View Single Post

  #2  
Old 05-06-2008, 06:58 PM
Disk_Contented's Avatar
Disk_Contented Offline
Temporary Ban
 
Join Date: Sep 2002
Location: In a plasma conduit
Posts: 1,625
Worst first..

O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
Quote:
Originally Posted by BleepingComputer.com
This program is required to run on startup in order to benefit from its functionality or so that the program will work.

A somewhat cryptic answer?

Quote:
Originally Posted by BleepingComputer.com
This program uses the Winlogon Notify key to automatically start. This key is used to run certain programs when specific actions occur such as computer starting up, a user logging in or logging off, or a computer shutting down.
Hmmm what programs. Good or bad?

Apparently,nwprovau is a component of "Client Service for NetWare". It certainly looks like the problem. You have this installed?

Next, a bit of adware?
Quote:
O8 - Extra context menu item: &Search -http://kl.bar.need2find.com/KL/menusearch.html?p=KL
Program that delivers advertisements on your PC.

Quote:
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
Personally, i wouldn't entertain this even from HP.

I remove this:
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Not needed IMHO

C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
What's a volume watcher?

O4 - HKCU\..\Run: [Shell] "C:\WINNT\system32\Rundll32.exe" "C:\WINNT\system32\shell32.dll",Control_RunDLL "C:\DOCUME~1\User\LOCALS~1\Temp\dat33.tmp"
Running a temp file at boot... I would delete it and see if it gets replaced. Could be anything.

Your main prob looks to be the winsock thing. Something malware is known to use.
If all else fails. there's the winsock fixer: http://majorgeeks.com/download4372.html

Keep us informed of results.
__________________
Where there's a will, There's a way.
Pay developers, not Rapidshare!
I know nowt, but at least I'm trying.
Quality, not quantity.
Prevention is better than cure.
Reply With Quote