Re: blown up TCP/IP/SID entries

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Kent W. England [MVP] (kwe_at_mvps.org)
Date: 05/14/04


Date: Thu, 13 May 2004 17:10:01 -0700

Gary wrote:
> Does anyone know the KB article or a weblink to the TCP/IP/SID issues
> with AD and XP pro? I have the fix, which is to edit the
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock and
> .....WinSock2 keys, but would like to learn more about the issue. I
> understand that this is a "not very publicized", but recognized issue
> by MSFT.

Are you talking about the LSP service stack at
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters
\Protocol_Catalog9\Catalog_Entries?

If so, this stack is usually broken by spyware and is fixed by LSPfix
from cexx.org. Read
http://www.spyany.com/program/article_spy_rm_SAHAgent.html manual
removal instructions for how the Layered Services are linked in this
registry key.

If the chain is not broken, but includes spyware, you have to know what
.dlls are involved in the spyware before you can hope to remove it. Some
anti-spyware can remove spyware that is embedded in the layered
services, but LSPfix is the easiest way to repair a damaged stack or
remove components from a working stack. These issues are usually
discussed in the virus or security groups.

-- 
Kent W. England, Microsoft MVP for Windows Security


Relevant Pages

  • Re: How to inhibit My Documents from opening upon boot
    ... and, most importantly, no spyware. ... "Dennis" wrote in message ... >> Please post these registry keys, as this problem is almost certainly ... >> Associate Expert - WindowsXP Expert Zone ...
    (microsoft.public.windowsxp.general)
  • Re: LAN conn status shows Automatic Private Address
    ... you probably have a damaged winsock2 key in the registry. ... It may be a third-party firewall or a Spyware or a Virus. ... Step 1: Delete registry keys ...
    (microsoft.public.windowsxp.network_web)
  • Re: Setupapi.log and keyboard problems
    ... Is it possible that those keys just stopped working, ... | the change in the above log indicative of spyware or a virus. ... | Avast and a bunch of Spyware Programs in addition to crap cleaner. ... | to use the number keys on the old keyboard. ...
    (microsoft.public.win2000.general)
  • Re: wga notification on legitimate installs
    ... For the M$ attitude to what IMHO is spyware see these forums: ... variant with the early keys that where leaked, and the more recent keys that ... It seems Microsoft are going much further then picking off the VLK installs ... Reading some of the forums, it seems people are getting new machines, direct ...
    (uk.comp.homebuilt)
  • Re: LAN conn status shows Automatic Private Address
    ... It may be a third-party firewall or a Spyware or a Virus. ... for replacing the winsock and winsock2 registry keys: ... Step 1: Delete registry keys ... It is important to restart the computer after deleting the Winsock keys. ...
    (microsoft.public.windowsxp.network_web)