Help Please

Discussion in 'Malware Help (A Specialist Will Reply)' started by nanouk77, Apr 27, 2005.

  1. nanouk77

    nanouk77 Private E-2

    Hi Folks

    I am having some problems with my pc

    The symptons include:

    I am unable to open i.e.

    I am unable to run any antivirus software

    There is a new icon in my tray ( a yellow triangle with an exclamation mark in it) that is telling me my pc has no antivirus software and to click to go to a recommended site.

    My Hijack this log is available for your viewing pleasure.

    Many Thanks in Advance.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below. If particular items cannot be run due to your problem, please note which ones (and tell me when you come back) and continue with the steps.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. nanouk77

    nanouk77 Private E-2

    hi. thanks for getting back so quickly.

    I was able to run the two online scans. the results are:

    Trend Micro
    TROJ Topantspy.b
    TROJ Golid.m
    TROJ Small.mar
    TROJ Netbuie.a
    TROJ Netbuie.a

    TrojanScan
    Trojan.Win32.Favadd.n
    Trojan.Win32.Hpt.i
    Trojan-Proxy.Win32.Agent.l
    Trojan.Win32.Editstar
    Trojan-Dropper.Win32.Small.ru

    As before, i was unable to run any programs already on my pc. When i ran stinger, it didnt detect any problems.

    I have attached my HJT log file as requested.

    I appreciate any help that you can give me.
    Thanks
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was that log from safe mode? If so, from now on only post logs from normal boot mode unless requested otherwise. Let's make a dent in your problem. Run the steps below.

    Download LSP - Fix

    Now run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the flsmngr.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move flsmngr.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    We need to stop, disable and remove a few bad services. They show in your HijackThis log as:
    O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\System32\ahtun.exe
    O23 - Service: nlgffxcavjyd (MsUpdate6) - Unknown owner - C:\WINDOWS\System32\msupd6.exe (file missing)

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Debug oupost relations or LAGOS ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above for nlgffxcavjyd or MsUpdate6.
    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Debug oupost relations

    If that does not work, try using the short name of the service: LAGOS

    Now repeat the HijackThis step to delete the other NT service:
    Use nlgffxcavjyd or the service short name of MsUpdate6

    Now exit HijackThis.

    Let me know how all the above steps go.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please re-run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\ahtun.exe
    C:\WINDOWS\System32\msupd6.exe
    C:\WINDOWS\System32\wiaadycc.exe
    c:\windows\rfbfekq.exe
    c:\windows\qxhghpi.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O2 - BHO: (no name) - {9287E855-A010-0278-5E1C-6C88CDB4863F} - (no file)
    O2 - BHO: (no name) - {A058E069-1E27-A016-6A11-2809D8B1322D} - (no file)
    O2 - BHO: (no name) - {D63FAE9B-506E-07A3-9DF7-A6E318A4F392} - (no file)
    O4 - HKLM\..\Run: [Access Browser] C:\WINDOWS\System32\wiaadycc.exe
    O4 - HKCU\..\Run: [txvnvfp] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [vjjsqnb] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [wyiumrt] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [cddocrq] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [vogahff] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [nkxtjyx] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [diikaeh] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [qcxmejf] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [eumchaq] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [ckvxlcc] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [coolyry] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [vrgiktv] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [kttnxwj] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [onvrqfo] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [adcbkve] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [cmtjkds] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [cbfncoi] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [rtbjtqn] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [yaytpam] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [xiclvpm] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [nogunyk] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [wohglow] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [wgtvfcf] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [fwlwfxp] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [yebvtyu] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [ivstjlq] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [kqehcfo] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [umauyay] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [giydaxp] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [qgdtxwh] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [xodghkm] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [rqiihwb] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [axbedky] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [ddkqiih] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [lllbbhs] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [vasocbr] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [jriwpax] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [kdbnlrp] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [mqiknul] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [eqvfxjf] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [aghrkwm] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [oylkuxw] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [eboqytr] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [kfcgavd] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [flnpang] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [bxlmlce] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [btfxost] c:\windows\rfbfekq.exe
    O4 - HKCU\..\Run: [wcmhaox] c:\windows\qxhghpi.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: Microsoft AntiSpyware helper - {2693DD19-48F5-47DF-838C-9CB1B4D262B7} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2693DD19-48F5-47DF-838C-9CB1B4D262B7} - (no file) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
    O21 - SSODL: Windows Explorer - {A502E265-837D-48F1-9826-16D82428A47A} - C:\WINDOWS\System32\koretcpl.dll
    O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\System32\ahtun.exe
    O23 - Service: nlgffxcavjyd (MsUpdate6) - Unknown owner - C:\WINDOWS\System32\msupd6.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\ahtun.exe
    C:\WINDOWS\System32\msupd6.exe
    C:\WINDOWS\System32\wiaadycc.exe
    c:\windows\rfbfekq.exe
    c:\windows\qxhghpi.exe
    C:\WINDOWS\System32\koretcpl.dll
    c:\windows\system32\flsmngr.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. nanouk77

    nanouk77 Private E-2

    Hi Chaslang

    status report so far:

    LSP fix completed, flsmngr.dll deleted

    debug outpost relations properties changed

    nlgffxcavjyd properties changed

    deleted lagos

    deleted MsUpdate6

    thats the story so far, will post again when asked.

    You are a life saver! Thanks.
     
  6. nanouk77

    nanouk77 Private E-2

    hi chaslang

    Followed the instructions on your previous thread to the letter.

    Heres where we stand:

    I can now run anti-virus/anti-spyware programs.

    But i cannot get norton to start.

    I cannot access hotmail/ebay, problems occur the page after the password page.

    I cannot do an update on any of my programs.

    I cannot get msn explorer or firefox to work, i can get i.e. to work.

    Thanks very much for your help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have some problems left over from the last procedure:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\wiaadycc.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [Access Browser] C:\WINDOWS\System32\wiaadycc.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O21 - SSODL: Windows Explorer - {A502E265-837D-48F1-9826-16D82428A47A} - C:\WINDOWS\System32\koretcpl.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\wiaadycc.exe
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Question:
    Do you really play all of these games? Are they that important that you want all these active x scripts on your PC an in your registry? They are not necessarily problems but I just don't like to see all of this. It's up to you what to do with them.
    O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.1.4.22/aces/aces-ob-assets.cab
    O16 - DPF: Ali Baba Slots TM by pogo - http://slots.pogo.com/applet-5.9.4.22/slots/alibaba-ob-assets.cab
    O16 - DPF: Armored Attack by pogo - http://game4.pogo.com/applet-6.0.4.37/cctank/cctank-ob-assets.cab
    O16 - DPF: Backgammon by pogo - http://gammon.pogo.com/applet-6.1.0.39/backgammon/backgammon-ob-assets.cab
    O16 - DPF: Big Shot Roulette TM by pogo - http://roulet.pogo.com/applet-6.0.0.25/roulette/roulette-ob-assets.cab
    O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.2.1.27/blackjack/blackjack-ob-assets.cab
    O16 - DPF: Buckaroo Blackjack TM by pogo - http://vbjack.pogo.com/applet-6.0.0.25/videoblackjack/videoblackjack-ob-assets.cab
    O16 - DPF: Bump by pogo - http://playweb11.pogo.com/applet-6.1.4.22/bump/bump-ob-assets.cab
    O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.2.0.30/canasta/canasta-ob-assets.cab
    O16 - DPF: Checkers by pogo - http://game3.pogo.com/applet-6.1.2.25/checkers2/checkers-ob-assets.cab
    O16 - DPF: Chess by pogo - http://game1.pogo.com/applet-6.1.5.21/chess2/chess2-ob-assets.cab
    O16 - DPF: Cribbage by pogo - http://crib.pogo.com/applet-5.9.4.30/cribbage/cribbage-ob-assets.cab
    O16 - DPF: Dice Derby by pogo - http://checkeredflag.pogo.com/applet-6.0.4.37/checkeredflag/checkeredflag-ob-assets.cab
    O16 - DPF: Dominoes by pogo - http://game5.pogo.com/applet-6.1.3.21/domino/domino-ob-assets.cab
    O16 - DPF: Euchre by pogo - http://euchre.pogo.com/applet-6.0.2.29/euchre/euchre-ob-assets.cab
    O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/applet-6.2.0.30/solitaire2/solitaire2-ob-assets.cab
    O16 - DPF: Fortune Bingo by pogo - http://superbingo.pogo.com/applet-5.9.5.30/superbingo/superbingo-ob-assets.cab
    O16 - DPF: Greenback Bayou by pogo - http://greenback.pogo.com/applet-5.9.5.30/greenback/greenback-ob-assets.cab
    O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.1.5.21/harvest/harvest-ob-assets.cab
    O16 - DPF: Hearts by pogo - http://hearts.pogo.com/applet-5.9.3.38/hearts/hearts-ob-assets.cab
    O16 - DPF: Heavy Cannon by pogo - http://playweb15.pogo.com/applet-6.0.2.21/heavycannon/heavycannon-ob-assets.cab
    O16 - DPF: High Stakes Poker by pogo - http://game5.pogo.com/applet-6.0.4.37/drawpoker/drawpoker-ob-assets.cab
    O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/applet-6.1.3.28/pool2/pool-ob-assets.cab
    O16 - DPF: Jigsaw Detective by pogo - http://game3.pogo.com/applet-6.0.4.37/jigsaw/jigsaw-ob-assets.cab
    O16 - DPF: Jokers Wild Poker by pogo - http://vpjoke.pogo.com/applet-5.9.3.29/videopoker2/jokerswild-ob-assets.cab
    O16 - DPF: Jungle Gin by pogo - http://game1.pogo.com/applet-6.2.1.27/gin/gin-ob-assets.cab
    O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.1.5.21/lottso/lottso-ob-assets.cab
    O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.1.4.29/mahjong/mahjong-ob-assets.cab
    O16 - DPF: Multiline Slots by pogo - http://game6.pogo.com/applet-6.1.1.21/mlslots/mlslots-ob-assets.cab
    O16 - DPF: Pai Gow by pogo - http://game3.pogo.com/applet-6.1.0.39/paigow/paigow-ob-assets.cab
    O16 - DPF: Payday FreeCell by pogo - http://game5.pogo.com/applet-6.1.3.21/freecell/freecell-ob-assets.cab
    O16 - DPF: Pebble Beach Golf by pogo - http://game4.pogo.com/applet-6.0.1.28/pebble/pebble-ob-assets.cab
    O16 - DPF: Perfect Pair Solitaire by pogo - http://waterwheel.pogo.com/applet-6.1.1.21/waterwheel/waterwheel-ob-assets.cab
    O16 - DPF: Phlinx by pogo - http://game1.pogo.com/applet-6.1.5.21/flinger/flinger-ob-assets.cab
    O16 - DPF: Pinochle by pogo - http://game4.pogo.com/applet-6.1.1.29/pinochle/pinochle-ob-assets.cab
    O16 - DPF: Pirate's Gold by pogo - http://swashbucks.pogo.com/applet-6.0.1.28/piratesgold/piratesgold-ob-assets.cab
    O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.1.4.22/popfu/popfu-ob-assets.cab
    O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.1.5.21/poppit2/poppit2-ob-assets.cab
    O16 - DPF: Poppit TM by pogo - http://game5.pogo.com/applet-6.1.1.29/poppit/poppit-ob-assets.cab
    O16 - DPF: Quick Shot by pogo - http://game4.pogo.com/applet-6.0.4.37/quickshot/quickshot-ob-assets.cab
    O16 - DPF: Showbiz Slots by pogo - http://game1.pogo.com/applet-6.2.0.37/slots/showbiz-ob-assets.cab
    O16 - DPF: Spades by pogo - http://spades.pogo.com/applet-5.9.5.30/spades/spades-ob-assets.cab
    O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.2.1.27/spider/spider-ob-assets.cab
    O16 - DPF: Squelchies by pogo - http://game1.pogo.com/applet-6.1.5.21/squelchies/squelchies-ob-assets.cab
    O16 - DPF: Sweet Tooth TM by pogo - http://sweettooth.pogo.com/applet-6.0.1.20/sweettooth/sweettooth-ob-assets.cab
    O16 - DPF: Tank Hunter by pogo - http://playweb08.pogo.com/applet-6.0.0.25/tank/tank-ob-assets.cab
    O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.2.0.30/holdem/holdem-ob-assets.cab
    O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.2.0.30/peaks/peaks-ob-assets.cab
    O16 - DPF: Tumble Bees by pogo - http://game1.pogo.com/applet-6.1.5.28/jumbee/jumbee-ob-assets.cab
    O16 - DPF: Turbo 21 TM by pogo - http://game5.pogo.com/applet-5.9.5.37/turbo21/turbo21-ob-assets.cab
    O16 - DPF: Vert Skater by pogo - http://game4.pogo.com/applet-6.0.1.28/vertskater/vertskater-ob-assets.cab
    O16 - DPF: Video Poker by pogo - http://vpoker.pogo.com/applet-6.0.3.35/videopoker2/videopoker-ob-assets.cab
    O16 - DPF: Word Whomp by pogo - http://game5.pogo.com/applet-6.0.4.37/wordwhomp/wordwhomp-ob-assets.cab
    O16 - DPF: Word Whomp Whackdown by pogo - http://whackdown.pogo.com/applet-6.0.2.21/whackdown/whackdown-ob-assets.cab
    O16 - DPF: WordJong by pogo - http://game1.pogo.com/applet-6.1.3.28/wordjong/wordjong-ob-assets.cab
    O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.2.0.30/worldclass/worldclass-ob-assets.cab
     
  8. nanouk77

    nanouk77 Private E-2

    Hi Chaslang

    i can confirm that i have system restore disabled and viewing of hidden files has been enabled.

    i ran hijackthis, "open misc tools section", "open process manager", but "C:\windows\system32\wiaadycc.exe" was not there.

    Neither was O4 - HKLM\..\Run: [Access Browser] C:\WINDOWS\System32\wiaadycc.exe when i ran scan.

    After reboot into safe mode the file C:\WINDOWS\System32\wiaadycc.exe
    wasnt there, but a file that ended in .ocx was there so i deleted that.

    I ran CCleaner and deleted all items in the prefetch folder.

    My Fiance plays all those games, and i wouldnt want to delete them without her permission!

    Please see attached HJT log.

    Thanks
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Your log is clean now. To help keep it that way you must follow the steps in the below link:

    How to Protect yourself from malware!

    All steps should be completed! You are in serious danger while running without an antivirus application and also without a firewall.
     
  10. nanouk77

    nanouk77 Private E-2

    hi chaslang

    thanks very much for all your help.

    could you tell me what i should do about the little problems that im having?

    for example: the antivirus software i cant run, unable to access certain websites etc

    these problems only occured since i had the spyware issues.

    oh, i cant download sp2 either, it says there are network issues?

    thanks
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please explain in more detail! What AV program can't you run? What websites can you not access? What is the exact error message trying to download SP2 and are you going to Microsoft to get it?
     
  12. nanouk77

    nanouk77 Private E-2

    hi chaslang

    Sorry for the delay in getting back to you.

    I cannot access norton internet security 2005 at all.
    I cannot run msn explorer, so im accessing the internet with ie6.
    I cannot access hotmail or ebay, when i enter my password, it then comes up with the standard error page.
    When i try to download sp2 i get the message:
    "Network policy settings prevent you from using Windows Update to download and install updates on your computer. If you believe you have received this message in error, please check with your system administrator."

    thanks
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you logged on with Administrator priviledges?

    Maybe you should check this link out: http://support.microsoft.com/kb/326686

    If that does not help, check out the info in the below quote box:
    Have you checked Local Security Settings --> Software Restrictions Policies --> Additional Rules to make sure there are no restrictions?

    Click Start, Run, and enter secpol.msc and click OK! Then look for the items I mentioned above.

    Can you download and install other applications on the PC?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds