Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Computer acting weird and no Internet Access  (Read 34612 times)

0 Members and 1 Guest are viewing this topic.

mecka

    Topic Starter


    Rookie

    Re: Computer acting weird and no Internet Access
    « Reply #30 on: February 12, 2012, 03:27:13 PM »
    My computer seems to be locked down ,i cant access internet and its been that way since the beginning post.I cann't clik and drag Recovery Console onto Combo Fix,for that matter cant click on any desktop icon and move it?Im and still stuck?

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Computer acting weird and no Internet Access
    « Reply #31 on: February 12, 2012, 04:07:28 PM »
    That's probably important files are infected and/or missing. Can you boot in Safe Mode?
    Windows 8 and Windows 10 dual boot with two SSD's

    mecka

      Topic Starter


      Rookie

      Re: Computer acting weird and no Internet Access
      « Reply #32 on: February 12, 2012, 04:55:07 PM »
      Yes

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Computer acting weird and no Internet Access
      « Reply #33 on: February 12, 2012, 06:57:38 PM »
      Save these instructions so you can have access to them while in Safe Mode.

      Please click here to download AVP Tool by Kaspersky.
      • Save it to your desktop.
      • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
      • Double click the setup file to run it.
      • Click Next to continue.
      • Accept the License agreement and click on next.
      • It will, by default, install it to your desktop folder. Click Next.
      • It will then open a box There will be a tab that says Automatic scan.
      • Under Automatic scan make sure these are checked.
      • Hidden Startup Objects
      • System Memory
      • Disk Boot Sectors.
      • My Computer.
      • Also any other drives (Removable that you may have)
      Leave the rest of the settings as they appear as default.
      •Then click on Scan at the to right hand Corner.
      •It will automatically Neutralize any objects found.
      •If some objects are left un-neutralized then click the button that says Neutralize all
      •If it says it cannot be neutralized then choose the delete option when prompted.
      •After that is done click on the reports button at the bottom and save it to file name it Kas.
      •Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

      Note: This tool will self uninstall when you close it so please save the log before closing it.
      Windows 8 and Windows 10 dual boot with two SSD's

      mecka

        Topic Starter


        Rookie

        Re: Computer acting weird and no Internet Access
        « Reply #34 on: February 26, 2012, 06:59:56 PM »
        Sorry for the delay ,was out of province for last few weeks.I was able to run the scan but however cannot copy to my flash drive to transfer to my only working computer .Seems that the computer is really locked down.ANy other ideas?

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Computer acting weird and no Internet Access
        « Reply #35 on: February 26, 2012, 07:15:32 PM »
        We are going to be using a Windows Recovery Environment to help disinfect the system so it may boot again.

        Download the OTLPE Standard REATOGO Windows Recovery Environment.
        • Place a blank CD-R disc in to your CD burning drive.
        • Download OTLPEStd.exe and double-click on it to burn to a CD using an ISO Burner. One can be found here.
        • Reboot your system using the boot CD you just created.
        • Note : If you do not know how to set your computer to boot from CD follow the steps here
        • Your system should now display a REATOGO-X-PE desktop.
        • Double-click on the OTLPE icon.
        • When asked "Do you wish to load the remote registry", select Yes
        • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
        • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
        • OTL should now start. Change the following settings
        • Change Drivers to Non-Microsoft
        • Press Run Scan to start the scan.
        • When finished, the file will be saved  in drive C:\_OTL\MovedFiles
        • Copy this file to your USB drive if you do not have internet connection on this system
        • Please post the contents of the OTL.txt file in your reply.
        Windows 8 and Windows 10 dual boot with two SSD's

        mecka

          Topic Starter


          Rookie

          Re: Computer acting weird and no Internet Access
          « Reply #36 on: March 24, 2012, 01:06:19 PM »
          Ok here is the log for OTL

          TL logfile created on: 3/24/2012 2:50:29 PM - Run
          OTLPE by OldTimer - Version 3.1.48.0     Folder = X:\Programs\OTLPE
          Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
          Internet Explorer (Version = 8.0.6001.18702)
          Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
           
          511.00 Mb Total Physical Memory | 306.00 Mb Available Physical Memory | 60.00% Memory free
          459.00 Mb Paging File | 337.00 Mb Available in Paging File | 73.00% Paging File free
          Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
           
          %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
          Drive C: | 149.04 Gb Total Space | 92.10 Gb Free Space | 61.80% Space Free | Partition Type: NTFS
          Drive D: | 14.90 Gb Total Space | 14.90 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
          Drive F: | 644.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
          Drive X: | 284.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
           
          Computer Name: REATOGO | User Name: SYSTEM
          Boot Mode: Normal | Scan Mode: All users
          Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
          Using ControlSet: ControlSet003
           
          ========== Win32 Services (SafeList) ==========
           
          SRV - File not found [Disabled] --  -- (HidServ)
          SRV - File not found [Auto] --  -- (helpsvc)
          SRV - File not found [Auto] --  -- (Dhcp)
          SRV - File not found [On_Demand] --  -- (AppMgmt)
          SRV - [2011/08/11 19:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
          SRV - [2009/10/14 16:31:02 | 000,098,304 | ---- | M] (WDC) [Auto] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService)
          SRV - [2009/06/16 11:58:08 | 000,020,480 | ---- | M] (Memeo) [Auto] -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe -- (WDSmartWareBackgroundService)
          SRV - [2003/03/09 16:31:02 | 000,065,795 | R--- | M] (HP) [Disabled] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
           
           
          ========== Driver Services (SafeList) ==========
           
          DRV - File not found [Kernel | On_Demand] --  -- (WDICA)
          DRV - File not found [Kernel | On_Demand] --  -- (RimUsb)
          DRV - File not found [Kernel | On_Demand] --  -- (PORTIO)
          DRV - File not found [Kernel | On_Demand] --  -- (PDRFRAME)
          DRV - File not found [Kernel | On_Demand] --  -- (PDRELI)
          DRV - File not found [Kernel | On_Demand] --  -- (PDFRAME)
          DRV - File not found [Kernel | On_Demand] --  -- (PDCOMP)
          DRV - File not found [Kernel | System] --  -- (PCIDump)
          DRV - File not found [Kernel | System] --  -- (lbrtfdc)
          DRV - File not found [Kernel | System] --  -- (i2omgmt)
          DRV - File not found [Kernel | System] --  -- (Changer)
          DRV - File not found [Kernel | On_Demand] --  -- (catchme)
          DRV - [2011/07/22 12:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
          DRV - [2011/07/12 17:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
          DRV - [2009/02/13 14:02:52 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wdcsam.sys -- (WDC_SAM)
          DRV - [2009/01/08 19:00:54 | 000,016,640 | ---- | M] (Wondershare) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\AsAudioDevice_351.sys -- (AsAudioDevice_351)
          DRV - [2008/04/13 14:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
          DRV - [2007/06/18 16:18:26 | 000,023,680 | ---- | M] (Motorola) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\motmodem.sys -- (motmodem)
          DRV - [2006/11/01 19:09:18 | 000,021,056 | ---- | M] (Webroot Software Inc (www.webroot.com)) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\sskbfd.sys -- (SSKBFD)
          DRV - [2004/10/07 21:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
          DRV - [2001/08/17 09:28:02 | 000,907,456 | ---- | M] (Conexant) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HCF_MSFT.sys -- (HCF_MSFT)
          DRV - [2001/08/17 08:19:34 | 000,036,480 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\sfmanm.sys -- (sfman) Creative SoundFont Manager Driver (WDM)
          DRV - [2001/08/17 08:19:28 | 000,006,912 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ctlfacem.sys -- (emu10k1) Creative Interface Manager Driver (WDM)
          DRV - [2001/08/17 08:19:26 | 000,283,904 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\emu10k1m.sys -- (emu10k) Creative SB Live! (WDM)
          DRV - [2001/08/17 08:19:20 | 000,003,712 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ctljystk.sys -- (ctljystk)
          DRV - [2001/08/17 08:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)
           
           
          ========== Standard Registry (SafeList) ==========
           
           
          ========== Internet Explorer ==========
           
           
           
          IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = about:blank
          IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
           
          IE - HKU\Kaitlyn_Cochrane_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
          IE - HKU\Kaitlyn_Cochrane_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
          IE - HKU\Kaitlyn_Cochrane_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
          IE - HKU\Kaitlyn_Cochrane_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
          IE - HKU\Kaitlyn_Cochrane_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
           
          IE - HKU\Keith__Cochrane_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
          IE - HKU\Keith__Cochrane_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
          IE - HKU\Keith__Cochrane_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
           
          IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
           
          IE - HKU\Lori_Cochrane_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
          IE - HKU\Lori_Cochrane_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
          IE - HKU\Lori_Cochrane_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
           
          IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
           
           
          FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: 
          FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
          FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
          FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
          FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
          FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
          FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
          FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: 
          FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.1: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
          FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
          FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
           
           
          [2008/02/07 22:43:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
          [2008/02/07 01:22:25 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
           
          O1 HOSTS File: ([2012/02/03 18:53:47 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
          O1 - Hosts: 127.0.0.1       localhost
          O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
          O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
          O3 - HKU\Kaitlyn_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
          O3 - HKU\Kaitlyn_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
          O3 - HKU\Kaitlyn_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
          O3 - HKU\Keith__Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
          O3 - HKU\Lori_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
          O3 - HKU\Lori_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
          O3 - HKU\Lori_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
          O4 - HKU\Kaitlyn_Cochrane_ON_C..\Run: [swg]  File not found
          O4 - HKU\Keith__Cochrane_ON_C..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
          O4 - HKU\Lori_Cochrane_ON_C..\Run: [swg]  File not found
          O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
          O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
          O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
          O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
          O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
          O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
          O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
          O7 - HKU\Kaitlyn_Cochrane_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
          O7 - HKU\Keith__Cochrane_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
          O7 - HKU\Keith__Cochrane_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
          O7 - HKU\Keith__Cochrane_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
          O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
          O7 - HKU\Lori_Cochrane_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
          O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
          O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} https://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB (Hewlett-Packard Online Support Services)
          O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
          O16 - DPF: {CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Java Plug-in 1.4.2_15)
          O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
          O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
          O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
          O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
          O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
          O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
          O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
          O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
          O32 - HKLM CDRom: AutoRun - 1
          O32 - AutoRun File - [2009/11/23 23:42:49 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
          O32 - AutoRun File - [2009/06/18 17:12:18 | 000,000,088 | R--- | M] () - F:\autorun.inf -- [ UDF ]
          O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
          O33 - MountPoints2\{9fd45541-824d-11df-aad9-00b0d0180150}\Shell - "" = AutoRun
          O33 - MountPoints2\{9fd45541-824d-11df-aad9-00b0d0180150}\Shell\AutoRun - "" = Auto&Play
          O33 - MountPoints2\{9fd45541-824d-11df-aad9-00b0d0180150}\Shell\AutoRun\command - "" = F:\WD SmartWare.exe -- [2009/10/14 17:28:45 | 003,271,968 | R--- | M] (Western Digital)
          O33 - MountPoints2\{b521a1b7-b658-11dc-aa36-00b0d0180150}\Shell - "" = AutoRun
          O33 - MountPoints2\{b521a1b7-b658-11dc-aa36-00b0d0180150}\Shell\AutoRun - "" = Auto&Play
          O33 - MountPoints2\{b521a1b7-b658-11dc-aa36-00b0d0180150}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
          O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
          O34 - HKLM BootExecute: (SsiEfr.e) -  File not found
          O35 - HKLM\..comfile [open] -- "%1" %*
          O35 - HKLM\..exefile [open] -- "%1" %*
          O37 - HKLM\...com [@ = comfile] -- "%1" %*
          O37 - HKLM\...exe [@ = exefile] -- "%1" %*
           
          ========== Files/Folders - Created Within 30 Days ==========
           
          [2012/03/24 14:12:59 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Keith  Cochrane\Recent
          [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
          [1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
          [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
           
          ========== Files - Modified Within 30 Days ==========
           
          [2012/03/24 14:33:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
          [2012/03/24 13:43:47 | 000,013,740 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
          [2012/02/28 23:19:17 | 535,969,792 | -HS- | M] () -- C:\hiberfil.sys
          [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
          [1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
          [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
           
          ========== Files Created - No Company Name ==========
           
          [2012/02/26 11:51:51 | 535,969,792 | -HS- | C] () -- C:\hiberfil.sys
          [2012/02/03 17:03:45 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
          [2012/02/03 17:03:45 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
          [2012/02/03 17:03:45 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
          [2012/02/03 17:03:45 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
          [2012/02/03 17:03:45 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
          [2012/01/14 23:04:42 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
          [2011/01/08 21:57:26 | 000,059,997 | -H-- | C] () -- C:\WINDOWS\hpothb07.dat
          [2010/11/15 22:18:23 | 000,000,257 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\hpothb07.tif
          [2010/11/15 22:18:23 | 000,000,185 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\hpothb07.dat
          [2010/10/02 01:09:40 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
          [2010/03/20 22:26:48 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\pool.bin
          [2009/04/18 16:14:16 | 000,120,832 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
          [2009/04/05 21:08:32 | 000,000,355 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
          [2008/07/28 23:46:20 | 000,000,121 | ---- | C] () -- C:\WINDOWS\bdagent.INI
          [2008/07/10 23:23:32 | 000,081,984 | ---- | C] () -- C:\WINDOWS\System32\bdod.bin
          [2008/02/07 01:40:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
          [2008/01/14 18:47:06 | 000,099,712 | ---- | C] () -- C:\WINDOWS\HPBroker.dll
          [2007/05/29 23:20:38 | 000,000,253 | -H-- | C] () -- C:\Documents and Settings\NetworkService\hpothb07.tif
          [2007/05/29 23:20:38 | 000,000,169 | -H-- | C] () -- C:\Documents and Settings\NetworkService\hpothb07.dat
          [2007/05/29 23:19:47 | 000,000,149 | -H-- | C] () -- C:\Program Files\hpothb07.dat
          [2007/05/29 23:19:46 | 000,000,257 | -H-- | C] () -- C:\Program Files\hpothb07.tif
          [2006/12/25 01:51:52 | 000,066,048 | ---- | C] () -- C:\Documents and Settings\Keith  Cochrane\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
          [2006/11/26 22:56:39 | 000,684,032 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
          [2006/11/26 22:56:39 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
          [2006/10/10 22:46:35 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
          [2006/10/03 22:24:41 | 000,212,849 | ---- | C] () -- C:\Program Files\hijackthis.zip
          [2006/09/12 21:40:41 | 000,000,341 | -H-- | C] () -- C:\Documents and Settings\Keith  Cochrane\hpothb07.dat
          [2006/09/12 21:40:40 | 000,000,501 | -H-- | C] () -- C:\Documents and Settings\Keith  Cochrane\hpothb07.tif
          [2006/07/31 15:39:48 | 000,000,253 | -H-- | C] () -- C:\Documents and Settings\Kaitlyn Cochrane\hpothb07.tif
          [2006/07/31 15:39:48 | 000,000,171 | -H-- | C] () -- C:\Documents and Settings\Kaitlyn Cochrane\hpothb07.dat
          [2006/07/31 15:39:27 | 000,000,253 | -H-- | C] () -- C:\Documents and Settings\Lori Cochrane\hpothb07.tif
          [2006/07/31 15:39:27 | 000,000,168 | -H-- | C] () -- C:\Documents and Settings\Lori Cochrane\hpothb07.dat
          [2006/05/06 00:38:22 | 000,684,032 | ---- | C] () -- C:\WINDOWS\libeay32.dll
          [2006/05/06 00:38:22 | 000,155,648 | ---- | C] () -- C:\WINDOWS\ssleay32.dll
          [2006/03/31 22:35:26 | 000,000,087 | ---- | C] () -- C:\WINDOWS\encore_launcher.ini
          [2006/03/30 14:28:01 | 000,000,022 | ---- | C] () -- C:\WINDOWS\exchng.ini
          [2006/03/30 14:28:00 | 000,000,271 | ---- | C] () -- C:\WINDOWS\ODBC.INI
          [2006/01/26 16:50:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlsz.INI
          [2006/01/01 17:31:37 | 000,000,162 | ---- | C] () -- C:\Documents and Settings\Keith  Cochrane\default.pls
          [2006/01/01 17:31:30 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
          [2005/12/01 00:15:46 | 000,000,041 | ---- | C] () -- C:\WINDOWS\MSREGUSR.INI
          [2005/08/31 13:43:32 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\resourceGeneric.dll
          [2005/08/26 16:28:34 | 000,143,360 | ---- | C] () -- C:\WINDOWS\unzip.exe
          [2005/08/26 16:28:20 | 000,024,576 | ---- | C] () -- C:\WINDOWS\shortcut.exe
          [2005/08/26 16:27:58 | 000,045,056 | ---- | C] () -- C:\WINDOWS\devenum.exe
          [2005/07/27 00:14:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
          [2005/07/04 19:23:35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
          [2005/07/01 11:06:39 | 000,020,454 | ---- | C] () -- C:\WINDOWS\hpoins01.dat
          [2005/07/01 11:06:39 | 000,016,618 | ---- | C] () -- C:\WINDOWS\hpomdl01.dat
          [2005/07/01 00:46:21 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
          [2005/07/01 00:40:04 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
          [2005/06/30 19:26:09 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
          [2005/06/30 19:24:54 | 000,109,400 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
          [2004/08/04 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
          [2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
          [2004/08/04 08:00:00 | 000,432,616 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
          [2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
          [2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
          [2004/08/04 08:00:00 | 000,067,572 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
          [2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
          [2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
          [2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
          [2004/08/04 08:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
          [2004/08/04 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
          [2004/08/04 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
          [2003/03/09 16:31:04 | 000,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
          [1996/11/21 02:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
          [1996/11/21 02:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
          [1996/11/21 02:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
           
          ========== LOP Check ==========
           
          [2012/01/14 19:22:13 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config\systemprofile\Application Data\searchquband
          [2012/01/14 19:22:45 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config\systemprofile\Application Data\searchqutoolbar
          [2007/01/26 15:29:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kaitlyn Cochrane\Application Data\BearShare
          [2010/05/06 20:34:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kaitlyn Cochrane\Application Data\Research In Motion
          [2010/02/16 21:56:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Keith  Cochrane\Application Data\GARMIN
          [2009/03/31 23:44:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Keith  Cochrane\Application Data\Leadertech
          [2011/12/25 14:56:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Keith  Cochrane\Application Data\searchquband
          [2011/12/25 14:57:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Keith  Cochrane\Application Data\searchqutoolbar
          [2012/01/18 05:22:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Keith  Cochrane\Application Data\Tific
          [2011/12/26 11:33:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Keith  Cochrane\Application Data\VirtualStore
          [2011/02/01 23:44:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Keith  Cochrane\Application Data\Western Digital
          [2009/04/18 13:18:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Keith  Cochrane\Application Data\Xilisoft Corporation
          [2007/06/28 09:04:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lori Cochrane\Application Data\BearShare
          [2010/05/09 13:18:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lori Cochrane\Application Data\Research In Motion
          [2009/04/19 21:50:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1F219
          [2009/04/18 12:30:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\223CA
          [2009/04/18 12:54:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\B61
          [2011/12/25 14:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
          [2011/12/26 21:33:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
          [2009/09/26 16:14:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCSettings
          [2011/02/01 23:49:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WD_SmartWareCommon
          [2011/02/01 23:44:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Western Digital
          [2010/06/27 16:02:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
          [2005/10/15 15:37:56 | 000,000,362 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1120230696.job
           
          ========== Purity Check ==========
           
           
          < End of report >

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Computer acting weird and no Internet Access
          « Reply #37 on: March 24, 2012, 05:07:44 PM »
          You should boot your computer with OTLPE disk and take the opportunity to save your important data just in case everything gets worse.

          * Open OTL
          * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

          Code: [Select]
          :OTL
          O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
          O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
          O3 - HKU\Kaitlyn_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
          O3 - HKU\Kaitlyn_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
          O3 - HKU\Kaitlyn_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
          O3 - HKU\Keith__Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
          O3 - HKU\Lori_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
          O3 - HKU\Lori_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
          O3 - HKU\Lori_Cochrane_ON_C\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
          O4 - HKU\Kaitlyn_Cochrane_ON_C..\Run: [swg]  File not found
          O4 - HKU\Lori_Cochrane_ON_C..\Run: [swg]  File not found

          :COMMANDS
          [resethosts]
          [purity]
          [start explorer]

          * Click Run Fix
          * OTLI2 may ask to reboot the machine. Please do so if asked.
          * Click OK
          * A report will open. Copy and Paste that report in your next reply.
          ***************************************************************
          Is there any change on your computer?
          Windows 8 and Windows 10 dual boot with two SSD's

          mecka

            Topic Starter


            Rookie

            Re: Computer acting weird and no Internet Access
            « Reply #38 on: March 25, 2012, 09:17:59 PM »
            ok before i follow your last instructions should i try to backup my pictures?I have tried but cant seem to send files to cd or flashdrives?

            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: Computer acting weird and no Internet Access
            « Reply #39 on: March 26, 2012, 10:49:11 AM »
            Quote
            ok before i follow your last instructions should i try to backup my pictures?I have tried but cant seem to send files to cd or flashdrives?
            You should be able to send files to your USB device. If you're using a CD/DVD to back them up you should use a burner such as Nero and burn a data disk. Are you getting any error messages?
            Windows 8 and Windows 10 dual boot with two SSD's

            mecka

              Topic Starter


              Rookie

              Re: Computer acting weird and no Internet Access
              « Reply #40 on: March 26, 2012, 12:53:22 PM »
              I have tried to both send to flash drive and burn to no avail with both ways.I right click on the picture and or file and it asks for send to ,but when i click on the lexar flash drive i am using nothing happens/no transferring .I am sure hoping i wont lose all my pictures on there .


              Thanks

              SuperDave

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: Computer acting weird and no Internet Access
              « Reply #41 on: March 26, 2012, 12:56:32 PM »
              Quote
              I right click on the picture and or file and it asks for send to ,but when i click on the lexar flash drive i am using nothing happens/no transferring .I am sure hoping i wont lose all my pictures on there .
              When you right-click and select Send to, do you see your lexar flash drive? What happens when you try to burn a CD/DVD?
              Windows 8 and Windows 10 dual boot with two SSD's

              mecka

                Topic Starter


                Rookie

                Re: Computer acting weird and no Internet Access
                « Reply #42 on: March 26, 2012, 01:35:00 PM »
                Yes i can see the flash drive but it wont send ,i have tried to burn but again cant send the pictures to the burner program.

                SuperDave

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: Computer acting weird and no Internet Access
                « Reply #43 on: March 27, 2012, 10:44:20 AM »
                Quote
                Yes i can see the flash drive but it wont send ,i have tried to burn but again cant send the pictures to the burner program.
                You could also copy and paste in your flash drive. As for the pictures just do a search using *.jpg or whatever format your pictures are saved with.
                Windows 8 and Windows 10 dual boot with two SSD's

                mecka

                  Topic Starter


                  Rookie

                  Re: Computer acting weird and no Internet Access
                  « Reply #44 on: March 28, 2012, 08:52:35 PM »
                  I was able to backup all my pictures to external hard drive,here is my OTL log

                  Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
                  Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
                  Registry key HKEY_USERS\Kaitlyn_Cochrane_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
                  Registry key HKEY_USERS\Kaitlyn_Cochrane_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
                  Registry key HKEY_USERS\Kaitlyn_Cochrane_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}\ deleted successfully.
                  Registry key HKEY_USERS\Keith__Cochrane_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}\ not found.
                  Registry key HKEY_USERS\Lori_Cochrane_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ not found.
                  Registry key HKEY_USERS\Lori_Cochrane_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
                  Registry key HKEY_USERS\Lori_Cochrane_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
                  Registry key HKEY_USERS\Kaitlyn_Cochrane_ON_C\Software\Microsoft\Windows\CurrentVersion\Run not found.
                  Registry key HKEY_USERS\Lori_Cochrane_ON_C\Software\Microsoft\Windows\CurrentVersion\Run not found.
                  ========== COMMANDS ==========
                  C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
                  HOSTS file reset successfully
                   
                  OTLPE by OldTimer - Version 3.1.48.0 log created on 03292012_004345