Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

start up repair- ci.dll


  • This topic is locked This topic is locked
6 replies to this topic

#1 rbd23

rbd23

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:34 PM

Posted 03 August 2011 - 02:21 AM

HI Farbar,
I'm having trouble with my Vaio laptop and while i was google-ing the issue i found a page where you helped someone with the same issue. the problem is about c:ci.dll file and I already have done the instructions you gave to the other member. I have the frst.txt file and just need the rest so i can fix my laptop.

Thank You!

Attached Files


Edited by rbd23, 03 August 2011 - 02:31 AM.


BC AdBot (Login to Remove)

 


#2 rbd23

rbd23
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:34 PM

Posted 03 August 2011 - 02:32 AM

Here is what I got from FRST.txt

Scan result of Farbars's Recovery Tool (FRST written by farbar) Version 2.2.0
Ran by SYSTEM at 2011-08-02 23:54:18
Running from E:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM\...\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" [x]
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35736 2011-01-30] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [395144 2011-05-17] (Ask)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [248552 2010-05-14] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421160 2011-06-07] (Apple Inc.)
HKU\SONY\...\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet [6174008 2010-11-04] (Yahoo! Inc.)
HKU\SONY\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" [399736 2011-04-26] (BitTorrent, Inc.)
HKU\SONY\...\Run: [ares] "C:\Program Files (x86)\Ares\Ares.exe" -h [1015808 2010-07-10] (Ares Development Group)
HKU\SONY\...\Run: [Google Update] "C:\Users\SONY\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2010-09-25] (Google Inc.)
HKU\SONY\...\Run: [DealRunner] C:\Program Files (x86)\DealRunner\DealRunner.exe [2020952 2011-03-18] (Jackpot Rewards)
HKU\SONY\...\Run: [RegistryBooster] "C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe" delay 20000 [67456 2011-03-14] (Uniblue Systems Limited)
HKU\SONY\...\Run: [InstallIQUpdater] "C:\Program Files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun [1205760 2011-05-10] (W3i, LLC)
Tcpip\Parameters: [DhcpNameServer] 71.9.127.107 68.190.192.35 68.116.46.115

==================== Services (Whitelisted) ======

3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.)

========================== Drivers (Whitelisted) =============

3 lmimirr; C:\Windows\System32\DRIVERS\lmimirr.sys [11552 2010-01-27] (LogMeIn, Inc.)
2 LMIRfsDriver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [72216 2010-01-27] (LogMeIn, Inc.)
3 SFEP; C:\Windows\System32\DRIVERS\SFEP.sys [11392 2007-08-03] (Sony Corporation)
3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [389120 2009-06-10] (Marvell)
3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [x]
4 LMIRfsClientNP; [x]

========================== NetSvcs ========================

============ One Month Created Files and Folders ==============

2011-08-02 23:54 - 2011-08-02 23:54 - 0000000 ____D C:\FRST
2011-07-20 13:15 - 2011-07-20 13:15 - 4369323 ____A C:\Users\SONY\Downloads\634465902089307745.flv
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Users\SONY\AppData\Roaming\Apple Computer
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Users\SONY\AppData\Local\Apple Computer
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Users\All Users\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Program Files\iTunes
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Program Files\iPod
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Program Files (x86)\iTunes
2011-07-09 10:45 - 2009-05-18 12:17 - 0034152 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2011-07-09 10:45 - 2008-04-17 11:12 - 0126312 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi64.dll
2011-07-09 10:45 - 2008-04-17 11:12 - 0107368 ____A (GEAR Software Inc.) C:\Windows\SysWOW64\GEARAspi.dll
2011-07-09 10:44 - 2011-07-09 10:45 - 0000000 ____D C:\Users\All Users\Apple Computer
2011-07-09 10:44 - 2011-07-09 10:45 - 0000000 ____D C:\ProgramData\Apple Computer
2011-07-09 10:44 - 2011-07-09 10:44 - 0000000 ____D C:\Users\SONY\AppData\Local\Apple
2011-07-09 10:44 - 2011-07-09 10:44 - 0000000 ____D C:\Program Files (x86)\QuickTime
2011-07-09 10:44 - 2011-07-09 10:44 - 0000000 ____D C:\Program Files (x86)\Apple Software Update
2011-07-09 10:43 - 2011-07-09 10:44 - 0000000 ____D C:\Users\All Users\Apple
2011-07-09 10:43 - 2011-07-09 10:44 - 0000000 ____D C:\ProgramData\Apple
2011-07-09 10:43 - 2011-07-09 10:43 - 0000000 ____D C:\Program Files\Common Files\Apple
2011-07-09 10:43 - 2011-07-09 10:43 - 0000000 ____D C:\Program Files\Bonjour
2011-07-09 10:43 - 2011-07-09 10:43 - 0000000 ____D C:\Program Files (x86)\Bonjour
2011-07-09 10:42 - 2011-07-09 10:42 - 81614632 ____A (Apple Inc.) C:\Users\SONY\Downloads\iTunes64Setup.exe
2011-07-09 10:40 - 2011-07-09 10:41 - 80695592 ____A (Apple Inc.) C:\Users\SONY\Downloads\iTunesSetup.exe

============ 3 Months Modified Files and Folders =============

2011-08-02 23:54 - 2011-08-02 23:54 - 0000000 ____D C:\FRST
2011-08-01 20:51 - 2011-02-09 21:11 - 0000000 ____D C:\Users\All Users\McAfee Security Scan
2011-08-01 20:51 - 2011-02-09 21:11 - 0000000 ____D C:\ProgramData\McAfee Security Scan
2011-08-01 20:51 - 2011-01-23 23:02 - 0000000 ____D C:\Users\SONY\AppData\Roaming\translateclient
2011-08-01 20:51 - 2010-08-28 11:02 - 0000000 ____D C:\users\LogMeInRemoteUser
2011-08-01 20:51 - 2010-07-16 20:17 - 0000000 ____D C:\Users\All Users\Norton
2011-08-01 20:51 - 2010-07-16 20:17 - 0000000 ____D C:\ProgramData\Norton
2011-08-01 20:51 - 2010-07-09 22:12 - 0000000 ____D C:\Users\SONY\AppData\Roaming\uTorrent
2011-08-01 20:51 - 2010-07-08 20:56 - 0000000 ____D C:\users\SONY
2011-08-01 20:51 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\registration
2011-08-01 20:51 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\AppCompat
2011-08-01 20:47 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\LogFiles
2011-08-01 06:18 - 2011-02-23 19:29 - 0524288 __ASH C:\Windows\System32\config\components{c60d916d-3fc5-11e0-947e-001e3deb570d}.TMContainer00000000000000000001.regtrans-ms
2011-08-01 06:18 - 2011-02-23 19:29 - 0065536 __ASH C:\Windows\System32\config\components{c60d916d-3fc5-11e0-947e-001e3deb570d}.TM.blf
2011-07-31 12:05 - 2010-07-08 20:45 - 2414374912 __ASH C:\hiberfil.sys
2011-07-31 11:21 - 2011-04-28 15:45 - 1116332 ___AH C:\Users\SONY\AppData\Local\IconCache.db
2011-07-31 10:47 - 2011-02-09 21:03 - 0000000 ____D C:\Users\SONY\AppData\Local\ElevatedDiagnostics
2011-07-24 10:25 - 2010-09-25 18:02 - 0000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3358567712-832749669-598720668-1000UA.job
2011-07-24 09:30 - 2010-07-08 20:48 - 1296394 ____A C:\Windows\WindowsUpdate.log
2011-07-24 09:15 - 2010-07-09 21:36 - 0000000 ____D C:\Program Files (x86)\Mozilla Firefox
2011-07-23 14:59 - 2011-04-11 22:16 - 0000408 ___AH C:\Windows\Tasks\Norton Security Scan for SONY.job
2011-07-23 14:25 - 2010-09-25 18:02 - 0000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3358567712-832749669-598720668-1000Core.job
2011-07-22 19:43 - 2009-07-13 20:45 - 0014016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2011-07-22 19:43 - 2009-07-13 20:45 - 0014016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2011-07-22 19:40 - 2009-07-13 21:13 - 0717892 ____A C:\Windows\System32\PerfStringBackup.INI
2011-07-22 19:36 - 2011-04-26 20:09 - 0000440 ____A C:\Windows\Tasks\PCConfidential.job
2011-07-22 19:36 - 2011-01-23 23:02 - 0003298 ____A C:\Windows\SysWOW64\StyleVista.png
2011-07-22 19:36 - 2011-01-23 23:02 - 0003137 ____A C:\Windows\SysWOW64\StyleVistaDown.png
2011-07-22 19:35 - 2011-06-02 18:24 - 0002624 ____A C:\Windows\setupact.log
2011-07-22 19:35 - 2011-04-26 20:10 - 0000342 ____A C:\Windows\Tasks\RegistryBooster.job
2011-07-22 19:35 - 2010-07-09 11:30 - 0633788 ____A C:\Windows\PFRO.log
2011-07-22 19:35 - 2009-07-13 21:08 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2011-07-22 13:02 - 2010-07-09 21:25 - 0000000 ____D C:\Users\All Users\Yahoo! Companion
2011-07-22 13:02 - 2010-07-09 21:25 - 0000000 ____D C:\ProgramData\Yahoo! Companion
2011-07-20 13:15 - 2011-07-20 13:15 - 4369323 ____A C:\Users\SONY\Downloads\634465902089307745.flv
2011-07-12 13:26 - 2010-09-25 18:03 - 0002391 ____A C:\Users\SONY\Desktop\Google Chrome.lnk
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Users\SONY\AppData\Roaming\Apple Computer
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Users\SONY\AppData\Local\Apple Computer
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Users\All Users\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Program Files\iTunes
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Program Files\iPod
2011-07-09 10:45 - 2011-07-09 10:45 - 0000000 ____D C:\Program Files (x86)\iTunes
2011-07-09 10:45 - 2011-07-09 10:44 - 0000000 ____D C:\Users\All Users\Apple Computer
2011-07-09 10:45 - 2011-07-09 10:44 - 0000000 ____D C:\ProgramData\Apple Computer
2011-07-09 10:45 - 2010-07-11 13:32 - 0000000 __SHD C:\Config.Msi
2011-07-09 10:44 - 2011-07-09 10:44 - 0000000 ____D C:\Users\SONY\AppData\Local\Apple
2011-07-09 10:44 - 2011-07-09 10:44 - 0000000 ____D C:\Program Files (x86)\QuickTime
2011-07-09 10:44 - 2011-07-09 10:44 - 0000000 ____D C:\Program Files (x86)\Apple Software Update
2011-07-09 10:44 - 2011-07-09 10:43 - 0000000 ____D C:\Users\All Users\Apple
2011-07-09 10:44 - 2011-07-09 10:43 - 0000000 ____D C:\ProgramData\Apple
2011-07-09 10:43 - 2011-07-09 10:43 - 0000000 ____D C:\Program Files\Common Files\Apple
2011-07-09 10:43 - 2011-07-09 10:43 - 0000000 ____D C:\Program Files\Bonjour
2011-07-09 10:43 - 2011-07-09 10:43 - 0000000 ____D C:\Program Files (x86)\Bonjour
2011-07-09 10:42 - 2011-07-09 10:42 - 81614632 ____A (Apple Inc.) C:\Users\SONY\Downloads\iTunes64Setup.exe
2011-07-09 10:41 - 2011-07-09 10:40 - 80695592 ____A (Apple Inc.) C:\Users\SONY\Downloads\iTunesSetup.exe
2011-07-09 10:41 - 2010-07-08 20:56 - 0000000 ____D C:\Users\SONY\AppData\LocalLow
2011-07-06 11:23 - 2011-01-08 16:56 - 0009104 ____A C:\Windows\yacs.log
2011-07-04 10:56 - 2011-04-26 19:39 - 0000000 ____D C:\Users\SONY\Desktop\Movie
2011-07-01 22:00 - 2011-01-23 23:02 - 0002086 ____A C:\Users\All Users\Start Menu\Programs\Startup\Translate Client.lnk
2011-07-01 22:00 - 2011-01-23 23:02 - 0000000 ____D C:\Program Files (x86)\Translate Client
2011-06-24 08:19 - 2011-02-23 19:29 - 0524288 __ASH C:\Windows\System32\config\components{c60d916d-3fc5-11e0-947e-001e3deb570d}.TMContainer00000000000000000002.regtrans-ms
2011-06-16 20:12 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\rescache
2011-06-16 19:46 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\Microsoft.NET
2011-06-16 19:38 - 2011-06-16 19:38 - 0000000 __SHD C:\Windows\System32\%APPDATA%
2011-06-16 19:25 - 2010-07-08 20:56 - 0000174 ___SH C:\Users\SONY\Start Menu\Programs\Startup\desktop.ini
2011-06-16 19:25 - 2010-07-08 20:56 - 0000174 ___SH C:\Users\SONY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
2011-06-16 19:24 - 2009-07-13 20:45 - 0409608 ____A C:\Windows\System32\FNTCACHE.DAT
2011-06-16 19:23 - 2010-07-14 08:26 - 0000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2011-06-16 17:06 - 2009-07-13 20:45 - 0000000 ____D C:\Windows\debug
2011-06-15 16:43 - 2011-06-15 16:43 - 0000000 ____D C:\Windows\Sun
2011-06-11 17:29 - 2011-06-11 17:29 - 0000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin
2011-06-11 17:29 - 2011-06-11 17:29 - 0000000 ____D C:\Program Files (x86)\W3i
2011-06-11 13:38 - 2011-06-11 13:38 - 0472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2011-06-11 13:38 - 2011-06-11 13:38 - 0153376 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2011-06-11 13:38 - 2011-06-11 13:38 - 0145184 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2011-06-11 13:38 - 2011-06-11 13:38 - 0145184 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2011-06-11 13:38 - 2011-06-11 13:38 - 0000000 ____D C:\Users\All Users\Sun
2011-06-11 13:38 - 2011-06-11 13:38 - 0000000 ____D C:\ProgramData\Sun
2011-06-11 13:38 - 2011-06-11 13:38 - 0000000 ____D C:\Program Files (x86)\Java
2011-06-11 13:37 - 2011-06-11 13:37 - 0874784 ____A (Sun Microsystems, Inc.) C:\Users\SONY\Downloads\xpiinstall.exe
2011-06-10 07:42 - 2011-05-29 13:13 - 0000000 ____D C:\Users\SONY\AppData\Roaming\dvdcss
2011-06-03 17:30 - 2011-06-16 17:06 - 49454024 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2011-06-02 21:16 - 2010-09-01 21:07 - 0000000 ____D C:\Users\SONY\Desktop\Best
2011-06-02 18:24 - 2011-06-02 18:24 - 0000000 ____A C:\Windows\setuperr.log
2011-05-29 11:05 - 2010-07-09 22:12 - 0000000 ____D C:\Program Files (x86)\Ask.com
2011-05-27 21:22 - 2011-06-16 16:49 - 9316352 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2011-05-27 20:38 - 2011-06-16 16:49 - 5984256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2011-05-27 19:25 - 2011-06-16 16:48 - 1638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2011-05-27 19:07 - 2011-06-16 16:48 - 3133952 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2011-05-27 19:00 - 2011-06-16 16:48 - 1638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2011-05-24 18:14 - 2010-07-08 22:04 - 0270720 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2011-05-19 20:37 - 2011-05-19 20:37 - 0000000 ____D C:\Users\Public\Downloads\Norton
2011-05-10 07:06 - 2011-05-10 07:06 - 4517664 ____A (Apple, Inc.) C:\Windows\System32\usbaaplrc.dll
2011-05-10 07:06 - 2011-05-10 07:06 - 0051712 ____A (Apple, Inc.) C:\Windows\System32\Drivers\usbaapl64.sys
2011-05-09 20:26 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\config\TxR
2011-05-09 20:23 - 2010-09-30 14:40 - 0000000 ____D C:\Program Files (x86)\Search Toolbar
2011-05-09 20:21 - 2011-02-16 23:58 - 0000000 ____D C:\Program Files\Microsoft Office
2011-05-09 20:21 - 2010-07-09 21:25 - 0000000 ____D C:\Users\SONY\AppData\Roaming\Yahoo!
2011-05-07 18:07 - 2010-07-09 22:00 - 0107592 ____A C:\Users\SONY\AppData\Local\GDIPFONTCACHEV1.DAT
2011-05-07 18:06 - 2011-05-07 11:32 - 0000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client
2011-05-07 12:05 - 2011-05-07 12:05 - 0000000 ____D C:\Users\SONY\Documents\DriverPerformer
2011-05-07 12:05 - 2011-05-07 12:05 - 0000000 ____D C:\ProgramDataMozilla
2011-05-07 12:05 - 2011-05-07 12:05 - 0000000 ____D C:\Program Files (x86)\Superfish
2011-05-07 12:05 - 2011-05-07 12:05 - 0000000 ____D C:\Program Files (x86)\Driver-Soft
2011-05-07 11:44 - 2011-05-07 11:32 - 0000000 ____D C:\Users\SONY\AppData\Roaming\TP
2011-05-07 11:21 - 2011-02-16 23:58 - 0000000 ____D C:\Program Files (x86)\Microsoft Office
2011-05-07 11:19 - 2011-02-17 00:00 - 0000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2011-05-07 11:15 - 2011-05-07 11:15 - 0000000 ____D C:\Users\SONY\AppData\Roaming\WinRAR
2011-05-07 11:15 - 2011-05-07 11:15 - 0000000 ____D C:\Program Files\WinRAR
2011-05-03 18:51 - 2011-06-16 16:48 - 0287744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
2011-05-03 18:51 - 2011-06-16 16:48 - 0157696 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
2011-05-03 18:51 - 2011-06-16 16:48 - 0126464 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
2011-05-02 21:21 - 2011-06-16 16:48 - 0976896 ____A (Microsoft Corporation) C:\Windows\System32\inetcomm.dll
2011-05-02 20:50 - 2011-06-16 16:48 - 0740864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2011-05-02 19:00 - 2011-05-02 19:00 - 0000355 ____A C:\Users\SONY\Desktop\Computer - Shortcut.lnk
2011-05-02 19:00 - 2010-07-09 21:20 - 0001073 ____A C:\Users\SONY\Desktop\Documents - Shortcut.lnk

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

========================= Memory info ======================

Percentage of memory in use: 16%
Total physical RAM: 3070.04 MB
Available physical RAM: 2564.06 MB
Total Pagefile: 3068.19 MB
Available Pagefile: 2545.38 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB

======================= Partitions =========================

1 Drive c: () (Fixed) (Total:224.64 GB) (Free:70.2 GB) NTFS
2 Drive d: (Recovery) (Fixed) (Total:8.25 GB) (Free:0.87 GB) NTFS
3 Drive e: () (Removable) (Total:1.84 GB) (Free:1.35 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==========================================================

Last Boot: 2011-07-24 10:06

======================= End Of Log ==========================

#3 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,719 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:34 PM

Posted 03 August 2011 - 02:52 AM

Hi rbd23,

Welcome to BC.:)

Your log(s) show that you are using so called peer-to-peer or file-sharing programs. These programs allow to share files between users as the name(s) suggest. In today's world the cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: "File-Sharing, otherwise known as Peer To Peer" and "Risks of File-Sharing Technology."


Removal Instructions

Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste). Save it on the flashdrive as fixlist.txt

start
cmd: bootrec /FixMbr
Control:
end

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Now please enter System Recovery Options.

Run FRST and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Also please restart normally and tell me how it went.

#4 rbd23

rbd23
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:34 PM

Posted 03 August 2011 - 03:43 AM

You are amazing!!! windows came up perfectly!!



Fix result of Farbars's Recovery Tool (FRST written by farbar version 2.2.0)
Ran by SYSTEM at 2011-08-03 01:24:57 R:1
Running from F:\

==============================================


========= bootrec /FixMbr =========

˙ūT h e o p e r a t i o n c o m p l e t e d s u c c e s s f u l l y .

========= End of CMD: =========


=========== Control: ===========
The element data type specified is not recognized, or does not apply to the
specified entry.
Run "bcdedit /?" for command line assistance.
Element not found.

==== End of Control: ====

==== End of Fixlog ====

#5 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,719 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:34 PM

Posted 03 August 2011 - 03:56 AM

Great. :thumbsup:

Please download Malwarebytes' Anti-Malware from one of these locations:
malwarebytes.org
majorgeeks.com
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the MBAM log.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.


#6 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,719 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:34 PM

Posted 07 August 2011 - 10:10 AM

I wonder if you still need assistance or with booting the computer the issue is resolved.

#7 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,719 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:34 PM

Posted 11 August 2011 - 04:21 PM

This thread will now be closed since the issue seems to be resolved.

If you need this topic reopened, please send me a PM and I will reopen it for you. If you should have a new issue, please start a new topic.

Every one else should start a new topic.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users