Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

white screen of death! [Closed]


  • This topic is locked This topic is locked

#1
abrar1588

abrar1588

    New Member

  • Member
  • Pip
  • 1 posts
I have a problem similar to the previuos user(flintstone). Ive followed all the steps mentioned and here is the scan result i.e. FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2013 02
Ran by SYSTEM at 02-02-2013 09:54:32
Running from H:\
Windows 7 Professional (X86) OS Language: English(US)
The current controlset is ControlSet001

==================== Registry (Whitelisted) ===================

HKLM\...\Run: [IAStorIcon] C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284696 2009-12-23] (Intel Corporation)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-18] ()
HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [496184 2010-03-21] (Conexant Systems, Inc.)
HKLM\...\Run: [331BigDog] C:\Program Files\USB Camera\VM331_STI.EXE [536576 2009-09-15] (Vimicro)
HKLM\...\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe [4204480 2010-03-30] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe [6285216 2010-03-18] (Lenovo (Beijing) Limited)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-01-21] (Microsoft Corporation)
HKLM\...\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [153136 2007-03-01] (Nero AG)
HKLM\...\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [1836328 2007-09-19] (Nero AG)
HKLM\...\Run: [] [x]
HKLM\...\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [640376 2008-06-11] (Adobe Systems Inc.)
HKLM\...\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe [2345592 2012-07-31] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe" [1107552 2012-08-19] ()
HKU\lenovo\...\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet [5252408 2010-05-31] (Yahoo! Inc.)
HKU\lenovo\...\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
HKU\lenovo\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [202024 2007-10-23] (Nero AG)
HKU\lenovo\...\Run: [Facebook Update] "C:\Users\lenovo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-11-09] (Facebook Inc.)
HKU\lenovo\...\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED [1022352 2012-07-01] (BitTorrent, Inc.)
HKU\lenovo\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17875120 2012-10-19] (Skype Technologies S.A.)
HKU\lenovo\...\Winlogon: [Shell] explorer.exe,C:\Users\lenovo\AppData\Roaming\skype.dat [110592 2011-11-16] ()
HKLM\...\Runonce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/w...4"&"ver=9.0.894 [x]
AppInit_DLLs: acaptuser32.dll
Tcpip\..\Interfaces\{9BE35EF2-DA63-4E17-BD82-2A3FBDE19656}: [NameServer]202.148.200.3 202.148.202.4
Tcpip\..\Interfaces\{C6452A0B-896D-4C8C-A55E-13049C5B6ABA}: [NameServer]202.148.200.3 202.148.202.4
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\lenovo\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Services (Whitelisted) ===================

2 Aircel. RunOuc; C:\Program Files\Aircel\UpdateDog\ouc.exe [655712 2012-11-17] ()
3 AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe [167264 2011-11-10] ()
2 avgfws; "C:\Program Files\AVG\AVG10\avgfws.exe" [2708024 2011-03-09] (AVG Technologies CZ, s.r.o.)
2 AVGIDSAgent; "C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe" [7391072 2012-01-31] (AVG Technologies CZ, s.r.o.)
2 avgwd; "C:\Program Files\AVG\AVG10\avgwdsvc.exe" [269520 2011-02-07] (AVG Technologies CZ, s.r.o.)
2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [582944 2009-08-11] (Broadcom Corporation.)
2 Change Modem Device Service; "C:\Windows\system32\ChgService.exe" -service [135168 2010-02-24] ()
2 HWDeviceService.exe; "C:\ProgramData\DatacardService\HWDeviceService.exe" -/service [271712 2011-03-14] ()
2 vToolbarUpdater11.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [935008 2012-08-19] ()

==================== Drivers (Whitelisted) ====================

3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [21256 2009-09-02] (Lenovo Corporation)
1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6x.sys [54112 2010-07-11] (AVG Technologies CZ, s.r.o.)
3 AVGIDSDriver; C:\Windows\System32\DRIVERS\AVGIDSDriver.Sys [134480 2011-05-27] (AVG Technologies CZ, s.r.o. )
0 AVGIDSEH; C:\Windows\System32\DRIVERS\AVGIDSEH.Sys [22992 2011-02-21] (AVG Technologies CZ, s.r.o. )
3 AVGIDSFilter; C:\Windows\System32\DRIVERS\AVGIDSFilter.Sys [24144 2011-02-09] (AVG Technologies CZ, s.r.o. )
3 AVGIDSShim; C:\Windows\System32\DRIVERS\AVGIDSShim.Sys [21968 2011-02-09] (AVG Technologies CZ, s.r.o. )
1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [255968 2012-11-11] (AVG Technologies CZ, s.r.o.)
1 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [34896 2011-03-01] (AVG Technologies CZ, s.r.o.)
0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [32592 2011-03-16] (AVG Technologies CZ, s.r.o.)
1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [297168 2011-04-04] (AVG Technologies CZ, s.r.o.)
3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [105984 2009-12-16] (QUALCOMM Incorporated)
2 cvintdrv; C:\Windows\System32\Drivers\cvintdrv.sys [7140 2000-09-13] ()
3 FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [36640 2010-10-04] ()
3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [89856 2012-11-17] (Huawei Technologies Co., Ltd.)
3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [26624 2012-11-17] (Huawei Technologies Co., Ltd.)
3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [186880 2012-11-17] (Huawei Technologies Co., Ltd.)
0 LHDmgr; C:\Windows\System32\DRIVERS\LhdX86.sys [32352 2010-01-15] (Lenovo.)
3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [179072 2009-11-08] (Vimicro Corporation)
3 wsvd; C:\Windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink)
3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [x]
3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [x]
3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [x]
3 pccsmcfd; C:\Windows\System32\DRIVERS\pccsmcfd.sys [x]
3 ztemtusbser; C:\Windows\System32\DRIVERS\CT_ZTEMT_U_USBSER.sys [x]
3 ZTEusbmdm6k; C:\Windows\System32\DRIVERS\ZTEusbmdm6k.sys [x]
3 ZTEusbnmea; C:\Windows\System32\DRIVERS\ZTEusbnmea.sys [x]
3 ZTEusbser6k; C:\Windows\System32\DRIVERS\ZTEusbser6k.sys [x]
3 ZTEusbvoice; C:\Windows\System32\DRIVERS\ZTEusbvoice.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-02-02 09:54 - 2013-02-02 09:54 - 00000000 ____D C:\FRST
2013-02-01 19:53 - 2013-02-01 19:53 - 00000000 ____D C:\Users\lenovo\AppData\Local\{60B64FE2-90C1-49EE-BD65-BB240B4126DA}
2013-02-01 19:48 - 2013-02-01 19:48 - 00000000 ____D C:\Users\lenovo\AppData\Local\{4DCCF06F-86C5-4F92-BC03-D66CAD8DBF3A}
2013-02-01 18:41 - 2013-02-01 18:41 - 00000000 ____D C:\Users\lenovo\AppData\Local\{F166C92C-22D9-466E-B31B-607FF4CA689F}
2013-02-01 18:22 - 2013-02-01 18:22 - 00000000 ____D C:\Users\lenovo\AppData\Local\{D7823EBC-1570-4B53-B507-22790D2156ED}
2013-02-01 18:14 - 2013-02-01 18:14 - 00000000 ____D C:\Users\lenovo\AppData\Local\{96C69DF1-8770-4A43-A807-F4AC024D5A55}
2013-02-01 18:10 - 2013-02-01 18:10 - 00000000 ____D C:\Users\lenovo\AppData\Local\{6B1748CE-D4DA-4804-B216-2B1DB8E15FFC}
2013-02-01 12:41 - 2013-02-01 12:41 - 00000000 ____D C:\Users\lenovo\AppData\Local\{5F4C0A91-4B97-4CBC-9FB8-4953FFBDADB6}
2013-02-01 12:35 - 2013-02-01 12:35 - 00000000 ____D C:\Users\lenovo\AppData\Local\{09602B99-357C-4ACA-A5E3-11FCA04DD6E9}
2013-02-01 12:25 - 2013-02-01 12:25 - 00000000 ____D C:\Users\lenovo\AppData\Local\{8559D7E5-7E6F-4EE4-9BD7-693FBE75D224}
2013-02-01 12:18 - 2013-02-01 12:18 - 00000000 ____D C:\Users\lenovo\AppData\Local\{E925BD0E-3C3B-4077-9FF0-1440FE1B560F}
2013-02-01 12:13 - 2013-02-01 20:07 - 00000004 ____A C:\Users\lenovo\AppData\Roaming\skype.ini
2013-02-01 12:08 - 2013-02-01 12:08 - 00110592 ____A C:\Users\lenovo\Downloads\Porn_with_Animals_Movie_82.mpeg.exe
2013-02-01 09:43 - 2013-02-01 10:01 - 16592780 ____A C:\Users\lenovo\Downloads\3d-splicing-audio-title.mp4
2013-02-01 08:08 - 2013-02-01 08:08 - 00021578 ____A C:\Users\lenovo\Downloads\guide to be constituted.xlsx
2013-02-01 07:28 - 2013-02-01 07:28 - 00000000 ____D C:\Users\lenovo\AppData\Local\{72EA8365-67EE-49EA-B678-7045A473381B}
2013-01-31 23:49 - 2013-01-31 23:49 - 00000000 ____D C:\Users\lenovo\AppData\Local\{5100EC6A-7868-4E73-8D10-C81D8E6A6E2C}
2013-01-30 21:10 - 2013-01-31 08:19 - 00000000 ____D C:\Users\lenovo\Downloads\NATURE GENETICS
2013-01-30 21:09 - 2013-01-30 21:09 - 00000000 ____D C:\Users\lenovo\AppData\Local\{DE92D385-AC4D-42B9-A4C4-639CDAE15D00}
2013-01-30 10:05 - 2013-01-30 10:05 - 00000000 ____D C:\Users\lenovo\AppData\Local\{96C7D605-378E-4069-9198-ABE6DAEB1F53}
2013-01-26 06:57 - 2013-01-26 06:57 - 00000000 ____D C:\Users\lenovo\AppData\Local\{40C29ED5-961C-46BE-AD2B-EA38C74FABF9}
2013-01-24 19:18 - 2013-01-24 19:18 - 00000000 ____D C:\Users\lenovo\AppData\Local\{61119B37-96A5-4971-83DD-D3A5128CD22B}
2013-01-23 20:01 - 2013-01-23 20:01 - 00000000 ____D C:\Users\lenovo\AppData\Local\{D8D572DC-12F7-4094-8A06-43F6A9BF96BF}
2013-01-23 06:56 - 2013-01-23 06:56 - 00000000 ____D C:\Users\lenovo\AppData\Local\{31A9554B-8BFC-4F03-94A4-56FD0CF27C77}
2013-01-22 02:37 - 2013-01-22 02:37 - 07891968 ____A C:\Users\lenovo\Downloads\Cell Signaling-2.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 05481984 ____A C:\Users\lenovo\Downloads\cytoskeleton.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 04816384 ____A C:\Users\lenovo\Downloads\Cell Biology-Introduction.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 03809280 ____A C:\Users\lenovo\Downloads\Cell Adhesion.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 03716608 ____A C:\Users\lenovo\Downloads\atherosclerosis.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 03426816 ____A C:\Users\lenovo\Downloads\Cell-cell adhesion.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 01384960 ____A C:\Users\lenovo\Downloads\Cell Membranes-3.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 00984750 ____A C:\Users\lenovo\Downloads\cellbio.pptx
2013-01-22 02:37 - 2013-01-22 02:37 - 00824832 ____A C:\Users\lenovo\Downloads\Active Transport-5.ppt
2013-01-20 18:10 - 2013-01-20 18:10 - 00000000 ____D C:\Users\lenovo\AppData\Local\{47A73A0A-B73C-4A26-AE9B-B5F35F1E236E}
2013-01-19 01:40 - 2013-01-19 01:40 - 00000000 ____D C:\Users\lenovo\AppData\Local\{560161A7-DE4B-4540-94D2-41ADF9165F4D}
2013-01-18 11:23 - 2013-01-18 11:23 - 00000000 ____D C:\Users\lenovo\AppData\Local\{9E6A5991-C887-4657-9767-B5BFA1CB0BDF}
2013-01-16 19:42 - 2013-01-16 19:42 - 00000000 ____D C:\Users\lenovo\AppData\Local\{28E384E8-64D9-4DD7-A7A4-7430AD566E14}
2013-01-15 07:17 - 2013-01-15 07:17 - 00000000 ____D C:\Users\lenovo\AppData\Local\{0E4D3CB4-63AB-4F20-80E5-779A531D7EE0}
2013-01-13 21:14 - 2013-01-24 11:12 - 00000000 ____D C:\Users\lenovo\Desktop\NCBS
2013-01-13 18:43 - 2013-01-13 18:43 - 00000000 ____D C:\Users\lenovo\AppData\Local\{35270F31-EA70-4E4D-80B7-B7ECD24BB806}
2013-01-12 19:13 - 2013-01-12 19:13 - 00000000 ____D C:\Users\lenovo\AppData\Local\{A720B37E-3858-419A-A5E0-053B7DB7A8B0}
2013-01-11 23:58 - 2013-01-11 23:58 - 00000000 ____D C:\Users\lenovo\AppData\Local\{47B7C0A8-187B-4496-9AAF-23232988AADB}
2013-01-11 19:36 - 2013-01-11 19:36 - 00000000 ____D C:\Users\lenovo\AppData\Local\{ACDF182D-66FD-4C26-BF11-CBD67879BE9E}
2013-01-11 09:26 - 2013-01-11 09:26 - 00000000 ____D C:\Users\lenovo\AppData\Local\{049CCDA5-A5FB-49E4-9092-9BAD5D74AD56}
2013-01-10 09:48 - 2013-01-10 09:48 - 00000000 ____D C:\Users\lenovo\AppData\Local\{951AC951-7B02-4BF2-87AB-02FD836A3910}
2013-01-10 03:15 - 2013-01-10 03:15 - 00000000 ____D C:\Users\lenovo\AppData\Local\{CEB6C2E0-5905-4837-AFF0-2517770DE708}
2013-01-07 23:07 - 2013-01-07 23:07 - 00000000 ____D C:\Users\lenovo\AppData\Local\{D2E7C9D7-5519-466D-A3D2-7BA480C9AD8A}
2013-01-07 00:35 - 2013-01-07 00:35 - 00000000 ____D C:\Users\lenovo\AppData\Local\{FA2E81F9-1FAF-45F8-ABAA-A3168EAFE8E5}

==================== One Month Modified Files and Folders ========

2013-02-02 09:54 - 2013-02-02 09:54 - 00000000 ____D C:\FRST
2013-02-01 20:08 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-02-01 20:08 - 2009-07-13 20:39 - 00295827 ____A C:\Windows\setupact.log
2013-02-01 20:07 - 2013-02-01 12:13 - 00000004 ____A C:\Users\lenovo\AppData\Roaming\skype.ini
2013-02-01 20:04 - 2009-07-13 20:34 - 00017904 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-02-01 20:04 - 2009-07-13 20:34 - 00017904 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-02-01 20:03 - 2011-01-29 02:22 - 00000000 ____D C:\Users\lenovo\AppData\Roaming\uTorrent
2013-02-01 20:01 - 2011-01-08 17:52 - 01131439 ____A C:\Windows\WindowsUpdate.log
2013-02-01 19:53 - 2013-02-01 19:53 - 00000000 ____D C:\Users\lenovo\AppData\Local\{60B64FE2-90C1-49EE-BD65-BB240B4126DA}
2013-02-01 19:53 - 2011-10-27 00:45 - 00000000 ____D C:\Users\lenovo\Tracing
2013-02-01 19:52 - 2012-09-17 02:01 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-02-01 19:48 - 2013-02-01 19:48 - 00000000 ____D C:\Users\lenovo\AppData\Local\{4DCCF06F-86C5-4F92-BC03-D66CAD8DBF3A}
2013-02-01 19:44 - 2011-01-28 22:06 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-936847727-1722016697-3553098207-1000UA.job
2013-02-01 19:30 - 2012-04-07 08:05 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-02-01 19:21 - 2012-09-17 02:01 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-02-01 19:17 - 2011-10-27 20:35 - 00000932 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-936847727-1722016697-3553098207-1000UA.job
2013-02-01 18:41 - 2013-02-01 18:41 - 00000000 ____D C:\Users\lenovo\AppData\Local\{F166C92C-22D9-466E-B31B-607FF4CA689F}
2013-02-01 18:22 - 2013-02-01 18:22 - 00000000 ____D C:\Users\lenovo\AppData\Local\{D7823EBC-1570-4B53-B507-22790D2156ED}
2013-02-01 18:14 - 2013-02-01 18:14 - 00000000 ____D C:\Users\lenovo\AppData\Local\{96C69DF1-8770-4A43-A807-F4AC024D5A55}
2013-02-01 18:10 - 2013-02-01 18:10 - 00000000 ____D C:\Users\lenovo\AppData\Local\{6B1748CE-D4DA-4804-B216-2B1DB8E15FFC}
2013-02-01 12:41 - 2013-02-01 12:41 - 00000000 ____D C:\Users\lenovo\AppData\Local\{5F4C0A91-4B97-4CBC-9FB8-4953FFBDADB6}
2013-02-01 12:35 - 2013-02-01 12:35 - 00000000 ____D C:\Users\lenovo\AppData\Local\{09602B99-357C-4ACA-A5E3-11FCA04DD6E9}
2013-02-01 12:26 - 2011-01-29 01:19 - 00000000 ____D C:\Users\lenovo\AppData\Roaming\Skype
2013-02-01 12:25 - 2013-02-01 12:25 - 00000000 ____D C:\Users\lenovo\AppData\Local\{8559D7E5-7E6F-4EE4-9BD7-693FBE75D224}
2013-02-01 12:18 - 2013-02-01 12:18 - 00000000 ____D C:\Users\lenovo\AppData\Local\{E925BD0E-3C3B-4077-9FF0-1440FE1B560F}
2013-02-01 12:08 - 2013-02-01 12:08 - 00110592 ____A C:\Users\lenovo\Downloads\Porn_with_Animals_Movie_82.mpeg.exe
2013-02-01 12:08 - 2012-10-02 06:53 - 00000000 ____A C:\Users\lenovo\AppData\Local\prvlcl.dat
2013-02-01 10:01 - 2013-02-01 09:43 - 16592780 ____A C:\Users\lenovo\Downloads\3d-splicing-audio-title.mp4
2013-02-01 09:43 - 2011-01-28 22:06 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-936847727-1722016697-3553098207-1000Core.job
2013-02-01 08:08 - 2013-02-01 08:08 - 00021578 ____A C:\Users\lenovo\Downloads\guide to be constituted.xlsx
2013-02-01 07:31 - 2012-08-18 06:34 - 00000000 ____D C:\Windows\System32\Drivers\AVG
2013-02-01 07:28 - 2013-02-01 07:28 - 00000000 ____D C:\Users\lenovo\AppData\Local\{72EA8365-67EE-49EA-B678-7045A473381B}
2013-01-31 23:49 - 2013-01-31 23:49 - 00000000 ____D C:\Users\lenovo\AppData\Local\{5100EC6A-7868-4E73-8D10-C81D8E6A6E2C}
2013-01-31 08:19 - 2013-01-30 21:10 - 00000000 ____D C:\Users\lenovo\Downloads\NATURE GENETICS
2013-01-31 07:17 - 2011-10-27 20:35 - 00000910 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-936847727-1722016697-3553098207-1000Core.job
2013-01-30 21:09 - 2013-01-30 21:09 - 00000000 ____D C:\Users\lenovo\AppData\Local\{DE92D385-AC4D-42B9-A4C4-639CDAE15D00}
2013-01-30 10:05 - 2013-01-30 10:05 - 00000000 ____D C:\Users\lenovo\AppData\Local\{96C7D605-378E-4069-9198-ABE6DAEB1F53}
2013-01-29 17:55 - 2011-01-08 04:59 - 00000000 ____D C:\Users\lenovo\AppData\Roaming\Mozilla
2013-01-28 06:53 - 2012-11-27 02:20 - 00000000 ____D C:\Users\lenovo\Desktop\NATURE NEWS
2013-01-28 06:52 - 2012-12-08 19:03 - 00000000 ____D C:\Users\lenovo\Desktop\IMMUNOTOXIN
2013-01-26 06:57 - 2013-01-26 06:57 - 00000000 ____D C:\Users\lenovo\AppData\Local\{40C29ED5-961C-46BE-AD2B-EA38C74FABF9}
2013-01-24 19:18 - 2013-01-24 19:18 - 00000000 ____D C:\Users\lenovo\AppData\Local\{61119B37-96A5-4971-83DD-D3A5128CD22B}
2013-01-24 11:12 - 2013-01-13 21:14 - 00000000 ____D C:\Users\lenovo\Desktop\NCBS
2013-01-23 20:01 - 2013-01-23 20:01 - 00000000 ____D C:\Users\lenovo\AppData\Local\{D8D572DC-12F7-4094-8A06-43F6A9BF96BF}
2013-01-23 06:56 - 2013-01-23 06:56 - 00000000 ____D C:\Users\lenovo\AppData\Local\{31A9554B-8BFC-4F03-94A4-56FD0CF27C77}
2013-01-22 02:37 - 2013-01-22 02:37 - 07891968 ____A C:\Users\lenovo\Downloads\Cell Signaling-2.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 05481984 ____A C:\Users\lenovo\Downloads\cytoskeleton.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 04816384 ____A C:\Users\lenovo\Downloads\Cell Biology-Introduction.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 03809280 ____A C:\Users\lenovo\Downloads\Cell Adhesion.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 03716608 ____A C:\Users\lenovo\Downloads\atherosclerosis.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 03426816 ____A C:\Users\lenovo\Downloads\Cell-cell adhesion.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 01384960 ____A C:\Users\lenovo\Downloads\Cell Membranes-3.ppt
2013-01-22 02:37 - 2013-01-22 02:37 - 00984750 ____A C:\Users\lenovo\Downloads\cellbio.pptx
2013-01-22 02:37 - 2013-01-22 02:37 - 00824832 ____A C:\Users\lenovo\Downloads\Active Transport-5.ppt
2013-01-21 08:56 - 2011-01-08 04:29 - 00726444 ____A C:\Windows\System32\PerfStringBackup.INI
2013-01-20 18:10 - 2013-01-20 18:10 - 00000000 ____D C:\Users\lenovo\AppData\Local\{47A73A0A-B73C-4A26-AE9B-B5F35F1E236E}
2013-01-19 01:40 - 2013-01-19 01:40 - 00000000 ____D C:\Users\lenovo\AppData\Local\{560161A7-DE4B-4540-94D2-41ADF9165F4D}
2013-01-18 14:59 - 2011-01-08 05:19 - 00000000 ____D C:\Users\lenovo\AppData\Roaming\vlc
2013-01-18 11:23 - 2013-01-18 11:23 - 00000000 ____D C:\Users\lenovo\AppData\Local\{9E6A5991-C887-4657-9767-B5BFA1CB0BDF}
2013-01-16 19:42 - 2013-01-16 19:42 - 00000000 ____D C:\Users\lenovo\AppData\Local\{28E384E8-64D9-4DD7-A7A4-7430AD566E14}
2013-01-16 06:01 - 2012-08-18 06:36 - 00000810 ____A C:\Users\Public\Desktop\AVG 2011.lnk
2013-01-15 07:17 - 2013-01-15 07:17 - 00000000 ____D C:\Users\lenovo\AppData\Local\{0E4D3CB4-63AB-4F20-80E5-779A531D7EE0}
2013-01-13 18:43 - 2013-01-13 18:43 - 00000000 ____D C:\Users\lenovo\AppData\Local\{35270F31-EA70-4E4D-80B7-B7ECD24BB806}
2013-01-12 19:13 - 2013-01-12 19:13 - 00000000 ____D C:\Users\lenovo\AppData\Local\{A720B37E-3858-419A-A5E0-053B7DB7A8B0}
2013-01-11 23:58 - 2013-01-11 23:58 - 00000000 ____D C:\Users\lenovo\AppData\Local\{47B7C0A8-187B-4496-9AAF-23232988AADB}
2013-01-11 19:36 - 2013-01-11 19:36 - 00000000 ____D C:\Users\lenovo\AppData\Local\{ACDF182D-66FD-4C26-BF11-CBD67879BE9E}
2013-01-11 19:36 - 2012-09-17 02:14 - 00002169 ____A C:\Users\lenovo\Desktop\Google Chrome.lnk
2013-01-11 09:26 - 2013-01-11 09:26 - 00000000 ____D C:\Users\lenovo\AppData\Local\{049CCDA5-A5FB-49E4-9092-9BAD5D74AD56}
2013-01-10 09:48 - 2013-01-10 09:48 - 00000000 ____D C:\Users\lenovo\AppData\Local\{951AC951-7B02-4BF2-87AB-02FD836A3910}
2013-01-10 03:15 - 2013-01-10 03:15 - 00000000 ____D C:\Users\lenovo\AppData\Local\{CEB6C2E0-5905-4837-AFF0-2517770DE708}
2013-01-07 23:07 - 2013-01-07 23:07 - 00000000 ____D C:\Users\lenovo\AppData\Local\{D2E7C9D7-5519-466D-A3D2-7BA480C9AD8A}
2013-01-07 00:35 - 2013-01-07 00:35 - 00000000 ____D C:\Users\lenovo\AppData\Local\{FA2E81F9-1FAF-45F8-ABAA-A3168EAFE8E5}

==================== Known DLLs (Whitelisted) =================


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================


==================== Memory info ===========================

Percentage of memory in use: 22%
Total physical RAM: 1910.85 MB
Available physical RAM: 1477.8 MB
Total Pagefile: 1910.85 MB
Available Pagefile: 1481.41 MB
Total Virtual: 2047.88 MB
Available Virtual: 1960.7 MB

==================== Partitions =============================

1 Drive c: (SOFTWARE) (Fixed) (Total:48.73 GB) (Free:19.63 GB) NTFS
2 Drive e: (STUDY MATERIAL) (Fixed) (Total:195.31 GB) (Free:66.24 GB) NTFS
3 Drive f: (ENTERTAINMENT) (Fixed) (Total:221.62 GB) (Free:7.09 GB) NTFS
5 Drive h: () (Removable) (Total:1.92 GB) (Free:1.92 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 1968 MB 0 B

Partitions of Disk 0:
===============

Disk ID: C3FFC3FF

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 48 GB 101 MB
Partition 3 Primary 195 GB 48 GB
Partition 4 Primary 221 GB 244 GB

=========================================================

Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy

=========================================================

Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C SOFTWARE NTFS Partition 48 GB Healthy

=========================================================

Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E STUDY MATER NTFS Partition 195 GB Healthy

=========================================================

Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F ENTERTAINME NTFS Partition 221 GB Healthy

=========================================================

Partitions of Disk 1:
===============

Disk ID: 370DBECB

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1967 MB 16 KB

=========================================================

Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H FAT32 Removable 1967 MB Healthy

=========================================================

Last Boot: 2013-02-02 02:07

==================== End Of Log ============================
  • 0

Advertisements


#2
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Hello and welcome to Geeks to Go. I am sorry that you are having troubles with your computer and will try my best to help you. I know that being infected is very frustrating, but I will be here to help you through the whole process of cleaning. Removing malware can be difficult and complicated and will most likely take many steps, so please stick with me until I have declared your computer clean. I always recommend printing my instructions before following them in case you cannot keep this webpage open. Please be sure to alway follow all steps exactly as they are written and let me know what happens each time. Stop and ask if something unexpected happens or if you are unsure of how to proceed.

Please respect my volunteered time and stay with me until I declare your computer clean. If you are going to be delayed for a while, please let me know.

Please note that I am currently in training as a GeekU Senior. My posts must be reviewed by an instructor, so there may be a slight delay.

I am currently reviewing your logs and will post a fix soon. Posted Image
  • 0

#3
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Hi abrar1588,

Please enter System Recovery Options again.

Run FRST and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt) please post it in your next reply.

If your computer will boot now, continue below:

You have the following Peer-to-Peer program(s) installed:

uTorrent

GeeksToGo does not recommend using such programs, but you should read the description of Peer-to-Peer programs below before deciding for yourself.

Description of Peer-to-Peer (P2P) software.
P2P(Peer-to-Peer) may be a great way to get lots of seemingly freeware, but it is a great way to get infected as well. The program(s) may be safe, but there's no way to tell if the file being shared is infected. P2P programs, more often than not, install adware and/or spyware and worse still, some worms spread via P2P networks, infecting you as well.
Once upon a time, P2P file sharing was fairly safe. This is no longer true. P2P programs form a direct conduit inside your computer, their security measures are easily circumvented, and malware writers are increasingly exploiting them to spread their wares on to your computer. If your P2P program is not configured correctly, your computer may also be sharing more files than you realize. There have been cases where people's passwords, address books and other personal, private, and financial details have been exposed to a file sharing network by a badly configured program.

If you need convincing, please read these short reports on the dangers of peer-2-peer programs and file sharing.We advise removing any P2P programs you have now and avoiding this type of software application. Whether you remove them or not is your decision. But if you decide to keep and use Peer-to-Peer programs I can guarantee that you will be coming back to this forum or another malware forum. If you do choose to keep the program(s), please do not use it / them until the computer is clean and I give the all clear.

Step 2: Run OTL scan.

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Please check the box next to Scan All Users.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic

Step 3: Run aswMBR.

Download aswMBR.exe to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image

Things I need in your next reply:
  • FRST fixlog.txt
  • OTL log
  • Extras log
  • aswMBR log
  • How is your computer running now? Any you missing any files?

  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP