Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Cant access security center - antivirus wont update - multiple bsod


  • Please log in to reply

#61
Bhinsz84

Bhinsz84

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\Administrator.BRIANS>nslookup www.complete-cs.com
*** Can't find server name for address 192.168.1.1: Non-existent domain
Server: cns.cmc.co.denver.comcast.net
Address: 68.87.85.102

Non-authoritative answer:
Name: www.complete-cs.com
Address: 74.208.137.228


C:\Documents and Settings\Administrator.BRIANS>
  • 0

Advertisements


#62
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Looks like dns are at least able to resolve an IP address.

Before I seek expert technical advice on this.

Try uninstalling your AV/Firewall and see if you get internet connection.

Tell me how you get on.
  • 0

#63
Bhinsz84

Bhinsz84

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
still nothing - my brother is working on this with me as well - we have gone so far as to reset the router back to origional state. still no connection on that end either.
  • 0

#64
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Okay, I think it's time I sort some advice on this but one last thing before I do. I think it's an outside chance but might as well try it.

Renew DNS client registration using the ipconfig command

Open Command Prompt.

Type:

ipconfig /registerdns
  • 0

#65
Bhinsz84

Bhinsz84

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
typed it in and it came back with "windows ip confifuration"

registration of te dns resource records for all adapters of this computer has been initiated. any errors will be reported in the event viewer in 15 minutes

nothing came up after 30 minutes. no change in connectivity.

also just to note some changed I have made in trying to fix my problem - i went to the advanced tcp/ip settings, options tab and selected tcpip filtering properties. i changed all three ports from "permit only" to "permit all". I did this with both of my connections and no change happened.

I have two connections - one is local area connection two - packets are being sent and recieved through this - i believe this is my home network and the packets sent and recieved are the other computers that connect to this system

the other connection is called 1394 connection 2. this one has no packets being send / recieved. I believe this is my internet connection. when i click on the two computers on the task bar that show this connection, and click the support tab, there is no address type, ip address, subnet mask or default gateway. when i click repair on this conection, it brings up an error that says tcpip is not enabled on this connection. however when i go to the properties tab for it, the internet protocol tcpip box is checked, and if i go to the properties tab for this both the obtain ip adderss / dns server address automatically bubles are checked. when i clicked "install" under the tcpip selection, it brings up a menu with "client, service and protocol" - I installed protocol with no change.

I am going to try to see if i can get the troubled computer's setings to match what I have on this one. Any other suggestions are welcome.

Thanks again for the hand.
  • 0

#66
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Meantime I will see if I can get some advice on this.
  • 0

#67
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello again Bhinsz84,

The possible Virut and Rootkit infections are raising concern.

Let's try a MBR fix through the Recovery Console that will have been installed when you ran ComboFix.

Logon to the Recovery Console.

1. Restart your computer.
2. Before Windows loads, you will be prompted to choose which Operating System to start.

Posted Image

Use the up and down arrow key to select Microsoft Windows Recovery Console
4. You must enter which Windows installation to log onto. Type 1 and press 'Enter'.
5. At the C:\Windows prompt, type the following bolded entry, and press 'Enter':

fixmbr

Reboot your machine.

After that re-run ComboFix. You will need to download a new version.

Download ComboFix from one of these locations:

Link 1
Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop

Post the log back here. Also, when you come back please tell me if you have run Drive Cleaner Pro.
  • 0

#68
Bhinsz84

Bhinsz84

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
I may have run DCP - but am not sure at this point since we have run a boatload of applications - if I have not done it with you or as part of the malware cleaning guide there is still a chance that I have run it since the program is saved on my desktop. the file was created on april 16th so there is a good chance that I have run it.

on running combofix - got the error again for PEV.cfxxe - a windows crash error, not bsod. this happened on stage four or five. i have a screenshot of the error if you want it. i dont know how to retrieve it but there was alot of information in the error log that gets reported to windows. I am sure you know how if you need this info

on combofix restart an error appeared " swreg.cfxxe - application error" application failed to initialize properly ( oxc ooooo7b)


combofix log is too big to post all in one - i will get it all in over multiple posts
  • 0

#69
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

combofix log is too big to post all in one - i will get it all in over multiple posts


Just save it to notepad and attach it, might be easier for you. :)
  • 0

#70
Bhinsz84

Bhinsz84

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
well i guess it wont let me do that either - its pretty darn big - i have attached it, if you dont want to open it i dont blame you - is there another way i can get it in here as text ?Attached File  log.txt   656.24KB   103 downloads

i did transfer this to my laptop and scaned it before posting it here.

Edited by Bhinsz84, 10 May 2011 - 10:53 PM.

  • 0

Advertisements


#71
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello Bhinsz84,

Got it. The reason it's so long is because of the reinstallation of SP3.

Nothing jumping out at me.

Please run aswMBR again.

Double click the aswMBR.exe to run it

Posted ImageClick the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply.
  • 0

#72
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Further to my last post.

Please also do this:

Please download Event Viewer by Vino Rosso and save it to your desktop.
  • Double-click VEW.exe
  • Under 'Select log to query', Check the System box
  • Under 'Select type to list', Check Error & Warning boxes
  • Under Number or date of Events > 'Number of events' Type 20 in the 1 to 20 box
  • Click the Run button.
Notepad will open with a log. Please post the log back here.
  • 0

#73
Bhinsz84

Bhinsz84

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
Vino's Event Viewer v01c run on Windows XP in English
Report run at 11/05/2011 6:02:51 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 11/05/2011 5:59:35 AM
Type: error Category: 0
Event: 29 Source: W32Time
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 29 minutes. NtpClient has no source of accurate time.

Log: 'System' Date/Time: 11/05/2011 5:59:35 AM
Type: error Category: 0
Event: 17 Source: W32Time
Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Log: 'System' Date/Time: 11/05/2011 5:44:46 AM
Type: error Category: 0
Event: 7024 Source: Service Control Manager
The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).

Log: 'System' Date/Time: 11/05/2011 5:44:35 AM
Type: error Category: 0
Event: 29 Source: W32Time
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time.

Log: 'System' Date/Time: 11/05/2011 5:44:35 AM
Type: error Category: 0
Event: 17 Source: W32Time
Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Log: 'System' Date/Time: 11/05/2011 5:44:35 AM
Type: error Category: 0
Event: 29 Source: W32Time
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time.

Log: 'System' Date/Time: 11/05/2011 5:44:35 AM
Type: error Category: 0
Event: 17 Source: W32Time
Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Log: 'System' Date/Time: 11/05/2011 2:27:32 AM
Type: error Category: 0
Event: 7034 Source: Service Control Manager
The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).

Log: 'System' Date/Time: 11/05/2011 2:17:57 AM
Type: error Category: 0
Event: 29 Source: W32Time
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 240 minutes. NtpClient has no source of accurate time.

Log: 'System' Date/Time: 11/05/2011 2:17:57 AM
Type: error Category: 0
Event: 17 Source: W32Time
Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 240 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Log: 'System' Date/Time: 11/05/2011 12:17:57 AM
Type: error Category: 0
Event: 29 Source: W32Time
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 120 minutes. NtpClient has no source of accurate time.

Log: 'System' Date/Time: 11/05/2011 12:17:57 AM
Type: error Category: 0
Event: 17 Source: W32Time
Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 120 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Log: 'System' Date/Time: 10/05/2011 11:17:57 PM
Type: error Category: 0
Event: 29 Source: W32Time
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 60 minutes. NtpClient has no source of accurate time.

Log: 'System' Date/Time: 10/05/2011 11:17:57 PM
Type: error Category: 0
Event: 17 Source: W32Time
Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Log: 'System' Date/Time: 10/05/2011 10:47:57 PM
Type: error Category: 0
Event: 29 Source: W32Time
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 29 minutes. NtpClient has no source of accurate time.

Log: 'System' Date/Time: 10/05/2011 10:47:57 PM
Type: error Category: 0
Event: 17 Source: W32Time
Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Log: 'System' Date/Time: 10/05/2011 10:33:12 PM
Type: error Category: 0
Event: 7024 Source: Service Control Manager
The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).

Log: 'System' Date/Time: 10/05/2011 10:32:57 PM
Type: error Category: 0
Event: 29 Source: W32Time
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time.

Log: 'System' Date/Time: 10/05/2011 10:32:57 PM
Type: error Category: 0
Event: 17 Source: W32Time
Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Log: 'System' Date/Time: 10/05/2011 10:32:57 PM
Type: error Category: 0
Event: 29 Source: W32Time
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 10/05/2011 10:38:01 PM
Type: warning Category: 0
Event: 3019 Source: MRxSmb
The redirector failed to determine the connection type.

Log: 'System' Date/Time: 10/05/2011 10:19:52 PM
Type: warning Category: 0
Event: 3019 Source: MRxSmb
The redirector failed to determine the connection type.

Log: 'System' Date/Time: 10/05/2011 1:39:38 PM
Type: warning Category: 0
Event: 36 Source: W32Time
The time service has not been able to synchronize the system time for 49152 seconds because none of the time providers has been able to provide a usable time stamp. The system clock is unsynchronized.

Log: 'System' Date/Time: 09/05/2011 3:44:42 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 001CC026223B. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 09/05/2011 3:44:36 PM
Type: warning Category: 0
Event: 27 Source: e1express
Intel® 82566DC-2 Gigabit Network Connection Link has been disconnected.

Log: 'System' Date/Time: 09/05/2011 3:44:24 PM
Type: warning Category: 0
Event: 27 Source: e1express
Intel® 82566DC-2 Gigabit Network Connection Link has been disconnected.

Log: 'System' Date/Time: 09/05/2011 11:29:11 AM
Type: warning Category: 0
Event: 2510 Source: Server
The server service was unable to map error code 998.

Log: 'System' Date/Time: 09/05/2011 11:29:11 AM
Type: warning Category: 0
Event: 2510 Source: Server
The server service was unable to map error code 998.

Log: 'System' Date/Time: 09/05/2011 11:27:03 AM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NwlnkIpx.

Log: 'System' Date/Time: 09/05/2011 11:03:15 AM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NetBT_Tcpip_{25F79FBE-10F7-4C22-AD2E-2EC2C56530BA}.

Log: 'System' Date/Time: 09/05/2011 11:02:55 AM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NetBT_Tcpip_{25F79FBE-10F7-4C22-AD2E-2EC2C56530BA}.

Log: 'System' Date/Time: 09/05/2011 10:59:53 AM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NetBT_Tcpip_{25F79FBE-10F7-4C22-AD2E-2EC2C56530BA}.

Log: 'System' Date/Time: 09/05/2011 10:59:31 AM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NetBT_Tcpip_{25F79FBE-10F7-4C22-AD2E-2EC2C56530BA}.

Log: 'System' Date/Time: 09/05/2011 10:59:07 AM
Type: warning Category: 0
Event: 1007 Source: Dhcp
Your computer has automatically configured the IP address for the Network Card with network address 001CC026223B. The IP address being used is 169.254.60.239.

Log: 'System' Date/Time: 09/05/2011 10:59:01 AM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 001CC026223B. The following error occurred: The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 09/05/2011 10:58:36 AM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 001CC026223B. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 09/05/2011 10:58:34 AM
Type: warning Category: 0
Event: 27 Source: e1express
Intel® 82566DC-2 Gigabit Network Connection Link has been disconnected.

Log: 'System' Date/Time: 09/05/2011 10:55:59 AM
Type: warning Category: 0
Event: 27 Source: e1express
Intel® 82566DC-2 Gigabit Network Connection Link has been disconnected.

Log: 'System' Date/Time: 09/05/2011 10:55:28 AM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NetBT_Tcpip_{25F79FBE-10F7-4C22-AD2E-2EC2C56530BA}.

Log: 'System' Date/Time: 09/05/2011 10:52:24 AM
Type: warning Category: 0
Event: 20 Source: Print
Printer Driver Microsoft XPS Document Writer for Windows NT x86 Version-3 was added or updated. Files:- (null).
  • 0

#74
Bhinsz84

Bhinsz84

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
aswMBR version 0.9.5 Copyright© 2011 AVAST Software
Run date: 2011-05-11 06:00:45
-----------------------------
06:00:45.109 OS Version: Windows 5.1.2600 Service Pack 3
06:00:45.109 Number of processors: 2 586 0xF0B
06:00:45.109 ComputerName: BRIANS UserName:
06:00:46.312 Initialize success
06:00:48.500 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T1L0-7
06:00:48.500 Disk 0 Vendor: WDC_WD6400AAKS-00A7B2 01.03B01 Size: 610480MB BusType: 3
06:00:48.515 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-12
06:00:48.515 Disk 1 Vendor: WDC_WD5000AAKS-75YGA0 12.01C02 Size: 476940MB BusType: 3
06:00:48.531 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP4T0L0-1d
06:00:48.531 Disk 2 Vendor: WDC_WD6401AALS-00L3B2 01.03B01 Size: 610480MB BusType: 3
06:00:48.546 Disk 0 MBR read error 0
06:00:48.546 Disk 0 MBR scan
06:00:48.562 MBR BIOS signature not found 0
06:00:48.578 Disk 0 scanning sectors +1250242560
06:00:48.578 Disk 0 scanning C:\WINDOWS\system32\drivers
06:00:53.609 Service scanning
06:00:54.484 Disk 0 trace - called modules:
06:00:54.500 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spqq.sys >>UNKNOWN [0x8ae75938]<<
06:00:57.375 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8add3ab8]
06:00:57.531 3 CLASSPNP.SYS[b8108fd7] -> nt!IofCallDriver -> \Device\0000006f[0x8ada6f18]
06:00:57.718 5 ACPI.sys[b7e74620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T1L0-7[0x8ada4d98]
06:00:57.890 Scan finished successfully
06:01:08.296 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Administrator.BRIANS\Desktop\MBR.dat"
06:01:08.312 The log file has been saved successfully to "C:\Documents and Settings\Administrator.BRIANS\Desktop\aswMBR.txt"
  • 0

#75
Bhinsz84

Bhinsz84

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
aswMBR version 0.9.5 Copyright© 2011 AVAST Software
Run date: 2011-05-11 06:00:45
-----------------------------
06:00:45.109 OS Version: Windows 5.1.2600 Service Pack 3
06:00:45.109 Number of processors: 2 586 0xF0B
06:00:45.109 ComputerName: BRIANS UserName:
06:00:46.312 Initialize success
06:00:48.500 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T1L0-7
06:00:48.500 Disk 0 Vendor: WDC_WD6400AAKS-00A7B2 01.03B01 Size: 610480MB BusType: 3
06:00:48.515 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-12
06:00:48.515 Disk 1 Vendor: WDC_WD5000AAKS-75YGA0 12.01C02 Size: 476940MB BusType: 3
06:00:48.531 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP4T0L0-1d
06:00:48.531 Disk 2 Vendor: WDC_WD6401AALS-00L3B2 01.03B01 Size: 610480MB BusType: 3
06:00:48.546 Disk 0 MBR read error 0
06:00:48.546 Disk 0 MBR scan
06:00:48.562 MBR BIOS signature not found 0
06:00:48.578 Disk 0 scanning sectors +1250242560
06:00:48.578 Disk 0 scanning C:\WINDOWS\system32\drivers
06:00:53.609 Service scanning
06:00:54.484 Disk 0 trace - called modules:
06:00:54.500 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spqq.sys >>UNKNOWN [0x8ae75938]<<
06:00:57.375 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8add3ab8]
06:00:57.531 3 CLASSPNP.SYS[b8108fd7] -> nt!IofCallDriver -> \Device\0000006f[0x8ada6f18]
06:00:57.718 5 ACPI.sys[b7e74620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T1L0-7[0x8ada4d98]
06:00:57.890 Scan finished successfully
06:01:08.296 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Administrator.BRIANS\Desktop\MBR.dat"
06:01:08.312 The log file has been saved successfully to "C:\Documents and Settings\Administrator.BRIANS\Desktop\aswMBR.txt"
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP