This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

1068 error for Toshiba laptop... [Solved]

87 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi ptaerehsahh,

=========================

You will need a functioning computer and a flash drive to complete this initial download step. Please read the instructions all the way through or print them out before proceeding.

=========================

1. Farbar Recovery Scan Tool

Download Farbar Recovery Scan Tool 32-Bit or Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt


[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

In your next post please provide the following:
  • FRST.txt
I sure hope I did this correctly for you…… :)
The only thing I wasn't sure of. and I should have posted here first is what to do after all that was done…. I didn't feel comfortable…. taking the flash drive out without ejecting it. So I restarted the computer….. I forgot to start in safe mode… so it again has froze up. but here is the log…

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-06-2013
Ran by [removed] on 31-05-2013 23:54:39
Running from F:\
Windows Vista ™ Home Basic Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log.

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [RtHDVCpl] RtHDVCpl.exe [x]
HKLM\…\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-04-15] (Intel Corporation)
HKLM\…\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.)
HKLM\…\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [431456 2008-02-06] (TOSHIBA Corporation)
HKLM\…\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [505720 2008-06-02] (TOSHIBA Corporation)
HKLM\…\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [716800 2008-05-09] (TOSHIBA Corporation)
HKLM\…\Run: [NDSTray.exe] NDSTray.exe [x]
HKLM\…\Run: [cfFncEnabler.exe] cfFncEnabler.exe [x]
HKLM\…\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup [30192 2010-07-04] (Google)
HKLM\…\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [51048 2008-10-17] (Symantec Corporation)
HKLM\…\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe" [988512 2008-02-25] (Symantec Corporation)
HKLM\…\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM\…\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [x]
HKLM\…\Run: [Skytel] Skytel.exe [x]
HKLM\…\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [404568 2012-03-27] (LG Electronics)
HKLM\…\Run: [vProt] "C:\Program Files\AVG SafeGuard toolbar\vprot.exe" [1151152 2013-03-02] ()
HKU\Default\…\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2008-04-24] (TOSHIBA)
HKU\Default User\…\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2008-04-24] (TOSHIBA)
HKU\Guest\…\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2008-04-24] (TOSHIBA)
HKU\Guest\…\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\Guest\…\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe -update activex [x]
HKU\Jim\…\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2008-04-24] (TOSHIBA)
HKU\Jim\…\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [ 2008-01-20] (Microsoft Corporation)
HKU\Jim\…\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\Jim\…\Policies\system: [LogonHoursAction] 2
HKU\Jim\…\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\luci\…\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [ 2008-04-24] (TOSHIBA)
HKU\luci\…\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" [x]
HKU\luci\…\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [ 2013-01-08] (Skype Technologies S.A.)
HKU\luci\…\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
HKU\luci\…\Policies\system: [LogonHoursAction] 2
HKU\luci\…\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft SharePoint Workspace.lnk
ShortcutTarget: Microsoft SharePoint Workspace.lnk -> C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
Startup: C:\Users\luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

========================== Services (Whitelisted) =================

S2 Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe [238968 2008-02-21] (Symantec Corporation)
S2 ccEvtMgr; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [149352 2008-10-17] (Symantec Corporation)
S2 ccSetMgr; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [149352 2008-10-17] (Symantec Corporation)
S2 CLTNetCnService; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [149352 2008-10-17] (Symantec Corporation)
S3 comHost; C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [55640 2007-08-21] (Symantec Corporation)
S2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2008-04-16] (TOSHIBA CORPORATION)
S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-07-04] (Google)
S3 LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE [3220856 2008-09-05] (Symantec Corporation)
S2 LiveUpdate Notice; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [149352 2008-10-17] (Symantec Corporation)
S2 lxbk_device; C:\Windows\system32\lxbkcoms.exe [537256 2008-02-19] ( )
S3 Symantec Core LC; C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe [1245064 2008-09-30] ()
S2 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [46392 2008-08-04] (TOSHIBA Corporation)
S2 TOSHIBA SMART Log Service; C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [126976 2007-12-03] (TOSHIBA Corporation)
S2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.)
S2 vToolbarUpdater14.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe [968880 2013-03-02] ()
S2 Yontoo Desktop Updater; C:\Users\luci\AppData\Roaming\Yontoo\YontooDesktop.exe [42784 2013-02-15] (Yontoo LLC)

==================== Drivers (Whitelisted) ====================

S1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [33112 2013-03-02] (AVG Technologies)
S3 COH_Mon; C:\Windows\system32\Drivers\COH_Mon.sys [23888 2008-07-30] (Symantec Corporation)
S2 CO_Mon; C:\Windows\system32\drivers\CO_Mon.sys [36056 2007-08-08] (Symantec Corporation)
S1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [371248 2010-06-10] (Symantec Corporation)
S1 IDSvix86; C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20100804.001\IDSvix86.sys [281648 2010-06-23] (Symantec Corporation)
S3 JL2005C; C:\Windows\System32\Drivers\jl2005c.sys [68730 2008-07-15] (Windows ® 2000 DDK provider)
S3 mr97310c; C:\Windows\System32\DRIVERS\mr97310c.sys [116992 2008-03-27] (Mars Semiconductor Corp.)
S3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [290304 2007-12-26] (Realtek Semiconductor Corporation )
S1 RtlProt; C:\Windows\System32\DRIVERS\rtlprot.sys [25896 2007-04-23] (Windows ® Codename Longhorn DDK provider)
S1 SPBBCDrv; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [447024 2009-03-17] (Symantec Corporation)
S3 SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [279088 2008-01-31] (Symantec Corporation)
S3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [317616 2008-01-31] (Symantec Corporation)
S1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [43696 2008-01-31] (Symantec Corporation)
S3 SYMDNS; C:\Windows\System32\Drivers\SYMDNS.SYS [13616 2009-02-19] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [124464 2010-06-18] (Symantec Corporation)
S3 SYMFW; C:\Windows\System32\Drivers\SYMFW.SYS [96560 2009-02-19] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [24112 2009-02-19] (Symantec Corporation)
S3 SYMNDISV; C:\Windows\System32\Drivers\SYMNDISV.SYS [41008 2009-02-19] (Symantec Corporation)
S3 SYMREDRV; C:\Windows\System32\Drivers\SYMREDRV.SYS [22320 2009-02-19] (Symantec Corporation)
S1 SYMTDI; C:\Windows\System32\Drivers\SYMTDI.SYS [184496 2009-02-19] (Symantec Corporation)
S3 catchme; \??\C:\Users\luci\AppData\Local\Temp\catchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NAVENG; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20100808.003\NAVENG.SYS [x]
S3 NAVEX15; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20100808.003\NAVEX15.SYS [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-05-31 23:54 - 2013-05-31 23:54 - 00000000 ____D C:\FRST
2013-05-31 08:31 - 2013-05-31 08:31 - 00007801 ____A C:\ComboFix.txt
2013-05-31 08:20 - 2013-05-31 08:30 - 00000000 ____D C:\Windows\erdnt
2013-05-31 08:20 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2013-05-31 08:20 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2013-05-31 08:20 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-05-31 08:20 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-05-31 08:20 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-05-31 08:20 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2013-05-31 08:20 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2013-05-31 08:20 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2013-05-31 08:17 - 2013-05-31 08:17 - 00000163 ____A C:\Users\luci\Desktop\1.txt
2013-05-31 08:03 - 2013-05-31 08:01 - 02218636 ____A C:\Users\luci\Desktop\tdsskiller.zip
2013-05-31 08:03 - 2013-05-31 07:59 - 00011776 ____A C:\Users\luci\Desktop\pastefile.wps
2013-05-31 07:57 - 2013-05-31 07:57 - 00001864 ____A C:\Users\luci\Desktop\RKreport[2]_D_05312013_02d1157.txt
2013-05-31 07:51 - 2013-05-31 07:51 - 00001962 ____A C:\Users\luci\Desktop\RKreport[1]_S_05312013_02d1151.txt
2013-05-30 23:35 - 2013-05-29 09:11 - 05073804 ____R (Swearware) C:\Users\luci\Desktop\ComboFix.exe
2013-05-30 23:35 - 2013-05-29 09:11 - 00816128 ____A C:\Users\luci\Desktop\RogueKiller.exe
2013-05-29 19:59 - 2013-05-30 21:47 - 00000000 ____D C:\Users\luci\AppData\Local\Temp(145)
2013-05-29 19:59 - 2013-05-29 19:59 - 00000000 ____D C:\Users\Jim\AppData\Local\Temp(135)
2013-05-29 19:59 - 2013-05-29 19:59 - 00000000 ____D C:\Users\Guest\AppData\Local\Temp(65)
2013-05-29 19:46 - 2013-05-31 08:31 - 00000000 ____D C:\Qoobox
2013-05-29 19:41 - 2013-05-31 07:57 - 00000000 ____D C:\Users\luci\Desktop\RK_Quarantine
2013-05-28 17:02 - 2013-05-28 17:02 - 00413431 ____A C:\Users\luci\Desktop\CBS.zip
2013-05-28 13:42 - 2013-05-28 13:30 - 10819777 ____A C:\Users\luci\Desktop\CBS.log
2013-05-24 22:09 - 2013-05-31 08:05 - 00000118 ____A C:\Users\luci\AppData\Roaming\wklnhst.dat
2013-05-24 22:09 - 2013-05-24 22:09 - 00000000 ____D C:\Users\luci\AppData\Roaming\Template
2013-05-23 15:02 - 2013-05-23 15:02 - 00000000 ____D C:\ProgramData\ErrorEND
2013-05-21 06:48 - 2013-05-28 08:52 - 00000000 ____D C:\Windows\pss
2013-05-21 06:10 - 2013-05-31 19:40 - 00000680 ____A C:\Users\luci\AppData\Local\d3d9caps.dat
2013-05-20 18:15 - 2013-05-20 18:15 - 00000000 ____D C:\found.001
2013-05-20 05:33 - 2013-05-20 05:33 - 00000000 ____D C:\found.000

==================== One Month Modified Files and Folders ========

2013-05-31 23:54 - 2013-05-31 23:54 - 00000000 ____D C:\FRST
2013-05-31 19:40 - 2013-05-21 06:10 - 00000680 ____A C:\Users\luci\AppData\Local\d3d9caps.dat
2013-05-31 09:43 - 2006-11-02 02:33 - 00703388 ____A C:\Windows\System32\PerfStringBackup.INI
2013-05-31 08:31 - 2013-05-31 08:31 - 00007801 ____A C:\ComboFix.txt
2013-05-31 08:31 - 2013-05-29 19:46 - 00000000 ____D C:\Qoobox
2013-05-31 08:30 - 2013-05-31 08:20 - 00000000 ____D C:\Windows\erdnt
2013-05-31 08:29 - 2006-11-02 02:23 - 00000215 ____A C:\Windows\system.ini
2013-05-31 08:17 - 2013-05-31 08:17 - 00000163 ____A C:\Users\luci\Desktop\1.txt
2013-05-31 08:05 - 2013-05-24 22:09 - 00000118 ____A C:\Users\luci\AppData\Roaming\wklnhst.dat
2013-05-31 08:05 - 2010-06-09 18:14 - 01261027 ____A C:\Windows\WindowsUpdate.log
2013-05-31 08:01 - 2013-05-31 08:03 - 02218636 ____A C:\Users\luci\Desktop\tdsskiller.zip
2013-05-31 07:59 - 2013-05-31 08:03 - 00011776 ____A C:\Users\luci\Desktop\pastefile.wps
2013-05-31 07:57 - 2013-05-31 07:57 - 00001864 ____A C:\Users\luci\Desktop\RKreport[2]_D_05312013_02d1157.txt
2013-05-31 07:57 - 2013-05-29 19:41 - 00000000 ____D C:\Users\luci\Desktop\RK_Quarantine
2013-05-31 07:51 - 2013-05-31 07:51 - 00001962 ____A C:\Users\luci\Desktop\RKreport[1]_S_05312013_02d1151.txt
2013-05-30 23:35 - 2006-11-02 04:49 - 00077288 ____A C:\Windows\setupact.log
2013-05-30 23:34 - 2010-06-13 15:14 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-05-30 23:34 - 2006-11-02 04:58 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-05-30 23:34 - 2006-11-02 04:45 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-05-30 23:34 - 2006-11-02 04:45 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-05-30 22:14 - 2012-11-22 11:19 - 00000000 ____D C:\Users\luci\AppData\Roaming\Skype
2013-05-30 22:14 - 2012-07-22 04:39 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-05-30 22:05 - 2010-08-22 15:12 - 00000000 ____D C:\users\Guest
2013-05-30 22:05 - 2010-06-13 19:17 - 00000000 ____D C:\users\Jim
2013-05-30 22:05 - 2010-06-09 18:18 - 00000000 ____D C:\users\luci
2013-05-30 22:05 - 2006-11-02 02:22 - 46137344 ____A C:\Windows\System32\config\software_previous
2013-05-30 22:05 - 2006-11-02 02:22 - 36700160 ____A C:\Windows\System32\config\components_previous
2013-05-30 22:05 - 2006-11-02 02:22 - 22806528 ____A C:\Windows\System32\config\system_previous
2013-05-30 22:05 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\security_previous
2013-05-30 22:05 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\sam_previous
2013-05-30 22:05 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\default_previous
2013-05-30 22:04 - 2006-11-02 03:18 - 00000000 __RSD C:\Windows\Media
2013-05-30 22:04 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\System32\spool
2013-05-30 22:04 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\System32\Msdtc
2013-05-30 22:03 - 2013-03-02 10:39 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-05-30 22:03 - 2013-03-02 10:39 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search
2013-05-30 22:03 - 2013-03-02 10:39 - 00000000 ____D C:\Program Files\AVG SafeGuard toolbar
2013-05-30 22:03 - 2013-02-27 19:20 - 00000000 ___RD C:\Program Files\Skype
2013-05-30 22:03 - 2013-02-27 19:20 - 00000000 ____D C:\Program Files\Common Files\Skype
2013-05-30 22:03 - 2006-11-02 03:18 - 00000000 __RHD C:\users\Default
2013-05-30 22:03 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\registration
2013-05-30 21:49 - 2011-01-01 18:20 - 00000000 ____D C:\Windows\Minidump
2013-05-30 21:47 - 2013-05-29 19:59 - 00000000 ____D C:\Users\luci\AppData\Local\Temp(145)
2013-05-29 23:10 - 2008-01-20 19:02 - 00145308 ____A C:\Windows\PFRO.log
2013-05-29 19:59 - 2013-05-29 19:59 - 00000000 ____D C:\Users\Jim\AppData\Local\Temp(135)
2013-05-29 19:59 - 2013-05-29 19:59 - 00000000 ____D C:\Users\Guest\AppData\Local\Temp(65)
2013-05-29 19:59 - 2006-11-02 03:18 - 00000000 ___RD C:\users\Public
2013-05-29 09:11 - 2013-05-30 23:35 - 05073804 ____R (Swearware) C:\Users\luci\Desktop\ComboFix.exe
2013-05-29 09:11 - 2013-05-30 23:35 - 00816128 ____A C:\Users\luci\Desktop\RogueKiller.exe
2013-05-28 17:02 - 2013-05-28 17:02 - 00413431 ____A C:\Users\luci\Desktop\CBS.zip
2013-05-28 13:30 - 2013-05-28 13:42 - 10819777 ____A C:\Users\luci\Desktop\CBS.log
2013-05-28 08:52 - 2013-05-21 06:48 - 00000000 ____D C:\Windows\pss
2013-05-24 22:09 - 2013-05-24 22:09 - 00000000 ____D C:\Users\luci\AppData\Roaming\Template
2013-05-23 15:02 - 2013-05-23 15:02 - 00000000 ____D C:\ProgramData\ErrorEND
2013-05-21 20:08 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-05-21 19:26 - 2010-06-09 20:15 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-05-21 15:20 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\System32\LogFiles
2013-05-21 06:48 - 2012-05-28 15:19 - 00000000 ____D C:\Users\luci\Desktop\Photo2Album Samples
2013-05-21 06:40 - 2010-07-28 18:56 - 00000000 ____D C:\Users\luci\Documents\Outlook Files
2013-05-21 06:16 - 2012-05-28 15:22 - 00000000 ____D C:\Photo2Album
2013-05-20 18:47 - 2013-03-02 10:39 - 00000000 ____D C:\Users\luci\AppData\Roaming\Yontoo
2013-05-20 18:15 - 2013-05-20 18:15 - 00000000 ____D C:\found.001
2013-05-20 05:33 - 2013-05-20 05:33 - 00000000 ____D C:\found.000
2013-05-12 09:56 - 2010-08-22 15:13 - 00000000 ____D C:\Users\Guest\AppData\Local\Google
2013-05-05 14:28 - 2012-11-22 11:18 - 00000000 ____D C:\ProgramData\Skype

Other Malware:
===========
C:\Users\luci\QuickTimeInstaller.exe

==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\…\.exe: exefile => OK
HKLM\…\exefile\DefaultIcon: %1 => OK
HKLM\…\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2013-04-10 03:56:27
Restore point made on: 2013-04-10 23:00:34
Restore point made on: 2013-04-12 07:00:46
Restore point made on: 2013-04-13 09:27:25
Restore point made on: 2013-04-14 12:38:48
Restore point made on: 2013-04-15 05:27:47
Restore point made on: 2013-04-16 05:08:06
Restore point made on: 2013-04-18 06:52:14
Restore point made on: 2013-04-19 05:03:36
Restore point made on: 2013-04-20 17:25:09
Restore point made on: 2013-04-21 05:50:52
Restore point made on: 2013-04-22 08:35:17
Restore point made on: 2013-04-23 23:00:28
Restore point made on: 2013-04-25 07:29:21
Restore point made on: 2013-04-26 15:46:51
Restore point made on: 2013-04-27 14:22:42
Restore point made on: 2013-04-28 06:07:02
Restore point made on: 2013-04-29 04:39:25
Restore point made on: 2013-04-30 11:35:14
Restore point made on: 2013-05-02 04:14:23
Restore point made on: 2013-05-03 08:53:14
Restore point made on: 2013-05-05 08:41:08
Restore point made on: 2013-05-06 05:09:11
Restore point made on: 2013-05-08 12:17:55
Restore point made on: 2013-05-10 05:40:18
Restore point made on: 2013-05-11 19:50:27
Restore point made on: 2013-05-13 04:40:07
Restore point made on: 2013-05-14 04:50:39
Restore point made on: 2013-05-15 06:06:56
Restore point made on: 2013-05-15 23:00:43
Restore point made on: 2013-05-17 05:27:39
Restore point made on: 2013-05-18 07:45:43

==================== Memory info ===========================

Percentage of memory in use: 13%
Total physical RAM: 2939.26 MB
Available physical RAM: 2542.39 MB
Total Pagefile: 2734.82 MB
Available Pagefile: 2591.22 MB
Total Virtual: 2047.88 MB
Available Virtual: 1964.27 MB

==================== Drives ================================

Drive c: (SQ004981V02) (Fixed) (Total:224.2 GB) (Free:155.13 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (TOSHIBA SYSTEM VOLUME) (Fixed) (Total:1.46 GB) (Free:1.32 GB) NTFS
Drive f: () (Removable) (Total:1.91 GB) (Free:0.69 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows Vista) (Size: 233 GB) (Disk ID: 1A757E79)
Partition 1: (Not Active) - (Size=1 GB) - (Type=27)
Partition 2: (Active) - (Size=224 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=7 GB) - (Type=17)

========================================================
Disk: 1 (Size: 2 GB) (Disk ID: F39324D7)
Partition 1: (Not Active) - (Size=2 GB) - (Type=06)


Last Boot: 2013-05-31 08:02

==================== End Of Log ============================
Hi ptaerehsahh,

So I restarted the computer….. I forgot to start in safe mode… so it again has froze up

Just to be clear, if the computer will start and function in normal mode, that is the preferred mode. If not use safe mode.

Caution: The FRST fix step must be run from the Recovery Environment

=========================

1. Uninstall via Programs and Features

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • AVG SafeGuard toolbar
=========================

2. FRST Fix Script

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

HKLM\…\Run: [vProt] "C:\Program Files\AVG SafeGuard toolbar\vprot.exe" [1151152 2013-03-02] ()
S2 vToolbarUpdater14.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe [968880 2013-03-02] ()
S2 Yontoo Desktop Updater; C:\Users\luci\AppData\Roaming\Yontoo\YontooDesktop.exe [42784 2013-02-15] (Yontoo LLC)
2013-05-29 19:59 - 2013-05-30 21:47 - 00000000 ____D C:\Users\luci\AppData\Local\Temp(145)
2013-05-29 19:59 - 2013-05-29 19:59 - 00000000 ____D C:\Users\Jim\AppData\Local\Temp(135)
2013-05-29 19:59 - 2013-05-29 19:59 - 00000000 ____D C:\Users\Guest\AppData\Local\Temp(65)
2013-05-30 22:03 - 2013-03-02 10:39 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-05-30 22:03 - 2013-03-02 10:39 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search
2013-05-30 22:03 - 2013-03-02 10:39 - 00000000 ____D C:\Program Files\AVG SafeGuard toolbar
C:\Users\luci\QuickTimeInstaller.exe

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
On Windows XP: Now please boot into the BartPE CD.
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

=========================

In your next post please provide the following:
  • Fixlog.txt
  • Describe what symptoms you are experiencing?
Windows has blocked some startup programs… This is the message I get when I start the computer in Normal Mode…. When I click on ANYTHING it goes straight to working icon like it's trying to open but never does. I then have to shut down the computer via on/off button….. Have had to do this 4 times finally booted back up to safe mode…. However I have tried everyway to uninstall AVG toolbar.. I did accidently this last time not paying enough attention deleted the uninstall of the AVG SafeGuard toolbar….. I went to get it out of the recycle bin and low and behold I can not find the recycle bin to get it out of. I have not done the 2nd part of your instructions until you ok me to do so….
Caution: The FRST fix step must be run from the Recovery Environment I want to be 100% on this. does this mean in safe mode? or like when I choose the Repair your computer menu?
Hi ptaerehsahh

Caution: The FRST fix step must be run from the Recovery Environment

I want to be 100% on this. does this mean in safe mode? or like when I choose the Repair your computer menu?


Follow the steps from post #31 to enter the Recovery Environment
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-06-2013 This step really really confused me so hope it is right… :D :D :D:) Ran by [removed] at 2013-06-02 02:13:01 Run:1 Running from F:\ Boot Mode: Recovery ============================================== HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\vProt => Value deleted successfully. vToolbarUpdater14.2.0 => Service deleted successfully. Yontoo Desktop Updater => Service deleted successfully. C:\Users\luci\AppData\Local\Temp(145) => Moved successfully. C:\Users\Jim\AppData\Local\Temp(135) => Moved successfully. C:\Users\Guest\AppData\Local\Temp(65) => Moved successfully. C:\ProgramData\AVG SafeGuard toolbar => Moved successfully. C:\Program Files\Common Files\AVG Secure Search => Moved successfully. C:\Program Files\AVG SafeGuard toolbar => Moved successfully. C:\Users\luci\QuickTimeInstaller.exe => Moved successfully. ==== End of Fixlog ====
Hi ptaerehsahh,

This step really really confused me so hope it is right…

You did great! :thumbup:

=========================

Now boot into Normal Mode to continue.

=========================

1. Reset TCP/IP stack to installation defaults

You must run the command prompt as an administrator or in an "elevated mode".
  • Start menu, in the search bar type "cmd"
  • Right-click the cmd icon, select "run as administrator"
    • If you have user account control (UAC) set up it may prompt you to accept that action.
  • Then type in "netsh int ip reset reset.log" then hit Enter
=========================

2. Reboot

=========================

3. Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 & 8 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • OTL.txt
  • What symptoms are you experiencing at the moment?
Still freezes up in normal mode so I can not get anywhere….. Safe Mode is still good…. Should I run in safe mode?????
Experience: Restarted computer in normal mode…… Message about security options blocked still comes up…. Still freezes up when you click anywhere…. still have to use power button to shut down. Nothing has changed in that part..

The OTL brought up double logfiles…. including 2 extra logs…..

I know. I'm a pain….. Thanks for bearin wiff me….. :notworthy:





OTL logfile created on: 6/2/2013 11:12:59 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\luci\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 2.49 Gb Available Physical Memory | 86.84% Memory free
5.94 Gb Paging File | 5.74 Gb Available in Paging File | 96.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 224.20 Gb Total Space | 154.61 Gb Free Space | 68.96% Space Free | Partition Type: NTFS
Drive E: | 1.91 Gb Total Space | 0.69 Gb Free Space | 36.24% Space Free | Partition Type: FAT
Unable to calculate disk information.

Computer Name: LUCI-PC | User Name: luci | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\luci\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (LiveUpdate Notice) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (TMachInfo) – C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (TNaviSrv) – C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (IAANTMON) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (lxbk_device) – C:\Windows\System32\lxbkcoms.exe ( )
SRV - (TosCoSrv) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TOSHIBA SMART Log Service) – C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (comHost) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (NAVEX15) – C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20100808.003\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20100808.003\NAVENG.SYS File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (catchme) – C:\Users\luci\AppData\Local\Temp\catchme.sys File not found
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\ipsdefs\20100804.001\IDSvix86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:\Windows\System32\drivers\symndisv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\drivers\symfw.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SYMDNS) – C:\Windows\System32\drivers\symdns.sys (Symantec Corporation)
DRV - (COH_Mon) – C:\Windows\System32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (tos_sps32) – C:\Windows\System32\drivers\tos_sps32.sys (TOSHIBA Corporation)
DRV - (JL2005C) – C:\Windows\System32\drivers\jl2005c.sys (Windows ® 2000 DDK provider)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (mr97310c) – C:\Windows\System32\drivers\mr97310c.sys (Mars Semiconductor Corp.)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (RTL8187B) – C:\Windows\System32\drivers\rtl8187B.sys (Realtek Semiconductor Corporation )
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (CO_Mon) – C:\Windows\System32\drivers\CO_Mon.sys (Symantec Corporation)
DRV - (RtlProt) – C:\Windows\System32\drivers\RtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (FwLnk) – C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (KR10I) – C:\Windows\System32\drivers\KR10I.sys (TOSHIBA CORPORATION)
DRV - (KR10N) – C:\Windows\System32\drivers\KR10N.sys (TOSHIBA CORPORATION)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…B&bmod=TSHB
IE - HKLM\..\SearchScopes,DefaultScope = {7F483B27-FA32-4A99-8F1C-E6E2282EAE18}
IE - HKLM\..\SearchScopes\{7F483B27-FA32-4A99-8F1C-E6E2282EAE18}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSHB

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s=jbR1Zar…q={searchTerms}
IE - HKCU\..\SearchScopes\{7F483B27-FA32-4A99-8F1C-E6E2282EAE18}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7TSHB_enUS383
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://mysearch.avg.com/search?cid={273E85…mp;d=2013-03-02 13:39:42&v=14.2.0.1&pid=safeguard&sg=1&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\11\NP_wtapp.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\14.2.0.1


O1 HOSTS File: ([2013/05/31 12:29:16 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Reg Error: Value error.) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\14.2.0.1\AVG SafeGuard toolbar_toolbar.dll File not found
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\14.2.0.1\AVG SafeGuard toolbar_toolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [cfFncEnabler.exe] cfFncEnabler.exe File not found
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" File not found
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [osCheck] C:\Program Files\Norton 360\osCheck.exe (Symantec Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Users\luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft SharePoint Workspace.lnk = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E7D4742D-1078-4833-B552-F1964685144D}: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Autumn Leaves.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Autumn Leaves.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/02 21:56:47 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\luci\Desktop\OTL.exe
[2013/06/01 03:54:30 | 000,000,000 | —D | C] – C:\FRST
[2013/05/31 12:31:12 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/05/31 12:31:12 | 000,000,000 | —D | C] – C:\Users\luci\AppData\Local\temp
[2013/05/31 12:30:48 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/05/31 12:20:40 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/05/31 12:20:40 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/05/31 12:20:40 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/05/31 12:20:04 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/05/31 03:35:52 | 005,073,804 | R— | C] (Swearware) – C:\Users\luci\Desktop\ComboFix.exe
[2013/05/29 23:46:51 | 000,000,000 | —D | C] – C:\Qoobox
[2013/05/29 23:41:30 | 000,000,000 | —D | C] – C:\Users\luci\Desktop\RK_Quarantine
[2013/05/25 02:09:53 | 000,000,000 | —D | C] – C:\Users\luci\AppData\Roaming\Template
[2013/05/23 19:02:04 | 000,000,000 | —D | C] – C:\ProgramData\ErrorEND
[2013/05/21 10:48:55 | 000,000,000 | —D | C] – C:\Windows\pss
[2013/05/20 22:15:21 | 000,000,000 | —D | C] – C:\found.001
[2013/05/20 09:33:46 | 000,000,000 | —D | C] – C:\found.000
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/02 22:38:00 | 000,000,680 | —- | M] () – C:\Users\luci\AppData\Local\d3d9caps.dat
[2013/06/02 21:12:50 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\luci\Desktop\OTL.exe
[2013/06/02 19:05:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/02 18:48:11 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/02 18:46:21 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/02 18:46:21 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/02 18:46:08 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/31 13:43:48 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/05/31 13:43:48 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/05/31 12:29:16 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/05/31 12:05:49 | 000,000,118 | —- | M] () – C:\Users\luci\AppData\Roaming\wklnhst.dat
[2013/05/31 12:01:42 | 002,218,636 | —- | M] () – C:\Users\luci\Desktop\tdsskiller.zip
[2013/05/31 11:59:50 | 000,011,776 | —- | M] () – C:\Users\luci\Desktop\pastefile.wps
[2013/05/31 02:14:48 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/29 13:11:46 | 005,073,804 | R— | M] (Swearware) – C:\Users\luci\Desktop\ComboFix.exe
[2013/05/29 13:11:10 | 000,816,128 | —- | M] () – C:\Users\luci\Desktop\RogueKiller.exe
[2013/05/28 21:02:48 | 000,413,431 | —- | M] () – C:\Users\luci\Desktop\CBS.zip
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/31 12:20:40 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/05/31 12:20:40 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/05/31 12:20:40 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/05/31 12:20:40 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/05/31 12:20:40 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/05/31 12:03:56 | 002,218,636 | —- | C] () – C:\Users\luci\Desktop\tdsskiller.zip
[2013/05/31 12:03:47 | 000,011,776 | —- | C] () – C:\Users\luci\Desktop\pastefile.wps
[2013/05/31 03:35:56 | 000,816,128 | —- | C] () – C:\Users\luci\Desktop\RogueKiller.exe
[2013/05/28 21:02:48 | 000,413,431 | —- | C] () – C:\Users\luci\Desktop\CBS.zip
[2013/05/25 02:09:52 | 000,000,118 | —- | C] () – C:\Users\luci\AppData\Roaming\wklnhst.dat
[2013/05/21 10:10:22 | 000,000,680 | —- | C] () – C:\Users\luci\AppData\Local\d3d9caps.dat
[2012/11/24 13:20:10 | 000,053,248 | —- | C] () – C:\Windows\System32\CommonDL.dll
[2012/11/24 13:20:10 | 000,002,413 | —- | C] () – C:\Windows\System32\lgAxconfig.ini
[2012/05/28 19:20:06 | 000,015,164 | —- | C] () – C:\Windows\mr310twc.ini
[2011/12/08 21:50:07 | 000,000,077 | —- | C] () – C:\Windows\m2khd.ini
[2011/02/25 23:09:37 | 000,093,507 | —- | C] () – C:\Users\luci\Cave Springs Church.jpg
[2010/06/14 22:49:55 | 000,000,632 | RHS- | C] () – C:\Users\luci\ntuser.pol

========== ZeroAccess Check ==========

[2006/11/02 08:51:16 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 02:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
Hi ptaerehsahh,

1. Start-up Repair
  • Remove all floppy disks, CDs, and DVDs from your computer, and then restart your computer.
  • Click the Start button, click the arrow next to the Lock button, and then click Restart.
  • Do one of the following:
    • If your computer has a single operating system installed, press and hold the F8 key as your computer restarts. You need to press F8 before the Windows logo appears. If the Windows logo appears, you will need to try again by waiting until the Windows logon prompt appears, and then shutting down and restarting your computer.
    • If your computer has more than one operating system, use the arrow keys to highlight the operating system you want to repair, and then press and hold F8.
  • On the Advanced Boot Options screen, use the arrow keys to highlight Repair your computer, and then press ENTER. (If Repair your computer is not listed as an option, then your computer does not include Start-up Repair as a preinstalled recovery option.)
  • Select a keyboard layout, and then click Next.
  • Select a user name and enter the password, and then click OK.
  • On the System Recovery Options menu, click Start-up Repair. Start-up Repair might prompt you to make choices as it tries to fix the problem and, if necessary, it might restart your computer as it makes repairs.
=========================

2. Reboot in Normal Mode

Reboot into Normal Mode and test

=========================

4. Farbar Service Scanner

Please download Farbar Service Scanner and save it to your desktop.
  • Right click and select "Run as Administrator"
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
=========================

In your next post please provide the following:
  • FSS.txt
  • Boot Mode Status
Hi ya….. Start up repair came up with nothing could be found wrong……. Normal start up still the same….. warning: security is blocked…… Farbar Service Scanner Version: 31-05-2013 01 Ran by [removed] (administrator) on 03-06-2013 at 03:23:01 Running from "C:\Users\luci\Desktop" Windows Vista ™ Home Basic Service Pack 2 (X86) Boot Mode: Minimal **************************************************************** Internet Services: ============ Dnscache Service is not running. Checking service configuration: The start type of Dnscache service is OK. The ImagePath of Dnscache service is OK. The ServiceDll of Dnscache service is OK. Dhcp Service is not running. Checking service configuration: The start type of Dhcp service is OK. The ImagePath of Dhcp service is OK. The ServiceDll of Dhcp service is OK. Nsi Service is not running. Checking service configuration: The start type of Nsi service is OK. The ImagePath of Nsi service is OK. The ServiceDll of Nsi service is OK. Checking LEGACY_Nsi: ATTENTION!=====> Unable to open LEGACY_Nsi\0000 registry key. The key does not exist. nsiproxy Service is not running. Checking service configuration: The start type of nsiproxy service is OK. The ImagePath of nsiproxy service is OK. tdx Service is not running. Checking service configuration: The start type of tdx service is OK. The ImagePath of tdx service is OK. afd Service is not running. Checking service configuration: The start type of afd service is OK. The ImagePath of afd service is OK. Connection Status: ============== Attempt to access Local Host IP returned error: Localhost is blocked: Other errors LAN connected. Attempt to access Google IP returned error. Other errors Attempt to access Google.com returned error: Other errors Attempt to access Yahoo IP returned error. Other errors Attempt to access Yahoo.com returned error: Other errors Windows Firewall: ============= mpsdrv Service is not running. Checking service configuration: The start type of mpsdrv service is OK. The ImagePath of mpsdrv service is OK. MpsSvc Service is not running. Checking service configuration: The start type of MpsSvc service is OK. The ImagePath of MpsSvc service is OK. The ServiceDll of MpsSvc service is OK. Checking LEGACY_MpsSvc: ATTENTION!=====> Unable to open LEGACY_MpsSvc\0000 registry key. The key does not exist. bfe Service is not running. Checking service configuration: The start type of bfe service is OK. The ImagePath of bfe service is OK. The ServiceDll of bfe service is OK. Checking LEGACY_bfe: ATTENTION!=====> Unable to open LEGACY_bfe\0000 registry key. The key does not exist. Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 System Restore: ============ SDRSVC Service is not running. Checking service configuration: The start type of SDRSVC service is OK. The ImagePath of SDRSVC service is OK. The ServiceDll of SDRSVC service is OK. Checking LEGACY_SDRSVC: ATTENTION!=====> Unable to open LEGACY_SDRSVC\0000 registry key. The key does not exist. VSS Service is not running. Checking service configuration: The start type of VSS service is OK. The ImagePath of VSS service is OK. System Restore Disabled Policy: ======================== Security Center: ============ wscsvc Service is not running. Checking service configuration: The start type of wscsvc service is OK. The ImagePath of wscsvc service is OK. The ServiceDll of wscsvc service is OK. Checking LEGACY_wscsvc: ATTENTION!=====> Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist. Windows Update: ============ wuauserv Service is not running. Checking service configuration: The start type of wuauserv service is OK. The ImagePath of wuauserv service is OK. The ServiceDll of wuauserv service is OK. BITS Service is not running. Checking service configuration: The start type of BITS service is set to Demand. The default start type is Auto. The ImagePath of BITS service is OK. The ServiceDll of BITS service is OK. Checking LEGACY_BITS: ATTENTION!=====> Unable to open LEGACY_BITS\0000 registry key. The key does not exist. EventSystem Service is not running. Checking service configuration: The start type of EventSystem service is OK. The ImagePath of EventSystem service is OK. The ServiceDll of EventSystem service is OK. Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 Other Services: ============== File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys [2013-02-13 09:13] - [2013-01-04 07:28] - 0905576 ____A (Microsoft Corporation) 74E2D020C47BB2B2FCCBA29A518A7EB4 C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log ****
Hi ptaerehsahh,

You have several registry keys missing.

Is your Internet connection OK?

If not describe it's current status and symptoms.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI