peppercat

Members
  • Content count

    28
  • Joined

  • Last visited

About peppercat

  • Rank
    New Member
  1. Hi Maurice ok done all that only 6 optional and nothing important so left the optional off as advised
  2. Hi Maurice Thankyou so much for your help I followed your instructions and have now got updates back,it gathered 101 first time, I did it again just to check another 12 ready to come on board BRILLIANT. Only 3 failed 2 of which were recommended and 1 important, that one was Security update for Internet explorer 8 for Windows 7 KB2544521 It looks as if I have been upgraded to Explorer 9 so I do not know if that is relevant I now need to set this up securely with regular updates scans etc Is there anything else I need to do or advice you can offer please thankyou again
  3. Sorry Ive sent a book by the look of it
  4. Hi Maurice I hope this is ok I repeated your instructions again just before I came to this to check myself and I still couldnt get it to run same error message 2012-06-28 11:11:23:835 1092 8ac Misc =========== Logging initialized (build: 7.3.7600.16385, tz: +0100) =========== 2012-06-28 11:11:23:850 1092 8ac Misc = Process: C:\Windows\system32\svchost.exe 2012-06-28 11:11:23:850 1092 8ac Misc = Module: c:\windows\system32\wuaueng.dll 2012-06-28 11:11:23:819 1092 8ac Service ************* 2012-06-28 11:11:23:850 1092 8ac Service ** START ** Service: Service startup 2012-06-28 11:11:23:866 1092 8ac Service ********* 2012-06-28 11:11:24:022 1092 8ac Agent * WU client version 7.3.7600.16385 2012-06-28 11:11:24:022 1092 8ac Agent * Base directory: C:\Windows\SoftwareDistribution 2012-06-28 11:11:24:022 1092 8ac Agent * Access type: No proxy 2012-06-28 11:11:24:022 1092 8ac Agent * Network state: Connected 2012-06-28 11:11:24:131 1092 8ac DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:12:09:262 1092 8ac Report CWERReporter::Init succeeded 2012-06-28 11:12:09:262 1092 8ac Agent *********** Agent: Initializing Windows Update Agent *********** 2012-06-28 11:12:09:277 1092 8ac Agent *********** Agent: Initializing global settings cache *********** 2012-06-28 11:12:09:277 1092 8ac Agent * WSUS server: <NULL> 2012-06-28 11:12:09:277 1092 8ac Agent * WSUS status server: <NULL> 2012-06-28 11:12:09:277 1092 8ac Agent * Target group: (Unassigned Computers) 2012-06-28 11:12:09:277 1092 8ac Agent * Windows Update access disabled: No 2012-06-28 11:12:09:277 1092 8ac DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:12:09:277 1092 8ac DnldMgr Download manager restoring 0 downloads 2012-06-28 11:12:09:277 1092 8ac Agent * Failed to load persisted download calls, error = 0xc8000222 2012-06-28 11:12:09:293 1092 8ac DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:12:09:293 1092 8ac Agent WARNING: DeleteVolatileServices::GetServiceList failed with 0xc8000222. 2012-06-28 11:12:09:293 1092 8ac DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:12:09:293 1092 8ac DnldMgr FATAL: DM:CAgentDownloadManager::RestoreDownloadJobs: GetSession failed with 0xc8000222. 2012-06-28 11:12:09:293 1092 8ac DnldMgr FATAL: DM:CAgentDownloadManager::DelayedInit: RestoreDownloadJobs failed with 0x00000000. 2012-06-28 11:12:09:293 1092 8ac AU ########### AU: Initializing Automatic Updates ########### 2012-06-28 11:12:09:309 1092 8ac AU AU setting next detection timeout to 2012-06-28 10:12:09 2012-06-28 11:12:09:309 1092 8ac AU AU setting next sqm report timeout to 2012-06-28 10:12:09 2012-06-28 11:12:09:309 1092 8ac DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:12:09:309 1092 8ac Agent WARNING: GetServiceList failed with error 0xc8000222. 2012-06-28 11:12:09:309 1092 8ac AU WARNING: QueryRegisteredProvider failed with error 0xc8000222 2012-06-28 11:12:09:309 1092 8ac AU # Approval type: Scheduled (User preference) 2012-06-28 11:12:09:309 1092 8ac AU # Scheduled install day/time: Every day at 14:00 2012-06-28 11:12:09:309 1092 8ac AU # Auto-install minor updates: Yes (User preference) 2012-06-28 11:12:09:309 1092 8ac AU # Will interact with non-admins (Non-admins are elevated (User preference)) 2012-06-28 11:12:09:309 1092 8ac AU # Power management is turned off through policy 2012-06-28 11:12:09:324 1092 8ac DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:12:09:324 1092 8ac AU FATAL: Failed to get session from datastore, error = 0xC8000222 2012-06-28 11:12:09:324 1092 8ac AU FATAL: Failed to Unserialize from data store, error = 0xC8000222 2012-06-28 11:12:09:324 1092 8ac AU # WARNING: Exit code = 0xC8000222 2012-06-28 11:12:09:324 1092 8ac AU ########### AU: Uninitializing Automatic Updates ########### 2012-06-28 11:12:09:324 1092 8ac AU WARNING: InitAUComponents Failed, will restart AU in 30 mins, error = 0xC8000222 2012-06-28 11:12:09:324 1092 8ac AU AU Restart required.... 2012-06-28 11:12:10:775 1092 8ac Report *********** Report: Initializing static reporting data *********** 2012-06-28 11:12:10:775 1092 8ac Report * OS Version = 6.1.7600.0.0.66304 2012-06-28 11:12:10:775 1092 8ac Report * OS Product Type = 0x00000003 2012-06-28 11:12:10:853 1092 8ac Report * Computer Brand = MEDIONPC 2012-06-28 11:12:10:853 1092 8ac Report * Computer Model = MS-7646 2012-06-28 11:12:10:853 1092 8ac Report * Bios Revision = A7646MLN.30B 2012-06-28 11:12:10:853 1092 8ac Report * Bios Name = Default System BIOS 2012-06-28 11:12:10:853 1092 8ac Report * Bios Release Date = 2010-07-08T00:00:00 2012-06-28 11:12:10:853 1092 8ac Report * Locale ID = 2057 2012-06-28 11:12:10:884 1092 230 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:12:10:884 1092 230 DnldMgr FATAL: DM:CAgentDownloadManager::CheckAllCallDownloadStates: GetSession failed with 0xc8000222. 2012-06-28 11:12:10:900 1092 230 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:12:10:900 1092 230 DnldMgr FATAL: DM:CAgentDownloadManager::PurgeExpiredFiles: GetSession failed with 0xc8000222. 2012-06-28 11:12:10:900 1092 230 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:12:10:900 1092 230 DnldMgr FATAL: DM:CAgentDownloadManager::PurgeExpiredUpdates: GetSession failed with 0xc8000222. 2012-06-28 11:12:15:907 1092 230 Report CWERReporter finishing event handling. (00000000) 2012-06-28 11:19:16:459 1092 cf8 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:19:16:459 1092 cf8 Agent WARNING: WU client fails CClientCallRecorder::EnumerateService with error 0xc8000222 2012-06-28 11:19:16:459 2584 770 Misc =========== Logging initialized (build: 7.3.7600.16385, tz: +0100) =========== 2012-06-28 11:19:16:459 2584 770 Misc = Process: c:\Program Files\Microsoft Security Client\MpCmdRun.exe 2012-06-28 11:19:16:459 2584 770 Misc = Module: C:\Windows\system32\wuapi.dll 2012-06-28 11:19:16:459 2584 770 COMAPI WARNING: ISusInternal::EnumerateService failed, hr=C8000222 2012-06-28 11:19:16:462 2584 770 COMAPI ------------- 2012-06-28 11:19:16:462 2584 770 COMAPI -- START -- COMAPI: Search [ClientId = Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)] 2012-06-28 11:19:16:462 2584 770 COMAPI --------- 2012-06-28 11:19:16:467 1092 230 Agent ************* 2012-06-28 11:19:16:467 1092 230 Agent ** START ** Agent: Finding updates [CallerId = Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)] 2012-06-28 11:19:16:467 1092 230 Agent ********* 2012-06-28 11:19:16:467 2584 770 COMAPI <<-- SUBMITTED -- COMAPI: Search [ClientId = Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)] 2012-06-28 11:19:16:468 1092 230 Agent * Online = Yes; Ignore download priority = No 2012-06-28 11:19:16:468 1092 230 Agent * Criteria = "(IsInstalled = 0 and IsHidden = 0 and CategoryIDs contains '6b9e8b26-8f50-44b9-94c6-7846084383ec' and CategoryIDs contains 'e0789628-ce08-4437-be74-2495b842f43b')" 2012-06-28 11:19:16:468 1092 230 Agent * ServiceID = {00000000-0000-0000-0000-000000000000} Third party service 2012-06-28 11:19:16:468 1092 230 Agent * Search Scope = {Machine} 2012-06-28 11:19:16:472 1092 230 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:19:16:472 1092 230 Agent WARNING: GetServiceList failed with error 0xc8000222. 2012-06-28 11:19:16:472 1092 230 Agent * WARNING: Online service registration/service ID resolution failed, hr=0xC8000222 2012-06-28 11:19:16:475 1092 230 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:19:16:476 1092 230 Agent * WARNING: Exit code = 0xC8000222 2012-06-28 11:19:16:476 1092 230 Agent ********* 2012-06-28 11:19:16:476 1092 230 Agent ** END ** Agent: Finding updates [CallerId = Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)] 2012-06-28 11:19:16:476 1092 230 Agent ************* 2012-06-28 11:19:16:476 1092 230 Agent WARNING: WU client failed Searching for update with error 0xc8000222 2012-06-28 11:19:16:476 2584 fe8 COMAPI >>-- RESUMED -- COMAPI: Search [ClientId = Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)] 2012-06-28 11:19:16:477 2584 fe8 COMAPI - Updates found = 0 2012-06-28 11:19:16:477 2584 fe8 COMAPI - WARNING: Exit code = 0x00000000, Result code = 0xC8000222 2012-06-28 11:19:16:477 2584 fe8 COMAPI --------- 2012-06-28 11:19:16:477 2584 fe8 COMAPI -- END -- COMAPI: Search [ClientId = Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)] 2012-06-28 11:19:16:477 2584 fe8 COMAPI ------------- 2012-06-28 11:19:16:477 2584 14c COMAPI WARNING: Operation failed due to earlier error, hr=C8000222 2012-06-28 11:19:16:477 2584 14c COMAPI FATAL: Unable to complete asynchronous search. (hr=C8000222) 2012-06-28 11:19:21:573 1092 230 Report REPORT EVENT: {86312D06-960D-4B98-95FB-94BBF5466A1B} 2012-06-28 11:19:16:475+0100 1 148 101 {00000000-0000-0000-0000-000000000000} 0 c8000222 Microsoft Security Essentials ( Failure Software Synchronization Windows Update Client failed to detect with error 0xc8000222. 2012-06-28 11:19:21:589 1092 230 Report CWERReporter::HandleEvents - WER report upload completed with status 0x8 2012-06-28 11:19:21:589 1092 230 Report WER Report sent: 7.3.7600.16385 0xc8000222 00000000-0000-0000-0000-000000000000 Scan 101 Unmanaged 2012-06-28 11:19:21:589 1092 230 Report CWERReporter finishing event handling. (00000000) 2012-06-28 11:20:33:594 1092 8ac AU ########### AU: Uninitializing Automatic Updates ########### 2012-06-28 11:20:33:595 1092 8ac Report CWERReporter finishing event handling. (00000000) 2012-06-28 11:20:33:598 1092 8ac Service ********* 2012-06-28 11:20:33:598 1092 8ac Service ** END ** Service: Service exit [Exit code = 0x240001] 2012-06-28 11:20:33:598 1092 8ac Service ************* 2012-06-28 11:28:17:689 1092 d64 Misc =========== Logging initialized (build: 7.3.7600.16385, tz: +0100) =========== 2012-06-28 11:28:17:689 1092 d64 Misc = Process: C:\Windows\system32\svchost.exe 2012-06-28 11:28:17:689 1092 d64 Misc = Module: c:\windows\system32\wuaueng.dll 2012-06-28 11:28:17:689 1092 d64 Service ************* 2012-06-28 11:28:17:689 1092 d64 Service ** START ** Service: Service startup 2012-06-28 11:28:17:689 1092 d64 Service ********* 2012-06-28 11:28:17:690 1092 d64 Agent * WU client version 7.3.7600.16385 2012-06-28 11:28:17:691 1092 d64 Agent * Base directory: C:\Windows\SoftwareDistribution 2012-06-28 11:28:17:691 1092 d64 Agent * Access type: No proxy 2012-06-28 11:28:17:692 1092 d64 Agent * Network state: Connected 2012-06-28 11:28:17:696 1092 d64 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:28:17:705 1092 b00 Report CWERReporter::Init succeeded 2012-06-28 11:28:17:706 1092 b00 Agent *********** Agent: Initializing Windows Update Agent *********** 2012-06-28 11:28:17:706 1092 b00 Agent *********** Agent: Initializing global settings cache *********** 2012-06-28 11:28:17:706 1092 b00 Agent * WSUS server: <NULL> 2012-06-28 11:28:17:706 1092 b00 Agent * WSUS status server: <NULL> 2012-06-28 11:28:17:706 1092 b00 Agent * Target group: (Unassigned Computers) 2012-06-28 11:28:17:706 1092 b00 Agent * Windows Update access disabled: No 2012-06-28 11:28:17:710 1092 b00 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:28:17:710 1092 b00 DnldMgr Download manager restoring 0 downloads 2012-06-28 11:28:17:710 1092 b00 Agent * Failed to load persisted download calls, error = 0xc8000222 2012-06-28 11:28:17:714 1092 b00 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:28:17:714 1092 b00 Agent WARNING: DeleteVolatileServices::GetServiceList failed with 0xc8000222. 2012-06-28 11:28:17:718 1092 b00 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:28:17:718 1092 b00 DnldMgr FATAL: DM:CAgentDownloadManager::RestoreDownloadJobs: GetSession failed with 0xc8000222. 2012-06-28 11:28:17:718 1092 b00 DnldMgr FATAL: DM:CAgentDownloadManager::DelayedInit: RestoreDownloadJobs failed with 0x00000000. 2012-06-28 11:28:17:723 1092 b00 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:28:18:079 1092 d64 Report *********** Report: Initializing static reporting data *********** 2012-06-28 11:28:18:079 1092 d64 Report * OS Version = 6.1.7600.0.0.66304 2012-06-28 11:28:18:079 1092 d64 Report * OS Product Type = 0x00000003 2012-06-28 11:28:18:097 1092 d64 Report * Computer Brand = MEDIONPC 2012-06-28 11:28:18:097 1092 d64 Report * Computer Model = MS-7646 2012-06-28 11:28:18:100 1092 d64 Report * Bios Revision = A7646MLN.30B 2012-06-28 11:28:18:100 1092 d64 Report * Bios Name = Default System BIOS 2012-06-28 11:28:18:100 1092 d64 Report * Bios Release Date = 2010-07-08T00:00:00 2012-06-28 11:28:18:100 1092 d64 Report * Locale ID = 2057 2012-06-28 11:28:18:105 1092 394 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:28:18:105 1092 394 DnldMgr FATAL: DM:CAgentDownloadManager::CheckAllCallDownloadStates: GetSession failed with 0xc8000222. 2012-06-28 11:28:18:108 1092 394 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:28:18:108 1092 394 DnldMgr FATAL: DM:CAgentDownloadManager::PurgeExpiredFiles: GetSession failed with 0xc8000222. 2012-06-28 11:28:18:113 1092 394 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:28:18:113 1092 394 DnldMgr FATAL: DM:CAgentDownloadManager::PurgeExpiredUpdates: GetSession failed with 0xc8000222. 2012-06-28 11:28:23:103 1092 394 Report CWERReporter finishing event handling. (00000000) 2012-06-28 11:28:28:256 1092 3ec DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:28:34:358 1092 6d0 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:29:02:697 1092 d64 AU ########### AU: Initializing Automatic Updates ########### 2012-06-28 11:29:02:698 1092 d64 AU AU setting next detection timeout to 2012-06-28 10:29:02 2012-06-28 11:29:02:698 1092 d64 AU AU setting next sqm report timeout to 2012-06-28 10:29:02 2012-06-28 11:29:02:708 1092 d64 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:29:02:708 1092 d64 Agent WARNING: GetServiceList failed with error 0xc8000222. 2012-06-28 11:29:02:708 1092 d64 AU WARNING: QueryRegisteredProvider failed with error 0xc8000222 2012-06-28 11:29:02:708 1092 d64 AU # Approval type: Scheduled (User preference) 2012-06-28 11:29:02:708 1092 d64 AU # Scheduled install day/time: Every day at 14:00 2012-06-28 11:29:02:708 1092 d64 AU # Auto-install minor updates: Yes (User preference) 2012-06-28 11:29:02:709 1092 d64 AU # Will interact with non-admins (Non-admins are elevated (User preference)) 2012-06-28 11:29:02:709 1092 d64 AU # Power management is turned off through policy 2012-06-28 11:29:02:717 1092 d64 DtaStor FATAL: Failed to initialize datastore, error = 0xC8000222 2012-06-28 11:29:02:717 1092 d64 AU FATAL: Failed to get session from datastore, error = 0xC8000222 2012-06-28 11:29:02:718 1092 d64 AU FATAL: Failed to Unserialize from data store, error = 0xC8000222 2012-06-28 11:29:02:718 1092 d64 AU # WARNING: Exit code = 0xC8000222 2012-06-28 11:29:02:718 1092 d64 AU ########### AU: Uninit
  5. Hi Maurice thankyou for your help I am not very techie but would like to try.I have tried your instructions but cannot seem to get a report for you it comes up as Windows Script Box with error 0xc8000222 code C8000222 and goes no further
  6. Hi can anyone help please I still have a problem from searchbrowsing trogan, removed thankfully by one of your brilliant members I am sure the remnants are preventing me from doing any updates it also appears to have removed all my printer drivers.Its really frustating
  7. Hi Gringo thank you I have just carried out your instructions and the PC seems good, faster than before and clean Great. Thanks also for the advice about my drives I will carry that out shortly. I am glad I came to your site instead of taking it into a shop I feel a certain satisfaction that I was able to see it cured although its all down to you,I also feel a little more confident to perhaps use it for other things and need to take more notice to back up and update programs and generally be more careful as do we all here. Thanks again
  8. Hi Gringo I hope that it got through to you this time When we started this you told me to back up files so I did a full backup to a external drive which I then disconnected ,is the external drive now infected if it is how do I clean it to stop it reinfecting the PC I also have another that has my photos on how can I check that to make sure I dont loose any of them. Thanks again for the time you have spent on Regards
  9. C:\Users\bethany\AppData\Local\Babylon\Setup\MyBabylonTB.exe Win32/Toolbar.Babylon application C:\Users\bethany\Downloads\gimp-setup.exe Win32/DownloadAdmin.A.Gen application C:\Users\bethany\Downloads\installer_adobe_photoshop.exe multiple threats C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3un8z7x5.default\prefs.js.BAK Win32/Adware.Bonzuna.A application C:\Users\User\Downloads\BonzunaInstaller(CH) (1).exe a variant of Win32/Adware.Bonzuna.A application C:\Users\User\Downloads\BonzunaInstaller(CH).exe a variant of Win32/Adware.Bonzuna.A application C:\Users\User\Downloads\gimp-setup.exe Win32/DownloadAdmin.A.Gen application C:\_OTL\MovedFiles\06132012_200006\C_Program Files\Search Core Systems\Windows Core Toolbar\browserhelper.dll Win32/Adware.Bonzuna.A application C:\_OTL\MovedFiles\06132012_200006\C_Program Files\Search Core Systems\Windows Core Toolbar\wcoretb.dll Win32/Adware.Bonzuna.A application C:\_OTL\MovedFiles\06132012_200006\C_Program Files\Search Core Systems\Windows Core Toolbar\wcthelper.exe Win32/Adware.Bonzuna.A application C:\_OTL\MovedFiles\06132012_200006\C_Program Files\Search Core Systems\Windows Core Toolbar\wcupdt.exe Win32/Adware.Bonzuna.A application
  10. That looks strange I hope thats how its meant to look if not I will try and send it again
  11. <p> </p> <div>Hi Gringo This is the result of the Eset Scan and these are the threats that it found </div> <div> </div> <div>Before I started any of the work with you on this you said to back files up so I did a total back up to my external drive and then disconnected it I have another one with my photos etc on are they likely to be infected if so have you any advice how to stop reinfecting the pc and remove it from the external drive if on.</div> <div> </div> <div>Thanks for your time I really appreciate it</div> <div> </div> <div>C:\Users\bethany\AppData\Local\Babylon\Setup\MyBabylonTB.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Toolbar.Babylon application</div> <div>C:\Users\bethany\Downloads\gimp-setup.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/DownloadAdmin.A.Gen application</div> <div>C:\Users\bethany\Downloads\installer_adobe_photoshop.exe<span class="Apple-tab-span" style="white-space:pre"> </span>multiple threats</div> <div>C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3un8z7x5.default\prefs.js.BAK<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Adware.Bonzuna.A application</div> <div>C:\Users\User\Downloads\BonzunaInstaller(CH) (1).exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Adware.Bonzuna.A application</div> <div>C:\Users\User\Downloads\BonzunaInstaller(CH).exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Adware.Bonzuna.A application</div> <div>C:\Users\User\Downloads\gimp-setup.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/DownloadAdmin.A.Gen application</div> <div>C:\_OTL\MovedFiles\06132012_200006\C_Program Files\Search Core Systems\Windows Core Toolbar\browserhelper.dll<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Adware.Bonzuna.A application</div> <div>C:\_OTL\MovedFiles\06132012_200006\C_Program Files\Search Core Systems\Windows Core Toolbar\wcoretb.dll<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Adware.Bonzuna.A application</div> <div>C:\_OTL\MovedFiles\06132012_200006\C_Program Files\Search Core Systems\Windows Core Toolbar\wcthelper.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Adware.Bonzuna.A application</div> <div>C:\_OTL\MovedFiles\06132012_200006\C_Program Files\Search Core Systems\Windows Core Toolbar\wcupdt.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Adware.Bonzuna.A application</div> <div> </div>
  12. Hi again I think I have it for you havnt a clue why it decided to do it that time but I got it up in a different window and it worked saving into notepad where it didnt last time hope it is what you want Regards Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 15:45:00, on 14/06/2012 Platform: Windows 7 (WinNT 6.00.3504) MSIE: Internet Explorer v8.00 (8.00.7600.16385) Boot mode: Normal Running processes: C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\AVG\AVG PC Tuneup\BoostSpeed.exe C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Windows\vVX6000.exe C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\Creative\Shared Files\CamTray.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Microsoft Office\Office\FINDFAST.EXE C:\Program Files\Microsoft Office\Office\OSA.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows Live\Toolbar\wltuser.exe C:\Windows\system32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\11.1.0\ScriptHelper.exe C:\Windows\system32\notepad.exe C:\Windows\system32\NOTEPAD.EXE C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe C:\Windows\system32\SearchFilterHost.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe" O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe" O4 - HKLM\..\Run: [VX6000] C:\Windows\vVX6000.exe O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" O4 - HKLM\..\Run: [V0330Cfg.exe] V0330Cfg.exe /d:3 O4 - HKLM\..\Run: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-18\..\Run: [Advanced SystemCare 5] "C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Advanced SystemCare 5] "C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart (User 'Default user') O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MIF5BA~1\Office14\ONBttnIE.dll/105 O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU) O9 - Extra button: eBay.co.uk - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4 (file missing) (HKCU) O9 - Extra 'Tools' menuitem: eBay.co.uk - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4 (file missing) (HKCU) O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Advanced SystemCare Service 5 (AdvancedSystemCareService5) - IObit - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgfws.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: vToolbarUpdater11.1.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe -- End of file - 11094 bytes
  13. Hi again I have just reloading it to desktop and tried running it but got the warning system denied write access to the host file I have tried what the y suggest typing filr search but not found the pc seems ok as normal quite quick actually all Browsers seem as normal so good I hope just pity I cant get that report to you perhaps I am not typing it right but think I am Regards
  14. Hi Gringo I hope you recieved MBAM log I have got a report from Hijack this but it has not loaded to Notepad and I cant copy and paste it there was also a warning that hosts are not accesible or something I will try again now
  15. Hi again Gringo I have just been on Google, Explorer and firefox and there was no sign of my problem visitor thankyou so much is there any thing I must do to keep it out and do you mind if you keep this open tomorrow just so I can try it out when Im not quite so weary and see if you have any advice on how to set this up a bit better Thanks again brilliant