Home / Other / Reviews and recommendations / Fix Corrupted Winsock Settings
0 Members and 2 Guests are viewing this topic. « previous next »
Pages: 1 2 [All] - (Bottom) Print
Author Topic: Fix Corrupted Winsock Settings  (Read 3105 times)
bobgar34
Topic Starter
Intermediate



Thanked: 3
Posts: 198

Experience: Experienced
OS: Windows XP

« on: October 03, 2009, 02:03:03 AM »

malicious software attacks that tamper with network settings and Winsock.  These corrupt Winsock settings can therefore lead to all kinds of networking troubles which are difficult  to analyze and understand for the inexperienced user.Winsock Repair is a free portable and  can fix most Winsock errors with the single push of a button so it makes more comfortable for you  fix the errors manually. Winsock Repair is a portable software program for the Windows operating system that has two primary functions. The first is to reset the TCP/IP stack which will rewrite important Windows Registry keys with their default values. The second will try to repair Winsock so that the network connectivity issues are a thing of the past. It does provide an option to list the installed LSPs (Layered Service Providers) which can be important as pre-installed LSPs might need to be reinstalled after fixing the Winsock errors. 




[attachment deleted by admin]
« Last Edit: October 04, 2009, 03:44:36 PM by patio » IP logged
kpac
Web moderator
Hacker



Thanked: 180
Posts: 5,874

Certifications: List
Computer: Specs
Experience: Expert
OS: Windows 7
kpac®

1 1 1
« Reply #1 on: October 04, 2009, 02:07:00 PM »

Better off with someone who can read a HJT log.
IP logged

Karnac
Mentor



Thanked: 211
Posts: 1,987


« Reply #2 on: October 04, 2009, 03:24:54 PM »

Just an aside here....this softwares installer triggered my antispyware, which blocked PSVRR.exe....you may want to run a scan if you've tried the program.....the download website is green WOT but......
« Last Edit: October 04, 2009, 03:50:00 PM by Karnac » IP logged



Never argue with a stupid person, they'll drag you down to their level and beat you with experience.
patio
Moderator
Genius



Thanked: 1069
Posts: 11,354

Experience: Beginner
OS: Windows 7


Maud' Dib

« Reply #3 on: October 04, 2009, 03:43:10 PM »

From Prevx:

Quote
PSVRR.EXE has been seen to perform the following behavior:

    * The Process is packed and/or encrypted using a software packing process
    * Checks for the use of debuggers
    * Creates a new Background Service on the machine
    * Reads email address and phone book details
    * Visits web sites on your PC without you knowing
    * Uses DNS to retrieve the IP address for web sites
    * Found on infected systems and resists interrogation by security products
    * Looks at the contents of the autoexec.bat file

PSVRR.EXE has been the subject of the following behavior:

    * Added as a Registry auto start to load Program on Boot up
    * Executed as a Process
    * Copied to multiple locations on the system
    * Created by processes which appear to be checking for interception by security products
    * Downloaded from covert web sites without the user knowing
    * This program is often downloaded from the web

Based on this info the link is being removed temporarily until further review...
patio.
IP logged

   
"
All generalizations are false, including this one.  "
Helpmeh
Egghead



Thanked: 117
Posts: 3,608

Experience: Experienced
OS: Windows XP


Roar.

1
« Reply #4 on: October 04, 2009, 07:10:50 PM »

Also from Prevx:
Quote
File Activity
One or more files with the name PSVRR.EXE creates, deletes, copies or moves the following files and folders:

Creates c:\docume~1\user\locals~1\temp\aut7.tmp
Creates c:\documents and settings\user\application data\psvr32.exe
Deletes c:\docume~1\user\locals~1\temp\aut7.tmp
Creates c:\documents and settings\user\application data\_pconfig.cfg
Website Activity
One or more files with the name PSVRR.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.

www .ophyemaweito .com / 0 / proxy .cfg
Port 80 IP:124.217.253.230
IP logged

Where's MagicSpeed?
Quote from: 'matt'
He's playing a game called IRL. Great graphics, *censored* gameplay.
bobgar34
Topic Starter
Intermediate



Thanked: 3
Posts: 198

Experience: Experienced
OS: Windows XP

« Reply #5 on: October 05, 2009, 03:05:45 AM »

i ran it through  sanboxie and saw nothing of the sort as far as PSVRR.EXE .  it has no installer it is portable!and before i post any thing i check it out myself and also visit virus total.  http://www.virustotal.com/analisis/51d4ff61d83d4249396f490bdb3d3f001038a56563b1cee6263deb2f86ffa9fb-1252338442    fully portable, meaning that it requires no installation and can be run directly from a USB flash disk. It also writes absolutely no settings to the Registry or the user’s folder. here is the authors email if you want to complain. rizonetech@gmail.com.

[attachment deleted by admin]
« Last Edit: October 05, 2009, 03:26:26 AM by bobgar34 » IP logged
Helpmeh
Egghead



Thanked: 117
Posts: 3,608

Experience: Experienced
OS: Windows XP


Roar.

1
« Reply #6 on: October 05, 2009, 08:32:05 AM »

i ran it through  sanboxie and saw nothing of the sort as far as PSVRR.EXE .  it has no installer it is portable!and before i post any thing i check it out myself and also visit virus total.  http://www.virustotal.com/analisis/51d4ff61d83d4249396f490bdb3d3f001038a56563b1cee6263deb2f86ffa9fb-1252338442    fully portable, meaning that it requires no installation and can be run directly from a USB flash disk. It also writes absolutely no settings to the Registry or the user’s folder. here is the authors email if you want to complain. rizonetech@gmail.com.
Quote
ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
IP logged

Where's MagicSpeed?
Quote from: 'matt'
He's playing a game called IRL. Great graphics, *censored* gameplay.
bobgar34
Topic Starter
Intermediate



Thanked: 3
Posts: 198

Experience: Experienced
OS: Windows XP

« Reply #7 on: October 05, 2009, 09:51:31 AM »

Just an aside here....this softwares installer triggered my antispyware, which blocked PSVRR.exe....you may want to run a scan if you've tried the program.....the download website is green WOT but......  it has no *censored* installer.
IP logged
Karnac
Mentor



Thanked: 211
Posts: 1,987


« Reply #8 on: October 05, 2009, 11:27:52 AM »

Bob , don't get all po'd...All I stated was that the program triggered my AV when I tried to save it....Whether it had an installer or not there was something in the file that caused PSVRR.exe to be blocked....My intention was to alert others of the possibility they may download something malicious to their computers......I certainly wasn't slagging your choice of programs, just giving others who may download it a heads up.

* Found on infected systems and resists interrogation by security products

Someone could download this and not even know they had it, it could be the wrapper, who knows, so why not play it safe.
« Last Edit: October 05, 2009, 04:59:55 PM by Karnac » IP logged



Never argue with a stupid person, they'll drag you down to their level and beat you with experience.
BC_Programmer
Mastermind


Thanked: 697
Posts: 15,881

Computer: Specs
Experience: Beginner
OS: Windows 7


Pinkie Pie is best pony

BC-Programming.com 1 1
« Reply #9 on: October 05, 2009, 01:11:52 PM »

In order to determine exactly what was happening, I decided to run a ProcMon trace while I ran and closed the program in question.

The resulting log was huge... most of it was basic registry reads that windows itself does to determine the various possible settings, appinit dlls, etc.

However, none of it was "bad" or something it wouldn't be accessing- most of the keys and files the program accessed were, not surprisingly, related to winsock.

However, this is the caveat! The Antispyware program karnac is using may be hard-coded to flag certain programs that access these keys as "spyware".

In fact this is a well known "caveat" of many anti-spyware programs. An example is the following article, which discusses a similar issue with one of the authors programs, and outlines exactly how easy it is to "sneak under the velvet rope" as he describes it. http://visualstudiomagazine.com/articles/2008/01/29/are-you-safer-now.aspx

I think that the reason it triggered the anti-spyware program was merely because it "hinted" at having references to certain registry keys- much as the author of the aforementioned article encountered with mcaffee.
IP logged

My Blog

BASeBlock 2.3.0 (NOW WITH MACGUFFINS!)
bobgar34
Topic Starter
Intermediate



Thanked: 3
Posts: 198

Experience: Experienced
OS: Windows XP

« Reply #10 on: October 05, 2009, 03:44:26 PM »

thanks ,and i will most certainly further investigate stuff before i post a review. i have learned a lot from this forum and have respect for all of you, and would never post something bad knowingly.
IP logged
patio
Moderator
Genius



Thanked: 1069
Posts: 11,354

Experience: Beginner
OS: Windows 7


Maud' Dib

« Reply #11 on: October 05, 2009, 04:16:21 PM »

bobgar i'll step in here for a bit...
It probably seems you feel bashed and/or being held under a microscope for your recent recommendations...i hope that's not the case.
But as a public Forum that doles out advice to many users we tend to err on the side of caution. It's part of what we do and should not be interpreted as being against your recommendations...

By all means continue to recommend apps that you find useful and should in fact be recommended...

patio.
IP logged

   
"
All generalizations are false, including this one.  "
evilfantasy
Malware Removal Specialist
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #12 on: October 05, 2009, 04:47:26 PM »

Keep em coming bobgar34. :D

I think it's safe to say all of us have had at least one link removed from an internet forum. I know I've had my hand slapped a time or two. (|
IP logged

Bighonk1
Greenhorn



Posts: 9


« Reply #13 on: October 06, 2009, 05:32:40 PM »

Since it has been considered safe ?It has been deemed safe right? can the link be posted again?
IP logged
patio
Moderator
Genius



Thanked: 1069
Posts: 11,354

Experience: Beginner
OS: Windows 7


Maud' Dib

« Reply #14 on: October 06, 2009, 05:49:27 PM »

I've been busy and have not finished testing as of yet.
IP logged

   
"
All generalizations are false, including this one.  "
Helpmeh
Egghead



Thanked: 117
Posts: 3,608

Experience: Experienced
OS: Windows XP


Roar.

1
« Reply #15 on: October 06, 2009, 06:02:20 PM »

How many times has a link been re-instated in someone's post?
IP logged

Where's MagicSpeed?
Quote from: 'matt'
He's playing a game called IRL. Great graphics, *censored* gameplay.
patio
Moderator
Genius



Thanked: 1069
Posts: 11,354

Experience: Beginner
OS: Windows 7


Maud' Dib

« Reply #16 on: October 06, 2009, 07:32:41 PM »

Many.
IP logged

   
"
All generalizations are false, including this one.  "
Helpmeh
Egghead



Thanked: 117
Posts: 3,608

Experience: Experienced
OS: Windows XP


Roar.

1
« Reply #17 on: October 06, 2009, 07:42:01 PM »

Many.
so you guys keep a record of which links are removed from certain threads?
IP logged

Where's MagicSpeed?
Quote from: 'matt'
He's playing a game called IRL. Great graphics, *censored* gameplay.
bobgar34
Topic Starter
Intermediate



Thanked: 3
Posts: 198

Experience: Experienced
OS: Windows XP

« Reply #18 on: October 07, 2009, 12:20:06 AM »

i just want to say thanks for the support everyone, i was really  down and out thinking i  screwed up. and the developer of that tool had some other cool utilities so i am going to take something i learned from B.C`s reply that procmon trace and regmon to evaluate things as i find them. as bad as i felt this turned out pretty good.:)
IP logged
patio
Moderator
Genius



Thanked: 1069
Posts: 11,354

Experience: Beginner
OS: Windows 7


Maud' Dib

« Reply #19 on: October 07, 2009, 08:34:09 AM »

No reason to feel bad bobgar...

IP logged

   
"
All generalizations are false, including this one.  "
bobgar34
Topic Starter
Intermediate



Thanked: 3
Posts: 198

Experience: Experienced
OS: Windows XP

« Reply #20 on: October 10, 2009, 06:10:06 PM »

ghacks has an article about the developer of this tool, he has released a new program called Rizone`s power tools, it looks like it could be a good one with more features coming soon.   the ghacks article: http://www.ghacks.net/2009/10/10/rizone%E2%80%99s-power-tools/       and the new program plus his many others can be found here:  http://www.rizonetech.com/?p=474     
IP logged
Pages: 1 2 [All] - (Top) Print 
Home / Other / Reviews and recommendations / Fix Corrupted Winsock Settings « previous next »
 


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright © 2010 Computer Hope ® All rights reserved.
Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC
Page created in 0.148 seconds with 19 queries.