New
#41
And the network is DHCP already but this is not the nerwork the computer lives on.
Sorry , a bit rushed - just been invaded by relatives
And the network is DHCP already but this is not the nerwork the computer lives on.
Sorry , a bit rushed - just been invaded by relatives
OK, no prob :)
Something about it appears to be 'stuck' on the IP address from the work server/router.
Please check the Device Manager for problems - with the NIC particularly.
The device driver is quite happy - NIC is OK as far as I can see. Certainly there appears to be no problems accessing the network/internet here or where the computer normally lives.
Reference an earlier post, there was some evidence of McAfee on this machine - I don't know why, probably came tacked onto some other application download. But when I removed Norton, I ran the McAfee removal tool too just for good measure.
Good - it may be that the McAfee was preinstalled by the manufacturer, and simply uninstalled previously without running the removal utility.
Unfortunately, those two are the bêtes noire of AV's - and between then cause almost as many problems as the viruses they are supposed to protect against. I've known machines brought to a standstill because of residuals from either or both - even after use of the removal tools.
It's been a while - please run another MGADiag report to confirm that nothing we've done has changed the results.
Here's a new MGADiag
Code:Diagnostic Report (1.9.0027.0): ----------------------------------------- Windows Validation Data--> Validation Code: 0 Cached Online Validation Code: N/A, hr = 0xc0000034 Windows Product Key: N/A, hr=0xc0000034 Windows Product Key Hash: N/A, hr=0xc0000034 Windows Product ID: 55041-033-4789644-86307 Windows Product ID Type: 6 Windows License Type: Volume MAK Windows OS version: 6.1.7601.2.00010100.1.0.048 ID: {3E36DFB7-0BF5-400E-A3E7-6BDF65CC4D74}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: Windows 7 Professional Architecture: 0x00000009 Build lab: 7601.win7sp1_gdr.120305-1505 TTS Error: Validation Diagnostic: Resolution Status: N/A Vista WgaER Data--> ThreatID(s): N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 Windows XP Notifications Data--> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data--> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data--> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3 Browser Data--> Proxy settings: User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data--> Other data--> Office Details: <GenuineResults><MachineData><UGUID>{3E36DFB7-0BF5-400E-A3E7-6BDF65CC4D74}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-BBBBB</PKey><PID>55041-033-4789644-86307</PID><PIDType>6</PIDType><SID>S-1-5-21-1935836800-3093289039-440424962</SID><SYSTEM><Manufacturer>Dell Inc.</Manufacturer><Model>Vostro 220s Series</Model></SYSTEM><BIOS><Manufacturer>Dell Inc.</Manufacturer><Version>1.1.4</Version><SMBIOSVersion major="2" minor="5"/><Date>20090417000000.000000+000</Date></BIOS><HWID>764A3707018400F8</HWID><UserLCID>0809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GMT Standard Time(GMT+00:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>DELL </OEMID><OEMTableID>FX09 </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> Spsys.log Content: 0x80070002 Licensing Data--> C:\Windows\system32\slmgr.vbs(1333, 5) (null): 0xC0000034 Windows Activation Technologies--> HrOffline: 0x00000000 HrOnline: 0x00000000 HealthStatus: 0x0000000000000000 Event Time Stamp: 3:13:2012 14:21 ActiveX: Registered, Version: 7.1.7600.16395 Admin Service: Registered, Version: 7.1.7600.16395 HealthStatus Bitmask Output: HWID Data--> HWID Hash Current: MAAAAAEAAgABAAIAAAACAAAAAQABAAEA6GFyhzAkqn/SGpjwYPZuY95YAB7kLEbK OEM Activation 1.0 Data--> N/A OEM Activation 2.0 Data--> BIOS valid for OA 2.0: yes Windows marker version: 0x20001 OEMID and OEMTableID Consistent: yes BIOS Information: ACPI Table Name OEMID Value OEMTableID Value APIC 041709 APIC1908 FACP 041709 FACP1908 HPET 041709 OEMHPET MCFG 041709 OEMMCFG SLIC DELL FX09 OEMB 041709 OEMB1908 GSCI 041709 GMCHSCI SSDT DpgPmm CpuPm
Since the problem is in the VBS script area, let's re-register the files, and check (a couple of) the proper registry entries.....
Please open an elevated command prompt, and run the following commands.... (copy/paste them!)
net stop wuauserv
regsvr32 wuapi.dll /s
regsvr32 wups.dll /s
regsvr32 wuaueng.dll /s
regsvr32 wucltui.dll /s
regsvr32 wuweb.dll /s
regsvr32 msxml.dll /s
regsvr32 msxml2.dll /s
regsvr32 msxml3.dll /s
regsvr32 urlmon.dll /s
regsvr32 softpub.dll /s
regsvr32 initpki.dll /s
regsvr32 mssip32.dll /s
regsvr32 wintrust.dll /s
regsvr32 dssenh.dll /s
regsvr32 rsaenh.dll /s
regsvr32 gpkcsp.dll /s
regsvr32 sccbase.dll /s
regsvr32 slbcsp.dll /s
regsvr32 cryptdlg.dll /s
regsvr32 jscript.dll /s
regsvr32 vbscript.dll /s
net start wuauserv
Hopefully, they'll complete without obvious response.
then run the following commands, and post the results
REG QUERY HKEY_CLASSES_ROOT\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8} /S
REG QUERY HKLM\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}
REG QUERY HKLM\SOFTWARE\Classes\VBS\CLSID
REG QUERY HKLM\SOFTWARE\Classes\VBScript\CLSID
REG QUERY HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}
REG QUERY HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}
OK, I've done all that.
You will see that after the first set of commands, window update service could not be started.
Code:Microsoft Windows [Version 6.1.7601] Copyright (c) 2009 Microsoft Corporation. All rights reserved. C:\Users\admin>net stop wuauserv The Windows Update service is stopping. The Windows Update service was stopped successfully. C:\Users\admin>regsvr32 wuapi.dll /s C:\Users\admin>regsvr32 wups.dll /s C:\Users\admin>regsvr32 wuaueng.dll /s C:\Users\admin>regsvr32 wucltui.dll /s C:\Users\admin>regsvr32 wuweb.dll /s C:\Users\admin>regsvr32 msxml.dll /s C:\Users\admin>regsvr32 msxml2.dll /s C:\Users\admin>regsvr32 msxml3.dll /s C:\Users\admin>regsvr32 urlmon.dll /s C:\Users\admin>regsvr32 softpub.dll /s C:\Users\admin>regsvr32 initpki.dll /s C:\Users\admin>regsvr32 mssip32.dll /s C:\Users\admin>regsvr32 wintrust.dll /s C:\Users\admin>regsvr32 dssenh.dll /s C:\Users\admin>regsvr32 rsaenh.dll /s C:\Users\admin>regsvr32 gpkcsp.dll /s C:\Users\admin>regsvr32 sccbase.dll /s C:\Users\admin>regsvr32 slbcsp.dll /s C:\Users\admin>regsvr32 cryptdlg.dll /s C:\Users\admin>regsvr32 jscript.dll /s C:\Users\admin>regsvr32 vbscript.dll /s C:\Users\admin>net start wuauserv The Windows Update service is starting. The Windows Update service could not be started. The service did not report an error. More help is available by typing NET HELPMSG 3534. C:\Users\admin>REG QUERY HKEY_CLASSES_ROOT\CLSID\{B54F3741-5B07-11cf-A4B0-00AA00 4A55E8} /S HKEY_CLASSES_ROOT\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8} (Default) REG_SZ VB Script Language HKEY_CLASSES_ROOT\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\Implemented Categ ories HKEY_CLASSES_ROOT\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\Implemented Categ ories\{F0B7A1A1-9847-11CF-8F20-00805F2CD064} (Default) REG_NONE HKEY_CLASSES_ROOT\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\Implemented Categ ories\{F0B7A1A2-9847-11CF-8F20-00805F2CD064} (Default) REG_NONE HKEY_CLASSES_ROOT\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32 (Default) REG_SZ vbscript.dll ThreadingModel REG_SZ Both HKEY_CLASSES_ROOT\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\OLEScript (Default) REG_NONE HKEY_CLASSES_ROOT\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\ProgID (Default) REG_SZ VBScript C:\Users\admin>REG QUERY HKLM\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00 AA004A55E8} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8} (Default) REG_SZ VB Script Language HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8} \Implemented Categories HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8} \InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8} \OLEScript HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8} \ProgID C:\Users\admin>REG QUERY HKLM\SOFTWARE\Classes\VBS\CLSID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBS\CLSID (Default) REG_SZ {B54F3741-5B07-11cf-A4B0-00AA004A55E8} C:\Users\admin>REG QUERY HKLM\SOFTWARE\Classes\VBScript\CLSID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBScript\CLSID (Default) REG_SZ {B54F3741-5B07-11cf-A4B0-00AA004A55E8} C:\Users\admin>REG QUERY HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B54F3741-5B07- 11cf-A4B0-00AA004A55E8} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B54F3741-5B07-11cf-A4B0-0 0AA004A55E8} (Default) REG_SZ VB Script Language HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B54F3741-5B07-11cf-A4B0-0 0AA004A55E8}\Implemented Categories HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B54F3741-5B07-11cf-A4B0-0 0AA004A55E8}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B54F3741-5B07-11cf-A4B0-0 0AA004A55E8}\OLEScript HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B54F3741-5B07-11cf-A4B0-0 0AA004A55E8}\ProgID C:\Users\admin>REG QUERY HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B54F3741-5B07- 11cf-A4B0-00AA004A55E8} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-0 0AA004A55E8} (Default) REG_SZ VB Script Language HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-0 0AA004A55E8}\Implemented Categories HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-0 0AA004A55E8}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-0 0AA004A55E8}\OLEScript HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-0 0AA004A55E8}\ProgID
..sorry - fat-fingered the 'post'!
post the results
Your responses all look OK to me, apart from that.
Can't help feeling we're getting somewhere - maybe I'm a born optimist.
the results:
Any joy?Code:C:\Users\admin>NET START WUAUSERV The requested service has already been started. More help is available by typing NET HELPMSG 2182. C:\Users\admin>SC QUERYEX WUAUSERV SERVICE_NAME: WUAUSERV TYPE : 20 WIN32_SHARE_PROCESS STATE : 4 RUNNING (STOPPABLE, NOT_PAUSABLE, ACCEPTS_PRESHUTDOWN) WIN32_EXIT_CODE : 0 (0x0) SERVICE_EXIT_CODE : 0 (0x0) CHECKPOINT : 0x0 WAIT_HINT : 0x0 PID : 976 FLAGS :