This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Unable to boot up

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I power on my computer it presents me and stays on the starting screen. It does not allow me to enter setup. I do not have a system restore disc. It is Windows XP. Can you help? Thank you.
Hopefully you have access to a computer that can burn CD's

We will need to make a BOOT CD

Print these instruction out so that you know what you are doing.

Two programs to download

First

Please downloadISOBurner and save it to your desktop. This program will allow you to burn OTLPE.ISO to make a bootable CD.
  •  
  • Double click the ISOBurner set up icon to install the program, from there on in it is fairly automatic.
  • There are Instructions for the iso burner here if you need them.

Second


  • Download OTLPE.iso save it to your desktop. Now burn OTLPE.iso to a CD using ISO Burner. {NOTE: This file is 292Mb in size so it may take some time to download.)
  • When downloaded double click OTLPE.iso > this will then open ISOBurner to burn the file to CD

  • Reboot the infected system using the boot CD you just created.
    Note : If you do not know how to set your computer to boot from CD follow the steps here
  • Your system should now display a REATOGO-X-PE desktop.
  • you will find an icon on the desktop called OTLPE > Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
    • Change Drivers to SafeList
  • Press Run Scan to start the scan.
  • When finished, the file will be saved  in drive C:\OTL.txt
  • Copy this file to your USB drive if you do not have internet connection on this system
  • Please post the contents of the C:\OTL.txt file in your reply.
below is the contents of the OTL file as instructed. Thank you for helping.

OTL logfile created on: 3/19/2010 10:44:07 AM - Run
OTLPE by OldTimer - Version 3.1.37.1 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

958.00 Mb Total Physical Memory | 719.00 Mb Available Physical Memory | 75.00% Memory free
858.00 Mb Paging File | 762.00 Mb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.32 Gb Total Space | 32.30 Gb Free Space | 45.93% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 276.80 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
Using ControlSet: ControlSet001

========== Win32 Services (SafeList) ==========

SRV - [2010/02/14 17:23:08 | 000,083,280 | —- | M] (BullGuard Ltd.) [On_Demand] – C:\Program Files\BullGuard Ltd\BullGuard\support\bgrasvc.exe – (BGRaSvc)
SRV - [2010/02/14 17:23:01 | 000,341,328 | —- | M] (BullGuard Ltd.) [Auto] – C:\Program Files\BullGuard Ltd\BullGuard\BsFire.dll – (BsFire)
SRV - [2010/02/14 17:22:59 | 000,304,464 | —- | M] (BullGuard Ltd.) [Auto] – C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe – (BgLiveSvc)
SRV - [2010/02/14 17:22:58 | 000,079,184 | —- | M] (BullGuard Ltd.) [Auto] – C:\Program Files\BullGuard Ltd\BullGuard\BsMain.dll – (BgMainSvc)
SRV - [2009/12/06 13:43:07 | 000,028,762 | —- | M] (MyWebSearch.com) [Disabled] – C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE – (MyWebSearchService)
SRV - [2009/08/05 18:48:42 | 000,704,864 | —- | M] (Microsoft Corporation) [On_Demand] – C:\Program Files\Windows Live\Family Safety\fsssvc.exe – (fsssvc)
SRV - [2009/05/19 07:36:18 | 000,240,512 | —- | M] (Microsoft Corporation) [Auto] – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2009/04/16 08:20:18 | 000,087,376 | —- | M] (BullGuard Ltd.) [Auto] – C:\Program Files\BullGuard Ltd\BullGuard\BsMailProxy.dll – (BsMailProxy)
SRV - [2009/04/06 06:32:54 | 000,132,432 | —- | M] (BullGuard Ltd.) [Auto] – C:\Program Files\BullGuard Ltd\BullGuard\BsFileScan.dll – (BsFileScan)
SRV - [2008/06/26 08:52:42 | 000,204,800 | —- | M] () [Auto] – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe – (LinksysUpdater)
SRV - [2008/05/16 01:11:44 | 000,648,504 | —- | M] (Pure Networks, Inc.) [Auto] – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe – (nmservice)
SRV - [2004/04/08 03:38:26 | 001,135,728 | —- | M] (America Online, Inc.) [Disabled] – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe – (AOL ACS)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand] – – (WDICA)
DRV - File not found [Kernel | On_Demand] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDRELI)
DRV - File not found [Kernel | On_Demand] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDCOMP)
DRV - File not found [Kernel | System] – – (PCIDump)
DRV - File not found [Kernel | System] – – (lbrtfdc)
DRV - File not found [Kernel | System] – – (Changer)
DRV - File not found [Kernel | On_Demand] – – (catchme)
DRV - [2010/02/14 17:23:04 | 000,256,792 | R— | M] (Agnitum Ltd.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\AfwCore.sys – (afwcore)
DRV - [2010/02/14 17:23:04 | 000,031,640 | R— | M] (Agnitum Ltd.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\Afw.sys – (afw)
DRV - [2009/08/08 11:17:20 | 000,039,808 | —- | M] (BitDefender S.R.L.) [Kernel | On_Demand] – C:\Program Files\BullGuard Ltd\BullGuard\Antirootkit\trufos.sys – (Trufos)
DRV - [2009/08/08 11:17:20 | 000,014,720 | —- | M] (BitDefender S.R.L.) [Kernel | On_Demand] – C:\Program Files\BullGuard Ltd\BullGuard\Antirootkit\profos.sys – (Profos)
DRV - [2009/08/05 18:48:42 | 000,054,752 | —- | M] (Microsoft Corporation) [Kernel | Auto] – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys – (fssfltr)
DRV - [2009/01/23 09:48:56 | 000,055,504 | —- | M] (BullGuard Ltd.) [Kernel | Auto] – C:\WINDOWS\system32\drivers\BdFileSpy.sys – (BdFileSpy)
DRV - [2008/05/16 01:10:32 | 000,023,992 | —- | M] (Pure Networks, Inc.) [Kernel | Auto] – C:\WINDOWS\system32\drivers\pnarp.sys – (pnarp)
DRV - [2008/05/16 01:10:30 | 000,025,272 | —- | M] (Pure Networks, Inc.) [Kernel | Auto] – C:\WINDOWS\system32\drivers\purendis.sys – (purendis)
DRV - [2008/04/18 14:45:28 | 000,134,912 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\etDevice.sys – (DCamUSBET)
DRV - [2007/09/07 09:43:56 | 000,006,656 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\etScan.sys – (ScanUSBET)
DRV - [2007/07/30 17:25:04 | 000,198,144 | —- | M] (eMPIA Technology Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\etFilter.sys – (FiltUSBET)
DRV - [2007/04/08 08:04:13 | 000,008,552 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto] – C:\WINDOWS\system32\drivers\asctrm.sys – (ASCTRM)
DRV - [2007/02/01 23:00:00 | 000,009,464 | —- | M] (Sonic Solutions) [Kernel | System] – C:\WINDOWS\system32\drivers\cdralw2k.sys – (Cdralw2k)
DRV - [2007/02/01 23:00:00 | 000,009,336 | —- | M] (Sonic Solutions) [Kernel | System] – C:\WINDOWS\system32\drivers\cdr4_xp.sys – (Cdr4_xp)
DRV - [2006/03/15 08:00:00 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\dac2w2k.sys – (dac2w2k)
DRV - [2006/03/15 08:00:00 | 000,088,448 | —- | M] (Microsoft Corporation) [Kernel | Auto] – C:\WINDOWS\system32\drivers\nwlnkipx.sys – (NwlnkIpx)
DRV - [2006/03/15 08:00:00 | 000,063,232 | —- | M] (Microsoft Corporation) [Kernel | Auto] – C:\WINDOWS\system32\drivers\nwlnknb.sys – (NwlnkNb)
DRV - [2006/03/15 08:00:00 | 000,055,936 | —- | M] (Microsoft Corporation) [Kernel | Auto] – C:\WINDOWS\system32\drivers\nwlnkspx.sys – (NwlnkSpx)
DRV - [2006/03/15 08:00:00 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\ql1280.sys – (ql1280)
DRV - [2006/03/15 08:00:00 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\ql12160.sys – (ql12160)
DRV - [2006/03/15 08:00:00 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\ql1080.sys – (ql1080)
DRV - [2006/03/15 08:00:00 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\ultra.sys – (ultra)
DRV - [2006/03/15 08:00:00 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Boot] – C:\WINDOWS\system32\drivers\symc8xx.sys – (symc8xx)
DRV - [2006/03/15 08:00:00 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Boot] – C:\WINDOWS\system32\drivers\sym_u3.sys – (sym_u3)
DRV - [2006/03/15 08:00:00 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Boot] – C:\WINDOWS\system32\drivers\sym_hi.sys – (sym_hi)
DRV - [2006/03/15 08:00:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\asc.sys – (asc)
DRV - [2006/03/15 08:00:00 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\sparrow.sys – (Sparrow)
DRV - [2006/03/15 08:00:00 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\mraid35x.sys – (mraid35x)
DRV - [2006/03/15 08:00:00 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\symc810.sys – (symc810)
DRV - [2006/03/15 08:00:00 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\asc3550.sys – (asc3550)
DRV - [2006/03/15 08:00:00 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\cmdide.sys – (CmdIde)
DRV - [2006/03/15 08:00:00 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\aliide.sys – (AliIde)
DRV - [2005/10/26 04:08:26 | 003,786,944 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\alcxwdm.sys – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/10/13 09:53:24 | 001,379,328 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2005/07/13 07:08:20 | 000,033,890 | —- | M] (Service & Quality Technology.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\Capt905c.sys – (SQTECH905C)
DRV - [2005/03/03 23:10:26 | 000,074,496 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\Rtlnicxp.sys – (RTL8023xp)
DRV - [2004/08/03 19:07:44 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\AMDAGP.SYS – (amdagp)
DRV - [2004/08/03 19:07:44 | 000,041,088 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\SISAGP.SYS – (sisagp)
DRV - [2004/08/03 18:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2003/12/08 07:53:48 | 000,053,600 | —- | M] (THOMSON) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\alcan5wn.sys – (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN)
DRV - [2003/12/08 04:53:02 | 000,070,688 | R— | M] (THOMSON) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\alcaudsl.sys – (alcaudsl)
DRV - [2003/01/10 11:13:04 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 10:00:04 | 000,002,944 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\msmpu401.sys – (ms_mpu401)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\Adam_Helferty_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\Adam_Helferty_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pcservicecall.co.uk/
IE - HKU\Adam_Helferty_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pcservicecall.co.uk/
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\Gail_Helferty_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pcservicecall.co.uk/
IE - HKU\Gail_Helferty_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\HelpAssistant_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\HelpAssistant_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\HelpAssistant_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\HelpAssistant_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\HelpAssistant_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local;

IE - HKU\John_Helferty_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pcservicecall.co.uk/
IE - HKU\John_Helferty_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\Louise_Helferty_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\Louise_Helferty_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.mywebsearch.com/mywebsearch/…G.UgTdOuy4i8OFQ
IE - HKU\Louise_Helferty_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\Louise_Helferty_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKU\Louise_Helferty_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Louise_Helferty_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local;



FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/07/01 07:17:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/07 04:06:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/12/06 13:43:09 | 000,000,000 | —D | M]

[2010/02/19 12:15:46 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/12/06 13:43:07 | 000,024,684 | —- | M] (MyWebSearch.com) – C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
[2009/08/07 04:05:19 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2009/08/07 04:05:19 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2009/08/07 04:05:19 | 000,000,759 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2009/08/07 04:05:20 | 000,000,831 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2009/06/25 09:01:29 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKU\Adam_Helferty_ON_C\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\Adam_Helferty_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKU\HelpAssistant_ON_C\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\HelpAssistant_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKU\HelpAssistant_ON_C\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKU\Louise_Helferty_ON_C\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\Louise_Helferty_ON_C\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\Louise_Helferty_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKU\Louise_Helferty_ON_C\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [BullGuard] C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe (BullGuard Ltd.)
O4 - HKLM..\Run: [etMonitor] C:\WINDOWS\etMon.exe (EMPIA Technology Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LELA] C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe (Linksys LLC - A Division of Cisco Systems)
O4 - HKLM..\Run: [My Web Search Bar] C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)
O4 - HKLM..\Run: [MyWebSearch Plugin] C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (MyWebSearch.com)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Pure Networks, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SpeedTouch USB Diagnostics] C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe (THOMSON Telecom Belgium)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKU\Adam_Helferty_ON_C..\Run: [Power2GoExpress] C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe (Cyberlink)
O4 - HKU\Adam_Helferty_ON_C..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\Administrator_ON_C..\Run: [Power2GoExpress] C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe (Cyberlink)
O4 - HKU\Gail_Helferty_ON_C..\Run: [Power2GoExpress] C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe (Cyberlink)
O4 - HKU\HelpAssistant_ON_C..\Run: [BullGuard] C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe (BullGuard Ltd.)
O4 - HKU\HelpAssistant_ON_C..\Run: [MalwareRemovalBot] C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe File not found
O4 - HKU\HelpAssistant_ON_C..\Run: [Power2GoExpress] C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe (Cyberlink)
O4 - HKU\HelpAssistant_ON_C..\Run: [STManager] C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe ()
O4 - HKU\John_Helferty_ON_C..\Run: [Power2GoExpress] C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe (Cyberlink)
O4 - HKU\John_Helferty_ON_C..\Run: [STManager] C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe ()
O4 - HKU\Louise_Helferty_ON_C..\Run: [BullGuard] C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe (BullGuard Ltd.)
O4 - HKU\Louise_Helferty_ON_C..\Run: [MalwareRemovalBot] C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe File not found
O4 - HKU\Louise_Helferty_ON_C..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)
O4 - HKU\Louise_Helferty_ON_C..\Run: [Power2GoExpress] C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe (Cyberlink)
O4 - HKU\Louise_Helferty_ON_C..\Run: [STManager] C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe ()
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Catalyst System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\emSwapAP2.EXE.lnk = C:\Program Files\USB CAMERA\DRIVER\emSwapAp2.exe (eMPIA Technology, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Adam_Helferty_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Gail_Helferty_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\HelpAssistant_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\HelpAssistant_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\HelpAssistant_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\John_Helferty_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Louise_Helferty_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\Louise_Helferty_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Louise_Helferty_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000049 - C:\WINDOWS\System32\BGLsp.dll (BullGuard Ltd.)
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.1.4.cab (Bebo Uploader Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Pure Networks, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/08/23 01:44:37 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R— | M] () - X:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/03/02 12:52:18 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\browserchoice.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/03/15 10:41:54 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/15 09:41:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/15 04:24:13 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/12 11:20:00 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/12 11:18:48 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/12 11:18:39 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/12 11:15:39 | 000,241,664 | —- | M] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/03/12 11:15:39 | 000,241,664 | —- | M] () – C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/03/12 11:15:14 | 005,505,024 | -H– | M] () – C:\Documents and Settings\Louise Helferty\ntuser.dat
[2010/03/12 11:15:14 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Louise Helferty\ntuser.ini
[2010/03/02 06:39:08 | 000,020,992 | —- | M] () – C:\Documents and Settings\Louise Helferty\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/24 23:01:16 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2009/09/18 05:53:36 | 000,131,776 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2007/10/23 14:07:05 | 000,020,992 | —- | C] () – C:\Documents and Settings\Louise Helferty\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/11 05:49:48 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/05/03 11:23:51 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2007/03/20 12:51:47 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2007/03/20 12:46:57 | 000,000,027 | —- | C] () – C:\WINDOWS\CDE DX4000EFDG.ini
[2007/03/14 17:22:30 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2007/02/15 07:00:18 | 000,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2007/02/08 16:34:06 | 000,000,021 | —- | C] () – C:\WINDOWS\PI4_setup.ini
[2007/01/18 10:47:52 | 000,000,136 | —- | C] () – C:\Documents and Settings\Adam Helferty\Local Settings\Application Data\fusioncache.dat
[2007/01/18 08:51:19 | 000,000,136 | —- | C] () – C:\Documents and Settings\John Helferty\Local Settings\Application Data\fusioncache.dat
[2007/01/18 08:38:43 | 000,000,136 | —- | C] () – C:\Documents and Settings\Gail Helferty\Local Settings\Application Data\fusioncache.dat
[2007/01/18 08:30:15 | 000,000,138 | —- | C] () – C:\Documents and Settings\Louise Helferty\Local Settings\Application Data\fusioncache.dat
[2006/08/23 01:25:46 | 000,001,458 | R— | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/08/22 18:09:18 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/09/01 19:39:24 | 000,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/09/01 19:39:24 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/09/01 19:39:00 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/08/05 09:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/01/01 18:22:16 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2005/01/01 18:18:35 | 000,157,184 | R— | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2005/01/01 18:18:27 | 000,000,164 | R— | C] () – C:\WINDOWS\avrack.ini

========== LOP Check ==========

[2006/08/23 02:32:44 | 000,000,000 | —D | M] – C:\WINDOWS\system32\config\systemprofile\Application Data\SampleView
[2006/08/23 02:32:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Adam Helferty\Application Data\SampleView
[2006/08/23 02:32:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SampleView
[2006/08/23 02:32:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Gail Helferty\Application Data\SampleView
[2007/12/03 13:49:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\Blackberry Desktop
[2009/10/07 10:30:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\BullGuard
[2007/08/17 08:07:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\EPSON
[2009/12/06 13:43:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\FunWebProducts
[2009/08/12 07:22:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\LimeWire
[2007/12/03 14:13:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\Research In Motion
[2006/08/23 02:32:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\SampleView
[2009/09/13 11:26:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\Spotify
[2008/07/18 03:52:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\Viewpoint
[2009/09/05 16:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\Windows Live Writer
[2009/07/01 06:20:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\WinPatrol
[2006/08/23 02:32:44 | 000,000,000 | —D | M] – C:\Documents and Settings\John Helferty\Application Data\SampleView

========== Purity Check ==========


< End of report >
Hi,

Please do the following:

Boot back into OTLPE



Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    SRV - [2009/12/06 13:43:07 | 000,028,762 | —- | M] (MyWebSearch.com) [Disabled] – C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE – (MyWebSearchService)
    IE - HKU\Louise_Helferty_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.mywebsearch.com/mywebsearch/…G.UgTdOuy4i8OFQ
    IE - HKU\Louise_Helferty_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
    O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com)
    O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKU\Adam_Helferty_ON_C\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
    O3 - HKU\HelpAssistant_ON_C\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
    O3 - HKU\Louise_Helferty_ON_C\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
    O4 - HKLM..\Run: [My Web Search Bar] C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com)
    O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)
    O4 - HKLM..\Run: [MyWebSearch Plugin] C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (MyWebSearch.com)
    O4 - HKU\HelpAssistant_ON_C..\Run: [MalwareRemovalBot] C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe File not found
    O4 - HKU\Louise_Helferty_ON_C..\Run: [MalwareRemovalBot] C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe File not found
    O4 - HKU\Louise_Helferty_ON_C..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com)
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
    [2009/12/06 13:43:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Louise Helferty\Application Data\FunWebProducts
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "Userinit"="C:\\WINDOWS\\system32\\Userinit.exe,"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableTaskMgr"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableTaskMgr"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "NoSetActiveDesktop"=-
    "NoActiveDesktopChanges"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "NoSetActiveDesktop"=-
    "NoActiveDesktopChanges"=-
    
    :Files
    C:\WINDOWS\system32\drivers\atapi.sys | C:\WINDOWS\ServicePackFiles\i386\atapi.sys /replace
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


If you cannot access the internet in OTLPE then use a usb stick to run the fix:


To put fix the on a USB

Save a file as fix.txt onto your USB
  • Click the red Run Fix button.
  • You should be presented with a message "No Fix has been Provided! Do you want to load it from a file? Click Yes.
  • Browse to the fix.txt file on your USB stick, and click Open. The fix will then appear in the Custom Scans/Fixes window.
  • Click the red Run Fix button again.

see if you can now boot into normal mode:

If you can run the following:

Download and run HAMeb_check.exe save it to your desktop.

Click on the icon to run it, when complete it will open a log for you, please post the content of the log in your next reply.

Note: The log is temporary - it will not be saved when closed, so please be sure to copy the content so that you can paste it into your next reply before you close the log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI