BleepingComputer.com: After Virus wireless cannot obtain a IP address

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
  • 4 Pages +
  • 1
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • You cannot reply to this topic

After Virus wireless cannot obtain a IP address

#16 User is offline   narenxp 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 2,739
  • Joined: 24-October 11
  • Gender:Male
  • Location:India

Posted 11 February 2012 - 05:20 PM

@ noknojon

:thumbup2:

@bennorton

Right click on transferred file

Click on OPEN WITH

click on BROWSE

Navigate to C:/WINDOWS

Select a file called REGEDIT and click ok

Click YES now

Restart the PC

This post has been edited by hamluis: 22 February 2012 - 01:13 PM
Reason for edit: Moved from XP to Am I Infected.


#17 User is offline   bennorton 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 29
  • Joined: 16-January 12

Posted 18 February 2012 - 09:58 AM

Sorry for the delay - file was succesfully added to reg - computer restarted and here is new fss


Farbar Service Scanner Version: 10-02-2012
Ran by Kelly Morse (administrator) on 18-02-2012 at 09:57:46
Running from "C:\Documents and Settings\Kelly Morse\Desktop"
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============
Dhcp Service is not running. Checking service configuration:
The start type of Dhcp service is OK.
The ImagePath of Dhcp service is OK.
The ServiceDll of Dhcp service is OK.

NetBt Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open NetBt registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open NetBt registry key. The service key does not exist.


Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Attempt to access Google IP returned error: Google IP is unreachable
Attempt to access Yahoo IP returend error: Yahoo IP is unreachable


Windows Firewall:
=============
sharedaccess Service is not running. Checking service configuration:
The start type of sharedaccess service is set to Disabled. The default start type is Auto.
The ImagePath of sharedaccess service is OK.
The ServiceDll of sharedaccess service is OK.


Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall"=DWORD:0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking LEGACY_wscsvc: Attention! Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist.


Windows Update:
============

File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
Attention! C:\WINDOWS\system32\Drivers\netbt.sys is missing.
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe
[2008-04-25 11:16] - [2008-04-14 07:00] - 0039424 ____A (Microsoft Corporation) CC3647D0E41550ACAA66FF9F4B40D6BC

C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
Gpc(6) IPSec(4) NwlnkIpx(9) NwlnkNb(10) PSched(7) SYMTDI(11) Tcpip(3) Tcpip6(13)
0x0D000000040000000100000002000000030000000B00000008000000050000000600000007000000090000000A0000000C0000000D000000
IpSec Tag value is correct.

**** End of log ****

#18 User is offline   narenxp 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 2,739
  • Joined: 24-October 11
  • Gender:Male
  • Location:India

Posted 18 February 2012 - 11:12 AM

Launch FSS again and type

netbt.sys
in search BOX and click on search files

post the generated log

#19 User is offline   bennorton 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 29
  • Joined: 16-January 12

Posted 18 February 2012 - 11:39 AM

Farbar Service Scanner Version: 10-02-2012
Ran by Kelly Morse (administrator) on 18-02-2012 at 11:34:28
Microsoft Windows XP Professional Service Pack 3 (X86)

************************************************
======== Search: "netbt.sys" =========

====== End Of Search ======

after seeing this i ran the last step you gave me again figuring i did something wrong and saved and restarted - same result

#20 User is offline   narenxp 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 2,739
  • Joined: 24-October 11
  • Gender:Male
  • Location:India

Posted 18 February 2012 - 04:01 PM

Do you have your OS CD?

We are missing netbt.sys

We need to find a copy,let me see if i can get you one

This post has been edited by narenxp: 18 February 2012 - 04:01 PM


#21 User is offline   bennorton 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 29
  • Joined: 16-January 12

Posted 19 February 2012 - 11:59 AM

i will look for the OS -

#22 User is offline   bennorton 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 29
  • Joined: 16-January 12

Posted 22 February 2012 - 09:30 AM

Found - Reinstallation CD - of the OS xp pro service pack 3 -

Found netbt.sy_ opened with notepad to view it its all jargon -

Repeated the steps you had me do above when you posted the netbt file -

opened it with regedit and added to registry - error -

Registry Editor - Cannot import Netbt.sys The specified file is not a registry script you can only import binary registry files from the reg editor -


unsure of next step - Thanks again for your help with this

This post has been edited by bennorton: 22 February 2012 - 09:37 AM


#23 User is offline   narenxp 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 2,739
  • Joined: 24-October 11
  • Gender:Male
  • Location:India

Posted 22 February 2012 - 09:42 AM

Ok,lets look at registry later,now

Insert your OS CD

Press windows+R key and type

cmd and click ok

Run these commands

expand e:\I386\netbt.sy_ c:\windows\system32\dllcache\netbt.sys
expand e:\I386\netbt.sy_ c:\windows\system32\drivers\netbt.sys


NOTE:The letter e should be replaced with your CD drive letter

Launch FSS again and type

netbt.sys in search BOX and click on search files

post the generated log

#24 User is offline   bennorton 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 29
  • Joined: 16-January 12

Posted 22 February 2012 - 09:50 AM

Farbar Service Scanner Version: 10-02-2012
Ran by Kelly Morse (administrator) on 22-02-2012 at 09:49:33
Microsoft Windows XP Professional Service Pack 3 (X86)

************************************************
======== Search: "netbt.sys" =========

C:\WINDOWS\system32\drivers\netbt.sys
[2012-02-22 09:48] - [2008-04-14 00:51] - 0162816 ____A (Microsoft Corporation) 74B2B2F5BEA5E9A3DC021D685551BD3D

C:\WINDOWS\system32\dllcache\netbt.sys
[2012-02-22 09:48] - [2008-04-14 00:51] - 0162816 ___AC (Microsoft Corporation) 74B2B2F5BEA5E9A3DC021D685551BD3D

====== End Of Search ======

#25 User is offline   narenxp 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 2,739
  • Joined: 24-October 11
  • Gender:Male
  • Location:India

Posted 22 February 2012 - 09:53 AM

BOOT THE PC into safemode


Press WIndows+R key and type

notepad and click ok

Copy the script


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"Tag"=dword:00000006
"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
  52,00,49,00,56,00,45,00,52,00,53,00,5c,00,6e,00,65,00,74,00,62,00,74,00,2e,\
  00,73,00,79,00,73,00,00,00
"DisplayName"="NetBios over Tcpip"
"Group"="PNP_TDI"
"DependOnService"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"Description"="NetBios over Tcpip"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Linkage]
"OtherDependencies"=hex(7):54,00,63,00,70,00,69,00,70,00,00,00,00,00
"Bind"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,54,00,63,00,70,\
  00,69,00,70,00,5f,00,7b,00,45,00,36,00,44,00,33,00,31,00,34,00,43,00,43,00,\
  2d,00,39,00,43,00,31,00,35,00,2d,00,34,00,35,00,46,00,46,00,2d,00,39,00,41,\
  00,39,00,43,00,2d,00,46,00,35,00,32,00,34,00,35,00,42,00,41,00,36,00,45,00,\
  41,00,42,00,37,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,\
  00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,31,00,35,00,37,00,34,00,42,00,\
  36,00,36,00,36,00,2d,00,39,00,34,00,30,00,45,00,2d,00,34,00,41,00,41,00,31,\
  00,2d,00,38,00,45,00,33,00,42,00,2d,00,33,00,31,00,30,00,32,00,44,00,44,00,\
  33,00,39,00,42,00,42,00,43,00,31,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,\
  00,63,00,65,00,5c,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,41,00,32,00,\
  37,00,34,00,44,00,35,00,42,00,38,00,2d,00,36,00,34,00,42,00,46,00,2d,00,34,\
  00,41,00,46,00,34,00,2d,00,39,00,43,00,45,00,31,00,2d,00,43,00,38,00,37,00,\
  34,00,35,00,31,00,31,00,38,00,41,00,35,00,36,00,32,00,7d,00,00,00,00,00
"Route"=hex(7):22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,45,\
  00,36,00,44,00,33,00,31,00,34,00,43,00,43,00,2d,00,39,00,43,00,31,00,35,00,\
  2d,00,34,00,35,00,46,00,46,00,2d,00,39,00,41,00,39,00,43,00,2d,00,46,00,35,\
  00,32,00,34,00,35,00,42,00,41,00,36,00,45,00,41,00,42,00,37,00,7d,00,22,00,\
  00,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,4e,00,64,00,69,\
  00,73,00,57,00,61,00,6e,00,49,00,70,00,22,00,00,00,00,00
"Export"=hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,\
  00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,45,00,36,00,\
  44,00,33,00,31,00,34,00,43,00,43,00,2d,00,39,00,43,00,31,00,35,00,2d,00,34,\
  00,35,00,46,00,46,00,2d,00,39,00,41,00,39,00,43,00,2d,00,46,00,35,00,32,00,\
  34,00,35,00,42,00,41,00,36,00,45,00,41,00,42,00,37,00,7d,00,00,00,5c,00,44,\
  00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,\
  54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,31,00,35,00,37,00,34,00,42,00,36,\
  00,36,00,36,00,2d,00,39,00,34,00,30,00,45,00,2d,00,34,00,41,00,41,00,31,00,\
  2d,00,38,00,45,00,33,00,42,00,2d,00,33,00,31,00,30,00,32,00,44,00,44,00,33,\
  00,39,00,42,00,42,00,43,00,31,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,\
  63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,\
  00,70,00,5f,00,7b,00,41,00,32,00,37,00,34,00,44,00,35,00,42,00,38,00,2d,00,\
  36,00,34,00,42,00,46,00,2d,00,34,00,41,00,46,00,34,00,2d,00,39,00,43,00,45,\
  00,31,00,2d,00,43,00,38,00,37,00,34,00,35,00,31,00,31,00,38,00,41,00,35,00,\
  36,00,32,00,7d,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters]
"NbProvider"="_tcp"
"NameServerPort"=dword:00000089
"CacheTimeout"=dword:000927c0
"BcastNameQueryCount"=dword:00000003
"BcastQueryTimeout"=dword:000002ee
"NameSrvQueryCount"=dword:00000003
"NameSrvQueryTimeout"=dword:000005dc
"Size/Small/Medium/Large"=dword:00000001
"SessionKeepAlive"=dword:0036ee80
"TransportBindName"="\\Device\\"
"EnableLMHOSTS"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{1574B666-940E-4AA1-8E3B-3102DD39BBC1}]
"NameServerList"=hex(7):00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{A274D5B8-64BF-4AF4-9CE1-C8745118A562}]
"NameServerList"=hex(7):00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{E6D314CC-9C15-45FF-9A9C-F5245BA6EAB7}]
"NameServerList"=hex(7):00,00
"NetbiosOptions"=dword:00000000
"DhcpNameServerList"=hex(7):31,00,39,00,32,00,2e,00,31,00,36,00,38,00,2e,00,31,\
  00,33,00,33,00,2e,00,32,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Security]
"Security"=hex:01,00,14,80,e8,00,00,00,f4,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,b8,00,08,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
  05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
  02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,25,02,\
  00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,00,00,14,\
  00,40,00,00,00,01,01,00,00,00,00,00,05,13,00,00,00,00,00,14,00,40,00,00,00,\
  01,01,00,00,00,00,00,05,14,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,\
  00,00,05,20,00,00,00,2c,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Enum]
"0"="Root\\LEGACY_NETBT\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001



Save it as

Filename:netbt.reg
Filetype:All files

Launch the netbt.reg and click YES

Restart the PC and post the new FSS log

#26 User is offline   bennorton 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 29
  • Joined: 16-January 12

Posted 22 February 2012 - 10:00 AM

computer wont boot into safe mode - comes up with windows vista boot manager - which gives me only 2 options windows vista which is not the os and windows memory diag

can i do it in regular mode -

also i assume i open the file with the regeditor like before

This post has been edited by bennorton: 22 February 2012 - 10:03 AM


#27 User is offline   narenxp 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 2,739
  • Joined: 24-October 11
  • Gender:Male
  • Location:India

Posted 22 February 2012 - 10:02 AM

There seems to be error importing the registry key which looks like something is blocking the import

Try it in regular mode again.If you can add it successsfully.Restart the PC

Post the new FSS LOG.

I will ask moderators to move this to am i infected forum to see if PC is still infected

good luck

This post has been edited by narenxp: 22 February 2012 - 10:04 AM


#28 User is offline   bennorton 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 29
  • Joined: 16-January 12

Posted 22 February 2012 - 10:04 AM

i can almost gurantee its not infected i just looked at the safe mode issue and its something to do with the install of drivers from the factory

#29 User is offline   bennorton 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 29
  • Joined: 16-January 12

Posted 22 February 2012 - 10:07 AM

Succesfully added file -

New FSS log -

Farbar Service Scanner Version: 10-02-2012
Ran by Kelly Morse (administrator) on 22-02-2012 at 10:07:23
Running from "C:\Documents and Settings\Kelly Morse\Desktop"
Microsoft Windows XP Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============
Dhcp Service is not running. Checking service configuration:
The start type of Dhcp service is OK.
The ImagePath of Dhcp service is OK.
The ServiceDll of Dhcp service is OK.

NetBt Service is not running. Checking service configuration:
The start type of NetBt service is OK.
The ImagePath of NetBt service is OK.


Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error: Google IP is unreachable
Attempt to access Yahoo IP returend error: Yahoo IP is unreachable


Windows Firewall:
=============
sharedaccess Service is not running. Checking service configuration:
The start type of sharedaccess service is set to Disabled. The default start type is Auto.
The ImagePath of sharedaccess service is OK.
The ServiceDll of sharedaccess service is OK.

netman Service is not running. Checking service configuration:
The start type of netman service is OK.
The ImagePath of netman service is OK.
The ServiceDll of netman service is OK.

winmgmt Service is not running. Checking service configuration:
The start type of winmgmt service is OK.
The ImagePath of winmgmt service is OK.
The ServiceDll of winmgmt service is OK.


Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall"=DWORD:0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============
Srservice Service is not running. Checking service configuration:
The start type of Srservice service is OK.
The ImagePath of Srservice service is OK.
The ServiceDll of Srservice: "C:\WINDOWS\system32\srsvc.dll".


System Restore Disabled Policy:
========================


Security Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking LEGACY_wscsvc: Attention! Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist.

winmgmt Service is not running. Checking service configuration:
The start type of winmgmt service is OK.
The ImagePath of winmgmt service is OK.
The ServiceDll of winmgmt service is OK.


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is OK.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv: "C:\WINDOWS\system32\wuauserv.dll".


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe
[2008-04-25 11:16] - [2008-04-14 07:00] - 0039424 ____A (Microsoft Corporation) CC3647D0E41550ACAA66FF9F4B40D6BC

C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
Gpc(6) IPSec(4) NetBT(6) NwlnkIpx(9) NwlnkNb(10) PSched(7) SYMTDI(11) Tcpip(3) Tcpip6(13)
0x0D000000040000000100000002000000030000000B00000008000000050000000600000007000000090000000A0000000C0000000D000000
IpSec Tag value is correct.

**** End of log ****

#30 User is offline   narenxp 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 2,739
  • Joined: 24-October 11
  • Gender:Male
  • Location:India

Posted 22 February 2012 - 10:21 AM

Download

Winsock fix

Launch it ,Click on FIX

Restart your PC after it gets completed

Check your browser.If you're still unable to connect


PLEASE create a restore point before trying this

Please copy the entire contents of the codebox below into Notepad:


REGEDIT4

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2]





Open a notepad ,copy the script,save it as

Filename:winsock.reg
save as type:All files


Launch it and click YES to add it to registry

After that, Reboot your computer.

After the restart,

Go to Network Connections
Right click on your normal connection icon, and choose Properties
Click the Install button
Choose Protocol then click Add
Click Have disk
In the drop down box, type in: C:\WINDOWS\INF and click OK
In the next dialog, click Internet Protocol (TCP/IP) then click OK
Click Close to leave the properties box

After that, restart your computer and see if you can browse now.

If that doesnt work

Insert your OS CD

Press Windows+R key and type

cmd and click ok

run this command

sfc /scannow

Allow it get completed

Post the new FSS log

This post has been edited by narenxp: 22 February 2012 - 10:30 AM


Share this topic:


  • 4 Pages +
  • 1
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users