Gnutella Forums

Gnutella Forums (https://www.gnutellaforums.com/)
-   BearShare Labs (https://www.gnutellaforums.com/bearshare-labs/)
-   -   [Resolved] my bearshare is jacked (https://www.gnutellaforums.com/bearshare-labs/62982-resolved-my-bearshare-jacked.html)

.jinxed October 26th, 2006 12:11 PM

[Resolved] my bearshare is jacked
 
ok so here is the situation...
after i load bearshare it wont crash or anything.. its fine.. until i start to download music then it freezes. i ran BearDiag as saw in another post someone made and here is the code.

Please help! ^-^

.jinxed October 26th, 2006 12:13 PM

Code:

BEARDIAG ISSUES - brief summary: (Extracted on 2006/10/26 15:07:45)

Microsoft Debug Manager found - not necessary
Sun Java update scheduler found - not necessary
Apple QuickTime taskbar player found - resource waster - not necessary
Sun Java update scheduler found - not necessary
Apple QuickTime taskbar player found - resource waster - not necessary
BearShare version 5.0.2.3 found. We recommend the 5.1.0.b25 beta version - see Recommended BearShare downloads
BearShare currently shows port 6346 for TCP and port 0 for UDP that need to match with your firewall/router configuration
BearShare configured "UDP port" setting should be altered to reflect a non-zero value - suggest 6346
BearShare configured 'Connection Type' is satellite - may need checking
You are behind a NAT firewall and/or router. They need to be correctly configured to allow BearShare to access the Internet.
 This is a common cause of problems with BearShare - it can't communicate.
 Check your firewall allows BearShare to communicate on TCP port 6346 and UDP port 6346
 If your connection is via a router, make sure it can forward BearShare traffic to a static IP address on your computer
 Refer to the following guidelines to correctly configure your firewall and router for use:
 - www.bearshare.com/help/firewalls/index.htm - the Firewall FAQ at the official BearShare Help site,
 - http://www.portforward.com/english/a...BearSindex.htm - the definitive guide to port forwarding and setting up a static IP address.
  (Hint: use static IP address 192.168.0.101, TCP Port 6346, and UDP port 6346).

More technical diagnostic troubleshooting information follows:

Code:

BEARDIAG: Bearcare for BearShare.
Details collected on 2006/10/26 15:06:46, BEARDIAG Version 01.99.13.0 beta, expires 2006/12/24 (59 days), running from C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\BearDiag.exe

System Hardware Information
CPU Type is: Intel(R) Pentium(R) 4 CPU 3.00GHz, CPU speed is approx: 3001Mhz, System BIOS date is: 2005/04/29
OS Version is: WIN_XP, Service pack: Service Pack 2, OS Build: 2600, Computer Name: JESSICASCOMPUTE
Browser name: C:\Program Files\Internet Explorer\iexplore.exe, version: 6.0.2900.2180, Admin user? YES

System Memory Parameters:        Memory in use:        42%
Total Physical RAM:        1015.3Mb        Available Physical RAM:        582.9Mb
Total Pagefile:                  2.4Gb        Available Pagefile:                2.0Gb

Process info for BearShare
Pagefile peak usage: 0, Number of threads: 20, Number of handles: 431, Virtual memory usage: 0

Internet IP Address 71.251.xxx.xxx  Local IP Address 192.168.0.101  You are behind a NAT firewall and/or router.

File Locations
Program files are at: C:\Program Files, System Temporary files are at: C:\DOCUME~1\HP_ADM~1.YOU\LOCALS~1\Temp, Common desktop is at:C:\Documents and Settings\All Users\Desktop
BearShare version installed is: 5.0.2.3, Gnutella servent BearShare full path is: C:\Program Files\BearShare\
Temporary downloads at: C:\Program Files\BearShare\Temp\, Completed downloads at: C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\Moya muzika, blyad'!\

Disk statistics
Drive C:        Total space: 180.10Gb        Free: 116.62Gb        Full: 35.2%        Vol type: NTFS

Folder Statistics
Temporary downloads folder:  Space used: 470,        File count: 2,        Write access allowed? YES,  # of DAT files: 1, #BAK: 1, #TIGER: 0, #TMP: 0, Other: 0
Completed downloads folder:  Space used: 77,        File count: 1,        Write access allowed? YES
BearShare library file 'library.db' size is 788.0Kb, '/db' library folder size is 3.2Mb, console log size is 0

FreePeers.ini settings
The freepeers.ini file is found at C:\Program Files\BearShare\FreePeers.ini. The extracted settings are as follows:

ProductLogic
NOT AVAILABLE        : bAlwaysUpdate; Always Download and announce latest signaled BearShare program updates from FreePeers.inc

Network
2        : connectionType; Network connection type
(0=Modem/AOL/ISDN, 1=Broadband/Cable/DSL/Wireless, 2=Satellite, 3=T1/T3/LAN/OC3/Microwave, 4=Custom values)
6346        : listenPort; TCP/IP port number to listen on

Hosts
No        : bNeverBecomeUltrapeer; Disable UltraPeer mode

Authentication
No        bAuthenticateHosts; Authenticate host connections
No        bAuthenticateDownloads; Authenticate search results and downloads

GBandwidthLogic
Yes        : bSymmetric; Is Internet connection symmetric
1500        : totalKbps; Maximum bandwidth for symmetric connections
1500        : sendKbps; Maximum outbound bandwidth for asymmetric connections
1500        : recvKbps; Maximum inbound bandwidth for asymmetric connections
No        : bMaxHostsKbps; Limit host bandwidth
0        : maxHostsKbps; Kbps of send/receive bandwidth to limit hosts
No        : bMaxUploadsKbps; Limit upload bandwidth
0        : maxUploadsKbps; Kbps of send bandwidth to limit uploads
No        : bMaxDownloadsKbps; Limit download bandwidth
0        : maxDownloadsKbps; Kbps of receive bandwidth to limit downloads

HostLogic
No        : m_bEverUltrapeerCapable; Has client ever been an UltraPeer?

FirewallLogic
No        : bTcpNFW; yes if TCP is not firewalled
No        : bUdpNFW; yes if UDP is not firewalled
0        : UDP Port; UDP port

Downloads
C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\Moya muzika, blyad'!        : szDownloadsDir; Directory where completed and hashed downloads are moved to
C:\Program Files\BearShare\Temp        : szTempDir; Directory where partial downloads are kept
50        : dlMaxFiles; Maximum files to download at once
999        : dlMaxStreams; Maximum connections total
999        : dlMaxStreamsFile; Maximum connections per file
No        : bDelCompletedDownloads;  ; Automatically remove completed downloads
Yes        : bEnableSparseFiles; Enable Sparse files for temporary files
No        : bDisablePushSources; Never send Push messages
No        : bDisablePushProxySources; Never send Push Proxy requests

Uploads
16        : maxTotUploads; Maximum files to upload at once
0        : lastSendBpsMaxAvg; last session average outgoing bandwidth

Firewall testing
Testing on port 6346 worked - http://www3.limewire.com:6346/ is accessible.
Testing on port 0 worked - http://www3.limewire.com:0/ is accessible.

C:\Program Files\BearShare\db\BearShareHostiles.zip: 1361560 bytes transferred over 7.62 seconds. Download speed is 1429Kbps.
LSPFix.exe: 186880 bytes transferred over 1.49 seconds. Download speed is 1006Kbps.


.jinxed October 26th, 2006 12:14 PM

Code:

StartupList report, 10/26/2006, 3:06:55 PM
StartupList version: 1.52
Started from : C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\StartupList.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\System32\svchost.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\D-Link AirPlus G\AirPlus.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BearShare\BearShare.EXE
C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\BearDiag.exe
C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\StartupList.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
D-Link AirPlus G Configuration Utility.lnk = ?
HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ehTray = C:\WINDOWS\ehome\ehtray.exe
SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
hpsysdrv = c:\windows\system\hpsysdrv.exe
High Definition Audio Property Page Shortcut = HDAudPropShortcut.exe
HotKeysCmds = C:\WINDOWS\system32\hkcmd.exe
AGRSMMSG = AGRSMMSG.exe
HPHUPD06 = c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
HPHmon06 = C:\WINDOWS\system32\hphmon06.exe
KBD = C:\HP\KBD\KBD.EXE
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
Recguard = C:\WINDOWS\SMINST\RECGUARD.EXE
ccApp = "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
URLLSTCK.exe = c:\Program Files\Norton Internet Security\UrlLstCk.exe
PS2 = C:\WINDOWS\system32\ps2.exe
SoundMan = SOUNDMAN.EXE
AlcWzrd = ALCWZRD.EXE
Alcmtr = ALCMTR.EXE
LSBWatcher = c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
Windows Registry Repair Pro = C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 6
MsnMsgr = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
BitTorrent = "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
STYLEXP = C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
Yahoo! Pager = "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
(no name) - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}

--------------------------------------------------

Enumerating Task Scheduler jobs:

HP DArC Task #Hewlett-Packard#7900#CN38U221J4EV.job
HP Usg Daily.job
Norton AntiVirus - Run Full System Scan - HP_Administrator.job
Norton SystemWorks One Button Checkup.job
Symantec Drmc.job
Symantec NetDetect.job

--------------------------------------------------

Enumerating Download Program Files:

[YInstStarter Class]
InProcServer32 = C:\Program Files\Yahoo!\Common\yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\Common\yinsthelper.dll

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

--------------------------------------------------
End of report, 7,394 bytes
Report generated in 0.063 seconds

Command line options:
  /verbose  - to add additional info on each section
  /complete - to include empty sections and unsuspicious data
  /full    - to include several rarely-important sections
  /force9x  - to include Win9x-only startups even if running on WinNT
  /forcent  - to include WinNT-only startups even if running on Win9x
  /forceall - to include all Win9x and WinNT startups, regardless of platform
  /history  - to list version history only

Code:

Current task list information for JESSICASCOMPUTE, running WIN_XP, Service Pack 2, build 2600
Details collected on 2006/10/26 15:06:51

 PID  Process Name            File Version  Pk Mem Usg. Command line that invoked task
    0 System Idle Process          0.0.0.0        0Mb  ><
    4 System                      0.0.0.0      2.39Mb  ><
  620 smss.exe              5.1.2600.2180      0.47Mb  >\SystemRoot\System32\smss.exe<
  672 csrss.exe                    0.0.0.0      4.07Mb  ><
  696 winlogon.exe          5.1.2600.2180      9.95Mb  >winlogon.exe<
  744 services.exe          5.1.2600.2180      4.05Mb  >C:\WINDOWS\system32\services.exe<
  756 lsass.exe              5.1.2600.2180      6.13Mb  >C:\WINDOWS\system32\lsass.exe<
  924 svchost.exe            5.1.2600.2180      4.8Mb  >C:\WINDOWS\system32\svchost -k DcomLaunch<
  992 svchost.exe                  0.0.0.0      4.45Mb  ><
 1032 svchost.exe            5.1.2600.2180    30.56Mb  >C:\WINDOWS\System32\svchost.exe -k netsvcs<
 1124 svchost.exe                  0.0.0.0        3Mb  ><
 1216 svchost.exe                  0.0.0.0      7.04Mb  ><
 1516 explorer.exe          6.0.2900.2180    28.91Mb  >C:\WINDOWS\Explorer.EXE<
 1592 ccProxy.exe              103.0.2.10    12.55Mb  >"c:\Program Files\Common Files\Symantec Shared\ccProxy.exe"<
 1608 ccSetMgr.exe              103.0.2.10      6.3Mb  >"c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"<
 1620 ISSVC.exe                  8.0.0.64      7.59Mb  >"c:\Program Files\Norton Internet Security\ISSVC.exe"<
 1632 navapsvc.exe                11.0.2.4    13.27Mb  >"c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"<
 1644 SNDSrvc.exe                5.4.2.17      4.58Mb  >"c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"<
 1668 SPBBCSvc.exe                1.0.1.47      5.29Mb  >"c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"<
 1748 ccEvtMgr.exe              103.0.2.10      6.65Mb  >"c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"<
 2036 spoolsv.exe            5.1.2600.2180      4.55Mb  >C:\WINDOWS\system32\spoolsv.exe<
  268 ehRecvr.exe            5.1.2700.2230      8.68Mb  >C:\WINDOWS\eHome\ehRecvr.exe<
  340 ehSched.exe            5.1.2700.2180      3.06Mb  >C:\WINDOWS\eHome\ehSched.exe<
  396 LSSrvc.exe                  1.0.13.1      1.38Mb  >"c:\Program Files\Common Files\LightScribe\LSSrvc.exe"<
  436 MDM.EXE                  7.0.9466.0      2.57Mb  >"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"<
 1316 SymWSC.exe              2005.1.0.111      8.34Mb  >"c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe"<
 2216 dllhost.exe            5.1.2600.2180      5.79Mb  >C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}<
 2588 alg.exe                      0.0.0.0      3.18Mb  ><
 2840 ehtray.exe            5.1.2700.2180      4.24Mb  >"C:\WINDOWS\ehome\ehtray.exe" <
 2848 jusched.exe                5.0.30.7      1.56Mb  >"C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" <
 2856 hpsysdrv.exe                1.7.0.0      1.64Mb  >"C:\windows\system\hpsysdrv.exe" <
 2948 hkcmd.exe                3.0.0.3971      3.71Mb  >"C:\WINDOWS\system32\hkcmd.exe" <
 2960 AGRSMMSG.exe              2.1.41.10      2.19Mb  >"C:\WINDOWS\AGRSMMSG.exe" <
 3040 hphmon06.exe                6.0.72.0      3.78Mb  >"C:\WINDOWS\system32\hphmon06.exe" <
 3048 kbd.exe                      1.0.2.0      5.01Mb  >"C:\HP\KBD\KBD.EXE" <
 3148 ehmsas.exe            5.1.2700.2180      3.35Mb  >C:\WINDOWS\eHome\ehmsas.exe -Embedding<
 3184 ccApp.exe                103.0.2.10    30.36Mb  >"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" <
 3280 SOUNDMAN.EXE                1.0.0.14      2.57Mb  >"C:\WINDOWS\SOUNDMAN.EXE" <
 3304 ALCWZRD.EXE                1.1.0.14      6.25Mb  >"C:\WINDOWS\ALCWZRD.EXE" <
 3356 ALCMTR.EXE                  1.5.0.0      3.05Mb  >"C:\WINDOWS\ALCMTR.EXE" <
 3380 svchost.exe            5.1.2600.2180      3.1Mb  >C:\WINDOWS\System32\svchost.exe -k HTTPFilter<
 3388 LSBurnWatcher.exe          4.10.14.0      3.03Mb  >"C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" <
 3408 qttask.exe                  6.5.1.17      2.05Mb  >"C:\Program Files\QuickTime\qttask.exe" -atboottime<
 3428 ctfmon.exe            5.1.2600.2180      2.91Mb  >"C:\WINDOWS\system32\ctfmon.exe" <
 3608 msnmsgr.exe                8.0.812.0    38.43Mb  >"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background<
 3852 AIRPLUS.exe                  1.0.0.0      4.84Mb  >"C:\Program Files\D-Link AirPlus G\AirPlus.exe" <
 3888 Updates from HP.exe          2.0.0.1      7.7Mb  >"C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe" -startup<
 3352 svchost.exe            5.1.2600.2180      3.45Mb  >C:\WINDOWS\system32\svchost.exe -k usnsvc<
 4572 IEXPLORE.EXE          6.0.2900.2180        48Mb  >"C:\Program Files\Internet Explorer\iexplore.exe" -Embedding<
 4172 BearShare.EXE                5.0.2.3    25.98Mb  >"C:\Program Files\BearShare\BearShare.EXE" <
 2392 BearDiag.exe              1.99.13.0    10.28Mb  >"C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\BearDiag.exe" <
 1196 wmiprvse.exe                0.0.0.0      7.08Mb  ><


BearShare library folder information for JESSICASCOMPUTE, running WIN_XP, Service Pack 2, build 2600
Details collected on 2006/10/26 15:07:46

 Volume in drive C is HP_PAVILION
 Volume Serial Number is 2CCD-1DA7

 Directory of C:\Program Files\BearShare\db

10/26/2006  03:07 PM    <DIR>          .
10/26/2006  03:07 PM    <DIR>          ..
10/26/2006  03:07 PM        1,361,560 BearShareHostiles.zip
09/09/2006  10:59 PM            3,103 config.bin
10/21/2006  10:14 PM          114,640 connect.txt
10/21/2006  10:14 PM            2,144 gwebcache.dat
09/09/2006  11:08 PM            3,692 Hostiles.old
04/30/2006  08:37 PM        10,384,336 Hostiles.txt
10/21/2006  10:14 PM                0 Hostiles-Chat.txt
10/26/2006  03:06 PM          806,912 library.2.db
10/26/2006  03:04 PM          806,912 library.2.db.lastgoodload.bak
10/26/2006  03:06 PM          806,912 library.db
10/26/2006  03:04 PM          806,912 library.db.lastgoodload.bak
10/21/2006  10:14 PM                19 searches.ini
              12 File(s)    15,097,142 bytes
              2 Dir(s)  125,202,690,048 bytes free

Code:

Firewall information for JESSICASCOMPUTE, running WIN_XP, Service Pack 2, build 2600
Details collected on 2006/10/26 15:07:49

Default gateway is 192.168.0.1


Domain profile configuration:
-------------------------------------------------------------------
Operational mode                  = Enable
Exception mode                    = Enable
Multicast/broadcast response mode = Enable
Notification mode                = Enable

Service configuration for Domain profile:
Mode    Customized  Name
-------------------------------------------------------------------
Enable  No          File and Printer Sharing

Allowed programs configuration for Domain profile:
Mode    Name / Program
-------------------------------------------------------------------
Enable  Remote Assistance / C:\WINDOWS\system32\sessmgr.exe
Enable  iTunes / C:\Program Files\iTunes\iTunes.exe
Enable  Windows Live Messenger 8.0 / C:\Program Files\MSN Messenger\msnmsgr.exe
Enable  Windows Live Messenger 8.0 (Phone) / C:\Program Files\MSN Messenger\msncall.exe

Port configuration for Domain profile:
Port  Protocol  Mode    Name
-------------------------------------------------------------------
139    TCP      Enable  NetBIOS Session Service
445    TCP      Enable  SMB over TCP
137    UDP      Enable  NetBIOS Name Service
138    UDP      Enable  NetBIOS Datagram Service

Standard profile configuration (current):
-------------------------------------------------------------------
Operational mode                  = Disable
Exception mode                    = Enable
Multicast/broadcast response mode = Enable
Notification mode                = Enable

Service configuration for Standard profile:
Mode    Customized  Name
-------------------------------------------------------------------
Enable  No          File and Printer Sharing

Allowed programs configuration for Standard profile:
Mode    Name / Program
-------------------------------------------------------------------
Enable  Remote Assistance / C:\WINDOWS\system32\sessmgr.exe
Enable  BackWeb for Pavilion / C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
Enable  Earthlink / C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
Enable  Windows Live Messenger 8.0 / C:\Program Files\MSN Messenger\msnmsgr.exe
Enable  Windows Live Messenger 8.0 (Phone) / C:\Program Files\MSN Messenger\msncall.exe
Enable  BitTorrent / C:\Program Files\BitTorrent\bittorrent.exe
Enable  LimeWire / C:\Program Files\LimeWire\LimeWire.exe
Enable  Yahoo! Messenger / C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
Enable  Yahoo! FT Server / C:\Program Files\Yahoo!\Messenger\YServer.exe

Port configuration for Standard profile:
Port  Protocol  Mode    Name
-------------------------------------------------------------------
139    TCP      Enable  NetBIOS Session Service
445    TCP      Enable  SMB over TCP
137    UDP      Enable  NetBIOS Name Service
138    UDP      Enable  NetBIOS Datagram Service

Log configuration:
-------------------------------------------------------------------
File location  = C:\WINDOWS\pfirewall.log
Max file size  = 4096 KB
Dropped packets = Disable
Connections    = Disable

Local Area Connection firewall configuration:
-------------------------------------------------------------------
Operational mode                  = Enable

Wireless Network Connection firewall configuration:
-------------------------------------------------------------------
Operational mode                  = Enable

1394 Connection firewall configuration:
-------------------------------------------------------------------
Operational mode                  = Enable


.jinxed October 26th, 2006 12:14 PM

Code:

Logfile of HijackThis v1.99.1
Scan saved at 3:07:07 PM, on 10/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\System32\svchost.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\D-Link AirPlus G\AirPlus.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BearShare\BearShare.EXE
C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\BearDiag.exe
C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 6
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


.

Ok that's it. lol.:D

.jinxed October 26th, 2006 12:18 PM

btw, i also had bearshare before and it was working perfectly fine. But when i had to put in the disk for my computer, the recovery disk(something was messing up my window system files as my friend sean said) and when i got the computer back up and running my bearshare downloads were gone, and when i opened bearshare it said the My Downloads folder was "missing" so i uninstalled it and tried limewire, same thing happened. :(

Peerless October 26th, 2006 01:21 PM

first thing....wtf is your home page doing set as "http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavili on&pf=desktop"

THAT is jacked....start up IE, go to tools>internet options and change that..to something...anydåmnthing (I use www.whatismyip.com )...HP is fekking EVIL...

since BS 'checks' with home upon startup (using IE) this may be the root of your problems

try that out, and report back

and....download AdAwareSE and Spybot Search & Destroy...install them...update them...and run them....

AaronWalkhouse October 26th, 2006 01:23 PM

The old downloads folder was probably deleted by the recovery program if it
was on the desktop. If you fish around in "C:\Documents and Settings" you
might get lucky and find the old account and it's desktop.

That old version of BearShare may be the problem. Go to this thread, where
you will find links to the beta version 5.1.0b25 and the BearStart utility. Since
that beta was a time-limited version you need BearStart to start it up.

Peerless October 26th, 2006 01:25 PM

and....the beta version mentioned in the diagnositcs report is mucho better

http://www.gnutellaforums.com/showthread.php?t=53386

download both the installer and the BearStart utility...

once installed, you have to run the BearStart utility to get the expired beta running...I do this by right clicking on the BearStart.exe, choosing 'pin to start menu' then starting from there...what it does is automatically goes to the beta version, starts it up, changes the date so that the program will run and yur off and running...don't forget to force UP mode ;)

.jinxed October 26th, 2006 01:25 PM

Quote:

Originally Posted by Peerless
first thing....wtf is your home page doing set as "http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavili on&pf=desktop"

THAT is jacked....start up IE, go to tools>internet options and change that..to something...anydåmnthing (I use www.whatismyip.com )...HP is fekking EVIL...

since BS 'checks' with home upon startup (using IE) this may be the root of your problems

try that out, and report back

and....download AdAwareSE and Spybot Search & Destroy...install them...update them...and run them....

yeah my thing is actually set to www.msn.com, however my default[when i click the default button] its that ie.redirect.hp.com... so yeah... and what do you mean about "since BS 'checks' with home upon startup (using IE) this may be the root of your problems" sorry i guess i'm noobish, cause i don't know what you mean by that :x

Peerless October 26th, 2006 01:26 PM

and FINALLY...download PeerGuardian 2 and use it....always when on any public network or BT tracker


All times are GMT -7. The time now is 08:28 AM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.