WA2_32.dll no longer valid

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wobbb1, Aug 1, 2010.

  1. wobbb1

    wobbb1 Private E-2

    Hi,

    All network unavailable, after opening a couple of emails (no subject/title, nonsense in message body) from someone in a large group email. I get "Mobile Device Properties" error window, with "....dll is no longer valid.". I have followed all the guidance provided, and have 5 log .txts. I will post the fifth in the next message. Please can someone help get my laptop back up.

    Thanks in advance,
    Robin
     

    Attached Files:

  2. wobbb1

    wobbb1 Private E-2

    5th log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to major Geeks!

    wa2_32.dll is not a valid file to begin with. Did you mean ws2_32.dll which is a valid Windows file? Your's appears to be okay.


    Uninstall the below old versions of software:
    NetMeter 1.1.4 BETA <-- considered malware and should not be used
    Spybot - Search & Destroy 1.5.2.20 <-- outdated version

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5577
    O2 - BHO: (no name) - AutorunsDisabled - (no file)
    O9 - Extra button: (no name) - AutorunsDisabled - (no file)
    O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} -
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
    O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} (Java Plug-in 1.5.0_09) -
    O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} (Java Plug-in 1.5.0_10) -
    O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.5.0_11) -
    O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} (Java Plug-in 1.6.0) -
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -
    O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} (Java Plug-in 1.6.0_15) -
    O24 - Desktop Component 0: (no name) - (no file)

    After clicking Fix, exit HJT.


    Use the below procedure to reset proxy settings:
    Proxy Server - Changing Settings



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. wobbb1

    wobbb1 Private E-2

    Hi,
    Whilst running Combofix, it rebooted and, after I logged back in, SAS plus a few other apps 'autoloaded' while Combofix finished doing it's stuff.

    I hope this hasn't caused things to screw up.

    Thanks again,
    Robin
     

    Attached Files:

  5. wobbb1

    wobbb1 Private E-2

    Forgot to say how things are running. No change.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not appear to be due to malware. Seems something changed your network setup. You network media shows as disconnected
    Code:
    Windows IP Configuration
     
            Host Name . . . . . . . . . . . . : DV5094EA
            Primary Dns Suffix  . . . . . . . : 
            Node Type . . . . . . . . . . . . : Mixed
            IP Routing Enabled. . . . . . . . : No
            WINS Proxy Enabled. . . . . . . . : No
     
    Ethernet adapter Local Area Connection:
     
            Media State . . . . . . . . . . . : Media disconnected
            Description . . . . . . . . . . . : Realtek RTL8139/810x Family Fast Ethernet NIC
    FIrst try running this: WinSock XP Fix if it does not help, you may have to work this in the Networking Forum but I suggest that you see what the below link discussese since it is related.

    http://www.anetforums.com/posts.aspx?ThreadIndex=29913


    Also something else that sometimes works is to update or re-burn the firmware for your router.
     
    Last edited: Aug 3, 2010
  7. wobbb1

    wobbb1 Private E-2

    Hi,

    After much searching I found this:
    http://forums.techguy.org/networking/530663-solved-broadcom-802-11b-g.html

    and did this:

    "Click the Start button, and then click Control Panel.
    In the Control Panel window, under Pick a category, double-click the Network and Internet Connections icon.
    In the Network and Internet Connections window, under or pick a Control Panel icon, double-click the Network Connections icon.
    In the Network Connections window, under LAN or High Speed Internet, click to select the Local Area Connection icon.
    On the menu bar, click File.
    On the File menu, click Properties.
    In the Local Area Connections Properties window, on the General tab, click the Install button.
    In the Select Network Component Type window, in the Click the type of network... box, click to select the Service icon.
    Click the Add... button.
    In the Select Network Service window, click the Have Disk... button.
    Click the OK button.
    In the Install From Disk window, click the Browse... button.
    In the Locate File window, browse to the C:\Windows\Inf folder (this is a hidden folder).
    Click to select NETWZC.INF.
    Click the Open button.
    In the Install From Disk window, click the OK button.
    In the Select Network Service window, in the Network Service box, click to select Wireless Zero Configuration.
    Click the OK button."

    All back to normal - so far. I hope this can be of use to others.

    Many thanks for your attention!

    Robin
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I'm happy to hear you got it fixed; however that was basically just a reinstall of the drivers for your wireless interface. Have you checked to make sure that your wired network connection is also working. What I showed earlier indicated that your wired interface was likely broken.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited: Aug 24, 2010
  9. wobbb1

    wobbb1 Private E-2

    All done, although system restore was already off...I can't remember if that was me or not.

    Wired connection OK.

    Thanks again,
    Robin
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.


    Make sure that you have re-enabled System Restore.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds