got them to run.)
Reinstalled everything again and found it sitting in my system
restore files. Shut down system restore, reboot and every thing bad
was gone. I knew I had it when everything updated OK.
As I've typed this out, I've tried, but I can't for the life of me
remember what the virus was??? Sorry, but I hope this is a map to fix
whatever you may have.
HTH,
-zero
--
Barb Zakrzewski
--
Barb Zakrzewski
--
Barb Zakrzewski