1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Windows Vista Can't get laptop to boot?

Discussion in 'Legacy Windows' started by dodopie, 2014/01/25.

  1. 2014/01/31
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    well that didn't work either, i'll just have to get a disk and try that,i'll get one today
     
  2. 2014/01/31
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    hey now, i got the laptop to boot in safe mode and used system restore, its starting up great now, should i still run the fubar?
     

  3. to hide this advert.

  4. 2014/01/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good news :)
    What exactly did you do?
     
  5. 2014/01/31
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    I just tried again to start in safe mode and it did!!! I had tried many times and it just got stuck while the drives were loading but this time it fully loaded so I was able to use system restore. And now its working great, the problem was that optmizer startup scan changes the some of the startup files to windows8 so the system restore point must of change them back. You think I need to do anything else? I would still like to make a vista boot disk but cant seem to figure out how, I have downloaded the files from your link, the three plus the iso file but couldnt get them to work.
     
  6. 2014/01/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Let's take a look at your computer...

    Please download Farbar Recovery Scan Tool and save it to your Desktop.

    Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please copy and paste it to your reply.
     
  7. 2014/01/31
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-01-2014 01
    Ran by jerry (administrator) on JERRY-PC on 31-01-2014 12:34:30
    Running from C:\Users\jerry\Desktop
    Microsoft® Windows Vista™ Home Basic Service Pack 2 (X86) OS Language: English(US)
    Internet Explorer Version 9
    Boot Mode: Normal

    The only official download link for FRST:
    Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
    Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
    Download link from any site other than Bleeping Computer is unpermitted or outdated.
    See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) ===================

    (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
    (Microsoft Corporation) C:\Windows\System32\SLsvc.exe
    (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Systweak Software, (www.systweak.com)) C:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe
    () C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
    (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    (Motive Communications, Inc.) C:\Program Files\Common Files\Motive\McciCMService.exe
    () C:\ACER\Mobility Center\MobilityService.exe
    () C:\Program Files\Micro Innovations\Optical Scroll\mouse32a.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
    (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
    (Systweak Software, (www.systweak.com)) C:\Program Files\Advanced System Optimizer 3\ASO3.exe
    (Systweak) C:\Program Files\Advanced System Optimizer 3\SystemProtector.exe
    (Realtek Semiconductor Corp.) C:\Users\jerry\AppData\Local\temp\RtkBtMnt.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


    ==================== Registry (Whitelisted) ==================

    HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
    HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    HKLM\...\Run: [Acer Assist Launcher] - C:\Program Files\Acer\Acer Assist\launcher.exe [1261568 2007-11-19] ()
    HKLM\...\Run: [FLMOFFICE4DMOUSE] - C:\Program Files\Micro Innovations\Optical Scroll\mouse32a.exe [356352 2009-07-20] ()
    HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12017368 2013-10-24] (Realtek Semiconductor)
    HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [555352 2013-05-02] (Alps Electric Co., Ltd.)
    HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    Winlogon\Notify\!SASWinLogon: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [X]
    HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
    HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
    HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
    HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)

    ==================== Internet (Whitelisted) ====================

    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vb32&d=1208&m=aspire_5515
    SearchScopes: HKLM - DefaultScope value is missing.
    SearchScopes: HKCU - DefaultScope {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo.com/search?fr=mcafee&p={searchTerms}
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKCU - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL =
    SearchScopes: HKCU - {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo.com/search?fr=mcafee&p={searchTerms}
    BHO: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    BHO: Qualys BrowserCheck IE Helper - {7D2FB79E-E58C-4DB5-A36F-AC1C73967FA5} - C:\Windows\Downloaded Program Files\qbc_bho.dll (Qualys, Inc.)
    BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
    BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
    Toolbar: HKCU - WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
    ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File [ ]
    Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [223232] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll "
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

    FireFox:
    ========
    FF ProfilePath: C:\Users\jerry\AppData\Roaming\Mozilla\Firefox\Profiles\puk50b2z.default
    FF Homepage: hxxp://www.yahoo.com/|hxxp://www.yahoo.com/
    FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
    FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF Plugin: @realarcade.com/RAClient - C:\ProgramData\RealArcade\npraclient.dll No File
    FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
    FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
    FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll (Coupons, Inc.)
    FF Extension: No Name - C:\Users\jerry\AppData\Roaming\Mozilla\Firefox\Profiles\puk50b2z.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2013-09-13]

    ========================== Services (Whitelisted) =================

    R2 ASO3DiskOptimizer; C:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe [241448 2013-03-05] (Systweak Software, (www.systweak.com))
    R2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2008-11-28] ()
    R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-12-06] ()
    S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [x]
    S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [x]

    ==================== Drivers (Whitelisted) ====================

    S3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
    R0 ahcix86s; C:\Windows\System32\DRIVERS\ahcix86s.sys [129552 2008-08-06] (AMD Technologies Inc.)
    R1 DritekPortIO; C:\Program Files\Launch Manager\DPortIO.sys [20112 2006-11-02] (Dritek System Inc.)
    S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2009-01-26] (Printing Communications Assoc., Inc. (PCAUSA))
    S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation)
    S3 SQTECH905C; C:\Windows\System32\Drivers\Capt905c.sys [29056 2007-05-03] (Service & Quality Technology.)
    S3 USB_RNDIS_XP; C:\Windows\System32\DRIVERS\usb8023.sys [15872 2013-02-11] (Microsoft Corporation)
    U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)
    S3 MRESP50; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [x]

    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2014-01-31 12:34 - 2014-01-31 12:34 - 00009890 _____ C:\Users\jerry\Desktop\FRST.txt
    2014-01-31 12:33 - 2014-01-31 12:34 - 00000000 ___DC C:\FRST
    2014-01-31 12:33 - 2014-01-31 12:33 - 01137152 _____ (Farbar) C:\Users\jerry\Desktop\FRST.exe
    2014-01-31 11:41 - 2010-03-02 13:14 - 00038224 ____N (CANON INC.) C:\Windows\system32\IJRMF.exe
    2014-01-31 08:53 - 2014-01-31 08:53 - 00000000 _____ C:\Windows\setuperr.log
    2014-01-31 08:53 - 2014-01-31 08:53 - 00000000 _____ C:\Windows\setupact.log
    2014-01-31 08:47 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
    2014-01-31 08:47 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
    2014-01-31 08:47 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
    2014-01-31 08:47 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
    2014-01-17 08:22 - 2014-01-31 08:47 - 00005163 _____ C:\Windows\system32\jupdate-1.7.0_51-b13.log
    2014-01-08 18:53 - 2014-01-08 18:53 - 00000000 ____D C:\ProgramData\Support.com
    2014-01-08 09:14 - 2014-01-08 09:14 - 00000000 ____D C:\Users\jerry\AppData\Roaming\AVAST Software
    2014-01-01 10:40 - 2014-01-01 10:43 - 00000000 ____D C:\Program Files\Mozilla Firefox

    ==================== One Month Modified Files and Folders =======

    2014-01-31 12:34 - 2014-01-31 12:34 - 00009890 _____ C:\Users\jerry\Desktop\FRST.txt
    2014-01-31 12:34 - 2014-01-31 12:33 - 00000000 ___DC C:\FRST
    2014-01-31 12:33 - 2014-01-31 12:33 - 01137152 _____ (Farbar) C:\Users\jerry\Desktop\FRST.exe
    2014-01-31 12:14 - 2012-09-09 18:28 - 00000884 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-01-31 11:55 - 2012-09-09 07:33 - 00000000 ____D C:\ProgramData\AVG
    2014-01-31 11:47 - 2012-09-08 20:04 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2014-01-31 11:42 - 2013-07-04 18:23 - 00000622 _____ C:\Windows\wininit.ini
    2014-01-31 11:42 - 2012-04-15 12:28 - 00000000 ____D C:\Users\jerry\AppData\Local\ZEN Entertainment
    2014-01-31 11:41 - 2013-04-22 08:51 - 00000000 ____D C:\Users\jerry\AppData\Roaming\Canon
    2014-01-31 11:41 - 2006-11-02 07:35 - 00000000 ____D C:\Windows\twain_32
    2014-01-31 11:40 - 2013-06-02 11:51 - 00000000 ____D C:\Users\jerry\AppData\Roaming\Catalina – Print Savings
    2014-01-31 11:31 - 2009-02-04 18:19 - 00000000 ____D C:\Program Files\Common Files\DeLorme
    2014-01-31 11:21 - 2011-09-09 06:41 - 00000000 ____D C:\Users\jerry\AppData\Roaming\Skype
    2014-01-31 09:21 - 2013-07-05 08:12 - 01400918 _____ C:\Windows\WindowsUpdate.log
    2014-01-31 08:53 - 2014-01-31 08:53 - 00000000 _____ C:\Windows\setuperr.log
    2014-01-31 08:53 - 2014-01-31 08:53 - 00000000 _____ C:\Windows\setupact.log
    2014-01-31 08:52 - 2009-03-19 02:58 - 00000000 ____D C:\Windows\Minidump
    2014-01-31 08:47 - 2014-01-17 08:22 - 00005163 _____ C:\Windows\system32\jupdate-1.7.0_51-b13.log
    2014-01-31 08:47 - 2013-11-17 20:22 - 00000000 ____D C:\Program Files\Java
    2014-01-31 08:45 - 2006-11-02 05:33 - 00759408 _____ C:\Windows\system32\PerfStringBackup.INI
    2014-01-31 08:40 - 2006-11-02 07:45 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    2014-01-31 08:40 - 2006-11-02 07:45 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    2014-01-31 08:39 - 2013-07-05 08:07 - 00146000 _____ C:\Windows\PFRO.log
    2014-01-31 08:39 - 2013-05-27 06:02 - 00000368 _____ C:\Windows\Tasks\Sing Along Update.job
    2014-01-31 08:39 - 2012-09-09 18:28 - 00000880 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-01-31 08:39 - 2009-02-01 05:47 - 00000000 ____D C:\Users\jerry
    2014-01-31 08:39 - 2008-12-15 13:54 - 00000000 _____ C:\Windows\system32\LogConfigTemp.xml
    2014-01-31 08:39 - 2006-11-02 07:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2014-01-31 08:38 - 2013-06-28 16:23 - 00001660 _____ C:\Windows\system32\ASOROSet.bin
    2014-01-31 08:38 - 2006-11-02 05:22 - 50593792 _____ C:\Windows\system32\config\SOFTWARE.bak
    2014-01-31 08:38 - 2006-11-02 05:22 - 14417920 _____ C:\Windows\system32\config\SYSTEM.bak
    2014-01-31 08:38 - 2006-11-02 05:22 - 00024576 _____ C:\Windows\system32\config\SECURITY.bak
    2014-01-31 08:33 - 2006-11-02 05:22 - 00053248 _____ C:\Windows\system32\config\SAM.bak
    2014-01-31 08:31 - 2013-07-05 08:08 - 00032630 _____ C:\Windows\Tasks\SCHEDLGU.TXT
    2014-01-31 07:49 - 2013-07-12 07:22 - 00000000 ____D C:\Windows\system32\MRT
    2014-01-31 07:47 - 2006-11-02 05:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
    2014-01-31 07:36 - 2013-11-30 08:06 - 00000000 ____D C:\Users\jerry\{f2e4091b-e072-4e10-9328-aa465f9dd029}
    2014-01-31 07:36 - 2013-08-30 08:35 - 00000000 ____D C:\Users\jerry\{8b2037bf-bdd1-42aa-870c-a1b34c3a2ad0}
    2014-01-31 07:36 - 2011-11-21 19:55 - 00000000 ____D C:\Users\jerry\AppData\Roaming\Catalina Marketing Corp
    2014-01-31 07:36 - 2009-02-01 21:00 - 00000000 ____D C:\Users\jerry\AppData\Local\PokerStars
    2014-01-31 07:36 - 2009-02-01 07:04 - 00000000 ____D C:\Users\jerry\AppData\Local\PokerStars.NET
    2014-01-31 07:36 - 2009-02-01 05:47 - 00000000 ___RD C:\Users\jerry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2014-01-31 07:36 - 2009-02-01 05:47 - 00000000 ___RD C:\Users\jerry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2014-01-31 07:36 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\spool
    2014-01-31 07:36 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\Msdtc
    2014-01-31 07:36 - 2006-11-02 05:22 - 50593792 _____ C:\Windows\system32\config\software_previous
    2014-01-31 07:36 - 2006-11-02 05:22 - 38010880 _____ C:\Windows\system32\config\components_previous
    2014-01-31 07:36 - 2006-11-02 05:22 - 14417920 _____ C:\Windows\system32\config\system_previous
    2014-01-31 07:36 - 2006-11-02 05:22 - 04763648 _____ C:\Windows\system32\config\default_previous
    2014-01-31 07:36 - 2006-11-02 05:22 - 00053248 _____ C:\Windows\system32\config\sam_previous
    2014-01-31 07:36 - 2006-11-02 05:22 - 00024576 _____ C:\Windows\system32\config\security_previous
    2014-01-31 07:35 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\registration
    2014-01-18 10:18 - 2013-07-27 12:47 - 00004907 ____C C:\StartUpManager_scandataINPUT.xml
    2014-01-18 10:18 - 2013-07-27 12:47 - 00000000 ____C C:\StartUpManager_scandataOUTPUT.xml
    2014-01-17 15:55 - 2012-08-28 07:29 - 00000000 ____D C:\Users\jerry\Desktop\sales tax con
    2014-01-17 09:41 - 2013-09-18 11:12 - 00000000 ____D C:\ProgramData\Oracle
    2014-01-16 09:59 - 2009-10-02 19:54 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
    2014-01-09 06:27 - 2010-02-15 15:27 - 00001356 _____ C:\Users\jerry\AppData\Local\d3d9caps.dat
    2014-01-08 18:53 - 2014-01-08 18:53 - 00000000 ____D C:\ProgramData\Support.com
    2014-01-08 09:14 - 2014-01-08 09:14 - 00000000 ____D C:\Users\jerry\AppData\Roaming\AVAST Software
    2014-01-08 09:11 - 2012-09-09 18:08 - 00000000 ____D C:\ProgramData\AVAST Software
    2014-01-04 10:48 - 2013-09-13 15:53 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
    2014-01-04 10:46 - 2013-06-28 07:06 - 00000406 _____ C:\Windows\Tasks\ASO-OneClickCare.job
    2014-01-03 18:26 - 2013-10-10 18:36 - 00000000 ____D C:\Users\jerry\Desktop\Art Diss
    2014-01-03 08:33 - 2013-06-28 07:06 - 00000436 _____ C:\Windows\Tasks\ASO-AutoCheckUpdate7Days.job
    2014-01-02 22:27 - 2009-02-04 21:24 - 00001022 _____ C:\Users\jerry\Desktop\startup.sa8
    2014-01-01 10:43 - 2014-01-01 10:40 - 00000000 ____D C:\Program Files\Mozilla Firefox

    Some content of TEMP:
    ====================
    C:\Users\jerry\AppData\Local\temp\Maint000.exe
    C:\Users\jerry\AppData\Local\temp\Maint001.exe
    C:\Users\jerry\AppData\Local\temp\Maint002.exe
    C:\Users\jerry\AppData\Local\temp\RtkBtMnt.exe
    C:\Users\jerry\AppData\Local\temp\uninst.exe


    ==================== Bamital & volsnap Check =================

    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\system32\winlogon.exe => MD5 is legit
    C:\Windows\system32\wininit.exe => MD5 is legit
    C:\Windows\system32\svchost.exe => MD5 is legit
    C:\Windows\system32\services.exe => MD5 is legit
    C:\Windows\system32\User32.dll => MD5 is legit
    C:\Windows\system32\userinit.exe => MD5 is legit
    C:\Windows\system32\rpcss.dll => MD5 is legit
    C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


    LastRegBack: 2014-01-31 08:45

    ==================== End Of Log ============================
     
  8. 2014/01/31
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-01-2014 01
    Ran by jerry at 2014-01-31 12:35:17
    Running from C:\Users\jerry\Desktop
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    Acer Assist (Version: - Acer Incorporated)
    Acer Empowering Technology (Version: 3.0.3013 - Acer Incorporated)
    Acer eRecovery Management (Version: 3.0.3014 - Acer Incorporated)
    Acer Mobility Center Plug-In (Version: 3.0.3000 - Acer Inc.)
    Acer Registration (Version: - Acer - Leader Technologies)
    Acrobat.com (Version: 2.0.0 - Adobe Systems Incorporated) Hidden
    Acrobat.com (Version: 2.0.0.0 - Adobe Systems Incorporated)
    Adobe Flash Player 11 ActiveX (Version: 11.9.900.170 - Adobe Systems Incorporated)
    Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated)
    Adobe Reader X (10.1.9) (Version: 10.1.9 - Adobe Systems Incorporated)
    Advanced System Optimizer (Version: 3.5.1000.15013 - Systweak Software)
    Aloha Solitaire (Version: 3.3.4.81 - Yahoo) Hidden
    Apple Application Support (Version: 2.3.4 - Apple Inc.)
    Apple Mobile Device Support (Version: 3.4.1.2 - Apple Inc.)
    Apple Software Update (Version: 2.1.3.127 - Apple Inc.)
    ArcSoft VideoImpression 2 (Version: - ArcSoft)
    Atheros Driver Installation Program (Version: 10.0 - Atheros)
    ATI Catalyst Install Manager (Version: 3.0.682.0 - ATI Technologies, Inc.)
    ATT-PRT22 (Version: - )
    BellSouth FastAccess DSL Help Center (Version: - )
    Catalyst Control Center Core Implementation (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Graphics Full Existing (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Graphics Full New (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Graphics Light (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Graphics Previews Vista (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center InstallProxy (Version: 2008.0703.2236.38526 - ATI Technologies, Inc.) Hidden
    Catalyst Control Center Localization Chinese Standard (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Chinese Traditional (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Czech (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Danish (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Dutch (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Finnish (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization French (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization German (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Greek (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Hungarian (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Italian (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Japanese (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Korean (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Norwegian (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Polish (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Portuguese (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Russian (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Spanish (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Swedish (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Thai (Version: 2008.0703.2236.38526 - ATI) Hidden
    Catalyst Control Center Localization Turkish (Version: 2008.0703.2236.38526 - ATI) Hidden
    CCC Help Chinese Standard (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Chinese Traditional (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Czech (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Danish (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Dutch (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help English (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Finnish (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help French (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help German (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Greek (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Hungarian (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Italian (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Japanese (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Korean (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Norwegian (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Polish (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Portuguese (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Russian (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Spanish (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Swedish (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Thai (Version: 2008.0703.2235.38526 - ATI) Hidden
    CCC Help Turkish (Version: 2008.0703.2235.38526 - ATI) Hidden
    ccc-core-static (Version: 2008.0703.2236.38526 - ATI) Hidden
    ccc-utility (Version: 2008.0703.2236.38526 - ATI) Hidden
    Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000 - Microsoft Corporation)
    Coupon Printer for Windows (Version: 5.0.0.4 - Coupons.com Incorporated) <==== ATTENTION
    Dell Touchpad (Version: 8.1200.101.129 - ALPS ELECTRIC CO., LTD.)
    Google Update Helper (Version: 1.3.21.153 - Google Inc.) Hidden
    InterVideo WinDVD 8 (Version: 8.0-B9.574 - InterVideo Inc.)
    InterVideo WinDVD 8 (Version: 8.0-B9.574 - InterVideo Inc.) Hidden
    Java 7 Update 51 (Version: 7.0.510 - Oracle)
    Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
    Launch Manager (Version: - )
    Lernout & Hauspie TruVoice American English TTS Engine (Version: - )
    LightScribe 1.4.142.1 (Version: 1.4.142.1 - http://www.lightscribe.com) Hidden
    Micro Innovations Optical Scroll Mouse (Version: - )
    Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation)
    Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
    Microsoft Office 2000 Small Business (Version: 9.00.2720 - Microsoft Corporation)
    Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
    Microsoft VC9 runtime libraries (Version: 2.0.0 - AOL Inc.) Hidden
    Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual J# 2.0 Redistributable Package (Version: - Microsoft Corporation)
    Microsoft Visual J# 2.0 Redistributable Package (Version: 2.0.50727 - Microsoft Corporation) Hidden
    Microsoft Works (Version: 08.05.0818 - Microsoft Corporation)
    Mozilla Firefox 26.0 (x86 en-US) (Version: 26.0 - Mozilla)
    Mozilla Maintenance Service (Version: 26.0 - Mozilla)
    MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (Version: 4.30.2100.0 - Microsoft Corporation)
    MyDSC2 (Version: 1.0 - My Company Name)
    Orion (Version: 2.0.1 - Convesoft)
    Primo (Version: 1.00.0000 - Your Company Name) Hidden
    QuickTime (Version: 7.74.80.86 - Apple Inc.)
    Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000 - Realtek)
    Realtek High Definition Audio Driver (Version: 6.0.1.7083 - Realtek Semiconductor Corp.)
    Runtime (Version: 1.00.0000 - Your Company Name) Hidden
    Skins (Version: 2008.0703.2236.38526 - ATI) Hidden
    Skype™ 6.11 (Version: 6.11.102 - Skype Technologies S.A.)
    swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
    Synaptics Pointing Device Driver (Version: 11.0.2.0 - Synaptics)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation)
    WOT for Internet Explorer (Version: 11.11.7.0 - WOT Services Oy)
    WOT for Internet Explorer (Version: 12.8.2.0 - WOT Services Oy)

    ==================== Restore Points =========================

    08-01-2014 14:12:10 avast! antivirus system restore point
    09-01-2014 14:01:08 Advanced System Optimizer
    09-01-2014 14:02:36 System Protector
    17-01-2014 01:06:44 avast! antivirus system restore point
    17-01-2014 13:19:47 Installed Java 7 Update 51
    17-01-2014 13:28:12 Windows Update
    17-01-2014 14:41:44 Windows Update
    18-01-2014 13:03:30 Advanced System Optimizer
    18-01-2014 13:05:19 System Protector
    31-01-2014 12:46:44 Windows Update
    31-01-2014 13:28:16 Advanced System Optimizer
    31-01-2014 13:29:54 System Protector
    31-01-2014 13:45:44 Installed Java 7 Update 51
    31-01-2014 16:25:23 Removed Microsoft Office Suite Activation Assistant.
    31-01-2014 16:28:27 削除 PlayMemories Home
    31-01-2014 16:40:13 Removed Catalina Savings Printer.

    ==================== Hosts content: ==========================

    2006-11-02 05:23 - 2013-05-29 17:55 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
    127.0.0.1 localhost

    ==================== Scheduled Tasks (whitelisted) =============

    Task: {0D5F8BE1-DEDC-4D4F-B95E-46F6AE5F2DC9} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-20] (Microsoft Corporation)
    Task: {18DFD9FC-082E-4E9B-8285-5F21D2B4EDAE} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
    Task: {1AC7A2FA-3698-4EAC-8862-9E8613062404} - System32\Tasks\{84C8645D-400E-41DE-8A4C-C50ED9F7263F} => Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/en/abandoninstall?page=tsProgressBar
    Task: {280AB5B2-1D4D-49EB-825E-655AFBCB2C05} - System32\Tasks\{561AABAD-EC03-4DF5-8E6A-C796A74DC967} => Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/en/abandoninstall?page=tsProgressBar
    Task: {2C89644E-28D8-4A66-A751-0B70A9BCABA4} - System32\Tasks\ASO-OneClickCare => C:\Program Files\Advanced System Optimizer 3\ASO3.exe [2013-03-05] (Systweak Software, (www.systweak.com))
    Task: {319FAA35-39D0-4A64-9E60-FADBA053ECC0} - System32\Tasks\{2E01B050-13EA-4E90-9E34-552E5F081546} => Iexplore.exe http://www.skype.com/go/downloading?source=lightinstaller&amp;ver=5.5.0.115&amp;LastError=404
    Task: {3373E415-DEA2-40F6-AB2A-4BAB660F3BA9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: {35DC3170-48C0-416A-8F27-C67A1C078855} - System32\Tasks\Vista Task Low => C:\Program Files\RealArcade\RealArcade.exe
    Task: {4932FF85-9349-4172-A3FE-42256E190335} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
    Task: {5916F864-469C-4391-8604-E4EA141A2699} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-20] ()
    Task: {72FF4B8A-796B-4DD1-A5CD-A21F026F7A8D} - System32\Tasks\Sing Along Update => C:\Program Files\SingAlong\SingalngUpdater.exe
    Task: {755F698D-CB30-4468-A4B0-9BB82BB56817} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated)
    Task: {797AE97D-84A6-4959-B880-EEDB90500E43} - System32\Tasks\{F3BF0C87-3AC7-4781-A042-67E7E429B834} => Iexplore.exe http://ui.skype.com/ui/0/6.5.0.158/en/go/help.faq.installer?LastError=1601
    Task: {7C5A51E8-1AD7-48C6-8879-257A8A9609F5} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
    Task: {8B0E6FAB-F43A-4988-AF0A-A21646C212F0} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
    Task: {9570FF52-BF93-442B-8B01-D86088F67142} - System32\Tasks\{360EC6A6-9926-4265-8585-00CCEE4D7C66} => Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/en/abandoninstall?page=tsProgressBar
    Task: {96CB783E-7AA4-442D-B326-4DBAB8B41263} - System32\Tasks\ASO-System Protector_startup => C:\Program Files\Advanced System Optimizer 3\SystemProtector.exe [2013-03-05] (Systweak)
    Task: {9ED703A9-5FFD-40D5-895A-4385EE1509DE} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-20] (Microsoft Corporation)
    Task: {A9430656-1D09-44F2-B94C-56436A836861} - System32\Tasks\{A4900B3F-AEB6-46E9-96AB-67B45B1D403D} => Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/en/abandoninstall?page=tsProgressBar
    Task: {CE228C9E-1CB1-4D09-B149-FEEB9357D2CF} - System32\Tasks\ASO-AutoCheckUpdate7Days => C:\Program Files\Advanced System Optimizer 3\CheckUpdate.exe [2013-03-05] (Systweak Software, (www.systweak.com))
    Task: {CED54B03-2C14-4E98-8B1D-BE5497F97991} - System32\Tasks\{ACBDADBA-FBBB-4ADA-9140-D4330122C586} => Iexplore.exe http://ui.skype.com/ui/0/6.1.0.129.272/en/abandoninstall?page=tsProgressBar
    Task: {CF4BFC00-B8A6-4357-A63E-DB152A19BFD9} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1182583647-3259410284-1344731716-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
    Task: {D11AAE5F-0543-4EA5-BF99-7C086F138423} - System32\Tasks\{0CDFB3CE-889E-4F59-8157-D1535BB4AD2F} => Iexplore.exe http://ui.skype.com/ui/0/5.8.0.158/en/abandoninstall?page=tsProgressBar
    Task: {D7448C71-F100-4161-9B4E-9C15EAD04710} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1182583647-3259410284-1344731716-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
    Task: {DE0A494E-3AA1-4CC5-980E-82AD4EDFB88D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: {E42D976B-9509-4289-87ED-0162E8DF7DC4} - System32\Tasks\{51A40FF1-D481-4BB8-9812-321A4F77DB89} => Iexplore.exe http://ui.skype.com/ui/0/5.8.0.158/en/abandoninstall?page=tsProgressBar
    Task: {FE8F5F51-5741-4E3E-8A86-7F9ED76C40F8} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\ASO-AutoCheckUpdate7Days.job => C:\Program Files\Advanced System Optimizer 3\CheckUpdate.exe
    Task: C:\Windows\Tasks\ASO-OneClickCare.job => C:\Program Files\Advanced System Optimizer 3\ASO3.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\Sing Along Update.job => C:\Program Files\SingAlong\SingalngUpdater.exe

    ==================== Loaded Modules (whitelisted) =============

    2009-07-20 17:10 - 2009-07-20 17:09 - 00073728 _____ () C:\Program Files\Micro Innovations\Optical Scroll\MOUDL32A.DLL
    2013-06-28 07:04 - 2013-03-05 15:55 - 00325928 _____ () C:\Program Files\Advanced System Optimizer 3\asohtm.dll
    2008-12-04 06:05 - 2008-07-03 22:37 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll
    2013-06-28 07:04 - 2011-11-11 17:22 - 00886272 _____ () C:\Program Files\Advanced System Optimizer 3\System.Data.SQLite.dll

    ==================== Alternate Data Streams (whitelisted) =========

    AlternateDataStreams: C:\ProgramData\TEMP:3AE23B30

    ==================== Safe Mode (whitelisted) ===================

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => " "= "Driver "
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ntrexeservice => " "= "Service "
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => " "= "Driver "

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (01/31/2014 11:24:30 AM) (Source: Application Hang) (User: )
    Description: The program hcenter.exe version 6.1.35.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
    Process ID: a94
    Start Time: 01cf1ea0d400b310
    Termination Time: 102

    Error: (01/31/2014 11:22:39 AM) (Source: Application Hang) (User: )
    Description: The program hcenter.exe version 6.1.35.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
    Process ID: 4a0
    Start Time: 01cf1e8a83992085
    Termination Time: 8

    Error: (01/31/2014 09:02:47 AM) (Source: Windows Search Service) (User: )
    Description: The entry <C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\TEMP> in the hash map cannot be updated.

    Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)

    Error: (01/31/2014 09:02:07 AM) (Source: Windows Search Service) (User: )
    Description: The entry <C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\SETTINGS.DB> in the hash map cannot be updated.

    Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)

    Error: (01/31/2014 09:02:03 AM) (Source: Windows Search Service) (User: )
    Description: The entry <C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\UPDATE.INI> in the hash map cannot be updated.

    Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)

    Error: (01/31/2014 09:02:03 AM) (Source: Windows Search Service) (User: )
    Description: The entry <C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\UPDATE.INI> in the hash map cannot be updated.

    Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)

    Error: (01/31/2014 08:52:26 AM) (Source: Windows Search Service) (User: )
    Description: The entry <C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\UPDATE.INI> in the hash map cannot be updated.

    Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)

    Error: (01/31/2014 08:52:26 AM) (Source: Windows Search Service) (User: )
    Description: The entry <C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\UPDATE.INI> in the hash map cannot be updated.

    Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)

    Error: (01/31/2014 08:52:07 AM) (Source: Windows Search Service) (User: )
    Description: The entry <C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\SETTINGS.DB> in the hash map cannot be updated.

    Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)

    Error: (01/31/2014 08:52:07 AM) (Source: Windows Search Service) (User: )
    Description: The entry <C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\SETTINGS.DB> in the hash map cannot be updated.

    Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)


    System errors:
    =============
    Error: (01/31/2014 08:41:30 AM) (Source: Service Control Manager) (User: )
    Description: Google Update Service (gupdate)%%2

    Error: (01/31/2014 08:40:41 AM) (Source: Service Control Manager) (User: )
    Description: Parallel port driver%%1058

    Error: (01/31/2014 08:01:17 AM) (Source: Service Control Manager) (User: )
    Description: Google Update Service (gupdate)%%2

    Error: (01/31/2014 08:00:11 AM) (Source: Service Control Manager) (User: )
    Description: Parallel port driver%%1058

    Error: (01/31/2014 07:56:50 AM) (Source: Service Control Manager) (User: )
    Description: Ati External Event Utility1

    Error: (01/31/2014 07:52:54 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
    Description: 0x80070643Definition Update for Windows Defender - KB915597 (Definition 1.165.3009.0){0FDF4C23-F6BB-4B51-B809-D725FEBF8CC1}200

    Error: (01/31/2014 07:51:31 AM) (Source: WinDefend) (User: )
    Description: %%%82527 has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.

    Signatures Attempted: %%%82524

    Error Code: 0x8050a001

    Error description: The program can't find definition files that help detect unwanted software. Check for updates to the definition files, and then try again. For information on installing updates, see Help and Support.

    Signatures loading: %%825

    Loading signature version: 1.165.1564.0

    Loading engine version: %%%825270

    Error: (01/31/2014 07:43:38 AM) (Source: DCOM) (User: )
    Description: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D}

    Error: (01/31/2014 07:43:09 AM) (Source: Service Control Manager) (User: )
    Description: Windows Update

    Error: (01/31/2014 07:42:35 AM) (Source: Service Control Manager) (User: )
    Description: Windows Search%%1053


    Microsoft Office Sessions:
    =========================
    Error: (01/31/2014 11:24:30 AM) (Source: Application Hang)(User: )
    Description: hcenter.exe6.1.35.0a9401cf1ea0d400b310102

    Error: (01/31/2014 11:22:39 AM) (Source: Application Hang)(User: )
    Description: hcenter.exe6.1.35.04a001cf1e8a839920858

    Error: (01/31/2014 09:02:47 AM) (Source: Windows Search Service)(User: )
    Description: Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)
    C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\TEMP

    Error: (01/31/2014 09:02:07 AM) (Source: Windows Search Service)(User: )
    Description: Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)
    C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\SETTINGS.DB

    Error: (01/31/2014 09:02:03 AM) (Source: Windows Search Service)(User: )
    Description: Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)
    C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\UPDATE.INI

    Error: (01/31/2014 09:02:03 AM) (Source: Windows Search Service)(User: )
    Description: Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)
    C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\UPDATE.INI

    Error: (01/31/2014 08:52:26 AM) (Source: Windows Search Service)(User: )
    Description: Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)
    C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\UPDATE.INI

    Error: (01/31/2014 08:52:26 AM) (Source: Windows Search Service)(User: )
    Description: Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)
    C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\UPDATE.INI

    Error: (01/31/2014 08:52:07 AM) (Source: Windows Search Service)(User: )
    Description: Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)
    C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\SETTINGS.DB

    Error: (01/31/2014 08:52:07 AM) (Source: Windows Search Service)(User: )
    Description: Context: Application, SystemIndex Catalog


    Details:
    A device attached to the system is not functioning. (0x8007001f)
    C:\USERS\JERRY\APPDATA\ROAMING\SYSTWEAK\ADVANCED SYSTEM PROTECTOR\SETTINGS.DB


    CodeIntegrity Errors:
    ===================================
    Date: 2012-09-09 18:19:45.199
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG2013\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

    Date: 2012-09-09 18:19:44.713
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG2013\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

    Date: 2012-09-09 18:19:44.224
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG2013\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

    Date: 2012-09-09 18:19:43.713
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG2013\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

    Date: 2012-09-09 18:19:40.302
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG2013\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.

    Date: 2012-09-09 18:19:39.712
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG2013\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.

    Date: 2012-09-09 18:19:39.157
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG2013\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.

    Date: 2012-09-09 18:19:38.589
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG2013\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.

    Date: 2012-09-08 22:44:37.400
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

    Date: 2012-09-08 22:44:36.296
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    Percentage of memory in use: 46%
    Total physical RAM: 2813.25 MB
    Available physical RAM: 1511.77 MB
    Total Pagefile: 5865.06 MB
    Available Pagefile: 4695.7 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1927.92 MB

    ==================== Drives ================================

    Drive c: (ACER) (Fixed) (Total:69.52 GB) (Free:28.57 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
    Drive d: () (Fixed) (Total:69.52 GB) (Free:69.34 GB) NTFS
    Drive f: () (Removable) (Total:7.21 GB) (Free:7.21 GB) FAT32

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 149 GB) (Disk ID: B63EE216)
    Partition 1: (Not Active) - (Size=10 GB) - (Type=27)
    Partition 2: (Active) - (Size=70 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=70 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (MBR Code: Windows 7 or 8) (Size: 7 GB) (Disk ID: 597E7343)
    Partition 1: (Active) - (Size=7 GB) - (Type=0B)

    ==================== End Of Log ============================
     
  9. 2014/01/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Looks OK.

    1. Uninstall Advanced System Optimizer 3 - by now you know why.

    2. I don't see any AV program running.
    Install ONE of these:

    - Avast! free antivirus: http://www.avast.com/eng/download-avast-home.html

    - free Microsoft Security Essentials: http://windows.microsoft.com/en-GB/windows/products/security-essentials
    Note for Windows 8 users: Microsoft Security Essentials comes preinstalled and renamed as Windows Defender.
    You can keep it or you have to disable it before installing another AV program. How to...

    - free Comodo Antivirus: http://www.comodo.com/home/internet-security/antivirus.php

    3. Create an image of your hard drive in case you run into similar issue again.
    Acronis True Image: http://www.acronis.com/ - not free, but the best

    Free alternatives:
    - Macrium Reflect: http://www.macrium.com/ReflectFree.asp
    - DriveImage XML: http://www.runtime.org/driveimage-xml.htm (tutorial: http://www.bleepingcomputer.com/tutorials/tutorial160.html)
    - SelfImage: http://www.excelcia.org/modules.php?name=News&file=article&sid=21
    - Paragon Drive Backup: http://www.paragon-software.com/home/db-express/
     
  10. 2014/01/31
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    ok, i re downloaded avast and tried microsoft security essentials, while installing i get this: if you have other antivirus it may conflict with mse recomend removing the other antivirus

    So what to do?
     
  11. 2014/01/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I clearly said:

    You can't be running two AV programs.
     
  12. 2014/02/01
    dodopie Contributing Member

    dodopie Well-Known Member Thread Starter

    Joined:
    2010/12/26
    Messages:
    458
    Likes Received:
    2
    ok, thanks for all your help
     
  13. 2014/02/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome [​IMG]
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.