1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive [InActive] No Wifi, no sound, unable to reset to factory condition.

Discussion in 'Malware and Virus Removal Archive' started by finalmisery, 2008/11/28.

  1. 2008/11/28
    finalmisery

    finalmisery Inactive Thread Starter

    Joined:
    2005/04/08
    Messages:
    42
    Likes Received:
    0
    Hello again, it's been a while.:)

    I suspect some kind of mal-ware activity, need help figuring it out.

    Little sister's ACER Aspire One is acting up in a peculiar way. I can't use it to connect to the internet anymore. I would go down to the icon tray to find the Connection icon, but it doesn't exist. I went to Network Connections to try to find any existing network connections but nothing was there. I attempted to create a new connection with the New Connection Wizard, however it does not progress after choosing Connection Type.

    Oh and I can't open the Help & Support program. Which really worries me now.

    I was willing to restore the mini-notebook to its factory condition, but it doesn't allow me to do so. Opened Acer eRecovery Management, chose "restore system to factory default" and clicked "Yes" and then "Next ". A little window popped up and presented an error:

    See the end of this message for details on invoking
    just-in-time (JIT) debugging instead of this dialog box.

    ************** Exception Text **************
    System.Runtime.InteropServices.COMException (0x80070424): The specified service does not exist as an installed service.
    at System.Management.ManagementScope.Initialize()
    at System.Management.ManagementObjectSearcher.Initialize()
    at System.Management.ManagementObjectSearcher.Get()
    at eRecovery.PopUp_RestoreDiskPartitionInfo.timer_Start_Tick(Object sender, EventArgs e)
    at System.Windows.Forms.Timer.OnTick(EventArgs e)
    at System.Windows.Forms.Timer.Callback(IntPtr hWnd, Int32 msg, IntPtr idEvent, IntPtr dwTime)


    ************** Loaded Assemblies **************
    mscorlib
    Assembly Version: 1.0.5000.0
    Win32 Version: 1.1.4322.2407
    CodeBase: file:///c:/windows/microsoft.net/framework/v1.1.4322/mscorlib.dll
    ----------------------------------------
    eRecoveryUI
    Assembly Version: 2.1.3.0
    Win32 Version: 2.1.3.0
    CodeBase: file:///C:/Acer/Empowering%20Technology/eRecovery/eRecoveryUI.exe
    ----------------------------------------
    Acer.Empowering.Windows.Forms
    Assembly Version: 1.0.1.31810
    Win32 Version: 1.0.1.31810
    CodeBase: file:///C:/Acer/Empowering%20Technology/eRecovery/Acer.Empowering.Windows.Forms.DLL
    ----------------------------------------
    System.Windows.Forms
    Assembly Version: 1.0.5000.0
    Win32 Version: 1.1.4322.2032
    CodeBase: file:///c:/windows/assembly/gac/system.windows.forms/1.0.5000.0__b77a5c561934e089/system.windows.forms.dll
    ----------------------------------------
    System
    Assembly Version: 1.0.5000.0
    Win32 Version: 1.1.4322.2407
    CodeBase: file:///c:/windows/assembly/gac/system/1.0.5000.0__b77a5c561934e089/system.dll
    ----------------------------------------
    System.Drawing
    Assembly Version: 1.0.5000.0
    Win32 Version: 1.1.4322.2032
    CodeBase: file:///c:/windows/assembly/gac/system.drawing/1.0.5000.0__b03f5f7f11d50a3a/system.drawing.dll
    ----------------------------------------
    Acer.Empowering.Framework.PasswordSetting
    Assembly Version: 2.3.4000.0
    Win32 Version: 2.3.4000.0
    CodeBase: file:///C:/Acer/Empowering%20Technology/eRecovery/Acer.Empowering.Framework.PasswordSetting.DLL
    ----------------------------------------
    Accessibility
    Assembly Version: 1.0.5000.0
    Win32 Version: 1.1.4322.573
    CodeBase: file:///c:/windows/assembly/gac/accessibility/1.0.5000.0__b03f5f7f11d50a3a/accessibility.dll
    ----------------------------------------
    System.Management
    Assembly Version: 1.0.5000.0
    Win32 Version: 1.1.4322.2032
    CodeBase: file:///c:/windows/assembly/gac/system.management/1.0.5000.0__b03f5f7f11d50a3a/system.management.dll
    ----------------------------------------

    ************** JIT Debugging **************
    To enable just in time (JIT) debugging, the config file for this
    application or machine (machine.config) must have the
    jitDebugging value set in the system.windows.forms section.
    The application must also be compiled with debugging
    enabled.

    For example:

    <configuration>
    <system.windows.forms jitDebugging= "true" />
    </configuration>

    When JIT debugging is enabled, any unhandled exception
    will be sent to the JIT debugger registered on the machine
    rather than being handled by this dialog.


    I am trying to install as many helpful applications from my laptop to my sister's, such as

    HJT,

    MBAM,

    ccleaner,

    recuva, < was wondering if that's something worth using.

    zonealarm,

    etc. Not sure what else I should have.

    Here's a HJT log of her computer:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:45:35 AM, on 11/28/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\McAfee\MSK\MskSrver.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\WINDOWS\system32\igfxext.exe
    C:\Program Files\OpenOffice.org 3\program\soffice.exe
    C:\Program Files\OpenOffice.org 3\program\soffice.bin
    C:\Program Files\iPod\bin\iPodService.exe
    C:\DOCUME~1\Kimberly\LOCALS~1\Temp\RtkBtMnt.exe
    c:\PROGRA~1\mcafee\msc\mcuimgr.exe
    C:\Acer\Empowering Technology\eRecovery\eRecovery.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=1008&m=aoa150
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=1008&m=aoa150
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: McAfee Phishing Filter - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
    O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    O4 - HKLM\..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe
    O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe
    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKUS\S-1-5-21-1618656104-1170644015-4075408155-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - HKUS\S-1-5-21-1618656104-1170644015-4075408155-1006\..\Run: [Aim6] (User '?')
    O4 - HKUS\S-1-5-21-1618656104-1170644015-4075408155-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
    O4 - S-1-5-21-1618656104-1170644015-4075408155-1006 Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User '?')
    O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1224987540937
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O20 - Winlogon Notify: obwfvtx - obwfvtx.dll (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 10481 bytes

    Hope this grabs your attention!
     
    Last edited: 2008/11/28
  2. 2008/11/28
    finalmisery

    finalmisery Inactive Thread Starter

    Joined:
    2005/04/08
    Messages:
    42
    Likes Received:
    0
    Is it possible to download MBAM into a flashdrive along with a recent update file, and install them onto a computer that is curren't incapable of accessing the internet?
     

  3. to hide this advert.

  4. 2008/11/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Download ComboFix by sUBs from here, then transfer the file to the problem pc's desktop.


    Please disable realtime protection applications as they sometimes interfere with the tool. Check this link for your applicable programs.

    • Close all open programs and windows
    • Double click ComboFix.exe and follow the prompts.
    • It may reboot your computer and resume running when you logon. Wait for it to complete. When finished, it will open a log for you. Post that log in your next reply.
    Note: Do not mouseclick combofix's window while its running. That may cause it to stall
     
  5. 2008/12/01
    finalmisery

    finalmisery Inactive Thread Starter

    Joined:
    2005/04/08
    Messages:
    42
    Likes Received:
    0
    ComboFix 08-11-30.01 - Kimberly 2008-12-01 2:46:43.2 - NTFSx86

    Running from: e:\documents\Downloads\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_TCPSR


    ((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
    .

    2008-11-28 11:30 . 2008-11-28 11:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
    2008-11-28 02:14 . 2008-12-01 02:59 225,312 --ahs---- c:\windows\system32\drivers\fidbox.dat
    2008-11-28 02:14 . 2008-12-01 02:50 3,644 --ahs---- c:\windows\system32\drivers\fidbox.idx
    2008-11-28 02:13 . 2008-11-28 02:13 <DIR> d-------- c:\program files\ZoneAlarmSB
    2008-11-28 02:10 . 2008-11-28 02:10 <DIR> d-------- c:\documents and settings\All Users\Application Data\MailFrontier
    2008-11-28 02:10 . 2008-07-09 09:05 75,248 --a------ c:\windows\zllsputility.exe
    2008-11-28 02:10 . 2004-04-27 04:40 11,264 --a------ c:\windows\system32\SpOrder.dll
    2008-11-28 02:10 . 2008-11-28 02:13 4,212 ---h----- c:\windows\system32\zllictbl.dat
    2008-11-28 02:09 . 2008-11-28 02:09 <DIR> d-------- c:\program files\Zone Labs
    2008-11-28 02:08 . 2008-11-28 11:11 <DIR> d-------- c:\windows\Internet Logs
    2008-11-28 01:51 . 2008-11-28 01:51 <DIR> d-------- c:\program files\Trend Micro
    2008-11-28 00:11 . 2008-11-28 00:11 <DIR> d-------- c:\program files\Recuva
    2008-11-27 23:52 . 2008-11-27 23:52 <DIR> d-------- c:\program files\Yahoo!
    2008-11-27 23:52 . 2008-11-27 23:52 <DIR> d-------- c:\program files\CCleaner
    2008-11-16 11:19 . 2008-11-16 11:19 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\SACore
    2008-11-16 00:51 . 2008-11-16 00:51 <DIR> d-------- C:\894cae369580a8ad97bf
    2008-11-15 10:50 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
    2008-11-04 12:02 . 2008-11-04 12:02 <DIR> d-------- c:\program files\Ares
    2008-11-03 21:18 . 2008-11-03 21:21 <DIR> d-------- c:\documents and settings\Kimberly\Application Data\LimeWire
    2008-11-03 20:52 . 2008-11-03 20:52 <DIR> d-------- c:\documents and settings\Kimberly\Application Data\Apple Computer
    2008-11-03 20:52 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
    2008-11-03 20:52 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
    2008-11-03 20:51 . 2008-11-03 20:52 <DIR> d-------- c:\program files\iTunes
    2008-11-03 20:51 . 2008-11-03 20:51 <DIR> d-------- c:\program files\iPod
    2008-11-03 20:51 . 2008-11-03 20:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    2008-11-03 20:50 . 2008-11-03 20:50 <DIR> d-------- c:\program files\Bonjour
    2008-11-03 20:48 . 2008-11-03 20:50 <DIR> d-------- c:\program files\QuickTime
    2008-11-03 20:48 . 2008-11-03 20:48 <DIR> d-------- c:\program files\Apple Software Update
    2008-11-03 20:48 . 2008-11-03 20:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
    2008-11-03 20:47 . 2008-10-01 13:01 32,000 --a------ c:\windows\system32\drivers\usbaapl.sys
    2008-11-03 20:46 . 2008-11-03 20:49 <DIR> d-------- c:\program files\Common Files\Apple
    2008-11-03 20:46 . 2008-11-03 20:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-01 07:58 2,124,444 ----a-w c:\windows\Internet Logs\tvDebug.zip
    2008-11-28 03:49 --------- d-----w c:\program files\Microsoft Works
    2008-11-28 03:49 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
    2008-11-28 02:49 --------- d-----w c:\program files\Google
    2008-11-16 05:52 14,336 ----a-w c:\windows\system32\svchost.exe
    2008-11-03 19:57 --------- d-----w c:\program files\SiteAdvisor
    2008-11-03 04:17 --------- d-----w c:\documents and settings\All Users\Application Data\SiteAdvisor
    2008-11-03 02:01 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
    2008-11-03 01:59 --------- d-----w c:\program files\McAfee
    2008-10-30 00:35 0 ----a-w c:\documents and settings\Kimberly\Application Data\wklnhst.dat
    2008-10-30 00:35 --------- d-----w c:\documents and settings\Kimberly\Application Data\Template
    2008-10-29 03:20 --------- d-----w c:\documents and settings\Kimberly\Application Data\OpenOffice.org
    2008-10-29 03:03 --------- d-----w c:\program files\OpenOffice.org 3
    2008-10-29 03:03 --------- d-----w c:\program files\JRE
    2008-10-29 03:03 --------- d-----w c:\program files\Java
    2008-10-29 03:02 --------- d-----w c:\program files\Common Files\Java
    2008-10-29 01:40 --------- d-----w c:\program files\Windows Media Connect 2
    2008-10-29 01:33 --------- d-----w c:\program files\Netflix
    2008-10-29 00:55 --------- d-----w c:\program files\MSXML 4.0
    2008-10-26 02:29 --------- d-----w c:\program files\Viewpoint
    2008-10-26 02:29 --------- d-----w c:\program files\AIM6
    2008-10-26 02:29 --------- d-----w c:\documents and settings\Kimberly\Application Data\acccore
    2008-10-26 02:29 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
    2008-10-26 02:28 --------- d-----w c:\program files\Common Files\AOL
    2008-10-26 02:28 --------- d-----w c:\documents and settings\All Users\Application Data\AOL OCP
    2008-10-26 02:28 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
    2008-10-26 02:28 --------- d-----w c:\documents and settings\All Users\Application Data\acccore
    2008-10-26 02:17 --------- d-----w c:\documents and settings\Kimberly\Application Data\InterVideo
    2008-10-26 01:46 --------- d--h--w c:\program files\InstallShield Installation Information
    2008-10-26 01:43 --------- d-----w c:\program files\Common Files\SNP2UVC
    2008-10-26 01:42 --------- d-----w c:\program files\Acer Incorporated
    2008-10-26 01:39 --------- d-----w c:\program files\Launch Manager
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-09-30 21:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
    2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
    2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
    2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
    2008-08-15 17:51 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "MSMSGS "= "c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LaunchApp "= "Alaunch" [X]
    "IgfxTray "= "c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
    "HotKeysCmds "= "c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
    "Persistence "= "c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
    "AzMixerSel "= "c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
    "SynTPEnh "= "c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-24 1044480]
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "IMJPMIG8.1 "= "c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
    "MSPY2002 "= "c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
    "PHIME2002ASync "= "c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
    "PHIME2002A "= "c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
    "mcagent_exe "= "c:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-04 582992]
    "LManager "= "c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-13 821768]
    "PLFSetL "= "c:\windows\PLFSetL.exe" [2007-07-05 94208]
    "eRecoveryService "= "c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-05-22 425984]
    "SunJavaUpdateSched "= "c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "QuickTime Task "= "c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
    "ZoneAlarm Client "= "c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
    "RTHDCPL "= "RTHDCPL.EXE" [2008-05-16 c:\windows\RTHDCPL.exe]

    c:\documents and settings\Kimberly\Start Menu\Programs\Startup\
    OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-06-04 114688]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
    \Shell\AutoRun\command - D:\LaunchU3.exe -a
    .
    Contents of the 'Scheduled Tasks' folder

    2008-11-04 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

    2008-08-15 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

    2008-08-15 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
    .
    .
    ------- Supplementary Scan -------
    .
    FireFox -: Profile - c:\documents and settings\Kimberly\Application Data\Mozilla\Firefox\Profiles\zn7gc23p.default\
    FireFox -: prefs.js - STARTUP.HOMEPAGE -
    FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
    FF -: plugin - c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
    FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
    FF -: plugin - c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
    FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-01 02:58:33
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    c:\program files\McAfee\SiteAdvisor\McSACore.exe
    c:\progra~1\McAfee\MSC\mcmscsvc.exe
    c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
    c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
    c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
    c:\program files\McAfee\MPF\MpfSrv.exe
    c:\program files\McAfee\MSK\msksrver.exe
    c:\program files\Viewpoint\Common\ViewpointService.exe
    c:\windows\system32\igfxsrvc.exe
    c:\windows\system32\igfxext.exe
    c:\program files\OpenOffice.org 3\program\soffice.exe
    c:\program files\OpenOffice.org 3\program\soffice.bin
    c:\program files\iPod\bin\iPodService.exe
    c:\docume~1\Kimberly\LOCALS~1\temp\RtkBtMnt.exe
    c:\progra~1\McAfee\MSC\mcuimgr.exe
    .
    **************************************************************************
    .
    Completion time: 2008-12-01 3:00:50 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-12-01 08:00:44
    ComboFix2.txt 2008-12-01 07:34:20

    Pre-Run: 103,710,814,208 bytes free
    Post-Run: 103,723,204,608 bytes free

    188 --- E O F --- 2008-11-03 03:03:08
     
  6. 2008/12/01
    finalmisery

    finalmisery Inactive Thread Starter

    Joined:
    2005/04/08
    Messages:
    42
    Likes Received:
    0
    I accidently posted the log twice.
     
    Last edited: 2008/12/01
  7. 2008/12/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Is there any change in connectivity? If not, please open the Device Manager and locate the Network Adapter. Right click the adapter and select Uninstall. OK the prompts and reboot.

    The network adapter should automatically be re-installed upon reboot, and hopefully the network connection icon in the Network Connections diaolg with it. Let me know if you can connect now.
     
  8. 2008/12/04
    finalmisery

    finalmisery Inactive Thread Starter

    Joined:
    2005/04/08
    Messages:
    42
    Likes Received:
    0
    I uninstalled the wireless adapter, but I'm not getting connection to the internet. The network icon isn't showing either.
     
  9. 2008/12/07
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Please download NetworkAdapterInfo and run it. When the log opens, save it and post it's contents here.

    Please download DDS and save it to your desktop.
    • Disable any script blocking protection
    • Double click dds.scr to run the tool.
    • When done, DDS.txt will open.
    • Click Yes at the next prompt for Optional Scan.
    • Save both reports to your desktop.
    ---------------------------------------------------

    Please include the contents of the following in your next reply:

    DDS.txt


    I may ask for the Attach.txt log later, so keep it handy.
     
  10. 2008/12/09
    finalmisery

    finalmisery Inactive Thread Starter

    Joined:
    2005/04/08
    Messages:
    42
    Likes Received:
    0
    Adapter Info Results:

    ~~~ Network Adapter Info report ~~~ by noahdfear


    IPAddress:

    end device properties




    DDS (Version 1.0) - NTFSx86
    Run by Kimberly at 22:42:32.75 on Tue 12/09/2008
    Internet Explorer: 7.0.5730.13

    ============== Running Processes ===============


    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=1008&m=aoa150
    mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=1008&m=aoa150
    uInternet Settings,ProxyOverride = *.local
    uURLSearchHooks: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
    BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
    BHO: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\progra~1\mcafee\msk\mcapbho.dll
    BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
    BHO: {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
    BHO: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptsn.dll
    BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    BHO: {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - c:\program files\zonealarmsb\bar\1.bin\SPYBLOCK.DLL
    TB: {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
    TB: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
    TB: {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - c:\program files\zonealarmsb\bar\1.bin\SPYBLOCK.DLL
    TB: {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
    TB: {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - c:\program files\zonealarmsb\bar\1.bin\SPYBLOCK.DLL
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    mRun: [LaunchApp] Alaunch
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [AzMixerSel] c:\program files\realtek\audio\installshield\AzMixerSel.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe "
    mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
    mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
    mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
    mRun: [mcagent_exe] c:\program files\mcafee.com\agent\mcagent.exe /runkey
    mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE
    mRun: [PLFSetL] c:\windows\PLFSetL.exe
    mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\eRAgent.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe "
    StartupFolder: c:\docume~1\kimberly\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\interv~1.lnk - c:\program files\intervideo\common\bin\WinCinemaMgr.exe
    IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-us\local\search.html
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
    IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
    Notify: igfxcui - igfxdev.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ============= SERVICES / DRIVERS ===============

    RSPR?S?C?P?P?01234RSPR?S?C?P?P?01234

    =============== Created Last 30 ================

    2008-12-01 02:06 161,792 a------- c:\windows\SWREG.exe
    2008-12-01 02:06 98,816 a------- c:\windows\sed.exe
    2008-11-28 04:30 <DIR> --d----- c:\windows\pss
    2008-11-28 02:14 262,176 a--sh--- c:\windows\system32\drivers\fidbox.dat
    2008-11-28 02:14 4,076 a--sh--- c:\windows\system32\drivers\fidbox.idx
    2008-11-28 02:13 <DIR> --d----- c:\program files\ZoneAlarmSB
    2008-11-28 02:10 4,212 ----h--- c:\windows\system32\zllictbl.dat
    2008-11-28 02:10 75,248 a------- c:\windows\zllsputility.exe
    2008-11-28 02:10 11,264 a------- c:\windows\system32\SpOrder.dll
    2008-11-28 02:09 <DIR> --d----- c:\program files\Zone Labs
    2008-11-28 02:08 <DIR> --d----- c:\windows\Internet Logs
    2008-11-28 01:51 <DIR> --d----- c:\program files\Trend Micro
    2008-11-27 23:52 <DIR> --d----- c:\program files\Yahoo!
    2008-11-27 23:52 <DIR> --d----- c:\program files\CCleaner
    2008-11-16 00:51 <DIR> --d----- C:\894cae369580a8ad97bf
    2008-11-15 10:50 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys

    ==================== Find3M ====================

    2008-11-16 00:52 14,336 a------- c:\windows\system32\svchost.exe
    2008-10-29 19:35 0 a------- c:\docume~1\kimberly\applic~1\wklnhst.dat
    2008-10-27 14:25 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
    2008-10-24 06:21 455,296 a------- c:\windows\system32\drivers\mrxsmb.sys
    2008-09-30 16:43 1,286,152 a------- c:\windows\system32\msxml4.dll
    2008-09-15 07:12 1,846,400 a------- c:\windows\system32\win32k.sys
    2008-08-15 12:51 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat

    ============= FINISH: 22:43:24.71 ===============

    Thank you for your time.
     
  11. 2008/12/09
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    RE: Network Adapter Info report :eek: That's not a good sign.
    Please export the following registry key to text and post it's contents here.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

    Let me know if you need guidance for doing that.
     
  12. 2008/12/10
    finalmisery

    finalmisery Inactive Thread Starter

    Joined:
    2005/04/08
    Messages:
    42
    Likes Received:
    0
    Nah, that was easy enough, i wasn't making any changes to the registry.

    here we go:

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
    Class Name: <NO CLASS>
    Last Write Time: 12/1/2008 - 2:35 AM
    Value 0
    Name: NV Hostname
    Type: REG_SZ
    Data: acer-6e40e97492

    Value 1
    Name: DataBasePath
    Type: REG_EXPAND_SZ
    Data: %SystemRoot%\System32\drivers\etc

    Value 2
    Name: ForwardBroadcasts
    Type: REG_DWORD
    Data: 0x0

    Value 3
    Name: IPEnableRouter
    Type: REG_DWORD
    Data: 0x0

    Value 4
    Name: Domain
    Type: REG_SZ
    Data:

    Value 5
    Name: Hostname
    Type: REG_SZ
    Data: acer-6e40e97492

    Value 6
    Name: DeadGWDetectDefault
    Type: REG_DWORD
    Data: 0x1


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters
    Class Name: <NO CLASS>
    Last Write Time: 10/26/2008 - 11:23 AM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\NdisWanIp
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: LLInterface
    Type: REG_SZ
    Data: WANARP

    Value 1
    Name: IpConfig
    Type: REG_MULTI_SZ
    Data: Tcpip\Parameters\Interfaces\{21BA8B9A-DDC6-4FA1-8C66-3A5987A267C3}
    Tcpip\Parameters\Interfaces\{71E173C0-ACB2-46C3-A829-CC37F70D5A89}

    Value 2
    Name: NumInterfaces
    Type: REG_DWORD
    Data: 0x2

    Value 3
    Name: IpInterfaces
    Type: REG_BINARY
    Data:
    00000000 9a 8b ba 21 c6 dd a1 4f - 8c 66 3a 59 87 a2 67 c3 ..º!ÆáO.f:Y.¢gÃ
    00000010 c0 73 e1 71 b2 ac c3 46 - a8 29 cc 37 f7 0d 5a 89 Àsáq²¬ÃƒF¨)ÃŒ7÷.Z.



    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{27EC6F16-42C6-4707-ACE7-664B357E5206}
    Class Name: <NO CLASS>
    Last Write Time: 10/26/2008 - 11:23 AM
    Value 0
    Name: LLInterface
    Type: REG_SZ
    Data:

    Value 1
    Name: IpConfig
    Type: REG_MULTI_SZ
    Data: Tcpip\Parameters\Interfaces\{27EC6F16-42C6-4707-ACE7-664B357E5206}


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{57CCE9DB-24C5-4022-92BA-1ECA9E55CD31}
    Class Name: <NO CLASS>
    Last Write Time: 10/26/2008 - 11:23 AM
    Value 0
    Name: LLInterface
    Type: REG_SZ
    Data:

    Value 1
    Name: IpConfig
    Type: REG_MULTI_SZ
    Data: Tcpip\Parameters\Interfaces\{57CCE9DB-24C5-4022-92BA-1ECA9E55CD31}


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{7A21CD21-5F00-4990-AEA2-90A026FC6F1A}
    Class Name: <NO CLASS>
    Last Write Time: 10/26/2008 - 11:22 AM
    Value 0
    Name: LLInterface
    Type: REG_SZ
    Data:

    Value 1
    Name: IpConfig
    Type: REG_MULTI_SZ
    Data: Tcpip\Parameters\Interfaces\{7A21CD21-5F00-4990-AEA2-90A026FC6F1A}


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DNSRegisteredAdapters
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces
    Class Name: <NO CLASS>
    Last Write Time: 10/26/2008 - 11:23 AM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{21BA8B9A-DDC6-4FA1-8C66-3A5987A267C3}
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: UseZeroBroadcast
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: EnableDHCP
    Type: REG_DWORD
    Data: 0x0

    Value 2
    Name: IPAddress
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 3
    Name: SubnetMask
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 4
    Name: DefaultGateway
    Type: REG_MULTI_SZ
    Data:

    Value 5
    Name: EnableDeadGWDetect
    Type: REG_DWORD
    Data: 0x1

    Value 6
    Name: DontAddDefaultGateway
    Type: REG_DWORD
    Data: 0x0


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{27EC6F16-42C6-4707-ACE7-664B357E5206}
    Class Name: <NO CLASS>
    Last Write Time: 12/4/2008 - 4:25 PM
    Value 0
    Name: UseZeroBroadcast
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: EnableDeadGWDetect
    Type: REG_DWORD
    Data: 0x1

    Value 2
    Name: EnableDHCP
    Type: REG_DWORD
    Data: 0x1

    Value 3
    Name: IPAddress
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 4
    Name: SubnetMask
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 5
    Name: DefaultGateway
    Type: REG_MULTI_SZ
    Data:

    Value 6
    Name: DefaultGatewayMetric
    Type: REG_MULTI_SZ
    Data:

    Value 7
    Name: NameServer
    Type: REG_SZ
    Data:

    Value 8
    Name: Domain
    Type: REG_SZ
    Data:

    Value 9
    Name: RegistrationEnabled
    Type: REG_DWORD
    Data: 0x1

    Value 10
    Name: RegisterAdapterName
    Type: REG_DWORD
    Data: 0x0

    Value 11
    Name: TCPAllowedPorts
    Type: REG_MULTI_SZ
    Data:

    Value 12
    Name: UDPAllowedPorts
    Type: REG_MULTI_SZ
    Data:

    Value 13
    Name: RawIPAllowedProtocols
    Type: REG_MULTI_SZ
    Data:

    Value 14
    Name: NTEContextList
    Type: REG_MULTI_SZ
    Data:

    Value 15
    Name: DhcpClassIdBin
    Type: REG_BINARY
    Data:

    Value 16
    Name: DhcpServer
    Type: REG_SZ
    Data: 255.255.255.255

    Value 17
    Name: Lease
    Type: REG_DWORD
    Data: 0xe10

    Value 18
    Name: LeaseObtainedTime
    Type: REG_DWORD
    Data: 0x491fb4ef

    Value 19
    Name: T1
    Type: REG_DWORD
    Data: 0x491fbbf7

    Value 20
    Name: T2
    Type: REG_DWORD
    Data: 0x491fc13d

    Value 21
    Name: LeaseTerminatesTime
    Type: REG_DWORD
    Data: 0x491fc2ff

    Value 22
    Name: AddressType
    Type: REG_DWORD
    Data: 0x0

    Value 23
    Name: IsServerNapAware
    Type: REG_DWORD
    Data: 0x0

    Value 24
    Name: DisableDynamicUpdate
    Type: REG_DWORD
    Data: 0x0


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{57CCE9DB-24C5-4022-92BA-1ECA9E55CD31}
    Class Name: <NO CLASS>
    Last Write Time: 11/27/2008 - 9:47 PM
    Value 0
    Name: UseZeroBroadcast
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: EnableDeadGWDetect
    Type: REG_DWORD
    Data: 0x1

    Value 2
    Name: EnableDHCP
    Type: REG_DWORD
    Data: 0x1

    Value 3
    Name: IPAddress
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 4
    Name: SubnetMask
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 5
    Name: DefaultGateway
    Type: REG_MULTI_SZ
    Data:

    Value 6
    Name: DefaultGatewayMetric
    Type: REG_MULTI_SZ
    Data:

    Value 7
    Name: NameServer
    Type: REG_SZ
    Data:

    Value 8
    Name: Domain
    Type: REG_SZ
    Data:

    Value 9
    Name: RegistrationEnabled
    Type: REG_DWORD
    Data: 0x1

    Value 10
    Name: RegisterAdapterName
    Type: REG_DWORD
    Data: 0x0

    Value 11
    Name: TCPAllowedPorts
    Type: REG_MULTI_SZ
    Data:

    Value 12
    Name: UDPAllowedPorts
    Type: REG_MULTI_SZ
    Data:

    Value 13
    Name: RawIPAllowedProtocols
    Type: REG_MULTI_SZ
    Data:

    Value 14
    Name: NTEContextList
    Type: REG_MULTI_SZ
    Data: 0x00000004

    Value 15
    Name: DhcpClassIdBin
    Type: REG_BINARY
    Data:

    Value 16
    Name: AddressType
    Type: REG_DWORD
    Data: 0x0

    Value 17
    Name: DisableDynamicUpdate
    Type: REG_DWORD
    Data: 0x0


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{71E173C0-ACB2-46C3-A829-CC37F70D5A89}
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: UseZeroBroadcast
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: EnableDHCP
    Type: REG_DWORD
    Data: 0x0

    Value 2
    Name: IPAddress
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 3
    Name: SubnetMask
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 4
    Name: DefaultGateway
    Type: REG_MULTI_SZ
    Data:

    Value 5
    Name: EnableDeadGWDetect
    Type: REG_DWORD
    Data: 0x1

    Value 6
    Name: DontAddDefaultGateway
    Type: REG_DWORD
    Data: 0x0


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7A21CD21-5F00-4990-AEA2-90A026FC6F1A}
    Class Name: <NO CLASS>
    Last Write Time: 12/4/2008 - 4:26 PM
    Value 0
    Name: UseZeroBroadcast
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: EnableDeadGWDetect
    Type: REG_DWORD
    Data: 0x1

    Value 2
    Name: EnableDHCP
    Type: REG_DWORD
    Data: 0x1

    Value 3
    Name: IPAddress
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 4
    Name: SubnetMask
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 5
    Name: DefaultGateway
    Type: REG_MULTI_SZ
    Data:

    Value 6
    Name: DefaultGatewayMetric
    Type: REG_MULTI_SZ
    Data:

    Value 7
    Name: NameServer
    Type: REG_SZ
    Data:

    Value 8
    Name: Domain
    Type: REG_SZ
    Data:

    Value 9
    Name: RegistrationEnabled
    Type: REG_DWORD
    Data: 0x1

    Value 10
    Name: RegisterAdapterName
    Type: REG_DWORD
    Data: 0x0

    Value 11
    Name: TCPAllowedPorts
    Type: REG_MULTI_SZ
    Data:

    Value 12
    Name: UDPAllowedPorts
    Type: REG_MULTI_SZ
    Data:

    Value 13
    Name: RawIPAllowedProtocols
    Type: REG_MULTI_SZ
    Data:

    Value 14
    Name: NTEContextList
    Type: REG_MULTI_SZ
    Data: 0x00000002

    Value 15
    Name: DhcpClassIdBin
    Type: REG_BINARY
    Data:

    Value 16
    Name: DhcpIPAddress
    Type: REG_SZ
    Data: 76.127.232.25

    Value 17
    Name: DhcpSubnetMask
    Type: REG_SZ
    Data: 255.255.248.0

    Value 18
    Name: DhcpServer
    Type: REG_SZ
    Data: 68.87.71.8

    Value 19
    Name: Lease
    Type: REG_DWORD
    Data: 0x53ab4

    Value 20
    Name: LeaseObtainedTime
    Type: REG_DWORD
    Data: 0x4903dda6

    Value 21
    Name: T1
    Type: REG_DWORD
    Data: 0x49067b00

    Value 22
    Name: T2
    Type: REG_DWORD
    Data: 0x49087103

    Value 23
    Name: LeaseTerminatesTime
    Type: REG_DWORD
    Data: 0x4909185a

    Value 24
    Name: AddressType
    Type: REG_DWORD
    Data: 0x0

    Value 25
    Name: IsServerNapAware
    Type: REG_DWORD
    Data: 0x0

    Value 26
    Name: DisableDynamicUpdate
    Type: REG_DWORD
    Data: 0x0


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\PersistentRoutes
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Winsock
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: UseDelayedAcceptance
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: HelperDllName
    Type: REG_EXPAND_SZ
    Data: %SystemRoot%\System32\wshtcpip.dll

    Value 2
    Name: MaxSockAddrLength
    Type: REG_DWORD
    Data: 0x10

    Value 3
    Name: MinSockAddrLength
    Type: REG_DWORD
    Data: 0x10

    Value 4
    Name: Mapping
    Type: REG_BINARY
    Data:
    00000000 0b 00 00 00 03 00 00 00 - 02 00 00 00 01 00 00 00 ................
    00000010 06 00 00 00 02 00 00 00 - 01 00 00 00 00 00 00 00 ................
    00000020 02 00 00 00 00 00 00 00 - 06 00 00 00 00 00 00 00 ................
    00000030 00 00 00 00 06 00 00 00 - 00 00 00 00 01 00 00 00 ................
    00000040 06 00 00 00 02 00 00 00 - 02 00 00 00 11 00 00 00 ................
    00000050 02 00 00 00 02 00 00 00 - 00 00 00 00 02 00 00 00 ................
    00000060 00 00 00 00 11 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000070 11 00 00 00 00 00 00 00 - 02 00 00 00 11 00 00 00 ................
    00000080 02 00 00 00 03 00 00 00 - 00 00 00 00 ............
     
  13. 2008/12/10
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    First, export that same key again, but this time save it as a reg file.
    Now, delete the following 2 keys.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7A21CD21-5F00-4990-AEA2-90A026FC6F1A}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{7A21CD21-5F00-4990-AEA2-90A026FC6F1A}

    Now open the Device Manager, expand Network Adapters, then right click on your adapter and select Uninstall. OK any prompts.
    Restart the computer and see if there's any change.
     
  14. 2008/12/11
    finalmisery

    finalmisery Inactive Thread Starter

    Joined:
    2005/04/08
    Messages:
    42
    Likes Received:
    0
    No, no change at all. :eek:
     
  15. 2008/12/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Please export the parameters key to text again and post it.
     
  16. 2008/12/11
    finalmisery

    finalmisery Inactive Thread Starter

    Joined:
    2005/04/08
    Messages:
    42
    Likes Received:
    0
    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
    Class Name: <NO CLASS>
    Last Write Time: 12/1/2008 - 2:35 AM
    Value 0
    Name: NV Hostname
    Type: REG_SZ
    Data: acer-6e40e97492

    Value 1
    Name: DataBasePath
    Type: REG_EXPAND_SZ
    Data: %SystemRoot%\System32\drivers\etc

    Value 2
    Name: ForwardBroadcasts
    Type: REG_DWORD
    Data: 0x0

    Value 3
    Name: IPEnableRouter
    Type: REG_DWORD
    Data: 0x0

    Value 4
    Name: Domain
    Type: REG_SZ
    Data:

    Value 5
    Name: Hostname
    Type: REG_SZ
    Data: acer-6e40e97492

    Value 6
    Name: DeadGWDetectDefault
    Type: REG_DWORD
    Data: 0x1


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters
    Class Name: <NO CLASS>
    Last Write Time: 12/11/2008 - 1:49 AM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\NdisWanIp
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: LLInterface
    Type: REG_SZ
    Data: WANARP

    Value 1
    Name: IpConfig
    Type: REG_MULTI_SZ
    Data: Tcpip\Parameters\Interfaces\{21BA8B9A-DDC6-4FA1-8C66-3A5987A267C3}
    Tcpip\Parameters\Interfaces\{71E173C0-ACB2-46C3-A829-CC37F70D5A89}

    Value 2
    Name: NumInterfaces
    Type: REG_DWORD
    Data: 0x2

    Value 3
    Name: IpInterfaces
    Type: REG_BINARY
    Data:
    00000000 9a 8b ba 21 c6 dd a1 4f - 8c 66 3a 59 87 a2 67 c3 ..º!ÆáO.f:Y.¢gÃ
    00000010 c0 73 e1 71 b2 ac c3 46 - a8 29 cc 37 f7 0d 5a 89 Àsáq²¬ÃƒF¨)ÃŒ7÷.Z.



    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{27EC6F16-42C6-4707-ACE7-664B357E5206}
    Class Name: <NO CLASS>
    Last Write Time: 10/26/2008 - 11:23 AM
    Value 0
    Name: LLInterface
    Type: REG_SZ
    Data:

    Value 1
    Name: IpConfig
    Type: REG_MULTI_SZ
    Data: Tcpip\Parameters\Interfaces\{27EC6F16-42C6-4707-ACE7-664B357E5206}


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{57CCE9DB-24C5-4022-92BA-1ECA9E55CD31}
    Class Name: <NO CLASS>
    Last Write Time: 10/26/2008 - 11:23 AM
    Value 0
    Name: LLInterface
    Type: REG_SZ
    Data:

    Value 1
    Name: IpConfig
    Type: REG_MULTI_SZ
    Data: Tcpip\Parameters\Interfaces\{57CCE9DB-24C5-4022-92BA-1ECA9E55CD31}


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DNSRegisteredAdapters
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces
    Class Name: <NO CLASS>
    Last Write Time: 12/11/2008 - 1:48 AM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{21BA8B9A-DDC6-4FA1-8C66-3A5987A267C3}
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: UseZeroBroadcast
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: EnableDHCP
    Type: REG_DWORD
    Data: 0x0

    Value 2
    Name: IPAddress
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 3
    Name: SubnetMask
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 4
    Name: DefaultGateway
    Type: REG_MULTI_SZ
    Data:

    Value 5
    Name: EnableDeadGWDetect
    Type: REG_DWORD
    Data: 0x1

    Value 6
    Name: DontAddDefaultGateway
    Type: REG_DWORD
    Data: 0x0


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{27EC6F16-42C6-4707-ACE7-664B357E5206}
    Class Name: <NO CLASS>
    Last Write Time: 12/4/2008 - 4:25 PM
    Value 0
    Name: UseZeroBroadcast
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: EnableDeadGWDetect
    Type: REG_DWORD
    Data: 0x1

    Value 2
    Name: EnableDHCP
    Type: REG_DWORD
    Data: 0x1

    Value 3
    Name: IPAddress
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 4
    Name: SubnetMask
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 5
    Name: DefaultGateway
    Type: REG_MULTI_SZ
    Data:

    Value 6
    Name: DefaultGatewayMetric
    Type: REG_MULTI_SZ
    Data:

    Value 7
    Name: NameServer
    Type: REG_SZ
    Data:

    Value 8
    Name: Domain
    Type: REG_SZ
    Data:

    Value 9
    Name: RegistrationEnabled
    Type: REG_DWORD
    Data: 0x1

    Value 10
    Name: RegisterAdapterName
    Type: REG_DWORD
    Data: 0x0

    Value 11
    Name: TCPAllowedPorts
    Type: REG_MULTI_SZ
    Data:

    Value 12
    Name: UDPAllowedPorts
    Type: REG_MULTI_SZ
    Data:

    Value 13
    Name: RawIPAllowedProtocols
    Type: REG_MULTI_SZ
    Data:

    Value 14
    Name: NTEContextList
    Type: REG_MULTI_SZ
    Data:

    Value 15
    Name: DhcpClassIdBin
    Type: REG_BINARY
    Data:

    Value 16
    Name: DhcpServer
    Type: REG_SZ
    Data: 255.255.255.255

    Value 17
    Name: Lease
    Type: REG_DWORD
    Data: 0xe10

    Value 18
    Name: LeaseObtainedTime
    Type: REG_DWORD
    Data: 0x491fb4ef

    Value 19
    Name: T1
    Type: REG_DWORD
    Data: 0x491fbbf7

    Value 20
    Name: T2
    Type: REG_DWORD
    Data: 0x491fc13d

    Value 21
    Name: LeaseTerminatesTime
    Type: REG_DWORD
    Data: 0x491fc2ff

    Value 22
    Name: AddressType
    Type: REG_DWORD
    Data: 0x0

    Value 23
    Name: IsServerNapAware
    Type: REG_DWORD
    Data: 0x0

    Value 24
    Name: DisableDynamicUpdate
    Type: REG_DWORD
    Data: 0x0


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{57CCE9DB-24C5-4022-92BA-1ECA9E55CD31}
    Class Name: <NO CLASS>
    Last Write Time: 11/27/2008 - 9:47 PM
    Value 0
    Name: UseZeroBroadcast
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: EnableDeadGWDetect
    Type: REG_DWORD
    Data: 0x1

    Value 2
    Name: EnableDHCP
    Type: REG_DWORD
    Data: 0x1

    Value 3
    Name: IPAddress
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 4
    Name: SubnetMask
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 5
    Name: DefaultGateway
    Type: REG_MULTI_SZ
    Data:

    Value 6
    Name: DefaultGatewayMetric
    Type: REG_MULTI_SZ
    Data:

    Value 7
    Name: NameServer
    Type: REG_SZ
    Data:

    Value 8
    Name: Domain
    Type: REG_SZ
    Data:

    Value 9
    Name: RegistrationEnabled
    Type: REG_DWORD
    Data: 0x1

    Value 10
    Name: RegisterAdapterName
    Type: REG_DWORD
    Data: 0x0

    Value 11
    Name: TCPAllowedPorts
    Type: REG_MULTI_SZ
    Data:

    Value 12
    Name: UDPAllowedPorts
    Type: REG_MULTI_SZ
    Data:

    Value 13
    Name: RawIPAllowedProtocols
    Type: REG_MULTI_SZ
    Data:

    Value 14
    Name: NTEContextList
    Type: REG_MULTI_SZ
    Data: 0x00000004

    Value 15
    Name: DhcpClassIdBin
    Type: REG_BINARY
    Data:

    Value 16
    Name: AddressType
    Type: REG_DWORD
    Data: 0x0

    Value 17
    Name: DisableDynamicUpdate
    Type: REG_DWORD
    Data: 0x0


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{71E173C0-ACB2-46C3-A829-CC37F70D5A89}
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: UseZeroBroadcast
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: EnableDHCP
    Type: REG_DWORD
    Data: 0x0

    Value 2
    Name: IPAddress
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 3
    Name: SubnetMask
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 4
    Name: DefaultGateway
    Type: REG_MULTI_SZ
    Data:

    Value 5
    Name: EnableDeadGWDetect
    Type: REG_DWORD
    Data: 0x1

    Value 6
    Name: DontAddDefaultGateway
    Type: REG_DWORD
    Data: 0x0


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\PersistentRoutes
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Winsock
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: UseDelayedAcceptance
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: HelperDllName
    Type: REG_EXPAND_SZ
    Data: %SystemRoot%\System32\wshtcpip.dll

    Value 2
    Name: MaxSockAddrLength
    Type: REG_DWORD
    Data: 0x10

    Value 3
    Name: MinSockAddrLength
    Type: REG_DWORD
    Data: 0x10

    Value 4
    Name: Mapping
    Type: REG_BINARY
    Data:
    00000000 0b 00 00 00 03 00 00 00 - 02 00 00 00 01 00 00 00 ................
    00000010 06 00 00 00 02 00 00 00 - 01 00 00 00 00 00 00 00 ................
    00000020 02 00 00 00 00 00 00 00 - 06 00 00 00 00 00 00 00 ................
    00000030 00 00 00 00 06 00 00 00 - 00 00 00 00 01 00 00 00 ................
    00000040 06 00 00 00 02 00 00 00 - 02 00 00 00 11 00 00 00 ................
    00000050 02 00 00 00 02 00 00 00 - 00 00 00 00 02 00 00 00 ................
    00000060 00 00 00 00 11 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000070 11 00 00 00 00 00 00 00 - 02 00 00 00 11 00 00 00 ................
    00000080 02 00 00 00 03 00 00 00 - 00 00 00 00 ............


    There are definitely differences between the two...
     
    Last edited: 2008/12/11
  17. 2008/12/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Please delete the following 4 keys.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{27EC6F16-42C6-4707-ACE7-664B357E5206}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{57CCE9DB-24C5-4022-92BA-1ECA9E55CD31}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{27EC6F16-42C6-4707-ACE7-664B357E5206}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{57CCE9DB-24C5-4022-92BA-1ECA9E55CD31}

    Uninstall all Network Adapters in the Device Manager and reboot.
    Get me a new export after restart.
     
  18. 2008/12/24
    finalmisery

    finalmisery Inactive Thread Starter

    Joined:
    2005/04/08
    Messages:
    42
    Likes Received:
    0
    sorry about taking so long, been busy with xmas matters. sure you might be too.

    um, the four keys you posted were actually two keys that were duplicated once. did you want me to delete all four keys under the parameters?
     
  19. 2008/12/27
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    They are 4 different keys. 2 under the parameters\adapters path, 2 under the parameters\interfaces path. Yes, delete all 4 keys.
     
  20. 2008/12/28
    finalmisery

    finalmisery Inactive Thread Starter

    Joined:
    2005/04/08
    Messages:
    42
    Likes Received:
    0
    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
    Class Name: <NO CLASS>
    Last Write Time: 12/1/2008 - 2:35 AM
    Value 0
    Name: NV Hostname
    Type: REG_SZ
    Data: acer-6e40e97492

    Value 1
    Name: DataBasePath
    Type: REG_EXPAND_SZ
    Data: %SystemRoot%\System32\drivers\etc

    Value 2
    Name: ForwardBroadcasts
    Type: REG_DWORD
    Data: 0x0

    Value 3
    Name: IPEnableRouter
    Type: REG_DWORD
    Data: 0x0

    Value 4
    Name: Domain
    Type: REG_SZ
    Data:

    Value 5
    Name: Hostname
    Type: REG_SZ
    Data: acer-6e40e97492

    Value 6
    Name: DeadGWDetectDefault
    Type: REG_DWORD
    Data: 0x1


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters
    Class Name: <NO CLASS>
    Last Write Time: 12/28/2008 - 5:26 PM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\NdisWanIp
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: LLInterface
    Type: REG_SZ
    Data: WANARP

    Value 1
    Name: IpConfig
    Type: REG_MULTI_SZ
    Data: Tcpip\Parameters\Interfaces\{21BA8B9A-DDC6-4FA1-8C66-3A5987A267C3}
    Tcpip\Parameters\Interfaces\{71E173C0-ACB2-46C3-A829-CC37F70D5A89}

    Value 2
    Name: NumInterfaces
    Type: REG_DWORD
    Data: 0x2

    Value 3
    Name: IpInterfaces
    Type: REG_BINARY
    Data:
    00000000 9a 8b ba 21 c6 dd a1 4f - 8c 66 3a 59 87 a2 67 c3 ..º!ÆáO.f:Y.¢gÃ
    00000010 c0 73 e1 71 b2 ac c3 46 - a8 29 cc 37 f7 0d 5a 89 Àsáq²¬ÃƒF¨)ÃŒ7÷.Z.



    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DNSRegisteredAdapters
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces
    Class Name: <NO CLASS>
    Last Write Time: 12/24/2008 - 11:23 AM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{21BA8B9A-DDC6-4FA1-8C66-3A5987A267C3}
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: UseZeroBroadcast
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: EnableDHCP
    Type: REG_DWORD
    Data: 0x0

    Value 2
    Name: IPAddress
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 3
    Name: SubnetMask
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 4
    Name: DefaultGateway
    Type: REG_MULTI_SZ
    Data:

    Value 5
    Name: EnableDeadGWDetect
    Type: REG_DWORD
    Data: 0x1

    Value 6
    Name: DontAddDefaultGateway
    Type: REG_DWORD
    Data: 0x0


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{71E173C0-ACB2-46C3-A829-CC37F70D5A89}
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: UseZeroBroadcast
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: EnableDHCP
    Type: REG_DWORD
    Data: 0x0

    Value 2
    Name: IPAddress
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 3
    Name: SubnetMask
    Type: REG_MULTI_SZ
    Data: 0.0.0.0

    Value 4
    Name: DefaultGateway
    Type: REG_MULTI_SZ
    Data:

    Value 5
    Name: EnableDeadGWDetect
    Type: REG_DWORD
    Data: 0x1

    Value 6
    Name: DontAddDefaultGateway
    Type: REG_DWORD
    Data: 0x0


    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\PersistentRoutes
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM

    Key Name: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Winsock
    Class Name: <NO CLASS>
    Last Write Time: 8/15/2008 - 12:33 PM
    Value 0
    Name: UseDelayedAcceptance
    Type: REG_DWORD
    Data: 0x0

    Value 1
    Name: HelperDllName
    Type: REG_EXPAND_SZ
    Data: %SystemRoot%\System32\wshtcpip.dll

    Value 2
    Name: MaxSockAddrLength
    Type: REG_DWORD
    Data: 0x10

    Value 3
    Name: MinSockAddrLength
    Type: REG_DWORD
    Data: 0x10

    Value 4
    Name: Mapping
    Type: REG_BINARY
    Data:
    00000000 0b 00 00 00 03 00 00 00 - 02 00 00 00 01 00 00 00 ................
    00000010 06 00 00 00 02 00 00 00 - 01 00 00 00 00 00 00 00 ................
    00000020 02 00 00 00 00 00 00 00 - 06 00 00 00 00 00 00 00 ................
    00000030 00 00 00 00 06 00 00 00 - 00 00 00 00 01 00 00 00 ................
    00000040 06 00 00 00 02 00 00 00 - 02 00 00 00 11 00 00 00 ................
    00000050 02 00 00 00 02 00 00 00 - 00 00 00 00 02 00 00 00 ................
    00000060 00 00 00 00 11 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000070 11 00 00 00 00 00 00 00 - 02 00 00 00 11 00 00 00 ................
    00000080 02 00 00 00 03 00 00 00 - 00 00 00 00 ............
     
  21. 2008/12/28
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    It doesn't appear the adapter reinstalled. Lets try something else. You'll need to create and obtain the necessary files then transfer to the affected machine.

    Download and install SubInACL from Microsoft.

    Close out all other programs and open windows.

    Highlight and copy the contents of the code box below.
    Code:
    cd /d  "%ProgramFiles%\Windows Resource Kits\Tools "
    subinacl /subkeyreg HKEY_LOCAL_MACHINE\Software /owner=administrators /grant=administrators=f /grant=system=f /grant=RESTRICTED=r
    subinacl /subkeyreg HKEY_LOCAL_MACHINE\System /owner=administrators /grant=administrators=f /grant=system=f /grant=RESTRICTED=r
    subinacl /subkeyreg HKEY_CURRENT_USER /owner=administrators /grant=administrators=f /grant=system=f /grant=RESTRICTED=r
    subinacl /subkeyreg HKEY_CLASSES_ROOT /owner=administrators /grant=administrators=f /grant=system=f /grant=RESTRICTED=r
    subinacl /subdirectories %SystemDrive% /grant=administrators=f /grant=system=f
    subinacl /subdirectories %windir%\*.* /grant=administrators=f /grant=system=f
    exit
    cls
    
    Click Start>Run and type cmd then hit enter to open a command window.
    Right click in the command window and select paste.
    It will take a while for the commands to process, so please be patient.
    The command window should close on it's own when finished.
    Reboot for the changes to take effect.


    After restarting, check the Device Manager to see if the adapter is installed. If not, click the uppermost entry (the one that represents the computer) then click Action>Scan for hardware changes. If the adapter is not detected, you'll need to run the Add Hardware Wizard in the Control Panel.

    If after restart the adapter is present but still not working, uninstall it once more then reboot to see if it reinstalls.

    If still not connecting or showing in Network Connections, click Create a new connection>Connect to the Internet>Set up my connection manually>Connect using broadband connection that is always on>Finish
    Now check the properties of the connection to verify that the correct adapter is in use.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.