Dataplan
asked on
Winsock error - xp pc
I have a customers pc with winsock problem (I think). Problems startet when the owner had an outdated Norton Internet Security. She then downloaded and installed Norman AV that she got for free from her bank (SR-Bank) in norway. Norman was recommended, so she installed it. But she did not uninstall Norton first.
When she came to me, she was unable to connect to the internett. I startet uninstalling both AV applications. Used uninstall tools, an deleted some folders manually, an deletet som reg. keys manually. I ran ccleaner and. spybot, many times. I ran antivirus scans from MiniPE (Bart) cd.
I have now tried EVERYTHING to get connected to the internett, but no luck:
winsock fix
netsh winsock reset (several combinations with catalog), and reboots.
deletet reg key for winsock and winsock2 under current control set.......!
Deletet and installed new driver for the network card.
Now I'm about to give up. Can you please help me? Is it some parts of Norton whitch prevents me from conecting? Or is it virus og adware/spyware?
I have booted with MiniPe cd, and connected to internet, so it's no HW failure.
I have fount one interesting thing: CLMLservice.exe used between 80 and 99%cpu nearly everytime I have booted the mashine, so I disabled the service and renamed the file. Thought may be the file was infectet or something.
I have turned off windows firewall. Checked that nox proxy is used. Tried with static ip.
I can then ping my router and dns. But not www.google.no
Internett explorer troubleshooter tells me that I have a winsock problem. But after fix and reboot, it's the same.
Kirsti, Dataplan
When she came to me, she was unable to connect to the internett. I startet uninstalling both AV applications. Used uninstall tools, an deleted some folders manually, an deletet som reg. keys manually. I ran ccleaner and. spybot, many times. I ran antivirus scans from MiniPE (Bart) cd.
I have now tried EVERYTHING to get connected to the internett, but no luck:
winsock fix
netsh winsock reset (several combinations with catalog), and reboots.
deletet reg key for winsock and winsock2 under current control set.......!
Deletet and installed new driver for the network card.
Now I'm about to give up. Can you please help me? Is it some parts of Norton whitch prevents me from conecting? Or is it virus og adware/spyware?
I have booted with MiniPe cd, and connected to internet, so it's no HW failure.
I have fount one interesting thing: CLMLservice.exe used between 80 and 99%cpu nearly everytime I have booted the mashine, so I disabled the service and renamed the file. Thought may be the file was infectet or something.
I have turned off windows firewall. Checked that nox proxy is used. Tried with static ip.
I can then ping my router and dns. But not www.google.no
Internett explorer troubleshooter tells me that I have a winsock problem. But after fix and reboot, it's the same.
Kirsti, Dataplan
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Tried "The king" suggestion, but still no luck.
Was optimistic, because I fount several hidden devices (Norman Security Driver, Norman Firewall). Deleted them, along with my network device. But still nothing.
Now I just tried uninstalling AVG and reinstalling Norman. To see If norman could fix it selves. But NO !
Anyone else?
Was optimistic, because I fount several hidden devices (Norman Security Driver, Norman Firewall). Deleted them, along with my network device. But still nothing.
Now I just tried uninstalling AVG and reinstalling Norman. To see If norman could fix it selves. But NO !
Anyone else?
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Tried all of this, still no luck.
Does it use DHCP or a static IP address? Do the
IPCONFIG /all entries match up with what should be there?
Can other machines on the network see the Internet?
IPCONFIG /all entries match up with what should be there?
Can other machines on the network see the Internet?
ASKER
Uses DHCP, does not receive an IP adress from router. Have triet several networks. They are all ok for other machines.
Have also tried static ip.¨Then I can ping my router.
All other machines can use internet.
It says "limited or no access....." on the network adapter.
Have also tried static ip.¨Then I can ping my router.
All other machines can use internet.
It says "limited or no access....." on the network adapter.
I've seen this before on a vista pc and I had to reinstall!
I thought it quicker to do that than spend hours fixing.
It was a similar issue ie two firewalls installed and no matter
What was tried, the issue remained until I installed a clean
OS.
I thought it quicker to do that than spend hours fixing.
It was a similar issue ie two firewalls installed and no matter
What was tried, the issue remained until I installed a clean
OS.
ASKER
Jippi
Now I receive IP from DHCP, I can also log into my router via IE7.
But still I have problem with dns, or something.
I started sfc /scannow.............not finished yet. Right after starting, i got an IP adress.
Now i kross my fingers........thanks for all your help som far. Im going to bed know. Hope to speak again in the morning :-)
Now I receive IP from DHCP, I can also log into my router via IE7.
But still I have problem with dns, or something.
I started sfc /scannow.............not finished yet. Right after starting, i got an IP adress.
Now i kross my fingers........thanks for all your help som far. Im going to bed know. Hope to speak again in the morning :-)
Did you just restart your PC??
ASKER
Yes, I have restartet my computer. But still cant access www.google.no or anything else. But I can log into my router 192.168.225.1 with IE7.
Is is now an NDS issue? I can ping ip adresses but not "names".
Anyone?
Is is now an NDS issue? I can ping ip adresses but not "names".
Anyone?
ASKER
ASKER
Sorry the file is in Norwegian.....:-)
Open a command prompt and do:
nslookup www.hotmail.com
and see what you get. Also, have a look at this question:
https://www.experts-exchange.com/questions/20932429/Windows-DNS-does-not-work.html
nslookup www.hotmail.com
and see what you get. Also, have a look at this question:
https://www.experts-exchange.com/questions/20932429/Windows-DNS-does-not-work.html
ASKER
nslookup www.hotmail.com returns:
Server: ns1.lyse.net
Address: 213.167.96.50
Navn: origin.mail.live.com
Addresses: 64.4.20.184, 64.4.20.186, 64.4.20.169, 64.4.20.174
Aliases: www.hotmail.com, mail.live.com
toplevel.mail.live.com.aka dns.net
I can connect to other computers in my network, I can browse network, and se the other computers.
Server: ns1.lyse.net
Address: 213.167.96.50
Navn: origin.mail.live.com
Addresses: 64.4.20.184, 64.4.20.186, 64.4.20.169, 64.4.20.174
Aliases: www.hotmail.com, mail.live.com
toplevel.mail.live.com.aka
I can connect to other computers in my network, I can browse network, and se the other computers.
Can you also list the output of IPCONFIG /all from the problem
PC and a working one?
Thanks
PC and a working one?
Thanks
Your DNS is working properly, it doesn't look like there is any problems there. I suggest running ComboFix, it can be downloaded from: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
and the instructions on usage are here: http://www.bleepingcomputer.com/combofix/how-to-use-combofix
I am still going to summarize them. Download the ComboFix.exe and save it with a different name like jabba.exe. Then reboot your PC in safe mode (without networking if possible) and then disable your antivirus+firewall temporarily and run ComboFix. After ComboFix is finished, it will create a log. Please send that log to us and re-enable your computer security programs (antivirus and firewall).
and the instructions on usage are here: http://www.bleepingcomputer.com/combofix/how-to-use-combofix
I am still going to summarize them. Download the ComboFix.exe and save it with a different name like jabba.exe. Then reboot your PC in safe mode (without networking if possible) and then disable your antivirus+firewall temporarily and run ComboFix. After ComboFix is finished, it will create a log. Please send that log to us and re-enable your computer security programs (antivirus and firewall).
ASKER
Now I tried to uninstall all drivers (also hidden ones) from safe mode. I also deletet the device driver files from windows\system32.
Rebootet, and now I'm back to:
I dont get IP adress from DHCP, so now I'm running sfc /scannow again to se if it will fix the problem.
Have downloaded Combofix, and will try that one as well.
This was a hard one to fix :-(
Rebootet, and now I'm back to:
I dont get IP adress from DHCP, so now I'm running sfc /scannow again to se if it will fix the problem.
Have downloaded Combofix, and will try that one as well.
This was a hard one to fix :-(
I know this may seem a silly idea, but do you have access to a second Network card?
If so, I'd disable the first one. Then shut down the PC, install the new card along with drivers and see if that makes any difference. Don't put the network cable in to the secondary card until you have installed the correct drivers.
I'm just trying to rule out any possible hardware issue and/or registry problem with the current card.
Thanks
John
If so, I'd disable the first one. Then shut down the PC, install the new card along with drivers and see if that makes any difference. Don't put the network cable in to the secondary card until you have installed the correct drivers.
I'm just trying to rule out any possible hardware issue and/or registry problem with the current card.
Thanks
John
ASKER
ComboFix 09-05-05.03 - Administrator 06.05.2009 14:38.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.47.1044.18 .511.394 [GMT 2:00]
Kjører fra: C:\jabba.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
FW: Personlig brannmur *disabled*
.
(((((((((((((((((((((((((( ( Filer Opprettet Fra 2009-04-06 til 2009-05-06 )))))))))))))))))))))))))) )))))))
.
2009-05-06 09:54 . 2009-05-06 09:50 3012988 ----a-r C:\jabba.exe
2009-05-06 09:52 . 2009-05-06 10:19 -------- d-----w c:\windows\LastGood
2009-05-06 09:47 . 2009-03-25 12:29 130432 ----a-w c:\windows\system32\driver s\Rtnicxp. sys
2009-05-06 09:47 . 2009-03-03 18:18 73728 ----a-w c:\windows\system32\RtNicP rop32.dll
2009-05-06 08:36 . 2008-04-14 16:22 116224 ----a-w c:\windows\system32\dllcac he\xrxwiad r.dll
2009-05-06 08:36 . 2001-10-06 12:02 23040 ----a-w c:\windows\system32\dllcac he\xrxwbtm p.dll
2009-05-06 08:36 . 2008-04-14 16:22 18944 ----a-w c:\windows\system32\dllcac he\xrxscnu i.dll
2009-05-06 08:36 . 2001-10-06 12:03 27648 ----a-w c:\windows\system32\dllcac he\xrxftpl t.exe
2009-05-06 08:36 . 2001-10-06 12:03 4608 ----a-w c:\windows\system32\dllcac he\xrxflnc h.exe
2009-05-06 08:36 . 2001-08-18 04:37 99865 ----a-w c:\windows\system32\dllcac he\xlog.ex e
2009-05-06 08:36 . 2001-08-17 18:11 16970 ----a-w c:\windows\system32\dllcac he\xem336n 5.sys
2009-05-06 08:36 . 2004-08-03 20:29 19455 ----a-w c:\windows\system32\dllcac he\wvchntx x.sys
2009-05-06 08:36 . 2008-04-13 18:46 19200 ----a-w c:\windows\system32\dllcac he\wstcode c.sys
2009-05-06 08:36 . 2004-08-03 20:29 12063 ----a-w c:\windows\system32\dllcac he\wsiintx x.sys
2009-05-06 08:36 . 2008-04-14 16:22 8192 ----a-w c:\windows\system32\dllcac he\wshirda .dll
2009-05-06 08:34 . 2001-08-17 19:28 64605 ----a-w c:\windows\system32\dllcac he\vvoice. sys
2009-05-06 08:33 . 2008-04-13 18:45 60032 ----a-w c:\windows\system32\dllcac he\usbaudi o.sys
2009-05-06 08:32 . 2001-10-06 12:02 440576 ----a-w c:\windows\system32\dllcac he\tridkb. dll
2009-05-06 08:31 . 2001-08-17 19:49 30464 ----a-w c:\windows\system32\dllcac he\tbatm15 5.sys
2009-05-06 08:30 . 2001-10-06 12:02 99328 ----a-w c:\windows\system32\dllcac he\srusd.d ll
2009-05-06 08:29 . 2001-08-17 18:12 24576 ----a-w c:\windows\system32\dllcac he\smc8000 n.sys
2009-05-06 08:28 . 2001-08-17 18:50 101760 ----a-w c:\windows\system32\dllcac he\sis300i p.sys
2009-05-06 08:27 . 2001-08-17 18:50 75392 ----a-w c:\windows\system32\dllcac he\s3savmx m.sys
2009-05-06 08:26 . 2001-08-17 18:19 3840 ----a-w c:\windows\system32\dllcac he\rpfun.s ys
2009-05-06 08:25 . 2008-04-13 18:41 17664 ----a-w c:\windows\system32\dllcac he\ppa3.sy s
2009-05-06 08:24 . 2001-10-06 12:01 41984 ----a-w c:\windows\system32\dllcac he\ovui2rc .dll
2009-05-06 08:23 . 2001-08-17 18:49 51552 ----a-w c:\windows\system32\dllcac he\ntgrip. sys
2009-05-06 08:22 . 2001-10-06 11:43 52255 ----a-w c:\windows\system32\dllcac he\n1000nt 5.sys
2009-05-06 08:21 . 2001-10-06 11:35 320384 ----a-w c:\windows\system32\dllcac he\mgaum.s ys
2009-05-06 08:20 . 2001-10-06 11:28 15744 ----a-w c:\windows\system32\dllcac he\lit220p .sys
2009-05-06 08:19 . 2001-10-06 12:02 62464 ----a-w c:\windows\system32\dllcac he\icam4ex t.dll
2009-05-06 08:18 . 2001-08-17 19:28 289887 ----a-w c:\windows\system32\dllcac he\hsf_fal l.sys
2009-05-06 08:17 . 2001-10-06 11:38 17408 ----a-w c:\windows\system32\dllcac he\gpr400. sys
2009-05-06 08:16 . 2004-08-04 13:00 45056 ----a-w c:\windows\system32\dllcac he\esunid. dll
2009-05-06 08:15 . 2001-08-17 18:11 77386 ----a-w c:\windows\system32\dllcac he\el656nd 5.sys
2009-05-06 08:14 . 2001-10-06 12:02 131156 ----a-w c:\windows\system32\dllcac he\digidbp .dll
2009-05-06 08:13 . 2001-10-06 12:02 170880 ----a-w c:\windows\system32\dllcac he\cl546x. dll
2009-05-06 08:12 . 2001-08-17 18:19 36992 ----a-w c:\windows\system32\dllcac he\aztw232 0.sys
2009-05-05 21:52 . 2009-05-05 21:52 -------- d-----w c:\windows\AiOTemp
2009-05-05 21:51 . 2009-05-06 07:33 -------- d--h--r d:\documents and settings\Kristine\Siste
2009-05-05 21:49 . 2009-05-05 21:49 10520 ----a-w c:\windows\system32\avgrss tx.dll
2009-05-05 21:49 . 2009-05-05 21:49 107912 ----a-w c:\windows\system32\driver s\avgtdix. sys
2009-05-05 21:49 . 2009-05-05 21:49 325640 ----a-w c:\windows\system32\driver s\avgldx86 .sys
2009-05-05 21:49 . 2009-05-05 21:49 -------- d-----w c:\windows\system32\driver s\Avg
2009-05-05 20:16 . 2009-05-05 20:16 -------- d-----w d:\documents and settings\Administrator\Pro gramdata\M alwarebyte s
2009-05-05 20:11 . 2009-05-05 20:11 -------- d-----w d:\documents and settings\Kristine\Programd ata\Malwar ebytes
2009-05-05 20:11 . 2009-05-05 20:11 -------- d-----w d:\documents and settings\All Users\Programdata\Malwareb ytes
2009-05-05 19:45 . 2009-05-05 20:53 -------- d-----w d:\documents and settings\All Users\Programdata\Lavasoft
2009-05-05 19:30 . 2009-05-05 20:50 -------- d-----w c:\programfiler\Norman
2009-05-05 19:30 . 2009-05-05 19:30 -------- d-----w d:\documents and settings\Kristine\Programd ata\Instal lShield
2009-05-05 10:51 . 2009-05-05 10:51 -------- d-----w d:\documents and settings\All Users\Programdata\NortonIn staller
2009-05-05 07:59 . 2009-05-05 07:59 -------- d-----w c:\programfiler\ACW
2009-05-05 07:35 . 2009-05-05 07:35 -------- d-----w c:\programfiler\AVG
2009-05-05 07:35 . 2009-05-05 21:49 -------- d-----w d:\documents and settings\All Users\Programdata\avg8
2009-04-30 12:43 . 2009-05-05 20:28 -------- d-----w d:\documents and settings\Kristine\Programd ata\Deskto picon
2009-04-30 12:43 . 2009-04-30 12:43 -------- d-----w c:\programfiler\Unlocker
2009-04-30 10:56 . 2009-04-30 11:48 -------- d-----w c:\windows\system32\data
2009-04-30 10:46 . 2009-04-30 10:46 -------- d-----w c:\programfiler\CCleaner
2009-04-07 16:23 . 2009-04-07 16:23 -------- d-----w d:\documents and settings\LocalService\Star t-meny
2009-04-07 16:22 . 2008-04-16 10:57 42552 ----a-w c:\windows\system32\driver s\ale_nf.s ys
2009-04-07 16:22 . 2008-02-07 10:12 79752 ----a-w c:\windows\system32\driver s\ndis_rd. sys
2009-04-07 16:22 . 2008-02-07 10:12 74624 ----a-w c:\windows\system32\driver s\tdi_rd.s ys
2009-04-07 16:22 . 2008-05-16 09:28 212024 ----a-w c:\windows\system32\nscrns av.scr
.
(((((((((((((((((((((((((( (((((((((( (((( Find3M Rapport )))))))))))))))))))))))))) )))))))))) )))))))))) ))))))
.
2009-05-05 21:50 . 2005-12-09 11:35 59272 ----a-w d:\documents and settings\Kristine\Lokale innstillinger\Programdata\ GDIPFONTCA CHEV1.DAT
2009-05-05 20:53 . 2005-12-09 19:23 -------- d-----w c:\programfiler\Fellesfile r\Wise Installation Wizard
2009-05-05 19:30 . 2005-12-09 19:23 -------- d--h--w c:\programfiler\InstallShi eld Installation Information
2009-05-05 11:16 . 2006-09-02 19:49 -------- d-----w c:\programfiler\LimeWire
2009-05-05 08:21 . 2004-09-20 09:03 61500 ----a-w c:\windows\system32\perfc0 14.dat
2009-05-05 08:21 . 2004-09-20 09:03 387742 ----a-w c:\windows\system32\perfh0 14.dat
2009-02-09 14:08 . 2004-09-20 09:03 1846784 ----a-w c:\windows\system32\win32k .sys
.
(((((((((((((((((((((((((( (((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))) )))))))))) )))))))))
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR E\Microsof t\Windows\ CurrentVer sion\Run]
"CTFMON.EXE"="c:\windows\s ystem32\ct fmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\programfiler\ Messenger\ msmsgs.exe " [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Run]
"IMJPMIG8.1"="c:\windows\I ME\imjp8_1 \IMJPMIG.E XE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windo ws\system3 2\IME\TINT LGNT\TINTS ETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\s ystem32\IM E\TINTLGNT \TINTSETP. EXE" [2004-08-04 455168]
"SunJavaUpdateSched"="c:\p rogramfile r\Java\jre 1.5.0_02\b in\jusched .exe" [2005-03-04 36975]
"Ulead AutoDetector v2"="c:\programfiler\Felle sfiler\Ule ad Systems\AutoDetector\monit or.exe" [2004-11-26 90112]
"PCMService"="c:\apps\Powe rcinema\PC MService.e xe" [2005-05-11 127118]
"ACTIVBOARD"="c:\apps\ABoa rd\ABoard. exe" [2003-05-02 24576]
"TkBellExe"="c:\programfil er\Fellesf iler\Real\ Update_OB\ realsched. exe" [2005-11-12 180269]
"QuickTime Task"="c:\programfiler\Qui ckTime\qtt ask.exe" [2005-11-12 98304]
"UnlockerAssistant"="c:\pr ogramfiler \Unlocker\ UnlockerAs sistant.ex e" [2008-05-02 15872]
"AVG8_TRAY"="c:\progra~1\A VG\AVG8\av gtray.exe" [2009-05-05 1932568]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-01-20 77824]
[HKEY_USERS\.DEFAULT\Softw are\Micros oft\Window s\CurrentV ersion\Run ]
"CTFMON.EXE"="c:\windows\s ystem32\CT FMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows nt\currentversion\winlogon \notify\av grsstarter ]
2009-05-05 21:49 10520 ----a-w c:\windows\system32\avgrss tx.dll
[HKEY_LOCAL_MACHINE\softwa re\microso ft\securit y center]
"AntiVirusOverride"=dword: 00000001
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ standardpr ofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ standardpr ofile\Auth orizedAppl ications\L ist]
"%windir%\\system32\\sessm gr.exe"=
"c:\\Programfiler\\AVG\\AV G8\\avgupd .exe"=
"c:\\Programfiler\\AVG\\AV G8\\avgnsx .exe"=
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\dr ivers\avgl dx86.sys [05.05.2009 23:49 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\syst em32\drive rs\avgtdix .sys [05.05.2009 23:49 107912]
S1 NGS;Norman General Security Driver;\??\c:\programfiler \norman\ng s\bin\ngs. sys --> c:\programfiler\norman\ngs \bin\ngs.s ys [?]
S1 NPROSEC;Norman Security driver;\??\c:\programfiler \Norman\Ng s\Bin\npro sec.sys --> c:\programfiler\Norman\Ngs \Bin\npros ec.sys [?]
S2 Automatisk LiveUpdate-planlegging;Aut omatisk LiveUpdate-planlegging; [x]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\A VG8\avgwds vc.exe [05.05.2009 23:49 298264]
S3 S3chipid;S3chipid;\??\c:\d ocume~1\Ei er\LOKALE~ 1\Temp\{2B 43252C-A1E 3-4C47-927 C-9F2C276D 3515}\S3ch ipid.sys --> c:\docume~1\Eier\LOKALE~1\ Temp\{2B43 252C-A1E3- 4C47-927C- 9F2C276D35 15}\S3chip id.sys [?]
S4 NDIS_RD;Norman Firewall NDIS driver;c:\windows\system32 \drivers\n dis_rd.sys [07.04.2009 18:22 79752]
S4 NPC;Norman Parental Control;"c:\programfiler\N orman\npc\ bin\npcsvc 32.exe" --> c:\programfiler\Norman\npc \bin\npcsv c32.exe [?]
S4 NPFSvc32;Norman Personal Firewall Service;"c:\programfiler\N orman\npf\ bin\npfsvc 32.exe" --> c:\programfiler\Norman\npf \bin\npfsv c32.exe [?]
S4 NPROSECSVC;Norman Security service;"c:\programfiler\N orman\Ngs\ Bin\Nprose c.exe" --> c:\programfiler\Norman\Ngs \Bin\Npros ec.exe [?]
S4 NUAA;Norman User Activity Agent;"c:\programfiler\Nor man\npc\bi n\nuaa.exe " --> c:\programfiler\Norman\npc \bin\nuaa. exe [?]
S4 NVOY;Norman Resource Provider;"c:\programfiler\ Norman\npm \bin\nvoy. exe" --> c:\programfiler\Norman\npm \bin\nvoy. exe [?]
S4 TDI_RD;Norman Firewall TDI driver;c:\windows\system32 \drivers\t di_rd.sys [07.04.2009 18:22 74624]
.
************************** ********** ********** ********** ********** ********
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-06 14:39
Windows 5.1.2600 Service Pack 3 NTFS
skanner skjulte prosesser ...
skanner skjulte autostart-oppføringer ...
skanner skjulte filer ...
skanning vellykket
skjulte filer: 0
************************** ********** ********** ********** ********** ********
.
--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------
- - - - - - - > 'winlogon.exe'(208)
c:\windows\system32\Ati2ev xx.dll
.
Tidspunkt ferdig: 2009-05-06 14:40
ComboFix-quarantined-files .txt 2009-05-06 12:40
Pre-Run: 22 744 543 232 byte ledig
Post-Run: 22 730 854 400 byte ledig
149 --- E O F --- 2009-03-20 18:34
Microsoft Windows XP Home Edition 5.1.2600.3.1252.47.1044.18
Kjører fra: C:\jabba.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
FW: Personlig brannmur *disabled*
.
((((((((((((((((((((((((((
.
2009-05-06 09:54 . 2009-05-06 09:50 3012988 ----a-r C:\jabba.exe
2009-05-06 09:52 . 2009-05-06 10:19 -------- d-----w c:\windows\LastGood
2009-05-06 09:47 . 2009-03-25 12:29 130432 ----a-w c:\windows\system32\driver
2009-05-06 09:47 . 2009-03-03 18:18 73728 ----a-w c:\windows\system32\RtNicP
2009-05-06 08:36 . 2008-04-14 16:22 116224 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2001-10-06 12:02 23040 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2008-04-14 16:22 18944 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2001-10-06 12:03 27648 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2001-10-06 12:03 4608 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2001-08-18 04:37 99865 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2001-08-17 18:11 16970 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2004-08-03 20:29 19455 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2008-04-13 18:46 19200 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2004-08-03 20:29 12063 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2008-04-14 16:22 8192 ----a-w c:\windows\system32\dllcac
2009-05-06 08:34 . 2001-08-17 19:28 64605 ----a-w c:\windows\system32\dllcac
2009-05-06 08:33 . 2008-04-13 18:45 60032 ----a-w c:\windows\system32\dllcac
2009-05-06 08:32 . 2001-10-06 12:02 440576 ----a-w c:\windows\system32\dllcac
2009-05-06 08:31 . 2001-08-17 19:49 30464 ----a-w c:\windows\system32\dllcac
2009-05-06 08:30 . 2001-10-06 12:02 99328 ----a-w c:\windows\system32\dllcac
2009-05-06 08:29 . 2001-08-17 18:12 24576 ----a-w c:\windows\system32\dllcac
2009-05-06 08:28 . 2001-08-17 18:50 101760 ----a-w c:\windows\system32\dllcac
2009-05-06 08:27 . 2001-08-17 18:50 75392 ----a-w c:\windows\system32\dllcac
2009-05-06 08:26 . 2001-08-17 18:19 3840 ----a-w c:\windows\system32\dllcac
2009-05-06 08:25 . 2008-04-13 18:41 17664 ----a-w c:\windows\system32\dllcac
2009-05-06 08:24 . 2001-10-06 12:01 41984 ----a-w c:\windows\system32\dllcac
2009-05-06 08:23 . 2001-08-17 18:49 51552 ----a-w c:\windows\system32\dllcac
2009-05-06 08:22 . 2001-10-06 11:43 52255 ----a-w c:\windows\system32\dllcac
2009-05-06 08:21 . 2001-10-06 11:35 320384 ----a-w c:\windows\system32\dllcac
2009-05-06 08:20 . 2001-10-06 11:28 15744 ----a-w c:\windows\system32\dllcac
2009-05-06 08:19 . 2001-10-06 12:02 62464 ----a-w c:\windows\system32\dllcac
2009-05-06 08:18 . 2001-08-17 19:28 289887 ----a-w c:\windows\system32\dllcac
2009-05-06 08:17 . 2001-10-06 11:38 17408 ----a-w c:\windows\system32\dllcac
2009-05-06 08:16 . 2004-08-04 13:00 45056 ----a-w c:\windows\system32\dllcac
2009-05-06 08:15 . 2001-08-17 18:11 77386 ----a-w c:\windows\system32\dllcac
2009-05-06 08:14 . 2001-10-06 12:02 131156 ----a-w c:\windows\system32\dllcac
2009-05-06 08:13 . 2001-10-06 12:02 170880 ----a-w c:\windows\system32\dllcac
2009-05-06 08:12 . 2001-08-17 18:19 36992 ----a-w c:\windows\system32\dllcac
2009-05-05 21:52 . 2009-05-05 21:52 -------- d-----w c:\windows\AiOTemp
2009-05-05 21:51 . 2009-05-06 07:33 -------- d--h--r d:\documents and settings\Kristine\Siste
2009-05-05 21:49 . 2009-05-05 21:49 10520 ----a-w c:\windows\system32\avgrss
2009-05-05 21:49 . 2009-05-05 21:49 107912 ----a-w c:\windows\system32\driver
2009-05-05 21:49 . 2009-05-05 21:49 325640 ----a-w c:\windows\system32\driver
2009-05-05 21:49 . 2009-05-05 21:49 -------- d-----w c:\windows\system32\driver
2009-05-05 20:16 . 2009-05-05 20:16 -------- d-----w d:\documents and settings\Administrator\Pro
2009-05-05 20:11 . 2009-05-05 20:11 -------- d-----w d:\documents and settings\Kristine\Programd
2009-05-05 20:11 . 2009-05-05 20:11 -------- d-----w d:\documents and settings\All Users\Programdata\Malwareb
2009-05-05 19:45 . 2009-05-05 20:53 -------- d-----w d:\documents and settings\All Users\Programdata\Lavasoft
2009-05-05 19:30 . 2009-05-05 20:50 -------- d-----w c:\programfiler\Norman
2009-05-05 19:30 . 2009-05-05 19:30 -------- d-----w d:\documents and settings\Kristine\Programd
2009-05-05 10:51 . 2009-05-05 10:51 -------- d-----w d:\documents and settings\All Users\Programdata\NortonIn
2009-05-05 07:59 . 2009-05-05 07:59 -------- d-----w c:\programfiler\ACW
2009-05-05 07:35 . 2009-05-05 07:35 -------- d-----w c:\programfiler\AVG
2009-05-05 07:35 . 2009-05-05 21:49 -------- d-----w d:\documents and settings\All Users\Programdata\avg8
2009-04-30 12:43 . 2009-05-05 20:28 -------- d-----w d:\documents and settings\Kristine\Programd
2009-04-30 12:43 . 2009-04-30 12:43 -------- d-----w c:\programfiler\Unlocker
2009-04-30 10:56 . 2009-04-30 11:48 -------- d-----w c:\windows\system32\data
2009-04-30 10:46 . 2009-04-30 10:46 -------- d-----w c:\programfiler\CCleaner
2009-04-07 16:23 . 2009-04-07 16:23 -------- d-----w d:\documents and settings\LocalService\Star
2009-04-07 16:22 . 2008-04-16 10:57 42552 ----a-w c:\windows\system32\driver
2009-04-07 16:22 . 2008-02-07 10:12 79752 ----a-w c:\windows\system32\driver
2009-04-07 16:22 . 2008-02-07 10:12 74624 ----a-w c:\windows\system32\driver
2009-04-07 16:22 . 2008-05-16 09:28 212024 ----a-w c:\windows\system32\nscrns
.
((((((((((((((((((((((((((
.
2009-05-05 21:50 . 2005-12-09 11:35 59272 ----a-w d:\documents and settings\Kristine\Lokale innstillinger\Programdata\
2009-05-05 20:53 . 2005-12-09 19:23 -------- d-----w c:\programfiler\Fellesfile
2009-05-05 19:30 . 2005-12-09 19:23 -------- d--h--w c:\programfiler\InstallShi
2009-05-05 11:16 . 2006-09-02 19:49 -------- d-----w c:\programfiler\LimeWire
2009-05-05 08:21 . 2004-09-20 09:03 61500 ----a-w c:\windows\system32\perfc0
2009-05-05 08:21 . 2004-09-20 09:03 387742 ----a-w c:\windows\system32\perfh0
2009-02-09 14:08 . 2004-09-20 09:03 1846784 ----a-w c:\windows\system32\win32k
.
((((((((((((((((((((((((((
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
"CTFMON.EXE"="c:\windows\s
"MSMSGS"="c:\programfiler\
[HKEY_LOCAL_MACHINE\SOFTWA
"IMJPMIG8.1"="c:\windows\I
"PHIME2002ASync"="c:\windo
"PHIME2002A"="c:\windows\s
"SunJavaUpdateSched"="c:\p
"Ulead AutoDetector v2"="c:\programfiler\Felle
"PCMService"="c:\apps\Powe
"ACTIVBOARD"="c:\apps\ABoa
"TkBellExe"="c:\programfil
"QuickTime Task"="c:\programfiler\Qui
"UnlockerAssistant"="c:\pr
"AVG8_TRAY"="c:\progra~1\A
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-01-20 77824]
[HKEY_USERS\.DEFAULT\Softw
"CTFMON.EXE"="c:\windows\s
[HKEY_LOCAL_MACHINE\softwa
2009-05-05 21:49 10520 ----a-w c:\windows\system32\avgrss
[HKEY_LOCAL_MACHINE\softwa
"AntiVirusOverride"=dword:
[HKLM\~\services\sharedacc
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"c:\\Programfiler\\AVG\\AV
"c:\\Programfiler\\AVG\\AV
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\dr
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\syst
S1 NGS;Norman General Security Driver;\??\c:\programfiler
S1 NPROSEC;Norman Security driver;\??\c:\programfiler
S2 Automatisk LiveUpdate-planlegging;Aut
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\A
S3 S3chipid;S3chipid;\??\c:\d
S4 NDIS_RD;Norman Firewall NDIS driver;c:\windows\system32
S4 NPC;Norman Parental Control;"c:\programfiler\N
S4 NPFSvc32;Norman Personal Firewall Service;"c:\programfiler\N
S4 NPROSECSVC;Norman Security service;"c:\programfiler\N
S4 NUAA;Norman User Activity Agent;"c:\programfiler\Nor
S4 NVOY;Norman Resource Provider;"c:\programfiler\
S4 TDI_RD;Norman Firewall TDI driver;c:\windows\system32
.
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-06 14:39
Windows 5.1.2600 Service Pack 3 NTFS
skanner skjulte prosesser ...
skanner skjulte autostart-oppføringer ...
skanner skjulte filer ...
skanning vellykket
skjulte filer: 0
**************************
.
--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------
- - - - - - - > 'winlogon.exe'(208)
c:\windows\system32\Ati2ev
.
Tidspunkt ferdig: 2009-05-06 14:40
ComboFix-quarantined-files
Pre-Run: 22 744 543 232 byte ledig
Post-Run: 22 730 854 400 byte ledig
149 --- E O F --- 2009-03-20 18:34
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
ComboFix 09-05-05.03 - Administrator 06.05.2009 14:57.2 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.47.1044.18 .511.366 [GMT 2:00]
Kjører fra: C:\jabba.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
FW: Personlig brannmur *disabled*
.
(((((((((((((((((((((((((( ( Filer Opprettet Fra 2009-04-06 til 2009-05-06 )))))))))))))))))))))))))) )))))))
.
2009-05-06 09:54 . 2009-05-06 09:50 3012988 ----a-r C:\jabba.exe
2009-05-06 09:52 . 2009-05-06 10:19 -------- d-----w c:\windows\LastGood
2009-05-06 09:47 . 2009-03-25 12:29 130432 ----a-w c:\windows\system32\driver s\Rtnicxp. sys
2009-05-06 09:47 . 2009-03-03 18:18 73728 ----a-w c:\windows\system32\RtNicP rop32.dll
2009-05-06 08:36 . 2008-04-14 16:22 116224 ----a-w c:\windows\system32\dllcac he\xrxwiad r.dll
2009-05-06 08:36 . 2001-10-06 12:02 23040 ----a-w c:\windows\system32\dllcac he\xrxwbtm p.dll
2009-05-06 08:36 . 2008-04-14 16:22 18944 ----a-w c:\windows\system32\dllcac he\xrxscnu i.dll
2009-05-06 08:36 . 2001-10-06 12:03 27648 ----a-w c:\windows\system32\dllcac he\xrxftpl t.exe
2009-05-06 08:36 . 2001-10-06 12:03 4608 ----a-w c:\windows\system32\dllcac he\xrxflnc h.exe
2009-05-06 08:36 . 2001-08-18 04:37 99865 ----a-w c:\windows\system32\dllcac he\xlog.ex e
2009-05-06 08:36 . 2001-08-17 18:11 16970 ----a-w c:\windows\system32\dllcac he\xem336n 5.sys
2009-05-06 08:36 . 2004-08-03 20:29 19455 ----a-w c:\windows\system32\dllcac he\wvchntx x.sys
2009-05-06 08:36 . 2008-04-13 18:46 19200 ----a-w c:\windows\system32\dllcac he\wstcode c.sys
2009-05-06 08:36 . 2004-08-03 20:29 12063 ----a-w c:\windows\system32\dllcac he\wsiintx x.sys
2009-05-06 08:36 . 2008-04-14 16:22 8192 ----a-w c:\windows\system32\dllcac he\wshirda .dll
2009-05-06 08:34 . 2001-08-17 19:28 64605 ----a-w c:\windows\system32\dllcac he\vvoice. sys
2009-05-06 08:33 . 2008-04-13 18:45 60032 ----a-w c:\windows\system32\dllcac he\usbaudi o.sys
2009-05-06 08:32 . 2001-10-06 12:02 440576 ----a-w c:\windows\system32\dllcac he\tridkb. dll
2009-05-06 08:31 . 2001-08-17 19:49 30464 ----a-w c:\windows\system32\dllcac he\tbatm15 5.sys
2009-05-06 08:30 . 2001-10-06 12:02 99328 ----a-w c:\windows\system32\dllcac he\srusd.d ll
2009-05-06 08:29 . 2001-08-17 18:12 24576 ----a-w c:\windows\system32\dllcac he\smc8000 n.sys
2009-05-06 08:28 . 2001-08-17 18:50 101760 ----a-w c:\windows\system32\dllcac he\sis300i p.sys
2009-05-06 08:27 . 2001-08-17 18:50 75392 ----a-w c:\windows\system32\dllcac he\s3savmx m.sys
2009-05-06 08:26 . 2001-08-17 18:19 3840 ----a-w c:\windows\system32\dllcac he\rpfun.s ys
2009-05-06 08:25 . 2008-04-13 18:41 17664 ----a-w c:\windows\system32\dllcac he\ppa3.sy s
2009-05-06 08:24 . 2001-10-06 12:01 41984 ----a-w c:\windows\system32\dllcac he\ovui2rc .dll
2009-05-06 08:23 . 2001-08-17 18:49 51552 ----a-w c:\windows\system32\dllcac he\ntgrip. sys
2009-05-06 08:22 . 2001-10-06 11:43 52255 ----a-w c:\windows\system32\dllcac he\n1000nt 5.sys
2009-05-06 08:21 . 2001-10-06 11:35 320384 ----a-w c:\windows\system32\dllcac he\mgaum.s ys
2009-05-06 08:20 . 2001-10-06 11:28 15744 ----a-w c:\windows\system32\dllcac he\lit220p .sys
2009-05-06 08:19 . 2001-10-06 12:02 62464 ----a-w c:\windows\system32\dllcac he\icam4ex t.dll
2009-05-06 08:18 . 2001-08-17 19:28 289887 ----a-w c:\windows\system32\dllcac he\hsf_fal l.sys
2009-05-06 08:17 . 2001-10-06 11:38 17408 ----a-w c:\windows\system32\dllcac he\gpr400. sys
2009-05-06 08:16 . 2004-08-04 13:00 45056 ----a-w c:\windows\system32\dllcac he\esunid. dll
2009-05-06 08:15 . 2001-08-17 18:11 77386 ----a-w c:\windows\system32\dllcac he\el656nd 5.sys
2009-05-06 08:14 . 2001-10-06 12:02 131156 ----a-w c:\windows\system32\dllcac he\digidbp .dll
2009-05-06 08:13 . 2001-10-06 12:02 170880 ----a-w c:\windows\system32\dllcac he\cl546x. dll
2009-05-06 08:12 . 2001-08-17 18:19 36992 ----a-w c:\windows\system32\dllcac he\aztw232 0.sys
2009-05-05 21:52 . 2009-05-05 21:52 -------- d-----w c:\windows\AiOTemp
2009-05-05 21:51 . 2009-05-06 07:33 -------- d--h--r d:\documents and settings\Kristine\Siste
2009-05-05 21:49 . 2009-05-05 21:49 10520 ----a-w c:\windows\system32\avgrss tx.dll
2009-05-05 21:49 . 2009-05-05 21:49 107912 ----a-w c:\windows\system32\driver s\avgtdix. sys
2009-05-05 21:49 . 2009-05-05 21:49 325640 ----a-w c:\windows\system32\driver s\avgldx86 .sys
2009-05-05 21:49 . 2009-05-05 21:49 -------- d-----w c:\windows\system32\driver s\Avg
2009-05-05 20:16 . 2009-05-05 20:16 -------- d-----w d:\documents and settings\Administrator\Pro gramdata\M alwarebyte s
2009-05-05 20:11 . 2009-05-05 20:11 -------- d-----w d:\documents and settings\Kristine\Programd ata\Malwar ebytes
2009-05-05 20:11 . 2009-05-05 20:11 -------- d-----w d:\documents and settings\All Users\Programdata\Malwareb ytes
2009-05-05 19:45 . 2009-05-05 20:53 -------- d-----w d:\documents and settings\All Users\Programdata\Lavasoft
2009-05-05 19:30 . 2009-05-05 19:30 -------- d-----w d:\documents and settings\Kristine\Programd ata\Instal lShield
2009-05-05 10:51 . 2009-05-05 10:51 -------- d-----w d:\documents and settings\All Users\Programdata\NortonIn staller
2009-05-05 07:59 . 2009-05-05 07:59 -------- d-----w c:\programfiler\ACW
2009-05-05 07:35 . 2009-05-05 07:35 -------- d-----w c:\programfiler\AVG
2009-05-05 07:35 . 2009-05-05 21:49 -------- d-----w d:\documents and settings\All Users\Programdata\avg8
2009-04-30 12:43 . 2009-05-05 20:28 -------- d-----w d:\documents and settings\Kristine\Programd ata\Deskto picon
2009-04-30 12:43 . 2009-04-30 12:43 -------- d-----w c:\programfiler\Unlocker
2009-04-30 10:56 . 2009-04-30 11:48 -------- d-----w c:\windows\system32\data
2009-04-30 10:46 . 2009-04-30 10:46 -------- d-----w c:\programfiler\CCleaner
2009-04-07 16:23 . 2009-04-07 16:23 -------- d-----w d:\documents and settings\LocalService\Star t-meny
2009-04-07 16:22 . 2008-04-16 10:57 42552 ----a-w c:\windows\system32\driver s\ale_nf.s ys
2009-04-07 16:22 . 2008-02-07 10:12 79752 ----a-w c:\windows\system32\driver s\ndis_rd. sys
2009-04-07 16:22 . 2008-02-07 10:12 74624 ----a-w c:\windows\system32\driver s\tdi_rd.s ys
2009-04-07 16:22 . 2008-05-16 09:28 212024 ----a-w c:\windows\system32\nscrns av.scr
.
(((((((((((((((((((((((((( (((((((((( (((( Find3M Rapport )))))))))))))))))))))))))) )))))))))) )))))))))) ))))))
.
2009-05-05 21:50 . 2005-12-09 11:35 59272 ----a-w d:\documents and settings\Kristine\Lokale innstillinger\Programdata\ GDIPFONTCA CHEV1.DAT
2009-05-05 20:53 . 2005-12-09 19:23 -------- d-----w c:\programfiler\Fellesfile r\Wise Installation Wizard
2009-05-05 19:30 . 2005-12-09 19:23 -------- d--h--w c:\programfiler\InstallShi eld Installation Information
2009-05-05 11:16 . 2006-09-02 19:49 -------- d-----w c:\programfiler\LimeWire
2009-05-05 08:21 . 2004-09-20 09:03 61500 ----a-w c:\windows\system32\perfc0 14.dat
2009-05-05 08:21 . 2004-09-20 09:03 387742 ----a-w c:\windows\system32\perfh0 14.dat
2009-02-09 14:08 . 2004-09-20 09:03 1846784 ----a-w c:\windows\system32\win32k .sys
.
(((((((((((((((((((((((((( (((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))) )))))))))) )))))))))
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR E\Microsof t\Windows\ CurrentVer sion\Run]
"CTFMON.EXE"="c:\windows\s ystem32\ct fmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\programfiler\ Messenger\ msmsgs.exe " [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Run]
"IMJPMIG8.1"="c:\windows\I ME\imjp8_1 \IMJPMIG.E XE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windo ws\system3 2\IME\TINT LGNT\TINTS ETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\s ystem32\IM E\TINTLGNT \TINTSETP. EXE" [2004-08-04 455168]
"SunJavaUpdateSched"="c:\p rogramfile r\Java\jre 1.5.0_02\b in\jusched .exe" [2005-03-04 36975]
"Ulead AutoDetector v2"="c:\programfiler\Felle sfiler\Ule ad Systems\AutoDetector\monit or.exe" [2004-11-26 90112]
"PCMService"="c:\apps\Powe rcinema\PC MService.e xe" [2005-05-11 127118]
"ACTIVBOARD"="c:\apps\ABoa rd\ABoard. exe" [2003-05-02 24576]
"TkBellExe"="c:\programfil er\Fellesf iler\Real\ Update_OB\ realsched. exe" [2005-11-12 180269]
"QuickTime Task"="c:\programfiler\Qui ckTime\qtt ask.exe" [2005-11-12 98304]
"UnlockerAssistant"="c:\pr ogramfiler \Unlocker\ UnlockerAs sistant.ex e" [2008-05-02 15872]
"AVG8_TRAY"="c:\progra~1\A VG\AVG8\av gtray.exe" [2009-05-05 1932568]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-01-20 77824]
[HKEY_USERS\.DEFAULT\Softw are\Micros oft\Window s\CurrentV ersion\Run ]
"CTFMON.EXE"="c:\windows\s ystem32\CT FMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows nt\currentversion\winlogon \notify\av grsstarter ]
2009-05-05 21:49 10520 ----a-w c:\windows\system32\avgrss tx.dll
[HKEY_LOCAL_MACHINE\softwa re\microso ft\securit y center]
"AntiVirusOverride"=dword: 00000001
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ standardpr ofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ standardpr ofile\Auth orizedAppl ications\L ist]
"%windir%\\system32\\sessm gr.exe"=
"c:\\Programfiler\\AVG\\AV G8\\avgupd .exe"=
"c:\\Programfiler\\AVG\\AV G8\\avgnsx .exe"=
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\dr ivers\avgl dx86.sys [05.05.2009 23:49 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\syst em32\drive rs\avgtdix .sys [05.05.2009 23:49 107912]
S1 NGS;NGS; [x]
S1 NPROSEC;NPROSEC; [x]
S2 Automatisk LiveUpdate-planlegging;Aut omatisk LiveUpdate-planlegging; [x]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\A VG8\avgwds vc.exe [05.05.2009 23:49 298264]
S3 S3chipid;S3chipid;\??\c:\d ocume~1\Ei er\LOKALE~ 1\Temp\{2B 43252C-A1E 3-4C47-927 C-9F2C276D 3515}\S3ch ipid.sys --> c:\docume~1\Eier\LOKALE~1\ Temp\{2B43 252C-A1E3- 4C47-927C- 9F2C276D35 15}\S3chip id.sys [?]
S4 NDIS_RD;NDIS_RD;c:\windows \system32\ drivers\nd is_rd.sys [07.04.2009 18:22 79752]
S4 NPC;NPC; [x]
S4 NPFSvc32;NPFSvc32; [x]
S4 NPROSECSVC;NPROSECSVC; [x]
S4 NUAA;NUAA; [x]
S4 NVOY;NVOY; [x]
S4 TDI_RD;TDI_RD;c:\windows\s ystem32\dr ivers\tdi_ rd.sys [07.04.2009 18:22 74624]
.
************************** ********** ********** ********** ********** ********
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-06 14:58
Windows 5.1.2600 Service Pack 3 NTFS
skanner skjulte prosesser ...
skanner skjulte autostart-oppføringer ...
skanner skjulte filer ...
skanning vellykket
skjulte filer: 0
************************** ********** ********** ********** ********** ********
.
--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------
- - - - - - - > 'winlogon.exe'(208)
c:\windows\system32\Ati2ev xx.dll
.
Tidspunkt ferdig: 2009-05-06 14:59
ComboFix-quarantined-files .txt 2009-05-06 12:59
ComboFix2.txt 2009-05-06 12:40
Pre-Run: 22 738 702 336 byte ledig
Post-Run: 22 727 610 368 byte ledig
149 --- E O F --- 2009-03-20 18:34
Microsoft Windows XP Home Edition 5.1.2600.3.1252.47.1044.18
Kjører fra: C:\jabba.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
FW: Personlig brannmur *disabled*
.
((((((((((((((((((((((((((
.
2009-05-06 09:54 . 2009-05-06 09:50 3012988 ----a-r C:\jabba.exe
2009-05-06 09:52 . 2009-05-06 10:19 -------- d-----w c:\windows\LastGood
2009-05-06 09:47 . 2009-03-25 12:29 130432 ----a-w c:\windows\system32\driver
2009-05-06 09:47 . 2009-03-03 18:18 73728 ----a-w c:\windows\system32\RtNicP
2009-05-06 08:36 . 2008-04-14 16:22 116224 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2001-10-06 12:02 23040 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2008-04-14 16:22 18944 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2001-10-06 12:03 27648 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2001-10-06 12:03 4608 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2001-08-18 04:37 99865 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2001-08-17 18:11 16970 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2004-08-03 20:29 19455 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2008-04-13 18:46 19200 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2004-08-03 20:29 12063 ----a-w c:\windows\system32\dllcac
2009-05-06 08:36 . 2008-04-14 16:22 8192 ----a-w c:\windows\system32\dllcac
2009-05-06 08:34 . 2001-08-17 19:28 64605 ----a-w c:\windows\system32\dllcac
2009-05-06 08:33 . 2008-04-13 18:45 60032 ----a-w c:\windows\system32\dllcac
2009-05-06 08:32 . 2001-10-06 12:02 440576 ----a-w c:\windows\system32\dllcac
2009-05-06 08:31 . 2001-08-17 19:49 30464 ----a-w c:\windows\system32\dllcac
2009-05-06 08:30 . 2001-10-06 12:02 99328 ----a-w c:\windows\system32\dllcac
2009-05-06 08:29 . 2001-08-17 18:12 24576 ----a-w c:\windows\system32\dllcac
2009-05-06 08:28 . 2001-08-17 18:50 101760 ----a-w c:\windows\system32\dllcac
2009-05-06 08:27 . 2001-08-17 18:50 75392 ----a-w c:\windows\system32\dllcac
2009-05-06 08:26 . 2001-08-17 18:19 3840 ----a-w c:\windows\system32\dllcac
2009-05-06 08:25 . 2008-04-13 18:41 17664 ----a-w c:\windows\system32\dllcac
2009-05-06 08:24 . 2001-10-06 12:01 41984 ----a-w c:\windows\system32\dllcac
2009-05-06 08:23 . 2001-08-17 18:49 51552 ----a-w c:\windows\system32\dllcac
2009-05-06 08:22 . 2001-10-06 11:43 52255 ----a-w c:\windows\system32\dllcac
2009-05-06 08:21 . 2001-10-06 11:35 320384 ----a-w c:\windows\system32\dllcac
2009-05-06 08:20 . 2001-10-06 11:28 15744 ----a-w c:\windows\system32\dllcac
2009-05-06 08:19 . 2001-10-06 12:02 62464 ----a-w c:\windows\system32\dllcac
2009-05-06 08:18 . 2001-08-17 19:28 289887 ----a-w c:\windows\system32\dllcac
2009-05-06 08:17 . 2001-10-06 11:38 17408 ----a-w c:\windows\system32\dllcac
2009-05-06 08:16 . 2004-08-04 13:00 45056 ----a-w c:\windows\system32\dllcac
2009-05-06 08:15 . 2001-08-17 18:11 77386 ----a-w c:\windows\system32\dllcac
2009-05-06 08:14 . 2001-10-06 12:02 131156 ----a-w c:\windows\system32\dllcac
2009-05-06 08:13 . 2001-10-06 12:02 170880 ----a-w c:\windows\system32\dllcac
2009-05-06 08:12 . 2001-08-17 18:19 36992 ----a-w c:\windows\system32\dllcac
2009-05-05 21:52 . 2009-05-05 21:52 -------- d-----w c:\windows\AiOTemp
2009-05-05 21:51 . 2009-05-06 07:33 -------- d--h--r d:\documents and settings\Kristine\Siste
2009-05-05 21:49 . 2009-05-05 21:49 10520 ----a-w c:\windows\system32\avgrss
2009-05-05 21:49 . 2009-05-05 21:49 107912 ----a-w c:\windows\system32\driver
2009-05-05 21:49 . 2009-05-05 21:49 325640 ----a-w c:\windows\system32\driver
2009-05-05 21:49 . 2009-05-05 21:49 -------- d-----w c:\windows\system32\driver
2009-05-05 20:16 . 2009-05-05 20:16 -------- d-----w d:\documents and settings\Administrator\Pro
2009-05-05 20:11 . 2009-05-05 20:11 -------- d-----w d:\documents and settings\Kristine\Programd
2009-05-05 20:11 . 2009-05-05 20:11 -------- d-----w d:\documents and settings\All Users\Programdata\Malwareb
2009-05-05 19:45 . 2009-05-05 20:53 -------- d-----w d:\documents and settings\All Users\Programdata\Lavasoft
2009-05-05 19:30 . 2009-05-05 19:30 -------- d-----w d:\documents and settings\Kristine\Programd
2009-05-05 10:51 . 2009-05-05 10:51 -------- d-----w d:\documents and settings\All Users\Programdata\NortonIn
2009-05-05 07:59 . 2009-05-05 07:59 -------- d-----w c:\programfiler\ACW
2009-05-05 07:35 . 2009-05-05 07:35 -------- d-----w c:\programfiler\AVG
2009-05-05 07:35 . 2009-05-05 21:49 -------- d-----w d:\documents and settings\All Users\Programdata\avg8
2009-04-30 12:43 . 2009-05-05 20:28 -------- d-----w d:\documents and settings\Kristine\Programd
2009-04-30 12:43 . 2009-04-30 12:43 -------- d-----w c:\programfiler\Unlocker
2009-04-30 10:56 . 2009-04-30 11:48 -------- d-----w c:\windows\system32\data
2009-04-30 10:46 . 2009-04-30 10:46 -------- d-----w c:\programfiler\CCleaner
2009-04-07 16:23 . 2009-04-07 16:23 -------- d-----w d:\documents and settings\LocalService\Star
2009-04-07 16:22 . 2008-04-16 10:57 42552 ----a-w c:\windows\system32\driver
2009-04-07 16:22 . 2008-02-07 10:12 79752 ----a-w c:\windows\system32\driver
2009-04-07 16:22 . 2008-02-07 10:12 74624 ----a-w c:\windows\system32\driver
2009-04-07 16:22 . 2008-05-16 09:28 212024 ----a-w c:\windows\system32\nscrns
.
((((((((((((((((((((((((((
.
2009-05-05 21:50 . 2005-12-09 11:35 59272 ----a-w d:\documents and settings\Kristine\Lokale innstillinger\Programdata\
2009-05-05 20:53 . 2005-12-09 19:23 -------- d-----w c:\programfiler\Fellesfile
2009-05-05 19:30 . 2005-12-09 19:23 -------- d--h--w c:\programfiler\InstallShi
2009-05-05 11:16 . 2006-09-02 19:49 -------- d-----w c:\programfiler\LimeWire
2009-05-05 08:21 . 2004-09-20 09:03 61500 ----a-w c:\windows\system32\perfc0
2009-05-05 08:21 . 2004-09-20 09:03 387742 ----a-w c:\windows\system32\perfh0
2009-02-09 14:08 . 2004-09-20 09:03 1846784 ----a-w c:\windows\system32\win32k
.
((((((((((((((((((((((((((
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
"CTFMON.EXE"="c:\windows\s
"MSMSGS"="c:\programfiler\
[HKEY_LOCAL_MACHINE\SOFTWA
"IMJPMIG8.1"="c:\windows\I
"PHIME2002ASync"="c:\windo
"PHIME2002A"="c:\windows\s
"SunJavaUpdateSched"="c:\p
"Ulead AutoDetector v2"="c:\programfiler\Felle
"PCMService"="c:\apps\Powe
"ACTIVBOARD"="c:\apps\ABoa
"TkBellExe"="c:\programfil
"QuickTime Task"="c:\programfiler\Qui
"UnlockerAssistant"="c:\pr
"AVG8_TRAY"="c:\progra~1\A
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-01-20 77824]
[HKEY_USERS\.DEFAULT\Softw
"CTFMON.EXE"="c:\windows\s
[HKEY_LOCAL_MACHINE\softwa
2009-05-05 21:49 10520 ----a-w c:\windows\system32\avgrss
[HKEY_LOCAL_MACHINE\softwa
"AntiVirusOverride"=dword:
[HKLM\~\services\sharedacc
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"c:\\Programfiler\\AVG\\AV
"c:\\Programfiler\\AVG\\AV
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\dr
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\syst
S1 NGS;NGS; [x]
S1 NPROSEC;NPROSEC; [x]
S2 Automatisk LiveUpdate-planlegging;Aut
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\A
S3 S3chipid;S3chipid;\??\c:\d
S4 NDIS_RD;NDIS_RD;c:\windows
S4 NPC;NPC; [x]
S4 NPFSvc32;NPFSvc32; [x]
S4 NPROSECSVC;NPROSECSVC; [x]
S4 NUAA;NUAA; [x]
S4 NVOY;NVOY; [x]
S4 TDI_RD;TDI_RD;c:\windows\s
.
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-06 14:58
Windows 5.1.2600 Service Pack 3 NTFS
skanner skjulte prosesser ...
skanner skjulte autostart-oppføringer ...
skanner skjulte filer ...
skanning vellykket
skjulte filer: 0
**************************
.
--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------
- - - - - - - > 'winlogon.exe'(208)
c:\windows\system32\Ati2ev
.
Tidspunkt ferdig: 2009-05-06 14:59
ComboFix-quarantined-files
ComboFix2.txt 2009-05-06 12:40
Pre-Run: 22 738 702 336 byte ledig
Post-Run: 22 727 610 368 byte ledig
149 --- E O F --- 2009-03-20 18:34
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Already done that, but can try again.
While running Combofix, I get a message that AVG is running. But i cant find it. I've looked at task bar, task mannager (prosesses), and in My computer-manage-services.
And then I get 3 messages saying: xecute prosesses remotely having problems, and need to close.
Sometimes I get a message, like the one I get when I get into Safe Mode..........you are running in safe mode, answare Yes to continue, og No to......restore point.
While running Combofix, I get a message that AVG is running. But i cant find it. I've looked at task bar, task mannager (prosesses), and in My computer-manage-services.
And then I get 3 messages saying: xecute prosesses remotely having problems, and need to close.
Sometimes I get a message, like the one I get when I get into Safe Mode..........you are running in safe mode, answare Yes to continue, og No to......restore point.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Done......! Still problems.
When I try to start Windows Firewall, i get a message: error 10047 and the rest in norwegian.
Tried to start manually from Services, but one of the dependent services didn't start.
Now I am googling on that problem :-)
I'm also running Microsoft Windows Tool for removing malicious (i think) software.
Have to try everything, because I don't want to reinstall, I want to understand and fix this !!!!
When I try to start Windows Firewall, i get a message: error 10047 and the rest in norwegian.
Tried to start manually from Services, but one of the dependent services didn't start.
Now I am googling on that problem :-)
I'm also running Microsoft Windows Tool for removing malicious (i think) software.
Have to try everything, because I don't want to reinstall, I want to understand and fix this !!!!
have you tried the second network card option?
Also, can you send me the IPCONFIG /all from the problem machine and a working machine?
Use:
IPCONFIG /all > log.txt
And then copy and paste the log.txt file contents
Also, can you send me the IPCONFIG /all from the problem machine and a working machine?
Use:
IPCONFIG /all > log.txt
And then copy and paste the log.txt file contents
ASKER
I have noe other NIC available, only Wireless.
Problem pc:
Windows IP-konfigurasjon
Vertsnavn . . . . . . . . . . . : KIRSTENS
Primær DNS-suffiks . . . . . . . :
Nodetype . . . . . . . . . . . . : Ukjent
IP-ruting aktivert . . . . . . . : Nei
WINS Proxy aktivert. . . . . . . : Nei
Ethernet-kort Lokal tilkobling 5:
Tilkoblingsspesifikt DNS-suffiks :
Beskrivelse . . . . . . . . . . : Realtek RTL8139/810x Family Fast Ethernet NIC
Fysisk adresse . . . . . . . . . : 00-14-85-B3-C8-73
DHCP aktivert. . . . . . . . . . : Ja
Automatisk konfigurasjon aktivert: Ja
Automatisk konfigurasjon av IP-adresse. . . : 169.254.182.239
Nettverksmaske . . . . . . . . . : 255.255.0.0
IP-adresse . . . . . . . . . . . : fe80::214:85ff:feb3:c873%4
Standard gateway . . . . . . . . :
DNS-servere. . . . . . . . . . . : fec0:0:0:ffff::1%1
fec0:0:0:ffff::2%1
fec0:0:0:ffff::3%1
Tunnelkort Teredo Tunneling Pseudo-Interface:
Tilkoblingsspesifikt DNS-suffiks :
Beskrivelse . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Fysisk adresse . . . . . . . . . : FF-FF-FF-FF-FF-FF-FF-FF
DHCP aktivert. . . . . . . . . . : Nei
IP-adresse . . . . . . . . . . . : fe80::ffff:ffff:fffd%5
Standard gateway . . . . . . . . :
NetBIOS over TCP/IP. . . . . . . : Deaktivert
Working pc with static ip:
Windows IP-konfigurasjon
Vertsnavn . . . . . . . . . . . : Kirsti-Acer
Primr DNS-suffiks . . . . . . . :
Nodetype . . . . . . . . . . . . : Hybrid
IP-ruting aktivert . . . . . . . : Nei
WINS Proxy aktivert . . . . . . . : Nei
Ethernet-kort Lokal tilkobling:
Tilkoblingsspesifikt DNS-suffiks :
Beskrivelse . . . . . . . . . . : Realtek RTL8168/8111 Family PCI-E Gigabit Ethernet NIC (NDIS 6.0)
Fysisk adresse . . . . . . . . . : 00-1F-E2-39-2B-D1
DHCP aktivert . . . . . . . . . . : Nei
Automatisk konfigurasjon aktivert : Ja
Koblingslokal IPv6-adresse. . . . : fe80::419a:3398:ff20:71ed% 10(Foretru kket)
IPv4-adresse. . . . . . . . . . . : 192.168.225.99(Foretrukket )
Nettverksmaske . . . . . . . . . .: 255.255.255.0
Standard gateway . . . . . . . . .: 192.168.225.1
DNS-servere . . . . . . . . . . . : 81.167.36.3
81.167.36.11
NetBIOS over Tcpip. . . . . . . . : Aktivert
Tunnelkort Lokal tilkobling*:
Medietilstand . . . . . . . . . . : Medium frakoblet
Tilkoblingsspesifikt DNS-suffiks :
Beskrivelse . . . . . . . . . . : isatap.{A26CB3DC-165D-46F4 -9CD3-DFA6 1218BEC1}
Fysisk adresse . . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP aktivert . . . . . . . . . . : Nei
Automatisk konfigurasjon aktivert : Ja
Tunnelkort Lokal tilkobling* 6:
Medietilstand . . . . . . . . . . : Medium frakoblet
Tilkoblingsspesifikt DNS-suffiks :
Beskrivelse . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Fysisk adresse . . . . . . . . . : 02-00-54-55-4E-01
DHCP aktivert . . . . . . . . . . : Nei
Automatisk konfigurasjon aktivert : Ja
Problem pc:
Windows IP-konfigurasjon
Vertsnavn . . . . . . . . . . . : KIRSTENS
Primær DNS-suffiks . . . . . . . :
Nodetype . . . . . . . . . . . . : Ukjent
IP-ruting aktivert . . . . . . . : Nei
WINS Proxy aktivert. . . . . . . : Nei
Ethernet-kort Lokal tilkobling 5:
Tilkoblingsspesifikt DNS-suffiks :
Beskrivelse . . . . . . . . . . : Realtek RTL8139/810x Family Fast Ethernet NIC
Fysisk adresse . . . . . . . . . : 00-14-85-B3-C8-73
DHCP aktivert. . . . . . . . . . : Ja
Automatisk konfigurasjon aktivert: Ja
Automatisk konfigurasjon av IP-adresse. . . : 169.254.182.239
Nettverksmaske . . . . . . . . . : 255.255.0.0
IP-adresse . . . . . . . . . . . : fe80::214:85ff:feb3:c873%4
Standard gateway . . . . . . . . :
DNS-servere. . . . . . . . . . . : fec0:0:0:ffff::1%1
fec0:0:0:ffff::2%1
fec0:0:0:ffff::3%1
Tunnelkort Teredo Tunneling Pseudo-Interface:
Tilkoblingsspesifikt DNS-suffiks :
Beskrivelse . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Fysisk adresse . . . . . . . . . : FF-FF-FF-FF-FF-FF-FF-FF
DHCP aktivert. . . . . . . . . . : Nei
IP-adresse . . . . . . . . . . . : fe80::ffff:ffff:fffd%5
Standard gateway . . . . . . . . :
NetBIOS over TCP/IP. . . . . . . : Deaktivert
Working pc with static ip:
Windows IP-konfigurasjon
Vertsnavn . . . . . . . . . . . : Kirsti-Acer
Primr DNS-suffiks . . . . . . . :
Nodetype . . . . . . . . . . . . : Hybrid
IP-ruting aktivert . . . . . . . : Nei
WINS Proxy aktivert . . . . . . . : Nei
Ethernet-kort Lokal tilkobling:
Tilkoblingsspesifikt DNS-suffiks :
Beskrivelse . . . . . . . . . . : Realtek RTL8168/8111 Family PCI-E Gigabit Ethernet NIC (NDIS 6.0)
Fysisk adresse . . . . . . . . . : 00-1F-E2-39-2B-D1
DHCP aktivert . . . . . . . . . . : Nei
Automatisk konfigurasjon aktivert : Ja
Koblingslokal IPv6-adresse. . . . : fe80::419a:3398:ff20:71ed%
IPv4-adresse. . . . . . . . . . . : 192.168.225.99(Foretrukket
Nettverksmaske . . . . . . . . . .: 255.255.255.0
Standard gateway . . . . . . . . .: 192.168.225.1
DNS-servere . . . . . . . . . . . : 81.167.36.3
81.167.36.11
NetBIOS over Tcpip. . . . . . . . : Aktivert
Tunnelkort Lokal tilkobling*:
Medietilstand . . . . . . . . . . : Medium frakoblet
Tilkoblingsspesifikt DNS-suffiks :
Beskrivelse . . . . . . . . . . : isatap.{A26CB3DC-165D-46F4
Fysisk adresse . . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP aktivert . . . . . . . . . . : Nei
Automatisk konfigurasjon aktivert : Ja
Tunnelkort Lokal tilkobling* 6:
Medietilstand . . . . . . . . . . : Medium frakoblet
Tilkoblingsspesifikt DNS-suffiks :
Beskrivelse . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Fysisk adresse . . . . . . . . . : 02-00-54-55-4E-01
DHCP aktivert . . . . . . . . . . : Nei
Automatisk konfigurasjon aktivert : Ja
Can you try disabling IPv6 protocol on the non-working machine? Untick the option from network connection properties and then reboot.
Thanks
Thanks
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
But how can I remove the rest of Norman?
Now I try recovering to the day that norman was installed. It fails.
Now I try recovering to one month before norman................!
Now I try recovering to the day that norman was installed. It fails.
Now I try recovering to one month before norman................!
ASKER
Didn't work out. I'm about to give up. Is there more to try?
As mentioned yesterday I had exactly the same issue as this and the only fix was to reinstall. There's an inherent problem with Vista's network implementation that gets corrupted easily.
Sorry I couldn't be of assistance but it really does look like the reinstall is the easiest option.
JOhn
Sorry I couldn't be of assistance but it really does look like the reinstall is the easiest option.
JOhn
Try the Norman Removal Tool again. Looks like AVG is out now. It should be able to get rid of Norman now. Make sure to download another antivirus and install after all antiviruses are out of your PC.
ASKER
The only Norman removal took I can find is:
Delnvc5
And it says: Cannot find Norman Virus Control installed
Delnvc5
And it says: Cannot find Norman Virus Control installed
Dataplan - I think you've made a valiant effort to resolve this issue but I honestly think a rebuild is your only choice now.
What do fellow Experts feel?
Thanks
John
What do fellow Experts feel?
Thanks
John
ASKER
I find som keys in regestry with Norman inside. Unable to remove them. How can I ?
Try using the browsers to surf the internet and see if it works ok now.
ASKER
I have tried, but no :-(
I cant even get an IP adress from DHCP. The windows Firewall won't start.
Last resort. I now try booting from MiniPe CD (bart), and try to delete norman from registry.
Anyone else?
I cant even get an IP adress from DHCP. The windows Firewall won't start.
Last resort. I now try booting from MiniPe CD (bart), and try to delete norman from registry.
Anyone else?
You could also try a Windows repair instead of a full re-install (requires that you have a windows xp cd with you):
http://www.informationweek.com/news/windows/showArticle.jhtml?articleID=189400897&cid=ref-true
http://www.informationweek.com/news/windows/showArticle.jhtml?articleID=189400897&cid=ref-true
ASKER
Halleluja !!!!
My computer now works. I dont know what did the trick, but i tried all this things one more time AFTER I had deletet all of Norman from MiniPE cd.
The last thing i did once more, was WinsocXPfix, not winsockFix. After reboot, I now have IP adress, and I can surf on the net again.
Thanks to all of you. Couldn't have done thise without you :-)
My computer now works. I dont know what did the trick, but i tried all this things one more time AFTER I had deletet all of Norman from MiniPE cd.
The last thing i did once more, was WinsocXPfix, not winsockFix. After reboot, I now have IP adress, and I can surf on the net again.
Thanks to all of you. Couldn't have done thise without you :-)
"Its good to see that it wasn't viruses that were the problem, it was multiple antiviruses this time" .. hahaha
Great!
Great!
Well done and great determination!
ASKER