Having problems after infection,errors appearing in some programs

Discussion in 'Windows - Virus and spyware problems' started by dermotk, Jul 3, 2008.

  1. dermotk

    dermotk Member

    Joined:
    Jan 22, 2008
    Messages:
    75
    Likes Received:
    0
    Trophy Points:
    16
    need help:after infection getting two errors at startup;(Rundll;error loading C:\windows\system32\wmyghtgq.dll and error loading C:\windows\system32\wkqijvfl.dll)the specific module could not be found.also could not run kaspersky online scanner because of java error;(java plugin fatal error;the java runtime environment cannot be loaded)and several java virtual machines running in the same process caused the error,also internet explorer security warning;windows has blocked this software because it can,t verify the publisher.
    have included sdfix and hijackthis report would appreciate any help.
    SDFix: Version 1.196
    Run by Dermot Kearney on Thu 07/03/2008 at 12:22

    Microsoft Windows XP [Version 5.1.2600]
    Running From: C:\SDFix

    Checking Services :


    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Rebooting


    Checking Files :

    Trojan Files Found:

    C:\Program Files\Setup.exe - Deleted





    Removing Temp Files

    ADS Check :



    Final Check :

    catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-07-03 12:35:05
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0


    Remaining Services :




    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
    "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
    "C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"="C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe:*:Enabled:McAfee Framework Service"
    "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
    "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
    "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
    "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
    "C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"="C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe:*:Enabled:Kaspersky Internet Security 7.0 Setup"
    "C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\sandra.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\sandra.exe:*:Enabled:SiSoftware Sandra Engineer"
    "C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\RpcSandraSrv.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Engineer"
    "C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\Win32\\RpcDataSrv.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\Win32\\RpcDataSrv.exe:*:Enabled:SiSoftware Sandra Engineer"
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
    "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
    "C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\sandra.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\sandra.exe:*:Enabled:SiSoftware Sandra Engineer"
    "C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\RpcSandraSrv.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Engineer"
    "C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\Win32\\RpcDataSrv.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Engineer 2007.SP1\\Win32\\RpcDataSrv.exe:*:Enabled:SiSoftware Sandra Engineer"

    Remaining Files :


    File Backups: - C:\SDFix\backups\backups.zip

    Files with Hidden Attributes :

    Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
    Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
    Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
    Mon 1 Oct 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
    Wed 5 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BITF.tmp"
    Wed 5 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BITD.tmp"
    Wed 5 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111678c52099a3b3123b12f2325\BIT11.tmp"
    Wed 5 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b04031f0b83ee952189dd8beb4ee929a\BITC.tmp"
    Wed 5 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b69c46c5109d0f8b0dee9fab84906813\BIT10.tmp"
    Wed 5 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b8fed23dd91f50d167cce60d3\BIT12.tmp"
    Wed 5 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fa6c916bb150f8a929e7a4ffdfbc120f\BITE.tmp"
    Mon 12 Feb 2007 3,096,576 A..H. --- "C:\Documents and Settings\Dermot Kearney\Application Data\U3\temp\Launchpad Removal.exe"
    Thu 18 Aug 2005 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
    Thu 18 Aug 2005 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch6\lock.tmp"
    Fri 2 Sep 2005 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch7\lock.tmp"
    Fri 4 May 2007 8 A..H. --- "C:\Documents and Settings\Dermot Kearney\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
    Fri 4 May 2007 8 A..H. --- "C:\Documents and Settings\Dermot Kearney\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
    Fri 4 May 2007 8 A..H. --- "C:\Documents and Settings\Dermot Kearney\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
    Fri 4 May 2007 8 A..H. --- "C:\Documents and Settings\Dermot Kearney\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"

    Finished!

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:52:33, on 7/3/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    C:\Program Files\ParetoLogic\Spam Controls\Pareto_SC.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\ParetoLogic\Spam Controls\FilterService.exe
    C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    C:\Program Files\Yahoo!\WIDGET~1\WidgetEngine\YahooWidgetEngine.exe
    C:\downloads\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.msn.com//
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {79644E21-21BB-4B12-BFBC-F8CEC3619285} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: (no name) - {FAAF4503-E52D-4B3B-9B12-D408F13AD817} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [IntelMeM] "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe"
    O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" /r
    O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
    O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
    O4 - HKLM\..\Run: [YCentral] c:\progra~1\yahoo!\YCentral\YahooCentral.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe"
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [7c320f4e] "rundll32.exe" "C:\WINDOWS\system32\wkqijvfl.dll",b
    O4 - HKLM\..\Run: [BM7f013cd2] "Rundll32.exe" "C:\WINDOWS\system32\wmyqhtgq.dll",s
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
    O4 - HKLM\..\Run: [Spam Controls] "C:\Program Files\ParetoLogic\Spam Controls\Pareto_SC.exe" -hideui
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [Spam Controls] "C:\Program Files\ParetoLogic\Spam Controls\Pareto_SC.exe" -hideui
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WIDGET~1\WidgetEngine\YahooWidgetEngine.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
    O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1176501749421
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: bw+0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw+0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: bwg0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwg0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
    O18 - Protocol: offline-8876480 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: fccaXRLC - fccaXRLC.dll (file missing)
    O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (file missing)
    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: ParetoLogic Mail Filter - ParetoLogic - C:\Program Files\ParetoLogic\Spam Controls\FilterService.exe
    O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Engineer 2007.SP1\Win32\RpcDataSrv.exe
    O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Engineer 2007.SP1\RpcSandraSrv.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

    --
    End of file - 26182 bytes
     
  2. ozy

    ozy Regular member

    Joined:
    Apr 17, 2003
    Messages:
    614
    Likes Received:
    0
    Trophy Points:
    26
    Download CCleaner and run in clean mode and registry mode which you will see on the left panel.
     
  3. dermotk

    dermotk Member

    Joined:
    Jan 22, 2008
    Messages:
    75
    Likes Received:
    0
    Trophy Points:
    16
    ozy,
    thanks for your reply i have run c/cleaner and saved the file.
    what next
     
  4. ozy

    ozy Regular member

    Joined:
    Apr 17, 2003
    Messages:
    614
    Likes Received:
    0
    Trophy Points:
    26
    1. “Disable System Restore” on all drives. http://download.nai.com/products/mcafee-avert/SystemHelpDocs/DisableSysRestore.htm

    2. Backup any sensitive data to an external drive, cd, dvd, separate partition or flash drive etc.

    3. Download CCleaner and save the file to your desktop. http://download.piriform.com/ccsetup209.exe
    a. Double click the install file
    b. Select the language and click OK
    c. Click next
    d. Click “I Agree”
    e. Click Next
    f. Untick the bottom checkbox and click install
    g. Click Finish
    h. You can delete the install file now or save it for future installations
    i. Open CCleaner from the desktop shortcut
    j. Click on the “Applications” tab and make sure all are ticked
    k. Click on “Analyze” at bottom
    l. Once finished scan click on run cleaner, bottom right
    m. Click on thr “Registry” button on the left panel
    n. Select “Scan for Issues”
    o. Click “Fix selected Issues” When asked to make a backup click YES and save the file somewhere safe
    p. Click on “Fix All Selected Issues”
    q. Click OK, Click close
    r. Repeat steps from letter “K” to “Q”
    s. Close the program.

    4. Download all three files to a folder on your desktop. Extract both zip files to the same folder. double click the sysclean file and follow the prompt. Click on the advanced button underneath for more options prior to scanning.

    SystemClean
    http://www.trendmicro.com/ftp/products/tsc/sysclean.com

    Virus Patten File
    http://www.trendmicro.com/ftp/products/pattern/lpt383.zip

    Malware Patten File
    http://www.trendmicro.com/ftp/products/pattern/spyware/ssapi/ssapiptn663.zip


    5. Download CWShredder and scan your system for “CoolWebSearch” malware.
    http://www.trendmicro.com/ftp/products/online-tools/cwshredder.exe
     
  5. dermotk

    dermotk Member

    Joined:
    Jan 22, 2008
    Messages:
    75
    Likes Received:
    0
    Trophy Points:
    16
    ozy,
    carrying out your instructions will get back when complete.
    thanks for your help.
     
  6. dermotk

    dermotk Member

    Joined:
    Jan 22, 2008
    Messages:
    75
    Likes Received:
    0
    Trophy Points:
    16
    ozy,
    all your instructions carried out,what next.
     
  7. ozy

    ozy Regular member

    Joined:
    Apr 17, 2003
    Messages:
    614
    Likes Received:
    0
    Trophy Points:
    26
    10. Next you can do a quick Spyware Audit which won’t actually install any program but just check the system for infection to see where we are in the fight against Spyware/Viruses

    a. Go here and follow the prompts. If you have no internet, skip this step.
    http://www.webroot.com/services/entaudit/auditbegin.php
    b. Click on the link and save the file to your “Desktop”
    c. Run the file and wait for all 5 steps to finish
    d. View the displayed results. If your system only shows cookies then you’re OK. If your system has any other one of three groups then more work needs to be done.
     
  8. dermotk

    dermotk Member

    Joined:
    Jan 22, 2008
    Messages:
    75
    Likes Received:
    0
    Trophy Points:
    16
    ozy,
    cannot connect to the internet in normal mode after carrying out your instructions last evening.i am working in safe mode at present,what can i do to return to normal mode and connect to the internet.
    when i tried to connect to the internet i got this message;
    windows has detected a problem with winsock provider calalog on this computer,this catalog allows programs to communicate with computer access to the network,would you like windows to reset the catalog to the default configuration,i have tried this twice put to no avail,
    in safe mode i ran superantispyware and found 19 infections,18 registry items;(rogue advanced antivirus 2008)1 file item;rogue antivirus xp 2008 i have quarentine and removed these from my computer,but still cannot connect in normal mode,
    need help urgently;

    Spy audit results; Current Risk Low

    Spyware Found on Your Enterprise Code 744815326
    Audit Time Trojans System Monitors Adware Adware Cookies




    Audit Summar
    Spyware was found within your Enterprise.Spyware is a term used to describe any program that tracks online activities and secretly transmitsinformation to a third party.
    The effects of spyware in a corporation include:
    • Threatened security of corporate intellectual property
    • Unnecessary burden on IT staff
    • Reduced employee productivity
    • Increased bandwidth consumption
    • Diminished workstation performance and network stability
    • Conflicts with legitimate software programs

    Once present on a machine, spyware removal is arduous and time-consuming. Many spyware programs deposit dozens if not hundreds of program traces, making manual removal nearly impossible. Businesses need to address the spyware threat immediately, to avoid compromising the security of proprietary intellectual property.

    Remove Spyware Now


    Eliminate spyware and regain control of your enterprise with Spy Sweeper Enterprise.

    Contact a Webroot Enterprise Sales Representative today to find out more.

    Call Now: 1.800.870.8102
    For contact numbers outside the U.S., click here
     
    Last edited: Jul 5, 2008
  9. ozy

    ozy Regular member

    Joined:
    Apr 17, 2003
    Messages:
    614
    Likes Received:
    0
    Trophy Points:
    26
    Restart computer. Do you have internet. If so continue with the following:
    While trying all these different programs make sure you limit Real-time Anti-Virus programs to one per system at any time. If you decide to try a different anti-virus make sure to uninstall the current one.
    Try and use the same rule for Anti-Spyware programs with real-time functuality aswell. Otherwise you will compromise your system resources.

    After completing steps, restart your system and use CCleaner again once restarted. Then carry on to next task.

    6. Download Trial version of Nod32 Anti-Virus 3.0
    for Windows XP/2000/Vista (32-bit)
    http://download1.eset.com/eval/win/eav/eav_nt32_enu.msi

    for Windows XP/2000/Vista (64-bit ONLY)
    http://download1.eset.com/eval/win/eav/eav_nt64_enu.msi


    Installation mode: Typical
    Enable threatsense early warning system
    Enable Detection of potentially unwanted applications

    You have now finished the install. Restart the computer and then right click on the Nod32 bottom toolbar icon and select “update”.
    Now you can scan your pc so again right click on the toolbar icon and select “computer scan”. Select “My Computer” and then select “Scan” at the bottom right.
    Wait for scan to finish to review results making sure any Bad files are Quarantined.

    7. Download and install Counterspy v2 trial version for 15 day fully functional.
    http://go.sunbelt-software.com/?linkid=410
    a. Click Next
    b. Agree to the license agreement
    c. Click Next
    d. Click Next again
    e. Click Install
    f. Click Finish – The check box above should be ticked to open the program.
    g. Click next – Getting Started
    h. Click next if using demo version
    i. Click next to enable automatic updates
    j. Select “YES” and Select “CAUTIOUS” then Next
    k. Select “YES” then Finish
    l. Select “Enter Counterspy Now”

    To update the CounterSpy application and security risk definitions Click Updates on the toolbar or select File - Check for updates... from the menu bar. The Update Services window opens and downloads the available updates. After it is complete, click Close.

    m. Now you are ready for a full system scan
    n. Select “System Scan” from the left menu
    o. Select “Full System”
    p. Select “Low Risk Programs”
    q. Select “Cookies”
    r. Select “Save Options”
    s. Above Select “Scan Now”

    Please wait for scan to complete. To be on the safe side “Quarantine All Objects”.

    Now click on “System Tools” and click “My PC Checkup” and Click “Start”.
    Click Continue and “OK”.

    Now go back into “System Tools” and select “PC Explorer”. Here you can check startup programs, ActiveX controls, BHO files, and much more. If unsure how to use leave as is for now.

    8. Restart your PC.
    9. You can do a scan with CCleaner again.

     
  10. dermotk

    dermotk Member

    Joined:
    Jan 22, 2008
    Messages:
    75
    Likes Received:
    0
    Trophy Points:
    16
    ozy,
    cannot access the internet in normal mode and cannot use the programs you listed in safe mode as program says system administrator has set policies to prevent installation.
    thanks for all you help ozy,i have run a hijackthis scan again,
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:50:46, on 7/6/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Safe mode with network support

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\downloads\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.msn.com//
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {79644E21-21BB-4B12-BFBC-F8CEC3619285} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: (no name) - {FAAF4503-E52D-4B3B-9B12-D408F13AD817} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [IntelMeM] "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe"
    O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" /r
    O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
    O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
    O4 - HKLM\..\Run: [YCentral] c:\progra~1\yahoo!\YCentral\YahooCentral.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe"
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [7c320f4e] "rundll32.exe" "C:\WINDOWS\system32\wkqijvfl.dll",b
    O4 - HKLM\..\Run: [BM7f013cd2] "Rundll32.exe" "C:\WINDOWS\system32\wmyqhtgq.dll",s
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
    O4 - HKLM\..\Run: [Spam Controls] "C:\Program Files\ParetoLogic\Spam Controls\Pareto_SC.exe" -hideui
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [Spam Controls] "C:\Program Files\ParetoLogic\Spam Controls\Pareto_SC.exe" -hideui
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WIDGET~1\WidgetEngine\YahooWidgetEngine.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - http://dl.tvunetworks.com/TVUAx.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1176501749421
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: bw+0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw+0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: bwg0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwg0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0s - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
    O18 - Protocol: offline-8876480 - {2C27A329-B092-4A05-8A47-5E2087708C06} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: fccaXRLC - fccaXRLC.dll (file missing)
    O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (file missing)
    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: ParetoLogic Mail Filter - ParetoLogic - C:\Program Files\ParetoLogic\Spam Controls\FilterService.exe
    O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Engineer 2007.SP1\Win32\RpcDataSrv.exe
    O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Engineer 2007.SP1\RpcSandraSrv.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

    --
    End of file - 24339 bytes
     
    Last edited: Jul 6, 2008
  11. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Hi dermotk,

    Try the following:

    Manually restoring the Internet connection

    1. Click on the Start button.
    2. Click on the Settings menu option.
    3. Click on the Control Panel option.
    4. When the Control Panel opens, double-click on the Network Connections icon. If your Control Panel is set to Category View, then double-click on Network and Internet Connections and then click on Network Connections at the bottom.
    5. You will now see a list of available network connections. Locate the connection for your Wireless or Lan adapter and right-click on it.
    6. Simply click on the Repair menu option.
    7. Let the repair process perform its tasks and when it has finished, your Internet connection should be working again.


    2OG
     
    Last edited: Jul 7, 2008
  12. dermotk

    dermotk Member

    Joined:
    Jan 22, 2008
    Messages:
    75
    Likes Received:
    0
    Trophy Points:
    16
    2oldgeek,
    thanks for your help,carried out your instructions but still cannot connect to the internet in normal mode,the diagnostic report said that there was an winsock2 error and
    could not make an http connection,
    could not make an https connection,
    could not make an ftp connection,
    any further help would be appreciated.
     
  13. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Oooooooooooh dermotk,

    Looking back over this thread, I see where ozy suggested that you “Disable System Restore”. I sure hope you didn’t do that. My rule is: Never clear your System Restore unless your computer is clean and functioning properly. If you Bork your computer, and loose functionality, then even a restore point that’s infected is better than no restore point at all. As they say “Any old port in a storm”.

    If , by chance, you still have a restore point that’s prior to your loosing the internet give it a try to see if you can regain your internet connection in normal mode. Then we can work on your infections that remain.


    Luck be with you….
    2OG
     
  14. dermotk

    dermotk Member

    Joined:
    Jan 22, 2008
    Messages:
    75
    Likes Received:
    0
    Trophy Points:
    16
    2oldgeek,
    unfortunately i did as ozy instructed and turned off system restore,
    hope you can help.
    i copied a diagnostic report after i tried the fix see below
    Network Diagnostics for Windows XP
    Last diagnostic run time: 07/07/08 11:17:42
    component name="HTTP, HTTPS, FTP Diagnostic" startDiagnosisTime="07/07/08 11:17:42"
    rootCause name="HTTP, HTTPS, FTP connectivity" status="confirm">

    Type="warn" text="FTP (Passive): Error 12007 connecting to ftp.microsoft.com: The server name or address could not be resolved
    "
    Type="warn" text="HTTPS: Error 12007 connecting to www.microsoft.com: The server name or address could not be resolved"
    Type="warn" text="FTP (Active): Error 12007 connecting to ftp.microsoft.com: The server name or address could not be resolved"
    Type="warn" text="HTTP: Error 12007 connecting to www.microsoft.com: The server name or address could not be resolved"
    Type="warn" text="HTTP: Error 12007 connecting to www.hotmail.com: The server name or address could not be resolved"
    Type="warn" text="HTTPS: Error 12007 connecting to www.passport.net: The server name or address could not be resolved

    Type="error" text="Could not make an HTTP connection."
    Type="error" text="Could not make an HTTPS connection."
    Type="error" text="Could not make an FTP connection."
    component name="Network Adapter Diagnostic" start DiagnosisTime="07/07/08 11:18:33">

    name="Network location detection" status="reject">

    Type="info" text="Using home Internet connection">

    name="Network adapter identification" status="reject">

    Type="info" text="Network connection: Name=Local Area Connection, Device=Intel(R) PRO/100 VE Network Connection, MediaType=LAN, SubMediaType=LAN">


    Type="info" text="Ethernet connection selected" name="Network adapter status" status="reject"
    Type="info" text="Network connection status: Connected"
    component name="WinSock Diagnostic" start Diagnosis Time="07/07/08 11:18:34"
    name="WinSock status" status="confirm"
    Type="info" text="Error attmpting to validate the Winsock base providers: 2">
    Type="error" text="Not all base service provider entries could be found in the winsock catalog. A reset is needed."

    Type="info" text="Redirecting user to support call"
    hope this will help.

     
    Last edited: Jul 7, 2008
  15. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Hey dermotk,

    When you loose functionality and don’t have a restore point to go back to, anything from there is a Crap Shoot at best.

    I personally have a complete HD backup using Acronis True Image. It makes a Backup every day and I am never more than 24Hours behind if something happens and I must restore it. That takes about 6 minutes to step my entire HD back to yesterday or before.

    We’ll give this the old try, try, try but I can’t guarantee anything so don’t get your hopes up too far.

    There are two easy ways to determine if Winsock2 is damaged:
    Winsock Test Method 1

    go to -> Start -> Run and type in netdiag /test:winsock ( get the space between the g and / )
    The end should say Winsock test ….. passed

    Winsock Test Method 2

    Run Msinfo32
    Click on the + by Components
    Click on the by Network
    Click on Protocol
    There should be 10 sections if the Winsock2 key is ok
    MSAFD Tcpip [TCP/IP]
    MSAFD Tcpip [UDP/IP]
    RSVP UDP Service Provider
    RSVP TCP Service Provider
    MSAFD NetBIOS [\Device\NetBT_Tcpip…
    MSAFD NetBIOS [\Device\NetBT_Tcpip…
    MSAFD NetBIOS [\Device\NetBT_Tcpip…
    MSAFD NetBIOS [\Device\NetBT_Tcpip…
    MSAFD NetBIOS [\Device\NetBT_Tcpip…
    MSAFD NetBIOS [\Device\NetBT_Tcpip…

    If the names are anything different from those in this list, then likely Winsock2 is corrupted and needs to be repaired.

    If you have any 3rd party software installed, the name MSAFD may be changed.

    There should be no fewer than 10 sections.

    Run these and let me know what it turns up.. Copy and paste the results to me, please.

    2OG
     
  16. dermotk

    dermotk Member

    Joined:
    Jan 22, 2008
    Messages:
    75
    Likes Received:
    0
    Trophy Points:
    16
    2oldgeek,unable to run method 1 netdiag/test:winsock it said.windows could not find.
    result of method 2 below.
    much appreciate your assistance 2oldgeek,


    Name MSAFD Tcpip [TCP/IP]
    Connectionless Service No
    Guarantees Delivery Yes
    Guarantees Sequencing Yes
    Maximum Address Size 16 bytes
    Maximum Message Size 0 bytes
    Message Oriented No
    Minimum Address Size 16 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting No
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data Yes
    Supports Graceful Closing Yes
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD Tcpip [UDP/IP]
    Connectionless Service Yes
    Guarantees Delivery No
    Guarantees Sequencing No
    Maximum Address Size 16 bytes
    Maximum Message Size 63.93 KB (65,467 bytes)
    Message Oriented Yes
    Minimum Address Size 16 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting Yes
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting Yes

    Name RSVP UDP Service Provider
    Connectionless Service Yes
    Guarantees Delivery No
    Guarantees Sequencing No
    Maximum Address Size 16 bytes
    Maximum Message Size 63.93 KB (65,467 bytes)
    Message Oriented Yes
    Minimum Address Size 16 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting Yes
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption Yes
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting Yes

    Name RSVP TCP Service Provider
    Connectionless Service No
    Guarantees Delivery Yes
    Guarantees Sequencing Yes
    Maximum Address Size 16 bytes
    Maximum Message Size 0 bytes
    Message Oriented No
    Minimum Address Size 16 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting No
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption Yes
    Supports Expedited Data Yes
    Supports Graceful Closing Yes
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD nwlnkipx [IPX]
    Connectionless Service Yes
    Guarantees Delivery No
    Guarantees Sequencing No
    Maximum Address Size 16 bytes
    Maximum Message Size 576 bytes
    Message Oriented Yes
    Minimum Address Size 14 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting Yes
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting Yes

    Name MSAFD nwlnkspx [SPX]
    Connectionless Service No
    Guarantees Delivery Yes
    Guarantees Sequencing Yes
    Maximum Address Size 16 bytes
    Maximum Message Size (1) bytes
    Message Oriented Yes
    Minimum Address Size 14 bytes
    Pseudo Stream Oriented Yes
    Supports Broadcasting No
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD nwlnkspx [SPX] [Pseudo Stream]
    Connectionless Service No
    Guarantees Delivery Yes
    Guarantees Sequencing Yes
    Maximum Address Size 16 bytes
    Maximum Message Size 0 bytes
    Message Oriented Yes
    Minimum Address Size 14 bytes
    Pseudo Stream Oriented Yes
    Supports Broadcasting No
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD nwlnkspx [SPX II]
    Connectionless Service No
    Guarantees Delivery Yes
    Guarantees Sequencing Yes
    Maximum Address Size 16 bytes
    Maximum Message Size (1) bytes
    Message Oriented Yes
    Minimum Address Size 14 bytes
    Pseudo Stream Oriented Yes
    Supports Broadcasting No
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing Yes
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD nwlnkspx [SPX II] [Pseudo Stream]
    Connectionless Service No
    Guarantees Delivery Yes
    Guarantees Sequencing Yes
    Maximum Address Size 16 bytes
    Maximum Message Size 0 bytes
    Message Oriented Yes
    Minimum Address Size 14 bytes
    Pseudo Stream Oriented Yes
    Supports Broadcasting No
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing Yes
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD NetBIOS [\Device\NwlnkNb] SEQPACKET 3
    Connectionless Service No
    Guarantees Delivery Yes
    Guarantees Sequencing Yes
    Maximum Address Size 20 bytes
    Maximum Message Size 62.50 KB (64,000 bytes)
    Message Oriented Yes
    Minimum Address Size 20 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting No
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD NetBIOS [\Device\NwlnkNb] DATAGRAM 3
    Connectionless Service Yes
    Guarantees Delivery No
    Guarantees Sequencing No
    Maximum Address Size 20 bytes
    Maximum Message Size 62.50 KB (64,000 bytes)
    Message Oriented Yes
    Minimum Address Size 20 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting Yes
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD NetBIOS [\Device\NetBT_Tcpip_{3BBF674C-1113-41D3-B7DF-E12A5AB9EF53}] SEQPACKET 0
    Connectionless Service No
    Guarantees Delivery Yes
    Guarantees Sequencing Yes
    Maximum Address Size 20 bytes
    Maximum Message Size 62.50 KB (64,000 bytes)
    Message Oriented Yes
    Minimum Address Size 20 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting No
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD NetBIOS [\Device\NetBT_Tcpip_{3BBF674C-1113-41D3-B7DF-E12A5AB9EF53}] DATAGRAM 0
    Connectionless Service Yes
    Guarantees Delivery No
    Guarantees Sequencing No
    Maximum Address Size 20 bytes
    Maximum Message Size 62.50 KB (64,000 bytes)
    Message Oriented Yes
    Minimum Address Size 20 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting Yes
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD NetBIOS [\Device\NetBT_Tcpip_{FB458613-4778-4C16-92F4-0450C437C848}] SEQPACKET 1
    Connectionless Service No
    Guarantees Delivery Yes
    Guarantees Sequencing Yes
    Maximum Address Size 20 bytes
    Maximum Message Size 62.50 KB (64,000 bytes)
    Message Oriented Yes
    Minimum Address Size 20 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting No
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD NetBIOS [\Device\NetBT_Tcpip_{FB458613-4778-4C16-92F4-0450C437C848}] DATAGRAM 1
    Connectionless Service Yes
    Guarantees Delivery No
    Guarantees Sequencing No
    Maximum Address Size 20 bytes
    Maximum Message Size 62.50 KB (64,000 bytes)
    Message Oriented Yes
    Minimum Address Size 20 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting Yes
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD NetBIOS [\Device\NetBT_Tcpip_{74046427-157B-460E-8CF1-35C9520B9896}] SEQPACKET 2
    Connectionless Service No
    Guarantees Delivery Yes
    Guarantees Sequencing Yes
    Maximum Address Size 20 bytes
    Maximum Message Size 62.50 KB (64,000 bytes)
    Message Oriented Yes
    Minimum Address Size 20 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting No
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No

    Name MSAFD NetBIOS [\Device\NetBT_Tcpip_{74046427-157B-460E-8CF1-35C9520B9896}] DATAGRAM 2
    Connectionless Service Yes
    Guarantees Delivery No
    Guarantees Sequencing No
    Maximum Address Size 20 bytes
    Maximum Message Size 62.50 KB (64,000 bytes)
    Message Oriented Yes
    Minimum Address Size 20 bytes
    Pseudo Stream Oriented No
    Supports Broadcasting Yes
    Supports Connect Data No
    Supports Disconnect Data No
    Supports Encryption No
    Supports Expedited Data No
    Supports Graceful Closing No
    Supports Guaranteed Bandwidth Yes
    Supports Multicasting No
     
    Last edited: Jul 7, 2008
  17. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Hi dermotk,

    I don’t really see any faults in that but, as a good shot in the dark as opposed to a reformat/reinstall, lets try running:

    WinSock XP Fix 1.2 -> Download Link

    It can create a registry backup of your current settings, so it is fairly safe to use.
    Run the Utility and then re-boot..

    Let me know…..
    2OG
     
  18. dermotk

    dermotk Member

    Joined:
    Jan 22, 2008
    Messages:
    75
    Likes Received:
    0
    Trophy Points:
    16
    2oldgeek,
    downloaded and ran WinSock XP Fix 1.2 but still could not access the internet in normal mode.
     
    Last edited: Jul 7, 2008
  19. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Hi dermotk,
    Well, I’ve been doing some research on the matter and hopefully I can come up with something.
    If not, I sure hope you have a means to reformat/reinstall.. I usually only recommend that at the point of No Hope….

    Give me a little more time and we’ll see…

    Hang in there,
    2OG
     
  20. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Hey dermotk,
    One more shot…

    Download LSPFix : HERE

    unzip and run LSPFix.exe

    Check "I know what I am doing" , move all entries from left to right and then click finish .

    REBOOT

    Now run WinsockFix again..

    REBOOT


    Buddy, if that don’t get it, I’ve ran out of options…..


    2OG
     

Share This Page