This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

1068 error for Toshiba laptop... [Solved]

87 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is about another laptop… Toshiba with Vista… *gag*…

Can not connect to internet wireless or Ethernet….

Services are turned off and will not allow me to enable or turn them on.

Windows Vista Home Basic
TOSHIBA
Satellite L355

Posting scans below….

OTL
OTL logfile created on: 5/25/2013 2:11:22 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:UsersluciDesktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 78.35% Memory free
5.94 Gb Paging File | 5.46 Gb Available in Paging File | 91.98% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 224.20 Gb Total Space | 151.30 Gb Free Space | 67.48% Space Free | Partition Type: NTFS
Drive F: | 1.91 Gb Total Space | 0.27 Gb Free Space | 14.17% Space Free | Partition Type: FAT
Unable to calculate disk information.

Computer Name: LUCI-PC | User Name: luci | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:UsersluciDesktopOTL.exe (OldTimer Tools)
PRC - C:Windowsexplorer.exe (Microsoft Corporation)
PRC - C:Program FilesToshibaTOSCDSPDTOSCDSPD.exe (TOSHIBA)


========== Modules (No Company Name) ==========

MOD - C:Program FilesCommon Filesmicrosoft sharedOFFICE14CulturesOFFICE.ODF ()
MOD - C:Program FilesMicrosoft OfficeOffice141033GrooveIntlResource.dll ()


========== Services (SafeList) ==========

SRV - (Yontoo Desktop Updater) – C:Program FilesYontooY2Desktop.Updater.exe C:UsersluciAppDataRoamingYontooYontooDesktop.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:WindowsSystem32MacromedFlashFlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:Program FilesSkypeUpdaterUpdater.exe (Skype Technologies)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:Program FilesMicrosoft OfficeOffice14GROOVE.EXE (Microsoft Corporation)
SRV - (GamesAppService) – C:Program FilesWildTangent GamesAppGamesAppService.exe (WildTangent, Inc.)
SRV - (LiveUpdate Notice) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (Symantec Core LC) – C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe ()
SRV - (LiveUpdate) – C:Program FilesSymantecLiveUpdateLuComServer_3_4.EXE (Symantec Corporation)
SRV - (TMachInfo) – C:Program FilesToshibaTOSHIBA Service StationTMachInfo.exe (TOSHIBA Corporation)
SRV - (TNaviSrv) – C:Program FilesToshibaTOSHIBA DVD PLAYERTNaviSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:Program FilesToshibaConfigFreeCFSvcs.exe (TOSHIBA CORPORATION)
SRV - (IAANTMON) – C:Program FilesIntelIntel Matrix Storage ManagerIAANTmon.exe (Intel Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:Program FilesSymantecLiveUpdateAluSchedulerSvc.exe (Symantec Corporation)
SRV - (lxbk_device) – C:WindowsSystem32lxbkcoms.exe ( )
SRV - (TosCoSrv) – C:Program FilesToshibaPower SaverTosCoSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:Program FilesWindows DefenderMpSvc.dll (Microsoft Corporation)
SRV - (TOSHIBA SMART Log Service) – C:Program FilesToshibaSMARTLogServiceTosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:WindowsSystem32TODDSrv.exe (TOSHIBA Corporation)
SRV - (comHost) – C:Program FilesCommon FilesSymantec SharedVAScannercomHost.exe (Symantec Corporation)
SRV - (UleadBurningHelper) – C:Program FilesCommon FilesUlead SystemsDVDULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32DRIVERSnwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32DRIVERSnwlnkflt.sys File not found
DRV - (NAVEX15) – C:PROGRA~2SymantecDEFINI~1VIRUSD~120100808.003NAVEX15.SYS File not found
DRV - (NAVENG) – C:PROGRA~2SymantecDEFINI~1VIRUSD~120100808.003NAVENG.SYS File not found
DRV - (IpInIp) – system32DRIVERSipinip.sys File not found
DRV - (IDSvix86) – C:ProgramDataSymantecDefinitionsSymcDataipsdefs20100804.001IDSvix86.sys (Symantec Corporation)
DRV - (SymEvent) – C:WindowsSystem32driversSYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:Program FilesCommon FilesSymantec SharedEENGINEeeCtrl.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCDrv.sys (Symantec Corporation)
DRV - (SymIM) – C:WindowsSystem32driversSymIMV.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:WindowsSystem32driverssymndisv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:WindowsSystem32driverssymtdi.sys (Symantec Corporation)
DRV - (SYMFW) – C:WindowsSystem32driverssymfw.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:WindowsSystem32driverssymredrv.sys (Symantec Corporation)
DRV - (SYMDNS) – C:WindowsSystem32driverssymdns.sys (Symantec Corporation)
DRV - (COH_Mon) – C:WindowsSystem32driversCOH_Mon.sys (Symantec Corporation)
DRV - (tos_sps32) – C:WindowsSystem32driverstos_sps32.sys (TOSHIBA Corporation)
DRV - (JL2005C) – C:WindowsSystem32driversjl2005c.sys (Windows ® 2000 DDK provider)
DRV - (RTL8169) – C:WindowsSystem32driversRtlh86.sys (Realtek Corporation )
DRV - (mr97310c) – C:WindowsSystem32driversmr97310c.sys (Mars Semiconductor Corp.)
DRV - (SRTSPL) – C:WindowsSystem32driverssrtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:WindowsSystem32driverssrtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:WindowsSystem32driverssrtspx.sys (Symantec Corporation)
DRV - (RTL8187B) – C:WindowsSystem32driversrtl8187B.sys (Realtek Semiconductor Corporation )
DRV - (tdcmdpst) – C:WindowsSystem32driverstdcmdpst.sys (TOSHIBA Corporation.)
DRV - (TVALZ) – C:WindowsSystem32driversTVALZ_O.SYS (TOSHIBA Corporation)
DRV - (CO_Mon) – C:WindowsSystem32driversCO_Mon.sys (Symantec Corporation)
DRV - (RtlProt) – C:WindowsSystem32driversRtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (FwLnk) – C:WindowsSystem32driversFwLnk.sys (TOSHIBA Corporation)
DRV - (KR10I) – C:WindowsSystem32driversKR10I.sys (TOSHIBA CORPORATION)
DRV - (KR10N) – C:WindowsSystem32driversKR10N.sys (TOSHIBA CORPORATION)
DRV - (AgereSoftModem) – C:WindowsSystem32driversAGRSM.sys (Agere Systems)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKLM..SearchScopes,DefaultScope = {7F483B27-FA32-4A99-8F1C-E6E2282EAE18}
IE - HKLM..SearchScopes{7F483B27-FA32-4A99-8F1C-E6E2282EAE18}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSHB

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Bar = http://www.google.com/ie
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Page = http://www.google.com
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.com/
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,StartPageCache = 1
IE - HKCU..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU..SearchScopes{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s;=jbR1Zar…q={searchTerms}
IE - HKCU..SearchScopes{7F483B27-FA32-4A99-8F1C-E6E2282EAE18}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7TSHB_enUS383
IE - HKCU..SearchScopes{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://mysearch.avg.com/search?cid={273E85…mp;d=2013-03-02 13:39:42&v;=14.2.0.1&pid;=safeguard&sg;=1&sap;=dsp&q;={searchTerms}
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - [removed]/npPicasa3,version=3.0.0: C:Program FilesPicasa2npPicasa3.dll (Google, Inc.)
FF - [removed]/NpCtrl,version=1.0: c:Program FilesMicrosoft Silverlight5.1.20125.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/OfficeAuthz,version=14.0: C:PROGRA~1MICROS~3Office14NPAUTHZ.DLL (Microsoft Corporation)
FF - [removed]/SharePoint,version=14.0: C:PROGRA~1MICROS~3Office14NPSPWRAP.DLL (Microsoft Corporation)
FF - [removed]/WPF,version=3.5: c:WindowsMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation)
FF - [removed]/Google Update;version=3: C:Program FilesGoogleUpdate1.3.21.145npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Program FilesGoogleUpdate1.3.21.145npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/GamesAppPresenceDetector,Version=1.0: C:Program FilesWildTangent GamesAppBrowserIntegrationRegistered11NP_wtapp.dll ()



O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:WindowsSystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Reg Error: Value error.) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesCommon FilesSymantec SharedIDSIPSBHO.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_06binssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:Program FilesMicrosoft OfficeOffice14URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:Program FilesYontooYontooIEClient.dll (Yontoo LLC)
O3 - HKLM..Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll (Symantec Corporation)
O3 - HKCU..ToolbarWebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll (Symantec Corporation)
O4 - HKCU..Run: [TOSCDSPD] C:Program FilesToshibaTOSCDSPDTOSCDSPD.exe (TOSHIBA)
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: LogonHoursAction = 2
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:WindowsSystem32GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:Program FilesMicrosoft OfficeOffice14EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_06binssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O18 - ProtocolHandlerskype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program FilesCommon FilesSkypeSkype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:PROGRA~1GoogleGOOGLE~1GOEC62~1.DLL) - C:Program FilesGoogleGoogle Desktop SearchGoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:Windowsexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:Windowssystem32userinit.exe) - C:WindowsSystem32userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:UsersPublicPicturesSample PicturesAutumn Leaves.jpg
O24 - Desktop BackupWallPaper: C:UsersPublicPicturesSample PicturesAutumn Leaves.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:autoexec.bat – [ NTFS ]
O33 - MountPoints2{d0723443-0c79-11e0-8740-001e33d8b61c}Shell - "" = AutoRun
O33 - MountPoints2{d0723443-0c79-11e0-8740-001e33d8b61c}ShellAutoRuncommand - "" = E:LaunchU3.exe -a
O33 - MountPoints2EShell - "" = AutoRun
O33 - MountPoints2EShellAutoRuncommand - "" = E:LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*
O38 - SubSystemsWindows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystemsWindows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:WindowsSystem32ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

========== Files/Folders - Created Within 30 Days ==========

[2013/05/25 02:09:53 | 000,000,000 | —D | C] – C:UsersluciAppDataRoamingTemplate
[2013/05/25 02:06:09 | 000,891,248 | —- | C] (AVG Technologies) – C:UsersluciDesktopavg_free_stb_all_9_40_cnet.exe
[2013/05/25 01:43:35 | 000,602,112 | —- | C] (OldTimer Tools) – C:UsersluciDesktopOTL.exe
[2013/05/23 19:20:07 | 000,467,464 | —- | C] (WinZip Computing) – C:UsersluciDesktopWinZipRegistryOptimizer.exe
[2013/05/23 19:02:04 | 000,000,000 | —D | C] – C:ProgramDataErrorEND
[2013/05/21 23:31:00 | 002,382,848 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mshtml.tlb
[2013/05/21 23:22:26 | 000,607,744 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeeds.dll
[2013/05/21 23:22:26 | 000,176,640 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieui.dll
[2013/05/21 23:22:26 | 000,142,848 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieUnatt.exe
[2013/05/21 23:22:26 | 000,065,024 | —- | C] (Microsoft Corporation) – C:WindowsSystem32jsproxy.dll
[2013/05/21 23:22:25 | 001,800,704 | —- | C] (Microsoft Corporation) – C:WindowsSystem32jscript9.dll
[2013/05/21 23:22:25 | 000,231,936 | —- | C] (Microsoft Corporation) – C:WindowsSystem32url.dll
[2013/05/21 23:22:24 | 001,427,968 | —- | C] (Microsoft Corporation) – C:WindowsSystem32inetcpl.cpl
[2013/05/21 10:48:55 | 000,000,000 | —D | C] – C:Windowspss
[2013/05/21 10:16:16 | 000,000,000 | —D | C] – C:UsersluciAppDataRoamingMicrosoftWindowsStart MenuProgramsPhoto2Album
[2013/05/20 22:54:48 | 000,037,376 | —- | C] (Microsoft Corporation) – C:WindowsSystem32cdd.dll
[2013/05/20 22:54:35 | 002,049,024 | —- | C] (Microsoft Corporation) – C:WindowsSystem32win32k.sys
[2013/05/20 22:15:21 | 000,000,000 | -HSD | C] – C:found.001
[2013/05/20 09:33:46 | 000,000,000 | -HSD | C] – C:found.000
[2013/05/05 18:28:24 | 000,000,000 | —D | C] – C:Program FilesCommon FilesSkype
[2011/06/11 21:40:29 | 038,147,376 | —- | C] (Apple Inc.) – C:UsersluciQuickTimeInstaller.exe
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/25 02:12:00 | 000,000,830 | —- | M] () – C:WindowstasksAdobe Flash Player Updater.job
[2013/05/25 02:09:54 | 000,000,036 | —- | M] () – C:UsersluciAppDataRoamingwklnhst.dat
[2013/05/25 02:08:10 | 000,000,886 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineUA.job
[2013/05/25 02:01:02 | 000,607,656 | —- | M] () – C:WindowsSystem32perfh009.dat
[2013/05/25 02:01:02 | 000,105,264 | —- | M] () – C:WindowsSystem32perfc009.dat
[2013/05/25 01:41:19 | 000,003,616 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/25 01:41:19 | 000,003,616 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/25 01:27:30 | 000,602,112 | —- | M] (OldTimer Tools) – C:UsersluciDesktopOTL.exe
[2013/05/25 00:44:37 | 000,000,882 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineCore.job
[2013/05/25 00:43:19 | 000,067,584 | –S- | M] () – C:Windowsbootstat.dat
[2013/05/25 00:43:08 | 3080,744,960 | -HS- | M] () – C:hiberfil.sys
[2013/05/24 17:38:59 | 000,000,680 | —- | M] () – C:UsersluciAppDataLocald3d9caps.dat
[2013/05/23 19:09:02 | 000,000,510 | —- | M] () – C:UsersluciDesktopErrorEND_Pro_Installer - Shortcut.lnk
[2013/05/21 23:41:17 | 000,405,872 | —- | M] () – C:WindowsSystem32FNTCACHE.DAT
[2013/05/21 10:17:15 | 000,000,055 | —- | M] () – C:WindowsAPOapp.INI
[2013/05/21 10:16:16 | 000,001,787 | —- | M] () – C:UsersluciDesktopPhoto2Album.lnk
[2013/05/15 10:11:09 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:WindowsSystem32FlashPlayerApp.exe
[2013/05/15 10:11:09 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:WindowsSystem32FlashPlayerCPLApp.cpl
[2013/05/05 19:20:11 | 000,001,699 | —- | M] () – C:UsersluciDesktopBackup and Restore Center.lnk
[2013/05/05 15:12:55 | 002,382,848 | —- | M] (Microsoft Corporation) – C:WindowsSystem32mshtml.tlb
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/25 02:09:52 | 000,000,036 | —- | C] () – C:UsersluciAppDataRoamingwklnhst.dat
[2013/05/24 22:58:12 | 3080,744,960 | -HS- | C] () – C:hiberfil.sys
[2013/05/23 19:09:02 | 000,000,510 | —- | C] () – C:UsersluciDesktopErrorEND_Pro_Installer - Shortcut.lnk
[2013/05/21 10:17:15 | 000,000,055 | —- | C] () – C:WindowsAPOapp.INI
[2013/05/21 10:10:22 | 000,000,680 | —- | C] () – C:UsersluciAppDataLocald3d9caps.dat
[2013/05/05 19:20:11 | 000,001,699 | —- | C] () – C:UsersluciDesktopBackup and Restore Center.lnk
[2012/11/24 13:20:10 | 000,053,248 | —- | C] () – C:WindowsSystem32CommonDL.dll
[2012/11/24 13:20:10 | 000,002,413 | —- | C] () – C:WindowsSystem32lgAxconfig.ini
[2012/05/28 19:20:06 | 000,015,164 | —- | C] () – C:Windowsmr310twc.ini
[2011/12/08 21:50:07 | 000,000,077 | —- | C] () – C:Windowsm2khd.ini
[2011/02/25 23:09:37 | 000,093,507 | —- | C] () – C:UsersluciCave Springs Church.jpg
[2010/07/28 21:46:20 | 000,013,824 | —- | C] () – C:UsersluciAppDataLocalDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/14 22:49:55 | 000,000,632 | RHS- | C] () – C:Userslucintuser.pol

========== ZeroAccess Check ==========

[2006/11/02 08:51:16 | 000,000,227 | RHS- | M] () – C:WindowsassemblyDesktop.ini

[HKEY_CURRENT_USERSoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]

[HKEY_CURRENT_USERSoftwareClassesclsid{fbeb8a05-beee-4442-804e-409d6c4515e9}InProcServer32]

[HKEY_LOCAL_MACHINESoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]
"" = %SystemRoot%system32shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINESoftwareClassesclsid{5839FCA9-774D-42A1-ACDA-D6A79037F57F}InProcServer32]
"" = %systemroot%system32wbemfastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINESoftwareClassesclsid{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}InProcServer32]
"" = %systemroot%system32wbemwbemess.dll – [2009/04/11 02:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/05/25 02:09:53 | 000,000,000 | —D | M] – C:UsersluciAppDataRoamingTemplate
[2012/11/23 00:31:20 | 000,000,000 | —D | M] – C:UsersluciAppDataRoamingWildTangent
[2013/05/20 22:47:47 | 000,000,000 | —D | M] – C:UsersluciAppDataRoamingYontoo

========== Purity Check ==========



========== Custom Scans ==========

< ILE%Desktop*.exe
%PROGRAMFILES%Common Files*.*
%systemroot%*.src
%systemroot%install*.*
%systemroot%system32DLL*.*
%systemroot%system32HelpFiles*.*
%systemroot%system32rundll*.*
%systemroot%winn32*.*
%systemroot%Java*.*
%systemroot%system32test*.*
%systemroot%system32Rundll32*.*
%systemroot%AppPatchCustom*.*
HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >


< >
[2006/11/02 08:58:10 | 000,000,006 | -H– | C] () – C:WindowsTasksSA.DAT
[2006/11/02 08:58:10 | 000,032,644 | —- | C] () – C:WindowsTasksSCHEDLGU.TXT
[2010/06/13 19:14:43 | 000,000,882 | —- | C] () – C:WindowsTasksGoogleUpdateTaskMachineCore.job
[2010/06/13 19:14:44 | 000,000,886 | —- | C] () – C:WindowsTasksGoogleUpdateTaskMachineUA.job
[2012/07/22 08:39:03 | 000,000,830 | —- | C] () – C:WindowsTasksAdobe Flash Player Updater.job

< End of report >


OTL extras


OTL Extras logfile created on: 5/25/2013 2:11:22 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:UsersluciDesktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 78.35% Memory free
5.94 Gb Paging File | 5.46 Gb Available in Paging File | 91.98% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 224.20 Gb Total Space | 151.30 Gb Free Space | 67.48% Space Free | Partition Type: NTFS
Drive F: | 1.91 Gb Total Space | 0.27 Gb Free Space | 14.17% Space Free | Partition Type: FAT
Unable to calculate disk information.

Computer Name: LUCI-PC | User Name: luci | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – C:WindowsSystem32control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:Windowswinhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%System32control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"cval" = 1

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyPublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyFirewallRules]
"{10392ACF-F158-4879-A242-6D25BAC2687C}" = lport=139 | protocol=6 | dir=in | app=system |
"{56E6B9F5-767D-4CCB-9880-C280DF657DB4}" = lport=138 | protocol=17 | dir=in | app=system |
"{72C38984-E1CB-44CE-A5FB-B2018521B1AC}" = rport=139 | protocol=6 | dir=out | app=system |
"{79FEE032-F010-4759-B909-F31D3582B42D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%system32spoolsv.exe |
"{9D33E8DC-C901-4666-9513-AD55F2F8F171}" = lport=6004 | protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14outlook.exe |
"{B66D41CB-6CE6-490A-9004-C53F784FA518}" = rport=138 | protocol=17 | dir=out | app=system |
"{C45C7C25-D6DC-49E4-B7BE-90672335E135}" = rport=137 | protocol=17 | dir=out | app=system |
"{CCA77738-F3B4-4CD1-B507-D897CEFA543E}" = rport=445 | protocol=6 | dir=out | app=system |
"{D345B308-F4F8-458E-BF0D-D8E61B08FCBD}" = lport=137 | protocol=17 | dir=in | app=system |
"{F7B37365-82C8-41F9-8A43-877253BF95DE}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FA13C5FE-4F76-42FD-B50A-1C62F1E24036}" = lport=445 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyFirewallRules]
"{05F7C0F3-2A98-4E47-B391-58C2DE6DDF0F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{09743A40-150F-4C30-B830-6332543D6BE1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{13CA4BFA-2D7B-4338-AFF4-95519C19264B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{15DE6A25-120E-4BCC-A45C-8293894E77C8}" = protocol=6 | dir=in | app=c:program filesmicrosoft officeoffice14onenote.exe |
"{2A2EC24C-8289-4E89-A83C-3F4E889E970D}" = protocol=17 | dir=in | app=c:windowssystem32lxbkcoms.exe |
"{3D7B1895-C945-4762-8D29-D3A89EE0A49C}" = protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14onenote.exe |
"{5CAEB0D3-D875-4CA7-B710-9EC5BF86619D}" = protocol=6 | dir=in | app=c:program filesmicrosoft officeoffice14groove.exe |
"{6A0FDE05-7646-48CD-BE67-6FEC99965558}" = dir=in | app=c:program filesskypephoneskype.exe |
"{A38ECFC6-1DFB-4D13-9E6B-E59033258ABD}" = protocol=6 | dir=in | app=c:windowssystem32lxbkcoms.exe |
"{B8BBEA03-EE71-4648-9E98-B3BF06ED313D}" = protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14groove.exe |
"{F395AC62-872E-4F51-ABB3-E7B5015CE4C1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{02CA24DD-C8B0-4280-BE53-7862869C2EB1}" = Realtek WiFi Protected Setup Library
"{0BDD3FAD-61CD-4BF3-B9C4-4CEFD43F53F8}" = Norton 360 HTMLHelp
"{0D5D0BEE-FBA9-4928-A50D-6CDFAB827755}" = TOSHIBA ConfigFree
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{21829177-4DED-4209-AD08-490B3AC9C01A}" = Norton 360
"{224821ED-CADA-4A8A-AC8D-3734CC0F0931}" = Amazon Links
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24DF7221-644B-4C3A-A478-459502D40522}" = Backup
"{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup
"{2D617065-1C52-4240-B5BC-C0AE12157777}" = Norton 360
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{45690715-80A6-4445-B61D-ADEC5888E8CD}" = Symantec Technical Support Controls
"{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{55A6283C-638A-4EE0-B491-51118554BDA2}" = Norton Confidential Core
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba" = WildTangent Games App (Toshiba Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 2.04
"{890EF3F8-742F-46BD-9E8E-084B3A1F4364}" = QuickBooks Financial Center
"{895722FE-25FE-4854-95AC-B0C42F9DBEDA}" = REALTEK RTL8187B Wireless LAN Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1B3874F-3057-11D6-B2EA-0050BA18806B}" = Camera Driver
"{D6E6FA4A-5445-4850-8365-CF216C1CBB7A}" = Symantec Real Time Storage Protection Component
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E1E56B8A-1AAF-422A-91DB-625059FB9863}" = TOSHIBA Desktop Links
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4FB5DCD-0681-4B6C-AF2E-121A2DA746EE}" = SymNet
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Digital Binoculars_is1" = Uninstall Digital Binoculars Driver
"Google Desktop" = Google Desktop
"HDMI" = Intel® Graphics Media Accelerator Driver
"Home Improvement 1-2-3" = Home Improvement 1-2-3
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Picasa 3" = Picasa 3
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"QuickTime" = QuickTime
"SymSetup.{2D617065-1C52-4240-B5BC-C0AE12157777}" = Norton 360 (Symantec Corporation)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WildTangent toshiba Master Uninstall" = WildTangent Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 3/10/2011 10:17:30 AM | Computer Name = luci-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 5/25/2013 1:33:01 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/25/2013 1:33:01 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/25/2013 2:08:00 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/25/2013 2:08:00 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/25/2013 2:08:05 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/25/2013 2:08:10 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/25/2013 2:08:10 AM | Computer Name = luci-PC | Source = Service Control Manager | ID = 7001
Description =


< End of report >

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:58:43 PM, on 5/25/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16483)
Boot mode: Normal

Running processes:
C:Windowssystem32taskeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesToshibaTOSCDSPDTOSCDSPD.exe
C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
C:UsersluciDesktopHiJackThis.exe

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:PROGRA~1COMMON~1SYMANT~1IDSIPSBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~1MICROS~3Office14GROOVEEX.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_06binssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:PROGRA~1MICROS~3Office14URLREDIR.DLL
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:Program FilesYontooYontooIEClient.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser2.6CoIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKCU..Run: [TOSCDSPD] C:Program FilesTOSHIBATOSCDSPDTOSCDSPD.exe
O4 - HKCU..Run: [swg] "C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe"
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:Windowssystem32GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:PROGRA~1MICROS~3Office14EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:PROGRA~1MICROS~3Office14ONBttnIE.dll/105
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_06binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_06binssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:Program FilesCommon FilesMicrosoft SharedOFFICE14MSOXMLMF.DLL
O20 - AppInit_DLLs: C:PROGRA~1GoogleGOOGLE~1GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:Windowssystem32browseui.dll

–
End of file - 4318 bytes
Hi ptaerehsahh,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 & 8 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"

=========================

Without Internet access you will need to download the tools I request onto a flash drive and transfer them to the desktop of the Toshiba laptop.

=========================

1. MiniToolBox

Please download MiniToolBox, save it to your desktop and run it.

Right click and select "Run as Administrator".

Check-mark the following check-boxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.

=========================

2. aswMBR

Download aswMBR.exe and save it to your desktop.

Right click and select "Run as Administrator".
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=========================

In your next post please provide the following:
  • Result.txt
  • aswMBR.txt
  • attach MBR.zip
Thanks for the reply OCD….. Hope I do not aggravate you too much. I'm not a computer wiz….. Pta….. MiniToolBox by Farbar Version:21-04-2013 Ran by [removed] (administrator) on 28-05-2013 at 04:32:41 Running from "F:\" Windows Vista ™ Home Basic Service Pack 2 (X86) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Could not flush the DNS Resolver Cache: Function failed during execution. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= Hosts content: ================================= ::1 localhost 127.0.0.1 localhost ========================= IP Configuration: ================================ # ———————————- # IPv4 Configuration # ———————————- pushd interface ipv4 reset set global icmpredirects=enabled popd # End of IPv4 configuration Windows IP Configuration Host Name . . . . . . . . . . . . : luci-PC Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No System Quarantine State . . . . . : Not Restricted Ethernet adapter Local Area Connection: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0) Physical Address. . . . . . . . . : 00-1E-33-D8-B6-1C DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Tunnel adapter Local Area Connection* 6: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : isatap.{0913D5A8-EAAD-4D04-821E-DF2C6404AAB0} Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Local Area Connection* 7: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 02-00-54-55-4E-01 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Local Area Connection* 12: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : isatap.{E7D4742D-1078-4833-B552-F1964685144D} Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Server: UnKnown Address: 127.0.0.1 Ping request could not find host google.com. Please check the name and try again. Server: UnKnown Address: 127.0.0.1 Ping request could not find host yahoo.com. Please check the name and try again. Unable to contact IP driver, error code 1753, =========================================================================== Interface List 10 …00 1e 33 d8 b6 1c …… Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0) 1 ……………………… Software Loopback Interface 1 12 …00 00 00 00 00 00 00 e0 isatap.{0913D5A8-EAAD-4D04-821E-DF2C6404AAB0} 13 …02 00 54 55 4e 01 …… Teredo Tunneling Pseudo-Interface 15 …00 00 00 00 00 00 00 e0 isatap.{E7D4742D-1078-4833-B552-F1964685144D} =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 =========================================================================== Persistent Routes: None IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 1 306 ::1/128 On-link 1 306 ff00::/8 On-link =========================================================================== Persistent Routes: None ========================= Winsock entries ===================================== Catalog5 01 C:\Windows\system32\NLAapi.dll [48128] (Microsoft Corporation) Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Microsoft Corporation) Catalog5 03 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Catalog5 04 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Catalog5 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog5 06 C:\Windows\system32\winrnr.dll [19968] (Microsoft Corporation) Catalog9 01 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 02 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 03 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 04 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 06 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 07 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 08 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 09 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 10 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 11 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 12 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 13 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 14 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 15 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 16 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 17 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 18 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 19 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 20 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 21 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 22 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 23 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Catalog9 24 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) ========================= Event log errors: =============================== Application errors: ================== Error: (05/28/2013 04:29:20 AM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp4580070422 Error: (05/28/2013 04:29:15 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/28/2013 04:29:12 AM) (Source: VSS) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206. Operation: Subscribing Writer Context: Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Writer Name: WMI Writer Writer Instance ID: {d5324549-f256-4164-9050-12ad499ef819} Error: (05/28/2013 04:29:12 AM) (Source: VSS) (User: ) Description: Volume Shadow Copy Service error: The EventSystem service is disabled or is attempting to start during Safe Mode. The Volume Shadow Copy service cannot start while in safe mode. If not in safe mode, make sure that EventSystem service is enabled. CLSID:{4e14fba2-2e22-11d1-9964-00c04fbbb345} Name:CEventSystem [0x80040206] Operation: Subscribing Writer Context: Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Writer Name: WMI Writer Writer Instance ID: {d5324549-f256-4164-9050-12ad499ef819} Error: (05/28/2013 04:29:12 AM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp4580070422 Error: (05/28/2013 04:28:19 AM) (Source: VSS) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206. Operation: Subscribing Writer Context: Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2} Writer Name: MSSearch Service Writer Writer Instance ID: {c83a367e-c219-4831-9b4f-f4ee3e5045e4} Error: (05/28/2013 04:28:19 AM) (Source: VSS) (User: ) Description: Volume Shadow Copy Service error: The EventSystem service is disabled or is attempting to start during Safe Mode. The Volume Shadow Copy service cannot start while in safe mode. If not in safe mode, make sure that EventSystem service is enabled. CLSID:{4e14fba2-2e22-11d1-9964-00c04fbbb345} Name:CEventSystem [0x80040206] Operation: Subscribing Writer Context: Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2} Writer Name: MSSearch Service Writer Writer Instance ID: {c83a367e-c219-4831-9b4f-f4ee3e5045e4} Error: (05/28/2013 04:28:19 AM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp4580070422 Error: (05/28/2013 04:28:13 AM) (Source: VSS) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206. Operation: Subscribing Writer Context: Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {a9bd332f-1944-4b20-b729-5705b187b65a} Error: (05/28/2013 04:28:13 AM) (Source: VSS) (User: ) Description: Volume Shadow Copy Service error: The EventSystem service is disabled or is attempting to start during Safe Mode. The Volume Shadow Copy service cannot start while in safe mode. If not in safe mode, make sure that EventSystem service is enabled. CLSID:{4e14fba2-2e22-11d1-9964-00c04fbbb345} Name:CEventSystem [0x80040206] Operation: Subscribing Writer Context: Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {a9bd332f-1944-4b20-b729-5705b187b65a} System errors: ============= Error: (05/28/2013 04:29:53 AM) (Source: Service Control Manager) (User: ) Description: Network List ServiceNetwork Location Awareness%%1068 Error: (05/28/2013 04:29:53 AM) (Source: Service Control Manager) (User: ) Description: Network Location AwarenessNetwork Store Interface Service%%1058 Error: (05/28/2013 04:29:53 AM) (Source: Service Control Manager) (User: ) Description: Network List ServiceNetwork Location Awareness%%1068 Error: (05/28/2013 04:29:53 AM) (Source: Service Control Manager) (User: ) Description: Network Location AwarenessNetwork Store Interface Service%%1058 Error: (05/28/2013 04:29:21 AM) (Source: Service Control Manager) (User: ) Description: Remote Access Connection ManagerTelephony%%1058 Error: (05/28/2013 04:29:21 AM) (Source: Service Control Manager) (User: ) Description: Remote Access Connection ManagerTelephony%%1058 Error: (05/28/2013 04:29:20 AM) (Source: Service Control Manager) (User: ) Description: Network List ServiceNetwork Location Awareness%%1068 Error: (05/28/2013 04:29:20 AM) (Source: Service Control Manager) (User: ) Description: Network Location AwarenessNetwork Store Interface Service%%1058 Error: (05/28/2013 04:29:20 AM) (Source: Service Control Manager) (User: ) Description: Network List ServiceNetwork Location Awareness%%1068 Error: (05/28/2013 04:29:20 AM) (Source: Service Control Manager) (User: ) Description: Network Location AwarenessNetwork Store Interface Service%%1058 Microsoft Office Sessions: ========================= Error: (05/28/2013 04:29:20 AM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp4580070422 Error: (05/28/2013 04:29:15 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/28/2013 04:29:12 AM) (Source: VSS)(User: ) Description: CoCreateInstance0x80040206 Operation: Subscribing Writer Context: Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Writer Name: WMI Writer Writer Instance ID: {d5324549-f256-4164-9050-12ad499ef819} Error: (05/28/2013 04:29:12 AM) (Source: VSS)(User: ) Description: {4e14fba2-2e22-11d1-9964-00c04fbbb345}CEventSystem0x80040206 Operation: Subscribing Writer Context: Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Writer Name: WMI Writer Writer Instance ID: {d5324549-f256-4164-9050-12ad499ef819} Error: (05/28/2013 04:29:12 AM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp4580070422 Error: (05/28/2013 04:28:19 AM) (Source: VSS)(User: ) Description: CoCreateInstance0x80040206 Operation: Subscribing Writer Context: Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2} Writer Name: MSSearch Service Writer Writer Instance ID: {c83a367e-c219-4831-9b4f-f4ee3e5045e4} Error: (05/28/2013 04:28:19 AM) (Source: VSS)(User: ) Description: {4e14fba2-2e22-11d1-9964-00c04fbbb345}CEventSystem0x80040206 Operation: Subscribing Writer Context: Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2} Writer Name: MSSearch Service Writer Writer Instance ID: {c83a367e-c219-4831-9b4f-f4ee3e5045e4} Error: (05/28/2013 04:28:19 AM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp4580070422 Error: (05/28/2013 04:28:13 AM) (Source: VSS)(User: ) Description: CoCreateInstance0x80040206 Operation: Subscribing Writer Context: Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {a9bd332f-1944-4b20-b729-5705b187b65a} Error: (05/28/2013 04:28:13 AM) (Source: VSS)(User: ) Description: {4e14fba2-2e22-11d1-9964-00c04fbbb345}CEventSystem0x80040206 Operation: Subscribing Writer Context: Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {a9bd332f-1944-4b20-b729-5705b187b65a} CodeIntegrity Errors: =================================== Date: 2012-01-13 21:03:23.770 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2012-01-13 21:03:23.489 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2012-01-13 21:03:23.333 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2012-01-13 21:03:23.161 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2012-01-13 21:03:23.021 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2011-08-16 23:30:58.254 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2011-08-16 23:30:58.098 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2011-08-16 23:30:57.895 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2011-08-16 23:30:57.724 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system. Date: 2011-08-16 23:30:57.521 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system. =========================== Installed Programs ============================ Acrobat.com (Version: 0.0.0) Acrobat.com (Version: 1.1.377) Adobe AIR (Version: 1.0.4990) Adobe AIR (Version: 1.0.8.4990) Adobe Flash Player 11 ActiveX (Version: 11.7.700.202) Adobe Reader 9 (Version: 9.0.0) Amazon Links (Version: 1.0) AppCore (Version: 2.0.0.79) Backup (Version: 1.0.0.382) Camera Driver ccCommon (Version: 107.0.5.5) CD/DVD Drive Acoustic Silencer (Version: 2.02.03) Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition DVD MovieFactory for TOSHIBA (Version: 5.51) GearDrvs (Version: 5.0.0.2) Google Desktop (Version: 5.9.1005.12335) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Toolbar for Internet Explorer (Version: 7.4.3607.2246) Google Update Helper (Version: 1.3.21.145) Home Improvement 1-2-3 Intel® Graphics Media Accelerator Driver Intel® Matrix Storage Manager Java™ 6 Update 6 (Version: 1.6.0.60) LiveUpdate (Symantec Corporation) (Version: 3.4.1.234) LiveUpdate (Symantec Corporation) (Version: 3.4.1.238) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Groove MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office InfoPath MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6612.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Suite Activation Assistant (Version: 2.9) Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Works (Version: 9.7.0621) Microsoft XML Parser (Version: 8.20.8730.4) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Norton 360 (Symantec Corporation) (Version: 2.0.0.242) Norton 360 (Version: 2.0.0.242) Norton 360 HTMLHelp (Version: 2.0.0.175) Norton Confidential Core (Version: 2.6.0.3) Picasa 3 (Version: 3.8) QuickBooks Financial Center (Version: 1.10.0000) QuickTime Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000) Realtek High Definition Audio Driver (Version: 6.0.1.5599) REALTEK RTL8187B Wireless LAN Driver (Version: Package:1.00.0026 Driver:6.1116.1226.2007) Realtek USB 2.0 Card Reader (Version: 6.0.6000.20130) Realtek WiFi Protected Setup Library (Version: Package:1.00.0026) Skype™ 6.3 (Version: 6.3.105) SPBBC 32bit (Version: 4.1.0.15) Symantec Real Time Storage Protection Component (Version: 10.2.3.9) Symantec Technical Support Controls (Version: 3.5.3) SymNet (Version: 8.0.3.4) Synaptics Pointing Device Driver (Version: 10.1.8.0) TOSHIBA Assist (Version: 2.01.08) TOSHIBA ConfigFree (Version: 7.2.20) TOSHIBA Desktop Links (Version: 1.7) TOSHIBA Disc Creator (Version: 2.0.1.3) TOSHIBA DVD PLAYER (Version: 1.31.14) TOSHIBA Extended Tiles for Windows Mobility Center (Version: 1.01.00) TOSHIBA Hardware Setup (Version: 2.00.08) TOSHIBA Recovery Disc Creator (Version: 2.0.0.2) Toshiba Registration (Version: 1.00.0000) TOSHIBA Service Station (Version: 1.1.14) TOSHIBA Speech System Applications TOSHIBA Speech System SR Engine(U.S.) Version1.0 TOSHIBA Speech System TTS Engine(U.S.) Version1.0 TOSHIBA Supervisor Password (Version: 2.00.04) TOSHIBA Value Added Package (Version: 1.1.24) Uninstall Digital Binoculars Driver Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition Update Installer for WildTangent Games App WildTangent Games (Version: 1.0.0.62) WildTangent Games App (Toshiba Games) (Version: 4.0.10.5) Windows Media Encoder 9 Series Windows Media Encoder 9 Series (Version: 9.00.3374) Yontoo 2.04 (Version: 2.04) ========================= Memory info: =================================== Percentage of memory in use: 25% Total physical RAM: 2939.26 MB Available physical RAM: 2200.48 MB Total Pagefile: 6084.8 MB Available Pagefile: 5473.57 MB Total Virtual: 2047.88 MB Available Virtual: 1952.7 MB ========================= Partitions: ===================================== 1 Drive c: (SQ004981V02) (Fixed) (Total:224.2 GB) (Free:151.21 GB) NTFS 3 Drive f: () (Removable) (Total:1.91 GB) (Free:0.69 GB) FAT ========================= Users: ======================================== User accounts for \\ Administrator Guest Jim luci ========================= Minidump Files ================================== C:\Windows\Minidump\Mini010111-01.dmp **** End of log **** aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-05-28 04:33:37 —————————– 04:33:37.442 OS Version: Windows 6.0.6002 Service Pack 2 04:33:37.442 Number of processors: 1 586 0x170A 04:33:37.442 ComputerName: LUCI-PC UserName: luci 04:33:38.098 Initialize success 04:33:46.724 AVAST engine download error: 0 04:34:06.786 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 04:34:06.802 Disk 0 Vendor: TOSHIBA_ FG00 Size: 238475MB BusType: 3 04:34:06.895 Disk 0 MBR read successfully 04:34:06.895 Disk 0 MBR scan 04:34:06.895 Disk 0 Windows VISTA default MBR code 04:34:06.911 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048 04:34:06.926 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 229585 MB offset 3074048 04:34:06.958 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 7389 MB offset 473264128 04:34:06.989 Disk 0 scanning sectors +488396800 04:34:07.160 Disk 0 scanning C:\Windows\system32\drivers 04:34:16.162 Service scanning 04:34:48.750 Modules scanning 04:35:04.506 Disk 0 trace - called modules: 04:35:04.537 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 04:35:04.537 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85ea77b8] 04:35:04.537 3 CLASSPNP.SYS[8a30b8b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8540d028] 04:35:04.553 Scan finished successfully 04:35:28.327 Disk 0 MBR has been saved successfully to "F:\MBR.dat" 04:35:28.358 The log file has been saved successfully to "F:\aswMBR.txt"

Attachments:

Hi ptaerehsahh,

Thanks for the reply OCD…..
Hope I do not aggravate you too much.
I'm not a computer wiz…..

You're welcome, and I'm sure you will do just fine. If you have any questions about a step, just ask. :thumbup:

Reminder, the tools I request for you to run need to be on the desktop of the problem computer. If you download them to a flash drive, they will need to be transferred to the desktop prior to running for them to work properly and to get accurate results.

1. Msconfig
  • Go to the Start [external image: Posted Image] button >> in the dialog box in the lower left hand corner type "msconfig" (without the quotes)
  • Locate msconfig in the left hand window >> right click and select "Run as Administrator"
  • On the General tab, ensure the Startup selection is set to Normal startup
  • Click Apply >> allow the system to reboot at this time
Check and see if you can now connect to the internet

=========================
I am so sorry. I ran them from the flash drive… Do I need to run them again? from the desktop… I went ahead and did the msconfig thing without even thinking about it like a dummy….. Normal startup will not let me do anything. I don't know if too many things are trying to load or what. but I can't even shut it down… It's been like this for over 30 minutes….. :pullhair:
Hi ptaerehsahh,

1. Chkdsk in Vista/7

You must run the command prompt as an administrator or in an "elevated mode".
  • Start menu, in the search bar type "cmd"
  • Right-click the cmd icon, select "run as administrator"
    • If you have user account control (UAC) set up it may prompt you to accept that action.
  • Then type in "chkdsk /r" (make note of the space between chkdsk and /)
=========================

2. Device Manager
  • Go to the Control Panel >> Device Manager >> expand Network Adapters
  • Any error symbols displayed?
  • If so write down what they are and post the information in your next reply.
=========================

In your next post please provide the following:
  • Results of chkdsk
  • Device Manager information
  • What was the Start-up menu set to in msconfig?
Yes I ran it in admin mode. but now it will not let me do anything what so ever. not even the start button…. nor the windows button will work… computer is up to desktop. when I go to bottom where toolbar is the arrow turns into a <—-> something like that… It will turn off holding the power button down…. but again when it cums up it will not let me do anything…. sorry I'm so difficult…..
Hi ptaerehsahh,

1. Reboot in Safe Mode using the F8 Method:
  • Restart your computer.
  • When the computer starts you will see your computer's hardware being listed. When you see this information start to gently tap the F8 key repeatedly until you are presented with the Windows 7 Advanced Boot Options.
  • Select the Safe Mode with Networking option using the arrow keys.
  • Then press the enter key on your keyboard to boot into Windows 7 Safe Mode.
  • When Windows starts you will be at a typical logon screen. Logon to your computer and Windows 7 will enter Safe mode.
=========================

1. System File Checker (SFC)
  • Click on the Start button and in the Search programs and files box type the following:
    • command
  • Don't press Enter, just let the search results populate above.
  • In the search results, locate the Programs section.
  • Locate the Command Prompt shortcut and right-click on it.
  • Select Run as administrator.
  • Click Yes on the User Account Control window that appears.
  • Important: If you are see a User Account Control window but also a message that says To continue, type an administrator password, and then click Yes, then your user account must be a standard account, not an administrator account. Before you can click Yes and open an elevated command prompt, you'll need to type the password of another user on your Windows 7 computer that has administrator level privileges.
  • Note: You will not see this window at all if your User Account Control settings are turned all the way down. See How To Disable User Account Control in Windows 7 for more information.
  • An elevated Command Prompt window will appear.

    • Type: sfc /scannow (There's a space between sfc and /scannow.)
  • Type: exit to close the command prompt window
  • Include the findings in your next reply
=========================

  • What type of Internet connection do you have?
  • Do you use a Router to connect to the Internet?
  • Is this the only computer that is having trouble connecting to the Internet?

In your next post please provide the following:
  • Can you access the Internet in Safe Mode
  • Results from System File Checker
Hi ya…… :P This has been one of the hardest steps… Took forever and a day it seems to get the laptop to finally boot in safe mode….. Then when I tried to post the report here it was to big….. So I am now wondering if I did it right…… I had to compress the file… so it is attached instead of posted. I'm sorry…. :(

Attachments:

Hi ptaerehsahh,
  • What type of Internet connection do you have?
  • Do you use a Router to connect to the Internet?
  • Is this the only computer that is having trouble connecting to the Internet?
  • Going back to the msconfig step. What was the Start-up setting set to?
  • Can you boot in Normal Mode?
  • Do you have the Windows Vista CD/DVD?
hm….. Lets see… Linksy's I think is the name of it…. wireless…. All computers here are online except for this one…. It is my moms and that is why she gave it to me because it just stopped all the sudden connecting to her router and came up that she could not turn any security on. Do not have CD's…. Yes I am in normal startup now….. :) pretty sure I ran msconfig in normal mode… but not 100%….
I am pretty sure she has always had it. though not activated.. I begged her to use AVG…. but she would have nothing of it…
Hi ptaerehsahh,

I am pretty sure she has always had it. though not activated.. I begged her to use AVG…. but she would have nothing of it…

What do you mean by not activated? Did she always have it installed but just didn't have it running?
Hi ptaerehsahh,

Print out these instructions as we may need to close every window that is open later in the fix.

You will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.

These tools must be run from the Desktop.

1. RogueKiller

Download to your desktop RogueKiller (by tigzy)

Right click and select "Run as Administrator"
  • Quit all programs
  • Wait until Prescan has finished …
  • Click on Scan, Do Not Fix Anything at this point.
  • Click the Report button, save the report to your desktop
=========================

2. ComboFix

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.
    ———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

=========================

In your next post please provide the following:
  • RKreport[1].txt
  • Combofix.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI