Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-06-2017 Ran by CSM7100 (13-06-2017 21:01:42) Running from F:\ Microsoft Windows XP Professional Service Pack 2 (X86) (2007-07-16 04:52:18) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= admin (S-1-5-21-3186419010-3260862241-2880911088-1005 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\admin Administrator (S-1-5-21-3186419010-3260862241-2880911088-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator CSM7100 (S-1-5-21-3186419010-3260862241-2880911088-1004 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\CSM7100 Guest (S-1-5-21-3186419010-3260862241-2880911088-501 - Limited - Disabled) HelpAssistant (S-1-5-21-3186419010-3260862241-2880911088-1003 - Limited - Disabled) SUPPORT_388945a0 (S-1-5-21-3186419010-3260862241-2880911088-1002 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Reader 6.0.1 (HKLM\...\{AC76BA86-7AD7-1033-7B44-A00000000001}) (Version: 006.000.001 - Adobe Systems Incorporated) CSM7000 (HKLM\...\{84EFBC95-37E3-49EF-B4CB-D9413E526E94}) (Version: 1.00.0001 - ESSEMTEC) ESSEMTEC-Manuals (HKLM\...\{EBB9958C-EAE1-41F6-B176-F619FF733B37}) (Version: 1.00.0000 - ESSEMTEC) Intel(R) Graphics Media Accelerator Driver (HKLM\...\{8A708DD8-A5E6-11D4-A706-000629E95E20}) (Version: 6.14.10.4436 - ) REALTEK GbE & FE Ethernet PCI NIC Driver (HKLM\...\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}) (Version: 1.05.0000 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.5282 - Realtek Semiconductor Corp.) WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{0000002F-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{0002E005-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{0BE35200-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{0BE35201-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{0BE35202-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{0BE35203-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{0BE35204-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{46763EE0-CAB2-11CE-8C20-00AA0051E5D4}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-3186419010-3260862241-2880911088-1004_Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32 -> no filepath ==================== Scheduled Tasks============================= (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== ==================== Alternate Data Streams (Whitelisted) ========= ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2007-03-31 01:40 - 2004-08-04 14:00 - 00000734 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3186419010-3260862241-2880911088-1004\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\CSM7100\Local Settings\Application Data\Microsoft\Wallpaper1.bmp DNS Servers: Media is not connected to internet. Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\startupreg: wsctf.exe => wsctf.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= 12-06-2017 10:12:40 System Checkpoint ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/12/2017 07:06:24 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Hanging application LightPlacer.exe, version 7.1.0.2, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (06/12/2017 06:34:29 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Hanging application LightPlacer.exe, version 7.1.0.2, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (01/25/2017 10:53:36 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application lightplacer.exe, version 7.1.0.2, faulting module lightplacer.exe, version 7.1.0.2, fault address 0x00024daa. Processing media-specific event for [lightplacer.exe!ws!] Error: (05/13/2016 01:30:57 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Hanging application LightPlacer.exe, version 7.1.0.2, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (10/19/2015 01:39:25 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application lightplacer.exe, version 7.1.0.2, faulting module lightplacer.exe, version 7.1.0.2, fault address 0x0003492d. Processing media-specific event for [lightplacer.exe!ws!] Error: (07/21/2014 01:15:20 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Hanging application LightPlacer.exe, version 7.1.0.2, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (07/17/2014 03:47:40 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Hanging application LightPlacer.exe, version 7.1.0.2, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (11/17/2014 06:01:23 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Hanging application LightPlacer.exe, version 7.1.0.2, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (09/05/2014 06:32:31 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application lightplacer.exe, version 7.1.0.2, faulting module lightplacer.exe, version 7.1.0.2, fault address 0x0000f74a. Processing media-specific event for [lightplacer.exe!ws!] Error: (09/04/2014 06:10:35 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application lightplacer.exe, version 7.1.0.2, faulting module lightplacer.exe, version 7.1.0.2, fault address 0x00030931. Processing media-specific event for [lightplacer.exe!ws!] System errors: ============= Error: (06/12/2017 09:08:20 AM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "%%1084 = This service cannot be started in Safe Mode" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error: (06/12/2017 09:04:52 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip Error: (06/12/2017 09:04:52 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. Error: (06/12/2017 09:04:52 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. Error: (06/12/2017 09:04:52 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. Error: (06/12/2017 09:04:52 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. Error: (06/12/2017 09:03:44 AM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "%%1084 = This service cannot be started in Safe Mode" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error: (06/12/2017 09:01:39 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip Error: (06/12/2017 09:01:39 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. Error: (06/12/2017 09:01:39 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. ==================== Memory info =========================== Processor: Intel(R) Celeron(R) D CPU 3.06GHz Percentage of memory in use: 39% Total physical RAM: 503.48 MB Available physical RAM: 304.38 MB Total Virtual: 1228.54 MB Available Virtual: 1057.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:16 GB) (Free:12.7 GB) NTFS ==>[drive with boot components (Windows XP)] Drive d: () (Fixed) (Total:58.49 GB) (Free:58.26 GB) NTFS Drive f: (ADATA 8 GB) (Removable) (Total:7.23 GB) (Free:0.4 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: B8879443) Partition 1: (Active) - (Size=16 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=58.5 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 7.2 GB) (Disk ID: 04DD5721) Partition 1: (Active) - (Size=7.2 GB) - (Type=0B) ==================== End of Addition.txt ============================