Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

windows 7 Freeze after boot. [Solved]


  • This topic is locked This topic is locked

#31
DrkMachine

DrkMachine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 126 posts
Combofix didn't reboot my system, so I went ahead and rebooted back into safe mode just to make sure there wasn't something that needed completing. And then rebooted back into normal. And it is still freezing.

Combofix Log

ComboFix 13-03-25.01 - User 03/25/2013 11:51:08.1.2 - x64 NETWORK
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4095.3057 [GMT -5:00]
Running from: c:\users\User\Desktop\ComboFix.exe
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\windows\SysWow64\URTTemp
c:\windows\SysWow64\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-02-25 to 2013-03-25 )))))))))))))))))))))))))))))))
.
.
2013-03-25 16:55 . 2013-03-25 16:55 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-03-25 16:55 . 2013-03-25 16:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-03-22 13:55 . 2013-03-22 13:55 -------- d-----w- c:\users\User\AppData\Local\Programs
2013-03-21 17:37 . 2013-03-21 17:37 -------- d-----w- c:\programdata\ATI
2013-03-21 17:37 . 2013-03-21 17:37 -------- d-----w- c:\program files (x86)\AMD AVT
2013-03-21 17:36 . 2013-03-21 17:36 -------- d-----w- c:\program files (x86)\AMD APP
2013-03-21 17:26 . 2013-03-21 17:31 -------- d-----w- c:\windows\system32\catroot2
2013-03-21 16:52 . 2013-03-21 16:54 -------- d-----w- c:\users\User\AppData\Roaming\.technic
2013-03-21 16:49 . 2013-03-21 16:49 310688 ----a-w- c:\windows\system32\javaws.exe
2013-03-21 16:49 . 2013-03-21 16:49 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-03-21 16:49 . 2013-03-21 16:49 188832 ----a-w- c:\windows\system32\javaw.exe
2013-03-21 16:49 . 2013-03-21 16:49 188320 ----a-w- c:\windows\system32\java.exe
2013-03-21 15:55 . 2013-03-21 15:56 -------- d-----w- c:\windows\SysWow64\wbem\Performance
2013-03-21 15:30 . 2013-03-21 15:30 -------- d-----w- C:\RegBackup
2013-03-21 15:29 . 2013-03-21 15:29 -------- d-----w- c:\program files (x86)\Tweaking.com
2013-03-17 14:52 . 2013-03-17 14:52 -------- d-----w- C:\_OTL
2013-02-28 01:36 . 2013-02-28 01:36 -------- d-----w- C:\FRST
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-21 17:21 . 2012-03-31 06:04 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-21 17:21 . 2011-05-13 22:46 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-21 16:49 . 2012-02-26 04:21 1085344 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-03-21 16:49 . 2011-05-29 16:36 963488 ----a-w- c:\windows\system32\deployJava1.dll
2013-02-27 20:50 . 2009-07-13 23:27 74752 ----a-w- c:\windows\system32\ndadmin.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\system32\readreg" [X]
"googletalk"="c:\users\User\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2010-08-26 393216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Razer Nostromo Driver"="c:\program files (x86)\Razer\Nostromo\RazerNostromoSysTray.exe" [2011-07-19 978840]
"Razer Mamba Driver"="c:\program files (x86)\Razer\Mamba\RazerTray.exe" [2009-12-15 3278728]
"CTxfiHlp"="CTXFIHLP.EXE" [2007-04-09 19968]
"CTHelper"="CTHELPER.EXE" [2007-04-09 19456]
"CloneCDTray"="c:\program files (x86)\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"AsioThk32Reg"="CTASIO.DLL" [2007-04-09 80896]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
"AsioReg"="CTASIO.DLL" [2007-04-09 80896]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\system32\READREG" [X]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2011-4-1 1207312]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ 
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-03-11 868848]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [2012-04-17 31432]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2012-04-03 224048]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2012-04-03 130864]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-12-19 240640]
R2 AMP;Active Malware Protection Minifilter Driver;c:\windows\system32\Drivers\amp.sys [2012-05-25 173408]
R2 AMPSE;Active Malware Protection Support Driver;c:\windows\system32\Drivers\ampse.sys [2012-05-25 1496416]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2010-11-09 21992]
R2 vseamps;vseamps;c:\program files\Common Files\Authentium\AntiVirus5\vseamps.exe [2012-05-25 121184]
R2 vsedsps;vsedsps;c:\program files\Common Files\Authentium\AntiVirus5\vsedsps.exe [2012-05-25 119136]
R3 50819778;50819778; [x]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-11-06 96256]
R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [2010-01-06 35840]
R3 HtcUsbMdmV64;HTC Proprietary USB Driver;c:\windows\system32\DRIVERS\HtcUsbMdmV64.sys [2010-03-08 121800]
R3 HtcVCom32;HTC Diagnostic Port;c:\windows\system32\DRIVERS\HtcVComV64.sys [2010-03-08 121800]
R3 mv2;mv2;c:\windows\system32\DRIVERS\mv2.sys [2011-09-28 12904]
R3 OverwolfUpdaterService;Overwolf Updater Service;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [2012-09-13 18360]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 RzSynapse;Razer Driver;c:\windows\system32\DRIVERS\RzSynapse.sys [2011-07-14 157184]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-04-03 147248]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys [2012-04-03 117040]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 vseqrts;vseqrts;c:\program files\Common Files\Authentium\AntiVirus5\vseqrts.exe [2012-05-25 180576]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-05-15 1255736]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster\Driver\WinRing0x64.sys [2010-11-01 14544]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-03-02 187392]
S3 rzjoystk;Razer VJoystick;c:\windows\system32\DRIVERS\rzjoystk.sys [2011-03-24 19968]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2012-04-03 166192]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 17:21]
.
2013-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-08 00:00]
.
2013-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-08 00:00]
.
2013-02-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2925201978-3475927693-2139486491-1000Core.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-23 18:40]
.
2013-03-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2925201978-3475927693-2139486491-1000UA.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-23 18:40]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 163552]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-25 7981088]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
.
------- Supplementary Scan -------
.
uStart Page = https://www.google.com/
mSearch Bar = hxxp://www.google.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 24.220.0.10 24.220.0.11 192.168.1.1
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
SafeBoot-34261847.sys
SafeBoot-69630829.sys
HKLM-Run-AsioReg - CTASIO.DLL
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2925201978-3475927693-2139486491-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b3,bc,d4,6e,be,8b,64,39,71,b1,28,86,f8,17,9c,23,4b,3a,74,eb,ca,23,56,
81,e3,45,68,b6,9d,ba,44,48,b3,70,a8,6f,53,b5,fd,ab,08,7e,f1,f7,be,d8,cc,48,\
"??"=hex:65,34,23,f1,ac,3e,ae,99,14,20,f8,2a,53,ca,02,2f
.
[HKEY_USERS\S-1-5-21-2925201978-3475927693-2139486491-1000\Software\SecuROM\License information*]
"datasecu"=hex:58,99,5d,56,85,33,eb,25,08,84,c9,a0,34,9b,6c,e8,04,d2,3d,bb,03,
24,bb,58,3d,49,85,a1,a4,b7,8f,82,96,43,74,f5,5c,6a,86,49,31,a6,f5,54,67,41,\
"rkeysecu"=hex:ac,ae,da,2f,51,79,87,3a,3b,d6,5e,2f,2f,c9,5e,e3
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-03-25 11:56:41
ComboFix-quarantined-files.txt 2013-03-25 16:56
ComboFix2.txt 2011-05-15 05:27
.
Pre-Run: 423,621,488,640 bytes free
Post-Run: 423,157,710,848 bytes free
.
- - End Of File - - E0D7061EAB8B37A16B6F86417BD8BE07



  • 0

Advertisements


#32
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,161 posts
Try this -
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Driver::
50819778


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
  • 0

#33
DrkMachine

DrkMachine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 126 posts
combofix log

ComboFix 13-03-25.01 - User 03/25/2013 14:59:49.2.2 - x64 NETWORK
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4095.3303 [GMT -5:00]
Running from: c:\users\User\Desktop\ComboFix.exe
Command switches used :: c:\users\User\Desktop\CFScript.txt
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2013-02-25 to 2013-03-25 )))))))))))))))))))))))))))))))
.
.
2013-03-25 20:05 . 2013-03-25 20:05 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-03-25 20:05 . 2013-03-25 20:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-03-22 13:55 . 2013-03-22 13:55 -------- d-----w- c:\users\User\AppData\Local\Programs
2013-03-21 17:37 . 2013-03-21 17:37 -------- d-----w- c:\programdata\ATI
2013-03-21 17:37 . 2013-03-21 17:37 -------- d-----w- c:\program files (x86)\AMD AVT
2013-03-21 17:36 . 2013-03-21 17:36 -------- d-----w- c:\program files (x86)\AMD APP
2013-03-21 17:26 . 2013-03-21 17:31 -------- d-----w- c:\windows\system32\catroot2
2013-03-21 16:52 . 2013-03-21 16:54 -------- d-----w- c:\users\User\AppData\Roaming\.technic
2013-03-21 16:49 . 2013-03-21 16:49 310688 ----a-w- c:\windows\system32\javaws.exe
2013-03-21 16:49 . 2013-03-21 16:49 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-03-21 16:49 . 2013-03-21 16:49 188832 ----a-w- c:\windows\system32\javaw.exe
2013-03-21 16:49 . 2013-03-21 16:49 188320 ----a-w- c:\windows\system32\java.exe
2013-03-21 15:55 . 2013-03-21 15:56 -------- d-----w- c:\windows\SysWow64\wbem\Performance
2013-03-21 15:30 . 2013-03-21 15:30 -------- d-----w- C:\RegBackup
2013-03-21 15:29 . 2013-03-21 15:29 -------- d-----w- c:\program files (x86)\Tweaking.com
2013-03-17 14:52 . 2013-03-17 14:52 -------- d-----w- C:\_OTL
2013-02-28 01:36 . 2013-02-28 01:36 -------- d-----w- C:\FRST
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-21 17:21 . 2012-03-31 06:04 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-21 17:21 . 2011-05-13 22:46 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-21 16:49 . 2012-02-26 04:21 1085344 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-03-21 16:49 . 2011-05-29 16:36 963488 ----a-w- c:\windows\system32\deployJava1.dll
2013-02-27 20:50 . 2009-07-13 23:27 74752 ----a-w- c:\windows\system32\ndadmin.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\system32\readreg" [X]
"googletalk"="c:\users\User\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2010-08-26 393216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Razer Nostromo Driver"="c:\program files (x86)\Razer\Nostromo\RazerNostromoSysTray.exe" [2011-07-19 978840]
"Razer Mamba Driver"="c:\program files (x86)\Razer\Mamba\RazerTray.exe" [2009-12-15 3278728]
"CTxfiHlp"="CTXFIHLP.EXE" [2007-04-09 19968]
"CTHelper"="CTHELPER.EXE" [2007-04-09 19456]
"CloneCDTray"="c:\program files (x86)\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"AsioThk32Reg"="CTASIO.DLL" [2007-04-09 80896]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
"AsioReg"="CTASIO.DLL" [2007-04-09 80896]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\system32\READREG" [X]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2011-4-1 1207312]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ 
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-03-11 868848]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys [2012-04-17 31432]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2012-04-03 224048]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2012-04-03 130864]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-12-19 240640]
R2 AMP;Active Malware Protection Minifilter Driver;c:\windows\system32\Drivers\amp.sys [2012-05-25 173408]
R2 AMPSE;Active Malware Protection Support Driver;c:\windows\system32\Drivers\ampse.sys [2012-05-25 1496416]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2010-11-09 21992]
R2 vseamps;vseamps;c:\program files\Common Files\Authentium\AntiVirus5\vseamps.exe [2012-05-25 121184]
R2 vsedsps;vsedsps;c:\program files\Common Files\Authentium\AntiVirus5\vsedsps.exe [2012-05-25 119136]
R3 50819778;50819778; [x]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-11-06 96256]
R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [2010-01-06 35840]
R3 HtcUsbMdmV64;HTC Proprietary USB Driver;c:\windows\system32\DRIVERS\HtcUsbMdmV64.sys [2010-03-08 121800]
R3 HtcVCom32;HTC Diagnostic Port;c:\windows\system32\DRIVERS\HtcVComV64.sys [2010-03-08 121800]
R3 mv2;mv2;c:\windows\system32\DRIVERS\mv2.sys [2011-09-28 12904]
R3 OverwolfUpdaterService;Overwolf Updater Service;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [2012-09-13 18360]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 RzSynapse;Razer Driver;c:\windows\system32\DRIVERS\RzSynapse.sys [2011-07-14 157184]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-04-03 147248]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys [2012-04-03 117040]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 vseqrts;vseqrts;c:\program files\Common Files\Authentium\AntiVirus5\vseqrts.exe [2012-05-25 180576]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-05-15 1255736]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster\Driver\WinRing0x64.sys [2010-11-01 14544]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-03-02 187392]
S3 rzjoystk;Razer VJoystick;c:\windows\system32\DRIVERS\rzjoystk.sys [2011-03-24 19968]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2012-04-03 166192]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 17:21]
.
2013-03-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-08 00:00]
.
2013-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-08 00:00]
.
2013-02-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2925201978-3475927693-2139486491-1000Core.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-23 18:40]
.
2013-03-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2925201978-3475927693-2139486491-1000UA.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-23 18:40]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 163552]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-25 7981088]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
"AsioReg"="CTASIO.DLL" [BU]
.
------- Supplementary Scan -------
.
uStart Page = https://www.google.com/
mSearch Bar = hxxp://www.google.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 24.220.0.10 24.220.0.11 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2925201978-3475927693-2139486491-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b3,bc,d4,6e,be,8b,64,39,71,b1,28,86,f8,17,9c,23,4b,3a,74,eb,ca,23,56,
81,e3,45,68,b6,9d,ba,44,48,b3,70,a8,6f,53,b5,fd,ab,08,7e,f1,f7,be,d8,cc,48,\
"??"=hex:65,34,23,f1,ac,3e,ae,99,14,20,f8,2a,53,ca,02,2f
.
[HKEY_USERS\S-1-5-21-2925201978-3475927693-2139486491-1000\Software\SecuROM\License information*]
"datasecu"=hex:58,99,5d,56,85,33,eb,25,08,84,c9,a0,34,9b,6c,e8,04,d2,3d,bb,03,
24,bb,58,3d,49,85,a1,a4,b7,8f,82,96,43,74,f5,5c,6a,86,49,31,a6,f5,54,67,41,\
"rkeysecu"=hex:ac,ae,da,2f,51,79,87,3a,3b,d6,5e,2f,2f,c9,5e,e3
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-03-25 15:07:20
ComboFix-quarantined-files.txt 2013-03-25 20:07
ComboFix2.txt 2013-03-25 16:56
ComboFix3.txt 2011-05-15 05:27
.
Pre-Run: 423,433,961,472 bytes free
Post-Run: 423,358,816,256 bytes free
.
- - End Of File - - 9D1942D802F0A9161ADA21FC8E7FBEA7



  • 0

#34
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,161 posts
That did not work, so I want to look deeper for that driver -
Step 1
You should still have FSS, but if you removed it I will include the download link -

Please download Farbar Service Scanner and run it on the computer with the issue.
In the Search box please paste in the following:

50819778

Press "Search".
It will create a log (FSS.txt) in the same directory the tool is run.
Please copy and paste the log to your reply.

Step 2
It seems that your F: drive is throwing some errors. I believe it's a USB drive
Please run a chkdsk on that drive, lets see if that helps out.
Open a command prompt (Start orb > type CMD > click on CMD.exe)
type the following at the prompt:

chkdsk f: /f

then press enter
  • 0

#35
DrkMachine

DrkMachine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 126 posts
Farbar Service Scanner Version: 03-03-2013
Ran by User (administrator) on 26-03-2013 at 15:04:40
Windows 7 Ultimate Service Pack 1 (X64)

************************************************
======== Search: "50819778" =========

====== End Of Search ======


  • 0

#36
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,161 posts
Hi again,
This will take you a little while to do, unless we get lucky right away :)
All of your reboots in this process should be to Normal Mode

Next we will check for driver conflicts

Step 1: Start MSConfig

Click Start, type msconfig in the Start Search box, and then press ENTER.
If you are prompted for an administrator password or for a confirmation, type the password, or provide confirmation.

Step 2: Configure Selective Startup options

1.In the System Configuration Utility dialog box, click Selective Startup on the General tab.

Posted Image

2.Click to clear the Load Startup Items check box.
Note The Use Original Boot.ini check box is unavailable.

3.Click the Services tab.

Posted Image

4.Click to select the Hide All Microsoft Services check box.
5.Click Disable All, and then click OK.
6. When you are prompted, click Restart.

Once back in windows does the problem still occur ?

If not then re-enable 50% of the drivers via MSConfig and reboot
  • 0

#37
DrkMachine

DrkMachine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 126 posts
hello again,

Unfortunately it is still freezing.


  • 0

#38
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,161 posts
So when you disabled all of the services, you still were freezing?

Let's move on to this:
This tool will disable any cd emulation drivers, and you can run it again to re-enable them after we see if the cures the problem.

Please download DeFogger to your desktop.

  • Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger may ask you to reboot the machine, if it does - click OK

Please reboot into normal mode, and see if it freezes now.
  • 0

#39
DrkMachine

DrkMachine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 126 posts
Yup still freezing after both fixes.


  • 0

#40
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,161 posts
Hi again,
First of all, thanks for all your patience with this. It seems to be a pretty tough nut to crack!

Still have a few things to try -
Let's rule out a corrupted user profile, by creating a new user profile, and logging into normal mode with it.

So from safe mode do the following -
  • To open User Accounts, click the Start button Posted Image, click Control Panel, click User Accounts and Family Safety, and then click User Accounts.
  • Click Manage another account. Posted ImageIf you're prompted for an administrator password or confirmation, type the password or provide confirmation.
  • Click Create a new account.
  • Type the name you want to give the user account, Select Administrator for the account type, and then click Create Account.

Now please try to start up in normal mode, using the new user that you just created.

Let me know how this works.
  • 0

Advertisements


#41
DrkMachine

DrkMachine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 126 posts
hey,

Thanks for YOUR patience and continued support :).

New account still freezing, but I got a popup this time, "Microsoft Windows has stopped responding". I had one of those "No, really?" moments. lol


  • 0

#42
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,161 posts
Now we know it's not a corrupted user profile.
First I want to look with one of the tools the techs here use, and then I would like you to do a System File Check (SFC)
the SFC will verify the integrity of all the protected Windows system files and will replace them if necessary


Step 1
Please download SINO by Artellos.
  • Save SINO to your desktop and right click SINO.exe and select Run as administrator. (If you downloaded the ZIP version you will need to extract it first)
  • Then please check the following checkboxes:

    System Info
    Services
    Boot Check
    Tasklist
    Startup Items
    Event Log
    BBCode

  • Once checked, hit the Run Scan! button and wait for the program to finish the scan.
  • A notepad window will pop up. Please copy all of the content into your next reply.
Note: If you try to interact with the program once it's started scanning it might appear to hang. The scan however will continue.

Step 2
This one is probably going to take a while.

Run System File Check
First we need to open an elevated command prompt - click the Start orb, and type CMD into the search box, but don't press enter.
You will see cmd.exe in the search results, please right click it and select Run as administrator.
In the elevated command prompt, type sfc /scannow and press Enter (note that there is a space between the "c" and the "/")
Posted Image

This will most likely take a long time to run. If it does not find anything to fix it will say:
Windows Resource Protection did not find any integrity violations.

After it is complete, keep the elevated command prompt open and copy the text below:

findstr /c:"[SR]" %windir%\Logs\CBS\CBS.log >"%userprofile%\Desktop\sfcdetails.txt"

Paste this text into the elevated command prompt by right clicking anywhere in the black and selecting Paste and then press Enter
Close the command prompt
Open the file sfcdetails.txt which has appeared on your desktop, copy all the text and paste it in your next response.

In your next reply I would like to see:
  • SINO log
  • sfcdetails.txt log

  • 0

#43
DrkMachine

DrkMachine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 126 posts
Sino log

System Investigator by Olrik
Log Created On: 2122_28-03-2013
SINO Version: 3.1.0.0

Total RAM: 4095 MB | Free RAM: 3501 MB | Pagefile Size: 4095 MB
C: | 403820 MB out of 701989 MB Free | Local Fixed Disk
D: | 0 MB out of 3167 MB Free | CD-ROM Disc
E: | None | CD-ROM Disc

<<<< System Information >>>>

Computer Name: MACHINE-PC
Username: User
Language Setting: ENU
Windows Directory: C:\Windows
Windows Version: Windows 7 Service Pack 1
UAC Status: On
Windows Mode: Safe Mode with Networking

<<<< Tasklist >>>>

[System Idle Process] - Process ID: 0
[System] - Process ID: 4
[smss.exe] - Process ID: 244
[C:\Windows\system32\csrss.exe] - Process ID: 328
[C:\Windows\system32\csrss.exe] - Process ID: 368
[C:\Windows\system32\wininit.exe] - Process ID: 376
[C:\Windows\system32\winlogon.exe] - Process ID: 416
[C:\Windows\system32\services.exe] - Process ID: 464
[C:\Windows\system32\lsass.exe] - Process ID: 472
[C:\Windows\system32\lsm.exe] - Process ID: 480
[C:\Windows\system32\svchost.exe] - Process ID: 572
[C:\Windows\system32\svchost.exe] - Process ID: 644
[C:\Windows\System32\svchost.exe] - Process ID: 736
[C:\Windows\system32\svchost.exe] - Process ID: 772
[C:\Windows\system32\svchost.exe] - Process ID: 816
[C:\Windows\system32\svchost.exe] - Process ID: 868
[C:\Windows\system32\svchost.exe] - Process ID: 896
[C:\Windows\system32\svchost.exe] - Process ID: 1012
[C:\Windows\Explorer.EXE] - Process ID: 1248
[C:\Windows\system32\ctfmon.exe] - Process ID: 1292
[C:\Windows\system32\svchost.exe] - Process ID: 1532
[C:\Users\User\AppData\Local\Temp\SINO\SINO.exe] - Process ID: 1600
[C:\Windows\sysWOW64\wbem\WmiPrvSE.exe] - Process ID: 1832
[C:\Windows\system32\wbem\wmiprvse.exe] - Process ID: 1888

<<<< Startup Items >>>>


<<<< MS Services >>>>

Base Filtering Engine (BFE) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
Cryptographic Services (CryptSvc) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k NetworkService
DCOM Server Process Launcher (DcomLaunch) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k DcomLaunch
DHCP Client (Dhcp) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
DNS Client (Dnscache) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k NetworkService
Extensible Authentication Protocol (EapHost) - Running [Manual | Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
Windows Event Log (eventlog) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
IKE and AuthIP IPsec Keying Modules (IKEEXT) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
CNG Key Isolation (KeyIso) - Running [Manual | Stoppable | Not_Pausable] - C:\Windows\system32\lsass.exe
Workstation (LanmanWorkstation) - Running [Auto | Stoppable | Pausable] - C:\Windows\System32\svchost.exe -k NetworkService
TCP/IP NetBIOS Helper (lmhosts) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
Windows Firewall (MpsSvc) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
Network Connections (Netman) - Running [Manual | Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Network List Service (netprofm) - Running [Manual | Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalService
Network Location Awareness (NlaSvc) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k NetworkService
Network Store Interface Service (nsi) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalService
Plug and Play (PlugPlay) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k DcomLaunch
IPsec Policy Agent (PolicyAgent) - Running [Manual | Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
Power (Power) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k DcomLaunch
User Profile Service (ProfSvc) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
RPC Endpoint Mapper (RpcEptMapper) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k RPCSS
Remote Procedure Call (RPC) (RpcSs) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k rpcss
Windows Management Instrumentation (Winmgmt) - Running [Auto | Stoppable | Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
WLAN AutoConfig (Wlansvc) - Running [Auto | Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Windows Driver Foundation - User-mode Driver Framework (wudfsvc) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Application Experience (AeLookupSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
Application Layer Gateway Service (ALG) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\alg.exe
Application Identity (AppIDSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Application Information (Appinfo) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
Application Management (AppMgmt) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
ASP.NET State Service (aspnet_state) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
Windows Audio Endpoint Builder (AudioEndpointBuilder) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Windows Audio (AudioSrv) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
ActiveX Installer (AxInstSV) (AxInstSV) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k AxInstSVGroup
BitLocker Drive Encryption Service (BDESVC) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
Background Intelligent Transfer Service (BITS) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
Bonjour Service (Bonjour Service) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\Program Files\Bonjour\mDNSResponder.exe"
Computer Browser (Browser) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
Bluetooth Support Service (bthserv) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k bthsvcs
Certificate Propagation (CertPropSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
Microsoft .NET Framework NGEN v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
COM+ System Application (COMSysApp) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Offline Files (CscService) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Disk Defragmenter (defragsvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k defragsvc
Wired AutoConfig (dot3svc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Diagnostic Policy Service (DPS) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
Encrypting File System (EFS) (EFS) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\lsass.exe
Windows Media Center Receiver Service (ehRecvr) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\ehome\ehRecvr.exe
Windows Media Center Scheduler Service (ehSched) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\ehome\ehsched.exe
COM+ Event System (EventSystem) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalService
Fax (Fax) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\fxssvc.exe
Function Discovery Provider Host (fdPHost) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalService
Function Discovery Resource Publication (FDResPub) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Windows Font Cache Service (FontCache) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
Group Policy Client (gpsvc) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
Human Interface Device Access (hidserv) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Health Key and Certificate Management (hkmsvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
HomeGroup Listener (HomeGroupListener) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
HomeGroup Provider (HomeGroupProvider) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
Windows CardSpace (idsvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe"
PnP-X IP Bus Enumerator (IPBusEnum) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
IP Helper (iphlpsvc) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k NetSvcs
KtmRm for Distributed Transaction Coordinator (KtmRm) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation
Server (LanmanServer) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
Link-Layer Topology Discovery Mapper (lltdsvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalService
Media Center Extender Service (Mcx2Svc) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Multimedia Class Scheduler (MMCSS) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
Distributed Transaction Coordinator (MSDTC) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\msdtc.exe
Microsoft iSCSI Initiator Service (MSiSCSI) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
Windows Installer (msiserver) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\msiexec.exe /V
Network Access Protection Agent (napagent) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k NetworkService
Netlogon (Netlogon) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\lsass.exe
Net.Tcp Port Sharing Service (NetTcpPortSharing) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
Peer Networking Identity Manager (p2pimsvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServicePeerNet
Peer Networking Grouping (p2psvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServicePeerNet
Program Compatibility Assistant Service (PcaSvc) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
BranchCache (PeerDistSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k PeerDist
Performance Logs & Alerts (pla) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
PNRP Machine Name Publication Service (PNRPAutoReg) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServicePeerNet
Peer Name Resolution Protocol (PNRPsvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServicePeerNet
Protected Storage (ProtectedStorage) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\lsass.exe
Quality Windows Audio Video Experience (QWAVE) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Remote Access Auto Connection Manager (RasAuto) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
Remote Access Connection Manager (RasMan) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
Routing and Remote Access (RemoteAccess) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
Remote Registry (RemoteRegistry) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k regsvc
Remote Procedure Call (RPC) Locator (RpcLocator) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\locator.exe
Security Accounts Manager (SamSs) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\lsass.exe
Smart Card (SCardSvr) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Task Scheduler (Schedule) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
Smart Card Removal Policy (SCPolicySvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
Windows Backup (SDRSVC) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k SDRSVC
Secondary Logon (seclogon) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
System Event Notification Service (SENS) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
Adaptive Brightness (SensrSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Remote Desktop Configuration (SessionEnv) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
Internet Connection Sharing (ICS) (SharedAccess) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
Shell Hardware Detection (ShellHWDetection) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
SNMP Trap (SNMPTRAP) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\snmptrap.exe
Print Spooler (Spooler) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\spoolsv.exe
Software Protection (sppsvc) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\sppsvc.exe
SPP Notification Service (sppuinotify) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalService
SSDP Discovery (SSDPSRV) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Secure Socket Tunneling Protocol Service (SstpSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalService
Windows Image Acquisition (WIA) (stisvc) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k imgsvc
Microsoft Software Shadow Copy Provider (swprv) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k swprv
Superfetch (SysMain) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Tablet PC Input Service (TabletInputService) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Telephony (TapiSrv) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k NetworkService
TPM Base Services (TBS) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
Remote Desktop Services (TermService) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k NetworkService
Themes (Themes) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
Thread Ordering Server (THREADORDER) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalService
Distributed Link Tracking Client (TrkWks) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Windows Modules Installer (TrustedInstaller) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\servicing\TrustedInstaller.exe
Interactive Services Detection (UI0Detect) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\UI0Detect.exe
Remote Desktop Services UserMode Port Redirector (UmRdpService) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
UPnP Device Host (upnphost) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Desktop Window Manager Session Manager (UxSms) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Credential Manager (VaultSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\lsass.exe
Virtual Disk (vds) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\vds.exe
Volume Shadow Copy (VSS) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\vssvc.exe
Windows Time (W32Time) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalService
Block Level Backup Engine Service (wbengine) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Windows\system32\wbengine.exe"
Windows Biometric Service (WbioSrvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k WbioSvcGroup
Windows Connect Now - Config Registrar (wcncsvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
Windows Color System (WcsPlugInService) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k wcssvc
Diagnostic Service Host (WdiServiceHost) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalService
Diagnostic System Host (WdiSystemHost) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
WebClient (WebClient) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalService
Windows Event Collector (Wecsvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k NetworkService
Problem Reports and Solutions Control Panel Support (wercplsupport) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k netsvcs
Windows Error Reporting Service (WerSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k WerSvcGroup
Windows Defender (WinDefend) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k secsvcs
WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalService
Windows Remote Management (WS-Management) (WinRM) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k NetworkService
Windows Live ID Sign-in Assistant (wlidsvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WMI Performance Adapter (wmiApSrv) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\wbem\WmiApSrv.exe
Parental Controls (WPCSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
Portable Device Enumerator Service (WPDBusEnum) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
Security Center (wscsvc) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
Windows Search (WSearch) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\SearchIndexer.exe /Embedding
Windows Update (wuauserv) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k netsvcs
WWAN AutoConfig (WwanSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

<<<< Non-MS Services >>>>

Adobe Acrobat Update Service (AdobeARMservice) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
AMD External Events Utility (AMD External Events Utility) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\Windows\system32\atiesrxx.exe
Apple Mobile Device (Apple Mobile Device) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
Microsoft .NET Framework NGEN v2.0.50727_X64 (clr_optimization_v2.0.50727_64) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
Microsoft .NET Framework NGEN v4.0.30319_X86 (clr_optimization_v4.0.30319_32) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
Microsoft .NET Framework NGEN v4.0.30319_X64 (clr_optimization_v4.0.30319_64) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
Google Update Service (gupdate) (gupdate) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
Google Update Service (gupdatem) (gupdatem) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc
InstallDriver Table Manager (IDriverT) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
iPod Service (iPod Service) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\Program Files\iPod\bin\iPodService.exe"
Logitech Bluetooth Service (LBTServ) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
Mozilla Maintenance Service (MozillaMaintenance) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
Net.Msmq Listener Adapter (NetMsmqActivator) - Stopped [Auto | Not_Stoppable | Not_Pausable] - "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator
Net.Pipe Listener Adapter (NetPipeActivator) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
Net.Tcp Listener Adapter (NetTcpActivator) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
Overwolf Updater Service (OverwolfUpdaterService) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
Performance Counter DLL Host (PerfHost) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\SysWow64\perfhost.exe
PnkBstrA (PnkBstrA) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Windows\system32\PnkBstrA.exe
vseamps (vseamps) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe"
vsedsps (vsedsps) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe"
vseqrts (vseqrts) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Authentium\AntiVirus5\vseqrts.exe"
Windows Activation Technologies Service (WatAdminSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Windows\system32\Wat\WatAdminSvc.exe
Zune Windows Mobile Connectivity Service (WMZuneComm) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "c:\Program Files\Zune\WMZuneComm.exe"
Zune Network Sharing Service (ZuneNetworkSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "c:\Program Files\Zune\ZuneNss.exe"
Zune Wireless Configuration Service (ZuneWlanCfgSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "c:\Program Files\Zune\ZuneWlanCfgSvc.exe"

<<<< bcdedit >>>>


<<<< Last 5 Application Errors or Warnings >>>>

Computer Name: Machine-PC | ID: 6000 | Source: Wlclntfy | Type: Warning | Date: 28-3-13 21:20:37 | Log: Application
Message: The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.


Computer Name: Machine-PC | ID: 6000 | Source: Wlclntfy | Type: Warning | Date: 28-3-13 14:31:53 | Log: Application
Message: The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.


Computer Name: Machine-PC | ID: 6000 | Source: Wlclntfy | Type: Warning | Date: 28-3-13 14:31:52 | Log: Application
Message: The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.


Computer Name: Machine-PC | ID: 6000 | Source: Wlclntfy | Type: Warning | Date: 27-3-13 23:7:7 | Log: Application
Message: The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.


Computer Name: Machine-PC | ID: 510 | Source: ESENT | Type: Warning | Date: 27-3-13 22:56:5 | Log: Application
Message: wuaueng.dll (1016) SUS20ClientDataStore: A request to write to the file "C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log" at offset 1189376 (0x0000000000122600) for 512 (0x00000200) bytes succeeded, but took an abnormally long time (74 seconds) to be serviced by the OS. In addition, 0 other I/O requests to this file have also taken an abnormally long time to be serviced since the last message regarding this problem was posted 151 seconds ago. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.


<<<< Last 5 System Errors or Warnings >>>>

Computer Name: Machine-PC | ID: 7001 | Source: Service Control Manager | Type: Error | Date: 28-3-13 21:20:49 | Log: System
Message: The Computer Browser service depends on the Server service which failed to start because of the following error:

%%1068


Computer Name: Machine-PC | ID: 7001 | Source: Service Control Manager | Type: Error | Date: 28-3-13 21:20:49 | Log: System
Message: The Computer Browser service depends on the Server service which failed to start because of the following error:

%%1068


Computer Name: Machine-PC | ID: 7001 | Source: Service Control Manager | Type: Error | Date: 28-3-13 21:20:49 | Log: System
Message: The Computer Browser service depends on the Server service which failed to start because of the following error:

%%1068


Computer Name: Machine-PC | ID: 7001 | Source: Service Control Manager | Type: Error | Date: 28-3-13 21:20:49 | Log: System
Message: The Computer Browser service depends on the Server service which failed to start because of the following error:

%%1068


Computer Name: Machine-PC | ID: 7001 | Source: Service Control Manager | Type: Error | Date: 28-3-13 21:20:49 | Log: System
Message: The Computer Browser service depends on the Server service which failed to start because of the following error:

%%1068


<<<< Special Events >>>>

There were no special events found



------ End of File ------



sfc log

2013-03-28 21:23:53, Info CSI 00000009 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:23:53, Info CSI 0000000a [SR] Beginning Verify and Repair transaction
2013-03-28 21:23:54, Info CSI 0000000c [SR] Verify complete
2013-03-28 21:23:54, Info CSI 0000000d [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:23:54, Info CSI 0000000e [SR] Beginning Verify and Repair transaction
2013-03-28 21:23:55, Info CSI 00000010 [SR] Verify complete
2013-03-28 21:23:55, Info CSI 00000011 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:23:55, Info CSI 00000012 [SR] Beginning Verify and Repair transaction
2013-03-28 21:23:56, Info CSI 00000014 [SR] Verify complete
2013-03-28 21:23:56, Info CSI 00000015 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:23:56, Info CSI 00000016 [SR] Beginning Verify and Repair transaction
2013-03-28 21:23:57, Info CSI 00000018 [SR] Verify complete
2013-03-28 21:23:57, Info CSI 00000019 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:23:57, Info CSI 0000001a [SR] Beginning Verify and Repair transaction
2013-03-28 21:23:59, Info CSI 0000001c [SR] Verify complete
2013-03-28 21:23:59, Info CSI 0000001d [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:23:59, Info CSI 0000001e [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:00, Info CSI 00000020 [SR] Verify complete
2013-03-28 21:24:00, Info CSI 00000021 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:00, Info CSI 00000022 [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:02, Info CSI 00000024 [SR] Verify complete
2013-03-28 21:24:02, Info CSI 00000025 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:02, Info CSI 00000026 [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:04, Info CSI 00000028 [SR] Verify complete
2013-03-28 21:24:04, Info CSI 00000029 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:04, Info CSI 0000002a [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:05, Info CSI 0000002c [SR] Verify complete
2013-03-28 21:24:06, Info CSI 0000002d [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:06, Info CSI 0000002e [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:06, Info CSI 00000030 [SR] Verify complete
2013-03-28 21:24:07, Info CSI 00000031 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:07, Info CSI 00000032 [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:08, Info CSI 00000034 [SR] Verify complete
2013-03-28 21:24:08, Info CSI 00000035 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:08, Info CSI 00000036 [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:12, Info CSI 00000039 [SR] Verify complete
2013-03-28 21:24:12, Info CSI 0000003a [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:12, Info CSI 0000003b [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:16, Info CSI 0000003f [SR] Verify complete
2013-03-28 21:24:16, Info CSI 00000040 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:16, Info CSI 00000041 [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:19, Info CSI 00000045 [SR] Verify complete
2013-03-28 21:24:19, Info CSI 00000046 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:19, Info CSI 00000047 [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:21, Info CSI 00000049 [SR] Verify complete
2013-03-28 21:24:22, Info CSI 0000004a [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:22, Info CSI 0000004b [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:26, Info CSI 0000005a [SR] Verify complete
2013-03-28 21:24:26, Info CSI 0000005b [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:26, Info CSI 0000005c [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:31, Info CSI 00000074 [SR] Verify complete
2013-03-28 21:24:31, Info CSI 00000075 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:31, Info CSI 00000076 [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:34, Info CSI 00000078 [SR] Verify complete
2013-03-28 21:24:34, Info CSI 00000079 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:34, Info CSI 0000007a [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:37, Info CSI 0000007c [SR] Verify complete
2013-03-28 21:24:37, Info CSI 0000007d [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:37, Info CSI 0000007e [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:41, Info CSI 00000080 [SR] Verify complete
2013-03-28 21:24:41, Info CSI 00000081 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:41, Info CSI 00000082 [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:44, Info CSI 00000084 [SR] Verify complete
2013-03-28 21:24:44, Info CSI 00000085 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:44, Info CSI 00000086 [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:48, Info CSI 00000088 [SR] Verify complete
2013-03-28 21:24:48, Info CSI 00000089 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:48, Info CSI 0000008a [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:53, Info CSI 000000ad [SR] Verify complete
2013-03-28 21:24:54, Info CSI 000000ae [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:54, Info CSI 000000af [SR] Beginning Verify and Repair transaction
2013-03-28 21:24:57, Info CSI 000000b1 [SR] Verify complete
2013-03-28 21:24:57, Info CSI 000000b2 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:24:57, Info CSI 000000b3 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:04, Info CSI 000000b5 [SR] Verify complete
2013-03-28 21:25:05, Info CSI 000000b6 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:05, Info CSI 000000b7 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:08, Info CSI 000000bb [SR] Verify complete
2013-03-28 21:25:08, Info CSI 000000bc [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:08, Info CSI 000000bd [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:10, Info CSI 000000bf [SR] Verify complete
2013-03-28 21:25:10, Info CSI 000000c0 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:10, Info CSI 000000c1 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:11, Info CSI 000000c3 [SR] Verify complete
2013-03-28 21:25:11, Info CSI 000000c4 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:11, Info CSI 000000c5 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:12, Info CSI 000000c7 [SR] Verify complete
2013-03-28 21:25:13, Info CSI 000000c8 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:13, Info CSI 000000c9 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:19, Info CSI 000000dc [SR] Verify complete
2013-03-28 21:25:19, Info CSI 000000dd [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:19, Info CSI 000000de [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:20, Info CSI 000000e0 [SR] Verify complete
2013-03-28 21:25:20, Info CSI 000000e1 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:20, Info CSI 000000e2 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:21, Info CSI 000000e4 [SR] Verify complete
2013-03-28 21:25:21, Info CSI 000000e5 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:21, Info CSI 000000e6 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:23, Info CSI 000000e8 [SR] Verify complete
2013-03-28 21:25:23, Info CSI 000000e9 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:23, Info CSI 000000ea [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:26, Info CSI 000000ed [SR] Verify complete
2013-03-28 21:25:26, Info CSI 000000ee [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:26, Info CSI 000000ef [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:32, Info CSI 000000f2 [SR] Verify complete
2013-03-28 21:25:32, Info CSI 000000f3 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:32, Info CSI 000000f4 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:34, Info CSI 000000f6 [SR] Verify complete
2013-03-28 21:25:34, Info CSI 000000f7 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:34, Info CSI 000000f8 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:35, Info CSI 000000fa [SR] Verify complete
2013-03-28 21:25:35, Info CSI 000000fb [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:35, Info CSI 000000fc [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:39, Info CSI 000000fe [SR] Verify complete
2013-03-28 21:25:39, Info CSI 000000ff [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:39, Info CSI 00000100 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:42, Info CSI 00000102 [SR] Verify complete
2013-03-28 21:25:43, Info CSI 00000103 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:43, Info CSI 00000104 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:45, Info CSI 00000106 [SR] Verify complete
2013-03-28 21:25:45, Info CSI 00000107 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:45, Info CSI 00000108 [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:53, Info CSI 0000011a [SR] Verify complete
2013-03-28 21:25:53, Info CSI 0000011b [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:53, Info CSI 0000011c [SR] Beginning Verify and Repair transaction
2013-03-28 21:25:57, Info CSI 00000124 [SR] Verify complete
2013-03-28 21:25:57, Info CSI 00000125 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:25:57, Info CSI 00000126 [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:00, Info CSI 00000128 [SR] Verify complete
2013-03-28 21:26:00, Info CSI 00000129 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:00, Info CSI 0000012a [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:12, Info CSI 0000012c [SR] Verify complete
2013-03-28 21:26:12, Info CSI 0000012d [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:12, Info CSI 0000012e [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:17, Info CSI 00000131 [SR] Verify complete
2013-03-28 21:26:18, Info CSI 00000132 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:18, Info CSI 00000133 [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:21, Info CSI 00000135 [SR] Verify complete
2013-03-28 21:26:21, Info CSI 00000136 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:21, Info CSI 00000137 [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:25, Info CSI 00000139 [SR] Verify complete
2013-03-28 21:26:25, Info CSI 0000013a [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:25, Info CSI 0000013b [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:28, Info CSI 0000013d [SR] Verify complete
2013-03-28 21:26:28, Info CSI 0000013e [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:28, Info CSI 0000013f [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:31, Info CSI 00000143 [SR] Verify complete
2013-03-28 21:26:31, Info CSI 00000144 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:31, Info CSI 00000145 [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:34, Info CSI 00000147 [SR] Verify complete
2013-03-28 21:26:34, Info CSI 00000148 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:34, Info CSI 00000149 [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:43, Info CSI 0000014b [SR] Verify complete
2013-03-28 21:26:43, Info CSI 0000014c [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:43, Info CSI 0000014d [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:48, Info CSI 00000150 [SR] Verify complete
2013-03-28 21:26:48, Info CSI 00000151 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:48, Info CSI 00000152 [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:51, Info CSI 00000154 [SR] Verify complete
2013-03-28 21:26:51, Info CSI 00000155 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:51, Info CSI 00000156 [SR] Beginning Verify and Repair transaction
2013-03-28 21:26:55, Info CSI 00000159 [SR] Verify complete
2013-03-28 21:26:55, Info CSI 0000015a [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:26:55, Info CSI 0000015b [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:01, Info CSI 0000015e [SR] Verify complete
2013-03-28 21:27:01, Info CSI 0000015f [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:01, Info CSI 00000160 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:04, Info CSI 00000162 [SR] Verify complete
2013-03-28 21:27:04, Info CSI 00000163 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:04, Info CSI 00000164 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:08, Info CSI 00000166 [SR] Verify complete
2013-03-28 21:27:08, Info CSI 00000167 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:08, Info CSI 00000168 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:11, Info CSI 0000016a [SR] Verify complete
2013-03-28 21:27:11, Info CSI 0000016b [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:11, Info CSI 0000016c [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:14, Info CSI 0000016f [SR] Verify complete
2013-03-28 21:27:14, Info CSI 00000170 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:14, Info CSI 00000171 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:19, Info CSI 00000173 [SR] Verify complete
2013-03-28 21:27:19, Info CSI 00000174 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:19, Info CSI 00000175 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:22, Info CSI 00000177 [SR] Verify complete
2013-03-28 21:27:22, Info CSI 00000178 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:22, Info CSI 00000179 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:25, Info CSI 0000017c [SR] Verify complete
2013-03-28 21:27:25, Info CSI 0000017d [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:25, Info CSI 0000017e [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:29, Info CSI 00000181 [SR] Verify complete
2013-03-28 21:27:29, Info CSI 00000182 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:29, Info CSI 00000183 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:33, Info CSI 00000186 [SR] Verify complete
2013-03-28 21:27:33, Info CSI 00000187 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:33, Info CSI 00000188 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:37, Info CSI 0000018a [SR] Verify complete
2013-03-28 21:27:37, Info CSI 0000018b [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:37, Info CSI 0000018c [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:41, Info CSI 0000018f [SR] Verify complete
2013-03-28 21:27:41, Info CSI 00000190 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:41, Info CSI 00000191 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:44, Info CSI 00000193 [SR] Verify complete
2013-03-28 21:27:44, Info CSI 00000194 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:44, Info CSI 00000195 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:45, Info CSI 00000197 [SR] Verify complete
2013-03-28 21:27:45, Info CSI 00000198 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:45, Info CSI 00000199 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:48, Info CSI 0000019b [SR] Verify complete
2013-03-28 21:27:48, Info CSI 0000019c [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:48, Info CSI 0000019d [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:50, Info CSI 0000019f [SR] Verify complete
2013-03-28 21:27:50, Info CSI 000001a0 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:50, Info CSI 000001a1 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:53, Info CSI 000001a3 [SR] Verify complete
2013-03-28 21:27:53, Info CSI 000001a4 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:53, Info CSI 000001a5 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:55, Info CSI 000001a7 [SR] Verify complete
2013-03-28 21:27:55, Info CSI 000001a8 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:55, Info CSI 000001a9 [SR] Beginning Verify and Repair transaction
2013-03-28 21:27:58, Info CSI 000001ab [SR] Verify complete
2013-03-28 21:27:58, Info CSI 000001ac [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:27:58, Info CSI 000001ad [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:03, Info CSI 000001af [SR] Verify complete
2013-03-28 21:28:03, Info CSI 000001b0 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:03, Info CSI 000001b1 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:11, Info CSI 000001b3 [SR] Verify complete
2013-03-28 21:28:11, Info CSI 000001b4 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:11, Info CSI 000001b5 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:13, Info CSI 000001b7 [SR] Verify complete
2013-03-28 21:28:13, Info CSI 000001b8 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:13, Info CSI 000001b9 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:15, Info CSI 000001bb [SR] Verify complete
2013-03-28 21:28:15, Info CSI 000001bc [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:15, Info CSI 000001bd [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:16, Info CSI 000001bf [SR] Verify complete
2013-03-28 21:28:16, Info CSI 000001c0 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:16, Info CSI 000001c1 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:18, Info CSI 000001c3 [SR] Verify complete
2013-03-28 21:28:18, Info CSI 000001c4 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:18, Info CSI 000001c5 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:20, Info CSI 000001c7 [SR] Verify complete
2013-03-28 21:28:20, Info CSI 000001c8 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:20, Info CSI 000001c9 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:25, Info CSI 000001d1 [SR] Verify complete
2013-03-28 21:28:25, Info CSI 000001d2 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:25, Info CSI 000001d3 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:27, Info CSI 000001d5 [SR] Verify complete
2013-03-28 21:28:27, Info CSI 000001d6 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:27, Info CSI 000001d7 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:29, Info CSI 000001d9 [SR] Verify complete
2013-03-28 21:28:29, Info CSI 000001da [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:29, Info CSI 000001db [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:31, Info CSI 000001dd [SR] Verify complete
2013-03-28 21:28:31, Info CSI 000001de [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:31, Info CSI 000001df [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:34, Info CSI 000001e1 [SR] Verify complete
2013-03-28 21:28:35, Info CSI 000001e2 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:35, Info CSI 000001e3 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:39, Info CSI 000001e6 [SR] Verify complete
2013-03-28 21:28:39, Info CSI 000001e7 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:39, Info CSI 000001e8 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:43, Info CSI 000001ea [SR] Verify complete
2013-03-28 21:28:43, Info CSI 000001eb [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:43, Info CSI 000001ec [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:43, Info CSI 000001ee [SR] Verify complete
2013-03-28 21:28:43, Info CSI 000001ef [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:43, Info CSI 000001f0 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:48, Info CSI 000001f3 [SR] Verify complete
2013-03-28 21:28:48, Info CSI 000001f4 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:48, Info CSI 000001f5 [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:55, Info CSI 000001f9 [SR] Verify complete
2013-03-28 21:28:55, Info CSI 000001fa [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:55, Info CSI 000001fb [SR] Beginning Verify and Repair transaction
2013-03-28 21:28:59, Info CSI 00000200 [SR] Verify complete
2013-03-28 21:28:59, Info CSI 00000201 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:28:59, Info CSI 00000202 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:04, Info CSI 00000208 [SR] Verify complete
2013-03-28 21:29:04, Info CSI 00000209 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:04, Info CSI 0000020a [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:09, Info CSI 00000213 [SR] Verify complete
2013-03-28 21:29:09, Info CSI 00000214 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:09, Info CSI 00000215 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:12, Info CSI 0000021a [SR] Verify complete
2013-03-28 21:29:13, Info CSI 0000021b [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:13, Info CSI 0000021c [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:16, Info CSI 0000021e [SR] Verify complete
2013-03-28 21:29:16, Info CSI 0000021f [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:16, Info CSI 00000220 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:18, Info CSI 00000224 [SR] Verify complete
2013-03-28 21:29:18, Info CSI 00000225 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:18, Info CSI 00000226 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:22, Info CSI 00000239 [SR] Verify complete
2013-03-28 21:29:22, Info CSI 0000023a [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:22, Info CSI 0000023b [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:25, Info CSI 0000024f [SR] Verify complete
2013-03-28 21:29:25, Info CSI 00000250 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:25, Info CSI 00000251 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:28, Info CSI 00000253 [SR] Verify complete
2013-03-28 21:29:28, Info CSI 00000254 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:28, Info CSI 00000255 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:30, Info CSI 00000257 [SR] Verify complete
2013-03-28 21:29:31, Info CSI 00000258 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:31, Info CSI 00000259 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:33, Info CSI 00000267 [SR] Verify complete
2013-03-28 21:29:33, Info CSI 00000268 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:33, Info CSI 00000269 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:36, Info CSI 0000026b [SR] Verify complete
2013-03-28 21:29:36, Info CSI 0000026c [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:36, Info CSI 0000026d [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:41, Info CSI 0000027b [SR] Verify complete
2013-03-28 21:29:41, Info CSI 0000027c [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:41, Info CSI 0000027d [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:42, Info CSI 0000027f [SR] Verify complete
2013-03-28 21:29:42, Info CSI 00000280 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:42, Info CSI 00000281 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:44, Info CSI 00000283 [SR] Verify complete
2013-03-28 21:29:44, Info CSI 00000284 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:44, Info CSI 00000285 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:47, Info CSI 00000288 [SR] Verify complete
2013-03-28 21:29:47, Info CSI 00000289 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:47, Info CSI 0000028a [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:49, Info CSI 0000028c [SR] Verify complete
2013-03-28 21:29:49, Info CSI 0000028d [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:49, Info CSI 0000028e [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:51, Info CSI 00000290 [SR] Verify complete
2013-03-28 21:29:51, Info CSI 00000291 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:51, Info CSI 00000292 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:54, Info CSI 00000294 [SR] Verify complete
2013-03-28 21:29:54, Info CSI 00000295 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:54, Info CSI 00000296 [SR] Beginning Verify and Repair transaction
2013-03-28 21:29:57, Info CSI 00000298 [SR] Verify complete
2013-03-28 21:29:57, Info CSI 00000299 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:29:57, Info CSI 0000029a [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:02, Info CSI 000002b4 [SR] Verify complete
2013-03-28 21:30:02, Info CSI 000002b5 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:02, Info CSI 000002b6 [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:11, Info CSI 000002b8 [SR] Verify complete
2013-03-28 21:30:11, Info CSI 000002b9 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:11, Info CSI 000002ba [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:14, Info CSI 000002bc [SR] Verify complete
2013-03-28 21:30:14, Info CSI 000002bd [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:14, Info CSI 000002be [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:17, Info CSI 000002c0 [SR] Verify complete
2013-03-28 21:30:17, Info CSI 000002c1 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:17, Info CSI 000002c2 [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:18, Info CSI 000002c6 [SR] Verify complete
2013-03-28 21:30:18, Info CSI 000002c7 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:18, Info CSI 000002c8 [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:20, Info CSI 000002ca [SR] Verify complete
2013-03-28 21:30:21, Info CSI 000002cb [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:21, Info CSI 000002cc [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:24, Info CSI 000002ce [SR] Verify complete
2013-03-28 21:30:24, Info CSI 000002cf [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:24, Info CSI 000002d0 [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:27, Info CSI 000002d2 [SR] Verify complete
2013-03-28 21:30:27, Info CSI 000002d3 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:27, Info CSI 000002d4 [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:30, Info CSI 000002d7 [SR] Verify complete
2013-03-28 21:30:30, Info CSI 000002d8 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:30, Info CSI 000002d9 [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:32, Info CSI 000002db [SR] Verify complete
2013-03-28 21:30:32, Info CSI 000002dc [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:32, Info CSI 000002dd [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:34, Info CSI 000002df [SR] Verify complete
2013-03-28 21:30:35, Info CSI 000002e0 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:35, Info CSI 000002e1 [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:36, Info CSI 000002e2 [SR] Cannot verify component files for Microsoft-Windows-WMI-Feature-Providers, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral, manifest is damaged (FALSE)
2013-03-28 21:30:37, Info CSI 000002e4 [SR] Verify complete
2013-03-28 21:30:37, Info CSI 000002e5 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:37, Info CSI 000002e6 [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:40, Info CSI 000002e9 [SR] Verify complete
2013-03-28 21:30:41, Info CSI 000002ea [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:41, Info CSI 000002eb [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:43, Info CSI 000002ed [SR] Verify complete
2013-03-28 21:30:43, Info CSI 000002ee [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:43, Info CSI 000002ef [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:45, Info CSI 000002f1 [SR] Verify complete
2013-03-28 21:30:45, Info CSI 000002f2 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:45, Info CSI 000002f3 [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:48, Info CSI 000002f5 [SR] Verify complete
2013-03-28 21:30:48, Info CSI 000002f6 [SR] Verifying 100 (0x0000000000000064) components
2013-03-28 21:30:48, Info CSI 000002f7 [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:50, Info CSI 000002f9 [SR] Verify complete
2013-03-28 21:30:50, Info CSI 000002fa [SR] Verifying 13 (0x000000000000000d) components
2013-03-28 21:30:50, Info CSI 000002fb [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:50, Info CSI 000002fd [SR] Verify complete
2013-03-28 21:30:50, Info CSI 000002fe [SR] Repairing 1 components
2013-03-28 21:30:50, Info CSI 000002ff [SR] Beginning Verify and Repair transaction
2013-03-28 21:30:50, Info CSI 00000300 [SR] Cannot verify component files for Microsoft-Windows-WMI-Feature-Providers, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral, manifest is damaged (FALSE)
2013-03-28 21:30:50, Info CSI 00000302 [SR] Repair complete
2013-03-28 21:30:50, Info CSI 00000303 [SR] Committing transaction
2013-03-28 21:30:50, Info CSI 00000307 [SR] Verify and Repair Transaction completed. All files and registry keys listed in this transaction have been successfully repaired



  • 0

#44
Crowbar

Crowbar

    Teacher

  • GeekU Moderator
  • 4,161 posts
I am assuming that the SFC did not fix your freezing issues, but if it did, please let me know...
Do you have a Windows 7 installation disk? If this next attempt does not work, I would like to try a Startup Repair, and you might need the install disk to do so.
Next time you boot your computer, just before you select safe mode, is there an option Repair Your Computer?

In the meantime, please try this:
Please download the System Update Readiness Tool from here and save it to your desktop
Right click the tool and select Run as Administrator.
In the Windows Update Standalone Installer dialog box, click Yes or OK.
In the Installation complete dialog box, click Close.

Note:
The tool can take several minutes to install. Even if the progress bar appears to stop, don't cancel the installation.


After the tool has run, try once again to boot to normal mode and let me know the outcome.
  • 0

#45
DrkMachine

DrkMachine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 126 posts
you would be correct that SFC didn't fix the freeze. I do not have a windows install disk, unfortunately I accuired this system second hand from my bosses son. If I press F8 while booting it does give me the repair your computer option.

Also the System Update Readiness Tool can't run in safemode, so I tried to boot into normal and hoped it would be stable long enough for it to run. Unfortunately it never made it beyond Preparing the installation.

Using MMC I see that there are 3 partitions on my HDD, but they do not show up in my "computer" window.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP