Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

STOP: C0000135 The program can't start because %hs is missing. Try resintalling


  • This topic is locked This topic is locked
3 replies to this topic

#1 Splattzilla

Splattzilla

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:01:59 AM

Posted 06 August 2017 - 11:01 PM

windows 7 64-bit laptop no more than 6-7 years old, sister dropped it off to fix. Tried restoring and all that jazz from recovery startup.

 

FRST64 log:
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-08-2017
Ran by SYSTEM on MININT-F9HEBIN (06-08-2017 20:42:52)
Running from e:\
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11
Boot Mode: Recovery
Default: ControlSet001
[b]ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.[/b]

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (AlcorMicroCorp.)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-16] (RealtekSemiconductor)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R)Corporation)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-23] ()
HKLM-x32\...\Run: [NACAgentUI] => C:\Program Files (x86)\Cisco\Cisco NAC Agent\NACAgentUI.exe [540088 2011-09-01] (CiscoSystems,Inc.)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [721856 2016-06-30] (Autodesk,Inc.)
HKLM\...\RunOnce: [*Restore] => C:\Windows\system32\rstrui.exe [296960 2017-04-27] (MicrosoftCorporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-07-17]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-07-17]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-07-17]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2017-03-07]
ShortcutTarget: Facebook Gameroom.lnk ->  (No File)
Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-11-07]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
GroupPolicy: Restriction <==== ATTENTION

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1295376 2016-06-30] (AutodeskInc.)
S2 AFBAgent; C:\Windows\system32\FBAgent.exe [379520 2011-03-03] (ASUSTeKComputerInc.)
S2 AVP17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe [241544 2016-06-28] (AOKasperskyLab)
S2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042544 2017-03-14] (MicrosoftCorporation)
S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\vssbridge64.exe [77328 2016-06-28] (AOKasperskyLab)
S2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (AOKasperskyLab)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
S2 NACAgent; C:\Program Files (x86)\Cisco\Cisco NAC Agent\NACAgent.exe [1233848 2011-09-01] (CiscoSystems,Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (MicrosoftCorporation)
S2 FontCache; %SystemRoot%\system32\FntCache.dll [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aliide; C:\Windows\system32\drivers\aliide.sys [15440 2009-07-13] (AcerLaboratoriesInc.)
S3 AmUStor; C:\Windows\System32\drivers\AmUStor.SYS [74840 2011-03-17] (AlcorMicro,Corp.)
S0 assd; C:\Windows\System32\Drivers\assd.sys [27264 2010-04-28] (ASUSCorporation)
S3 cmdide; C:\Windows\system32\drivers\cmdide.sys [17488 2009-07-13] (CMDTechnology,Inc.)
S0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [238936 2016-06-10] (AOKasperskyLab)
S3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ()
S0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [554416 2016-06-02] (AOKasperskyLab)
S0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [63920 2016-06-07] (AOKasperskyLab)
S1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [86352 2016-06-15] (AOKasperskyLab)
S2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [78216 2016-05-31] (AOKasperskyLab)
S3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [189264 2016-06-26] (AOKasperskyLab)
S1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [305496 2016-09-12] (AOKasperskyLab)
S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1036512 2017-01-11] (AOKasperskyLab)
S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [57936 2017-01-11] (AOKasperskyLab)
S3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [52144 2016-05-19] (AOKasperskyLab)
S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [41648 2015-06-07] (KasperskyLabZAO)
S1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [45488 2016-05-31] (AOKasperskyLab)
S3 kltap; C:\Windows\System32\DRIVERS\kltap.sys [52152 2016-06-07] (TheOpenVPNProject)
S1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [75696 2016-05-17] (AOKasperskyLab)
S1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [134880 2017-01-11] (AOKasperskyLab)
S1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [194480 2016-06-14] (AOKasperskyLab)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [28416 2008-04-16] (ResearchInMotionLimited)
S3 viaide; C:\Windows\system32\drivers\viaide.sys [17488 2009-07-13] (VIATechnologies,Inc.)
S3 vsmraid; C:\Windows\system32\drivers\vsmraid.sys [161872 2009-07-13] (VIATechnologiesInc.,Ltd)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-08-06 20:42 - 2017-08-06 20:42 - 000000000 ____D C:\FRST
2017-07-16 16:18 - 2017-07-16 16:18 - 000000000 __SHD C:\found.002

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-29 12:03 - 2014-04-23 23:54 - 000885512 _____ C:\Windows\ntbtlog.txt

Some files in TEMP:
====================
2017-01-13 21:56 - 2015-01-26 06:59 - 000060296 _____ (Autodesk, Inc.) C:\Users\Owner\AppData\Local\Temp\AcDeltree.exe

==================== Known DLLs (Whitelisted) =========================

C:\Windows\System32\LPK.dll IS MISSING <==== ATTENTION
C:\Windows\System32\USP10.dll IS MISSING <==== ATTENTION

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2017-05-09 18:49] - [2017-04-17 07:37] - 000512000 _____ (Microsoft Corporation) 5E9F8D029D9B03110D835CBFC058068B

C:\Windows\System32\dnsapi.dll => MD5 is legit
C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Association (Whitelisted) =============


==================== Restore Points  =========================

Restore point date: 2017-05-22 15:35
Restore point date: 2017-05-25 18:11
Restore point date: 2017-05-30 14:11
Restore point date: 2017-05-30 16:36
Restore point date: 2017-06-02 17:12
Restore point date: 2017-06-07 18:05
Restore point date: 2017-06-13 18:09
Restore point date: 2017-06-14 09:23
Restore point date: 2017-06-14 19:27

==================== Memory info =========================== 

Percentage of memory in use: 12%
Total physical RAM: 6049.14 MB
Available physical RAM: 5312.46 MB
Total Virtual: 6047.29 MB
Available Virtual: 5301.38 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:571.17 GB) (Free:435.26 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: () (Removable) (Total:14.6 GB) (Free:14.6 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: AA9693FE)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=571.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 14.6 GB) (Disk ID: 00000000)

Partition: GPT.

LastRegBack: 2017-06-13 20:02

==================== End of FRST.txt ============================


BC AdBot (Login to Remove)

 


#2 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,925 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:04:59 AM

Posted 07 August 2017 - 11:30 AM

Welcome. :)

 

Open FRST as you did before.

Type the following in the edit box on FRST, after "Search:".

FntCache.dll;LPK.dll;USP10.dll

It then should look like:

Search: FntCache.dll;LPK.dll;USP10.dll

Click Search Files button and post the log (Search.txt) it makes on the USB drive in your next reply.
 


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#3 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,925 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:04:59 AM

Posted 14 August 2017 - 09:41 PM

Are you still with us?


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#4 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,925 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:04:59 AM

Posted 21 August 2017 - 08:11 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users