Community Discussions and Support
socket read error 2746 after rootkit virus

DamianJanzen:

Either you were infected with a RootKit (trojan) or a virus.  There are no RootKit Viruses like there are no Volkswagon Chevrolets.

If NetBT.sys was affected (supports NetBIOS over TCP/IP) it could have been the TDSS RootKit (possibly the TD Level 4 or TDL4).  It may have been replaced with a wrong version and you could have other problems involved.

Changing the MTU should only be done when you are a circuit, such as DSL, where there is a tunneling effect that it reduces the Maximum Transmission Unit.  For example PPPoE uses 8 bytes so the MTU for DSL is 1492.

My suggestion is to read; I'm infected - What do I do now?  in the Malwarebytes' Forums. 

And then get one on one personal assistance from a trained Forum Helper by posting in;  Malware Removal Help

 

<p>DamianJanzen:</p><p>Either you were infected with a RootKit (trojan) or a virus.  There are no RootKit Viruses like there are no Volkswagon Chevrolets.</p><p>If NetBT.sys was affected (supports NetBIOS over TCP/IP) it could have been the TDSS RootKit (possibly the TD Level 4 or TDL4).  It may have been replaced with a wrong version and you could have other problems involved. </p><p>Changing the MTU should only be done when you are a circuit, such as DSL, where there is a tunneling effect that it reduces the Maximum Transmission Unit.  For example PPPoE uses 8 bytes so the MTU for DSL is 1492.</p><p>My suggestion is to read; <a href="http://forums.malwarebytes.org/index.php?showtopic=9573" mce_href="http://forums.malwarebytes.org/index.php?showtopic=9573" id="tid-link-9573" title="View topic, started 09 January 2009 - 07:11 AM" class="topic_title">I'm infected - What do I do now?</a>  in the Malwarebytes' Forums.  </p><p>And then get one on one personal assistance from a trained Forum Helper by posting in;  <a href="http://forums.malwarebytes.org/index.php?showforum=7" mce_href="http://forums.malwarebytes.org/index.php?showforum=7" title="Return to Malware Removal Help" itemprop="url"><span itemprop="title">Malware Removal Help</span></a> </p><p> </p>

I recently removed a rootkit virus from my machine (XP sp3) with Comodo which required replacing NetBT.sys. Everything seems to be working well now except sending mail with Pegasus. Anything more than a couple of words returns a socket read error 2746. I am not having any other internet errors or problems.

I have searched this error and have tried adjusting my MTU and Rwin settings and also tried the command line option -z 5120 with no change. If I log as the same pmail user on another machine on my network (mailboxes are on server) it sends without a problem. It's just from this computer.

Any ideas?

Below is the error in the Pmail pop up window.


>> 0042 220 smtp104.rog.mail.gq1.yahoo.com ESMTP

<< 0020 EHLO [192.168.x.x]

>> 0036 250-smtp104.rog.mail.gq1.yahoo.com

>> 0032 250-AUTH LOGIN PLAIN XYMCOOKIE

>> 0016 250-PIPELINING

>> 0019 250-SIZE 41697280

>> 0014 250 8BITMIME

<< 0012 AUTH LOGIN

>> 0018 334 VdgXNlcmgfgd5hd54bWUh6sf

<< 0034 YrXVkadfgW9wrGlsfgZWFwc0Byb2dlcnMugfdY29t

>> 0018 334 UGFzc3dvdfdg53cmQ6

<< 0014 cHVhy5445yZXBvdfghggfhdg2Vy

>> 0018 235 OK, go ahead

<< 0048 MAIL FROM:<damian@xxxxxxxxxxxx.com> SIZE=11292

>> 0020 250 OK , completed

<< 0036 RCPT TO:<justine@xxxxxx.xx.xxx>

>> 0020 250 OK , completed

<< 0006 DATA

>> 0036 354 Start Mail. End with CRLF.CRLF

7: Socket read error 2746.

&lt;p&gt;I recently removed a rootkit virus from my machine (XP sp3) with Comodo which required replacing NetBT.sys. Everything seems to be working well now except sending mail with Pegasus. Anything more than a couple of words returns a socket read error 2746. I am not having any other internet errors or problems. &lt;/p&gt;&lt;p&gt;I have searched this error and have tried adjusting my MTU and Rwin settings and also tried the command line option -z 5120 with no change. If I log as the same pmail user on another machine on my network (mailboxes are on server) it sends without a problem. It&#039;s just from this computer. Any ideas? &lt;/p&gt;&lt;p&gt; Below is the error in the Pmail pop up window.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;gt;&amp;gt; 0042 220 smtp104.rog.mail.gq1.yahoo.com ESMTP&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;lt;&amp;lt; 0020 EHLO [192.168.x.x]&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;gt;&amp;gt; 0036 250-smtp104.rog.mail.gq1.yahoo.com&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;gt;&amp;gt; 0032 250-AUTH LOGIN PLAIN XYMCOOKIE&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;gt;&amp;gt; 0016 250-PIPELINING&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;gt;&amp;gt; 0019 250-SIZE 41697280&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;gt;&amp;gt; 0014 250 8BITMIME&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;lt;&amp;lt; 0012 AUTH LOGIN&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;gt;&amp;gt; 0018 334 VdgXNlcmgfgd5hd54bWUh6sf&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;lt;&amp;lt; 0034 YrXVkadfgW9wrGlsfgZWFwc0Byb2dlcnMugfdY29t&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;gt;&amp;gt; 0018 334 UGFzc3dvdfdg53cmQ6&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;lt;&amp;lt; 0014 cHVhy5445yZXBvdfghggfhdg2Vy&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;gt;&amp;gt; 0018 235 OK, go ahead&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;lt;&amp;lt; 0048 MAIL FROM:&amp;lt;damian@xxxxxxxxxxxx.com&amp;gt; SIZE=11292&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;gt;&amp;gt; 0020 250 OK , completed&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;lt;&amp;lt; 0036 RCPT TO:&amp;lt;justine@xxxxxx.xx.xxx&amp;gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;gt;&amp;gt; 0020 250 OK , completed&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;lt;&amp;lt; 0006 DATA&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;gt;&amp;gt; 0036 354 Start Mail. End with CRLF.CRLF&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;7: Socket read error 2746.&lt;/span&gt;&lt;/p&gt;

Something else to add - when I try to send mail from Pegasus with this computer, it causes my router

to go crazy and reset. It's a linksys 2-line telephony router. I send mail, router resets and phone lines get dropped and reset.

&lt;p&gt;Something else to add - when I try to send mail from Pegasus with this computer, it causes my router&lt;/p&gt;&lt;p&gt; to go crazy and reset. It&#039;s a linksys 2-line telephony router. I send mail, router resets and phone lines get dropped and reset.&lt;/p&gt;

Well, this is getting aggravating. Every time I try to send mail, all the IP based phones in our office disconnect and people get mad at me. 

 Any ideas on the above issue? I was looking at various IP settings and host files, etc. looking for something obviously amiss but haven't found anything yet.

&lt;p&gt;Well, this is getting aggravating. Every time I try to send mail, all the IP based phones in our office disconnect and people get mad at me.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;Any ideas on the above issue?&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;nbsp;I was looking at various IP settings and host files, etc. looking for something obviously amiss but haven&#039;t found anything yet.&lt;/span&gt;&lt;/p&gt;

Make sure the option in menu Tools/Options/Advanced Settings has  Load Windows Internet Services button set to Always

HTH

Martin 

&lt;p&gt;Make sure the option in menu Tools/Options/Advanced Settings has &amp;nbsp;Load Windows Internet Services button set to Always&lt;/p&gt;&lt;p&gt;HTH&lt;/p&gt;&lt;p&gt;Martin&amp;nbsp;&lt;/p&gt;

Yes, It is indeed set to "always"

&lt;p&gt;Yes,&amp;nbsp;&lt;span style=&quot;font-size: 10pt;&quot;&gt;It is indeed set to &quot;always&quot;&lt;/span&gt;&lt;/p&gt;

Here's a link to previous posts regarding your issue found by simply searching for 2746. Maybe there's a solution that works for you as well.

Here&#039;s a link to &lt;a href=&quot;http://community.pmail.com/search/SearchResults.aspx?q=2746&amp;amp;s=10&quot; mce_href=&quot;http://community.pmail.com/search/SearchResults.aspx?q=2746&amp;amp;s=10&quot; target=&quot;_blank&quot;&gt;previous posts regarding your issue&lt;/a&gt; found by simply searching for 2746. Maybe there&#039;s a solution that works for you as well.
			Michael
--
IERenderer's Homepage
PGP Key ID (RSA 2048): 0xC45D831B
S/MIME Fingerprint: 94C6B471 0C623088 A5B27701 742B8666 3B7E657C

I have exhausted all of the avenues in any previous postings about this issue. I reduce the MTU, turned off discovery, tried the command line switches, I disabled offload processing in the net card options, I ran a winsock fix from Microsoft, I have read all of the search result returned threads.

 No luck.

Still stuck with the problem that sending any email with any size over a few bytes causes our router to reset and disconnect all of the IP hosted telephony lines. 

&lt;p&gt;I have exhausted all of the avenues in any previous postings about this issue. I reduce the MTU, turned off discovery, tried the command line switches, I disabled offload processing in the net card options, I ran a winsock fix from Microsoft, I have read all of the search result returned threads.&lt;/p&gt;&lt;p&gt;&amp;nbsp;No luck.&lt;/p&gt;&lt;p&gt;Still stuck with the problem that sending any email with any size over a few bytes causes our router to reset and disconnect all of the IP hosted telephony lines.&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft