This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

System freezing up? Virus?

244 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

BJ2011,

That is the concern of those reading your thread also. That is why you were asked to make sure you have excellent backups.

Now, to do a little trouble shooting to prove what is going wrong.

You appear to have a Western Digital Hard drive so go here: http://support.wdc.com/product/download.as…d=3&lang=en and download the diagnostic tool. Follow the directions and run it. Then post your results here.
Here is the info from the OTL scan. The result for the WINDlg scan came back as passed under the SMART status.


OTL logfile created on: 7/11/2011 10:35:54 AM - Run 2
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\ADavis\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.74 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 54.39% Memory free
5.48 Gb Paging File | 4.09 Gb Available in Paging File | 74.55% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.99 Gb Total Space | 247.44 Gb Free Space | 86.82% Space Free | Partition Type: NTFS

Computer Name: ADAVIS-PC | User Name: ADavis | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\ADavis\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10t_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe (Suyin)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Lexmark 2400 Series\lxcrmon.exe ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\ADavis\Downloads\OTL.exe (OldTimer Tools)
MOD - c:\Program Files (x86)\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer Group)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (lxcr_device) – C:\Windows\SysNative\lxcrcoms.exe ( )
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (McAfee SiteAdvisor Service) – c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (McAfee, Inc.)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (GREGService) – C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (lxcr_device) – C:\Windows\SysWow64\lxcrcoms.exe ( )


========== Driver Services (SafeList) ==========

DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (ETD) – C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronic Corp.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…04z1k5a47l2j274
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…04z1k5a47l2j274

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=685749"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=panda&type=panda2_0yatb&p="

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/05/24 21:59:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/26 22:03:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/01/30 01:05:04 | 000,000,000 | —D | M] (No name found) – C:\Users\ADavis\AppData\Roaming\Mozilla\Extensions
[2011/06/14 21:05:08 | 000,000,000 | —D | M] (No name found) – C:\Users\ADavis\AppData\Roaming\Mozilla\Firefox\Profiles\afr7xwbh.default\extensions
[2011/03/02 00:22:32 | 000,000,000 | —D | M] (Xfinity.com Toolbar) – C:\Users\ADavis\AppData\Roaming\Mozilla\Firefox\Profiles\afr7xwbh.default\extensions\{7000b6ca-4388-4d95-893d-6659c2d4d1ce}
[2011/06/14 07:42:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) –
() (No name found) – C:\USERS\ADAVIS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AFR7XWBH.DEFAULT\EXTENSIONS\[removed]
[2011/06/26 22:03:46 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/07/01 16:32:28 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [lxcrmon.exe] C:\Program Files (x86)\Lexmark 2400 Series\lxcrmon.exe ()
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [VideoWebCamera] C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe (Suyin)
O4 - HKCU..\Run: [DW6] C:\Program Files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
O4 - Startup: C:\Users\ADavis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ZooskMessenger.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: phoenix.edu ([]* in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/11 10:39:55 | 000,000,000 | —D | C] – C:\Users\ADavis\Documents\WinDlg_124
[2011/07/11 08:26:07 | 000,000,000 | —D | C] – C:\Users\ADavis\Documents\Disk Recovery Instructions
[2011/07/10 23:53:40 | 000,000,000 | —D | C] – C:\73ee6a3e107d0b53a3c1d614
[2011/07/08 13:17:46 | 000,000,000 | —D | C] – C:\Windows\CheckSur
[2011/07/03 02:45:14 | 000,000,000 | —D | C] – C:\8be829f691e7eb7433c9b23b
[2011/07/03 02:39:22 | 000,000,000 | —D | C] – C:\Windows\SysNative\EventProviders
[2011/07/02 10:03:41 | 000,000,000 | —D | C] – C:\Users\ADavis\AppData\Local\Secunia PSI
[2011/07/02 10:02:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Secunia
[2011/07/02 07:22:15 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/07/01 16:03:00 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/07/01 14:23:27 | 000,000,000 | —D | C] – C:\ComboFix
[2011/07/01 10:33:29 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/07/01 09:13:33 | 000,000,000 | —D | C] – C:\CF
[2011/06/30 23:20:18 | 004,129,832 | R— | C] (Swearware) – C:\Users\ADavis\Desktop\ComboFix.exe
[2011/06/30 06:43:18 | 000,000,000 | —D | C] – C:\541bf72e2bcb04740433cb5e66
[2011/06/29 09:21:41 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/06/29 09:21:41 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/06/29 09:21:10 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/06/29 09:21:07 | 000,000,000 | —D | C] – C:\Qoobox
[2011/06/29 08:00:20 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drvinst.exe
[2011/06/29 08:00:19 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\devrtl.dll
[2011/06/29 07:59:27 | 002,228,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssrch.dll
[2011/06/29 07:59:27 | 001,401,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2011/06/29 07:59:26 | 002,326,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tquery.dll
[2011/06/29 07:59:26 | 001,553,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2011/06/29 07:59:25 | 000,491,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssph.dll
[2011/06/29 07:59:24 | 000,779,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssvp.dll
[2011/06/29 07:59:24 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2011/06/29 07:59:24 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2011/06/29 07:59:24 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchProtocolHost.exe
[2011/06/29 07:59:24 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msscntrs.dll
[2011/06/29 07:59:23 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssphtb.dll
[2011/06/29 07:59:23 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssphtb.dll
[2011/06/29 07:59:23 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchFilterHost.exe
[2011/06/29 07:59:23 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscntrs.dll
[2011/06/29 00:29:32 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\AVG
[2011/06/28 10:28:42 | 000,000,000 | —D | C] – C:\06c13ec8562a5b0418ca2026568788
[2011/06/27 12:10:46 | 000,000,000 | —D | C] – C:\Users\ADavis\Documents\Note Pad
[2011/06/26 22:00:46 | 000,000,000 | —D | C] – C:\Users\ADavis\AppData\Local\The Weather Channel
[2011/06/26 11:26:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\The Weather Channel FW
[2011/06/25 23:35:34 | 000,000,000 | —D | C] – C:\Users\ADavis\AppData\Roaming\AVG10
[2011/06/25 23:34:43 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2011/06/25 23:32:49 | 000,000,000 | —D | C] – C:\ProgramData\AVG10
[2011/06/25 23:32:49 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\AVG
[2011/06/25 23:31:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2011/06/25 23:23:04 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/06/25 16:33:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intel Corporation
[2011/06/23 11:01:05 | 000,000,000 | —D | C] – C:\Users\ADavis\AppData\Local\{C989FBBD-27AF-483F-BBFD-EE20CF92A908}
[2011/06/23 11:00:31 | 000,000,000 | —D | C] – C:\Users\ADavis\AppData\Local\{D1810653-8CB3-4D41-BA82-B60BD4F894A8}
[2011/06/17 06:43:02 | 000,000,000 | —D | C] – C:\found.000
[2011/06/16 11:12:08 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/06/16 06:33:25 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/16 06:33:24 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/16 06:33:23 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/16 06:33:22 | 002,303,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/06/16 06:33:22 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9.dll
[2011/06/16 06:33:22 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/06/16 06:33:22 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/16 06:33:21 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/06/15 16:50:02 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/06/15 16:50:02 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/06/15 16:49:55 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/15 06:02:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\ZooskMessenger
[2011/06/14 08:03:20 | 000,000,000 | —D | C] – C:\Users\ADavis\Documents\FAFSA 2011
[2011/06/14 07:42:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/06/13 15:19:47 | 000,000,000 | —D | C] – C:\Users\ADavis\Documents\Cassy
[2011/04/14 15:57:23 | 001,224,704 | —- | C] ( ) – C:\Windows\SysWow64\lxcrserv.dll
[2011/04/14 15:57:23 | 000,991,232 | —- | C] ( ) – C:\Windows\SysWow64\lxcrusb1.dll
[2011/04/14 15:57:23 | 000,684,032 | —- | C] ( ) – C:\Windows\SysWow64\lxcrcomc.dll
[2011/04/14 15:57:23 | 000,643,072 | —- | C] ( ) – C:\Windows\SysWow64\lxcrpmui.dll
[2011/04/14 15:57:23 | 000,585,728 | —- | C] ( ) – C:\Windows\SysWow64\lxcrlmpm.dll
[2011/04/14 15:57:23 | 000,537,520 | —- | C] ( ) – C:\Windows\SysWow64\lxcrcoms.exe
[2011/04/14 15:57:23 | 000,421,888 | —- | C] ( ) – C:\Windows\SysWow64\lxcrcomm.dll
[2011/04/14 15:57:23 | 000,413,696 | —- | C] ( ) – C:\Windows\SysWow64\lxcrinpa.dll
[2011/04/14 15:57:23 | 000,397,312 | —- | C] ( ) – C:\Windows\SysWow64\lxcriesc.dll
[2011/04/14 15:57:23 | 000,385,968 | —- | C] ( ) – C:\Windows\SysWow64\lxcrih.exe
[2011/04/14 15:57:23 | 000,181,168 | —- | C] ( ) – C:\Windows\SysWow64\lxcrppls.exe
[2011/04/14 15:57:23 | 000,163,840 | —- | C] ( ) – C:\Windows\SysWow64\lxcrprox.dll
[2011/04/14 15:57:23 | 000,094,208 | —- | C] ( ) – C:\Windows\SysWow64\lxcrpplc.dll
[2010/09/05 09:16:24 | 000,051,712 | —- | C] ( ) – C:\Windows\AutosetFrequency.exe
[1 C:\Users\ADavis\AppData\Local\*.tmp files -> C:\Users\ADavis\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/11 10:35:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-423400263-3511664193-1932377409-1000UA.job
[2011/07/11 09:59:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/11 09:35:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-423400263-3511664193-1932377409-1000Core.job
[2011/07/11 09:06:04 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/11 09:05:58 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/11 08:26:37 | 000,730,682 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/07/11 08:26:37 | 000,626,956 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/07/11 08:26:37 | 000,107,942 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/07/11 07:08:43 | 000,000,326 | —- | M] () – C:\Windows\tasks\GlaryInitialize.job
[2011/07/11 07:08:42 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/11 06:57:42 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/11 06:57:33 | 2207,285,248 | -HS- | M] () – C:\hiberfil.sys
[2011/07/02 10:03:36 | 000,001,113 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/07/01 16:32:28 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/07/01 10:25:12 | 000,000,000 | —- | M] () – C:\Users\ADavis\AppData\Local\{BF5BEF9C-F1CF-4309-A3A8-84D10DEB4F86}
[2011/07/01 09:14:15 | 004,129,832 | R— | M] (Swearware) – C:\Users\ADavis\Desktop\ComboFix.exe
[2011/07/01 02:56:21 | 000,274,320 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/30 06:48:21 | 000,002,411 | —- | M] () – C:\Users\ADavis\Desktop\Google Chrome.lnk
[2011/06/29 00:29:32 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\iavifw.avm
[2011/06/28 12:28:13 | 000,001,046 | —- | M] () – C:\Users\ADavis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ZooskMessenger.lnk
[2011/06/27 17:51:16 | 000,655,467 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavifw.avm
[2011/06/26 01:45:56 | 000,256,000 | —- | M] () – C:\Windows\PEV.exe
[2011/06/24 20:48:40 | 000,000,000 | —- | M] () – C:\0x0304A000.sfl[2011/06/24 05:58:19 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/06/20 01:36:37 | 000,037,024 | —- | M] () – C:\Users\ADavis\Documents\Turnitin_Originality_Report_192102791 for Wk 4 Team Paper-Media Assessment and Article Review.html
[2011/06/14 07:43:02 | 000,001,145 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[1 C:\Users\ADavis\AppData\Local\*.tmp files -> C:\Users\ADavis\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/02 10:03:36 | 000,001,113 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/07/02 10:03:36 | 000,001,076 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2011/07/01 10:25:12 | 000,000,000 | —- | C] () – C:\Users\ADavis\AppData\Local\{BF5BEF9C-F1CF-4309-A3A8-84D10DEB4F86}
[2011/06/29 09:21:41 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/06/29 09:21:41 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/06/29 09:21:41 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/06/29 09:21:41 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/06/29 09:21:41 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/06/29 00:29:32 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\iavifw.avm
[2011/06/28 23:26:56 | 000,655,467 | —- | C] () – C:\Windows\SysNative\drivers\AVG\iavifw.avm
[2011/06/24 20:48:40 | 000,000,000 | —- | C] () – C:\0x0304A000.sfl
[2011/06/20 01:36:36 | 000,037,024 | —- | C] () – C:\Users\ADavis\Documents\Turnitin_Originality_Report_192102791 for Wk 4 Team Paper-Media Assessment and Article Review.html
[2011/06/14 07:43:02 | 000,001,145 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/14 07:42:57 | 000,001,157 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/04/21 23:03:09 | 000,000,017 | —- | C] () – C:\Windows\SysWow64\shortcut_ex.dat
[2011/04/14 15:57:23 | 000,385,024 | —- | C] () – C:\Windows\SysWow64\lxcrcomx.dll
[2011/04/14 15:57:23 | 000,274,432 | —- | C] () – C:\Windows\SysWow64\LXCRinst.dll
[2011/03/12 00:58:04 | 000,007,605 | —- | C] () – C:\Users\ADavis\AppData\Local\Resmon.ResmonCfg
[2011/03/09 08:30:50 | 000,534,528 | —- | C] () – C:\Windows\SysWow64\EncDec.dll
[2011/02/25 23:48:36 | 000,003,584 | —- | C] () – C:\Users\ADavis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/25 22:34:00 | 001,389,568 | —- | C] () – C:\Windows\SysWow64\msxml6.dll
[2011/02/11 19:15:08 | 000,874,048 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2011/01/30 01:04:50 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/01/15 19:22:20 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/15 01:54:36 | 000,000,063 | —- | C] () – C:\Windows\wininit.ini
[2011/01/14 23:19:45 | 000,744,400 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/09/05 09:16:24 | 000,206,208 | —- | C] () – C:\Windows\PLFSetI.exe
[2010/09/05 09:16:24 | 000,000,637 | —- | C] () – C:\Windows\AutoSetFrequency.ini
[2010/09/05 09:16:24 | 000,000,378 | —- | C] () – C:\Windows\PidList.ini
[2010/08/25 20:34:30 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/08/25 20:34:30 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

< End of report >
Hi, Tomk! Sorry, I wasn't able to get back to you on yesterday. I had a research paper due for class on yesterday. Thankfully, I was able to borrow another laptop to get the paper done. Also, as I was attempting to run the scan again, my laptop sent me the message to insert by boot disk. I couldn't remember what I did with it. I'm out-of-town til Thursday evening. I will go home and search for it. Or I am going to have to find away to get hold of another disk. :smack:
That doesn't sound good. It appears that your system is failing… but we don't know why. Could be hard drive failing - which we are trying to check. Could be power supply. Could be something else. The bottom line is, the indications are not good. I'm concerned that even if you get a boot disk - something in your system is on its last leg, and your computer isn't long for this world. How old is this computer? Any warranty left on it?

The laptop was purchased Jan 2011. The warranty has lapsed.

Are you sure? It appears that you have a Gateway laptop and their website indicates that they give a 1 year warranty. January 2011 is less than a year ago.
I just attempted to restore my laptop with the factory disc. The restore was unsuccessful. I received the below message. "Restore failed - Error code=0x45d (WIMApply Image cannot apply image. The request could not be performed because of an I/O device error. Restore unsuccessful. Please try Completely Restore System to Factory Default instead of trying to Restore Operating System and Retain User Data again. I also had received this following message." Should I go ahead and try the other option?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI