This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer wont boot up except in safe mode

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Just recently had to recover data and restore computer to manufacturers settings. Its a Dell 1501 with windows vista. After putting alot back on it, I tried to put printer back on. It was installed and when it came to boot back up, it wouldnt boot up after about an hour. It will boot in safe mode but not regular. Computer must still be infected. Please advise what to run. Thank you in advance
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
I can see that you've had assistance with a similar problems here in the WTT forums previously. Since I can see that there have been some infections you've dealt with in the past, I do believe it is important that we make sure your machine is malware free, however, I'm not sure it is the source of your issue since you've had this problem on a number of occasions. I'd like to start with a couple of questions before we move forward.

You indicated you had recently restored the machine to the manufacturer settings. Can you please advise how you did this? Did you reformat the machine completely using the Recovery/Repair disks supplied with your computer or did you restore from a recovery partition (suce as the D:\ drive)?

Also, after you did the restore, did you ensure that you had applied all the Vista updates? Many times after reinstalling, you need to run the Windows update utility several times to ensure that all the updates have been installed. It is also important to visit the Dell website to ensure you have the latest drivers for your machine. Can you please let me know if you you did install all the updates including Service Pack 2 for Vista and if you have checked for updated drivers (especially those related to wireless and networking)?
I reformatted from the System Recovery menu in Vista. Also, it seems to be acting very strang. The computer started from the main screen yesterday and now it is not today. It seems that everytime I let the Windows Updates install, once they install and the computer restarts, it will not start up again. The Windows updates are what are keeping the computer from restarting. I let it try to start up for over an hour and a half too so it is obviously more than just a slow load up problem.
After a reformat, it is important to ensure that you have updated drivers for all of the devices on your machine. If these haven't been installed, you may find the system will not load properly, and may even hang on a welcome screen. Typically, you will find that the system will still boot into safe mode in these cases because only limited drivers are necessary to run in this mode. As this is happening right after a reformat, it is more likely this is the problem than having been infected by malware. In fact, if you had outdated drivers on your machine prior to the reformat - it could have contributed to problems like this in the past as well.

You indicated this started happening right after you installed the printer. You may want to check the manufacturer's website for your printer and see if they have updated drivers available for Vista. Even the printer drivers not being right could cause this kind of behavior.

I would suggest that you visit our Microsoft Windows Forum to request assistance in updating your drivers and getting all your Windows Updates installed. If you are still having problems after getting everything updated, I will be more than happy to help you run some scans and check for malware, but I suspect you'll find that things will be running much better after everything is updated properly.
I have done what was needed for updating software and updates. Computer now will not boot once again except in safe mode. I would prefer to proceed with malware detection to see what can be found, if any. Thanks
Both of these tools will run in Safe Mode. Since you are using Vista, please be sure to right-click and choose Run as Administrator when using any tools.

If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.

Download DeFogger

Please download DeFogger to your desktop.

Right-Click and choose Run as Administrator on DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right-Click and choose Run as Administrator on GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




OTL Custom Scan

Download OTL to your Desktop
  • Right-click and choose Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-14 02:31:16
Windows 6.0.6000 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK8037GSX rev.DL240D
Running: gmer.exe; Driver: C:\Users\steve\AppData\Local\Temp\ugroypob.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR

—- EOF - GMER 1.0.15 —-
OTL logfile created on: 12/14/2010 2:37:13 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\steve\Downloads
Windows Vista Home Basic Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

893.00 Mb Total Physical Memory | 340.00 Mb Available Physical Memory | 38.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 64.45 Gb Total Space | 35.05 Gb Free Space | 54.37% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.63 Gb Free Space | 66.27% Space Free | Partition Type: NTFS

Computer Name: STEVE-PC | User Name: steve | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\steve\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AOL 9.0a\shellmon.exe (AOL, LLC.)
PRC - C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)
PRC - C:\Program Files\Common Files\aol\1291487754\ee\aolsoftware.exe (America Online, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\steve\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\WMASF.DLL (Microsoft Corporation)
MOD - C:\Windows\System32\WMVCORE.DLL (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072e
c96e0be7\GdiPlus.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msshsq.dll (Microsoft Corporation)
MOD - C:\Windows\System32\PortableDeviceApi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\IconCodecService.dll (Microsoft Corporation)
MOD - C:\Windows\System32\davclnt.dll (Microsoft Corporation)
MOD - C:\Windows\System32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Windows\System32\WindowsCodecs.dll (Microsoft Corporation)
MOD - C:\Windows\System32\SLC.dll (Microsoft Corporation)
MOD - C:\Windows\System32\thumbcache.dll (Microsoft Corporation)
MOD - C:\Windows\System32\ntlanman.dll (Microsoft Corporation)
MOD - C:\Windows\System32\duser.dll (Microsoft Corporation)
MOD - C:\Windows\System32\drprov.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cscapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\actxprxy.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (rpcnetp) – C:\Windows\System32\rpcnetp.exe ()
SRV - (GoogleDesktopManager-051210-111108) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (STacSV) – C:\Program Files\SigmaTel\C-Major Audio\WDM\stacsv.exe (SigmaTel, Inc.)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SymAppCore) – C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
SRV - (comHost) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (ISPwdSvc) – C:\Program Files\Norton Internet Security\isPwdSvc.exe (Symantec Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)


========== Driver Services (SafeList) ==========

DRV - (USBSTOR) – C:\Windows\System32\drivers\usbstor.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20070531.019\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20070531.019\NAVENG.SYS (Symantec Corporation)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20061025.029\IDSvix86.sys (Symantec Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (rimsptsk) – C:\Windows\system32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (ATWPKT2) – C:\Windows\System32\drivers\atwpkt2.sys (America Online)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\Windows\System32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=0070630
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBHO.dll (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1291487754\ee\aolsoftware.exe (America Online, Inc.)
O4 - HKLM..\Run: [IS CfgWiz] C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe (Symantec Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [osCheck] C:\Program Files\Norton Internet Security\osCheck.exe (Symantec Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Windows\sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AOL Fast Start] C:\Program Files\AOL 9.0a\AOL.EXE (AOL, LLC.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\dellwall1.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\dellwall1.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/12/12 00:04:58 | 000,000,000 | —D | C] – C:\ProgramData\AOL Downloads
[2010/12/08 00:48:50 | 000,000,000 | —D | C] – C:\ProgramData\Macromedia
[2010/12/08 00:47:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nullsoft
[2010/12/08 00:43:17 | 000,000,000 | —D | C] – C:\Program Files\AOL 9.0a
[2010/12/07 20:34:23 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/12/07 20:11:56 | 000,044,544 | —- | C] (Absolute Software Corp.) – C:\Windows\System32\agremove.exe
[2010/12/06 21:56:47 | 000,000,000 | —D | C] – C:\ProgramData\WEBREG
[2010/12/06 21:24:24 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\HP
[2010/12/06 00:09:10 | 000,000,000 | —D | C] – C:\Program Files\Hewlett-Packard
[2010/12/06 00:08:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Hewlett-Packard
[2010/12/06 00:02:17 | 000,000,000 | —D | C] – C:\Program Files\HP
[2010/12/05 23:56:56 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2010/12/05 19:54:17 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/12/05 19:48:57 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2010/12/05 19:46:29 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Microsoft Help
[2010/12/05 19:45:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2010/12/05 19:41:32 | 000,000,000 | —D | C] – C:\Users\steve\Documents\MS Office
[2010/12/05 19:41:02 | 000,000,000 | —D | C] – C:\Users\steve\microsoft office 2007
[2010/12/05 19:40:32 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\WinRAR
[2010/12/05 19:39:58 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2010/12/04 17:01:07 | 000,000,000 | —D | C] – C:\ATI
[2010/12/04 13:42:57 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\AOL
[2010/12/04 13:42:48 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\AOL
[2010/12/04 13:40:00 | 000,000,000 | —D | C] – C:\ProgramData\Viewpoint
[2010/12/04 13:39:57 | 000,000,000 | —D | C] – C:\Program Files\Viewpoint
[2010/12/04 13:38:57 | 000,000,000 | —D | C] – C:\Users\Public\Documents\AOL Downloads
[2010/12/04 13:37:09 | 000,000,000 | —D | C] – C:\Users\steve\{43868b63-d101-4ab2-b7b0-ee80c098eb03}
[2010/12/04 13:36:19 | 000,000,000 | —D | C] – C:\Program Files\AOL
[2010/12/04 13:35:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\aolshare
[2010/12/04 13:35:44 | 000,000,000 | —D | C] – C:\Program Files\AOL 9.0
[2010/12/04 13:35:44 | 000,000,000 | —D | C] – C:\ProgramData\AOL
[2010/12/04 13:35:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\aol
[2010/12/04 13:33:09 | 000,000,000 | -H-D | C] – C:\TEMP
[2010/12/04 13:23:44 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\AdobeUM
[2010/12/04 13:21:27 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\Adobe
[2010/12/04 13:21:27 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Adobe
[2010/12/04 13:18:18 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\Macromedia
[2010/12/04 13:13:13 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\Google
[2010/12/04 11:34:59 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/12/04 10:44:17 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\PowerDVD DX
[2010/12/04 10:44:10 | 000,000,000 | —D | C] – C:\Users\steve\Documents\My Google Gadgets
[2010/12/04 10:43:49 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\ATI
[2010/12/04 10:43:49 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\ATI
[2010/12/04 10:43:37 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Google
[2010/12/04 10:43:33 | 000,000,000 | -H-D | C] – C:\Users\steve\AppData\Roaming\GTek
[2010/12/04 10:43:18 | 000,000,000 | R–D | C] – C:\Users\steve\Searches
[2010/12/04 10:43:09 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\Identities
[2010/12/04 10:43:07 | 000,000,000 | R–D | C] – C:\Users\steve\Contacts
[2010/12/04 10:43:06 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\VirtualStore
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\AppData\Local\Temporary Internet Files
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Templates
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Start Menu
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\SendTo
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Recent
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\PrintHood
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\NetHood
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Documents\My Videos
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Documents\My Pictures
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Documents\My Music
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\My Documents
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Local Settings
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\AppData\Local\History
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Cookies
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Application Data
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\AppData\Local\Application Data
[2010/12/04 10:42:44 | 000,000,000 | –SD | C] – C:\Users\steve\AppData\Roaming\Microsoft
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Videos
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Saved Games
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Pictures
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Music
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Links
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Favorites
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Downloads
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Documents
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Desktop
[2010/12/04 10:42:44 | 000,000,000 | -H-D | C] – C:\Users\steve\AppData
[2010/12/04 10:42:44 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Temp
[2010/12/04 10:42:44 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Microsoft
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Templates
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Start Menu
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Videos
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Pictures
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Music
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Favorites
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\Documents and Settings
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Documents
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Desktop
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Application Data
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/14 00:39:58 | 000,617,662 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/14 00:39:58 | 000,103,440 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/14 00:31:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/12 22:52:06 | 000,017,408 | —- | M] () – C:\Windows\System32\rpcnetp.exe
[2010/12/12 22:50:18 | 000,017,408 | —- | M] () – C:\Windows\System32\rpcnetp.dll
[2010/12/12 22:50:05 | 000,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/12 22:50:05 | 000,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/12 17:19:37 | 000,044,544 | —- | M] (Absolute Software Corp.) – C:\Windows\System32\agremove.exe
[2010/12/10 15:54:43 | 000,319,752 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/09 20:20:25 | 022,724,608 | —- | M] () – C:\Windows\ocsetup_install_NetFx3.etl
[2010/12/09 20:20:24 | 000,049,152 | —- | M] () – C:\Windows\ocsetup_cbs_install_NetFx3.perf
[2010/12/09 20:20:24 | 000,016,384 | —- | M] () – C:\Windows\ocsetup_cbs_install_NetFx3.dpx
[2010/12/08 01:35:35 | 000,014,336 | —- | M] () – C:\Users\steve\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/08 00:48:40 | 000,000,747 | —- | M] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL 9.0.lnk
[2010/12/08 00:48:40 | 000,000,739 | —- | M] () – C:\Users\Public\Desktop\AOL.lnk
[2010/12/07 21:42:16 | 000,000,945 | —- | M] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/12/07 21:02:02 | 001,657,350 | —- | M] () – C:\Windows\System32\wlan.tmf
[2010/12/07 20:19:37 | 000,001,643 | —- | M] () – C:\Users\steve\Desktop\AOL.lnk
[2010/12/07 00:35:44 | 000,023,327 | —- | M] () – C:\Users\steve\Documents\HRM_Case_2.docx
[2010/12/05 23:10:19 | 000,017,159 | —- | M] () – C:\Users\steve\Documents\Ethics Exam 2.docx
[2010/12/04 13:35:03 | 000,000,335 | —- | M] () – C:\Windows\nsreg.dat
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/12 22:50:18 | 000,017,408 | —- | C] () – C:\Windows\System32\rpcnetp.dll
[2010/12/12 17:23:02 | 000,017,408 | —- | C] () – C:\Windows\System32\rpcnetp.exe
[2010/12/08 22:12:57 | 000,049,152 | —- | C] () – C:\Windows\ocsetup_cbs_install_NetFx3.perf
[2010/12/08 22:12:56 | 000,016,384 | —- | C] () – C:\Windows\ocsetup_cbs_install_NetFx3.dpx
[2010/12/08 00:48:40 | 000,000,747 | —- | C] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL 9.0.lnk
[2010/12/07 21:02:01 | 001,657,350 | —- | C] () – C:\Windows\System32\wlan.tmf
[2010/12/07 20:26:46 | 000,014,336 | —- | C] () – C:\Users\steve\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/07 20:19:37 | 000,001,643 | —- | C] () – C:\Users\steve\Desktop\AOL.lnk
[2010/12/06 22:45:18 | 000,023,327 | —- | C] () – C:\Users\steve\Documents\HRM_Case_2.docx
[2010/12/05 23:57:40 | 000,001,734 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/12/05 21:38:51 | 000,017,159 | —- | C] () – C:\Users\steve\Documents\Ethics Exam 2.docx
[2010/12/05 17:56:07 | 022,724,608 | —- | C] () – C:\Windows\ocsetup_install_NetFx3.etl
[2010/12/04 13:35:03 | 000,000,335 | —- | C] () – C:\Windows\nsreg.dat
[2010/12/04 13:13:00 | 000,000,945 | —- | C] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/12/04 10:42:44 | 000,000,258 | —- | C] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/12/04 10:42:44 | 000,000,240 | —- | C] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2007/06/30 18:27:31 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2007/06/30 18:27:30 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007/06/30 18:27:21 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2007/06/30 10:47:42 | 000,065,536 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2006/11/07 14:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/16 23:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 23:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll

========== LOP Check ==========

[2010/12/12 02:05:32 | 000,006,232 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
O4 - HKCU..\Run: [AOL Fast Start] C:\Program Files\AOL 9.0a\AOL.EXE (AOL, LLC.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\dellwall1.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\dellwall1.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/12/12 00:04:58 | 000,000,000 | —D | C] – C:\ProgramData\AOL Downloads
[2010/12/08 00:48:50 | 000,000,000 | —D | C] – C:\ProgramData\Macromedia
[2010/12/08 00:47:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nullsoft
[2010/12/08 00:43:17 | 000,000,000 | —D | C] – C:\Program Files\AOL 9.0a
[2010/12/07 20:34:23 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/12/07 20:11:56 | 000,044,544 | —- | C] (Absolute Software Corp.) – C:\Windows\System32\agremove.exe
[2010/12/06 21:56:47 | 000,000,000 | —D | C] – C:\ProgramData\WEBREG
[2010/12/06 21:24:24 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\HP
[2010/12/06 00:09:10 | 000,000,000 | —D | C] – C:\Program Files\Hewlett-Packard
[2010/12/06 00:08:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Hewlett-Packard
[2010/12/06 00:02:17 | 000,000,000 | —D | C] – C:\Program Files\HP
[2010/12/05 23:56:56 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2010/12/05 19:54:17 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/12/05 19:48:57 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2010/12/05 19:46:29 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Microsoft Help
[2010/12/05 19:45:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2010/12/05 19:41:32 | 000,000,000 | —D | C] – C:\Users\steve\Documents\MS Office
[2010/12/05 19:41:02 | 000,000,000 | —D | C] – C:\Users\steve\microsoft office 2007
[2010/12/05 19:40:32 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\WinRAR
[2010/12/05 19:39:58 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2010/12/04 17:01:07 | 000,000,000 | —D | C] – C:\ATI
[2010/12/04 13:42:57 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\AOL
[2010/12/04 13:42:48 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\AOL
[2010/12/04 13:40:00 | 000,000,000 | —D | C] – C:\ProgramData\Viewpoint
[2010/12/04 13:39:57 | 000,000,000 | —D | C] – C:\Program Files\Viewpoint
[2010/12/04 13:38:57 | 000,000,000 | —D | C] – C:\Users\Public\Documents\AOL Downloads
[2010/12/04 13:37:09 | 000,000,000 | —D | C] – C:\Users\steve\{43868b63-d101-4ab2-b7b0-ee80c098eb03}
[2010/12/04 13:36:19 | 000,000,000 | —D | C] – C:\Program Files\AOL
[2010/12/04 13:35:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\aolshare
[2010/12/04 13:35:44 | 000,000,000 | —D | C] – C:\Program Files\AOL 9.0
[2010/12/04 13:35:44 | 000,000,000 | —D | C] – C:\ProgramData\AOL
[2010/12/04 13:35:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\aol
[2010/12/04 13:33:09 | 000,000,000 | -H-D | C] – C:\TEMP
[2010/12/04 13:23:44 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\AdobeUM
[2010/12/04 13:21:27 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\Adobe
[2010/12/04 13:21:27 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Adobe
[2010/12/04 13:18:18 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\Macromedia
[2010/12/04 13:13:13 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\Google
[2010/12/04 11:34:59 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/12/04 10:44:17 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\PowerDVD DX
[2010/12/04 10:44:10 | 000,000,000 | —D | C] – C:\Users\steve\Documents\My Google Gadgets
[2010/12/04 10:43:49 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\ATI
[2010/12/04 10:43:49 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\ATI
[2010/12/04 10:43:37 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Google
[2010/12/04 10:43:33 | 000,000,000 | -H-D | C] – C:\Users\steve\AppData\Roaming\GTek
[2010/12/04 10:43:18 | 000,000,000 | R–D | C] – C:\Users\steve\Searches
[2010/12/04 10:43:09 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\Identities
[2010/12/04 10:43:07 | 000,000,000 | R–D | C] – C:\Users\steve\Contacts
[2010/12/04 10:43:06 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\VirtualStore
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\AppData\Local\Temporary Internet Files
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Templates
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Start Menu
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\SendTo
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Recent
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\PrintHood
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\NetHood
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Documents\My Videos
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Documents\My Pictures
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Documents\My Music
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\My Documents
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Local Settings
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\AppData\Local\History
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Cookies
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\Application Data
[2010/12/04 10:42:45 | 000,000,000 | -HSD | C] – C:\Users\steve\AppData\Local\Application Data
[2010/12/04 10:42:44 | 000,000,000 | –SD | C] – C:\Users\steve\AppData\Roaming\Microsoft
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Videos
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Saved Games
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Pictures
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Music
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Links
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Favorites
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Downloads
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Documents
[2010/12/04 10:42:44 | 000,000,000 | R–D | C] – C:\Users\steve\Desktop
[2010/12/04 10:42:44 | 000,000,000 | -H-D | C] – C:\Users\steve\AppData
[2010/12/04 10:42:44 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Temp
[2010/12/04 10:42:44 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Microsoft
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Templates
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Start Menu
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Videos
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Pictures
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Music
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Favorites
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\Documents and Settings
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Documents
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Desktop
[2010/12/04 10:38:58 | 000,000,000 | -HSD | C] – C:\ProgramData\Application Data
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/14 00:39:58 | 000,617,662 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/14 00:39:58 | 000,103,440 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/14 00:31:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/12 22:52:06 | 000,017,408 | —- | M] () – C:\Windows\System32\rpcnetp.exe
[2010/12/12 22:50:18 | 000,017,408 | —- | M] () – C:\Windows\System32\rpcnetp.dll
[2010/12/12 22:50:05 | 000,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/12 22:50:05 | 000,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/12 17:19:37 | 000,044,544 | —- | M] (Absolute Software Corp.) – C:\Windows\System32\agremove.exe
[2010/12/10 15:54:43 | 000,319,752 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/09 20:20:25 | 022,724,608 | —- | M] () – C:\Windows\ocsetup_install_NetFx3.etl
[2010/12/09 20:20:24 | 000,049,152 | —- | M] () – C:\Windows\ocsetup_cbs_install_NetFx3.perf
[2010/12/09 20:20:24 | 000,016,384 | —- | M] () – C:\Windows\ocsetup_cbs_install_NetFx3.dpx
[2010/12/08 01:35:35 | 000,014,336 | —- | M] () – C:\Users\steve\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/08 00:48:40 | 000,000,747 | —- | M] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL 9.0.lnk
[2010/12/08 00:48:40 | 000,000,739 | —- | M] () – C:\Users\Public\Desktop\AOL.lnk
[2010/12/07 21:42:16 | 000,000,945 | —- | M] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/12/07 21:02:02 | 001,657,350 | —- | M] () – C:\Windows\System32\wlan.tmf
[2010/12/07 20:19:37 | 000,001,643 | —- | M] () – C:\Users\steve\Desktop\AOL.lnk
[2010/12/07 00:35:44 | 000,023,327 | —- | M] () – C:\Users\steve\Documents\HRM_Case_2.docx
[2010/12/05 23:10:19 | 000,017,159 | —- | M] () – C:\Users\steve\Documents\Ethics Exam 2.docx
[2010/12/04 13:35:03 | 000,000,335 | —- | M] () – C:\Windows\nsreg.dat
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/12 22:50:18 | 000,017,408 | —- | C] () – C:\Windows\System32\rpcnetp.dll
[2010/12/12 17:23:02 | 000,017,408 | —- | C] () – C:\Windows\System32\rpcnetp.exe
[2010/12/08 22:12:57 | 000,049,152 | —- | C] () – C:\Windows\ocsetup_cbs_install_NetFx3.perf
[2010/12/08 22:12:56 | 000,016,384 | —- | C] () – C:\Windows\ocsetup_cbs_install_NetFx3.dpx
[2010/12/08 00:48:40 | 000,000,747 | —- | C] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL 9.0.lnk
[2010/12/07 21:02:01 | 001,657,350 | —- | C] () – C:\Windows\System32\wlan.tmf
[2010/12/07 20:26:46 | 000,014,336 | —- | C] () – C:\Users\steve\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/07 20:19:37 | 000,001,643 | —- | C] () – C:\Users\steve\Desktop\AOL.lnk
[2010/12/06 22:45:18 | 000,023,327 | —- | C] () – C:\Users\steve\Documents\HRM_Case_2.docx
[2010/12/05 23:57:40 | 000,001,734 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/12/05 21:38:51 | 000,017,159 | —- | C] () – C:\Users\steve\Documents\Ethics Exam 2.docx
[2010/12/05 17:56:07 | 022,724,608 | —- | C] () – C:\Windows\ocsetup_install_NetFx3.etl
[2010/12/04 13:35:03 | 000,000,335 | —- | C] () – C:\Windows\nsreg.dat
[2010/12/04 13:13:00 | 000,000,945 | —- | C] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/12/04 10:42:44 | 000,000,258 | —- | C] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/12/04 10:42:44 | 000,000,240 | —- | C] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2007/06/30 18:27:31 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2007/06/30 18:27:30 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007/06/30 18:27:21 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2007/06/30 10:47:42 | 000,065,536 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2006/11/07 14:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/16 23:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 23:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll

========== LOP Check ==========

[2010/12/12 02:05:32 | 000,006,232 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
From your logs, it does not appear you have installed the Vista service packs. I re-read your previous notes, and I see that the system doesn't restart properly and complete the install of updates. This is going to be critical in terms of getting your system updated for proper security fixes, as well as for many of the optional driver updates that may be causing the booting issues.

I'd suggest at this point you do a startup repair of Vista. You can follow the instructions from Microsoft (found here[/uron how to do this. Hopefully, you will then be able to boot into normal mode.

If this works, you should then use the Windows Update Utility to install all of the necessary Windows updates before doing anything else. There have been many security fixes in the Vista Service packs and you do need to get those installed.

After doing this, please let me know how the system is behaving.
I am having problems with this. Everytime I have tried to go to the link attached, the entire computer freeze and I have to go into task manager to get out of the web browser. It has happened multiple times. When I go to the start tab and try to install the windows updates, the program begins to load for 2-3 seconds and stops and nothing pops up. I just dont understand this computer anymore
You may want to print these instructions for use as you follow the steps.

If you have a Windows Vista installation disc, you need to restart (boot) your computer using the installation disc. If you do not restart your computer from the disc, the option to repair your computer will not appear.

If you have a Windows Vista installation disc:

1. Insert the installation disc.

2. Restart your computer by clicking on the Start [external image: Posted Image] button , then click the arrow next to the Lock [external image: Posted Image] button , and then click Restart.

3. If prompted, press any key to start Windows from the installation disc. Note: If your computer is not configured to start from a CD or DVD, check the information that came with your computer. You may need to change your computer's BIOS settings.

4. Choose your language settings, and then click Next.

5. Click Repair your computer.

6. Select the operating system you want to repair, and then click Next.

7. On the System Recovery Options menu, click Startup Repair. Startup Repair might prompt you to make choices as it tries to fix the problem, and if necessary, it might restart your computer as it makes repairs.

If this works, you should then use the Windows Update Utility to install all of the necessary Windows updates before doing anything else. There have been many security fixes in the Vista Service packs and you do need to get those installed.

If repairs are not successful, you'll see a summary of the problem and links to contact information for support. Your computer manufacturer might include additional assistance information.

After doing this, please let me know how the system is behaving.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI