Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Infected with fake antivirus program


  • This topic is locked This topic is locked

#1
beesfree

beesfree

    New Member

  • Member
  • Pip
  • 1 posts
Hello, I was actually sent here from the Bleeping Computer Forum. I posted there to get help on fake anti-virus infection on my computer.

While browsing the internet about three weeks ago, a pop up showed up on my computer, closed all my browser windows, and asked me to run an anti virus check on my system because I had been infected. It warned that the threats were coming from people trying to steal identify information. In fact, it stated that I needed to update windows, and indicated that the firewall was disabled. It looked like a windows security pop-up with some minor differences, which was a bit strange, so I did not click on it. I went to check whether my firewall was disabled, and instead found that I could not access that part of my computer. The pop-ups were constant and kept indicating that I had all these threats and had to upgrade my windows. I tried to get on the internet again, but the "windows security" warned that the internet was disabled to "protect" my computer from further threats. Finally, although reluctuntaly, I thought "windows" had changed it's look for 2012, despite my misgivings I tried to update the software, but strangely enough I was prompted to make a purchase which I did not make.

That is the virus that infected my computer. Right now, a friend helped with a "systems recovery" prompt, which allows me to get back on the internet. However, I do not think the problem is fixed.

I've run aDDS scan and created a GMER log.

Here is the pasted OTL Log that I've just run.


OTL logfile created on: 1/6/2012 4:50:54 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\beesfree\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.37 Mb Total Physical Memory | 191.00 Mb Available Physical Memory | 18.83% Memory free
2.38 Gb Paging File | 1.72 Gb Available in Paging File | 72.07% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 50.79 Gb Free Space | 68.15% Space Free | Partition Type: NTFS

Computer Name: beesfree-B9647B | User Name: beesfree | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/06 16:47:19 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\beesfree\Desktop\OTL.exe
PRC - [2011/12/21 01:24:51 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/09/06 14:45:30 | 003,722,416 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/09/06 14:45:28 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2011/05/24 16:09:22 | 018,162,552 | ---- | M] (Enterasys Networks, Inc) -- C:\Program Files\Enterasys Networks\NAC Agent\NacAgent.exe
PRC - [2011/05/20 17:24:13 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2008/04/13 17:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2012/01/06 12:19:19 | 001,664,512 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12010601\algo.dll
MOD - [2012/01/04 19:39:57 | 000,053,248 | ---- | M] () -- C:\Documents and Settings\beesfree\Local Settings\Temp\ShutdownGuardian.dll
MOD - [2012/01/04 11:47:22 | 001,662,976 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12010401\algo.dll
MOD - [2012/01/03 12:16:27 | 000,268,808 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12010401\aswRep.dll
MOD - [2011/12/21 01:24:51 | 002,124,760 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/08/03 22:02:36 | 006,271,136 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2009/10/07 16:01:14 | 000,757,760 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
MOD - [2008/06/10 18:50:34 | 000,069,632 | ---- | M] () -- C:\Program Files\Enterasys Networks\NAC Agent\rt\bin\java.dll
MOD - [2008/06/10 18:50:26 | 000,020,480 | ---- | M] () -- C:\Program Files\Enterasys Networks\NAC Agent\rt\bin\jetvm\jvm.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/09/06 14:45:28 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)


========== Driver Services (SafeList) ==========

DRV - [2011/09/06 14:38:05 | 000,442,200 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/09/06 14:37:53 | 000,320,856 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/09/06 14:36:38 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/09/06 14:36:36 | 000,052,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/09/06 14:36:23 | 000,110,552 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/09/06 14:36:12 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/09/06 14:33:11 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009/10/07 16:01:32 | 002,649,216 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2007/05/10 11:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/11/02 17:51:58 | 000,013,560 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD\000.fcl -- ({95808DC4-FA4A-4c74-92FE-5B863F82066B})
DRV - [2005/08/05 12:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2004/09/29 13:45:32 | 000,026,525 | R--- | M] (SMC2208USB/ETH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SMC2208.SYS -- (SMC2208)
DRV - [2004/04/20 09:05:10 | 000,057,404 | R--- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftser2k.sys -- (FTSER2K)
DRV - [2004/04/20 09:04:56 | 000,024,209 | R--- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2003/01/24 06:13:06 | 000,024,197 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\FTD2XX.sys -- (FTD2XX)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.647: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.647: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/05/20 17:24:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/12/22 12:57:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/22 14:10:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/04/23 18:44:09 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\beesfree\Application Data\Mozilla\Extensions
[2011/12/14 09:33:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\beesfree\Application Data\Mozilla\Firefox\Profiles\3ymxnsqb.default\extensions
[2011/12/14 09:33:34 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\beesfree\Application Data\Mozilla\Firefox\Profiles\3ymxnsqb.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/12/22 14:09:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/28 09:55:30 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/12/21 01:24:52 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/12/20 22:30:41 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/20 22:30:41 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\beesfree\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.4_0\
CHR - Extension: Skype Extension = C:\Documents and Settings\beesfree\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7550_0\

O1 HOSTS File: ([2008/04/13 17:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NAC Assessment Agent.lnk = C:\Program Files\Enterasys Networks\NAC Agent\NacAgent.exe (Enterasys Networks, Inc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1303521990750 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{398A1A20-697E-472B-902F-DDAAD6E98A5C}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\beesfree\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\beesfree\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/22 18:05:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/06 16:47:16 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\beesfree\Desktop\OTL.exe
[2011/12/26 19:13:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\beesfree\Desktop\gmer
[2011/12/26 19:01:28 | 000,000,000 | R--D | C] -- C:\Documents and Settings\beesfree\Start Menu\Programs\Administrative Tools
[2011/12/26 18:58:12 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\beesfree\Desktop\dds.scr
[2011/12/22 12:42:48 | 000,000,000 | ---D | C] -- C:\## aswSnx private storage(2)
[9 C:\Documents and Settings\beesfree\Desktop\*.tmp files -> C:\Documents and Settings\beesfree\Desktop\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\beesfree\My Documents\*.tmp files -> C:\Documents and Settings\beesfree\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/06 16:47:19 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\beesfree\Desktop\OTL.exe
[2012/01/06 04:52:00 | 000,000,428 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{410C6F96-59EB-497A-9637-D265B27EE2D0}.job
[2012/01/04 19:43:45 | 000,433,756 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/04 19:43:45 | 000,068,164 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/01/04 19:39:45 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/04 19:39:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/02 15:45:41 | 000,043,224 | ---- | M] () -- C:\Documents and Settings\beesfree\Desktop\prince gag bio-1.pdf
[2012/01/01 11:48:29 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/12/28 20:02:52 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\beesfree\Desktop\hmmmmm.bmp
[2011/12/28 18:57:50 | 000,044,098 | ---- | M] () -- C:\Documents and Settings\beesfree\Desktop\beesfree gag cover page.pdf
[2011/12/28 18:44:37 | 000,102,315 | ---- | M] () -- C:\Documents and Settings\beesfree\Desktop\beesfree gag Resume.pdf
[2011/12/28 15:48:19 | 000,154,039 | ---- | M] () -- C:\Documents and Settings\beesfree\Desktop\beesfree gag_new.rtf
[2011/12/27 15:02:48 | 000,002,223 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\BrainMaster 2.5 Software.lnk
[2011/12/26 19:11:05 | 000,294,216 | ---- | M] () -- C:\Documents and Settings\beesfree\Desktop\gmer.zip
[2011/12/26 18:58:17 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\beesfree\Desktop\dds.scr
[2011/12/26 18:56:42 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\beesfree\defogger_reenable
[2011/12/26 18:55:16 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\beesfree\Desktop\Defogger.exe
[2011/12/22 14:10:07 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\beesfree\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/12/22 14:10:07 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/22 13:01:15 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/12/22 13:01:12 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/12/22 12:46:25 | 000,014,860 | -HS- | M] () -- C:\Documents and Settings\beesfree\Local Settings\Application Data\eaobxq8b3hgh6kfp1iyw6q758a4y
[2011/12/22 12:46:25 | 000,014,860 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\eaobxq8b3hgh6kfp1iyw6q758a4y
[2011/12/14 15:42:09 | 000,270,984 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/14 14:45:33 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/12/13 09:29:14 | 000,002,161 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\BrainMaster 3.4 Software.lnk
[9 C:\Documents and Settings\beesfree\Desktop\*.tmp files -> C:\Documents and Settings\beesfree\Desktop\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\beesfree\My Documents\*.tmp files -> C:\Documents and Settings\beesfree\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/02 15:45:41 | 000,043,224 | ---- | C] () -- C:\Documents and Settings\beesfree\Desktop\prince gag bio-1.pdf
[2011/12/27 22:31:05 | 000,044,098 | ---- | C] () -- C:\Documents and Settings\beesfree\Desktop\beesfree gag cover page.pdf
[2011/12/27 22:30:46 | 000,102,315 | ---- | C] () -- C:\Documents and Settings\beesfree\Desktop\beesfree gag Resume.pdf
[2011/12/27 11:00:00 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\beesfree\Desktop\hmmmmm.bmp
[2011/12/26 19:11:05 | 000,294,216 | ---- | C] () -- C:\Documents and Settings\beesfree\Desktop\gmer.zip
[2011/12/26 18:56:42 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\beesfree\defogger_reenable
[2011/12/26 18:55:15 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\beesfree\Desktop\Defogger.exe
[2011/12/22 14:10:07 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\beesfree\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/12/21 20:38:37 | 000,014,860 | -HS- | C] () -- C:\Documents and Settings\beesfree\Local Settings\Application Data\eaobxq8b3hgh6kfp1iyw6q758a4y
[2011/12/21 20:38:37 | 000,014,860 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\eaobxq8b3hgh6kfp1iyw6q758a4y
[2011/10/18 12:43:01 | 000,135,664 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/10/18 12:41:56 | 000,000,173 | ---- | C] () -- C:\Documents and Settings\beesfree\Local Settings\Application Data\msmathematics.qat.beesfree
[2011/09/13 15:18:18 | 000,000,092 | R--- | C] () -- C:\WINDOWS\System32\ftdiun2k.ini
[2011/05/16 13:02:38 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2011/05/16 13:02:30 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\beesfree\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/23 18:43:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/04/22 19:16:24 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2011/04/22 19:16:23 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2011/04/22 19:16:23 | 000,025,088 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2011/04/22 18:47:51 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4814.dll
[2011/04/22 18:21:13 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2011/04/22 18:08:09 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/04/22 18:02:02 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/04/22 10:50:04 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/04/22 10:48:50 | 000,270,984 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/13 17:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/04/13 17:00:00 | 000,433,756 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/04/13 17:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/04/13 17:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/04/13 17:00:00 | 000,068,164 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/04/13 17:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/04/13 17:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/04/13 17:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/04/13 17:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/04/13 17:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2005/04/14 21:52:33 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2005/04/14 21:52:33 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/07/26 10:00:00 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\cviUSI.dll
[2003/01/24 05:56:20 | 000,000,059 | ---- | C] () -- C:\WINDOWS\System32\FTD2XXUN.ini
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2011/09/23 17:00:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/24 14:12:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NAC Assessment Agent
[2011/09/13 14:24:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\beesfree\Application Data\TeamViewer
[2012/01/06 04:52:00 | 000,000,428 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{410C6F96-59EB-497A-9637-D265B27EE2D0}.job

========== Purity Check ==========



< End of report >


These are the extras:

OTL Extras logfile created on: 1/6/2012 4:50:54 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\beesfree\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.37 Mb Total Physical Memory | 191.00 Mb Available Physical Memory | 18.83% Memory free
2.38 Gb Paging File | 1.72 Gb Available in Paging File | 72.07% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 50.79 Gb Free Space | 68.15% Space Free | Partition Type: NTFS

Computer Name: beesfree-B9647B | User Name: beesfree | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{062864C8-1087-43BC-AD2B-61A6B902E564}" = BrainMaster 2.5 Core Software
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{235FA0C0-A78A-440C-9A97-63B9ADEEA3AB}" = BrainMaster 3.4 Software
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{26D3E377-1DCA-4043-9410-B4A9BACF1033}" = Nero 7 Ultra Edition
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{46D7A790-7E29-46A3-914E-5914CCA4FF79}" = Enterasys NAC Assessment Agent
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D090F70-6F08-4B60-9357-A1DFD4458F09}" = Microsoft Mathematics
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9D0F85-5658-4A5E-95A9-65F7DB2916EE}" = Broadcom 440x 10/100 Integrated Controller
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF0896A6-3DAA-44EE-8B6E-D81237A2D4EC}" = Enterasys NAC Assessment Agent
"{E536B68E-3D84-4F07-BBD5-30109DC6AF9A}" = Enterasys NAC Assessment Agent
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast" = avast! Free Antivirus
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"Defraggler" = Defraggler
"DW WLAN Card Utility" = DW WLAN Card Utility
"FTDICOMM" = FTDI USB Serial Converter Drivers
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"InstallShield_{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"R for Windows 2.13.1_is1" = R for Windows 2.13.1
"RealPlayer 12.0" = RealPlayer
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/5/2011 12:12:09 AM | Computer Name = beesfree-B9647B | Source = Microsoft Office 11 | ID = 1000
Description = Faulting application winword.exe, version 11.0.8328.0, stamp 4c717ed1,
faulting module gdi32.dll, version 5.1.2600.5698, stamp 49006fbe, debug? 0, fault
address 0x00006df0.

Error - 11/14/2011 5:37:45 PM | Computer Name = beesfree-B9647B | Source = Microsoft Office 11 | ID = 1000
Description = Faulting application winword.exe, version 11.0.8328.0, stamp 4c717ed1,
faulting module ntdll.dll, version 5.1.2600.6055, stamp 4d00f27d, debug? 0, fault
address 0x00010a1b.

Error - 11/17/2011 1:25:41 PM | Computer Name = beesfree-B9647B | Source = MsiInstaller | ID = 10005
Description = Product: Enterasys NAC Assessment Agent -- The installer has encountered
an unexpected error installing this package. This may indicate a problem with this
package. The error code is 2753. The arguments are: NacAgent, ,

Error - 11/17/2011 1:26:19 PM | Computer Name = beesfree-B9647B | Source = MsiInstaller | ID = 10005
Description = Product: Enterasys NAC Assessment Agent -- The installer has encountered
an unexpected error installing this package. This may indicate a problem with this
package. The error code is 2753. The arguments are: NacAgent, ,

Error - 12/21/2011 10:49:35 PM | Computer Name = beesfree-B9647B | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 8.0.0.4325, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 12/21/2011 10:49:55 PM | Computer Name = beesfree-B9647B | Source = Application Hang | ID = 1001
Description = Fault bucket -1612583200.

Error - 12/21/2011 11:06:31 PM | Computer Name = beesfree-B9647B | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 8.0.0.4325, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/2/2012 5:49:32 PM | Computer Name = beesfree-B9647B | Source = .NET Runtime | ID = 1023
Description = Application: plugin-container.exe CoreCLR Version: 4.0.60831.0 Description:
The process was terminated due to an internal error in the .NET Runtime at IP 7928D2A6
(79150000) with exit code 8013150a.

Error - 1/2/2012 5:49:35 PM | Computer Name = beesfree-B9647B | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 9.0.1.4371, faulting
module coreclr.dll, version 4.0.60831.0, fault address 0x0013d2a6.

Error - 1/3/2012 11:14:33 PM | Computer Name = beesfree-B9647B | Source = Microsoft Office 11 | ID = 1000
Description = Faulting application excel.exe, version 11.0.8342.0, stamp 4ea7ca01,
faulting module excel.exe, version 11.0.8342.0, stamp 4ea7ca01, debug? 0, fault
address 0x00881ae8.

[ System Events ]
Error - 12/22/2011 2:46:07 PM | Computer Name = beesfree-B9647B | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 AFD aswRdr aswSnx aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS RasAcd Rdbss Tcpip

Error - 12/22/2011 2:48:10 PM | Computer Name = beesfree-B9647B | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 12/22/2011 3:01:04 PM | Computer Name = beesfree-B9647B | Source = Service Control Manager | ID = 7022
Description = The avast! Antivirus service hung on starting.

Error - 12/22/2011 3:54:06 PM | Computer Name = beesfree-B9647B | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.105 for the Network Card with network
address 001BFCC0B5A3 has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).

Error - 12/26/2011 9:18:19 PM | Computer Name = beesfree-B9647B | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.

Error - 12/27/2011 2:01:08 PM | Computer Name = beesfree-B9647B | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.151 for the Network Card with network
address 001BFCC0B5A3 has been denied by the DHCP server 10.26.255.34 (The DHCP Server
sent a DHCPNACK message).

Error - 12/28/2011 10:54:23 AM | Computer Name = beesfree-B9647B | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.

Error - 12/28/2011 10:54:59 AM | Computer Name = beesfree-B9647B | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.

Error - 12/28/2011 10:55:34 AM | Computer Name = beesfree-B9647B | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort0, did not respond within the timeout
period.

Error - 12/31/2011 9:22:06 PM | Computer Name = beesfree-B9647B | Source = Dhcp | ID = 1002
Description = The IP address lease 10.10.10.102 for the Network Card with network
address 001BFCC0B5A3 has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).


< End of report >
  • 0

Advertisements


#2
Gammo

Gammo

    Trusted Helper

  • Malware Removal
  • 2,299 posts
I'm closing this topic since you're already being helped at Bleeping Computer: http://www.bleepingc...pic434964.html/
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP