SHOP PRODUCTS
Houzz Logo Print
lynnalexandra

Now Troubleshooting DD's laptop - Soooo Slow

lynnalexandra
10 years ago

My efforts this weekend with my own laptop - and Joe's incredible help and generosity - has spurred me to tackling my daughter's laptop. Previously she had not wanted me near it (personal emails, chats, etc she didn't want me to see). When she saw what I accomplished on my laptop, she asked me to help her. Well - hers is even worse. Not sure there are bad software programs installed like mine. I can't even open explorer yet - but I'm sure a good deal of the problem is a hard drive that's too full. Every action I tried to take on this laptop took forever. CPU usage was low. Physical memory was about 40-50% (not sure what that means).

Her computer is a Dell Inspiron, intel i5 processor, Windows 7. The computer is just under 2 1/2 years old. I know I should get more info but every action takes so much time, I'm going to start with running some of the diagnostics.

She also way too many things at start up (it took her somewhere between 10-25 minutes to start). (Her laptop is similar to my Dell at work - so I think she also has an outdated wireless driver - but that fix is down the road). I think I've learned a lot about where to start. I'm going to run some of the programs I ran when troubleshooting my laptop.

I'll do minitoolbox, Hijackthis, DDS, WinDirStat, TFC cleaner. But since this computer is so slow, I may be doing one at a time. Trying to run minitoolbox now. It's taking some time.

MiniToolBox by Farbar Version: 13-07-2013
Ran by haha (administrator) on 03-09-2013 at 09:55:38
Running from "C:\Users\haha\Downloads"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************
========================= IP Configuration: ================================

Intel(R) Centrino(R) Wireless-N 1030 = Wireless Network Connection (Connected)
Realtek PCIe FE Family Controller = Local Area Connection (Media disconnected)
Bluetooth Device (Personal Area Network) = Bluetooth Network Connection (Media disconnected)
Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected)

# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled
add route prefix=169.254.0.0/16 interface="iftype0_0" nexthop=192.168.1.105 metric=1 publish=Yes

popd
# End of IPv4 configuration


Windows IP Configuration

Host Name . . . . . . . . . . . . : KyraLaptop-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : hsd1.dc.comcast.net.

Wireless LAN adapter Wireless Network Connection 2:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter
Physical Address. . . . . . . . . : BC-77-37-38-72-10
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Ethernet adapter Bluetooth Network Connection:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network)
Physical Address. . . . . . . . . : BC-77-37-38-72-13
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : hsd1.dc.comcast.net.
Description . . . . . . . . . . . : Realtek PCIe FE Family Controller
Physical Address. . . . . . . . . : 14-FE-B5-A5-20-96
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wireless Network Connection:

Connection-specific DNS Suffix . : hsd1.dc.comcast.net.
Description . . . . . . . . . . . : Intel(R) Centrino(R) Wireless-N 1030
Physical Address. . . . . . . . . : BC-77-37-38-72-0F
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2601:a:3d00:7c:b8a6:16d4:32a:5c84(Preferred)
Temporary IPv6 Address. . . . . . : 2601:a:3d00:7c:1c2e:a7ed:d0f4:120d(Preferred)
Link-local IPv6 Address . . . . . : fe80::b8a6:16d4:32a:5c84%10(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.139(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Monday, September 02, 2013 3:23:27 PM
Lease Expires . . . . . . . . . . : Wednesday, September 04, 2013 9:46:20 AM
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DHCPv6 IAID . . . . . . . . . . . : 196900663
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-39-82-54-14-FE-B5-A5-20-96
DNS Servers . . . . . . . . . . . : 75.75.75.75
75.75.76.76
192.168.1.1
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter Local Area Connection* 16:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft 6to4 Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.hsd1.dc.comcast.net.:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : hsd1.dc.comcast.net.
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.(90F8D9F9-677F-42AE-BDBE-7AFAE71A0532):

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #4
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.(F249B192-7D7D-4F41-B2C8-79A4222BF98B):

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #6
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: cdns01.comcast.net
Address: 75.75.75.75

Name: google.com
Addresses: 2607:f8b0:4004:801::1002
74.125.228.46
74.125.228.39
74.125.228.38
74.125.228.34
74.125.228.37
74.125.228.40
74.125.228.35
74.125.228.36
74.125.228.32
74.125.228.33
74.125.228.41

Pinging google.com [74.125.228.0] with 32 bytes of data:
Reply from 74.125.228.0: bytes=32 time=17ms TTL=55
Reply from 74.125.228.0: bytes=32 time=17ms TTL=55

Ping statistics for 74.125.228.0:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 17ms, Maximum = 17ms, Average = 17ms
Server: cdns01.comcast.net
Address: 75.75.75.75

Name: yahoo.com
Addresses: 206.190.36.45
98.138.253.109
98.139.183.24

Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=99ms TTL=51
Reply from 98.139.183.24: bytes=32 time=110ms TTL=51

Ping statistics for 98.139.183.24:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 99ms, Maximum = 110ms, Average = 104ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 timeReply from 127.0.0.1: bytes=32 timePing statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
15...bc 77 37 38 72 10 ......Microsoft Virtual WiFi Miniport Adapter
14...bc 77 37 38 72 13 ......Bluetooth Device (Personal Area Network)
11...14 fe b5 a5 20 96 ......Realtek PCIe FE Family Controller
10...bc 77 37 38 72 0f ......Intel(R) Centrino(R) Wireless-N 1030
1...........................Software Loopback Interface 1
12...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
22...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
20...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #4
21...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #6
18...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.139 25
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
169.254.0.0 255.255.0.0 192.168.1.105 192.168.1.139 26
192.168.1.0 255.255.255.0 On-link 192.168.1.139 281
192.168.1.139 255.255.255.255 On-link 192.168.1.139 281
192.168.1.255 255.255.255.255 On-link 192.168.1.139 281
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.1.139 281
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.1.139 281
===========================================================================
Persistent Routes:
Network Address Netmask Gateway Address Metric
169.254.0.0 255.255.0.0 192.168.1.105 1
===========================================================================

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
10 33 2601:a:3d00:7c::/64 On-link
10 41 2601:a:3d00:7c::/64 fe80::5a6d:8fff:fe73:8026
10 281 2601:a:3d00:7c:1c2e:a7ed:d0f4:120d/128
On-link
10 281 2601:a:3d00:7c:b8a6:16d4:32a:5c84/128
On-link
10 281 fe80::/64 On-link
10 281 fe80::b8a6:16d4:32a:5c84/128
On-link
1 306 ff00::/8 On-link
10 281 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\wshbth.dll [36352] (Microsoft Corporation)
Catalog5 06 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 09 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 10 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\wshbth.dll [47104] (Microsoft Corporation)
x64-Catalog5 06 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 09 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (09/03/2013 09:01:31 AM) (Source: Application Hang) (User: )
Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: ba4

Start Time: 01cea8231b43b4a7

Termination Time: 0

Application Path: C:\Windows\Explorer.EXE

Report Id:

Error: (09/02/2013 06:28:47 PM) (Source: Application Error) (User: )
Description: Faulting application name: dw20.exe, version: 2.0.50727.4927, time stamp: 0x4a2746a4
Faulting module name: ntdll.dll, version: 6.1.7601.18205, time stamp: 0x51dba4e7
Exception code: 0xc015000f
Fault offset: 0x000000000006fcec
Faulting process id: 0xefc
Faulting application start time: 0xdw20.exe0
Faulting application path: dw20.exe1
Faulting module path: dw20.exe2
Report Id: dw20.exe3

Error: (09/02/2013 06:07:49 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT AUTHORITY)
Description: The performance counter name string value in the registry is not formatted correctly. The malformed string is ???????I???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????�?????????????????e???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????n???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????G????????u??????�:????????�?????????????????????????????????????????????????????????????????????????????????????????????????�???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????@??????????????!?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????�?????????????????????????????????O?????????????. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values.

Error: (09/02/2013 06:02:18 PM) (Source: Application Error) (User: )
Description: Windows cannot access the file C:\Windows\SysWOW64\msi.dll for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Adobe Reader and Acrobat Manager because of this error.

Program: Adobe Reader and Acrobat Manager
File: C:\Windows\SysWOW64\msi.dll

The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.

Additional Data
Error value: C00000B5
Disk type: 3

Error: (09/02/2013 06:02:18 PM) (Source: Application Error) (User: )
Description: Faulting application name: AdobeARM.exe, version: 1.7.4.0, time stamp: 0x515deb31
Faulting module name: msi.dll, version: 5.0.7601.17807, time stamp: 0x4f802294
Exception code: 0xc0000006
Fault offset: 0x00183902
Faulting process id: 0xd88
Faulting application start time: 0xAdobeARM.exe0
Faulting application path: AdobeARM.exe1
Faulting module path: AdobeARM.exe2
Report Id: AdobeARM.exe3

Error: (09/02/2013 05:55:30 PM) (Source: Application Error) (User: )
Description: Windows cannot access the file C:\Windows\System32\riched20.dll for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Microsoft .NET Error Reporting Shim because of this error.

Program: Microsoft .NET Error Reporting Shim
File: C:\Windows\System32\riched20.dll

The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.

Additional Data
Error value: C00000B5
Disk type: 3

Error: (09/02/2013 05:55:30 PM) (Source: Application Error) (User: )
Description: Faulting application name: dw20.exe, version: 2.0.50727.4927, time stamp: 0x4a2746a4
Faulting module name: RICHED20.DLL, version: 5.31.23.1230, time stamp: 0x4ce7c991
Exception code: 0xc0000006
Fault offset: 0x00000000000427b0
Faulting process id: 0xefc
Faulting application start time: 0xdw20.exe0
Faulting application path: dw20.exe1
Faulting module path: dw20.exe2
Report Id: dw20.exe3

Error: (09/02/2013 05:26:34 PM) (Source: Application Error) (User: )
Description: Faulting application name: DSUpd.exe, version: 2.0.0.18, time stamp: 0x4be1cfbd
Faulting module name: mscorwks.dll, version: 2.0.50727.5472, time stamp: 0x5174ddb3
Exception code: 0xc0000006
Fault offset: 0x000000000062f3e0
Faulting process id: 0x%9
Faulting application start time: 0xDSUpd.exe0
Faulting application path: DSUpd.exe1
Faulting module path: DSUpd.exe2
Report Id: DSUpd.exe3

Error: (09/02/2013 05:26:34 PM) (Source: Application Error) (User: )
Description: Faulting application name: GfxUI.exe, version: 8.15.10.2253, time stamp: 0x4cf32fe2
Faulting module name: mscorwks.dll, version: 2.0.50727.5472, time stamp: 0x5174ddb3
Exception code: 0xc0000006
Fault offset: 0x000000000044e65c
Faulting process id: 0x%9
Faulting application start time: 0xGfxUI.exe0
Faulting application path: GfxUI.exe1
Faulting module path: GfxUI.exe2
Report Id: GfxUI.exe3

Error: (09/02/2013 05:26:34 PM) (Source: .NET Runtime) (User: )
Description: .NET Runtime version 2.0.50727.5472 - Fatal Execution Engine Error (715EF7AE) (80131506)

System errors:
=============
Error: (09/03/2013 09:37:00 AM) (Source: iaStor) (User: )
Description: The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Error: (09/03/2013 09:18:08 AM) (Source: Ntfs) (User: )
Description: The file system structure on the disk is corrupt and unusable.
Please run the chkdsk utility on the volume OS.

Error: (09/03/2013 09:18:07 AM) (Source: Ntfs) (User: )
Description: The file system structure on the disk is corrupt and unusable.
Please run the chkdsk utility on the volume OS.

Error: (09/03/2013 09:14:05 AM) (Source: Ntfs) (User: )
Description: The file system structure on the disk is corrupt and unusable.
Please run the chkdsk utility on the volume OS.

Error: (09/03/2013 09:12:45 AM) (Source: Ntfs) (User: )
Description: The file system structure on the disk is corrupt and unusable.
Please run the chkdsk utility on the volume OS.

Error: (09/03/2013 09:06:47 AM) (Source: DCOM) (User: )
Description: (995C996E-D918-4A8C-A302-45719A6F4EA7)

Error: (09/03/2013 08:51:09 AM) (Source: Ntfs) (User: )
Description: The file system structure on the disk is corrupt and unusable.
Please run the chkdsk utility on the volume OS.

Error: (09/03/2013 08:50:53 AM) (Source: Ntfs) (User: )
Description: The file system structure on the disk is corrupt and unusable.
Please run the chkdsk utility on the volume OS.

Error: (09/03/2013 08:46:23 AM) (Source: Ntfs) (User: )
Description: The file system structure on the disk is corrupt and unusable.
Please run the chkdsk utility on the volume OS.

Error: (09/03/2013 08:40:57 AM) (Source: Ntfs) (User: )
Description: The file system structure on the disk is corrupt and unusable.
Please run the chkdsk utility on the volume OS.

Microsoft Office Sessions:
=========================
Error: (09/03/2013 09:01:31 AM) (Source: Application Hang)(User: )
Description: Explorer.EXE6.1.7601.17567ba401cea8231b43b4a70C:\Windows\Explorer.EXE

Error: (09/02/2013 06:28:47 PM) (Source: Application Error)(User: )
Description: dw20.exe2.0.50727.49274a2746a4ntdll.dll6.1.7601.1820551dba4e7c015000f000000000006fcecefc01cea82319b3cd79C:\Windows\Microsoft.NET\Framework64\v2.0.50727\dw20.exeC:\Windows\SYSTEM32\ntdll.dll08422436-141f-11e3-b9fe-bc7737387213

Error: (09/02/2013 06:07:49 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT AUTHORITY)
Description: ???????I???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????�?????????????????e???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????n???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????G????????u??????�:????????�?????????????????????????????????????????????????????????????????????????????????????????????????�???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????@??????????????!?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????�?????????????????????????????????O?????????????16000000008234000083340000600B0000

Error: (09/02/2013 06:02:18 PM) (Source: Application Error)(User: )
Description: C:\Windows\SysWOW64\msi.dllAdobe Reader and Acrobat ManagerC00000B53

Error: (09/02/2013 06:02:18 PM) (Source: Application Error)(User: )
Description: AdobeARM.exe1.7.4.0515deb31msi.dll5.0.7601.178074f802294c000000600183902d8801cea821fde85e6eC:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exeC:\Windows\system32\msi.dll54c5eb83-141b-11e3-b9fe-bc7737387213

Error: (09/02/2013 05:55:30 PM) (Source: Application Error)(User: )
Description: C:\Windows\System32\riched20.dllMicrosoft .NET Error Reporting ShimC00000B53

Error: (09/02/2013 05:55:30 PM) (Source: Application Error)(User: )
Description: dw20.exe2.0.50727.49274a2746a4RICHED20.DLL5.31.23.12304ce7c991c000000600000000000427b0efc01cea82319b3cd79C:\Windows\Microsoft.NET\Framework64\v2.0.50727\dw20.exeC:\Windows\system32\RICHED20.DLL61f00a0f-141a-11e3-b9fe-bc7737387213

Error: (09/02/2013 05:26:34 PM) (Source: Application Error)(User: )
Description: DSUpd.exe2.0.0.184be1cfbdmscorwks.dll2.0.50727.54725174ddb3c0000006000000000062f3e0

Error: (09/02/2013 05:26:34 PM) (Source: Application Error)(User: )
Description: GfxUI.exe8.15.10.22534cf32fe2mscorwks.dll2.0.50727.54725174ddb3c0000006000000000044e65c

Error: (09/02/2013 05:26:34 PM) (Source: .NET Runtime)(User: )
Description: .NET Runtime version 2.0.50727.5472 - Fatal Execution Engine Error (715EF7AE) (80131506)

**** End of log ****

I'll come back with other programs.

Thank you.
Lynn.

Comments (16)

  • lynnalexandra
    Original Author
    10 years ago
    last modified: 9 years ago

    The laptop is so slow that I'm having trouble getting the other programs downloaded and run. I downloaded DDS - which took over 20 minutes to run. Then I copied and pasted one of the logs, went to copy and paste the other, and the computer seized up.

    (It didn't help that I accidentally hit the Firefox icon in the task bar. FF is totally bogged down, so I was using Chrome. Now I can't close FF, I can't bring up Task manager. I waited about another 20 minutes, and the Chrome page showed up again. But as soon as I put my cursor somewhere, it froze again. Neither Chrome nor Firefox are moving.

    I had hoped it would recover enough to post the DDS logs. It took so long to run in the first place. But if it doesn't unfreeze soon, I will have to restart the computer by hitting the power button. Then restart - rerun DDS - and hope that I get to post results before it freezes up too much. It had been moving at a snail's pace with just Chrome. FF caused it to totally seize up.

    I notice there are error messages from the minitoolbox log. It suggests running chkdsk utility.

    This computer has not been maintained for probably 9 months as my daughter has been possessive of it - but is now learning her lesson. If she's not capable of maintenance than she has to let me do it.

    Thank you.
    Lynn.

    I'm going to shut it down and restart.

  • lynnalexandra
    Original Author
    10 years ago
    last modified: 9 years ago

    I restarted the computer and it autoatically started running chkdsk. It is finding unreadable files,it is deleting corrupt files it is deleting orphan file record segments, deleting index entry files, and correcting error in indexes.

    Glad to see that it is automatically choosing to repair as well as scan. Are these the kind of disk problems that mean ultimate death of the drive? or can chkdsk fix many things? or is this too soon to know?

    While I wait for it to do it's thing, I might as well ask about lPhant - a program I saw in my daughter's taskbar. I did google it and it seems as thought there's the original lPhant (for file - peer-to-peer sharing) - and a more rogue imposter lPhant5. I dont know which she has but it seems either should be removed.

    Lynn.

  • Related Discussions

    Is this a good laptop (for 12yo) - price and spec wise?

    Q

    Comments (27)
    So after much thought - we decided to talk to our daughter and let her know that we wanted to get her a laptop - but that we also have concerns about her use of technology - and that we would only do this with a contract. I'm going to be working on the contract for a while - and would welcome any ideas. So far, I know it will include that I have administrative control of the laptop - which will be used to update programs, run antivirus and antispyware - and generally ensure me that I have access (unlike her ipod which she changed her password on so I don't have access). It also includes that all technology (ipods, laptop, etc) will be in the parent's bedroom - from when it's time to get ready for bed - until after school the next day (or the next morning if there's no school). (not having it in the kitchen over night bc. she'll sneak down and get it if she's awake in the middle of the night. She won't sneak into our bedroom to get it.) This will prevent her from using it in the middle of the night (esp. tempting when her friend lives in Vietnam is is available to chat at those times) - and thinking she can have the laptop open in the bathroom while she's getting ready for bed. For now, I am not setting time limits - but will include that those could get added in the future if we think she's using it too much. The reason to not add it now is that she is using it a bit too much. BUT - that's bc. she loves her new Sims game - which is actually motivating her to do her homework as soon as she comes home. For the first time ever, I do not have to monitor her homework and keep asking her to do it (I still pay attention to what she's doing, but it's nice that the impetus to do it and stay organized is now coming from her). She's also coming out of a serious depression - and having some pretty terrific, responsible behavior - so any limits on amount of her free time spent on the computer - when she's meeting all her responsibilities - isn't as pressing for right now. She's also healing form a broken ankle - so in fairness to her, there's not as much active stuff she can do with her free time. ------------------------------- I have some questions about how to set up her computer so I have administrative control. I have that set up on my computer now - and she can use it as a guest. But if my computer is off - and restarts, she needs the password to get on. She doesn't have the password to my computer (which is how I want it). But I do want her to be able to log into her own computer without me giving her the administrator's password. Is there a way to do this? Set it up so she can start the computer and log in as a guest? Thanks. Lynn.
    ...See More

    why is Gardenweb soooo slow- ONLY Gardenweb...

    Q

    Comments (18)
    I have no idea why you are seeing that because the page is indeed there and working fine, I have used the link on 3 computers to check. Here is a direct link to the easylist Add EasyList to Adblock Plus or you can do it from with in adblock plus add filter ("Tools" -> "AdBlock Plus Preferences..." -> "Filters" -> "Add Filter Subscription...") select easylist from the list apply ok. Choosing a filter subscription I know some people do use easylist and fanboy together however there in the directions from the creator they do state not to use those 2 in combination. "As a rule of thumb, you should not use filter subscriptions with overlapping competencies. For example, using EasyList (mainly targeted at English-language sites) with an EasyList supplement for your region (like RuAdList for Russian sites) is fine. However, Fanboy's List (another list with main focus on English-language sites) shouldn't be used in combination with EasyList."
    ...See More

    Setting up daughter's new laptop

    Q

    Comments (17)
    The laptop's all set up - and dd received it on Tuesday. For now we'll try open office. She does have a desktop pc with word if she needs it. And at school they use Mac's. So no matter what we use at home, it won't be quite the same as in school. abreeze - thanks for the link. It's beyond anything she or I will do now - but one or both of us might get more versed in powerpoint over time. That's a helpful comparison. I created recovery disks - but when I went to create a password reset disk, the laptop kept asking me to insert a disk. There was a disk in there. I even switched disks in case one was bad. But it was birthday day - so I figured I'd get to this later. Well - it came back and bit me in the butt. Birthday night had some trauma. After dinner, my mother fell backwards and hit her head on the sidewalk. I took her to the ER. My daughter was distraught - and the parent controls had logged her off at 9pm. Husband thought this was a reasonable exception - so he logged into the admin account for her. She immediately eliminated the time controls. No big deal, I thought - I'll reset them another time. Somehow she tricked my husband into entering the admin password again - told him she'd restarted the computer by accident. Well - that sneak had gotten him to enter the password in a field that allowed her to change it. She changed the passwords and locked us out of the laptop. So this is where that password reset disk would have been helpful - to override what she did and reset a new admin password. So this is partly a note to people about the important of creating a password reset disk (or set up on flash drive). I'd never even heard of this before. We're at the beach with my daughter and friend - it's instead of a birthday party. So we're not having the confrontation with this weekend. Monday - we tell her she has to hand back the reins for the admin account (or no laptop). The joys of parenting preteens. It took her less than 24 hours to violate most of the terms of the contract she signed. Sure wish I'd had that reset password disk. When I get admin control back, I'll be sure to create one somehow. (I assume at this point my only option is getting her to give me that new password she created.) Thanks. Lynn.
    ...See More

    Please help..College starting and Laptop just crashed

    Q

    Comments (14)
    Thanks for all the input. I did try hooking a monitor to the laptop to eliminate the possibility that it was just the screen or the cable that connects--it showed nothing. I agree that the repair may not be cost effective--but wanted to try everything I could before purchasing another PC. Also just tried Zep16's advise to keep hitting the F8 key, but just as he suspected--the menu never appeared. Although laptops are difficult to troubleshoot because replacement parts aren't readily available. We do have 2 of these laptops exactly alike and I wondered if it would be advisable to switch out the hard drives, etc... to see if I could pin point the problem. Since my knowledge is limited, I wasn't sure if taking the hard drive from the working machine was a good idea. Thanks again--All input appreciated.
    ...See More
  • owbist
    10 years ago
    last modified: 9 years ago

    As this computer seems to be slow due to user tardiness I would suggest you have your daughter back up any data she needs and then use the recovery partition to return to factory defaults. Putting the onus on your daughter will help her understand the need for diligence I suspect.

    Easier to spend a couple of hours removing bloatware and installing needed stuff than what happened with the other machine which also seemed to have driver issues.

    Not too many would have the stamina shown by Joe :~)

  • lynnalexandra
    Original Author
    10 years ago
    last modified: 9 years ago

    Owbist - I understand what you're saying. My daughter really does not know how to maintain her computer. But from a more troubled time, she had not wanted me fiddling with it without her around. The issue for her to learn is to stop being mistrustful of my maintaining her computer. (I can teach her some - but she's not going to master it all).

    I dont know if there's a recovery partition but we did make recovery and repair disks when we first got the computer. She does have to get a handle on the files she has - and how to organize them. There's so many pics, videos, music, etc. Those can be backed up. What would be a huge loss for her would be her Sims 2 saved games and custom content. We did back that up to external drive - but discovered we could not get it transferred. She briefly had an HP Windows 7 desktop and we couldn't transfer the content. Neither could a computer science grad we had here. We've followed the instructions we see online and it just hasn't worked.

    So if we start from square one, she will loose all that stuff. If that's what has to happen, so be it - but I don't want to deliberately inflict that consequence just so she learns a lesson. If it's avoidable, I'd like to avoid it.

    And yes - Joe was extraordinarily generous with his time. That was not a level of assistance I had expected and I'm extremely grateful. (I hear you - don't expect that kind of help again if this laptop is so badly messed up.)

    Thank you.
    Lynn.

  • lynnalexandra
    Original Author
    10 years ago
    last modified: 9 years ago

    Chkdsk finished, computer restarted and hopefully will allow me to run and post some diagnostics.
    Here's one of the two files from DDS. I want to get it posted before it bogs down.

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    . DDS (Ver_2012-11-20.01)
    . Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 5/1/2011 3:47:43 PM
    System Uptime: 9/2/2013 3:14:55 PM (24 hours ago)
    . Motherboard: Dell Inc. : : 05TM8C
    Processor: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz : CPU : 782/100mhz
    . ==== Disk Partitions =========================
    . C: is FIXED (NTFS) - 451 GiB total, 227.894 GiB free.
    D: is CDROM (UDF)
    . ==== Disabled Device Manager Items =============
    . ==== System Restore Points ===================
    . .
    ==== Installed Programs ======================
    . 7-Zip
    7-Zip 9.20
    Adobe Flash Player 11 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Reader X (10.1.7)
    Adobe Shockwave Player 11.6
    Advanced Audio FX Engine
    AOL Toolbar
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Auslogics Disk Defrag
    avast! Free Antivirus
    Bonjour
    Bulk Rename Utility 2.7.1.2
    Canon IJ Network Scan Utility
    Canon IJ Network Tool
    Canon MX850 series
    CCleaner
    CEP (Color Enable Package) v.9.2 (beta)
    Cisco Connect
    Consumer In-Home Service Agreement
    Cozi
    D3DX10
    Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
    Dell DataSafe Local Backup
    Dell DataSafe Local Backup - Support Software
    Dell DataSafe Online
    Dell Edoc Viewer
    Dell Getting Started Guide
    Dell Home Systems Service Agreement
    Dell Marketplace Webslice IE8
    Dell MusicStage
    Dell PhotoStage
    Dell Stage
    Dell Support Center
    Dell Touchpad
    Dell VideoStage
    Dell Webcam Central
    DirectX 9 Runtime
    Download Updater (AOL Inc.)
    eBay
    Facebook Messenger 2.1.4814.0
    Facebook Video Calling 1.2.0.159
    Facebook Video Calling 1.2.0.287
    FlipShare
    Google Chrome
    Google Earth
    Google Talk Plugin
    Google Update Helper
    Intel PROSet Wireless
    Intel(R) Control Center
    Intel(R) Management Engine Components
    Intel(R) Processor Graphics
    Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
    Intel(R) PROSet/Wireless WiFi Software
    Intel(R) Turbo Boost Technology Monitor 2.0
    Intel(R) Wireless Display
    Internet Explorer
    iSyncr
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 35
    Java(TM) 6 Update 35 (64-bit)
    Junk Mail filter update
    Lphant
    Magical Jelly Bean KeyFinder
    Malwarebytes Anti-Malware version 1.65.0.1400
    Mesh Runtime
    Messenger Companion
    Microsoft .NET Framework 4 Client Profile
    Microsoft Application Error Reporting
    Microsoft Office 2010
    Microsoft Office 2010 Service Pack 1 (SP1)
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Click-to-Run 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office Home and Student 2010
    Microsoft Office Office 64-bit Components 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared 64-bit MUI (English) 2010
    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Single Image 2010
    Microsoft Office Word MUI (English) 2010
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    Microsoft WSE 3.0 Runtime
    Moozy
    Mozilla Firefox 22.0 (x86 en-US)
    Mozilla Maintenance Service
    MP3 Key Changer - Version 2.0.1.630
    MSVCRT
    MSVCRT_amd64
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP3 Parser
    MSXML 4.0 SP3 Parser (KB2721691)
    MSXML 4.0 SP3 Parser (KB2758694)
    OpenOffice.org 3.4.1
    Origin
    PDF-Viewer
    PDFCreator
    PhotoShowExpress
    Quickset64
    QuickTime
    RBVirtualFolder64Inst
    Realtek High Definition Audio Driver
    Roxio Activation Module
    Roxio BackOnTrack
    Roxio Burn
    Roxio Creator Starter
    Roxio Express Labeler 3
    Roxio File Backup
    SaveTheChildren Reminder by We-Care.com v4.0.18.4
    Secunia PSI (2.0.0.3003)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
    Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition
    Security Update for Microsoft Filter Pack 2.0 (KB2553501) 32-Bit Edition
    Security Update for Microsoft InfoPath 2010 (KB2760406) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553091)
    Security Update for Microsoft Office 2010 (KB2553096)
    Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2687276) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition
    Security Update for Microsoft OneNote 2010 (KB2760600) 32-Bit Edition
    Security Update for Microsoft Publisher 2010 (KB2553147) 32-Bit Edition
    Security Update for Microsoft Visio 2010 (KB2810068) 32-Bit Edition
    Security Update for Microsoft Visio Viewer 2010 (KB2687505) 32-Bit Edition
    Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition
    Sims2Pack Clean Installer
    Skype Toolbars
    Skype™ 6.3
    Sonic CinePlayer Decoder Pack
    SpywareBlaster 4.6
    SUPERAntiSpyware
    Swiki version 1.0
    Swiki_IE
    swMSM
    The Sims 2 Body Shop
    The Sims 2 Glamour Life Stuff
    The Sims™ 2 Apartment Life
    The Sims™ 2 Best of Business Collection
    The Sims™ 2 Bon Voyage
    The Sims™ 2 Double Deluxe
    The Sims™ 2 FreeTime
    The Sims™ 2 Fun with Pets Collection
    The Sims™ 2 Seasons
    The Sims™ 2 University Life Collection
    The Sims™ 3
    TiVo Desktop 2.8.2
    TrustedID
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
    Update for Microsoft Office 2010 (KB2553065)
    Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2566458)
    Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
    Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
    Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition
    Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
    Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
    Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition
    Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
    VoiceOver Kit
    Wincore MediaBar
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Language Selector
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live Messenger Companion Core
    Windows Live MIME IFilter
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live Remote Client
    Windows Live Remote Client Resources
    Windows Live Remote Service
    Windows Live Remote Service Resources
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    WinRAR 4.01 (32-bit)
    Wondershare Dr.Fone for Android(Build 2.1.0.21)
    . ==== End Of File ===========================

    DDS:

  • lynnalexandra
    Original Author
    10 years ago
    last modified: 9 years ago

    DDS (Ver_2012-11-20.01) - NTFS_AMD64
    Internet Explorer: 10.0.9200.16660 BrowserJavaVersion: 1.6.0_35
    Run by haha at 15:04:04 on 2013-09-03
    . ============== Running Processes ===============
    . C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Windows\system32\taskhost.exe
    C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Flip Video\FlipShareServer\FlipShareServer.exe
    C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
    C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
    C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
    C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
    C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Windows\System32\rundll32.exe
    C:\Users\haha\AppData\Local\Facebook\Update\FacebookUpdate.exe
    C:\Program Files (x86)\Skype\Phone\Skype.exe
    C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
    C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
    C:\Program Files\AVAST Software\Avast\AvastUI.exe
    C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Program Files (x86)\Lphant Applications\Lphant\Lphant.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\explorer.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Program Files\CCleaner\CCleaner64.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Users\haha\Downloads\Setup (1).exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Users\haha\AppData\Local\Temp\dynamicsetup__155.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\System32\cscript.exe
    . ============== Pseudo HJT Report ===============
    . uStart Page = hxxp://search.lphant.net
    uDefault_Page_URL = hxxp://www.dell.com
    mSearchAssistant = hxxp://start.facemoods.com/?a=fmtoby&s=(searchTerms)&f=4
    uURLSearchHooks: (9565115d-c7d6-46d3-bd63-b67b481a4368) -
    uURLSearchHooks: (90b49673-5506-483e-b92b-ca0265bd9ca8) -
    uURLSearchHooks: (472734EA-242A-422b-ADF8-83D1E48CC825) -
    mWinlogon: Userinit = userinit.exe,
    BHO: (2EECD738-5844-4a99-B4B6-146BF802613B) -
    BHO: Swiki_IE: (34191E35-BBFC-4587-87A9-4B397107119D) - C:\Program Files (x86)\Swiki_IE\ScriptHost.dll
    BHO: avast! WebRep: (8E5E2654-AD2D-48bf-AC2D-D17F00898D06) - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    BHO: Windows Live ID Sign-in Helper: (9030D464-4C02-4ABF-8ECC-5164760863C6) - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: DataMngr: (978C7B0C-1709-4f9e-AE1C-95DC75079894) - C:\Program Files (x86)\Lphant Applications\MediaBar\Datamngr\BrowserConnection.dll
    BHO: Wincore MediaBar: (9a95b751-bf3e-4ea8-a938-2d4d84cd4964) - C:\Program Files (x86)\Lphant Applications\MediaBar\Datamngr\ToolBar\lpdtxmltbpi.dll
    BHO: Windows Live Messenger Companion Helper: (9FDDE16B-836F-4806-AB1F-1455CBEFF289) - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO: Skype add-on for Internet Explorer: (AE805869-2E5C-4ED4-8F7B-F1F7851A4497) - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    BHO: Office Document Cache Handler: (B4F3A835-0E21-4959-BA22-42B3008E02FF) - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
    BHO: WeCareReminder Class: (D824F0DE-3D60-4F57-9EB1-66033ECD8ABB) - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: (DBC80044-A445-435b-BC74-9C25C1C588A9) - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO: (FD72061E-9FDE-484D-A58A-0BAB4151CAD8) -
    TB: avast! WebRep: (8E5E2654-AD2D-48bf-AC2D-D17F00898D06) - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    TB: Wincore MediaBar: (9a95b751-bf3e-4ea8-a938-2d4d84cd4964) - C:\Program Files (x86)\Lphant Applications\MediaBar\Datamngr\ToolBar\lpdtxmltbpi.dll
    uRun: [Google Update] "C:\Users\haha\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    uRun: [Facebook Update] "C:\Users\haha\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
    uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
    uRun: [Wondershare Helper Compact.exe] "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelperSetup.exe"
    mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
    mRun: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
    mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
    mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
    mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun: [DATAMNGR] C:\PROGRA~2\LPHANT~1\MediaBar\Datamngr\DATAMN~1.EXE
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    mPolicies-Explorer: NoActiveDesktop = dword:1
    mPolicies-Explorer: NoActiveDesktopChanges = dword:1
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
    IE: (0000036B-C524-4050-81A0-243669A86B9F) - (B63DBA5F-523F-4B9C-A43D-65DF1977EAD3) - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    IE: (219C3416-8CB2-491a-A3C7-D9FCDDC9D600) - (5F7B1267-94A9-47F5-98DB-E99415F33AEC) - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: (2670000A-7350-4f3c-8081-5663EE0C6C49) - (48E73304-E1D6-4330-914C-F5F514E3486C) - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: (789FE86F-6FC4-46A1-9849-EDE0DB0C95CA) - (FFFDC614-B694-4AE6-AB38-5D6374584B52) - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    IE: (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    . INFO: HKCU has more than 50 listed domains.
    If you wish to scan all of them, select the 'Force scan all domains' option.
    . DPF: (8AD9C840-044E-11D1-B3E9-00805F499D93) - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
    DPF: (CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA) - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
    DPF: (CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA) - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
    TCP: NameServer = 75.75.75.75 75.75.76.76 192.168.1.1
    TCP: Interfaces\(20D9107D-9DD7-478E-BC62-B482877B5DDF) : DHCPNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
    TCP: Interfaces\(20D9107D-9DD7-478E-BC62-B482877B5DDF)\348616F637027457563747 : DHCPNameServer = 10.1.10.1
    TCP: Interfaces\(20D9107D-9DD7-478E-BC62-B482877B5DDF)\645696E6E45647 : DHCPNameServer = 192.168.2.1
    TCP: Interfaces\(20D9107D-9DD7-478E-BC62-B482877B5DDF)\6616D696C6970227F6F6D6 : DHCPNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
    TCP: Interfaces\(20D9107D-9DD7-478E-BC62-B482877B5DDF)\6616D696C6970227F6F6D60216962707F62747 : DHCPNameServer = 208.59.247.45 208.59.247.46 192.168.1.1
    TCP: Interfaces\(20D9107D-9DD7-478E-BC62-B482877B5DDF)\C497E6E6D27657563747 : DHCPNameServer = 192.168.33.1
    TCP: Interfaces\(3DC643EE-9DD9-4372-A59F-E744F1FC887B) : DHCPNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
    Filter: text/xml - (807573E5-5146-11D5-A672-00B0D022E945) - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    Handler: cozi - (5356518D-FE9C-4E08-9C1F-1E872ECD367F) - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
    Handler: skype-ie-addon-data - (91774881-D725-4E58-B298-07617B9B86A8) - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    Handler: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
    Handler: wlpg - (E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324) - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    AppInit_DLLs= C:\PROGRA~2\LPHANT~1\MediaBar\Datamngr\datamngr.dll C:\PROGRA~2\LPHANT~1\MediaBar\Datamngr\IEBHO.dll
    SSODL: WebCheck -
    mASetup: (8A69D345-D564-463c-AFF1-A69D9E530F96) - "C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.62\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
    x64-BHO: (27B4851A-3207-45A2-B947-BE8AFE6163AB) -
    x64-BHO: avast! WebRep: (318A227B-5E9F-45bd-8999-7F8F10CA4CF5) - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
    x64-BHO: Java(tm) Plug-In SSV Helper: (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C:\Program Files\Java\jre6\bin\ssv.dll
    x64-BHO: Windows Live ID Sign-in Helper: (9030D464-4C02-4ABF-8ECC-5164760863C6) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    x64-BHO: DataMngr: (978C7B0C-1709-4f9e-AE1C-95DC75079894) - C:\Program Files (x86)\Lphant Applications\MediaBar\Datamngr\x64\BrowserConnection.dll
    x64-BHO: Office Document Cache Handler: (B4F3A835-0E21-4959-BA22-42B3008E02FF) - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
    x64-BHO: Java(tm) Plug-In 2 SSV Helper: (DBC80044-A445-435b-BC74-9C25C1C588A9) - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    x64-TB: avast! WebRep: (318A227B-5E9F-45bd-8999-7F8F10CA4CF5) - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
    x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
    x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
    x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
    x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
    x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
    x64-Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
    x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
    x64-Run: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe
    x64-Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
    x64-Run: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup
    x64-IE: (2670000A-7350-4f3c-8081-5663EE0C6C49) - (48E73304-E1D6-4330-914C-F5F514E3486C) - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    x64-IE: (789FE86F-6FC4-46A1-9849-EDE0DB0C95CA) - (FFFDC614-B694-4AE6-AB38-5D6374584B52) - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    x64-DPF: (8AD9C840-044E-11D1-B3E9-00805F499D93) - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
    x64-DPF: (CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA) - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
    x64-DPF: (CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA) - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
    x64-Filter: text/xml - (807573E5-5146-11D5-A672-00B0D022E945) - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    x64-Handler: cozi - (5356518D-FE9C-4E08-9C1F-1E872ECD367F) -
    x64-Handler: skype-ie-addon-data - (91774881-D725-4E58-B298-07617B9B86A8) -
    x64-Handler: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) -
    x64-Handler: wlpg - (E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324) -
    x64-Notify: igfxcui - igfxdev.dll
    x64-SSODL: WebCheck -
    . ================= FIREFOX ===================
    . FF - ProfilePath - C:\Users\haha\AppData\Roaming\Mozilla\Firefox\Profiles\q0w9k7ih.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?q=(searchTerms)&s_it=adknowledgeaol-ff&s_qt=sb&tb_uuid=20130106190145497&tb_oid=06-01-2013&tb_mrud=15-04-2013
    FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/?mtmhp=hyplogusaolp00000023
    FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2612669&SearchSource=2&q=
    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll
    FF - plugin: C:\Users\haha\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll
    FF - plugin: C:\Users\haha\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
    FF - plugin: C:\Users\haha\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll
    FF - plugin: C:\Users\haha\AppData\Roaming\Mozilla\Firefox\Profiles\q0w9k7ih.default\extensions\(22dfbf5b-a7cd-4b25-9471-3dc68c71855f)\plugins\np-mswmp.dll
    FF - plugin: C:\Users\haha\AppData\Roaming\Mozilla\Firefox\Profiles\q0w9k7ih.default\extensions\(90b49673-5506-483e-b92b-ca0265bd9ca8)\plugins\np-mswmp.dll
    FF - plugin: C:\Users\haha\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
    FF - plugin: C:\Users\haha\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
    FF - plugin: C:\Users\haha\AppData\Roaming\Mozilla\plugins\npo1d.dll
    FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
    FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
    FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
    FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
    FF - ExtSQL: 1969-12-31 19:00; (7affbfae-c4e2-4915-8c0f-00fa3ec610a1); C:\Users\haha\AppData\Roaming\Mozilla\Firefox\Profiles\q0w9k7ih.default\extensions\(7affbfae-c4e2-4915-8c0f-00fa3ec610a1)
    . ---- FIREFOX POLICIES ----
    . .
    . FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109936&tt=100512_2_
    FF - user.js: extensions.BabylonToolbar_i.babExt -
    FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
    FF - user.js: extensions.BabylonToolbar_i.id - b8457168000000000000bc7737387210
    FF - user.js: extensions.BabylonToolbar_i.hardId - b8457168000000000000bc7737387210
    FF - user.js: extensions.BabylonToolbar_i.instlDay - 15473
    FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
    FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
    FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1715:35:37
    FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
    FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
    FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
    FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
    FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
    FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false
    FF - user.js: browser.sessionstore.resume_from_crash - false
    . ============= SERVICES / DRIVERS ===============
    . R? avast! Antivirus;avast! Antivirus
    R? Bluetooth Device Monitor;Bluetooth Device Monitor
    R? Bluetooth Media Service;Bluetooth Media Service
    R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
    R? clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64
    R? dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.)
    R? Impcd;Impcd
    R? MyWiFiDHCPDNS;Wireless PAN DHCP Server
    R? PSI;PSI
    R? RoxMediaDB12OEM;RoxMediaDB12OEM
    R? RoxWatch12;Roxio Hard Drive Watcher 12
    R? RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader
    R? Secunia PSI Agent;Secunia PSI Agent
    R? Secunia Update Agent;Secunia Update Agent
    R? SkypeUpdate;Skype Updater
    R? TivoBeacon2;TiVo Beacon Service
    R? TsUsbFlt;TsUsbFlt
    R? TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0
    R? UNS;Intel(R) Management and Security Application User Notification Service
    R? USBAAPL64;Apple Mobile USB Driver
    R? WatAdminSvc;Windows Activation Technologies Service
    R? wlcrasvc;Windows Live Mesh remote connections service
    S? !SASCORE;SAS Core Service
    S? AERTFilters;Andrea RT Filters Service
    S? aswFsBlk;aswFsBlk
    S? aswMonFlt;aswMonFlt
    S? aswRvrt;aswRvrt
    S? aswSnx;aswSnx
    S? aswSP;aswSP
    S? aswVmm;aswVmm
    S? Bluetooth OBEX Service;Bluetooth OBEX Service
    S? btmaux;Intel Bluetooth Auxiliary Service
    S? btmhsf;btmhsf
    S? CtClsFlt;Creative Camera Class Upper Filter Driver
    S? cvhsvc;Client Virtualization Handler
    S? FlipShareServer;FlipShare Server
    S? iBtFltCoex;iBtFltCoex
    S? IntcDAud;Intel(R) Display Audio
    S? NOBU;Dell DataSafe Online
    S? nusb3hub;Renesas Electronics USB 3.0 Hub Driver
    S? nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver
    S? PxHlpa64;PxHlpa64
    S? RTL8167;Realtek 8167 NT Driver
    S? SASDIFSV;SASDIFSV
    S? SASKUTIL;SASKUTIL
    S? Sftfs;Sftfs
    S? sftlist;Application Virtualization Client
    S? Sftplay;Sftplay
    S? Sftredir;Sftredir
    S? SftService;SoftThinks Agent Service
    S? Sftvol;Sftvol
    S? sftvsa;Application Virtualization Service Agent
    S? TurboB;Turbo Boost UI Monitor driver
    S? wdkmd;Intel WiDi KMD
    . =============== Created Last 30 ================
    . 2013-09-03 13:16:57 -------- d-----w- C:\ProgramData\3917B
    2013-08-15 18:00:33 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
    2013-08-15 18:00:33 2048 ----a-w- C:\Windows\System32\tzres.dll
    2013-08-15 18:00:03 224256 ----a-w- C:\Windows\System32\wintrust.dll
    2013-08-15 18:00:03 1472512 ----a-w- C:\Windows\System32\crypt32.dll
    2013-08-15 18:00:03 1166848 ----a-w- C:\Windows\SysWow64\crypt32.dll
    2013-08-15 18:00:02 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
    2013-08-15 18:00:02 175104 ----a-w- C:\Windows\SysWow64\wintrust.dll
    2013-08-15 18:00:02 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
    2013-08-15 18:00:02 139776 ----a-w- C:\Windows\System32\cryptnet.dll
    2013-08-15 18:00:02 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
    . ==================== Find3M ====================
    . 2013-08-21 15:47:24 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2013-08-21 15:47:24 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2013-07-26 05:13:37 2241024 ----a-w- C:\Windows\System32\wininet.dll
    2013-07-26 05:12:08 3958784 ----a-w- C:\Windows\System32\jscript9.dll
    2013-07-26 05:12:04 136704 ----a-w- C:\Windows\System32\iesysprep.dll
    2013-07-26 05:12:03 67072 ----a-w- C:\Windows\System32\iesetup.dll
    2013-07-26 03:35:08 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
    2013-07-26 03:13:24 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
    2013-07-26 03:12:04 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2013-07-26 03:12:00 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
    2013-07-26 03:12:00 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
    2013-07-26 02:49:14 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2013-07-26 02:39:38 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
    2013-07-26 01:59:38 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
    2013-07-25 09:25:54 1888768 ----a-w- C:\Windows\System32\WMVDECOD.DLL
    2013-07-25 08:57:27 1620992 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
    2013-07-18 07:25:32 0 ----a-w- C:\Windows\SysWow64\sho885B.tmp
    2013-07-09 06:03:30 5550528 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2013-07-09 05:54:22 1732032 ----a-w- C:\Windows\System32\ntdll.dll
    2013-07-09 05:53:12 243712 ----a-w- C:\Windows\System32\wow64.dll
    2013-07-09 05:51:16 1217024 ----a-w- C:\Windows\System32\rpcrt4.dll
    2013-07-09 05:03:34 3968960 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2013-07-09 05:03:34 3913664 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2013-07-09 04:53:47 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
    2013-07-09 04:52:33 663552 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
    2013-07-09 04:52:33 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
    2013-07-09 04:45:07 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
    2013-07-09 02:49:42 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
    2013-07-09 02:49:41 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
    2013-07-09 02:49:39 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
    2013-07-09 02:49:38 2048 ----a-w- C:\Windows\SysWow64\user.exe
    2013-07-06 06:03:53 1910208 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2013-06-27 21:17:07 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
    2013-06-27 21:17:07 1030952 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
    2013-06-22 22:10:24 98616 ----a-w- C:\Windows\System32\drivers\ssudbus.sys
    2013-06-15 04:32:16 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys
    2011-08-13 18:57:35 1110476 ----a-w- C:\Program Files (x86)\7-Zip.exe
    . ============= FINISH: 15:24:04.80 ===============

  • lynnalexandra
    Original Author
    10 years ago
    last modified: 9 years ago

    I'm going to run Hijackthis. When i do, it brings up this screen which I'm typing here so I can reference it later if needed:

    For some reason your system denied write access to the Hosts file. If any hijacked domains are in this file, HijackThis may NOT be able to fix this.

    If that hapens, you need to edit the file yourself. To do this, click Start, Run and type:
    notepad C:\\Windows\System32\drivers\etc\hosts

    and press Enter. Find the line(s) HijackThis reports and delete them. Save the file as "hosts." (with quotes), and reboot.

    I guess I might be using those instructions later.
    I'll post back with Hijackthis results. I'm typing this on my own laptop which is working just great now.

    Thank you.
    Lynn.

  • lynnalexandra
    Original Author
    10 years ago
    last modified: 9 years ago

    The scan is run - but a pop-up from Notepad says:

    Cannot find the c:\\program Files (x86)\Trend Micro\HijackThis\hijackthis.log file. Do you want a new file.

    When I click Yes I want a new file, none gets created.

    When I right click properties on the Hijackthis desktop icon, it shows that it is in c:\\(rpgra, Fo;es (x86)\Trend Micro\HijackThis\(I can't see the rest) - but it's in program files.

    Not sure what to do next. I see there are options in Hijack this special permissions but I don't understand it. And it seems that the user account does have permission.

    Lynn

  • Elmer J Fudd
    10 years ago
    last modified: 9 years ago

    owbist said "use the recovery partition to return to factory defaults.".

    I made the same suggestion early on in this user's other extravaganza thread. Some 90 posts and days later, she's still running useless utilities repeatedly and posting volumes of info that she doesn't understand (and that's mostly useless anyway).

    Lynn, buy yourself some tea that you like and a candle. Light the candle, have some tea, and enjoy a quiet evening after you trigger recovery on the PCs that aren't up to par. It'll fix the slow running problems. Anything else you'd do otherwise may not be time well spent.

  • grandms
    10 years ago
    last modified: 9 years ago

    I think at this point, after following every word of your other thread, I must agree with Owbist and Snidely. This laptop is not as old as the one you were previously working on, so restoring it and updating the MS security updates should not take so much time and effort as it would have on a system running XP.

    Believe me, as a mother, grandmother, and now, great-grandmother, I know your feelings, but there comes a time when you must be pragmatic about the situation and do what is necessary. Sometimes it's called "tough love."

  • zep516
    10 years ago
    last modified: 9 years ago

    1 download adwcleaner from here http://www.bleepingcomputer.com/download/adwcleaner/

    Run adwcleaner, hit the clean button, post the log created.

    Next

    Run Junk removal tool http://www.bleepingcomputer.com/download/junkware-removal-tool/

    Post the log.

    Reinstall Hijackthis if you're still having issues with that program.

    This post was edited by zep516 on Tue, Sep 3, 13 at 23:48

  • zep516
    10 years ago
    last modified: 9 years ago

    Here's the issue with firefox,

    FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109936&tt=100512_2_
    FF - user.js: extensions.BabylonToolbar_i.babExt -
    FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
    FF - user.js: extensions.BabylonToolbar_i.id - b8457168000000000000bc7737387210
    FF - user.js: extensions.BabylonToolbar_i.hardId - b8457168000000000000bc7737387210
    FF - user.js: extensions.BabylonToolbar_i.instlDay - 15473
    FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
    FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
    FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1715:35:37
    FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
    FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
    FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
    FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
    FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
    FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false
    FF - user.js: browser.sessionstore.resume_from_crash - false

    We will be getting rid of that, by running the tools above.

  • lynnalexandra
    Original Author
    10 years ago
    last modified: 9 years ago

    Hi, Joe,

    It's so good to see your posts here. I had thought that perhaps I was coming to the wrong place with bogged down laptops and complicaed log files. I thought that perhaps Lanzdown was a more appropriate place for troubleshooting of this degree.

    I am going to run the stuff you suggested -but wonder if should focus my troubleshooting on one forum. If you tell me to post here, I will. Otherwise I"ll post there.

    Thank you.
    Lynn.

  • zep516
    10 years ago
    last modified: 9 years ago

    Remember to right click on every tool I have you download and run "as administrator"

    Also

    Lphant---> It's a file sharing program. It's one of the biggest ways to get infected.

    "Researchers have examined potential security risks including the release of personal information, bundled spyware, and viruses downloaded from the network."

    I'd get rid of that. Uninstall it,

    It's already hijacked the start page,

    uStart Page = hxxp://search.lphant.net

    Start up entries, you can turn them all off except the bolded ones, using hijackthis like we did before

    1 Facebook Update
    2 Skype
    3 Wondershare Helper Compact.exe
    4 Dell Webcam Central
    5 Dell DataSafe Online
    6 RoxWatchTray
    7 Desktop Disc Tool
    8 avast
    9 Adobe ARM
    10 IJNetworkScanUtility
    11 APSDaemon
    12 DATAMNGR--------That will go away when you uninstall that lphant
    13 QuickTime Task
    14 iTunesHelper
    15 [Launcher] C:\Program Files (x86)\Dell DataSafe Local

    This post was edited by zep516 on Tue, Sep 3, 13 at 23:47

  • zep516
    10 years ago
    last modified: 9 years ago

    You can post here, unless someone at landz is helping you already.

  • lynnalexandra
    Original Author
    10 years ago
    last modified: 9 years ago

    For the sake of wrapping this thread up, let me say that I started getting help at landZ. Seems that's a more appropriate place for posting long log files. Maybe saving my posts here for help and questions that don't run over 100 posts and involve pages of logs.

    I appreciate all the help I get at this forum. I just don't want to burden folks here with questions that might require the kind of generosity and stamina that Joe offered in helping me with my own thinkpad.

    Thank you very much.
    Lynn.