This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer will only boot in safe mode [Closed]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer will only boot in safe mode. I have tried a system restore. I have windows vista and a Toshiba Satellite. And here is my hijack this log.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:54:34 PM, on 4/16/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\helppane.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\cmd.exe
C:\Windows\system32\sfc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Simpson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AB8O3VKK\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100429 -Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729; OfficeLiveConnector.1.5; OfficeLivePatch.1.3; .NET4.0C)
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe -update activex
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: LightShot - {000D21C0-9D53-4E88-923D-B38D3A1B631E} - C:\Users\Simpson\AppData\Local\Skillbrains\lightshot-ie\2.6.0.0\LightShot.dll (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://atitesting.webex.com/client/T27LD/nbr/ieatgpc1.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: pinger - Unknown owner - C:\TOSHIBA\IVP\ISM\pinger.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 13153 bytes
Hi and Welcome!! ericaps :)

My name is Robybel.

I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! ;)

==============================================================
Ok go ahead

Please download Farbar Recovery Scan Tool 32-Bit
Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

here is the log. Thank you for your reply! Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-04-2013 02 Ran by [removed] on 22-04-2013 12:48:08 Running from G:\ Windows Vista ™ Home Premium Service Pack 1 (X86) OS Language: English(US) Internet Explorer Version 9 Boot Mode: Recovery The current controlset is ControlSet003 ==================== Registry (Whitelisted) ================== HKLM\…\Run: [RtHDVCpl] RtHDVCpl.exe [x] HKLM\…\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start [413696 2007-10-25] (Chicony) HKLM\…\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1348904 2008-08-14] (Synaptics, Inc.) HKLM\…\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [431456 2008-01-17] (TOSHIBA Corporation) HKLM\…\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe [54608 2007-10-31] (TOSHIBA Corporation) HKLM\…\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [448080 2007-06-15] (TOSHIBA Corporation) HKLM\…\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1008184 2008-01-20] (Microsoft Corporation) HKLM\…\Run: [NDSTray.exe] NDSTray.exe [x] HKLM\…\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup [1862144 2008-02-13] (Google) HKLM\…\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [712704 2008-01-22] (TOSHIBA Corporation) HKLM\…\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" [398728 2008-01-29] (Symantec Corporation) HKLM\…\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.) HKLM\…\Run: [Skytel] Skytel.exe [x] HKLM\…\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-03-01] (Nero AG) HKLM\…\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-02-18] (Hewlett-Packard) HKLM\…\Run: [] [x] HKLM\…\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup [103768 2009-09-12] (Citrix Systems, Inc.) HKLM\…\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [40368 2011-08-30] (Adobe Systems Incorporated) HKLM\…\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-29] (Adobe Systems Incorporated) HKLM\…\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.) HKLM\…\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.) HKLM\…\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2011-12-07] (Apple Inc.) HKU\Default\…\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2008-01-29] () HKU\Default User\…\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2008-01-29] () HKU\Simpson\…\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2008-01-29] () HKU\Simpson\…\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [ 2008-01-20] (Microsoft Corporation) HKU\Simpson\…\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [ 2008-07-30] (Hewlett-Packard Company) HKU\Simpson\…\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [ 2008-01-20] (Microsoft Corporation) HKU\Simpson\…\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [x] HKU\Simpson\…\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized [ 2010-05-13] (Skype Technologies S.A.) HKU\Simpson\…\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent [ 2009-03-28] (Electronic Arts) HKU\Simpson\…\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x] HKU\Simpson\…\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100429 -Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729; OfficeLiveConnector.1.5; OfficeLivePatch.1.3; .NET4.0C) [x] HKU\Simpson\…\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe -update activex [ 2011-12-01] (Adobe Systems, Inc.) Startup: C:ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Simpson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ========================== Services (Whitelisted) ================= S2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2007-12-25] (TOSHIBA CORPORATION) S3 GameConsoleService; C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe [165416 2008-03-28] (WildTangent, Inc.) S3 GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [1862144 2008-02-13] (Google) S3 LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2999664 2007-09-12] (Symantec Corporation) S2 LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll [537992 2008-01-29] (Symantec Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [227232 2010-01-15] (McAfee, Inc.) S2 pinger; C:\TOSHIBA\IVP\ISM\pinger.exe [136816 2007-01-25] () S2 Swupdtmr; c:\TOSHIBA\IVP\swupdate\swupdtmr.exe [66928 2007-10-23] () S2 TOSHIBA SMART Log Service; C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [126976 2007-12-03] (TOSHIBA Corporation) S2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) S3 msiserver; %systemroot%\system32\msiexec /V [x] ==================== Drivers (Whitelisted) ==================== S3 NETwLv32; C:\Windows\System32\DRIVERS\NETwLv32.sys [6637056 1999-12-31] (Intel Corporation) S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13464 2013-04-18] () S3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [18432 2007-12-17] (Chicony Electronics Co., Ltd.) S1 Cdr4_xp; No ImagePath S1 Cdralw2k; No ImagePath S3 IO_Memory; \??\C:\WINDOWS\SYSTEM32\SYSPREP\Drivers\ioport.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S0 Lbd; system32\DRIVERS\Lbd.sys [x] S1 MpKsl8384e340; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{98B763DA-147B-4934-9404-4FF487724633}\MpKsl8384e340.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 SVRPEDRV; \??\C:\Windows\System32\sysprep\UP_date\PEDrv.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-04-22 12:46 - 2013-04-22 12:46 - 00000000 ____D C:\FRST 2013-04-18 12:17 - 1999-12-31 16:00 - 00053248 ____A (Windows XP Bundled build C-Centric Single User) C:\Windows\System32\CSVer.dll 2013-04-18 12:16 - 2013-04-18 12:16 - 00007044 ____A C:\Windows\DPINST.LOG 2013-04-18 12:16 - 1999-12-31 16:00 - 06637056 ____A (Intel Corporation) C:\Windows\System32\Drivers\NETwLv32.sys 2013-04-18 12:16 - 1999-12-31 16:00 - 02756608 ____A (Intel Corporation) C:\Windows\System32\NETwLr32.dll 2013-04-18 12:16 - 1999-12-31 16:00 - 00675840 ____A (Intel Corporation) C:\Windows\System32\NETwLc32.dll 2013-04-18 12:15 - 2013-04-18 12:17 - 00000000 ____D C:\Windows\LastGood 2013-04-18 12:14 - 2013-04-18 12:14 - 00000000 ____D C:\Intel 2013-04-18 12:14 - 1999-12-31 16:00 - 00363112 ____A (Realtek ) C:\Windows\System32\Drivers\Rtlh86.sys 2013-04-18 12:14 - 1999-12-31 16:00 - 00080488 ____A (Realtek Semiconductor Corporation) C:\Windows\System32\RtNicProp32.dll 2013-04-18 12:13 - 2013-04-18 12:13 - 00013464 ____A C:\Windows\System32\Drivers\SWDUMon.sys 2013-04-18 12:13 - 2013-04-18 12:13 - 00000390 ____A C:\Windows\Tasks\SlimDrivers Startup.job 2013-04-18 12:13 - 2013-04-18 12:13 - 00000000 ____D C:\Users\Simpson\AppData\Local\SlimWare Utilities Inc 2013-04-18 12:12 - 2013-04-18 12:12 - 00001854 ____A C:\Users\Public\Desktop\SlimDrivers.lnk 2013-04-18 12:12 - 2013-04-18 12:12 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers 2013-04-16 15:55 - 2013-04-16 15:55 - 00013155 ____A C:\Users\Simpson\Documents\hijackthis 4-16.txt 2013-04-15 17:09 - 2013-04-18 12:18 - 00027722 ____A C:\Windows\WindowsUpdate.log 2013-04-10 14:51 - 2013-04-10 15:12 - 00000000 ____D C:\Windows\System32\MpEngineStore ==================== One Month Modified Files and Folders ======== 2013-04-22 12:46 - 2013-04-22 12:46 - 00000000 ____D C:\FRST 2013-04-18 12:19 - 2010-07-24 09:34 - 00002040 ____A C:\Users\Public\Desktop\Google Earth.lnk 2013-04-18 12:19 - 2006-11-02 05:01 - 00032576 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-04-18 12:19 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-04-18 12:18 - 2013-04-15 17:09 - 00027722 ____A C:\Windows\WindowsUpdate.log 2013-04-18 12:17 - 2013-04-18 12:15 - 00000000 ____D C:\Windows\LastGood 2013-04-18 12:17 - 2010-01-28 13:58 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-04-18 12:17 - 2010-01-28 13:58 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-04-18 12:17 - 2008-04-17 11:26 - 00000000 ____D C:\users\Simpson 2013-04-18 12:17 - 2006-11-02 02:33 - 00703516 ____A C:\Windows\System32\PerfStringBackup.INI 2013-04-18 12:16 - 2013-04-18 12:16 - 00007044 ____A C:\Windows\DPINST.LOG 2013-04-18 12:16 - 2009-08-14 10:22 - 00000000 ____D C:\Program Files\DIFX 2013-04-18 12:14 - 2013-04-18 12:14 - 00000000 ____D C:\Intel 2013-04-18 12:14 - 2008-02-13 17:38 - 00000000 ____D C:\Program Files\Realtek 2013-04-18 12:13 - 2013-04-18 12:13 - 00013464 ____A C:\Windows\System32\Drivers\SWDUMon.sys 2013-04-18 12:13 - 2013-04-18 12:13 - 00000390 ____A C:\Windows\Tasks\SlimDrivers Startup.job 2013-04-18 12:13 - 2013-04-18 12:13 - 00000000 ____D C:\Users\Simpson\AppData\Local\SlimWare Utilities Inc 2013-04-18 12:12 - 2013-04-18 12:12 - 00001854 ____A C:\Users\Public\Desktop\SlimDrivers.lnk 2013-04-18 12:12 - 2013-04-18 12:12 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers 2013-04-18 12:10 - 2010-08-14 20:02 - 00000374 ____A C:\Windows\System32\Drivers\etc\hosts.ics 2013-04-18 12:02 - 2010-06-30 14:24 - 00001356 ____A C:\Users\Simpson\AppData\Local\d3d9caps.dat 2013-04-18 11:53 - 2006-11-02 04:47 - 00003744 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-04-18 11:53 - 2006-11-02 04:47 - 00003744 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-04-16 15:55 - 2013-04-16 15:55 - 00013155 ____A C:\Users\Simpson\Documents\hijackthis 4-16.txt 2013-04-15 18:17 - 2010-07-18 14:08 - 00000380 ____A C:\Windows\Tasks\update-sys.job 2013-04-15 17:35 - 2008-02-13 18:15 - 00000000 ____D C:\Program Files\Google 2013-04-15 17:25 - 2009-07-25 11:58 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-04-15 17:25 - 2006-11-02 02:22 - 56098816 ____A C:\Windows\System32\config\software_previous 2013-04-15 17:25 - 2006-11-02 02:22 - 40108032 ____A C:\Windows\System32\config\components_previous 2013-04-15 17:25 - 2006-11-02 02:22 - 19398656 ____A C:\Windows\System32\config\system_previous 2013-04-15 17:25 - 2006-11-02 02:22 - 00524288 ____A C:\Windows\System32\config\default_previous 2013-04-15 17:25 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\security_previous 2013-04-15 17:25 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\sam_previous 2013-04-15 17:24 - 2011-05-27 16:25 - 00000000 ____D C:\Users\Simpson\Documents\Electronic Arts 2013-04-15 17:24 - 2010-07-18 14:08 - 00000000 ____D C:\Users\Simpson\AppData\Local\Skillbrains 2013-04-15 17:24 - 2008-05-02 07:49 - 00000000 ____D C:\Windows\Minidump 2013-04-15 17:24 - 2006-11-02 03:18 - 00000000 __RSD C:\Windows\Media 2013-04-15 17:24 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\System32\spool 2013-04-15 17:24 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\System32\Msdtc 2013-04-15 17:24 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\rescache 2013-04-15 17:23 - 2011-05-27 15:51 - 00000000 ____D C:\Program Files\Electronic Arts 2013-04-15 17:23 - 2011-01-03 14:22 - 00000000 ____D C:\Program Files\Yahoo! 2013-04-15 17:23 - 2010-07-20 15:55 - 00000000 ___RD C:\Program Files\Skype 2013-04-15 17:23 - 2010-07-20 15:55 - 00000000 ____D C:\Program Files\Common Files\Skype 2013-04-15 17:23 - 2010-04-15 15:42 - 00000000 ____D C:ProgramData\McAfee Security Scan 2013-04-15 17:23 - 2010-04-15 15:42 - 00000000 ____D C:\Program Files\McAfee Security Scan 2013-04-15 17:23 - 2009-11-14 08:27 - 00000000 ____D C:\Program Files\StyleEase 2013-04-15 17:23 - 2008-08-01 09:29 - 00000000 ____D C:\Program Files\LightScribeTemplateLabeler 2013-04-15 17:23 - 2008-08-01 09:27 - 00000000 ____D C:\Program Files\Common Files\LightScribe 2013-04-15 17:23 - 2008-03-11 01:04 - 00000000 ____D C:ProgramData\Microsoft Help 2013-04-15 17:23 - 2008-02-13 17:38 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-04-15 17:23 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\registration 2013-04-15 16:55 - 2008-04-24 12:39 - 00000000 ____D C:\Program Files\Norton Security Scan 2013-04-15 15:22 - 2008-02-13 18:15 - 00000000 ____D C:\Program Files\Google(14) 2013-04-13 16:52 - 2010-07-20 15:56 - 00000000 ____D C:\Users\Simpson\AppData\Roaming\Skype 2013-04-10 15:12 - 2013-04-10 14:51 - 00000000 ____D C:\Windows\System32\MpEngineStore 2013-04-10 12:28 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\Microsoft.NET ==================== Known DLLs (ALL) ========================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit TDL4: custom:26000022 <===== ATTENTION! ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2012-06-16 23:00:27 Restore point made on: 2012-06-22 09:00:16 Restore point made on: 2012-06-28 02:12:54 Restore point made on: 2012-07-05 10:30:56 Restore point made on: 2012-07-13 03:17:46 Restore point made on: 2012-07-17 03:32:28 Restore point made on: 2012-07-21 08:53:14 Restore point made on: 2012-07-27 07:02:57 Restore point made on: 2012-08-01 10:23:04 Restore point made on: 2012-08-08 04:27:45 Restore point made on: 2012-08-14 08:32:50 Restore point made on: 2012-08-17 23:00:45 Restore point made on: 2012-08-19 06:10:39 Restore point made on: 2012-08-20 10:55:43 Restore point made on: 2012-08-21 07:10:16 Restore point made on: 2012-08-24 10:06:51 ==================== Memory info =========================== Percentage of memory in use: 14% Total physical RAM: 3061.21 MB Available physical RAM: 2607.54 MB Total Pagefile: 2848.84 MB Available Pagefile: 2679.99 MB Total Virtual: 2047.88 MB Available Virtual: 1972.95 MB ==================== Drives ================================ Drive c: (SQ004659V05) (Fixed) (Total:184.84 GB) (Free:107.65 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: (TOSHIBA SYSTEM VOLUME) (Fixed) (Total:1.46 GB) (Free:1.32 GB) NTFS Drive g: (RADIO) (Removable) (Total:1.86 GB) (Free:1.67 GB) FAT Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Disk ### Status Size Free Dyn Gpt ——– ———- ——- ——- — — Disk 0 Online 186 GB 0 B Disk 1 No Media 0 B 0 B Disk 2 Online 1908 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 OEM 1500 MB 1024 KB Partition 2 Primary 185 GB 1501 MB ================================================================================ == Disk: 0 Partition 1 Type : 27 Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 4 E TOSHIBA SYS NTFS Partition 1500 MB Healthy Hidden ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 C SQ004659V05 NTFS Partition 185 GB Healthy ========================================================= Partitions of Disk 2: =============== Partition ### Type Size Offset ————- —————- ——- ——- * Partition 1 Primary 1908 MB 0 B ================================================================================ == Disk: 2 There is no partition selected. There is no partition selected. Please select a partition and try again. ========================================================= ============================== MBR & Partition Table ================== ==================================================================== Disk: 0 (MBR Code: Windows Vista) (Size: 186 GB) (Disk ID: 7A8BA399) Partition 1: (Active) - (Size=0 byte) - (Type=00) Partition 2: (Not Active) - (Size=1 GB) - (Type=27) Partition 3: (Active) - (Size=185 GB) - (Type=07) (NTFS) ==================================================================== Disk: 2 (Size: 2 GB) (Disk ID: 00000000) Last Boot: 2013-04-18 11:50 ==================== End Of Log ============================
Hi ericaps ;)

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

start
TDL4: custom:26000022 <===== ATTENTION!
end

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
On Windows XP: Now please boot into the BartPE CD.
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Reboot and see if you can open windows normally..
yes sorry I haven't been able to reply I have been working a lot. Hopefully will be able to to do the next step you sent today.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 21-04-2013 02 Ran by [removed] at 2013-04-25 17:17:48 Run:1 Running from G:\ Boot Mode: Recovery ============================================== The operation completed successfully. The operation completed successfully. ==== End of Fixlog ==== When I restarted it came to the Start Windows normally or in safe mode prompt. I selected start normally and it went to the Microsoft loading screen and then went to a black screen and never loaded
Hi ericaps ;)

Sorry for delay.

Re-try this

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

cmd: bootrec /FixMbr
cmd: bootrec /fixboot

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
On Windows XP: Now please boot into the BartPE CD.
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Let me know if you can to run windows normally
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 21-04-2013 02 Ran by [removed] at 2013-04-28 19:36:15 Run:2 Running from G:\ Boot Mode: Recovery ============================================== ========= bootrec /FixMbr ========= ÿþT h e o p e r a t i o n c o m p l e t e d s u c c e s s f u l l y . ========= End of CMD: ========= ========= bootrec /fixboot ========= ÿþT h e o p e r a t i o n c o m p l e t e d s u c c e s s f u l l y . ========= End of CMD: ========= ==== End of Fixlog ==== When rebooting it took my password and went to the windows loading screen and after 10 minutes it still did not boot.
Hi ericaps :)

  • Download ListParts to a USB flash drive.
  • Download ListParts64 to a USB flash drive.
  • Plug the USB drive into the infected machine.

Boot your computer into Recovery Environment

  • Restart the computer and press F8 repeatedly until the Advanced Options Menu appears.
  • Select Repair your computer.
  • Select Language and click Next
  • Enter password (if necessary) and click OK, you should now see the screen below …

[external image: Posted Image]

  • Select the Command Prompt option.
  • A command window will open.
  • Type notepad then hit Enter.
  • Notepad will open.
  • Click File > Open then select Computer.
  • Note down the drive letter for your USB Drive.
  • Close Notepad.
[*]Back in the command window ….

  • Type e:\listparts.exe and hit Enter (where e: is replaced by the drive letter for your USB drive)
  • Type e:\listparts64.exe and hit Enter (where e: is replaced by the drive letter for your USB drive)
  • ListParts will start to run.
  • Press the Scan button.
  • When finished scanning it will make a log Result.txt on the flash drive.
[*]Close the command window.

[*]Post me the Result.txt log please.

When I scanned with list parts I received an Error that stated: AutoIT Error Line 3203 (File "G:\listparts.exe): Error: Expected a "=" operator in assignment statement. I hit OK and tried again and received the same error
Hi ericaps :)

Ok no problem ;)

Try this:


How to start your computer by using the Last Known Good Configuration feature

  • Start your computer.
  • When you see the "Please select the operating system to start" message, press the F8 key.
  • When the Windows Advanced Options menu appears, use the ARROW keys to select Last Known Good Configuration (your most recent settings that worked), and then press ENTER.
  • If you are running other operating systems on your computer, use the ARROW keys to select Microsoft Windows XP, and then press ENTER.

Next

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.

Please let me know if you can to restart windows in normally mode.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI