reopening topic finally go the time to follow instructions

Q: reopening topic finally go the time to follow instructions

osted 22 November 2010 - 10:09 PMMy sons computer on start up fails. The page offering last good configuration or a couple of safe mode options all which lead to application error messages fist service.exe application error messages then issas.exe application error messages. clicking Ok to these errors boxes leads to a black page hang. I have seen the symptoms description on several internet sights. but have found no repair instruction... What am I to do, bo who.Guidence please chris cjeweler For Blondie I have followed your instruction and this was the log produced- did not get the second smaller logOTL logfile created on: 12/26/2010 9:08:10 PM - Run OTLPE by OldTimer - Version Folder = D:\repair alex\OTLPEMicrosoft Windows XP Service Pack 2 (Version = 5.1.2600) - Type = SYSTEMInternet Explorer (Version = 6.0.2900.2180)Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1,024.00 Mb Total Physical Memory | 851.00 Mb Available Physical Memory | 83.00% Memory free923.00 Mb Paging File | 892.00 Mb Available in Paging File | 97.00% Paging File freePaging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 74.52 Gb Total Space | 21.44 Gb Free Space | 28.77% Space Free | Partition Type: NTFSDrive D: | 7.46 Gb Total Space | 5.46 Gb Free Space | 73.12% Space Free | Partition Type: FAT32Drive X: | 151.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: MININT-JVC | User Name: SYSTEMBoot Mode: Normal | Scan Mode: All usersCompany Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 DaysUsing ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV - File not found [Auto] -- C:\Program Files\Linksys Wireless-G PCI Adapter with SRX\WLService.exe WMP54GX.exe -- (WMP54GXSVC)SRV - File not found [Disabled] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)SRV - [2010/11/12 03:23:48 | 001,415,680 | ---- | M] () [Auto] -- C:\WINDOWS\system32\verifier32.exe -- (ClipSrv32)SRV - [2010/08/27 08:54:35 | 000,030,192 | ---- | M] (Google) [On_Demand] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-051210-111108)SRV - [2010/08/13 19:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)SRV - [2009/10/27 18:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)SRV - [2009/09/16 18:23:32 | 000,365,072 | ---- | M] (McAfee, Inc.) [On_Demand] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)SRV - [2009/09/16 17:22:08 | 000,144,704 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)SRV - [2009/09/16 16:28:38 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand] -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)SRV - [2009/07/10 07:26:20 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)SRV - [2009/07/08 18:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)SRV - [2009/07/08 02:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)SRV - [2005/04/05 01:58:28 | 000,163,840 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe -- (Adobe Version Cue CS2) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (WDICA)DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)DRV - File not found [Kernel | System] -- -- (PCIDump)DRV - File not found [Kernel | Auto] -- -- (MCSTRM)DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\DRIVERS\lmimirr.sys -- (lmimirr)DRV - File not found [Kernel | System] -- -- (lbrtfdc)DRV - File not found [Kernel | System] -- -- (i2omgmt)DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\drivers\hap17v2k.sys -- (hap17v2k)DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\CTHWIUT.DLL -- (CTHWIUT.DLL)DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\CTEXFIFX.DLL -- (CTEXFIFX.DLL)DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\CTERFXFX.DLL -- (CTERFXFX.DLL)DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\CTEDSPSY.DLL -- (CTEDSPSY.DLL)DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\CTEDSPIO.DLL -- (CTEDSPIO.DLL)DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\CTEDSPFX.DLL -- (CTEDSPFX.DLL)DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\CTEAPSFX.DLL -- (CTEAPSFX.DLL)DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\CT20XUT.DLL -- (CT20XUT.DLL)DRV - File not found [Kernel | System] -- -- (Changer)DRV - [2009/09/16 17:22:48 | 000,214,664 | ---- | M] (McAfee, Inc.) [Kernel | System] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)DRV - [2009/09/16 17:22:48 | 000,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)DRV - [2009/09/16 17:22:48 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mfesmfk.sys -- (mfesmfk)DRV - [2009/09/16 17:22:48 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)DRV - [2009/09/16 17:22:14 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mferkdk.sys -- (mferkdk)DRV - [2009/07/16 19:32:26 | 000,120,136 | ---- | M] (McAfee, Inc.) [Kernel | System] -- C:\WINDOWS\system32\drivers\Mpfp.sys -- (MPFP)DRV - [2005/04/18 23:47:00 | 000,840,192 | ---- | M] (Airgo Networks, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\WniHdd51.sys -- (Airgo)DRV - [2004/08/04 06:08:22 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)DRV - [2004/08/03 22:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)DRV - [2003/11/21 22:20:10 | 000,113,152 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)DRV - [2003/07/10 09:40:38 | 000,145,232 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\emupia2k.sys -- (emupia)DRV - [2003/07/10 09:38:28 | 000,651,792 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ctac32k.sys -- (ctac32k)DRV - [2003/06/27 08:24:54 | 000,159,040 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\haP16v2k.sys -- (hap16v2k)DRV - [2003/06/27 08:24:42 | 000,860,592 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ha10kx2k.sys -- (ha10kx2k)DRV - [2003/06/20 03:35:46 | 000,602,112 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\ctsblfx.dll -- (CTSBLFX.DLL)DRV - [2003/06/20 03:34:34 | 000,589,824 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\ctaudfx.dll -- (CTAUDFX.DLL)DRV - [2003/06/20 03:34:04 | 000,114,688 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\commonfx.dll -- (COMMONFX.DLL)DRV - [2003/06/20 03:33:40 | 000,136,016 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)DRV - [2003/06/20 03:33:24 | 000,006,144 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ctprxy2k.sys -- (ctprxy2k)DRV - [2003/06/20 03:33:16 | 000,190,208 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)DRV - [2003/06/20 03:33:02 | 000,509,328 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)DRV - [2003/03/27 02:58:56 | 000,287,920 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ctdvda2k.sys -- (ctdvda2k) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = EB F1 28 01 B9 1E 3F 46 88 7D BE 0B D3 7E BE CC [binary data]IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\cg_home_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.comIE - HKU\cg_home_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/IE - HKU\cg_home_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = EB F1 28 01 B9 1E 3F 46 88 7D BE 0B D3 7E BE CC [binary data]IE - HKU\cg_home_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKU\cg_home_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKU\Guest_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/IE - HKU\Guest_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-usIE - HKU\Guest_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CC 81 51 9D A9 E1 CA 01 [binary data]IE - HKU\Guest_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = EB F1 28 01 B9 1E 3F 46 88 7D BE 0B D3 7E BE CC [binary data] IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = EB F1 28 01 B9 1E 3F 46 88 7D BE 0B D3 7E BE CC [binary data] [2010/02/14 00:51:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cg home\Application Data\Mozilla\Extensions[2010/02/14 00:51:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cg home\Application Data\Mozilla\Extensions\[email protected] O1 HOSTS File: ([2010/09/25 05:24:32 | 000,000,736 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hostsO1 - Hosts: localhostO2 - BHO: (no name) - {0128F1EB-1EB9-463F-887D-BE0BD37EBECc} - C:\WINDOWS\system32\autodisc32.dll (Inprise Corporation)O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)O2 - BHO: (ec5e8ea6) - {DA0585E6-4A0D-B844-E4B2-85C680CCAC2E} - C:\WINDOWS\system32\oleaccrc32.dll (Inprise Corporation)O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O3 - HKU\cg_home_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)O3 - HKU\cg_home_ON_C\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O3 - HKU\Guest_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)O3 - HKU\Guest_ON_C\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O4 - HKLM..\Run: [] File not foundO4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)O4 - HKLM..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe (Adobe Sytems Incorporated)O4 - HKLM..\Run: [AsioReg] C:\WINDOWS\System32\CTASIO.DLL (Creative Technology Ltd)O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)O4 - HKLM..\Run: [eyveomay] C:\Documents and Settings\cg home\Local Settings\Application Data\ylcnyb\wsoysysguard.exe File not foundO4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)O4 - HKLM..\Run: [ntshruiwow.exe] C:\WINDOWS\ntshruiwow.exe ()O4 - HKLM..\Run: [RTHDBPL] C:\WINDOWS\lsass.exe ()O4 - HKU\cg_home_ON_C..\Run: [eyveomay] C:\Documents and Settings\cg home\Local Settings\Application Data\ylcnyb\wsoysysguard.exe File not foundO4 - HKU\cg_home_ON_C..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)O4 - HKU\Guest_ON_C..\Run: [qlxnuupt] C:\Documents and Settings\Guest\Local Settings\Application Data\kpxbfe\olulsysguard.exe File not foundO4 - HKU\Guest_ON_C..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)O4 - HKU\Guest_ON_C..\Run: [ttool] C:\WINDOWS\srsdllpro.exe File not foundO4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ImageMixer for HDD Camcorder.lnk = C:\Program Files\PIXELA\ImageMixer for HDD Camcorder\IMx3Launcher.exe (PIXELA CORPORATION)O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\OfficeSAS.lnk = C:\Program Files\Microsoft Office\Office14\OfficeSAS\OfficeSASScheduler.exe (Microsoft Corporation)O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: RTHDBPL = C:\Documents and Settings\cg home\Application Data\SysWin\lsass.exe ()O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\cg_home_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\Guest_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} https://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB (Hewlett-Packard Online Support Services)O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1234325006375 (MUWebControl Class)O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = - AppInit_DLLs: (C:\WINDOWS\SYSTEM32\OLEACCRC32.DLL C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL) - C:\WINDOWS\System32\OLEACCRC32.DLL (Inprise Corporation)O20 - AppInit_DLLs: (C:\WINDOWS\system32\oleaccrc32.dll) - C:\WINDOWS\system32\oleaccrc32.dll (Inprise Corporation)O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)O24 - Desktop WallPaper: O24 - Desktop BackupWallPaper: O32 - HKLM CDRom: AutoRun - 1O32 - AutoRun File - [2009/02/09 14:53:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]O32 - AutoRun File - [2004/11/02 22:04:58 | 000,000,046 | R--- | M] () - X:\autorun.inf -- [ CDFS ]O33 - MountPoints2\{172f8316-2269-11de-a552-000d9d57877c}\Shell\AutoRun\command - "" = F:\InstallSeagateManager.exe -- File not foundO33 - MountPoints2\{92039d46-9452-11df-a68d-001217a8949c}\Shell - "" = AutoRunO33 - MountPoints2\{92039d46-9452-11df-a68d-001217a8949c}\Shell\AutoRun - "" = Auto&PlayO33 - MountPoints2\{92039d46-9452-11df-a68d-001217a8949c}\Shell\AutoRun\command - "" = D:\LaunchU3.exe -- File not foundO33 - MountPoints2\D\Shell - "" = AutoRunO33 - MountPoints2\D\Shell\AutoRun - "" = Auto&PlayO33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\LaunchU3.exe -- File not foundO34 - HKLM BootExecute: (autocheck autochk *) - File not foundO35 - HKLM\..comfile [open] -- "%1" %*O35 - HKLM\..exefile [open] -- "%1" %*O37 - HKLM\...com [@ = comfile] -- "%1" %*O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2009/09/07 00:02:32 | 000,208,543 | ---- | C] (PKWARE, Inc) -- C:\Documents and Settings\cg home\wdst.exe[2007/04/09 19:32:58 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ][3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ][1 C:\Documents and Settings\cg home\*.tmp files -> C:\Documents and Settings\cg home\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010/12/11 17:19:54 | 1073,299,456 | -HS- | M] () -- C:\hiberfil.sys[2010/12/11 17:19:53 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ][3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ][1 C:\Documents and Settings\cg home\*.tmp files -> C:\Documents and Settings\cg home\*.tmp -> ] ========== Files Created - No Company Name ========== [2010/12/11 17:19:54 | 1073,299,456 | -HS- | C] () -- C:\hiberfil.sys[2010/11/12 03:40:45 | 000,002,868 | ---- | C] () -- C:\WINDOWS\System32\GnuHashes.ini[2010/04/25 16:17:32 | 000,000,075 | ---- | C] () -- C:\Documents and Settings\cg home\jagex_runescape_preferences2.dat[2010/04/25 16:17:32 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\cg home\jagex__preferences3.dat[2010/04/25 16:16:15 | 000,000,041 | ---- | C] () -- C:\Documents and Settings\cg home\jagex_runescape_preferences.dat[2010/03/04 05:13:40 | 000,000,242 | ---- | C] () -- C:\WINDOWS\cdplayer.ini[2009/09/07 00:02:36 | 000,000,102 | ---- | C] () -- C:\Documents and Settings\cg home\sdk.bat[2009/06/23 17:34:24 | 000,044,032 | ---- | C] () -- C:\Documents and Settings\cg home\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2009/05/06 03:49:16 | 000,870,128 | ---- | C] () -- C:\Documents and Settings\Guest\Application Data\mcs.rma[2009/05/06 03:49:16 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Guest\Application Data\871B78[2009/04/07 02:45:20 | 000,000,653 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI[2009/04/07 02:34:08 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll[2009/04/02 08:13:07 | 000,000,098 | ---- | C] () -- C:\WINDOWS\topo4.INI[2009/02/26 07:19:46 | 000,043,080 | R--- | C] () -- C:\WINDOWS\System32\e10kxwdm.ini[2009/02/26 07:19:46 | 000,000,175 | R--- | C] () -- C:\WINDOWS\System32\ctzapxx.ini[2009/02/26 06:42:15 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll[2009/02/26 05:27:57 | 000,870,128 | ---- | C] () -- C:\Documents and Settings\cg home\Application Data\mcs.rma[2009/02/26 05:27:57 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\cg home\Application Data\871B78[2009/02/09 07:31:02 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI[2008/01/14 23:47:06 | 000,099,712 | ---- | C] () -- C:\WINDOWS\HPBroker.dll[2007/04/12 15:10:28 | 000,105,728 | ---- | C] () -- C:\WINDOWS\System32\APOMgrH.dll[2003/03/21 09:56:12 | 000,000,194 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI[2002/09/16 03:59:46 | 000,005,515 | ---- | C] () -- C:\WINDOWS\System32\ENSDEF.INI< End of report >Mod Edit: Since it has been a while since you first posted, use this topic as a new starting point. Hi there,Please rerun OTLPE, copy/paste the following text into the "custom scan/fix" field and click the NONE button. Then click Run Scan. Post me the resulting log (it will be a short one)./md5start

Gringo - as requested.

Old topic:


and here's the new problem:



Sandy Cormack

A:Gringo - Reopening Topic

Greetings And Welcome To The Forums!!My name is Gringo and I'll be glad to help you with your malware problems. I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of usPlease do not run any tools unless instructed to do so.
We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.Please do not attach logs or use code boxes, just copy and paste the text.
Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.Please read every post completely before doing anything.
Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.Please provide feedback about your experience as we go.
A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.NOTE: At... Read more

