Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

generic14.bzsz? More?


  • This topic is locked This topic is locked
41 replies to this topic

#31 nasdaq

nasdaq

  •  Avatar image
  • Malware Response Team
  • 48,329 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:42 PM

Posted 11 January 2012 - 09:40 AM

Close all applications.
Disconnect from the internet. Meaning disconnect the internet cable from the wall or your router.

Try the fix again

BC AdBot (Login to Remove)

 


#32 ser909

ser909
  • Topic Starter

  •  Avatar image
  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:08:42 PM

Posted 11 January 2012 - 10:08 PM

Followed your instructions.
Got same messages.

Same results:
No programs can connect to the internet though I seem to have a network connection.

Here is latest FSS log:

Farbar Service Scanner
Ran by Eddie (administrator) on 11-01-2012 at 21:52:17
MicrosoftÆ Windows Vistaô Home Premium Service Pack 2 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
WAN connected
Google IP is accessible.
Yahoo IP is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============
SDRSVC Service is not running. Checking service configuration:
The start type of SDRSVC service is OK.
The ImagePath of SDRSVC service is OK.
The ServiceDll of SDRSVC service is OK.
Checking LEGACY_SDRSVC: Attention! Unable to open LEGACY_SDRSVC\0000 registry key. The key does not exist.

VSS Service is not running. Checking service configuration:
The start type of VSS service is OK.
The ImagePath of VSS service is OK.


System Restore Disabled Policy:
========================


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcsvc.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****

#33 nasdaq

nasdaq

  •  Avatar image
  • Malware Response Team
  • 48,329 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:42 PM

Posted 12 January 2012 - 09:34 AM

Click the Posted Image button. In the Search box, type Command Prompt, and then, in the list of results, double-click Command Prompt.

at the cursor type:
ipconfig /flushdns <-- (A space between g and / is needed)

repeat with
ipconfig /renew

Then hit Enter, type Exit, hit the Enter key.

OR if this fails.

You may need to run CMD - Command Prompt on Vista - Windows 7 with Elevated Privilege
http://www.mydigitallife.info/2007/02/17/how-to-open-elevated-command-prompt-with-administrator-privileges-in-windows-vista/
<<<>>>

Make sure that no proxy settings are set.

In Internet Explorer go to Tools - Internet Options - Connections Tab - Lan Settings and remove the reference to 127.0.0.1:5577 if found, then uncheck "Use a proxy server" and check "Automatically detect settings".
===

If you use Firefox in Tools Menu > Options... > Advanced Tab > Network Tab > Connection > Settings. Select the Auto-detect proxy settings for this network option. Or no proxy if you do not need it.
===

Keep me posted.

#34 ser909

ser909
  • Topic Starter

  •  Avatar image
  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:08:42 PM

Posted 12 January 2012 - 11:50 AM

Flushdns gave message:
"Successfully flushed the DNS Resolver Cache."
Renew waited a minute then gave message:
"An error occurred while renewing interface Local Area Connection: unable to contact your DHCP server. Request has timed out."

#35 nasdaq

nasdaq

  •  Avatar image
  • Malware Response Team
  • 48,329 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:42 PM

Posted 12 January 2012 - 03:36 PM

You can try the suggested fix it here.
http://support.microsoft.com/kb/811259

#36 ser909

ser909
  • Topic Starter

  •  Avatar image
  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:08:42 PM

Posted 12 January 2012 - 10:27 PM

I'm not sure how to proceed.
Having read the Microsoft article, am I supposed to make a determination whether I have Winsock2 corruption (don't know what that is) and then run Diagnose and Repair?
It's not clear to me that I have corruption.
The article says there should be 10 sections in Network Protocol but then lists 14 including 6 NetBIOS sections.
I have 20 sections including 12 NetBIOS sections.
Should I run the Microsoft Diagnose and Repair and then the reset, anyway?
The article references a "netdiag" test failure.
Am I supposed to run "netdiag"?
Where is netdiag?
Is that the same as Diagnose and Repair?
Thanks for any help.

#37 nasdaq

nasdaq

  •  Avatar image
  • Malware Response Team
  • 48,329 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:42 PM

Posted 13 January 2012 - 09:03 AM

All I want you to do is to run the Fix it on the Fix it for me Section.

Let me know if your internet connection is back.

If you get any error message please post it.

#38 ser909

ser909
  • Topic Starter

  •  Avatar image
  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:08:42 PM

Posted 13 January 2012 - 02:12 PM

Ran the Fix it.
No error message
It asked for a reboot
Rebooted
Still no internet connection.

#39 nasdaq

nasdaq

  •  Avatar image
  • Malware Response Team
  • 48,329 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:42 PM

Posted 14 January 2012 - 08:47 AM

To save time and effort I suggest you start a new topic in the Networking forum

http://www.bleepingcomputer.com/forums/forum21.html

The experts have more knowledge of this problem than me.


From my side:
Time for some housekeeping

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bold text into the Run box and click OK:

ComboFix /Uninstall
===

#40 ser909

ser909
  • Topic Starter

  •  Avatar image
  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:08:42 PM

Posted 15 January 2012 - 03:39 PM

Ran the Combofix /Uninstall
I'm not sure how to proceed.
Is it your opinion that I'm now malware-free and just have a network issue which would be resolved in the Networking Forum?
Am I then done with this topic?

#41 nasdaq

nasdaq

  •  Avatar image
  • Malware Response Team
  • 48,329 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:42 PM

Posted 16 January 2012 - 08:57 AM

I still think it's a network issue.

#42 ser909

ser909
  • Topic Starter

  •  Avatar image
  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:08:42 PM

Posted 16 January 2012 - 11:19 PM

I posted in the Network forum.

http://www.bleepingcomputer.com/forums/topic438502.html

Thank you for your help.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users