This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

bsod 0x00000050

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ibm thinkpad T42 running, widows xp sp3 and norton

BSOD appears when trying to dowload files. most notably norton definition files. But has appeared at othertimes when machine was sitting idle.

Error code 0X00000050 (0XFCA80000,0X00000000,0X804E7428,0X00000000)

Ran windows memory test overnight with no errors.
Ran chkdsk with no errors.

Hijackthis report:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:29:28 PM, on 1/17/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\IPSBHO.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [SupportAnyPC] "C:\DOCUME~1\k\LOCALS~1\Temp\winvnc.exe" -servicehelper
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1255377659354
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

–
End of file - 8584 bytes
Hi 83valentine,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Nothing showing… but that could be a symptom of a haxdoor virus. Let's try to get a deeper scan log.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.

If you can't download the program… do you have access to another computer? If so, you can download the program onto a Usb drive and transfer it to your "problem" computer in order to run it.
Tomk, Thank you for your response. I have not had any luck running DDS. I have downloaded it from 2 different sites and both downloads ran for a while and locked up. I have disabled norton internet security as well. Thanks Brad
83valentine,

Let's try this:

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Also please describe how your computer behaves at the moment.
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5577 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 8.0.6001.18702 1/23/2011 12:20:26 PM mbam-log-2011-01-23 (12-20-26).txt Scan type: Quick scan Objects scanned: 143991 Time elapsed: 2 minute(s), 35 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) The computer is not letting me do anything in regular mode. was able to Run TFC and Malware bites in safemode, the log is above. when logged into regular mode, computer is frozen as if it is trying to load programs at startup. sorry for log time between responses, I was looking for email from the forum saying you responded, and never recieved it. Brad
Let's try for a different log.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
These were run in safe mode.

OTL Extras logfile created on: 1/24/2011 8:55:45 AM - Run 1
OTL by OldTimer - Version 3.2.20.5 Folder = C:\Documents and Settings\k\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 362.00 Mb Available Physical Memory | 71.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 94.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 32.54 Gb Total Space | 17.48 Gb Free Space | 53.73% Space Free | Partition Type: NTFS

Computer Name: IBM-A3265B1A4E3 | User Name: k | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\IBM\Updater\jre\bin\java.exe" = C:\Program Files\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector – (IBM)
"C:\Program Files\IBM\Updater\jre\bin\javaw.exe" = C:\Program Files\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector – (IBM)
"C:\Program Files\IBM\Updater\ucsmb.exe" = C:\Program Files\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector – (IBM Corporation, Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\IBM\Updater\jre\bin\java.exe" = C:\Program Files\IBM\Updater\jre\bin\java.exe:*:Enabled:IBM Update Connector – (IBM)
"C:\Program Files\IBM\Updater\jre\bin\javaw.exe" = C:\Program Files\IBM\Updater\jre\bin\javaw.exe:*:Enabled:IBM Update Connector – (IBM)
"C:\Program Files\IBM\Updater\ucsmb.exe" = C:\Program Files\IBM\Updater\ucsmb.exe:*:Enabled:IBM Update Connector – (IBM Corporation, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1007F41F-7D69-468E-8017-3849A5A973C2}" = IBM ThinkVantage Technologies Welcome Message
"{11783F13-C3A9-44A8-929B-21A476F65272}" = IBM Rescue and Recovery with Rapid Restore
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = IBM DLA
"{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin
"{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = IBM ThinkPad Keyboard Customizer Utility
"{22B71A00-4DED-11D4-A5E5-0004AC564F43}" = IBM Access Connections
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6C72E14A-C1F3-45E5-8810-83CE3C19ED63}" = IBM 32-bit Runtime Environment for Java 2, v1.4.1
"{6CE96A14-61E2-48CC-837E-22710A953ADE}" = IBM Themes
"{72806716-7088-41B2-8FA6-717A2A164DAB}" = IBM Active Protection System
"{82512BC9-BD5D-4C50-BE4D-B98E7DF78687}" = IBM ThinkPad UltraNav Wizard
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D815BF3-2399-459C-B121-49373FEFB9E8}" = IBM Update Connector
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = IBM RecordNow!
"{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}" = IBM Wireless LAN Adapters Software (11a/b, 11b/g, 11a/b/g)
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{EA664480-3844-11D5-8C25-444553540000}" = IBM TrackPoint Accessibility Features
"{EC6AF20D-4376-4070-BEE4-D3A0DFF7E140}" = Access IBM
"{F386C340-DF4B-4BBA-9503-420FB7EDB395}" = Wallpapers
"{F413B3A4-EE5D-457C-BAE5-6E58D9589ED5}" = Access IBM Message Center
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_05591014" = IBM Integrated 56K Modem
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CSCLIB" = Canon Camera Support Core Library
"EasyEject Utility" = IBM ThinkPad EasyEject Utility
"EOS Utility" = Canon Utilities EOS Utility
"ERUNT_is1" = ERUNT 1.1j
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"InstallShield_{6C72E14A-C1F3-45E5-8810-83CE3C19ED63}" = IBM 32-bit Runtime Environment for Java 2, v1.4.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"NIS" = Norton Internet Security
"PhotoStitch" = Canon Utilities PhotoStitch
"Power Features" = IBM ThinkPad Battery MaxiMiser and Power Management Features
"Power Management Driver" = IBM ThinkPad Power Management Driver
"Presentation Director" = IBM ThinkPad Presentation Director
"PROSet" = Intel® PRO Network Adapters and Drivers
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SynTPDeinstKey" = IBM ThinkPad UltraNav Driver
"ThinkPad Configuration" = IBM ThinkPad Configuration
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"ThinkPadSoftwareInstaller" = ThinkPad Software Installer
"Windows XP Service Pack" = Windows XP Service Pack 3
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/23/2011 8:00:11 PM | Computer Name = IBM-A3265B1A4E3 | Source = ESENT | ID = 455
Description = wuaueng.dll (2236) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 1/23/2011 8:30:18 PM | Computer Name = IBM-A3265B1A4E3 | Source = ESENT | ID = 490
Description = wuauclt (2100) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 1/23/2011 8:30:30 PM | Computer Name = IBM-A3265B1A4E3 | Source = ESENT | ID = 489
Description = wuauclt (2100) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 1/23/2011 8:30:35 PM | Computer Name = IBM-A3265B1A4E3 | Source = ESENT | ID = 455
Description = wuaueng.dll (2100) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 1/23/2011 8:30:45 PM | Computer Name = IBM-A3265B1A4E3 | Source = ESENT | ID = 489
Description = wuauclt (2100) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 1/23/2011 8:30:45 PM | Computer Name = IBM-A3265B1A4E3 | Source = ESENT | ID = 455
Description = wuaueng.dll (2100) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 1/23/2011 8:57:43 PM | Computer Name = IBM-A3265B1A4E3 | Source = ESENT | ID = 489
Description = wuauclt (2728) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 1/23/2011 8:57:45 PM | Computer Name = IBM-A3265B1A4E3 | Source = ESENT | ID = 455
Description = wuaueng.dll (2728) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 1/23/2011 8:57:58 PM | Computer Name = IBM-A3265B1A4E3 | Source = ESENT | ID = 489
Description = wuauclt (2728) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 1/23/2011 8:57:58 PM | Computer Name = IBM-A3265B1A4E3 | Source = ESENT | ID = 455
Description = wuaueng.dll (2728) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

[ System Events ]
Error - 1/23/2011 8:42:48 PM | Computer Name = IBM-A3265B1A4E3 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/23/2011 8:42:53 PM | Computer Name = IBM-A3265B1A4E3 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/23/2011 8:42:57 PM | Computer Name = IBM-A3265B1A4E3 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/23/2011 8:43:01 PM | Computer Name = IBM-A3265B1A4E3 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/23/2011 8:43:05 PM | Computer Name = IBM-A3265B1A4E3 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/23/2011 8:43:10 PM | Computer Name = IBM-A3265B1A4E3 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/23/2011 8:43:14 PM | Computer Name = IBM-A3265B1A4E3 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/23/2011 8:43:18 PM | Computer Name = IBM-A3265B1A4E3 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/23/2011 8:43:23 PM | Computer Name = IBM-A3265B1A4E3 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/23/2011 8:43:27 PM | Computer Name = IBM-A3265B1A4E3 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.


< End of report >

OTL logfile created on: 1/24/2011 8:55:45 AM - Run 1
OTL by OldTimer - Version 3.2.20.5 Folder = C:\Documents and Settings\k\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 362.00 Mb Available Physical Memory | 71.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 94.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 32.54 Gb Total Space | 17.48 Gb Free Space | 53.73% Space Free | Partition Type: NTFS

Computer Name: IBM-A3265B1A4E3 | User Name: k | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/24 08:54:39 | 000,603,136 | —- | M] (OldTimer Tools) – C:\Documents and Settings\k\Desktop\OTL.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2011/01/24 08:54:39 | 000,603,136 | —- | M] (OldTimer Tools) – C:\Documents and Settings\k\Desktop\OTL.exe
MOD - [2010/08/23 10:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – – (PsaSrv)
SRV - [2010/02/25 18:21:50 | 000,126,392 | R— | M] (Symantec Corporation) [Unknown | Stopped] – C:\Program Files\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe – (NIS)
SRV - [2005/09/30 20:22:50 | 000,096,341 | —- | M] (Canon Inc.) [Auto | Stopped] – C:\Program Files\Canon\CAL\CALMAIN.exe – (CCALib8)
SRV - [2004/11/09 04:53:00 | 000,073,728 | —- | M] (IBM Corp.) [Auto | Stopped] – C:\WINDOWS\system32\QCONSVC.EXE – (QCONSVC)
SRV - [2004/07/16 21:24:24 | 000,036,864 | —- | M] () [On_Demand | Stopped] – C:\WINDOWS\system32\acs.exe – (ACS)
SRV - [2004/03/19 14:21:10 | 000,339,968 | —- | M] () [Auto | Stopped] – C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe – (IBM Rapid Restore Ultra Service)
SRV - [2004/02/26 02:26:00 | 000,057,344 | —- | M] () [Auto | Stopped] – C:\WINDOWS\system32\ibmpmsvc.exe – (IBMPMSVC)
SRV - [2003/07/11 19:19:22 | 000,032,768 | —- | M] () [Auto | Stopped] – C:\WINDOWS\system32\TpKmpSvc.exe – (TpKmpSVC)


========== Driver Services (SafeList) ==========

DRV - [2011/01/16 19:55:48 | 000,030,144 | —- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\psadd.sys – (psadd)
DRV - [2010/12/17 10:01:40 | 001,360,760 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\Definitions\VirusDefs\20110103.001\NAVEX15.SYS – (NAVEX15)
DRV - [2010/12/17 10:01:39 | 000,086,008 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\Definitions\VirusDefs\20110103.001\NAVENG.SYS – (NAVENG)
DRV - [2010/11/22 20:20:07 | 000,691,248 | —- | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\Definitions\BASHDefs\20101123.003\BHDrvx86.sys – (BHDrvx86)
DRV - [2010/11/08 18:50:31 | 000,341,944 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\Definitions\IPSDefs\20101231.001\IDSXpx86.sys – (IDSxpx86)
DRV - [2010/06/23 11:18:34 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2010/06/23 11:18:34 | 000,102,448 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2010/05/05 22:01:59 | 000,361,904 | —- | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\WINDOWS\System32\Drivers\NIS\1108000.005\SYMTDI.SYS – (SYMTDI)
DRV - [2010/04/28 23:03:51 | 000,116,784 | —- | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\NIS\1108000.005\Ironx86.SYS – (SymIRON)
DRV - [2010/04/21 21:02:20 | 000,173,104 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\NIS\1108000.005\SYMEFA.SYS – (SymEFA)
DRV - [2010/04/21 20:29:50 | 000,325,680 | —- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\NIS\1108000.005\SRTSP.SYS – (SRTSP)
DRV - [2010/04/21 20:29:50 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\NIS\1108000.005\SRTSPX.SYS – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/25 18:22:57 | 000,501,888 | —- | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\NIS\1108000.005\ccHPx86.sys – (ccHP)
DRV - [2009/12/18 10:50:14 | 000,124,976 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2009/11/05 16:06:13 | 000,328,752 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\NIS\1108000.005\SYMDS.SYS – (SymDS)
DRV - [2009/10/09 15:25:52 | 000,015,781 | —- | M] (Meetinghouse Data Communications) [Kernel | Auto | Stopped] – C:\WINDOWS\system32\drivers\mdc8021x.sys – (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2008/04/13 12:54:36 | 000,028,672 | —- | M] (National Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nscirda.sys – (NSCIRDA)
DRV - [2008/04/13 12:36:39 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/13 12:36:39 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2004/11/09 04:53:00 | 000,012,288 | —- | M] (IBM Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\qcndisif.sys – (QCNDISIF)
DRV - [2004/11/09 04:53:00 | 000,011,520 | —- | M] (IBM Corp.) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\ANC.sys – (ANC)
DRV - [2004/11/09 04:53:00 | 000,002,432 | —- | M] () [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\IBMBLDID.SYS – (IBMTPCHK)
DRV - [2004/09/23 18:39:58 | 000,064,256 | —- | M] (IBM) [Kernel | Auto | Stopped] – C:\WINDOWS\system32\drivers\ibmfilter.sys – (ibmfilter)
DRV - [2004/09/02 02:05:00 | 000,100,603 | —- | M] (Sonic Solutions) [File_System | Auto | Stopped] – C:\WINDOWS\system32\dla\tfsnudfa.sys – (tfsnudfa)
DRV - [2004/09/02 02:05:00 | 000,098,714 | —- | M] (Sonic Solutions) [File_System | Auto | Stopped] – C:\WINDOWS\system32\dla\tfsnudf.sys – (tfsnudf)
DRV - [2004/09/02 02:05:00 | 000,086,202 | —- | M] (Sonic Solutions) [File_System | Auto | Stopped] – C:\WINDOWS\system32\dla\tfsnifs.sys – (tfsnifs)
DRV - [2004/09/02 02:05:00 | 000,034,843 | —- | M] (Sonic Solutions) [File_System | Auto | Stopped] – C:\WINDOWS\system32\dla\tfsncofs.sys – (tfsncofs)
DRV - [2004/09/02 02:05:00 | 000,025,723 | —- | M] (Sonic Solutions) [File_System | Auto | Stopped] – C:\WINDOWS\system32\dla\tfsnboio.sys – (tfsnboio)
DRV - [2004/09/02 02:05:00 | 000,014,715 | —- | M] (Sonic Solutions) [File_System | Auto | Stopped] – C:\WINDOWS\system32\dla\tfsnopio.sys – (tfsnopio)
DRV - [2004/09/02 02:05:00 | 000,006,363 | —- | M] (Sonic Solutions) [File_System | Auto | Stopped] – C:\WINDOWS\system32\dla\tfsnpool.sys – (tfsnpool)
DRV - [2004/09/02 02:05:00 | 000,004,123 | —- | M] (Sonic Solutions) [File_System | Auto | Stopped] – C:\WINDOWS\system32\dla\tfsndrct.sys – (tfsndrct)
DRV - [2004/09/02 02:05:00 | 000,002,239 | —- | M] (Sonic Solutions) [File_System | Auto | Stopped] – C:\WINDOWS\system32\dla\tfsndres.sys – (tfsndres)
DRV - [2004/08/25 14:28:46 | 000,787,456 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2004/08/17 04:21:00 | 000,087,168 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\drvmcdb.sys – (drvmcdb)
DRV - [2004/08/03 23:41:36 | 000,606,684 | —- | M] (LT) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ltmdmnt.sys – (ltmodem5)
DRV - [2004/07/29 02:37:00 | 000,016,384 | —- | M] (IBM Corp.) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\TPPWR.SYS – (TPPWR)
DRV - [2004/07/29 02:36:00 | 000,014,848 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\SMAPINT.SYS – (Smapint)
DRV - [2004/07/29 02:36:00 | 000,009,341 | —- | M] () [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\TDSMAPI.SYS – (TDSMAPI)
DRV - [2004/07/22 19:41:42 | 000,393,408 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ar5211.sys – (AR5211)
DRV - [2004/07/22 16:25:58 | 000,197,888 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\HSFHWICH.sys – (HSFHWICH)
DRV - [2004/07/22 16:24:52 | 000,676,096 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2004/07/22 16:24:20 | 001,041,152 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2004/07/15 03:31:00 | 000,007,168 | —- | M] () [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\TSMAPIP.SYS – (TSMAPIP)
DRV - [2004/07/14 12:29:04 | 000,005,627 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\sscdbhk5.sys – (sscdbhk5)
DRV - [2004/07/14 12:28:50 | 000,023,545 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\ssrtln.sys – (ssrtln)
DRV - [2004/07/14 03:56:00 | 000,040,448 | —- | M] (Sonic Solutions) [File_System | Auto | Stopped] – C:\WINDOWS\system32\drivers\drvnddm.sys – (drvnddm)
DRV - [2004/07/06 17:50:36 | 000,059,520 | —- | M] (IBM Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\shockprf.sys – (Shockprf)
DRV - [2004/06/16 11:47:28 | 000,270,928 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2004/06/09 21:19:46 | 000,016,340 | —- | M] (IBM Corporation) [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\TPHKDRV.sys – (TPHKDRV)
DRV - [2004/05/14 13:59:00 | 000,004,608 | —- | M] (IBM Corporation) [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\ShockMgr.sys – (ShockMgr)
DRV - [2004/03/19 13:03:58 | 000,005,120 | —- | M] (IBM Corporation) [Kernel | Auto | Stopped] – C:\WINDOWS\system32\egathdrv.sys – (EGATHDRV)
DRV - [2004/02/26 02:26:00 | 000,011,344 | —- | M] (IBM Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ibmpmdrv.sys – (IBMPMDRV)
DRV - [2001/11/01 04:57:14 | 000,095,104 | —- | M] (S3 Graphics, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s3ssavm.sys – (S3SSavage)
DRV - [2001/08/17 15:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 15:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 15:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 15:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 15:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 14:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 14:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 14:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 14:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 14:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 14:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 14:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 14:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 14:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 14:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2001/08/17 14:48:14 | 000,011,520 | —- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\TwoTrack.sys – (TwoTrack)
DRV - [2001/08/17 13:20:04 | 000,096,256 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ac97intc.sys – (ac97intc) Intel® 82801 Audio Driver Install Service (WDM)
DRV - [2000/05/31 21:29:54 | 000,007,012 | —- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] – C:\WINDOWS\system32\drivers\PMEMNT.SYS – (PMEM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.yahoo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\IPSFFPlgn\ [2010/06/01 17:27:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\coFFPlgn\ [2010/02/10 20:19:30 | 000,000,000 | —D | M]


O1 HOSTS File: ([2001/08/18 03:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BMMGAG] C:\Program Files\ThinkPad\Utilities\PWRMONIT.DLL (IBM Corp.)
O4 - HKLM..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE ()
O4 - HKLM..\Run: [BMMMONWND] C:\Program Files\ThinkPad\Utilities\BATINFEX.DLL ()
O4 - HKLM..\Run: [EZEJMNAP] C:\Program Files\ThinkPad\Utilities\EzEjMnAp.Exe (IBM Corp.)
O4 - HKLM..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe ()
O4 - HKLM..\Run: [IBMPRC] C:\IBMTOOLS\utils\ibmprc.exe (IBM Corp.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE (IBM Corp.)
O4 - HKLM..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE (IBM Corp.)
O4 - HKLM..\Run: [S3TRAY2] C:\WINDOWS\System32\S3Tray2.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [SupportAnyPC] File not found
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TP4EX] C:\WINDOWS\System32\TP4EX.exe (IBM Corporation)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe ()
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe (IBM Corp.)
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (IBM Corp.)
O4 - HKLM..\Run: [UC_SMB] File not found
O4 - HKLM..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe ()
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1255377659354 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/1.4.1/…all-141-win.cab (Java Plug-in 1.4.1)
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.4.1/…all-141-win.cab (Java Plug-in 1.4.1)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll ()
O20 - Winlogon\Notify\QConGina: DllName - QConGina.dll - C:\WINDOWS\System32\QConGina.dll (IBM Corp.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/09 16:26:17 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{e0a61dc3-3759-11df-880a-000e9b8e459e}\Shell\AutoRun\command - "" = E:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()

CREATERESTOREPOINT
Error starting restore point: The function was called in safe mode.
Error closing restore point: The sequence number is invalid.

========== Files/Folders - Created Within 30 Days ==========

[2011/01/24 08:54:39 | 000,603,136 | —- | C] (OldTimer Tools) – C:\Documents and Settings\k\Desktop\OTL.exe
[2011/01/23 18:28:16 | 000,000,000 | —D | C] – C:\Documents and Settings\k\Local Settings\Application Data\Symantec
[2011/01/23 12:05:51 | 000,264,704 | —- | C] (OldTimer Tools) – C:\Documents and Settings\k\Desktop\TFC.exe
[2011/01/17 11:51:12 | 000,000,000 | —D | C] – C:\Documents and Settings\k\Start Menu\Programs\HiJackThis
[2011/01/17 10:05:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis
[2011/01/17 10:05:48 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/01/16 20:22:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2011/01/16 19:53:59 | 000,000,000 | —D | C] – C:\WINDOWS\Downloaded Installations
[2011/01/16 19:52:26 | 000,000,000 | —D | C] – C:\SWTOOLS
[2011/01/16 19:49:11 | 227,528,072 | —- | C] (Lenovo Group Limited ) – C:\Documents and Settings\k\Desktop\tvtrnr423_016en.exe
[2011/01/16 19:14:15 | 000,000,000 | —D | C] – C:\Documents and Settings\k\Application Data\Malwarebytes
[2011/01/16 19:07:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/01/16 19:07:05 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/01/16 19:07:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/01/16 19:07:02 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/01/16 19:07:02 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/01/16 19:05:12 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/01/16 19:04:21 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2011/01/16 19:04:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2011/01/16 12:41:36 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2011/01/07 15:38:16 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2009/10/09 13:51:26 | 000,151,552 | —- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll

========== Files - Modified Within 30 Days ==========

[2011/01/24 08:54:39 | 000,603,136 | —- | M] (OldTimer Tools) – C:\Documents and Settings\k\Desktop\OTL.exe
[2011/01/23 19:37:40 | 000,002,278 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/23 19:37:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/23 19:01:29 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/23 19:01:29 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{1AC8F9E9-7A52-4DD9-8FE2-843BE1628F82}.job
[2011/01/23 18:58:20 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{940CA5F4-A597-41C7-AFAA-A3105B076463}.job
[2011/01/23 18:57:45 | 000,000,414 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{9CC176C6-80F7-4F04-9F47-D67709F95B58}.job
[2011/01/23 17:29:52 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/23 12:05:51 | 000,264,704 | —- | M] (OldTimer Tools) – C:\Documents and Settings\k\Desktop\TFC.exe
[2011/01/20 07:29:21 | 000,626,176 | —- | M] () – C:\Documents and Settings\k\Desktop\dds.scr
[2011/01/17 11:52:26 | 000,000,036 | —- | M] () – C:\Documents and Settings\k\Local Settings\Application Data\housecall.guid.cache
[2011/01/17 11:51:13 | 000,001,976 | —- | M] () – C:\Documents and Settings\k\Desktop\HiJackThis.lnk
[2011/01/16 19:55:48 | 000,030,144 | —- | M] (Lenovo (United States) Inc.) – C:\WINDOWS\System32\drivers\psadd.sys
[2011/01/16 19:50:43 | 227,528,072 | —- | M] (Lenovo Group Limited ) – C:\Documents and Settings\k\Desktop\tvtrnr423_016en.exe
[2011/01/16 19:07:06 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/13 21:07:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK

========== Files Created - No Company Name ==========

[2011/01/20 07:29:20 | 000,626,176 | —- | C] () – C:\Documents and Settings\k\Desktop\dds.scr
[2011/01/17 11:52:26 | 000,000,036 | —- | C] () – C:\Documents and Settings\k\Local Settings\Application Data\housecall.guid.cache
[2011/01/17 10:05:49 | 000,001,976 | —- | C] () – C:\Documents and Settings\k\Desktop\HiJackThis.lnk
[2011/01/16 19:07:06 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/16 18:11:53 | 000,000,438 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{1AC8F9E9-7A52-4DD9-8FE2-843BE1628F82}.job
[2011/01/16 14:49:16 | 000,000,438 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{940CA5F4-A597-41C7-AFAA-A3105B076463}.job
[2009/10/31 19:46:02 | 000,009,728 | —- | C] () – C:\Documents and Settings\k\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/12 11:51:55 | 000,000,165 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/10/12 09:48:27 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/10/09 15:47:28 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/10/09 15:45:40 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2009/10/09 15:45:07 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2009/10/09 15:45:07 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2009/10/09 15:44:27 | 000,002,432 | —- | C] () – C:\WINDOWS\System32\drivers\IBMBLDID.SYS
[2009/10/09 15:37:42 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2009/10/09 15:37:42 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2009/10/09 15:37:42 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2009/10/09 15:37:42 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2009/10/09 15:37:42 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2009/10/09 15:37:42 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2009/10/09 15:36:24 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/10/09 15:28:42 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\FPCALL.dll
[2009/10/09 15:28:24 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2009/10/09 15:27:55 | 000,009,341 | —- | C] () – C:\WINDOWS\System32\drivers\TDSMAPI.SYS
[2009/10/09 15:26:13 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2009/10/09 15:26:13 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2009/10/09 14:07:14 | 000,002,481 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2009/10/09 13:51:26 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2004/11/08 18:12:56 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/03/19 13:12:10 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\pwdmon.dll
[2004/03/19 13:12:10 | 000,019,692 | —- | C] () – C:\WINDOWS\ibmprc.ini
[2004/01/09 07:10:32 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\AIBMRUNL.dll
[2003/02/20 10:32:29 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/02/20 10:03:32 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1980/01/01 01:00:00 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\e1000msg.dll
[1980/01/01 01:00:00 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\SynTPCoI.dll
[1980/01/01 01:00:00 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\tpinspm.dll

========== LOP Check ==========

[2009/10/09 15:36:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IBM
[2009/12/18 10:43:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2010/03/06 21:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\k\Application Data\GARMIN
[2009/10/09 15:46:44 | 000,000,314 | —- | M] () – C:\WINDOWS\Tasks\BMMTask.job
[2011/01/23 19:01:29 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{1AC8F9E9-7A52-4DD9-8FE2-843BE1628F82}.job
[2011/01/23 18:58:20 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{940CA5F4-A597-41C7-AFAA-A3105B076463}.job
[2011/01/23 18:57:45 | 000,000,414 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{9CC176C6-80F7-4F04-9F47-D67709F95B58}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/10/09 16:26:17 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2009/10/09 16:25:38 | 000,000,194 | RHS- | M] () – C:\BOOT.INI
[2009/10/09 15:31:34 | 000,000,000 | -H– | M] () – C:\BOOTLOG.PRV
[2009/10/09 15:48:16 | 000,000,000 | -H– | M] () – C:\BOOTLOG.TXT
[2003/02/20 09:54:04 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2009/10/09 15:46:20 | 000,000,355 | —- | M] () – C:\ccrrec.ver
[2009/10/09 16:26:17 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2009/10/09 15:35:48 | 000,000,754 | —- | M] () – C:\drivez.log
[2009/10/09 16:26:18 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2009/10/09 15:34:08 | 000,000,164 | —- | M] () – C:\LOGFILE.txt
[2009/10/12 12:29:43 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/10/09 15:12:40 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/10/12 15:04:29 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/01/23 19:36:56 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2009/10/09 14:07:16 | 000,001,543 | —- | M] () – C:\SYSLEVEL.IBM
[2009/10/09 14:05:30 | 000,000,043 | —- | M] () – C:\TCPACHIP.LOG

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2003/02/20 10:13:04 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >
[2003/07/15 17:35:04 | 000,002,193 | —- | M] () – C:\WINDOWS\system32\TpShPrm.jpg

< %systemroot%\*.jpg >
[2002/10/10 14:07:40 | 000,055,408 | —- | M] () – C:\WINDOWS\1024 x 768 IBM Americas Map.jpg

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/04/08 19:19:16 | 000,001,738 | -H– | M] () – C:\Documents and Settings\k\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2003/02/20 10:02:10 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2003/02/20 10:02:10 | 000,626,688 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2003/02/20 10:02:10 | 000,413,696 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/10/12 15:14:08 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/10/12 15:21:38 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\k\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2003/02/20 10:21:00 | 000,000,079 | —- | M] () – C:\Documents and Settings\k\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/12/18 10:41:53 | 000,403,128 | —- | M] (Symantec Corporation) – C:\Documents and Settings\k\Desktop\NISDownloader.exe
[2011/01/24 08:54:39 | 000,603,136 | —- | M] (OldTimer Tools) – C:\Documents and Settings\k\Desktop\OTL.exe
[2011/01/23 12:05:51 | 000,264,704 | —- | M] (OldTimer Tools) – C:\Documents and Settings\k\Desktop\TFC.exe
[2011/01/16 19:50:43 | 227,528,072 | —- | M] (Lenovo Group Limited ) – C:\Documents and Settings\k\Desktop\tvtrnr423_016en.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-17 14:25:16

< End of report >
83valentine,

I realize that you ran chkdsk before posting here… but your event log is showing a bunch of disk errors. Let's try it again:

Click on Start in the lower left of your screen and select Run
Type CMD in the box and click OK
Type chkdsk c: /r, (don't forget the spaces. There are two. It is chkdsk^c/:^/r) and hit enter
Type Y to agree to run at restart
Type Exit and hit enter.

Now reboot your computer and let Chkdsk run.
found one bad cluster, non safe mode is running a little better, still slightly slow. What is the difference between chkdsk c: /r that found bad sectors and chkdsk /r that I ran and did not find bad clusters?

What is the difference between chkdsk c: /r that found bad sectors and chkdsk /r that I ran and did not find bad clusters?

I'm honestly not sure what happens if you don't tell it what disk to check. Maybe it only looks in memory?

Please run chkdsk again and make sure it comes back without any errors.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI