This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Laptop refuses to start up

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I followed the self help guide to boot up lap top in safe mode. Go to boot.ini select safe mode Restarted but it now refuses to get any further than a very faint windows load screen and freezes. I have looked at the bios and reset to factory defaults, gone to the F8 and tried all different start up types but its not playing ball at all now Anyone got any ideas? System is XP service pack 2, laptop is easy note packard bell
Hopefully you have access to a computer that can burn CD's

We will need to make a BOOT CD

Print these instruction out so that you know what you are doing.

Two programs to download

First

Please downloadISOBurner and save it to your desktop. This program will allow you to burn OTLPE.ISO to make a bootable CD.
  •  
  • Double click the ISOBurner set up icon to install the program, from there on in it is fairly automatic.
  • There are Instructions for the iso burner here if you need them.

Second


  • Download OTLPE.iso save it to your desktop. Now burn OTLPE.iso to a CD using ISO Burner. {NOTE: This file is 292Mb in size so it may take some time to download.)
  • When downloaded double click OTLPE.iso > this will then open ISOBurner to burn the file to CD

  • Reboot the infected system using the boot CD you just created.
    Note : If you do not know how to set your computer to boot from CD follow the steps here
  • Your system should now display a REATOGO-X-PE desktop.
  • you will find an icon on the desktop called OTLPE > Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
    • Change Drivers to SafeList
  • Press Run Scan to start the scan.
  • When finished, the file will be saved  in drive C:\OTL.txt
  • Copy this file to your USB drive if you do not have internet connection on this system
  • Please post the contents of the C:\OTL.txt file in your reply.
Thank you for that I have carried out your instructions and this is what I got

OTL logfile created on: 2/3/2010 11:49:35 AM - Run
OTLPE by OldTimer - Version 3.1.27.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 775.00 Mb Available Physical Memory | 76.00% Memory free
902.00 Mb Paging File | 840.00 Mb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 103.97 Gb Total Space | 73.32 Gb Free Space | 70.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 276.79 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
using ControlSet: ControlSet002

========== Win32 Services (SafeList) ==========

SRV - [2010/02/01 07:28:06 | 00,297,752 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto] – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd)
SRV - [2009/11/12 11:33:00 | 00,545,568 | —- | M] (Apple Inc.) [Disabled] – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service)
SRV - [2009/08/28 14:42:54 | 00,144,672 | —- | M] (Apple Inc.) [Disabled] – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/08/05 16:48:42 | 00,704,864 | —- | M] (Microsoft Corporation) [Disabled] – C:\Program Files\Windows Live\Family Safety\fsssvc.exe – (fsssvc)
SRV - [2009/05/21 05:34:05 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) [Disabled] – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2009/05/19 05:36:18 | 00,240,512 | —- | M] (Microsoft Corporation) [Disabled] – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2008/12/12 06:17:38 | 00,238,888 | —- | M] (Apple Inc.) [Auto] – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service)
SRV - [2008/12/08 06:53:12 | 00,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [Disabled] – C:\Program Files\Citrix\GoToAssist\508\g2aservice.exe – (GoToAssist)
SRV - [2007/10/12 02:33:38 | 00,202,016 | —- | M] (SupportSoft, Inc.) [Auto] – C:\Program Files\TalkTalk\bin\sprtsvc.exe – (sprtsvc_TalkTalk) SupportSoft Sprocket Service (TalkTalk)
SRV - [2007/09/20 15:05:06 | 00,589,824 | —- | M] ( ) [Disabled] – C:\WINDOWS\System32\lxdocoms.exe – (lxdo_device)
SRV - [2007/08/02 07:42:16 | 00,382,320 | —- | M] (SupportSoft, Inc.) [On_Demand] – C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe – (SupportSoft RemoteAssist)
SRV - [2007/08/02 07:42:14 | 00,148,768 | —- | M] (SupportSoft, Inc.) [Auto] – C:\Program Files\Common Files\Supportsoft\bin\tgsrvc.exe – (tgsrvc_TalkTalk) SupportSoft Repair Service (TalkTalk)
SRV - [2007/07/17 07:26:03 | 00,094,208 | —- | M] () [Disabled] – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdoserv.exe – (lxdoCATSCustConnectService)
SRV - [2005/01/31 04:45:20 | 00,049,152 | —- | M] (Ulead Systems, Inc.) [Auto] – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe – (UleadBurningHelper)
SRV - [2004/04/08 03:38:26 | 01,135,728 | —- | M] (America Online, Inc.) [Auto] – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe – (AOL ACS)
SRV - [2003/07/28 07:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) [Disabled] – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose)
SRV - [2001/11/12 08:31:48 | 00,020,480 | —- | M] (X10) [Disabled] – C:\Program Files\Common Files\X10\Common\X10nets.exe – (x10nets)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand] – – (WDICA)
DRV - File not found [Kernel | On_Demand] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDRELI)
DRV - File not found [Kernel | On_Demand] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDCOMP)
DRV - File not found [Kernel | System] – – (PCIDump)
DRV - File not found [Kernel | System] – – (lbrtfdc)
DRV - File not found [Kernel | System] – – (Changer)
DRV - File not found [Kernel | On_Demand] – – (AFGSp50)
DRV - File not found [Kernel | On_Demand] – – (AFGMp50)
DRV - [2010/02/01 09:58:53 | 00,096,512 | —- | M] () [Kernel | Boot] – C:\WINDOWS\system32\drivers\atapi.sys – (atapi)
DRV - [2010/01/21 09:40:44 | 00,335,240 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2010/01/21 09:40:44 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2010/01/21 09:31:01 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2009/08/28 14:42:52 | 00,040,448 | —- | M] (Apple, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\usbaapl.sys – (USBAAPL)
DRV - [2009/08/05 16:48:42 | 00,054,752 | —- | M] (Microsoft Corporation) [Kernel | Auto] – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys – (fssfltr)
DRV - [2009/05/18 09:17:00 | 00,026,600 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2008/04/13 13:36:39 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\amdagp.sys – (amdagp)
DRV - [2008/04/13 13:36:39 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\sisagp.sys – (sisagp)
DRV - [2008/04/13 11:36:05 | 00,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2007/11/13 05:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv)
DRV - [2006/12/25 03:41:27 | 00,008,552 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto] – C:\WINDOWS\system32\drivers\asctrm.sys – (ASCTRM)
DRV - [2005/11/28 05:45:16 | 00,007,040 | —- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\x10hid.sys – (X10Hid)
DRV - [2005/11/03 10:50:58 | 01,353,820 | —- | M] (Intel Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\ialmnt5.sys – (ialm)
DRV - [2005/10/26 15:12:48 | 00,020,640 | —- | M] (Sonic Solutions) [Kernel | Boot] – C:\WINDOWS\system32\drivers\pxhelp20.sys – (PxHelp20)
DRV - [2005/06/20 06:33:18 | 00,190,400 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2005/05/25 10:55:58 | 03,134,976 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/05/13 12:39:24 | 01,094,881 | R— | M] (Agere Systems) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2005/03/04 06:10:26 | 00,074,496 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\Rtlnicxp.sys – (RTL8023xp)
DRV - [2005/01/07 12:07:16 | 00,145,920 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\Hdaudio.sys – (HdAudAddService)
DRV - [2004/10/29 13:48:10 | 03,222,784 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\w29n51.sys – (w29n51) Intel®
DRV - [2004/08/10 09:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink)
DRV - [2004/08/10 09:00:00 | 00,007,936 | —- | M] (Microsoft Corporation) [Recognizer | System] – C:\WINDOWS\system32\drivers\fs_rec.sys – (Fs_Rec)
DRV - [2004/08/10 09:00:00 | 00,002,864 | —- | M] (Microsoft Corporation) [Adapter | On_Demand] – C:\WINDOWS\system32\winsock.dll – (Winsock)
DRV - [2003/01/10 11:13:04 | 00,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 09:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\sparrow.sys – (Sparrow)
DRV - [2001/08/17 09:07:42 | 00,030,688 | —- | M] (LSI Logic) [Kernel | Boot] – C:\WINDOWS\system32\drivers\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 09:07:40 | 00,028,384 | —- | M] (LSI Logic) [Kernel | Boot] – C:\WINDOWS\system32\drivers\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 09:07:36 | 00,032,640 | —- | M] (LSI Logic) [Kernel | Boot] – C:\WINDOWS\system32\drivers\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 09:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\symc810.sys – (symc810)
DRV - [2001/08/17 08:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\ultra.sys – (ultra)
DRV - [2001/08/17 08:52:20 | 00,045,312 | —- | M] (QLogic Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\ql12160.sys – (ql12160)
DRV - [2001/08/17 08:52:20 | 00,040,320 | —- | M] (QLogic Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\ql1080.sys – (ql1080)
DRV - [2001/08/17 08:52:18 | 00,049,024 | —- | M] (QLogic Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\ql1280.sys – (ql1280)
DRV - [2001/08/17 08:52:16 | 00,179,584 | —- | M] (Mylex Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 08:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 08:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\asc.sys – (asc)
DRV - [2001/08/17 08:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\asc3550.sys – (asc3550)
DRV - [2001/08/17 08:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\aliide.sys – (AliIde)
DRV - [2001/08/17 08:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\cmdide.sys – (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\Ally_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
IE - HKU\Ally_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\Ally_ON_C\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKU\Ally_ON_C\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKU\Ally_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\Ally_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\ally_test_ON_C\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKU\ally_test_ON_C\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKU\ally_test_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\Emily_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\Emily_ON_C\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKU\Emily_ON_C\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKU\Emily_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1


IE - HKU\Matt_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\Matt_ON_C\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKU\Matt_ON_C\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKU\Matt_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\Russ_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\Russ_ON_C\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKU\Russ_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2010/02/01 07:29:23 | 00,000,000 | —D | M]

[2007/03/16 10:50:31 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2007/03/11 18:08:58 | 00,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

O1 HOSTS File: ([2010/01/21 05:26:32 | 00,373,587 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 12876 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKU\Ally_ON_C\..\Toolbar\ShellBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\Ally_ON_C\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\Ally_ON_C\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\Ally_ON_C\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKU\ally_test_ON_C\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\ally_test_ON_C\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\ally_test_ON_C\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKU\Emily_ON_C\..\Toolbar\ShellBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\Emily_ON_C\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\Emily_ON_C\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\Emily_ON_C\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKU\Matt_ON_C\..\Toolbar\ShellBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\Matt_ON_C\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\Matt_ON_C\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\Matt_ON_C\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKU\Russ_ON_C\..\Toolbar\ShellBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\Russ_ON_C\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKU\Russ_ON_C\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\Russ_ON_C\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AGRSMMSG] C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKU\Ally_ON_C..\Run: [SmpcSys] C:\APPS\SMP\SMPSYS.EXE (Packard Bell BV)
O4 - HKU\Ally_ON_C..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe File not found
O4 - HKU\Ally_ON_C..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKU\Emily_ON_C..\Run: [ontgmqif] C:\Documents and Settings\Emily\Local Settings\Application Data\dqcbif\nllasysguard.exe File not found
O4 - HKU\Emily_ON_C..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKU\Emily_ON_C..\Run: [Skype] C:\APPS\skype\phone\Skype.exe ()
O4 - HKU\Emily_ON_C..\Run: [userinit] C:\Documents and Settings\Emily\Application Data\sdra64.exe File not found
O4 - HKU\Matt_ON_C..\Run: [BitTorrent DNA] C:\Documents and Settings\Matt\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKU\Matt_ON_C..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKU\Ally_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Ally_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKU\ally_test_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\ally_test_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKU\Emily_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Emily_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Matt_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Matt_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Russ_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Russ_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\Administrator_ON_C\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\Ally_ON_C\..Trusted Domains: org.uk ([www.mab] * in Trusted sites)
O15 - HKU\Ally_ON_C\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\ally_test_ON_C\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\Emily_ON_C\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\Russ_ON_C\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {4ECE056F-E50F-4F9D-B069-EB342D21F26A} http://www3.snapfish.co.uk/SnapfishActivia3.cab (Snapfish Activia3)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\508\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\508\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\APPS\DESKTOP\DESKTOP.HTM
O24 - Desktop BackupWallPaper: C:\APPS\DESKTOP\DESKTOP.HTM
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 06:06:41 | 00,000,053 | R— | M] () - X:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/29 10:43:10 | 00,000,000 | —D | C] – C:\Avenger
[2010/01/29 10:26:50 | 00,000,000 | —D | C] – C:\Documents and Settings\Russ\Application Data\Malwarebytes
[2010/01/29 10:26:06 | 00,000,000 | -HSD | C] – C:\Documents and Settings\Russ\IECompatCache
[2010/01/29 10:23:28 | 00,000,000 | -HSD | C] – C:\Documents and Settings\Emily\IECompatCache
[2010/01/29 10:12:07 | 00,000,000 | —D | C] – C:\Documents and Settings\Matt\Program Files
[2010/01/29 09:07:49 | 00,000,000 | —D | C] – C:\Documents and Settings\Ally\Application Data\Malwarebytes
[2010/01/29 09:07:43 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/29 09:07:40 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/29 09:07:40 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/29 09:02:51 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/01/29 09:02:18 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/01/29 04:43:59 | 00,000,000 | —D | C] – C:\Program Files\TrendMicro
[2010/01/21 10:16:29 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2010/01/21 09:31:02 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/01/21 09:31:01 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/01/21 09:30:55 | 00,335,240 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/01/21 09:30:53 | 00,027,784 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/01/21 09:30:46 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/01/19 16:09:47 | 00,000,000 | —D | C] – C:\Documents and Settings\ally test\Application Data\AdobeUM
[2010/01/19 16:09:01 | 00,000,000 | —D | C] – C:\Documents and Settings\ally test\Local Settings\Application Data\Adobe
[2010/01/19 14:58:47 | 00,000,000 | —D | C] – C:\Documents and Settings\ally test\Tracing
[2010/01/19 14:56:30 | 00,000,000 | —D | C] – C:\Documents and Settings\ally test\Local Settings\Application Data\Apple Computer
[2010/01/19 14:41:17 | 00,000,000 | —D | C] – C:\Documents and Settings\Russ\Application Data\AdobeUM
[2010/01/17 06:33:51 | 00,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2008/12/08 12:01:40 | 00,438,272 | —- | C] ( ) – C:\WINDOWS\System32\lxdohcp.dll
[2008/12/08 12:01:39 | 00,954,368 | —- | C] ( ) – C:\WINDOWS\System32\lxdousb1.dll
[2008/12/08 12:01:39 | 00,360,448 | —- | C] ( ) – C:\WINDOWS\System32\lxdoinpa.dll
[2008/12/08 12:01:39 | 00,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdoiesc.dll
[2008/12/08 12:01:38 | 01,069,056 | —- | C] ( ) – C:\WINDOWS\System32\lxdoserv.dll
[2008/12/08 12:01:38 | 00,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxdopmui.dll
[2008/12/08 12:01:38 | 00,569,344 | —- | C] ( ) – C:\WINDOWS\System32\lxdolmpm.dll
[2008/12/08 12:01:38 | 00,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdoprox.dll
[2008/12/08 12:01:35 | 00,663,552 | —- | C] ( ) – C:\WINDOWS\System32\lxdohbn3.dll
[2008/12/08 12:01:33 | 00,851,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdocomc.dll
[2008/12/08 12:01:33 | 00,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxdocomm.dll
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Russ\Desktop\*.tmp files -> C:\Documents and Settings\Russ\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\Ally\My Documents\*.tmp files -> C:\Documents and Settings\Ally\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/02/03 11:49:08 | 04,718,592 | —- | M] () – C:\Documents and Settings\Administrator\NTUSER.DAT
[2010/02/01 14:27:11 | 00,262,144 | -H– | M] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/02/01 14:27:11 | 00,262,144 | -H– | M] () – C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/02/01 14:27:11 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/01 14:26:51 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/01 14:26:50 | 07,077,888 | —- | M] () – C:\Documents and Settings\Russ\NTUSER.DAT
[2010/02/01 14:26:50 | 00,000,278 | -HS- | M] () – C:\Documents and Settings\Russ\ntuser.ini
[2010/02/01 14:26:36 | 00,000,696 | —- | M] () – C:\WINDOWS\win.ini
[2010/02/01 14:26:36 | 00,000,297 | RHS- | M] () – C:\BOOT.INI
[2010/02/01 14:26:36 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/02/01 14:25:06 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/01 14:23:20 | 10,634,40384 | -HS- | M] () – C:\hiberfil.sys
[2010/02/01 12:30:00 | 00,000,246 | —- | M] () – C:\WINDOWS\tasks\Setup my PC.job
[2010/02/01 12:06:31 | 54,966,920 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/02/01 09:58:53 | 00,096,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atapi.sys
[2010/02/01 09:58:53 | 00,096,512 | —- | M] () – C:\WINDOWS\System32\drivers\atapi.sys
[2010/02/01 09:24:40 | 00,284,915 | —- | M] () – C:\Documents and Settings\Russ\Desktop\gmer.zip
[2010/01/29 10:42:26 | 08,650,752 | —- | M] () – C:\Documents and Settings\Ally\NTUSER.DAT
[2010/01/29 10:42:26 | 00,000,278 | -HS- | M] () – C:\Documents and Settings\Ally\ntuser.ini
[2010/01/29 10:24:47 | 07,340,032 | —- | M] () – C:\Documents and Settings\Emily\NTUSER.DAT
[2010/01/29 10:24:47 | 00,000,278 | -HS- | M] () – C:\Documents and Settings\Emily\ntuser.ini
[2010/01/29 10:20:54 | 03,145,728 | —- | M] () – C:\Documents and Settings\Matt\NTUSER.DAT
[2010/01/29 10:20:54 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Matt\ntuser.ini
[2010/01/29 10:12:15 | 00,102,224 | —- | M] () – C:\Documents and Settings\Matt\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/01/29 09:02:23 | 00,000,614 | —- | M] () – C:\Documents and Settings\Ally\Desktop\NTREGOPT.lnk
[2010/01/29 09:02:22 | 00,000,595 | —- | M] () – C:\Documents and Settings\Ally\Desktop\ERUNT.lnk
[2010/01/29 04:44:31 | 00,002,439 | —- | M] () – C:\Documents and Settings\Ally\Desktop\HiJackThis.lnk
[2010/01/29 04:30:14 | 00,016,384 | —- | M] () – C:\Documents and Settings\Ally\My Documents\Ally 40th.xls
[2010/01/21 09:40:44 | 00,492,629 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/01/21 09:40:44 | 00,335,240 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/01/21 09:40:44 | 00,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/21 09:40:44 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/01/21 09:40:44 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/01/21 09:31:24 | 04,927,488 | —- | M] () – C:\Documents and Settings\ally test\NTUSER.DAT
[2010/01/21 09:31:01 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/01/21 09:30:46 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/01/21 05:26:32 | 00,373,587 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/01/19 16:48:52 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\ally test\ntuser.ini
[2010/01/19 16:33:27 | 00,048,128 | —- | M] () – C:\Documents and Settings\ally test\My Documents\voucher.pub
[2010/01/19 15:43:37 | 00,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/01/17 07:20:32 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/01/11 11:52:02 | 07,142,912 | —- | M] () – C:\Documents and Settings\Emily\My Documents\Art work.ppt
[2010/01/08 08:28:01 | 00,020,992 | —- | M] () – C:\Documents and Settings\Ally\My Documents\Weldon benenfit fraud.doc
[2010/01/08 08:15:13 | 00,401,920 | —- | M] () – C:\Documents and Settings\Ally\My Documents\Weldon Electoral roll.doc
[2010/01/08 07:35:14 | 00,029,696 | —- | M] () – C:\Documents and Settings\Ally\My Documents\Allys CV.doc
[2010/01/07 11:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 11:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/04 13:28:01 | 00,102,224 | —- | M] () – C:\Documents and Settings\Emily\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/01/04 13:25:25 | 00,081,404 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/01/04 13:15:04 | 00,102,224 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/01/04 13:14:19 | 00,391,976 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Russ\Desktop\*.tmp files -> C:\Documents and Settings\Russ\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\Ally\My Documents\*.tmp files -> C:\Documents and Settings\Ally\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/02/01 09:24:37 | 00,284,915 | —- | C] () – C:\Documents and Settings\Russ\Desktop\gmer.zip
[2010/01/29 09:02:23 | 00,000,614 | —- | C] () – C:\Documents and Settings\Ally\Desktop\NTREGOPT.lnk
[2010/01/29 09:02:22 | 00,000,595 | —- | C] () – C:\Documents and Settings\Ally\Desktop\ERUNT.lnk
[2010/01/29 04:44:00 | 00,002,439 | —- | C] () – C:\Documents and Settings\Ally\Desktop\HiJackThis.lnk
[2010/01/21 09:30:46 | 54,966,920 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/01/21 09:30:46 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2010/01/21 09:30:46 | 00,492,629 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2010/01/21 09:30:46 | 00,142,495 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/19 16:33:21 | 00,048,128 | —- | C] () – C:\Documents and Settings\ally test\My Documents\voucher.pub
[2010/01/08 08:28:01 | 00,020,992 | —- | C] () – C:\Documents and Settings\Ally\My Documents\Weldon benenfit fraud.doc
[2010/01/08 08:15:13 | 00,401,920 | —- | C] () – C:\Documents and Settings\Ally\My Documents\Weldon Electoral roll.doc
[2010/01/07 12:15:01 | 07,142,912 | —- | C] () – C:\Documents and Settings\Emily\My Documents\Art work.ppt
[2008/12/08 12:08:58 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxdovs.dll
[2008/12/08 12:08:52 | 00,348,160 | —- | C] () – C:\WINDOWS\System32\lxdocoin.dll
[2008/12/08 12:07:59 | 00,692,224 | —- | C] () – C:\WINDOWS\System32\lxdodrs.dll
[2008/12/08 12:07:59 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\lxdocnv4.dll
[2008/12/08 12:07:59 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\lxdocaps.dll
[2008/12/08 12:07:25 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\LXDOPMON.DLL
[2008/12/08 12:07:25 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\LXDOFXPU.DLL
[2008/12/08 12:07:05 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\lxdooem.dll
[2008/12/08 12:02:37 | 00,028,672 | —- | C] () – C:\WINDOWS\hookdllX.dll
[2008/12/08 12:02:37 | 00,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2008/12/08 12:01:58 | 00,000,060 | -H– | C] () – C:\WINDOWS\System32\lxdorwrd.ini
[2008/12/08 12:01:40 | 00,348,160 | —- | C] () – C:\WINDOWS\System32\lxdoinst.dll
[2008/12/08 12:01:35 | 00,208,896 | —- | C] () – C:\WINDOWS\System32\lxdogrd.dll
[2008/10/08 12:28:30 | 00,000,750 | —- | C] () – C:\WINDOWS\{D084B1A9-153B-409D-AEBF-C40FCEF925EA}_WiseFW.ini
[2008/04/06 10:53:04 | 00,000,000 | —- | C] () – C:\WINDOWS\BBCAuto.INI
[2008/04/06 10:52:46 | 00,000,061 | —- | C] () – C:\WINDOWS\Tiny_Run.ini
[2008/04/06 02:22:11 | 00,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2008/02/10 06:30:36 | 00,005,632 | —- | C] () – C:\Documents and Settings\Russ\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/12 12:35:51 | 00,000,037 | —- | C] () – C:\WINDOWS\Pacf.INI
[2007/10/08 06:53:20 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\Docobj.dll
[2007/10/08 06:53:08 | 00,000,264 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2007/09/13 10:44:47 | 00,000,128 | —- | C] () – C:\Documents and Settings\Emily\Local Settings\Application Data\fusioncache.dat
[2007/06/18 07:09:48 | 00,000,112 | —- | C] () – C:\WINDOWS\ActiveSkin.INI
[2007/06/06 15:54:25 | 00,022,528 | —- | C] () – C:\Documents and Settings\Ally\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/24 14:03:44 | 00,000,030 | —- | C] () – C:\WINDOWS\iedit.INI
[2007/04/08 10:46:46 | 00,012,288 | —- | C] () – C:\Documents and Settings\Emily\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/03/20 11:57:18 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\LXPRMON.DLL
[2007/03/20 11:57:18 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\LXPMONUI.DLL
[2007/03/18 07:47:16 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/03/11 14:29:15 | 00,000,127 | —- | C] () – C:\Documents and Settings\Ally\Local Settings\Application Data\fusioncache.dat
[2006/12/25 04:13:09 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/12/25 03:48:49 | 00,000,514 | —- | C] () – C:\WINDOWS\System32\SETUPPC.INI
[2006/12/25 03:42:17 | 00,007,604 | —- | C] () – C:\WINDOWS\HDReg.ini
[2006/12/25 03:22:48 | 00,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2006/03/23 09:24:10 | 00,006,399 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/05 09:01:54 | 00,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/05/12 14:24:00 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/09/10 10:50:43 | 00,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/18 08:00:00 | 00,035,328 | -H– | C] () – C:\WINDOWS\System32\msls50.dll
[2004/08/03 17:59:44 | 00,096,512 | —- | C] () – C:\WINDOWS\System32\drivers\atapi.sys
[2003/01/07 10:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/06/10 16:13:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Ally\Application Data\9500 Series
[2009/06/09 02:47:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Ally\Application Data\aAvgApi
[2008/10/21 11:35:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Ally\Application Data\Affinegy
[2009/06/10 16:16:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Ally\Application Data\Lexmark Productivity Studio
[2007/03/11 14:35:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Ally\Application Data\OD2
[2009/11/17 13:23:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Ally\Application Data\Smilebox
[2007/03/21 13:43:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Ally\Application Data\Ulead Systems
[2008/12/08 14:36:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Emily\Application Data\9500 Series
[2008/10/20 02:08:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Emily\Application Data\Affinegy
[2010/01/29 10:21:40 | 00,000,000 | -HSD | M] – C:\Documents and Settings\Emily\Application Data\lowsec
[2007/10/31 15:46:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Emily\Application Data\OD2
[2007/10/22 04:57:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Emily\Application Data\Ulead Systems
[2007/03/11 18:07:51 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\X10 Commander
[2008/12/29 06:35:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Matt\Application Data\9500 Series
[2008/10/10 04:20:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Matt\Application Data\Affinegy
[2009/05/14 13:06:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Matt\Application Data\AVG7
[2009/05/19 13:40:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Matt\Application Data\AVGTOOLBAR
[2010/01/29 10:20:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Matt\Application Data\DNA
[2008/12/29 07:01:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Matt\Application Data\My Battle for Middle-earth™ II Files
[2008/02/26 13:16:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Matt\Application Data\Ulead Systems
[2007/03/11 18:07:51 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\X10 Commander
[2008/12/23 22:36:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Russ\Application Data\9500 Series
[2008/10/08 12:20:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Russ\Application Data\Affinegy
[2009/05/21 04:22:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Russ\Application Data\OD2
[2008/01/16 07:23:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Russ\Application Data\Ulead Systems
[2008/04/11 11:22:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Russ\Application Data\Viewpoint
[2010/02/01 12:30:00 | 00,000,246 | —- | M] () – C:\WINDOWS\Tasks\Setup my PC.job

========== Purity Check ==========


< End of report >
Hi,

Please do the following:

Copy and paste the following fix into Notepad - make sure wordwrap is unchecked:


:OTL
O4 - HKU\Emily_ON_C..\Run: [ontgmqif] C:\Documents and Settings\Emily\Local Settings\Application Data\dqcbif\nllasysguard.exe File not found
O4 - HKU\Emily_ON_C..\Run: [userinit] C:\Documents and Settings\Emily\Application Data\sdra64.exe File not found
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\Administrator_ON_C\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\Ally_ON_C\..Trusted Domains: org.uk ([www.mab] * in Trusted sites)
O15 - HKU\Ally_ON_C\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\ally_test_ON_C\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\Emily_ON_C\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\Russ_ON_C\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
[2010/01/29 10:21:40 | 00,000,000 | -HSD | M] – C:\Documents and Settings\Emily\Application Data\lowsec

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
"Userinit"="C:\\WINDOWS\\system32\\Userinit.exe,"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoSetActiveDesktop"=-
"NoActiveDesktopChanges"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoSetActiveDesktop"=-
"NoActiveDesktopChanges"=-



save it as Fix.txt > save as "all files" and save it to a USB stick:

Now go back to the infected PC>

Restart OTLPE

Click on OTL to open

  • Click the red Run Fix button.
  • You should be presented with a message "No Fix has been Provided! Do you want to load it from a file? Click Yes.
  • Browse to the Fix.txt file on your USB stick, and click Open. The fix will then appear in the Custom Scans/Fixes window.
  • Click the red Run Fix button again.


You should now be able to start the infected PC normally

Let me know if you are successful:

then run this scan on the infected PC as there will probably be more work to do:

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thank you for that. I have done all with regard to OLP and did the fix, but when I tried to start the machine normally it just froze in the same place. On the windows start up page, but very faint and the little scroll bar didnt scroll. Your further thoughts would be appreciated. BTW booting from the burnt cd was ok
are you able to boot into safe mode? when your computer boots up - tap F8 repeatedly until an option menu appears. arrow up to "safe mode with networking" Let me know if that works
OK

Let's try this:

Go back into OTLPE…

First I want to make sure you have service pack files accessible to you and that agpCPQ.sys exists there

Navigate to C:\WINDOWS\ServicePackFiles\i386

bottom left of the ReattoGo GUI is a small windows type symbol > that's your start button

go to Start> My computer> C:\ local files > windows > Service pack files > i386

locate > agpCPQ.sys - if it is there > right click it and choose copy


now back out of that folder and head to c:\windows\system32\drivers folder

>locate the agpCPQ.sys file > right click on it and choose "rename" rename it to agpCPQ.sys.old

now right click in the space beside that file and choose "paste"

the agpCPQ.sys file you previously copied from the i386 folder will now be in the drivers folder

exit and see if you can reboot normally.
Done No good on restart normal, restart in safe mode with network prompt same hang point I really appreciate your patience with this you are really good guuys
Ok,

maybe this isn't a malware hangup here.

It may be related to your video driver itself.

Try this:

Tap F8 on startup again and then try booting into Enable VGA mode instead of Safe mode.

That loads Windows normally except it forces the video into a basic VGA mode that all video hardware supports, and the specific drivers for your video hardware are not loaded.

If that gets you to the desktop, you can then un-install the video drivers in Add/Remove programs and then re-install them.

Try and find the most up to date drivers there are if that works.
what happens when you try and boot in normal mode? Do you know if you have the recovery console installed on this machine do you have your installation disk?
Just a thought Dont forget it was me who changed the sysconfig boot.ini file to boot in safe mode that then caused the laptop to not start on restart so maybe ID10T error is more likely?
That's a description of the recovery console.
http://support.microsoft.com/kb/314058

This may not assist us in this situation anyway.

Do you recall specifically what you did in the BIOS?
Try entering back into the BIOS (is it F2 on your computer?)

and undo all the changes you made.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI