1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

window socket error

Discussion in 'Virus & Other Malware Removal' started by Zenith, Sep 15, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. Zenith

    Zenith Thread Starter

    Joined:
    Sep 15, 2003
    Messages:
    2
    Operating System Version:Windows 98

    I don't know what's happening, about every 20 seconds one of these two error messages pop up

    'Windows socket error: (11001), on API 'ASync Lookup''
    'Windows socket error: (10049), on API 'connect''

    could anyone help me fix this?
     
  2. Davey7549

    Davey7549

    Joined:
    Feb 28, 2001
    Messages:
    11,584
    Zenith
    Welcome to TSG!
    It is very possible you picked up a virus\trojan.
    Have a look at this thread and follow the instruction for the free online virus scan and fix all problem found, then follow the spybot instructions and fix all problems found and then finally follow the hijack this instructions then post the results back here without fixing any problems.
    http://forums.techguy.org/t157605/s.html

    Dave
     
  3. brindle

    brindle

    Joined:
    Jun 14, 2002
    Messages:
    3,520
    This is from computerseasy.com

    : Hello sockerers error!!
    : I have the same problem this week : "Windows socket error:(10049),API 'connect' and Windows socket error:(11001), API 'ASync Lookup' ", and it was just after i download a cracker file with kazaa !!!
    : Norton, antitrojan, the cleanner.... doesn't find anything, the solution was McAfee, it find a backdoor-rp, which is a trojan...
    : The file was "Shellapi32.exe" in c:\windows\system
    : I removed it in ms-dos with del c:\windows\system\shella~1.exe and i clean my registry with regcleanner and everything was ended !!!!!
    : No formating your hd!!!!!!
    : Good hunting....
     
  4. Zenith

    Zenith Thread Starter

    Joined:
    Sep 15, 2003
    Messages:
    2
    Logfile of HijackThis v1.97.2
    Scan saved at 8:50:38 PM, on 9/15/03
    Platform: Windows 98 Gold (Win9x 4.10.1998)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\PTSNOOP.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\MIXER.EXE
    C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
    C:\WINDOWS\SYSTEM\MPS.EXE
    D:\PROGRAM FILES\CANON\MULTIPASS4\MPDBMGR.EXE
    C:\WINDOWS\SYSTEM\INTERNAT.EXE
    C:\PROGRAM FILES\SYMPATICO\ACCESS MANAGER\APP\ENTERNET.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WINDOWS\EXPLORER.EXE
    D:\UNZIPED\HIJACKTHIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.sympatico.ca/iesearchpane.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico
    F1 - win.ini: load=ptsnoop.exe
    O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRAM FILES\FLASHGET\JCCATCH.DLL
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRAM FILES\FLASHGET\FGIEBAR.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [mps] C:\WINDOWS\SYSTEM\mps.exe /s
    O4 - HKLM\..\Run: [lehugbk] "C:\WINDOWS\SYSTEM\LEHUGBK.exe"
    O4 - HKLM\..\Run: [rcydmhd] "C:\WINDOWS\SYSTEM\RCYDMHD.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE" -atboottime
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKCU\..\Run: [AIM] D:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [WinXp] C:\WINDOWS\LOADSYS.EXE
    O8 - Extra context menu item: Download using FlashGet - D:\PROGRAM FILES\FLASHGET\jc_link.htm
    O8 - Extra context menu item: Download All by FlashGet - D:\PROGRAM FILES\FLASHGET\jc_all.htm
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: FlashGet (HKLM)
    O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
    O9 - Extra button: AIM (HKLM)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/25e8f3ec25b2c0892804/netzip/RdxIE601.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37864.3536458333
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} (InstallShield Setup Player 2K2) - http://securedshopper.com/simplyftp/oneclick/setup.exe
    O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://www.pcpowerscan.com/pcpowerscan.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/d052c1d7d32ead/housecall.antivirus.com/housecall/xscan53.cab

    don't know which to remove so could anyone tell me?
     
  5. Rollin' Rog

    Rollin' Rog

    Joined:
    Dec 9, 2000
    Messages:
    45,855
    First do a ctrl-alt-del and end task the process

    mps.exe

    Now run HijackThis and check and "fix" these entries:

    O4 - HKLM\..\Run: [mps] C:\WINDOWS\SYSTEM\mps.exe /s
    O4 - HKLM\..\Run: [lehugbk] "C:\WINDOWS\SYSTEM\LEHUGBK.exe"
    O4 - HKLM\..\Run: [rcydmhd] "C:\WINDOWS\SYSTEM\RCYDMHD.exe"

    O4 - HKCU\..\Run: [WinXp] C:\WINDOWS\LOADSYS.EXE

    Now open Explorer and navigate to c:\windows\system and delete the following files

    mps.exe
    lehugbk.exe
    rcydmhd.exe

    In C:\windows delete

    loadsys.exe

    If you get an "access denied" message when trying to delete any file, you must restart in Safe Mode and delete them from there.

    To restart in Safe Mode press the ctrl key promptly on rebooting and select Safe Mode from the boot menu.

    Post another Scanlog when you have finished.

    Please report exactly any stages at which you have problems
     
  6. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/165094

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice