Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Computer Running Slowly after Virus Removal


  • This topic is locked This topic is locked
17 replies to this topic

#1 mlions

mlions

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:10:23 AM

Posted 14 December 2011 - 03:19 PM

Hello - About a week ago I was infected with a nasty virus that completely shut down my computer. After doing some research and following directions I found here on Bleepingcomputer.com (one of the greatest websites I must say) I was able to remove the virus. However, after removal, I was unable to connect to to the Internet via wireless. My icon in the lower right corner just continued to say "Acquiring Network Address." I tried everything and, many days of working on it, I was able to get my Wireless Internet back.

However, I noticed that my computer is running somewhat slow and that in order for me to get my Internet to connect, I must do Start > Run > services.msc. Then from there I must click on DHCP Client and click "Start." Once I do this, my Internet comes back on and I am able to use the web. However, after ever restart I make, I have to go through this same process. I am curious if I am still infected or if something got messed up during the removal.

Thank you in advance for any help you may be able to offer!!!

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,199 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:23 AM

Posted 14 December 2011 - 04:20 PM

Hello, lets do these and see how it is after.
For the connection try these...

Please click Start > Run, type inetcpl.cpl in the runbox and press enter.
Click the Connections tab and click the LAN settings option.
Verify if "Use a proxy..." is checked, if so, UNcheck it and click OK/OK to exit.
Now check if the internet is working again.

OR

Go to Start ... Run and type in cmd
A dos Window will appear.
Type in the dos window: netsh winsock reset
Click on the enter key.

Reboot your system to complete the process.


<<><><><><<><><><><>
Please download MiniToolBox, save it to your desktop and run it.

Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.


<><><><><><>

You may still have infcections so lets run these.


Next run MBAM (MalwareBytes):

Please download Malwarebytes Anti-Malware and save it to your desktop.
Download Link 1
Download Link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
    For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

Troubleshoot Malwarebytes' Anti-Malware



I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and check Remove found threats
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image


NOTE: In some instances if no malware is found there will be no log produced.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 mlions

mlions
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:10:23 AM

Posted 15 December 2011 - 08:36 PM

Thank you Boopme for getting back to me. I apologize for the delay in my response, but it took me a little while to get everything running. Here is what I have:

"Use Proxy..." - was not checked.

Tried the Winsock Reset, rebooted my computer and still had to go to manually start my Internet.

MiniTool Box log:

MiniToolBox by Farbar
Ran by administrator) on 15-12-2011 at 14:40:08
Microsoft Windows XP Professional Service Pack 3 (X86)

***************************************************************************

========================= Flush DNS: ===================================


Windows IP Configuration



Successfully flushed the DNS Resolver Cache.


========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================

127.0.0.1 localhost

========================= IP Configuration: ================================

Marvell Yukon 88E8036 PCI-E Fast Ethernet Controller = Local Area Connection (Disconnected)
1394 Net Adapter = 1394 Connection (Disconnected)
Intel® PRO/Wireless 3945ABG Network Connection = Wireless Network Connection (Connected)


# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip


# Interface IP Configuration for "Wireless Network Connection"

set address name="Wireless Network Connection" source=dhcp
set dns name="Wireless Network Connection" source=dhcp register=PRIMARY
set wins name="Wireless Network Connection" source=dhcp


popd
# End of interface IP configuration




Windows IP Configuration



Host Name . . . . . . . . . . . . : Laptop

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Unknown

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No



Ethernet adapter Wireless Network Connection:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Intel® PRO/Wireless 3945ABG Network Connection

Physical Address. . . . . . . . . : 00-18-DE-63-0D-44

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 192.168.1.105

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 192.168.1.1

DHCP Server . . . . . . . . . . . : 192.168.1.1

DNS Servers . . . . . . . . . . . : 192.168.2.1

NetBIOS over Tcpip. . . . . . . . : Disabled

Lease Obtained. . . . . . . . . . : Thursday, December 15, 2011 10:46:22

Lease Expires . . . . . . . . . . : Friday, December 16, 2011 10:46:22

Server: UnKnown
Address: 192.168.2.1

Name: google.com
Addresses: 173.194.37.20, 173.194.37.16, 173.194.37.17, 173.194.37.18
173.194.37.19



Pinging google.com [173.194.37.17] with 32 bytes of data:



Reply from 173.194.37.17: bytes=32 time=44ms TTL=54

Reply from 173.194.37.17: bytes=32 time=44ms TTL=54



Ping statistics for 173.194.37.17:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 44ms, Maximum = 44ms, Average = 44ms

Server: UnKnown
Address: 192.168.2.1

Name: yahoo.com
Addresses: 98.137.149.56, 98.139.180.149, 209.191.122.70, 72.30.2.43



Pinging yahoo.com [98.139.180.149] with 32 bytes of data:



Reply from 98.139.180.149: bytes=32 time=108ms TTL=46

Reply from 98.139.180.149: bytes=32 time=227ms TTL=46



Ping statistics for 98.139.180.149:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 108ms, Maximum = 227ms, Average = 167ms

Server: UnKnown
Address: 192.168.2.1

Name: bleepingcomputer.com
Address: 208.43.87.2



Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:



Reply from 208.43.87.2: Destination host unreachable.

Reply from 208.43.87.2: Destination host unreachable.



Ping statistics for 208.43.87.2:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms



Pinging 127.0.0.1 with 32 bytes of data:



Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x10003 ...00 18 de 63 0d 44 ...... Intel® PRO/Wireless 3945ABG Network Connection
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.105 25
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
169.254.0.0 255.255.0.0 192.168.1.105 192.168.1.105 20
192.168.1.0 255.255.255.0 192.168.1.105 192.168.1.105 25
192.168.1.105 255.255.255.255 127.0.0.1 127.0.0.1 25
192.168.1.255 255.255.255.255 192.168.1.105 192.168.1.105 25
224.0.0.0 240.0.0.0 192.168.1.105 192.168.1.105 25
255.255.255.255 255.255.255.255 192.168.1.105 192.168.1.105 1
Default Gateway: 192.168.1.1
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 16 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 17 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (12/15/2011 10:38:11 AM) (Source: PerfNet) (User: )
Description: Unable to open the Server service. Server performance data
will not be returned. Error code returned is in data DWORD 0.

Error: (12/14/2011 07:33:47 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9406

Error: (12/14/2011 07:33:47 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9406

Error: (12/14/2011 07:33:47 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (12/14/2011 07:33:45 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7453

Error: (12/14/2011 07:33:45 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7453

Error: (12/14/2011 07:33:45 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (12/14/2011 07:33:43 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5500

Error: (12/14/2011 07:33:43 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5500

Error: (12/14/2011 07:33:43 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


System errors:
=============
Error: (12/15/2011 10:41:28 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
AFD

Error: (12/15/2011 10:41:03 AM) (Source: Service Control Manager) (User: )
Description: The Apple Mobile Device service failed to start due to the following error:
%%1053

Error: (12/15/2011 10:41:03 AM) (Source: Service Control Manager) (User: )
Description: Timeout (30000 milliseconds) waiting for the Apple Mobile Device service to connect.

Error: (12/15/2011 10:41:03 AM) (Source: Service Control Manager) (User: )
Description: The Symantec Network Proxy service terminated with service-specific error 4294967295 (0xFFFFFFFF).

Error: (12/15/2011 10:41:03 AM) (Source: Service Control Manager) (User: )
Description: The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:
%%31

Error: (12/15/2011 10:41:03 AM) (Source: Service Control Manager) (User: )
Description: The DHCP Client service depends on the AFD service which failed to start because of the following error:
%%31

Error: (12/15/2011 10:41:03 AM) (Source: Service Control Manager) (User: )
Description: The Intel® PROSet/Wireless Service service depends on the following nonexistent service: s24trans

Error: (12/14/2011 10:43:13 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
AFD

Error: (12/14/2011 10:42:56 AM) (Source: Service Control Manager) (User: )
Description: The Symantec Network Proxy service terminated with service-specific error 4294967295 (0xFFFFFFFF).

Error: (12/14/2011 10:42:56 AM) (Source: Service Control Manager) (User: )
Description: The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:
%%31


Microsoft Office Sessions:
=========================

=========================== Installed Programs ============================

Adobe Flash Player 10 ActiveX (Version: 10.2.153.1)
Adobe Reader 7.0.7 (Version: 7.0.7)
AIM 6
Apple Application Support (Version: 2.1.5)
Apple Mobile Device Support (Version: 4.0.0.97)
Apple Software Update (Version: 2.1.3.127)
Audacity 1.2.6
Aura Video Converter 1.3.1
AutoUpdate (Version: 1.1)
Avira AntiVir Personal - Free Antivirus (Version: 10.2.0.704)
BlackBerry Desktop Software 4.2.2 (Version: 4.2.2.14)
BlackBerry Device Software Updater (Version: 4.7.0.48)
Bonjour (Version: 3.0.0.10)
CC_ccProxyExt (Version: 104.0.1.17)
ccCommon (Version: 104.0.1.17)
ccPxyCore (Version: 104.0.1.17)
Click to DVD 2.0.03 Menu Data (Version: 2.0.03)
Click to DVD 2.5.30 (Version: 2.5.30)
Click to DVD Tutorial (Version: 1.00)
DivX (Version: 6.2.2)
DivX Converter (Version: 6.1.1)
DVD Decrypter (Remove Only)
DVD Shrink 3.2
DVDFab 8.1.3.2 (31/10/2011) Qt
DVDFab Decrypter 3.0.9.6
DVgate Plus
ERUNT 1.1j
GRE POWERPREP
HandBrake 0.9.5 (Version: 0.9.5)
High Definition Audio Driver Package - KB835221 (Version: 20040219.000000)
Image Converter 2 Plus (Version: 2.2.06)
ImageStation (Version: 1.0.0)
Intel® Graphics Media Accelerator Driver (Version: 6.14.10.4543)
Intel® PROSet/Wireless Software (Version: 10.5.0.0 API)
InterVideo WinDVD for VAIO (Version: 5.0-B11.768)
ISScript (Version: 3.00.185)
iTunes (Version: 10.5.1.42)
J2SE Runtime Environment 5.0 Update 11 (Version: 1.5.0.110)
J2SE Runtime Environment 5.0 Update 7 (Version: 1.5.0.70)
J2SE Runtime Environment 5.0 Update 9 (Version: 1.5.0.90)
Java Auto Updater (Version: 2.0.2.1)
Java™ 6 Update 19 (Version: 6.0.190)
LAN Setting Utility
LiveUpdate 2.7 (Symantec Corporation) (Version: 2.7.39.0)
Macromedia Flash Player 8 (Version: 8.0.24.0)
Macromedia Flash Player 8 Plugin (Version: 8.0.24.0)
Malwarebytes' Anti-Malware version 1.51.2.1300 (Version: 1.51.2.1300)
mCore (Version: 7.00.0000)
mDriver (Version: 7.00.0000)
Memory Stick Formatter
Microsoft .NET Framework 1.0 Hotfix (KB2572066)
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.0 Hotfix (KB979904)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2572067)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1)
Microsoft Data Access Components KB870669
Microsoft Digital Image Library 9 - Blocker (Version: 9.00.0000)
Microsoft Digital Image Starter Edition 2006 (Version: 11.0.0422)
Microsoft Digital Image Starter Edition 2006 Editor (Version: 11.0.0422)
Microsoft Digital Image Starter Edition 2006 Library (Version: 11.0.0422)
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Visio 2007 Service Pack 3 (SP3)
Microsoft Office Visio MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Visio Professional 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs (Version: 12.0.4518.1014)
Microsoft SQL Server Desktop Engine (VAIO_VEDB) (Version: 8.00.761)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries (Version: 1.0.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Works (Version: 08.05.0818)
mMHouse (Version: 7.00.0000)
mPfMgr (Version: 7.00.0000)
mProSafe (Version: 9.00.0000)
MSRedist (Version: 1.0.0.0)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
mWlsSafe (Version: 9.00.0000)
mXML (Version: 7.00.0000)
Nero 7 Ultra Edition (Version: 7.01.9440)
Nero PhotoShow Express 4 (Version: 4.0)
Norton AntiSpam (Version: 2006.2.0.150)
Norton AntiSpam (Version: 2006.2.0.153)
Norton AntiVirus 2006 (Version: 12.0.2.5)
Norton Internet Security (Version: 1.0.0)
Norton Internet Security (Version: 9.0.3.4)
Norton Internet Security 2006 (Symantec Corporation) (Version: 9.0.3.4)
Norton Protection Center (Version: 1.1.2)
Norton WMI Update (Version: 2005.1.2.20)
Office 2003 Trial Assistant (Version: 1.0.0)
OpenMG AAC Add-on Module 1.0.00 (Version: 1.0.00.04270)
OpenMG Limited Patch 4.5-06-05-12-01
OpenMG Metadata Extractor for Windows Media Player (Version: 1.0.02.03110)
OpenMG Secure Module 4.5.01 (Version: 4.5.01.04270)
Pro Media Director Version 2.1.0.0
Quicken 2006 (Version: 15.1.4.5)
QuickTime (Version: 7.70.80.34)
Realtek High Definition Audio Driver (Version: 5.10.0.5268)
Roxio DigitalMedia Audio (Version: 2.0.4)
Roxio DigitalMedia Copy (Version: 2.0.4)
Roxio DigitalMedia Data (Version: 2.0.4)
Roxio Media Manager (Version: 9.1.072)
Search Enhancement by AOL Search
Setting Utility Series
Soft Data Fax Modem with SmartCP
Sonic Encoders (Version: 1.00)
SonicStage 4.0 (Version: 4.0)
Sony Certificate PCH
Sony MP4 Shared Library (Version: 2.0)
Sony USB Driver
Sony Utilities DLL
Sony Video Shared Library (Version: 2.0.01)
SPBBC (Version: 2.0.0.73)
Spybot - Search & Destroy (Version: 1.6.2)
Symantec KB-DocID:2003093015493306 (Version: 1.0.0.1)
SymNet (Version: 6.0.4.402)
TeamViewer 6 (Version: 6.0.11656)
Trend Micro Anti-Spyware
Update Rollup 2 for Windows XP Media Center Edition 2005
VAIO Backup Utility (Version: 1.00.7246)
VAIO Breeze Wallpaper (Version: 1.0.01.13200)
VAIO Central (Version: 1.1.02.032706)
VAIO Entertainment Platform (Version: 1.3.32.06120)
VAIO Event Service
VAIO Hardware Diagnostics
VAIO Light Flo Wallpaper
VAIO Media 5.0 (Version: 5.0.20)
VAIO Media AC3 Decoder 1.0
VAIO Media Integrated Server 5.0
VAIO Media Redistribution 5.0 (Version: 5.0.20)
VAIO Media Registration Tool 5.0 (Version: 5.0.00)
VAIO Media Tutorial (Version: 1.00)
VAIO Original Screen Saver
VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
VAIO Power Management
VAIO Registration (Version: 17.1.1)
VAIO Security Center (Version: 2.02.0320)
VAIO Support Central (Version: 1.1.1.060802)
VAIO Update 2
VAIO Wireless LAN Setup Utility
VAIOSurveySA (Version: 4.02)
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (Version: 9.0.30729.01)
WD Diagnostics (Version: 1.08.0000)
WebFldrs XP (Version: 9.50.7523)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows Media Format 11 runtime
Windows Media Player 10 Hotfix [See KB886612 for more information]
Windows Media Player 11
Windows XP Media Center Edition 2005 KB2502898
Windows XP Media Center Edition 2005 KB2619340
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3 (Version: 20080414.031525)
WinRAR archiver
Wireless Switch Setting Utility

========================= Devices: ================================

Name: Marvell Yukon 88E8036 PCI-E Fast Ethernet Controller
Description: Marvell Yukon 88E8036 PCI-E Fast Ethernet Controller
Class Guid: {4D36E972-E325-11CE-BFC1-08002BE10318}
Manufacturer: Marvell
Service: yukonwxp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: 1394 Net Adapter
Description: 1394 Net Adapter
Class Guid: {4D36E972-E325-11CE-BFC1-08002BE10318}
Manufacturer: Microsoft
Service: NIC1394
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


========================= Memory info: ===================================

Percentage of memory in use: 81%
Total physical RAM: 502.11 MB
Available physical RAM: 92.58 MB
Total Pagefile: 1225.98 MB
Available Pagefile: 480.64 MB
Total Virtual: 2047.88 MB
Available Virtual: 1971.21 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:69.07 GB) (Free:20.56 GB) NTFS

========================= Users: ========================================

User accounts for \\LAPTOP

Administrator ASPNET Guest
HelpAssistant SUPPORT_388945a0

========================= Minidump Files ==================================

C:\WINDOWS\Minidump\Mini031610-01.dmp
C:\WINDOWS\Minidump\Mini051011-01.dmp
C:\WINDOWS\Minidump\Mini051011-02.dmp
C:\WINDOWS\Minidump\Mini051011-03.dmp
C:\WINDOWS\Minidump\Mini051011-04.dmp
C:\WINDOWS\Minidump\Mini051011-05.dmp
C:\WINDOWS\Minidump\Mini051211-01.dmp
C:\WINDOWS\Minidump\Mini051511-01.dmp
C:\WINDOWS\Minidump\Mini052311-01.dmp
C:\WINDOWS\Minidump\Mini052311-02.dmp
C:\WINDOWS\Minidump\Mini121211-01.dmp

**** End of log ****

MBAM Log:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8377

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12/15/2011 3:01:18 PM
mbam-log-2011-12-15 (15-01-18).txt

Scan type: Quick scan
Objects scanned: 195747
Time elapsed: 16 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

ESET Scan Log:

C:\WINDOWS\system32\Process.exe Win32/PrcView application cleaned by deleting - quarantined


Please let me know what I need to do next.

Thank you again for your help with this...I really appreciate it!

Edited by mlions, 16 December 2011 - 09:38 AM.


#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,199 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:23 AM

Posted 21 December 2011 - 12:42 PM

Hello, sorry I somehow lost you.

Looks like you have a small amount of RAM installed and you machine may be filling up a bit.

Lets run this and get some junk files off.

Next run ATF and SAS:

Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".

From your regular user account..
Download Attribune's ATF-Cleaner and then SUPERAntiSpyware , Free Home Version. Save both to desktop ..
DO NOT run yet.
Open SUPER from icon and install and Update it
Under Scanner Options make sure the following are checked (leave all others unchecked):
Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining
.
Click the "Close" button to leave the control center screen and exit the program. DO NOT run yet.

Now reboot into Safe Mode: How to enter safe mode(XP)
Using the F8 Method
Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode
.

Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.

NOW Scan with SUPER
Open from the desktop icon or the program Files list
On the left, make sure you check C:\Fixed Drive.
Perform a Complete scan. After scan,Verify they are all checked.
Click OK on the summary screen to quarantine all found items.
If asked if you want to reboot, click "Yes" and reboot normally.

To retrieve the removal information after reboot, launch SUPERAntispyware again.
Click Preferences, then click the Statistics/Logs tab.
Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
If there are several logs, click the current dated log and press View log.
A text file will open in your default text editor.
Please copy and paste the Scan Log results in your next reply.
Click Close to exit the program.


Please ask any needed questions,post logs and Let us know how the PC is running now.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 mlions

mlions
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:10:23 AM

Posted 22 December 2011 - 10:09 AM

It seems that I cannot download the ATF-Clearner. When I click on the link to down from the website you provided me, it says that "ID does not exist." I wanted to check with you and see what I should do. Thanks!

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,199 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:23 AM

Posted 22 December 2011 - 12:47 PM

http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 mlions

mlions
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:10:23 AM

Posted 22 December 2011 - 01:40 PM

I've used that link and I am brought to the ATF-Clearner website. Then when I click on the "Please download ATF-Cleaner" I get the error message in a new window that "This ID does not exist." Should I download ATF-Clearner 3 (it is located on the home page.)?

#8 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,199 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:23 AM

Posted 22 December 2011 - 04:21 PM

I have to contact them...

Run TFC by OT (Temp File Cleaner)
Please download TFC by Old Timer and save it to your desktop.
alternate download link

Save any unsaved work. TFC will close ALL open programs including your browser!
Double-click on TFC.exe to run it. If you are using Vista, right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#9 mlions

mlions
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:10:23 AM

Posted 27 December 2011 - 10:16 AM

Did you want me to run the TFC.exe in Safe Mode? Or should I only do that with SAS?

#10 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,199 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:23 AM

Posted 27 December 2011 - 02:20 PM

You can do TFC in Safe also.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#11 mlions

mlions
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:10:23 AM

Posted 28 December 2011 - 10:40 PM

I ran both of the programs you told me. My computer seems to be running better, but I am still having problems connecting to the internet after starting-up. My wireless continues to say "Acquiring Network Address" and never connects to the Internet until I manually go into services.msc and then start my DHCP Client.

Also, here is my SAS Log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/28/2011 at 03:50 PM

Application Version : 5.0.1142

Core Rules Database Version : 8088
Trace Rules Database Version: 5900

Scan type : Complete Scan
Total Scan Time : 04:49:19

Operating System Information
Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator

Memory items scanned : 246
Memory threats detected : 0
Registry items scanned : 40422
Registry threats detected : 0
File items scanned : 102700
File threats detected : 173

Adware.Tracking Cookie
C:\Documents and Settings\Lyons\Cookies\0BLIMC0S.txt [ /accounts.youtube.com ]
C:\Documents and Settings\Lyons\Cookies\LODPZ2MV.txt [ /interclick.com ]
C:\Documents and Settings\Lyons\Cookies\F7VLELY1.txt [ /collective-media.net ]
C:\Documents and Settings\Lyons\Cookies\8CRIL8KW.txt [ /c.gigcount.com ]
C:\Documents and Settings\Lyons\Cookies\L035ISNY.txt [ /lfstmedia.com ]
C:\Documents and Settings\Lyons\Cookies\1P3LYAX6.txt [ /ad.yieldmanager.com ]
C:\Documents and Settings\Lyons\Cookies\M9NP89EH.txt [ /yieldmanager.net ]
C:\Documents and Settings\Lyons\Cookies\TS7AMWL2.txt [ /ads.as4x.tmcs.ticketmaster.com ]
C:\Documents and Settings\Lyons\Cookies\7H4EX22J.txt [ /specificclick.net ]
C:\Documents and Settings\Lyons\Cookies\LTHMZHHI.txt [ /adlegend.com ]
C:\Documents and Settings\Lyons\Cookies\SIHEQ2MH.txt [ /amazon-adsystem.com ]
C:\Documents and Settings\Lyons\Cookies\98RC9LUO.txt [ /rtst.122.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\IX3G679X.txt [ /anrtx.tacoda.net ]
C:\Documents and Settings\Lyons\Cookies\85X3PAGQ.txt [ /verizontelecom.112.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\F1EDOYT2.txt [ /bs.serving-sys.com ]
C:\Documents and Settings\Lyons\Cookies\CX4E2V06.txt [ /ads.pubmatic.com ]
C:\Documents and Settings\Lyons\Cookies\NCYXFQ0Q.txt [ /serving-sys.com ]
C:\Documents and Settings\Lyons\Cookies\JG9SVPV5.txt [ /www.googleadservices.com ]
C:\Documents and Settings\Lyons\Cookies\D9JTGN3G.txt [ /pointroll.com ]
C:\Documents and Settings\Lyons\Cookies\2O2MXJ9S.txt [ /mediaservices-d.openxenterprise.com ]
C:\Documents and Settings\Lyons\Cookies\GH7X7EUA.txt [ /adbrite.com ]
C:\Documents and Settings\Lyons\Cookies\1R7FO7DD.txt [ /accounts.google.com ]
C:\Documents and Settings\Lyons\Cookies\S9JXLG7T.txt [ /247realmedia.com ]
C:\Documents and Settings\Lyons\Cookies\TC1ORBLM.txt [ /questionmarket.com ]
C:\Documents and Settings\Lyons\Cookies\2SG3SMU1.txt [ /legolas-media.com ]
C:\Documents and Settings\Lyons\Cookies\80QB5FDH.txt [ /ad.360yield.com ]
C:\Documents and Settings\Lyons\Cookies\FTIKCB4Z.txt [ /pro-market.net ]
C:\Documents and Settings\Lyons\Cookies\YXY3VXSI.txt [ /gsimedia.net ]
C:\Documents and Settings\Lyons\Cookies\FAARMBKT.txt [ /liveperson.net ]
C:\Documents and Settings\Lyons\Cookies\NI8YA37F.txt [ /viewablemedia.net ]
C:\Documents and Settings\Lyons\Cookies\AUMQS8CA.txt [ /accounts.google.com ]
C:\Documents and Settings\Lyons\Cookies\BJF45LJV.txt [ /at.atwola.com ]
C:\Documents and Settings\Lyons\Cookies\42FGIPQ5.txt [ /adxpose.com ]
C:\Documents and Settings\Lyons\Cookies\H9BSW6BO.txt [ /tacoda.at.atwola.com ]
C:\Documents and Settings\Lyons\Cookies\JTEVX1E9.txt [ /liveperson.net ]
C:\Documents and Settings\Lyons\Cookies\JRJL7EY1.txt [ /ads.cnn.com ]
C:\Documents and Settings\Lyons\Cookies\ZCQLQJGK.txt [ /eyewonder.com ]
C:\Documents and Settings\Lyons\Cookies\T08Z9Q3I.txt [ /content.yieldmanager.com ]
C:\Documents and Settings\Lyons\Cookies\N20CAJYT.txt [ /kontera.com ]
C:\Documents and Settings\Lyons\Cookies\DT5KALNJ.txt [ /mediaforge.com ]
C:\Documents and Settings\Lyons\Cookies\345FQQK1.txt [ /mlb.112.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\W91FDF2X.txt [ /idgenterprise.112.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\T1ZK20VU.txt [ /stryker.112.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\N12ZR7T2.txt [ /doubleclick.net ]
C:\Documents and Settings\Lyons\Cookies\NNG51406.txt [ /usatoday1.112.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\AVKD0RSB.txt [ /invitemedia.com ]
C:\Documents and Settings\Lyons\Cookies\2JRFXYEU.txt [ /dc.tremormedia.com ]
C:\Documents and Settings\Lyons\Cookies\Q0LG5EOH.txt [ /nike.112.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\IGRD149X.txt [ /lucidmedia.com ]
C:\Documents and Settings\Lyons\Cookies\DJN2295Q.txt [ /mediabrandsww.com ]
C:\Documents and Settings\Lyons\Cookies\WJMB2V6V.txt [ /2o7.net ]
C:\Documents and Settings\Lyons\Cookies\U1WDXDKC.txt [ /a1.interclick.com ]
C:\Documents and Settings\Lyons\Cookies\2DS7GO8K.txt [ /tribalfusion.com ]
C:\Documents and Settings\Lyons\Cookies\817HG3M2.txt [ /realmedia.com ]
C:\Documents and Settings\Lyons\Cookies\CIGXLRDN.txt [ /ads.undertone.com ]
C:\Documents and Settings\Lyons\Cookies\F1QBETKY.txt [ /trafficmp.com ]
C:\Documents and Settings\Lyons\Cookies\RLE0O4HT.txt [ /ru4.com ]
C:\Documents and Settings\Lyons\Cookies\XZ1R4L5F.txt [ /warnerbros.112.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\9Q625PCF.txt [ /eyeviewads.com ]
C:\Documents and Settings\Lyons\Cookies\AP8MDVX8.txt [ /insightexpressai.com ]
C:\Documents and Settings\Lyons\Cookies\KRRN7F17.txt [ /ads.pointroll.com ]
C:\Documents and Settings\Lyons\Cookies\A0AG7LDC.txt [ /ad.wsod.com ]
C:\Documents and Settings\Lyons\Cookies\439XM7O9.txt [ /atdmt.com ]
C:\Documents and Settings\Lyons\Cookies\VRB4C3AK.txt [ /akamai.interclickproxy.com ]
C:\Documents and Settings\Lyons\Cookies\LWYHEUA3.txt [ /revsci.net ]
C:\Documents and Settings\Lyons\Cookies\DE7T9Y9X.txt [ /media.adfrontiers.com ]
C:\Documents and Settings\Lyons\Cookies\ZL3K49XG.txt [ /ar.atwola.com ]
C:\Documents and Settings\Lyons\Cookies\1W1CJUW3.txt [ /media6degrees.com ]
C:\Documents and Settings\Lyons\Cookies\HM4XHZ6H.txt [ /ssdev.112.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\K0BK4Z1H.txt [ /mm.chitika.net ]
C:\Documents and Settings\Lyons\Cookies\J2XI5BOQ.txt [ /adserver.adtechus.com ]
C:\Documents and Settings\Lyons\Cookies\DL0BF77A.txt [ /histats.com ]
C:\Documents and Settings\Lyons\Cookies\HGMN4DL1.txt [ /pubads.g.doubleclick.net ]
C:\Documents and Settings\Lyons\Cookies\4GEE0SR5.txt [ /www.googleadservices.com ]
C:\Documents and Settings\Lyons\Cookies\DXNW3XI0.txt [ /ads.shorttail.net ]
C:\Documents and Settings\Lyons\Cookies\O8BU3TS1.txt [ /in.getclicky.com ]
C:\Documents and Settings\Lyons\Cookies\QUEDR1I3.txt [ /eset.122.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\22K9N9QL.txt [ /ads.bridgetrack.com ]
C:\Documents and Settings\Lyons\Cookies\QI3S7WBL.txt [ /overture.com ]
C:\Documents and Settings\Lyons\Cookies\QZI0KDQW.txt [ /network.realmedia.com ]
C:\Documents and Settings\Lyons\Cookies\1ITH0GTZ.txt [ /leeenterprises.112.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\R9JXHK39.txt [ /liveperson.net ]
C:\Documents and Settings\Lyons\Cookies\QTN693JD.txt [ /tracking.dsmmadvantage.com ]
C:\Documents and Settings\Lyons\Cookies\7VITJ6HE.txt [ /10technology.112.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\KKUGS4HN.txt [ /microsoftsto.112.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\MA9WS3BC.txt [ /clickability.com ]
C:\Documents and Settings\Lyons\Cookies\7AP0JU6Y.txt [ /bizrate.com ]
C:\Documents and Settings\Lyons\Cookies\IV83O825.txt [ /ads.bleepingcomputer.com ]
C:\Documents and Settings\Lyons\Cookies\5N66OBM9.txt [ /stats.townnews.com ]
C:\Documents and Settings\Lyons\Cookies\26B8Q1OS.txt [ /sales.liveperson.net ]
C:\Documents and Settings\Lyons\Cookies\9QUK00XI.txt [ /timeinc.122.2o7.net ]
C:\Documents and Settings\Lyons\Cookies\UR13MTSY.txt [ /technoratimedia.com ]
C:\Documents and Settings\Lyons\Cookies\UDU2K127.txt [ /martiniadnetwork.com ]
C:\DOCUMENTS AND SETTINGS\LYONS\Cookies\20LMFV81.txt [ Cookie:lyons@www.google.com/accounts ]
C:\DOCUMENTS AND SETTINGS\LYONS\Cookies\I15X7SAO.txt [ Cookie:lyons@thechart.blogs.cnn.com/2011/10/13/are-female-orgasms-really-just-a-bonus/ ]
C:\DOCUMENTS AND SETTINGS\LYONS\Cookies\A8VT5UVS.txt [ Cookie:lyons@google.com/accounts/ ]
C:\DOCUMENTS AND SETTINGS\LYONS\Cookies\JBIGBXFR.txt [ Cookie:lyons@adsonar.com/adserving ]
C:\DOCUMENTS AND SETTINGS\LYONS\Cookies\AUSY1751.txt [ Cookie:lyons@www.google.com/accounts/recovery ]
C:\DOCUMENTS AND SETTINGS\LYONS\Cookies\LM3SV5WY.txt [ Cookie:lyons@google.com/accounts/recovery/ ]
C:\DOCUMENTS AND SETTINGS\LYONS\Cookies\U5VGWJI2.txt [ Cookie:lyons@verizon.com/vztracker/ ]
C:\DOCUMENTS AND SETTINGS\LYONS\Cookies\EOE4X5XG.txt [ Cookie:lyons@marquee.blogs.cnn.com/2011/11/15/ex-porn-star-sasha-grey-i-wont-stop-reading-to-kids/ ]
media.kyte.tv [ C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\B5DLJWF5 ]
media.mtvnservices.com [ C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\B5DLJWF5 ]
media1.break.com [ C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\B5DLJWF5 ]
msnbcmedia.msn.com [ C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\B5DLJWF5 ]
secure-us.imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\B5DLJWF5 ]
2mdn.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
a.ads2.msads.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
ad.insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
adbureau.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
ads1.msn.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
ads2.msads.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
adsatt.espn.go.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
b.ads2.msads.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
cdn.eyewonder.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
cdn.tremormedia.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
cdn4.specificclick.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
core.insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
crackle.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
ds.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
espn360.channelfinder.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
gals21.fantasygirlrevenue.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
googleads.g.doubleclick.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
hs.interpolls.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
ia.media-imdb.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
interclick.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
m1.2mdn.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
macromedia.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
media.monster.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
media.mtvnservices.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
media.nbcmiami.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
media.noob.us [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
media.scanscout.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
media.tattomedia.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
media01.isagenix.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
media01.kyte.tv [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
media1.break.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
msnbcmedia.msn.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
msntest.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
naiadsystems.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
objects.tremormedia.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
oddcast.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
pornstars.foxmagazine.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
richmedia247.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
s0.2mdn.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
secure-us.imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
serving-sys.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
sftrack.searchforce.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
spe.atdmt.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
speed.pointroll.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
static.sexsearch.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
think-porn.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
udn.specificclick.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
vmixmedia-0.vo.llnwd.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
wdw1.wdpromedia.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
wdw2.wdpromedia.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
www.crackle.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
www.daywithapornstar.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
www.freepornofreeporn.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
www.naiadsystems.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
www.porngarden.info [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
www.pornotube.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
www.pornpros.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
www.thepornstarlist.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
yieldmanager.edgesuite.net [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
zedo.com [ C:\DOCUMENTS AND SETTINGS\LYONS\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\FMSRXUTS ]
convoad.technoratimedia.net [ C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UY9N95WW ]
crackle.com [ C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UY9N95WW ]
media.kyte.tv [ C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UY9N95WW ]
media.mtvnservices.com [ C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UY9N95WW ]
media1.break.com [ C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UY9N95WW ]
objects.tremormedia.com [ C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UY9N95WW ]
secure-us.imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UY9N95WW ]


Thank you VERY much for this help! I truly appreciate your time and effort!!!

#12 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,199 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:23 AM

Posted 28 December 2011 - 10:58 PM

Your welcome.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

64-bit users go HERE
  • Double-click SystemLook.exe to run it.
  • Vista\Win 7 users:: Right click on SystemLook.exe, click Run As Administrator
  • Copy the content of the following box and paste it into the main textfield:
    :filefind
    netbt.sys
    :reg
    HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\netbt /s
    
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Edited by boopme, 28 December 2011 - 11:01 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#13 mlions

mlions
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:10:23 AM

Posted 29 December 2011 - 10:04 AM

Here is my log from System Look:

SystemLook 30.07.11 by jpshortstuff
Log created at 09:58 on 29/12/2011 by Lyons
Administrator - Elevation successful

========== filefind ==========

Searching for "netbt.sys"
C:\WINDOWS\$NtServicePackUninstall$\netbt.sys -----c- 162816 bytes [21:37 28/12/2008] [12:00 15/03/2006] 0C80E410CD2F47134407EE7DD19CC86B

========== reg ==========

[HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\netbt]
"Type"= 0x0000000001 (1)
"Start"= 0x0000000001 (1)
"ErrorControl"= 0x0000000001 (1)
"Tag"= 0x0000000006 (6)
"ImagePath"="system32\DRIVERS\netbt.sys"
"DisplayName"="NetBios over Tcpip"
"Group"="PNP_TDI"
"DependOnService"="Tcpip"
"DependOnGroup"=" "
"Description"="NetBios over Tcpip"

[HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\netbt\Enum]
"0"="Root\LEGACY_NETBT\0000"
"Count"= 0x0000000001 (1)
"NextInstance"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\netbt\Linkage]
"OtherDependencies"="Tcpip"
"Bind"="\Device\Tcpip_{4BF12059-1E29-4EE0-AFC5-BF4022A112E6} \Device\Tcpip_{C0D5DBCB-3C02-4C48-823C-F18537BAE119} \Device\Tcpip_{EA5A8CFA-2C1C-49B8-B7CA-1BBD97A29522} \Device\Tcpip_{467FF04D-DE05-41D3-8747-DFAB3E5F171A} \Device\Tcpip_{DAA9DBCF-4367-4DE7-9DA8-DD8FE0D66D5B} \Device\Tcpip_{A1E396F7-30F2-4DAE-9B4F-40EB61CDAB31}"
"Route"=""Tcpip" "{4BF12059-1E29-4EE0-AFC5-BF4022A112E6}" "Tcpip" "{C0D5DBCB-3C02-4C48-823C-F18537BAE119}" "Tcpip" "{EA5A8CFA-2C1C-49B8-B7CA-1BBD97A29522}" "Tcpip" "{467FF04D-DE05-41D3-8747-DFAB3E5F171A}" "Tcpip" "NdisWanIp""
"Export"="\Device\NetBT_Tcpip_{4BF12059-1E29-4EE0-AFC5-BF4022A112E6} \Device\NetBT_Tcpip_{C0D5DBCB-3C02-4C48-823C-F18537BAE119} \Device\NetBT_Tcpip_{EA5A8CFA-2C1C-49B8-B7CA-1BBD97A29522} \Device\NetBT_Tcpip_{467FF04D-DE05-41D3-8747-DFAB3E5F171A} \Device\NetBT_Tcpip_{DAA9DBCF-4367-4DE7-9DA8-DD8FE0D66D5B} \Device\NetBT_Tcpip_{A1E396F7-30F2-4DAE-9B4F-40EB61CDAB31}"

[HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\netbt\Parameters]
"NbProvider"="_tcp"
"NameServerPort"= 0x0000000089 (137)
"CacheTimeout"= 0x00000927c0 (600000)
"BcastNameQueryCount"= 0x0000000003 (3)
"BcastQueryTimeout"= 0x00000002ee (750)
"NameSrvQueryCount"= 0x0000000003 (3)
"NameSrvQueryTimeout"= 0x00000005dc (1500)
"Size/Small/Medium/Large"= 0x0000000001 (1)
"SessionKeepAlive"= 0x000036ee80 (3600000)
"TransportBindName"="\Device\"

[HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\netbt\Parameters\Interfaces]
(No values found)

[HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\netbt\Parameters\Interfaces\Tcpip_{1574B666-940E-4AA1-8E3B-3102DD39BBC1}]
"NameServerList"=" "
"NetbiosOptions"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\netbt\Parameters\Interfaces\Tcpip_{A274D5B8-64BF-4AF4-9CE1-C8745118A562}]
"NameServerList"=" "
"NetbiosOptions"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\netbt\Parameters\Interfaces\Tcpip_{E6D314CC-9C15-45FF-9A9C-F5245BA6EAB7}]
"NameServerList"=" "
"NetbiosOptions"= 0x0000000000 (0)
"DhcpNameServerList"="192.168.133.2"

[HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\netbt\Security]
"Security"=01 00 14 80 e8 00 00 00 f4 00 00 00 14 00 00 00 30 00 00 00 02 00 1c 00 01 00 00 00 02 80 14 00 ff 01 0f 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 b8 00 08 00 00 00 00 00 14 00 8d 01 02 00 01 01 00 00 00 00 00 05 0b 00 00 00 00 00 18 00 9d 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 00 00 18 00 ff 01 0f 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 18 00 ff 01 0f 00 01 02 00 00 00 00 00 05 20 00 00 00 25 02 00 00 00 00 14 00 fd 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 14 00 40 00 00 00 01 01 00 00 00 00 00 05 13 00 00 00 00 00 14 00 40 00 00 00 01 01 00 00 00 00 00 05 14 00 00 00 00 00 18 00 9d 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 2c 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00 (REG_BINARY)


-= EOF =-

#14 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,199 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:11:23 AM

Posted 29 December 2011 - 10:20 PM

YES~~~

Open Windows Explorer, navigate to C:\WINDOWS\system32\dllcache folder, copy netbt.sys file from there and paste it to C:\WINDOWS\system32\Drivers folder.

Then...

Following steps involve registry editing. Please create new restore point before proceeding!!!

Download XP.zip file from here: http://www.smartestcomputing.us.com/files/download/9-registry-network-keys/
Unzip the file.
You'll find six files inside.
Right click on netbt.reg file, click "Merge".
Allow registry merge.
Restart computer and see if internet works.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#15 mlions

mlions
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:10:23 AM

Posted 30 December 2011 - 11:05 AM

It didn't work. After restarting, I still had to manually start my DHCP client.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users