This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

No internet access following redirect virus removal

I have a client computer that had a redirect virus. After multiple scans, I have it cleaned up. When I disable the Sophos Endpont, I am able to get to any website through any browser. When i re-enable Sophos, I get the error err_socket_not_connected in Chrome. In Sophos Central Admin, the machine shows as not having any outstanding alerts (everything has been cleared), and it has a green check. Does anyone know how to get websites to come back through?



This thread was automatically locked due to age.
Parents
  • Hi,

    I'm not sure how the virus performed the redirect and the platform (Win10, Win7, etc...) but I wonder if the redirect virus used a Layered Service Provider (LSP)?  

    Sophos also uses one on Windows 7 so it would be interesting to see the Winsock catalog entries.

    In an administrative command prompt can you run:

    netsh winsock show catalog > winsock.txt

    If you can make available winsock.txt that would be helpful.

    Regards,
    Jak

Reply
  • Hi,

    I'm not sure how the virus performed the redirect and the platform (Win10, Win7, etc...) but I wonder if the redirect virus used a Layered Service Provider (LSP)?  

    Sophos also uses one on Windows 7 so it would be interesting to see the Winsock catalog entries.

    In an administrative command prompt can you run:

    netsh winsock show catalog > winsock.txt

    If you can make available winsock.txt that would be helpful.

    Regards,
    Jak

Children
  • Thank you for the response. I think you may be on the right path here. This is the output from the Winsock catalog:

     


    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Layered Chain Entry
    Description: LavasoftLSP over [MSAFD Tcpip [TCP/IP]]
    Provider ID: {D7384C3A-5C67-466F-9FA3-A5BE0D8E38C7}
    Provider Path: C:\WINDOWS\system32\LavasoftTcpService64.dll
    Catalog Entry ID: 1019
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x66
    Protocol Chain Length: 2
    Protocol Chain: 1018 : 1006


    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Layered Chain Entry
    Description: LavasoftLSP over [MSAFD Tcpip [UDP/IP]]
    Provider ID: {4BF471EF-CE30-4C19-B133-E7BC6AFEA30F}
    Provider Path: C:\WINDOWS\system32\LavasoftTcpService64.dll
    Catalog Entry ID: 1020
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x609
    Protocol Chain Length: 2
    Protocol Chain: 1018 : 1007


    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Layered Chain Entry
    Description: LavasoftLSP over [MSAFD Tcpip [TCP/IPv6]]
    Provider ID: {DB2CA45C-D093-4755-A57D-809277689C3D}
    Provider Path: C:\WINDOWS\system32\LavasoftTcpService64.dll
    Catalog Entry ID: 1021
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x66
    Protocol Chain Length: 2
    Protocol Chain: 1018 : 1009


    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Layered Chain Entry
    Description: LavasoftLSP over [MSAFD Tcpip [UDP/IPv6]]
    Provider ID: {A6DC38D5-7E78-43B9-BD47-5571390C5610}
    Provider Path: C:\WINDOWS\system32\LavasoftTcpService64.dll
    Catalog Entry ID: 1022
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x609
    Protocol Chain Length: 2
    Protocol Chain: 1018 : 1010


    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: Hyper-V RAW
    Provider ID: {1234191B-4BF7-4CA7-86E0-DFD7C32B5445}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1001
    Version: 2
    Address Family: 34
    Max Address Length: 36
    Min Address Length: 36
    Socket Type: 1
    Protocol: 1
    Service Flags: 0x20026
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: MSAFD Tcpip [TCP/IP]
    Provider ID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1006
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x20066
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: MSAFD Tcpip [UDP/IP]
    Provider ID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1007
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x20609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: MSAFD Tcpip [RAW/IP]
    Provider ID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1008
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 3
    Protocol: 0
    Service Flags: 0x20609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: MSAFD Tcpip [TCP/IPv6]
    Provider ID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1009
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x20066
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: MSAFD Tcpip [UDP/IPv6]
    Provider ID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1010
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x20609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: MSAFD Tcpip [RAW/IPv6]
    Provider ID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1011
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 3
    Protocol: 0
    Service Flags: 0x20609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: RSVP TCPv6 Service Provider
    Provider ID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1002
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x22066
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: RSVP TCP Service Provider
    Provider ID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1003
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x22066
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: RSVP UDPv6 Service Provider
    Provider ID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1004
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x22609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: RSVP UDP Service Provider
    Provider ID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1005
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x22609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider
    Description: MSAFD Irda [IrDA]
    Provider ID: {3972523D-2AF1-11D1-B655-00805F3642CC}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1012
    Version: 2
    Address Family: 26
    Max Address Length: 32
    Min Address Length: 8
    Socket Type: 1
    Protocol: 1
    Service Flags: 0x20006
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Layered Service Provider
    Description: LavasoftLSP
    Provider ID: {2B611370-2190-4059-9AF8-5BC0F58FB742}
    Provider Path: C:\WINDOWS\system32\LavasoftTcpService64.dll
    Catalog Entry ID: 1018
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 0
    Protocol: 0
    Service Flags: 0x66
    Protocol Chain Length: 0

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Layered Chain Entry (32)
    Description: LavasoftLSP over [MSAFD Tcpip [TCP/IP]]
    Provider ID: {409EB6E9-5824-4C4D-B25B-7C6E470F5A0B}
    Provider Path: C:\WINDOWS\system32\LavasoftTcpService.dll
    Catalog Entry ID: 1014
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x66
    Protocol Chain Length: 2
    Protocol Chain: 1013 : 1006


    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Layered Chain Entry (32)
    Description: LavasoftLSP over [MSAFD Tcpip [UDP/IP]]
    Provider ID: {DF8DD135-F34F-4594-BCB3-746647ADA7C3}
    Provider Path: C:\WINDOWS\system32\LavasoftTcpService.dll
    Catalog Entry ID: 1015
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x609
    Protocol Chain Length: 2
    Protocol Chain: 1013 : 1007


    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Layered Chain Entry (32)
    Description: LavasoftLSP over [MSAFD Tcpip [TCP/IPv6]]
    Provider ID: {218D9085-D05B-4342-BCAA-452679988B82}
    Provider Path: C:\WINDOWS\system32\LavasoftTcpService.dll
    Catalog Entry ID: 1016
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x66
    Protocol Chain Length: 2
    Protocol Chain: 1013 : 1009


    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Layered Chain Entry (32)
    Description: LavasoftLSP over [MSAFD Tcpip [UDP/IPv6]]
    Provider ID: {F13EBAAA-58C9-4558-9591-3129EBEE2A14}
    Provider Path: C:\WINDOWS\system32\LavasoftTcpService.dll
    Catalog Entry ID: 1017
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x609
    Protocol Chain Length: 2
    Protocol Chain: 1013 : 1010


    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: Hyper-V RAW
    Provider ID: {1234191B-4BF7-4CA7-86E0-DFD7C32B5445}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1001
    Version: 2
    Address Family: 34
    Max Address Length: 36
    Min Address Length: 36
    Socket Type: 1
    Protocol: 1
    Service Flags: 0x20026
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: MSAFD Tcpip [TCP/IP]
    Provider ID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1006
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x20066
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: MSAFD Tcpip [UDP/IP]
    Provider ID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1007
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x20609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: MSAFD Tcpip [RAW/IP]
    Provider ID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1008
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 3
    Protocol: 0
    Service Flags: 0x20609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: MSAFD Tcpip [TCP/IPv6]
    Provider ID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1009
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x20066
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: MSAFD Tcpip [UDP/IPv6]
    Provider ID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1010
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x20609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: MSAFD Tcpip [RAW/IPv6]
    Provider ID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1011
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 3
    Protocol: 0
    Service Flags: 0x20609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: RSVP TCPv6 Service Provider
    Provider ID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1002
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x22066
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: RSVP TCP Service Provider
    Provider ID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1003
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 1
    Protocol: 6
    Service Flags: 0x22066
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: RSVP UDPv6 Service Provider
    Provider ID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1004
    Version: 2
    Address Family: 23
    Max Address Length: 28
    Min Address Length: 28
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x22609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: RSVP UDP Service Provider
    Provider ID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1005
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 2
    Protocol: 17
    Service Flags: 0x22609
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Base Service Provider (32)
    Description: MSAFD Irda [IrDA]
    Provider ID: {3972523D-2AF1-11D1-B655-00805F3642CC}
    Provider Path: %SystemRoot%\system32\mswsock.dll
    Catalog Entry ID: 1012
    Version: 2
    Address Family: 26
    Max Address Length: 32
    Min Address Length: 8
    Socket Type: 1
    Protocol: 1
    Service Flags: 0x20006
    Protocol Chain Length: 1

    Winsock Catalog Provider Entry
    ------------------------------------------------------
    Entry Type: Layered Service Provider (32)
    Description: LavasoftLSP
    Provider ID: {2B611370-2190-4059-9AF8-5BC0F58FB742}
    Provider Path: C:\WINDOWS\system32\LavasoftTcpService.dll
    Catalog Entry ID: 1013
    Version: 2
    Address Family: 2
    Max Address Length: 16
    Min Address Length: 16
    Socket Type: 0
    Protocol: 0
    Service Flags: 0x66
    Protocol Chain Length: 0

    Name Space Provider Entry
    ------------------------------------------------------
    Description: E-mail Naming Shim Provider
    Provider ID: {964ACBA2-B2BC-40EB-8C6A-A6DB40161CAE}
    Name Space: 37
    Active: 1
    Version: 0


    Name Space Provider Entry
    ------------------------------------------------------
    Description: PNRP Cloud Namespace Provider
    Provider ID: {03FE89CE-766D-4976-B9C1-BB9BC42C7B4D}
    Name Space: 39
    Active: 1
    Version: 0


    Name Space Provider Entry
    ------------------------------------------------------
    Description: PNRP Name Namespace Provider
    Provider ID: {03FE89CD-766D-4976-B9C1-BB9BC42C7B4D}
    Name Space: 38
    Active: 1
    Version: 0


    Name Space Provider Entry
    ------------------------------------------------------
    Description: Network Location Awareness Legacy (NLAv1) Namespace
    Provider ID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
    Name Space: 15
    Active: 1
    Version: 0


    Name Space Provider Entry
    ------------------------------------------------------
    Description: Tcpip
    Provider ID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
    Name Space: 12
    Active: 1
    Version: 0


    Name Space Provider Entry
    ------------------------------------------------------
    Description: NTDS
    Provider ID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
    Name Space: 32
    Active: 1
    Version: 0


    Name Space Provider Entry (32)
    ------------------------------------------------------
    Description: E-mail Naming Shim Provider
    Provider ID: {964ACBA2-B2BC-40EB-8C6A-A6DB40161CAE}
    Name Space: 37
    Active: 1
    Version: 0


    Name Space Provider Entry (32)
    ------------------------------------------------------
    Description: PNRP Cloud Namespace Provider
    Provider ID: {03FE89CE-766D-4976-B9C1-BB9BC42C7B4D}
    Name Space: 39
    Active: 1
    Version: 0


    Name Space Provider Entry (32)
    ------------------------------------------------------
    Description: PNRP Name Namespace Provider
    Provider ID: {03FE89CD-766D-4976-B9C1-BB9BC42C7B4D}
    Name Space: 38
    Active: 1
    Version: 0


    Name Space Provider Entry (32)
    ------------------------------------------------------
    Description: Network Location Awareness Legacy (NLAv1) Namespace
    Provider ID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
    Name Space: 15
    Active: 1
    Version: 0


    Name Space Provider Entry (32)
    ------------------------------------------------------
    Description: Tcpip
    Provider ID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
    Name Space: 12
    Active: 1
    Version: 0


    Name Space Provider Entry (32)
    ------------------------------------------------------
    Description: NTDS
    Provider ID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
    Name Space: 32
    Active: 1
    Version: 0

  • Hi,

    Would I be right in saying that LavasoftTcpService64.dll and LavasoftTcpService.dll was part of the redirecting malware?

    If the entries are in the Winsock catalog, but the file has been cleaned up then the types of errors you are getting make sense.

    I notice that beyond the LavasoftTcpService64 and LavasoftTcpService DLLs everything else is pretty standard.

    Now, if you have Windows 7 I'd expect to see Sophos entries in the catalog for Web Protection/Control if that is enabled. 
    If you are Windows 8.1 and later then Sophos does not use an LSP and this would be expected.

    To get rid of the above, in an administrative command prompt run:

    netsh winsock reset

    It will ask you to reboot.  Once rebooted, I would suggest run the previous command again:

    netsh winsock show catalog > cat2.txt

    This will prove that the LavasoftTcpService64.dll and LavasoftTcpService.dll entries have gone.

    If they are back, we would need to see what is re-registering them.

    Regards,

    Jak

  • Thank you Jak! It worked and he's now back up and running.