Go here and download the Nvidia driver. For now, just run that and see if it will overwrite the existing info. If not, go to Programs and Features and uninstall any Nvidia graphics listings there, reboot, then do the install.
get-answers-fast redirects, slow loading vista system
Started by
builder4580
, Jan 04 2012 07:32 PM
#106
Posted 07 February 2012 - 05:15 PM
Go here and download the Nvidia driver. For now, just run that and see if it will overwrite the existing info. If not, go to Programs and Features and uninstall any Nvidia graphics listings there, reboot, then do the install.
#107
Posted 07 February 2012 - 10:28 PM
I'm back! This time on my XP desktop computer - which has its own multiple problems!
Don't know how much time I have here before I get a BSOD, so will be as brief as possible.
Downloaded and ran Nvidia driver, but it did not overwrite.
Uninstalled Nvidia listing, rebooted and attempted the install.
Got a message that the install was not done and to try again later.
Clicked on finish, and my screen went black. I'm talking about my external screen,
so I guess the port it is attached to is no longer recognized.
Rebooted. External screen still black.
My laptop screen is the same - black, but I can shine a torch on it and just make out the
screen behind, but the text is too blurred to read.
Don't know how much time I have here before I get a BSOD, so will be as brief as possible.
Downloaded and ran Nvidia driver, but it did not overwrite.
Uninstalled Nvidia listing, rebooted and attempted the install.
Got a message that the install was not done and to try again later.
Clicked on finish, and my screen went black. I'm talking about my external screen,
so I guess the port it is attached to is no longer recognized.
Rebooted. External screen still black.
My laptop screen is the same - black, but I can shine a torch on it and just make out the
screen behind, but the text is too blurred to read.
#108
Posted 08 February 2012 - 04:23 PM
Even without the correct Nvidia drivers installed, Windows' generic graphics drivers should have still allowed the display to work. Very strange behavior, but that laptop screen issue again does sound like the inverter is bad. Simple test is always seeing if you can vaguely view Windows in the display, by using a flashlight or tilting the display, and looking at different angles. Here are the steps, though that price is likely a bit on the high side. You need to remove the inverter, then go to places like Amazon or Ebay and search, using the nomenclature off the inverter. Without visuals everything else would have to be on hold for now.
#109
Posted 08 February 2012 - 07:14 PM
Here are the steps,......
2. Locate the rubber screw covers around your laptop screen. There are typically four, but some models may have more.
My screen doesn't have any that I have been able to locate, .....looking front, side, top and back!
Looks like I will need to spend some time figuring out how to open it up.
Another problem I'm having now - ahhhh! when will they stop! - is my mouse pointer disappears for about 10-15 minutes
every time I click on any button.
Anyway, I need a computer to trade forex and stock options, so today I purchased a Samsung 4GB mem & 500GB HDD
AMD Quad-Core A6-3410 MX APU with Win 7 Home Premium (64b) from WalMart, so hopefully I am set up for a few more trading days!
I still need to fix my Dell as a backup, but from what you write it looks like I have some work to do.
I can still vaguely view Windows in the display, by using a flashlight or tilting the display, but now with my pointer issue
it has become a real pain-in-the-rear to do anything, and I'm not sure pursuing this further at this time is the best use of
either your time or mine. However, if this is helping you to add to your knowledge base, then I will continue.
After my purchase today, I am going to have to re-evaluate how much I am prepared to spend to repair my Dell.
If we shelve this for now, can I reactivate the thread at a later date, or do you need continuity?
2. Locate the rubber screw covers around your laptop screen. There are typically four, but some models may have more.
My screen doesn't have any that I have been able to locate, .....looking front, side, top and back!
Looks like I will need to spend some time figuring out how to open it up.
Another problem I'm having now - ahhhh! when will they stop! - is my mouse pointer disappears for about 10-15 minutes
every time I click on any button.
Anyway, I need a computer to trade forex and stock options, so today I purchased a Samsung 4GB mem & 500GB HDD
AMD Quad-Core A6-3410 MX APU with Win 7 Home Premium (64b) from WalMart, so hopefully I am set up for a few more trading days!
I still need to fix my Dell as a backup, but from what you write it looks like I have some work to do.
I can still vaguely view Windows in the display, by using a flashlight or tilting the display, but now with my pointer issue
it has become a real pain-in-the-rear to do anything, and I'm not sure pursuing this further at this time is the best use of
either your time or mine. However, if this is helping you to add to your knowledge base, then I will continue.
After my purchase today, I am going to have to re-evaluate how much I am prepared to spend to repair my Dell.
If we shelve this for now, can I reactivate the thread at a later date, or do you need continuity?
#110
Posted 08 February 2012 - 07:15 PM
Delete double posting
Edited by builder4580, 08 February 2012 - 07:19 PM.
#111
Posted 08 February 2012 - 07:24 PM
There is a plastic border (bevel) around most laptop screens, and the screws that hold it are covered by tough sticky-glue rubber stoppers, that hide the screws. Remove the stoppers with a small screwdriver and your fingernails, unscrew the screws, then using again a small (and sharp-bladed) screwdriver, and your fingernails (one reason computer repair folks should not be nail biters), you pop free the bevel. Usually easiest starting place is at the bottom of the screen. There's the inverter, order one, receive it, out and in.
And yes, if you do still plan on correcting this laptop's situation in the very near future, we can leave this thread as it stands for now.
And yes, if you do still plan on correcting this laptop's situation in the very near future, we can leave this thread as it stands for now.
#112
Posted 08 February 2012 - 08:49 PM
Finally got my border off - no screws - mine just has a series of "lugs" at the back of the one piece plastic molding around the screen.
I see 4 screws behind & below the molding that appear to hold a metal frame around the screen, so will go to work on these tomorrow.
I see 4 screws behind & below the molding that appear to hold a metal frame around the screen, so will go to work on these tomorrow.
#113
Posted 08 February 2012 - 09:08 PM
Darn, upload lag killed my answer, so retyping it. If you have the bevel off, the inverter should be there at the bottom of the lcd panel. One plug, I think pink, or pink wires, coming down the panel to the left to unplug, and a larger white one to the right. Shouldn't have to remove the lcd panel from the brackets.
#114
Posted 09 February 2012 - 05:54 PM
Inverter is at the bottom, but on my laptop, it is behind a metal frame.
Had to remove the lcd to access it. No pink wires, all mine are grey.
I have numbers everywhere! The one next to the yellow lightning bolt caution
is L790K19201 07920 (serial number?) - differs from the image on
post #108 - Here are the steps
Had to remove the lcd to access it. No pink wires, all mine are grey.
I have numbers everywhere! The one next to the yellow lightning bolt caution
is L790K19201 07920 (serial number?) - differs from the image on
post #108 - Here are the steps
#116
Posted 15 February 2012 - 11:17 PM
Ordered an inverter. It will not be shipped till payment is cleared, so probably will not get it till next week.
#117
Posted 16 February 2012 - 04:10 PM
Very good. You run into any questions after getting it, let me know.
#118
Posted 27 February 2012 - 07:09 PM
Great!! I've got my screen back and visible, but my external screen is still black.
My guess is I need to retry downloading and installing the Nvidia driver again, but will wait for your instructions.
My guess is I need to retry downloading and installing the Nvidia driver again, but will wait for your instructions.
#119
Posted 27 February 2012 - 08:46 PM
Very good news. Always a solid feeling when you can effect somewhat complex repairs yourself, yes? Good work.
There may be a graphics setting (such as right clicking the desktop - some nVidia graphics option) that switches from internal to external monitors. Before you make any driver changes, I need to come up to speed on your system. Please delete any existing copies of ComboFix, then download ComboFix.exe from here to your desktop, run that and post the new log please.
There may be a graphics setting (such as right clicking the desktop - some nVidia graphics option) that switches from internal to external monitors. Before you make any driver changes, I need to come up to speed on your system. Please delete any existing copies of ComboFix, then download ComboFix.exe from here to your desktop, run that and post the new log please.
#120
Posted 27 February 2012 - 09:38 PM
Always a solid feeling when you can effect somewhat complex repairs yourself, yes?
Yes, especially as I am electronically incompetent! I'm OK around small engines like lawn mowers,
and autos of yesteryear - pre catalytic converter days; but electronics is not my bag.
Here is my Combofix Log:
ComboFix 12-02-27.02 - cormact 02/27/2012 21:08:54.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.1749 [GMT -6:00]
Running from: c:\users\cormact\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\cormact\g2mdlhlpx.exe
c:\windows\Downloaded Program Files\Temp
.
.
((((((((((((((((((((((((( Files Created from 2012-01-28 to 2012-02-28 )))))))))))))))))))))))))))))))
.
.
2012-02-28 03:17 . 2012-02-28 03:19 -------- d-----w- c:\users\cormact\AppData\Local\temp
2012-02-28 03:17 . 2012-02-28 03:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-28 03:17 . 2012-02-28 03:17 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-02-27 23:42 . 2012-02-27 23:42 -------- d-----w- c:\program files\Common Files\Java
2012-02-08 00:46 . 2008-08-22 08:00 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2012-02-07 16:10 . 2012-02-07 16:10 253336 ----a-w- c:\users\cormact\AppData\Roaming\Microsoft\IdentityCRL\ppcrlui.dll
2012-02-07 16:10 . 2012-02-07 16:10 14744 ----a-w- c:\users\cormact\AppData\Roaming\Microsoft\IdentityCRL\ppcrlconfig.dll
2012-02-06 23:12 . 2012-02-06 23:12 -------- d-----w- C:\CYDELogs
2012-02-02 03:05 . 2012-02-06 23:11 -------- d-----w- C:\CAT-Logs
2012-02-01 17:18 . 2009-04-11 04:39 67072 ----a-w- c:\windows\system32\drivers\cdrom.sys
2012-01-31 02:55 . 2012-01-31 02:55 -------- d-----w- c:\users\Administrator\Bluetooth Software
2012-01-31 02:55 . 2012-01-31 02:55 -------- d-----w- c:\users\Administrator\AppData\Local\ArcSoft
2012-01-31 02:55 . 2012-01-31 02:55 -------- d-----w- c:\users\Administrator\AppData\Local\MediaDirect
2012-01-31 02:55 . 2012-01-31 02:55 -------- d-----w- c:\users\Administrator\AppData\Roaming\ArcSoft
2012-01-31 02:13 . 2012-01-31 02:13 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-31 01:46 . 2012-01-31 01:46 309320 ----a-w- c:\windows\system32\drivers\TrufosAlt.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-27 23:41 . 2010-05-11 13:40 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-01-30 21:49 . 2011-05-16 12:32 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-10 03:09 . 2011-06-16 22:24 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-12-15 15:34 . 2011-12-15 15:34 677136 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-02-28 01:34 . 2011-05-29 17:13 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-04-17 05:13 721408 ----a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-04-17 05:13 721408 ----a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Facebook Update"="c:\users\cormact\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-11-02 137536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-05-10 857648]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-08-29 36864]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"PSQLLauncher"="c:\program files\Fingerprint Reader Suite\launcher.exe" [2007-04-17 49168]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-07 405504]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"BrStsMon00"="c:\program files\Browny02\Brother\BrStMonW.exe" [2010-06-10 2621440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-11-27 296056]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - [N/A]
Device Monitor.lnk - c:\program files\ArcSoft\MediaConverter 4 Platinum\Monitor.exe [2011-5-1 139264]
QuickSet.lnk - [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"disableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-17 05:04 86528 ----a-w- c:\windows\System32\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
.
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-08-29 73728]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-07 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305091848-4078153160-3836742915-1000Core.job
- c:\users\cormact\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-02 04:34]
.
2012-02-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305091848-4078153160-3836742915-1000UA.job
- c:\users\cormact\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-02 04:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page =
IE: Read EXIF - c:\program files\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: vectorvest.com\www
TCP: DhcpNameServer = 192.168.0.1 192.168.0.1
TCP: Interfaces\{F8E68292-91F9-4C77-A9B5-BBA0B6764383}: NameServer = 68.94.156.1,68.94.157.1
FF - ProfilePath - c:\users\cormact\AppData\Roaming\Mozilla\Firefox\Profiles\njucu1qh.default\
.
.
**************************************************************************
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files:
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\psqlpwd.dll
c:\program files\Fingerprint Reader Suite\homefus2.dll
c:\program files\Fingerprint Reader Suite\infra.dll
.
- - - - - - - > 'Explorer.exe'(3228)
c:\program files\Fingerprint Reader Suite\farchns.dll
c:\program files\Fingerprint Reader Suite\infra.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLANExt.exe
c:\program files\Fingerprint Reader Suite\upeksvr.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\wbem\unsecapp.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2012-02-27 21:24:51 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-28 03:24
ComboFix2.txt 2012-02-01 23:41
ComboFix3.txt 2012-02-01 17:52
.
Pre-Run: 166,257,364,992 bytes free
Post-Run: 166,259,331,072 bytes free
.
- - End Of File - - 219B5041475BACBE556EB49DF74C8EA6
Yes, especially as I am electronically incompetent! I'm OK around small engines like lawn mowers,
and autos of yesteryear - pre catalytic converter days; but electronics is not my bag.
Here is my Combofix Log:
ComboFix 12-02-27.02 - cormact 02/27/2012 21:08:54.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.1749 [GMT -6:00]
Running from: c:\users\cormact\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\cormact\g2mdlhlpx.exe
c:\windows\Downloaded Program Files\Temp
.
.
((((((((((((((((((((((((( Files Created from 2012-01-28 to 2012-02-28 )))))))))))))))))))))))))))))))
.
.
2012-02-28 03:17 . 2012-02-28 03:19 -------- d-----w- c:\users\cormact\AppData\Local\temp
2012-02-28 03:17 . 2012-02-28 03:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-28 03:17 . 2012-02-28 03:17 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-02-27 23:42 . 2012-02-27 23:42 -------- d-----w- c:\program files\Common Files\Java
2012-02-08 00:46 . 2008-08-22 08:00 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2012-02-07 16:10 . 2012-02-07 16:10 253336 ----a-w- c:\users\cormact\AppData\Roaming\Microsoft\IdentityCRL\ppcrlui.dll
2012-02-07 16:10 . 2012-02-07 16:10 14744 ----a-w- c:\users\cormact\AppData\Roaming\Microsoft\IdentityCRL\ppcrlconfig.dll
2012-02-06 23:12 . 2012-02-06 23:12 -------- d-----w- C:\CYDELogs
2012-02-02 03:05 . 2012-02-06 23:11 -------- d-----w- C:\CAT-Logs
2012-02-01 17:18 . 2009-04-11 04:39 67072 ----a-w- c:\windows\system32\drivers\cdrom.sys
2012-01-31 02:55 . 2012-01-31 02:55 -------- d-----w- c:\users\Administrator\Bluetooth Software
2012-01-31 02:55 . 2012-01-31 02:55 -------- d-----w- c:\users\Administrator\AppData\Local\ArcSoft
2012-01-31 02:55 . 2012-01-31 02:55 -------- d-----w- c:\users\Administrator\AppData\Local\MediaDirect
2012-01-31 02:55 . 2012-01-31 02:55 -------- d-----w- c:\users\Administrator\AppData\Roaming\ArcSoft
2012-01-31 02:13 . 2012-01-31 02:13 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-31 01:46 . 2012-01-31 01:46 309320 ----a-w- c:\windows\system32\drivers\TrufosAlt.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-27 23:41 . 2010-05-11 13:40 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-01-30 21:49 . 2011-05-16 12:32 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-10 03:09 . 2011-06-16 22:24 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-12-15 15:34 . 2011-12-15 15:34 677136 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-02-28 01:34 . 2011-05-29 17:13 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-04-17 05:13 721408 ----a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-04-17 05:13 721408 ----a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Facebook Update"="c:\users\cormact\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-11-02 137536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-05-10 857648]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-08-29 36864]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"PSQLLauncher"="c:\program files\Fingerprint Reader Suite\launcher.exe" [2007-04-17 49168]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-07 405504]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"BrStsMon00"="c:\program files\Browny02\Brother\BrStMonW.exe" [2010-06-10 2621440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-11-27 296056]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - [N/A]
Device Monitor.lnk - c:\program files\ArcSoft\MediaConverter 4 Platinum\Monitor.exe [2011-5-1 139264]
QuickSet.lnk - [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"disableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-17 05:04 86528 ----a-w- c:\windows\System32\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
.
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-08-29 73728]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-07 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305091848-4078153160-3836742915-1000Core.job
- c:\users\cormact\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-02 04:34]
.
2012-02-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305091848-4078153160-3836742915-1000UA.job
- c:\users\cormact\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-02 04:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page =
IE: Read EXIF - c:\program files\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: vectorvest.com\www
TCP: DhcpNameServer = 192.168.0.1 192.168.0.1
TCP: Interfaces\{F8E68292-91F9-4C77-A9B5-BBA0B6764383}: NameServer = 68.94.156.1,68.94.157.1
FF - ProfilePath - c:\users\cormact\AppData\Roaming\Mozilla\Firefox\Profiles\njucu1qh.default\
.
.
**************************************************************************
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files:
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\psqlpwd.dll
c:\program files\Fingerprint Reader Suite\homefus2.dll
c:\program files\Fingerprint Reader Suite\infra.dll
.
- - - - - - - > 'Explorer.exe'(3228)
c:\program files\Fingerprint Reader Suite\farchns.dll
c:\program files\Fingerprint Reader Suite\infra.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLANExt.exe
c:\program files\Fingerprint Reader Suite\upeksvr.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\wbem\unsecapp.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2012-02-27 21:24:51 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-28 03:24
ComboFix2.txt 2012-02-01 23:41
ComboFix3.txt 2012-02-01 17:52
.
Pre-Run: 166,257,364,992 bytes free
Post-Run: 166,259,331,072 bytes free
.
- - End Of File - - 219B5041475BACBE556EB49DF74C8EA6
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users