" TCP\IP network transport is not installed" after UPS trojan fix

Discussion in 'Malware Help (A Specialist Will Reply)' started by RTD, Nov 9, 2008.

  1. RTD

    RTD Private E-2

    Hello,
    On 11/5 we opened the UPS trojan zip days after sending a package - duh..:confused

    Not long after opening the zip the pc( XP sp 2 ) rebooted and wouldn't boot to the log in screen. After searching the net on a different pc, I discovered our new "package".
    Before finding this site I downloaded Trojan Remover and Malware Bytes. Loaded them in safe mode and ran them. The TR found and repaired many issues as did the MB. I was then able to boot normally with the exception of the error " TCP/IP network transport is not installed" coming up as windows starts. Tried the "WINSOCK" repair utility with no change.

    Removed the winsock and winsock2 keys from the reg and restarted pc, no change.

    Found your site and performed the Readme steps which found more junk ( see logs) but has not corected tcpip issue.. Can you help?

    Thank you

    J
     

    Attached Files:

  2. RTD

    RTD Private E-2

    Rest of logs...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  4. RTD

    RTD Private E-2

    In looking at the msinfo32 - there are supposed to be 10 entries, i had 3 additional. Ran through the procedures, issue still exists and now in msinfo32 there aree only 4 entries:
    MSAFD TCPIP
    MSAFD UDPIP
    RSVP UDP
    RSVP TCP
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You deleted the two reg keys for winsock and winsock2? Restarted and finished the procedures by reinstalling the TCP/IP ?
     
  6. RTD

    RTD Private E-2

    Yep, I did it a second time when the first didn't work just make sure. It's still not a happy camper..
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me exactly what you did, step by step.
     
  8. RTD

    RTD Private E-2

    Went to Run - msinfo32, expanded componenents/network/protocol and compared my list to the list on the link you gave me. My list had more entries.

    I then performed the winsock reset with the netsh winsock reset command in the command line. Restarted the pc, same error occured at start up " tct\ipnetwork transport is not installed.

    I then went to the corrupted reg keys instructions - went into regedit and deleted: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Winsock
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Winsock2 . restarted the pc - same error occurred.

    Installed the tcp\ip by going to properties of the network connection, install, protocol and then add, chose have disk and entered c:\windows\inf - chose internet protocol tcpip and hit ok, restarted the pc and the error occurred again. Ran through procedure again with the same results.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the log from running MGTools.exe. It will be here --> C:\MGLogs.zip
     
  10. RTD

    RTD Private E-2

    Here you go...

    Thanks again for your time on this...

    J
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Two things to consider ( as I am not seeing any malware):

    You have registry mechanic installed....I don't know how many times you may have run this, but you might consider restoring what it removed.

    Have you tried doing a system restore to a time prior to these issues?
     
  12. RTD

    RTD Private E-2

    I'll try undoing the reg mech and if that doesn't work then I'll look for a restore point before the 5th and let you know.
     
  13. RTD

    RTD Private E-2

    Resteored the changes made in reg mech from the first scan which didn't correct the issue.

    tried restore points from the 3rd and the 4th in windows and in safe mode which netted the same result of getting the message " your computer cannot be restored to (date ) system checkpoint. No changes have been made to your computer..
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest that you post in the software section as I do not think this is a malware issue. It is more likely a corrupt registry issue.

    You could try these procedures but I have no idea as to whether it will help your situation:
    Here is the link to the MS article How to recover from a corrupt registry.
     
  15. RTD

    RTD Private E-2

    I'll do that..

    Thank you so much for your time on this, it is really appreciated.

    J
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome...good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds