Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Unable to access internet. Even though everything seems to be working fine.


  • This topic is locked This topic is locked
53 replies to this topic

#1 samak

samak

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 04 January 2012 - 01:46 PM

I have done everything properly to connect my laptop to the LAN internet. I have a few computers connected already, but this time, this computer will not connect. It is a Toshiba laptop with Windows XP. Windows cannot detect any problems with the internet connection, however, I am still unable to access the internet with this laptop. I have a post here for reference to this problem with some previous logs:
http://www.bleepingcomputer.com/forums/topic435679.html/page__p__2534510#entry2534510

Attached to this message is the attach.txt and ark.txt

The following is the report from DDS:


.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_03
Run by home at 12:52:33 on 2012-01-04
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.193 [GMT -5:00]
.
FW: Sygate Personal Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Sygate\SPF\smc.exe
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\IProsetMonitor.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\wuauclt.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://caculator/
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [AtiPTA] atiptaxx.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [WG511WLU] c:\program files\netgear\wg511\utility\WG511WLU.exe -hide
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\home.layfer\application data\dvdvideosoftiehelpers\freeyoutubedownload.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: turbotax.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
TCP: Interfaces\{2FFCCE2A-96AB-454B-96DE-10A45E3B257E} : NameServer = 192.168.1.2
TCP: Interfaces\{BA59BC0B-0419-4780-B782-0D9F4A2A64AC} : NameServer = 192.168.1.1
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 192.168.1.112 home2
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\home.layfer\application data\mozilla\firefox\profiles\zwdff30u.default\
FF - prefs.js: browser.search.selectedEngine - Hadith Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/\r
FF - plugin: c:\documents and settings\home.layfer\application data\mozilla\firefox\profiles\zwdff30u.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\documents and settings\home.layfer\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\home.layfer\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\home.layfer\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdbplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Ad blocker: {4DC70064-89E2-4a55-8FC6-E8CDEAE3612C} - %profile%\extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3612C}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Torbutton: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca} - %profile%\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
FF - Ext: Add to Search Bar: add-to-searchbox@maltekraus.de - %profile%\extensions\add-to-searchbox@maltekraus.de
FF - Ext: Ghostery: firefox@ghostery.com - %profile%\extensions\firefox@ghostery.com
FF - Ext: Element Hiding Helper for Adblock Plus: elemhidehelper@adblockplus.org - %profile%\extensions\elemhidehelper@adblockplus.org
FF - Ext: Webmail Ad Blocker: gmailnoads@mywebber.com - %profile%\extensions\gmailnoads@mywebber.com
.
============= SERVICES / DRIVERS ===============
.
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-1-5 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 74480]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IPROSetMonitor.exe [2011-12-27 132768]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-11-22 366152]
R3 AWINDIS5;AWINDIS5 Protocol Driver;c:\windows\system32\AWINDIS5.SYS [2007-10-28 16194]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-11-22 22216]
S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter;\??\c:\windows\system32\drivers\nsdriver.sys --> c:\windows\system32\drivers\NSDriver.sys [?]
S3 camfilt2;camfilt2;c:\windows\system32\drivers\camfilt2.sys [2010-4-1 94720]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\1.tmp --> c:\windows\system32\1.tmp [?]
S3 NDISKIO;NDISKIO;\??\c:\docume~1\home~1.lay\locals~1\temp\0000009d.nmc\nse\bin\ndiskio.sys --> c:\docume~1\home~1.lay\locals~1\temp\0000009d.nmc\nse\bin\ndiskio.sys [?]
S3 nsak;nsak;\??\c:\docume~1\home~1.lay\locals~1\temp\0000009d.nmc\nse\bin\nsak.sys --> c:\docume~1\home~1.lay\locals~1\temp\0000009d.nmc\nse\bin\nsak.sys [?]
S3 PRISM_ICB;NETGEAR WG511 Wireless LAN Driver;c:\windows\system32\drivers\WG511ICB.sys [2011-12-27 393472]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 7408]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-8-5 136176]
S4 vsdatant;vsdatant; [x]
.
=============== File Associations ===============
.
chm.file="hh.exe" %1
txtfile=c:\windows\notepad.exe %1
.
=============== Created Last 30 ================
.
2011-12-27 23:55:34 132768 ----a-w- c:\windows\system32\IPROSetMonitor.exe
2011-12-27 23:54:25 294600 ----a-w- c:\windows\system32\PROUnstl.exe
2011-12-27 23:12:32 11861 ----a-w- c:\windows\system32\drivers\mdc8021x.sys
2011-12-27 23:12:21 393472 ----a-w- c:\windows\system32\drivers\WG511ICB.sys
.
==================== Find3M ====================
.
2011-11-18 22:31:14 169472 ----a-w- c:\windows\system32\Ncs2Setp.dll
2011-11-18 22:17:04 683640 ----a-w- c:\windows\system32\ncs2dmix.dll
2011-11-18 22:17:04 557176 ----a-w- c:\windows\system32\accesor.dll
2011-11-18 22:07:10 160376 ----a-w- c:\windows\system32\ncs2instutility.dll
2011-11-18 22:04:14 2241656 ----a-w- c:\windows\system32\ncscolib.dll
2011-11-09 21:27:18 30368 ----a-w- c:\windows\system32\drivers\iqvw32.sys
.
============= FINISH: 12:53:45.39 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:54 AM

Posted 08 January 2012 - 02:50 PM

Hi

Please do the following:

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#3 samak

samak
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 08 January 2012 - 06:45 PM

Farbar Service Scanner
Ran by home (administrator) on 08-01-2012 at 18:44:10
Microsoft Windows XP Home Edition Service Pack 2 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error: Google IP is offline
Attempt to access Yahoo IP returend error: Yahoo IP is offline


Windows Firewall:
=============

Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is set to Disabled. The default start type is Auto.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.


Windows Update:
===========
BITS Service is not running. Checking service configuration:
The start type of BITS service is set to Demand. The default start type is Auto.
The ImagePath of BITS service is OK.
The ServiceDll of BITS: "C:\WINDOWS\system32\qmgr.dll".


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys
[2004-08-03 18:14] - [2008-06-20 05:44] - 0138368 ____A (Microsoft Corporation) 944CA435BFCFC82CC1ED9E3A7D731AA9

C:\WINDOWS\system32\Drivers\netbt.sys
[2004-08-03 18:14] - [2004-08-03 18:14] - 0162816 ____A (Microsoft Corporation) 0C80E410CD2F47134407EE7DD19CC86B

C:\WINDOWS\system32\Drivers\tcpip.sys
[2004-08-03 18:14] - [2008-06-20 05:45] - 0360320 ____A (Microsoft Corporation) 2A5554FC5B1E04E131230E3CE035C3F9

C:\WINDOWS\system32\Drivers\ipsec.sys
[2004-08-03 18:14] - [2004-08-03 18:14] - 0074752 ____A (Microsoft Corporation) 64537AA5C003A6AFEEE1DF819062D0D1

C:\WINDOWS\system32\dnsrslvr.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0045568 ____A (Microsoft Corporation) 7379DE06FD196E396A00AA97B990C00D

C:\WINDOWS\system32\ipnathlp.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0331264 ____A (Microsoft Corporation) 36CC8C01B5E50163037BEF56CB96DEFF

C:\WINDOWS\system32\netman.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0198144 ____A (Microsoft Corporation) DAB9E6C7105D2EF49876FE92C524F565

C:\WINDOWS\system32\wbem\WMIsvc.dll
[2007-10-28 17:55] - [2004-08-03 19:56] - 0144896 ____A (Microsoft Corporation) F399242A80C4066FD155EFA4CF96658E

C:\WINDOWS\system32\srsvc.dll
[2007-10-28 17:57] - [2004-08-03 19:56] - 0170496 ____A (Microsoft Corporation) 92BDF74F12D6CBEC43C94D4B7F804838

C:\WINDOWS\system32\Drivers\sr.sys
[2007-10-28 17:57] - [2004-08-03 18:06] - 0073472 ____A (Microsoft Corporation) E41B6D037D6CD08461470AF04500DC24

C:\WINDOWS\system32\wscsvc.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0081408 ____A (Microsoft Corporation) 4D59DAA66C60858CDF4F67A900F42D4A

C:\WINDOWS\system32\wbem\WMIsvc.dll
[2007-10-28 17:55] - [2004-08-03 19:56] - 0144896 ____A (Microsoft Corporation) F399242A80C4066FD155EFA4CF96658E

C:\WINDOWS\system32\wuauserv.dll
[2007-10-28 17:58] - [2004-08-03 19:56] - 0006656 ____A (Microsoft Corporation) 13D72740963CBA12D9FF76A7F218BCD8

C:\WINDOWS\system32\qmgr.dll
[2007-10-28 17:58] - [2004-08-03 19:56] - 0382464 ____A (Microsoft Corporation) 2C69EC7E5A311334D10DD95F338FCCEA

C:\WINDOWS\system32\es.dll
[2004-08-03 19:56] - [2008-07-07 15:32] - 0253952 ____A (Microsoft Corporation) 60D1A6342238378BFB7545C81EE3606C

C:\WINDOWS\system32\cryptsvc.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0060416 ____A (Microsoft Corporation) 10654F9DDCEA9C46CFB77554231BE73B

C:\WINDOWS\system32\svchost.exe
[2004-08-03 19:56] - [2004-08-03 19:56] - 0014336 ____A (Microsoft Corporation) 8F078AE4ED187AAABC0A305146DE6716

C:\WINDOWS\system32\rpcss.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0395776 ____A (Microsoft Corporation) 5C83A4408604F737717AB96371201680

C:\WINDOWS\system32\services.exe
[2004-08-03 19:56] - [2004-08-03 19:56] - 0108032 ____A (Microsoft Corporation) C6CE6EEC82F187615D1002BB3BB50ED4


Extra List:
=======
AegisP(13) Gpc(4) IPSec(6) irda(3) MDC8021X(16) NetBT(7) NwlnkIpx(19) NwlnkNb(20) PSched(8) Tcpip(5) wpsdrvnt(9)
0x140000000600000001000000020000000300000004000000050000000900000007000000080000000A0000000B0000000C0000000D0000000E0000000F0000001000000011000000120000001300000014000000


**** End of log ****

#4 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:54 AM

Posted 08 January 2012 - 07:37 PM

Please do the following:

Go to Start > Run > type cmd > OK

type the following commands one at a time at the command prompt > press enter after each command:

netsh int ip reset reset.log

netsh winsock reset catalog


reboot the computer, see if it will now connect


NEXT

Please run the following:

Note: you will be unable to install the Recovery console until we get a connection back, ComboFix will run from a USB stick:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#5 samak

samak
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 08 January 2012 - 10:42 PM

I ran the following commands:
netsh int ip reset reset.log

netsh winsock reset catalog

However, after rebooting, the computer was not able to connect.

Attached is the combofix.txt

After running combofix, windows did not allow me to log on, it says that I must activate windows. I was able to boot into safe mode and allowed combofix to finish running and generate the combofix.txt file. Attached is the combofix.txt. Windows will still not let me log on unless I activate windows.



Thanks for your help so far.

#6 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:54 AM

Posted 08 January 2012 - 11:07 PM

that's unusual,

if you say to activate, it will probably reset itself

can you please try posting the Combofix log again as it didn't attach


could you also re-run Farbar Service Scanner and post a fresh log as well

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#7 samak

samak
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 08 January 2012 - 11:20 PM

Should I run the Farbar Service Scanner in safe mode? Or safe mode with networking?

Here is the combofix.txt again.

Attached Files



#8 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:54 AM

Posted 08 January 2012 - 11:26 PM

Hi

Boot into normal mode and agree to activate, it will reset itself

run Farbar Service scanner in normal mode

if for some reason you still cannot log on to normal mode, then try safe mode with networking

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#9 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:54 AM

Posted 09 January 2012 - 08:40 AM

Hi

Would you also run the following scan, it will give us more information:

Please download MiniToolBox, save it to your desktop and run it.

Place a checkmark in the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using the "Reset FF Proxy Settings" option, Firefox should be closed.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#10 samak

samak
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 09 January 2012 - 08:03 PM

I got windows activated. I ran Farbar service again. Here are the results:

Farbar Service Scanner
Ran by home (administrator) on 09-01-2012 at 19:55:54
Microsoft Windows XP Home Edition Service Pack 2 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error: Google IP is offline
Attempt to access Yahoo IP returend error: Yahoo IP is offline


Windows Firewall:
=============

Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============

Windows Update:
===========
BITS Service is not running. Checking service configuration:
The start type of BITS service is set to Demand. The default start type is Auto.
The ImagePath of BITS service is OK.
The ServiceDll of BITS service is OK.


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys
[2004-08-03 18:14] - [2008-06-20 05:44] - 0138368 ____A (Microsoft Corporation) 944CA435BFCFC82CC1ED9E3A7D731AA9

C:\WINDOWS\system32\Drivers\netbt.sys
[2004-08-03 18:14] - [2004-08-03 18:14] - 0162816 ____A (Microsoft Corporation) 0C80E410CD2F47134407EE7DD19CC86B

C:\WINDOWS\system32\Drivers\tcpip.sys
[2004-08-03 18:14] - [2008-06-20 05:45] - 0360320 ____A (Microsoft Corporation) 2A5554FC5B1E04E131230E3CE035C3F9

C:\WINDOWS\system32\Drivers\ipsec.sys
[2004-08-03 18:14] - [2004-08-03 18:14] - 0074752 ____A (Microsoft Corporation) 64537AA5C003A6AFEEE1DF819062D0D1

C:\WINDOWS\system32\dnsrslvr.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0045568 ____A (Microsoft Corporation) 7379DE06FD196E396A00AA97B990C00D

C:\WINDOWS\system32\ipnathlp.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0331264 ____A (Microsoft Corporation) 36CC8C01B5E50163037BEF56CB96DEFF

C:\WINDOWS\system32\netman.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0198144 ____A (Microsoft Corporation) DAB9E6C7105D2EF49876FE92C524F565

C:\WINDOWS\system32\wbem\WMIsvc.dll
[2007-10-28 17:55] - [2004-08-03 19:56] - 0144896 ____A (Microsoft Corporation) F399242A80C4066FD155EFA4CF96658E

C:\WINDOWS\system32\srsvc.dll
[2007-10-28 17:57] - [2004-08-03 19:56] - 0170496 ____A (Microsoft Corporation) 92BDF74F12D6CBEC43C94D4B7F804838

C:\WINDOWS\system32\Drivers\sr.sys
[2007-10-28 17:57] - [2004-08-03 18:06] - 0073472 ____A (Microsoft Corporation) E41B6D037D6CD08461470AF04500DC24

C:\WINDOWS\system32\wscsvc.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0081408 ____A (Microsoft Corporation) 4D59DAA66C60858CDF4F67A900F42D4A

C:\WINDOWS\system32\wbem\WMIsvc.dll
[2007-10-28 17:55] - [2004-08-03 19:56] - 0144896 ____A (Microsoft Corporation) F399242A80C4066FD155EFA4CF96658E

C:\WINDOWS\system32\wuauserv.dll
[2007-10-28 17:58] - [2004-08-03 19:56] - 0006656 ____A (Microsoft Corporation) 13D72740963CBA12D9FF76A7F218BCD8

C:\WINDOWS\system32\qmgr.dll
[2007-10-28 17:58] - [2004-08-03 19:56] - 0382464 ____A (Microsoft Corporation) 2C69EC7E5A311334D10DD95F338FCCEA

C:\WINDOWS\system32\es.dll
[2004-08-03 19:56] - [2008-07-07 15:32] - 0253952 ____A (Microsoft Corporation) 60D1A6342238378BFB7545C81EE3606C

C:\WINDOWS\system32\cryptsvc.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0060416 ____A (Microsoft Corporation) 10654F9DDCEA9C46CFB77554231BE73B

C:\WINDOWS\system32\svchost.exe
[2004-08-03 19:56] - [2004-08-03 19:56] - 0014336 ____A (Microsoft Corporation) 8F078AE4ED187AAABC0A305146DE6716

C:\WINDOWS\system32\rpcss.dll
[2004-08-03 19:56] - [2004-08-03 19:56] - 0395776 ____A (Microsoft Corporation) 5C83A4408604F737717AB96371201680

C:\WINDOWS\system32\services.exe
[2004-08-03 19:56] - [2004-08-03 19:56] - 0108032 ____A (Microsoft Corporation) C6CE6EEC82F187615D1002BB3BB50ED4


Extra List:
=======
AegisP(13) Gpc(4) IPSec(6) irda(3) MDC8021X(16) NetBT(7) NwlnkIpx(19) NwlnkNb(20) PSched(8) Tcpip(5) wpsdrvnt(9)
0x140000000600000001000000020000000300000004000000050000000900000007000000080000000A0000000B0000000C0000000D0000000E0000000F0000001000000011000000120000001300000014000000


**** End of log ****

#11 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:54 AM

Posted 09 January 2012 - 08:07 PM

OK good, if you could please run the mini tool box instructions from this post

http://www.bleepingcomputer.com/forums/topic436228.html/page__view__findpost__p__2545384

thanks

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#12 samak

samak
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 09 January 2012 - 08:16 PM

I ran Minitoolbox and here are the results:

MiniToolBox by Farbar
Ran by home (administrator) on 09-01-2012 at 20:00:53
Microsoft Windows XP Home Edition Service Pack 2 (X86)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================


Windows IP Configuration



Successfully flushed the DNS Resolver Cache.


========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================

"network.proxy.http", "127.0.0.1"
"network.proxy.http_port", 8118
"network.proxy.no_proxies_on", "127.0.0.1"
"network.proxy.socks", "127.0.0.1"
"network.proxy.socks_port", 9050
"network.proxy.socks_remote_dns", true
"network.proxy.ssl", "127.0.0.1"
"network.proxy.ssl_port", 8118

"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================

127.0.0.1 localhost

========================= IP Configuration: ================================

1394 Net Adapter = 1394 Connection (Connected)
Intel® PRO/100 VE Network Connection = Local Area Connection 2 (Connected)


# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip


# Interface IP Configuration for "Local Area Connection 2"

set address name="Local Area Connection 2" source=dhcp
set dns name="Local Area Connection 2" source=dhcp register=NONE
set wins name="Local Area Connection 2" source=dhcp


popd
# End of interface IP configuration




Windows IP Configuration



Host Name . . . . . . . . . . . . : layfer

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Hybrid

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No



Ethernet adapter Local Area Connection 2:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Intel® PRO/100 VE Network Connection

Physical Address. . . . . . . . . : 00-02-3F-7D-53-45

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 192.168.1.106

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 192.168.1.1

DHCP Server . . . . . . . . . . . : 192.168.1.1

DNS Servers . . . . . . . . . . . : 192.168.1.1

Lease Obtained. . . . . . . . . . : Monday, January 09, 2012 7:52:24 PM

Lease Expires . . . . . . . . . . : Tuesday, January 10, 2012 7:52:24 PM

DNS request timed out.
timeout was 2 seconds.
Server: UnKnown
Address: 192.168.1.1

DNS request timed out.
timeout was 2 seconds.
DNS request timed out.
timeout was 2 seconds.


Pinging google.com [74.125.227.16] with 32 bytes of data:



Request timed out.

Request timed out.



Ping statistics for 74.125.227.16:

Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),

Server: unknown
Address: 192.168.1.1

Name: yahoo.com
Addresses: 98.137.149.56, 98.139.180.149, 209.191.122.70, 72.30.2.43



Pinging yahoo.com [72.30.2.43] with 32 bytes of data:



Request timed out.

Request timed out.



Ping statistics for 72.30.2.43:

Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),

Server: unknown
Address: 192.168.1.1

Name: bleepingcomputer.com
Address: 208.43.87.2



Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:



Request timed out.

Request timed out.



Ping statistics for 208.43.87.2:

Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),



Pinging 127.0.0.1 with 32 bytes of data:



Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x10003 ...00 02 3f 7d 53 45 ...... Intel® PRO/100 VE Network Connection
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.106 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.106 192.168.1.106 20
192.168.1.106 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.1.255 255.255.255.255 192.168.1.106 192.168.1.106 20
224.0.0.0 240.0.0.0 192.168.1.106 192.168.1.106 20
255.255.255.255 255.255.255.255 192.168.1.106 192.168.1.106 1
Default Gateway: 192.168.1.1
===========================================================================
Persistent Routes:
None

========================= Event log errors: ===============================

Application errors:
==================
Error: (01/09/2012 07:32:49 PM) (Source: ACW_DE) (User: )
Description: Application has encountered error.
/common/fetchacw.aspx?file=cf;1033;acwresource The server name or address could not be resolved

Error: (01/09/2012 07:32:28 PM) (Source: ACW_DE) (User: )
Description: Application has encountered error.
/common/fetchacw.aspx?file=cf;1033;acwresource The server name or address could not be resolved

Error: (01/09/2012 07:32:20 PM) (Source: ACW_DE) (User: )
Description: Application has encountered error.
/common/fetchacw.aspx?file=cf;1033;acwresource The server name or address could not be resolved

Error: (01/08/2012 11:43:43 PM) (Source: Windows Product Activation) (User: )
Description: You have not activated Windows within the grace period. To activate Windows, contact a customer service representative by telephone.

Error: (01/08/2012 11:42:53 PM) (Source: Windows Product Activation) (User: )
Description: You have not activated Windows within the grace period. To activate Windows, contact a customer service representative by telephone.

Error: (01/08/2012 09:01:51 PM) (Source: Windows Product Activation) (User: )
Description: You have not activated Windows within the grace period. To activate Windows, contact a customer service representative by telephone.

Error: (01/08/2012 08:51:48 PM) (Source: crypt32) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Error: (01/08/2012 08:51:48 PM) (Source: crypt32) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (01/08/2012 08:51:48 PM) (Source: crypt32) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Error: (01/08/2012 08:51:48 PM) (Source: crypt32) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.


System errors:
=============
Error: (01/09/2012 07:36:24 PM) (Source: DCOM) (User: SYSTEM)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (01/09/2012 07:32:25 PM) (Source: DCOM) (User: Administrator)
Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error: (01/09/2012 07:32:08 PM) (Source: DCOM) (User: Administrator)
Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error: (01/09/2012 07:32:04 PM) (Source: DCOM) (User: Administrator)
Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error: (01/09/2012 07:18:34 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
AFD
Fips
intelppm
IPSec
MRxSmb
NetBIOS
NetBT
RasAcd
Rdbss
SASDIFSV
SASKUTIL
Tcpip
wpsdrvnt
WS2IFSL

Error: (01/09/2012 07:18:34 PM) (Source: Service Control Manager) (User: )
Description: The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
%%31

Error: (01/09/2012 07:18:34 PM) (Source: Service Control Manager) (User: )
Description: The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:
%%31

Error: (01/09/2012 07:18:34 PM) (Source: Service Control Manager) (User: )
Description: The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:
%%31

Error: (01/09/2012 07:18:34 PM) (Source: Service Control Manager) (User: )
Description: The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:
%%31


Microsoft Office Sessions:
=========================
Error: (10/02/2010 04:23:02 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.6021.5000. This session lasted 6921 seconds with 5580 seconds of active time. This session ended with a crash.

Error: (07/08/2010 11:53:47 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.6021.5000. This session lasted 174 seconds with 60 seconds of active time. This session ended with a crash.


=========================== Installed Programs ============================

7-Zip 4.65
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) (Version: 8.1.2)
Adobe Flash Player 10 ActiveX (Version: 10.0.45.2)
Adobe Flash Player 10 Plugin (Version: 10.0.32.18)
Adobe Photoshop 7.0 (Version: 7.0)
Adobe Reader 8.1.2 (Version: 8.1.2)
Adobe Reader 8.1.2 Security Update 1 (KB403742)
Adobe Shockwave Player 11.5 (Version: 11.5.8.612)
ALPS Touch Pad Driver
ATI Display Driver
AutoUpdate (Version: 1.1)
CCleaner (Version: 3.10)
Compatibility Pack for the 2007 Office system (Version: 12.0.6021.5000)
Defraggler (Version: 2.06)
DivX Codec (Version: 6.7.0)
DivX Content Uploader (Version: 1.2.1)
DivX Converter (Version: 6.5.1)
DivX Player (Version: 6.6.0)
DivX Web Player (Version: 1.4.0)
Excel@ Middle School
Fontboard Arabic Keyboards
Free YouTube Download version 3.0.1.610
Google Talk (remove only)
Google Talk Plugin (Version: 1.3.1.0)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Update Helper (Version: 1.2.183.23)
Hercules Deluxe Optical Glass (Version: 2.8.0.0)
HijackThis 2.0.2 (Version: 2.0.2)
hp LaserJet 1010 Series (Version: 3.00.0000)
Intel® Network Connections 16.8.46.0 (Version: 16.8.46.0)
Java™ 6 Update 2 (Version: 1.6.0.20)
Java™ 6 Update 3 (Version: 1.6.0.30)
Java™ SE Development Kit 6 Update 3 (Version: 1.6.0.30)
JD Secure 3.1
Malwarebytes' Anti-Malware version 1.51.2.1300 (Version: 1.51.2.1300)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 (Version: 2.0.50727)
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 (Version: 3.0.04506.30)
Microsoft Office Access MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Professional 2007 (Version: 12.0.4518.1014)
Microsoft Office Proof (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proof (French) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs (Version: 12.0.4518.1014)
Microsoft VC9 runtime libraries (Version: 1.0.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Mozilla Firefox (3.6) (Version: 3.6 (en-US))
MSXML 6.0 Parser (KB925673) (Version: 6.00.3888.0)
NETGEAR WG511 54 Mbps Wireless PC Card
Opera 11.50 (Version: 11.50.1074)
Photo Story 3 for Windows (Version: 3.0.1115.11)
Polipo 1.0.4.1
QuickTime
Shipping Assistant 3.7 (Version: 3.7.188.0)
Skype™ 4.2 (Version: 4.2.169)
Sophos Anti-Rootkit 1.5.0 (Version: 1.5.0)
Speccy (Version: 1.04)
Spybot - Search & Destroy (Version: 1.6.2)
SUPERAntiSpyware Free Edition (Version: 4.33.0.1000)
Sygate Personal Firewall (Version: 5.6.2808)
Tor 0.2.1.26
Toshiba Soft Modem AMR
TurboTax Deluxe 2007
Vidalia 0.2.10
VLC media player 1.0.3 (Version: 1.0.3)
WebFldrs XP (Version: 9.50.7523)
Windows Communication Foundation (Version: 3.0.04506.30)
Windows Imaging Component (Version: 3.0.0.0)
Windows Media Format Runtime
Windows Media Player 10
Windows Presentation Foundation (Version: 3.0.6920.0)
Windows Workflow Foundation (Version: 3.0.4203.2)
WinRAR archiver
XML Paper Specification Shared Components Pack 1.0
XPS Annotator 1.21
Yahoo! Messenger

========================= Memory info: ===================================

Percentage of memory in use: 38%
Total physical RAM: 510.98 MB
Available physical RAM: 312.49 MB
Total Pagefile: 1246.8 MB
Available Pagefile: 1107.47 MB
Total Virtual: 2047.88 MB
Available Virtual: 1977.75 MB

========================= Partitions: =====================================

2 Drive c: () (Fixed) (Total:29.8 GB) (Free:9.23 GB) NTFS
3 Drive d: () (Fixed) (Total:7.44 GB) (Free:5.31 GB) FAT32
6 Drive g: () (Removable) (Total:0.49 GB) (Free:0.13 GB) FAT

========================= Users: ========================================

User accounts for \\LAYFER

Administrator Guest HelpAssistant
home SUPPORT_388945a0

========================= Minidump Files ==================================

No minidump file found

**** End of log ****

#13 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:54 AM

Posted 09 January 2012 - 08:19 PM

Hi

Please do the following:

Go to Start > Run > type in CMD to open a command prompt.

Type in the following command in the command prompt and press Enter.


netsh int ip reset reset.log

Then also type the following command and hit enter.

netsh winsock reset catalog

Once that completes then restart the system and see then if you are able to get online.


next this -

Go to Start > Run then type: CMD into the run box

You will now see a black DOS-like screen.

Type the following at the command prompt:

IPconfig /release (Note the space between the "g" and the slash / it needs to be there)

Hit enter Then type:

IPconfig /Renew (Note the space between the "g" and the slash / it needs to be there)

Hit enter

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#14 samak

samak
  • Topic Starter

  • Members
  • 61 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 09 January 2012 - 08:28 PM

I typed in these commands:

netsh int ip reset reset.log

netsh winsock reset catalog


After restarting, was not able to connect.

Next, I typed in these commands properly, and still cannot connect:

IPconfig /release

IPconfig /Renew

NOTE: all of this is being done with a direct LAN connection. I can try the wireless card, but have not tried it yet. I don't know if that will make a difference.


Thank you

Edited by samak, 09 January 2012 - 08:30 PM.


#15 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:12:54 AM

Posted 09 January 2012 - 08:56 PM

Hi,

Please try the following: (wired or wireless shouldn't make a difference)

Please copy the entire contents of the codebox below into Notepad:

  • Open Notepad
  • Copy the contents of the codebox below using CTRL C

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2]

  • Now return to Notepad and use CTRL V to paste the script
  • Verify that you have pasted the complete script
  • Save the Notepad file to your Desktop as FixReg.reg using Save as Type: All files
  • Locate FixReg.reg on your desktop
  • Double click to run, and when prompted Allow the file to merge with your registry
  • OK your way out.
After that, Reboot your computer.


After the reboot, we will reinstall TCP/IP
  • Go to Start the Settings and choose Network Connections
  • Right click on your normal connection icon, and choose Properties
  • Click the Install button
  • Choose Protocol then click Add
  • Click Have disk
  • In the drop down box, type in: C:\WINDOWS\INF and click OK
  • In the next dialog, click Internet Protocol (TCP/IP) then click OK
  • Click Close to leave the properties box
After that, Reboot your computer and see if you have regained your connection.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users