ectexas
Topic Starter
Please help.
I was having a problem with my comupter desktop being hidden and my virusscan telling me that I was having a hard drive crash.
My computer guy fixed this, but now it is spouting off random ads (audio) and redirecting my internet searches to different sites other than what I intend.
Here is the OTL Extras log
OTL Extras logfile created on: 9/5/2011 12:38:11 PM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.38 Gb Available Physical Memory | 79.27% Memory free
6.75 Gb Paging File | 6.39 Gb Available in Paging File | 94.63% Paging File free
Paging file location(s): C:\pagefile.sys 4000 5000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.51 Gb Total Space | 889.19 Gb Free Space | 95.46% Space Free | Partition Type: NTFS
Drive D: | 473.56 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 1.87 Gb Total Space | 1.82 Gb Free Space | 97.44% Space Free | Partition Type: FAT
Computer Name: RICK | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\JCW Software LLC\FastManager\FastManager.exe" = C:\Program Files\JCW Software LLC\FastManager\FastManager.exe:*:Enabled:FastManager – (JCW Software LLC)
"C:\Documents and Settings\Administrator\Local Settings\Temp\7zS52.tmp\setup\HPZnui01.exe" = C:\Documents and Settings\Administrator\Local Settings\Temp\7zS52.tmp\setup\HPZnui01.exe:*:Enabled:hpznui01.exe
"C:\Documents and Settings\Administrator\Local Settings\Temp\7zS52.tmp\setup\hponicifs01.exe" = C:\Documents and Settings\Administrator\Local Settings\Temp\7zS52.tmp\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1B1DDAD2-C704-49F8-8FC2-18DAAD9A87C5}" = Sound Blaster Audigy
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 26
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{324CEC09-007A-48eb-90E0-9D42D4D5EB0A}" = NetDeviceManager
"{32A72502-BC2C-4C39-ACEA-BC3D463F0697}" = EN
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{411C5D92-2AE4-436F-A027-1E441EDC05CE}" = VIPRE Antivirus Premium
"{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}" = Acronis True Image Home
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}" = FontNav
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{63218538-4A69-497F-8455-904261B0E9E4}" = CorelDRAW Graphics Suite X3
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7EC003A3-51E9-4019-BEC0-DF99B0DF5CCF}" = NVDVD
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}" = HP Officejet Pro All-In-One Series
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8C5FAD77-F678-4758-A296-C12F08D179E0}" = Microsoft IntelliPoint 6.2
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{91793EA9-4AA4-4AC4-9AAF-3A6E15FBA723}" = FastManager
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.85
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C1D1FC57-3EB9-4B21-BCA3-F1C927508200}" = VIPRE Antivirus Premium
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C94E45B0-6AA6-4FB9-9AAE-22085F631880}" = VBA
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}" = Update Manager
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F7F23DFB-31E1-B7EC-7A6D-7668B595ADAE}" = FlipShare
"{F843FCA5-5AF8-4080-88A8-652453FBC841}" = CardScan 8.0.5
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only)
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"FastManager Updates" = FastManager Updates
"Google Updater" = Google Updater
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"PROPLUS" = Microsoft Office Professional Plus 2007
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YTdetect" = Yahoo! Detect
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/29/2011 11:21:00 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {201C41F9-7586-4D18-8DFE-A86D2F5B1107}.
Error - 8/29/2011 11:21:15 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {201C41F9-7586-4D18-8DFE-A86D2F5B1107}.
Error - 8/29/2011 11:21:15 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {2C877784-DD57-4336-B4DB-1D6AC39B43D2}.
Error - 8/29/2011 11:21:15 AM | Computer Name = RICK | Source = MsiInstaller | ID = 11935
Description = Product: ESScore – Error 1935.An error occurred during the installation
of assembly component {26D149B5-DE47-41A1-89B3-121769423104}. HRESULT: 0x8002802F.
assembly interface: , function: CreateAssemblyCache, assembly name: VirtualCollectionBase-Defs-PlatReq,Version="1.0.5227.4054",PublicKeyToken="B0CFD8589C27B05F",Culture="neutral",FileVersion="1.0.0.0",ProcessorArchitecture="MSIL"
Error - 9/2/2011 9:25:56 AM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x016f2655.
Error - 9/2/2011 9:30:32 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {26D149B5-DE47-41A1-89B3-121769423104}.
Error - 9/2/2011 9:31:41 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {26D149B5-DE47-41A1-89B3-121769423104}.
Error - 9/2/2011 9:31:48 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {201C41F9-7586-4D18-8DFE-A86D2F5B1107}.
Error - 9/2/2011 9:31:48 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {2C877784-DD57-4336-B4DB-1D6AC39B43D2}.
Error - 9/2/2011 9:31:48 AM | Computer Name = RICK | Source = MsiInstaller | ID = 11935
Description = Product: ESScore – Error 1935.An error occurred during the installation
of assembly component {26D149B5-DE47-41A1-89B3-121769423104}. HRESULT: 0x8002802F.
assembly interface: , function: CreateAssemblyCache, assembly name: VirtualCollectionBase-Defs-PlatReq,Version="1.0.5227.4054",PublicKeyToken="B0CFD8589C27B05F",Culture="neutral",FileVersion="1.0.0.0",ProcessorArchitecture="MSIL"
[ System Events ]
Error - 8/26/2011 5:44:38 PM | Computer Name = RICK | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{6742BB89-A2A6-4C30-A689-6C997F12A218}. The
backup browser is stopping.
Error - 8/29/2011 6:52:29 AM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
Error - 8/30/2011 7:01:42 AM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
Error - 8/31/2011 7:28:59 AM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
Error - 8/31/2011 7:31:24 AM | Computer Name = RICK | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{6742BB89-A2A6-4C30-A689-6C997F12A218}. The
backup browser is stopping.
Error - 8/31/2011 12:17:01 PM | Computer Name = RICK | Source = NetBT | ID = 4321
Description = The name "OFFICE :1d" could not be registered on the Interface
with IP address 192.168.1.100. The machine with the IP address 192.168.1.107 did
not allow the name to be claimed by this machine.
Error - 9/1/2011 7:18:29 AM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
Error - 9/2/2011 7:19:04 AM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
Error - 9/2/2011 7:41:46 AM | Computer Name = RICK | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{6742BB89-A2A6-4C30-A689-6C997F12A218}. The
backup browser is stopping.
Error - 9/5/2011 12:36:30 PM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
< End of report >
Here is the OTL "OTL Log"
OTL logfile created on: 9/5/2011 12:38:11 PM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.38 Gb Available Physical Memory | 79.27% Memory free
6.75 Gb Paging File | 6.39 Gb Available in Paging File | 94.63% Paging File free
Paging file location(s): C:\pagefile.sys 4000 5000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.51 Gb Total Space | 889.19 Gb Free Space | 95.46% Space Free | Partition Type: NTFS
Drive D: | 473.56 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 1.87 Gb Total Space | 1.82 Gb Free Space | 97.44% Space Free | Partition Type: FAT
Computer Name: RICK | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
PRC - C:\Program Files\CardScan\CardScan\CardScanAgent.exe (CardScan, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (Macrovision Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\vcore.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\remediation.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libZip.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libVvs.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libtd.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libRTF.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libOleA.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libRar.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libNSIS.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libMsCab.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libMsi.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libMachoUniv.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libEmail.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libBase64.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\lgpl.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\lib7zip.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\vipre.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
MOD - C:\Program Files\Flip Video\FlipShare\Core.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\qca2.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtGui4.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtXml4.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtSql4.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtCore4.dll ()
MOD - C:\Program Files\Common Files\Acronis\Common\gc.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\unrar.dll ()
MOD - C:\WINDOWS\system32\P17.dll ()
MOD - C:\WINDOWS\system32\hpgt34.dll ()
========== Win32 Services (SafeList) ==========
SRV - (NetTcpPortSharing) – File not found
SRV - (idsvc) – File not found
SRV - (FontCache3.0.0.0) – File not found
SRV - (clr_optimization_v2.0.50727_32) – File not found
SRV - (aspnet_state) – File not found
SRV - (SBAMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
SRV - (SBPIMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (FlipShare Service) – C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
========== Driver Services (SafeList) ==========
DRV - (sbapifs) – C:\WINDOWS\system32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (sbaphd) – C:\WINDOWS\system32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (SBRE) – C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (SbFw) – C:\WINDOWS\system32\drivers\SbFw.sys (Sunbelt Software, Inc.)
DRV - (SbTis) – C:\WINDOWS\system32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (SbHips) – C:\WINDOWS\system32\drivers\sbhips.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCL) – C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvgts) – C:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D8 25 33 DD 8F 66 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll File not found
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files\Google\Google Updater\2.4.1691.8062\npCIDetect13.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2011/08/22 16:25:51 | 000,435,780 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15023 more lines…
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [CardScanAgent] C:\Program Files\CardScan\CardScan\CardScanAgent.exe (CardScan, Inc.)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.dll ()
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://sanford.webex.com/client/T27L10NSP1…ort/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1 192.168.1.1 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6742BB89-A2A6-4C30-A689-6C997F12A218}: DhcpNameServer = 192.168.15.1 192.168.1.1 192.168.15.1
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/06 18:52:01 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/08/23 07:00:00 | 000,000,110 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{1cb00aae-f3c9-11de-8da4-00221546b5c3}\Shell\AutoRun\command - "" = K:\Setup_FlipShare.exe
O33 - MountPoints2\{1cb00aae-f3c9-11de-8da4-00221546b5c3}\Shell\Setup FlipShare\command - "" = K:\Setup_FlipShare.exe
O33 - MountPoints2\{45cef042-82a8-11de-a766-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{45cef042-82a8-11de-a766-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{45cef042-82a8-11de-a766-806d6172696f}\Shell\AutoRun\command - "" = D:\CTRun\Start.EXE
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\SETUP.EXE – [2001/08/23 07:00:00 | 001,310,720 | R— | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/09/05 12:37:10 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2011/09/05 12:37:07 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/08/22 16:36:20 | 000,000,000 | —D | C] – C:\Program Files\Windows Installer Clean Up
[2011/08/22 16:36:09 | 000,000,000 | —D | C] – C:\Program Files\MSECACHE
[2011/08/22 16:17:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2011/08/22 15:22:33 | 015,338,952 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\windows-kb890830-v3.22.exe
[2011/08/22 14:23:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2011/08/22 14:23:12 | 000,335,872 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsar.dll
[2011/08/22 14:23:12 | 000,331,776 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrshe.dll
[2011/08/22 14:23:12 | 000,286,720 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsfr.dll
[2011/08/22 14:23:12 | 000,282,624 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsit.dll
[2011/08/22 14:23:12 | 000,282,624 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrses.dll
[2011/08/22 14:23:12 | 000,282,624 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsel.dll
[2011/08/22 14:23:12 | 000,278,528 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsde.dll
[2011/08/22 14:23:12 | 000,274,432 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrspt.dll
[2011/08/22 14:23:12 | 000,274,432 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsnl.dll
[2011/08/22 14:23:12 | 000,274,432 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsesm.dll
[2011/08/22 14:23:12 | 000,270,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsru.dll
[2011/08/22 14:23:12 | 000,270,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsptb.dll
[2011/08/22 14:23:12 | 000,270,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsja.dll
[2011/08/22 14:23:12 | 000,266,240 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsko.dll
[2011/08/22 14:23:12 | 000,262,144 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrshu.dll
[2011/08/22 14:23:12 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrstr.dll
[2011/08/22 14:23:12 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssl.dll
[2011/08/22 14:23:12 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssk.dll
[2011/08/22 14:23:12 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrspl.dll
[2011/08/22 14:23:12 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsth.dll
[2011/08/22 14:23:12 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssv.dll
[2011/08/22 14:23:12 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsno.dll
[2011/08/22 14:23:12 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsda.dll
[2011/08/22 14:23:12 | 000,249,856 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsfi.dll
[2011/08/22 14:23:12 | 000,249,856 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrseng.dll
[2011/08/22 14:23:12 | 000,249,856 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrscs.dll
[2011/08/22 14:23:12 | 000,229,376 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrszhc.dll
[2011/08/22 14:23:12 | 000,126,976 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrszht.dll
[2011/08/22 14:23:11 | 000,543,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\easyupdatusapiu.dll
[2011/08/22 14:21:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/08/22 14:20:17 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Administrator\My Documents\spybotsd162.exe
[2011/08/22 13:48:43 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/08/22 13:48:43 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/08/22 13:48:43 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/08/22 13:32:50 | 000,000,000 | —D | C] – C:\WINDOWS\System32\system
[2011/08/22 13:22:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Recent
[2011/08/22 10:28:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2011/08/22 10:28:39 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/08/22 10:28:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/08/22 10:28:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/08/22 10:28:35 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/08/22 10:28:35 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2002/04/10 20:41:06 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/05 12:37:24 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2011/09/05 12:37:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/05 12:34:14 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/09/05 11:36:44 | 000,013,736 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/09/05 11:36:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/09/02 11:28:23 | 012,429,824 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\073009.cdb
[2011/09/02 09:36:17 | 000,002,828 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/09/02 08:32:27 | 000,002,525 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\FastManager.lnk
[2011/09/02 06:37:01 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/22 17:13:36 | 000,000,960 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to EasyShare.lnk
[2011/08/22 17:11:28 | 000,000,764 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to Card Scan.lnk
[2011/08/22 16:25:51 | 000,435,780 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/08/22 16:24:02 | 000,000,793 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to mbam.lnk
[2011/08/22 16:19:12 | 000,001,743 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/08/22 16:13:17 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/08/22 16:07:49 | 000,000,237 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Windows Update.url
[2011/08/22 15:42:22 | 000,000,115 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\netstat.bat
[2011/08/22 15:22:33 | 015,338,952 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\windows-kb890830-v3.22.exe
[2011/08/22 14:34:28 | 000,436,514 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.old
[2011/08/22 14:29:18 | 000,475,466 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/22 14:29:18 | 000,076,374 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/22 14:23:30 | 000,273,344 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/08/22 14:23:30 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/08/22 14:22:45 | 000,273,344 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/08/22 14:21:37 | 000,000,960 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/08/22 14:21:37 | 000,000,942 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Spybot - Search & Destroy.lnk
[2011/08/22 14:20:17 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Administrator\My Documents\spybotsd162.exe
[2011/08/10 08:38:00 | 000,288,816 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Rebel.pdf
[2011/08/10 08:38:00 | 000,280,306 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Bulldog.pdf
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/08/22 17:13:36 | 000,000,960 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to EasyShare.lnk
[2011/08/22 17:11:28 | 000,000,764 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to Card Scan.lnk
[2011/08/22 16:36:20 | 000,002,343 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Install Clean Up.lnk
[2011/08/22 16:24:02 | 000,000,793 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to mbam.lnk
[2011/08/22 16:19:12 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/08/22 16:19:12 | 000,001,743 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/08/22 15:42:22 | 000,000,115 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\netstat.bat
[2011/08/22 14:21:37 | 000,000,960 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/08/22 14:21:37 | 000,000,942 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Spybot - Search & Destroy.lnk
[2011/08/22 14:13:24 | 000,000,237 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Windows Update.url
[2011/08/10 10:38:29 | 000,288,816 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Rebel.pdf
[2011/08/10 10:38:29 | 000,280,306 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Bulldog.pdf
[2011/05/21 06:01:00 | 002,123,582 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/01/31 16:27:59 | 000,273,344 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/01/31 16:27:58 | 000,273,344 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/01/31 16:27:58 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2009/12/29 16:15:43 | 000,023,452 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\{BE6C4EE5-8015-4479-89B2-EBD1E205A93E}.jpg
[2009/12/11 13:40:12 | 000,016,896 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/30 09:12:02 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/08/20 13:29:54 | 000,101,376 | —- | C] () – C:\WINDOWS\System32\hpgt34.dll
[2009/08/18 12:05:26 | 000,150,228 | —- | C] () – C:\WINDOWS\hpwins05.dat
[2009/08/18 12:04:51 | 000,016,050 | —- | C] () – C:\WINDOWS\hpwscr05.dat
[2009/08/18 12:04:51 | 000,004,785 | —- | C] () – C:\WINDOWS\hpwmdl05.dat
[2009/08/16 16:19:40 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/08/16 16:19:40 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD2140.DAT
[2009/08/14 12:20:08 | 000,274,432 | —- | C] () – C:\WINDOWS\System32\Carcla40.dll
[2009/08/14 08:49:07 | 000,002,828 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/08/07 10:11:51 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2009/08/07 10:08:47 | 000,005,627 | R— | C] () – C:\WINDOWS\System32\Ludap17.ini
[2009/08/07 10:08:47 | 000,000,039 | R— | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2009/08/07 10:01:44 | 000,003,636 | R— | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2009/08/07 10:01:41 | 000,000,962 | R— | C] () – C:\WINDOWS\System32\AsusSetup.ini
[2009/08/07 10:01:41 | 000,000,400 | R— | C] () – C:\WINDOWS\System32\raidmgmt.ini
[2009/08/06 18:57:51 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/08/06 18:57:48 | 000,024,921 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/08/06 18:57:36 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/08/06 18:53:26 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/08/06 18:49:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/08/06 11:44:36 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/08/06 11:43:40 | 000,321,136 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2008/10/07 11:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 11:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/04/14 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 07:00:00 | 000,475,466 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 07:00:00 | 000,076,374 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2008/02/19 01:33:34 | 000,446,352 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2005/05/03 06:38:42 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\P17.dll
[2003/10/02 05:48:18 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
========== LOP Check ==========
[2011/01/31 13:44:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AMPSoft
[2011/01/31 13:44:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\CardScan
[2011/01/31 13:45:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Skinux
[2011/01/31 14:02:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/01/31 14:02:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CardScan
[2011/01/31 14:02:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Flip Video
[2011/01/31 14:02:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JCWSoftwareLLC
[2011/01/31 14:02:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/10/31 17:46:49 | 000,000,452 | —- | M] () – C:\WINDOWS\Tasks\EasyShare Registration Task.job
[2010/03/31 09:09:02 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
========== Purity Check ==========
< End of report >
Here is the HIJackThis Log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:46:37 PM, on 9/5/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\CardScan\CardScan\CardScanAgent.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [CardScanAgent] "C:\Program Files\CardScan\CardScan\CardScanAgent.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SBAMTray] "C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://sanford.webex.com/client/T27L10NSP1…ort/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) - Unknown owner - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (file missing)
O23 - Service: Google Update Service (gupdate1ca241a9f03aee) (gupdate1ca241a9f03aee) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows CardSpace (idsvc) - Unknown owner - c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VIPRE Antivirus Premium (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: SB Recovery Service (SBPIMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe
–
End of file - 8677 bytes
I tried to run the aswMBR.exe file but when I double clicked on it it would not run.
Thanks,
Ectexas
I was having a problem with my comupter desktop being hidden and my virusscan telling me that I was having a hard drive crash.
My computer guy fixed this, but now it is spouting off random ads (audio) and redirecting my internet searches to different sites other than what I intend.
Here is the OTL Extras log
OTL Extras logfile created on: 9/5/2011 12:38:11 PM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.38 Gb Available Physical Memory | 79.27% Memory free
6.75 Gb Paging File | 6.39 Gb Available in Paging File | 94.63% Paging File free
Paging file location(s): C:\pagefile.sys 4000 5000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.51 Gb Total Space | 889.19 Gb Free Space | 95.46% Space Free | Partition Type: NTFS
Drive D: | 473.56 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 1.87 Gb Total Space | 1.82 Gb Free Space | 97.44% Space Free | Partition Type: FAT
Computer Name: RICK | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\JCW Software LLC\FastManager\FastManager.exe" = C:\Program Files\JCW Software LLC\FastManager\FastManager.exe:*:Enabled:FastManager – (JCW Software LLC)
"C:\Documents and Settings\Administrator\Local Settings\Temp\7zS52.tmp\setup\HPZnui01.exe" = C:\Documents and Settings\Administrator\Local Settings\Temp\7zS52.tmp\setup\HPZnui01.exe:*:Enabled:hpznui01.exe
"C:\Documents and Settings\Administrator\Local Settings\Temp\7zS52.tmp\setup\hponicifs01.exe" = C:\Documents and Settings\Administrator\Local Settings\Temp\7zS52.tmp\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1B1DDAD2-C704-49F8-8FC2-18DAAD9A87C5}" = Sound Blaster Audigy
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 26
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{324CEC09-007A-48eb-90E0-9D42D4D5EB0A}" = NetDeviceManager
"{32A72502-BC2C-4C39-ACEA-BC3D463F0697}" = EN
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{411C5D92-2AE4-436F-A027-1E441EDC05CE}" = VIPRE Antivirus Premium
"{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}" = Acronis True Image Home
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}" = FontNav
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{63218538-4A69-497F-8455-904261B0E9E4}" = CorelDRAW Graphics Suite X3
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7EC003A3-51E9-4019-BEC0-DF99B0DF5CCF}" = NVDVD
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}" = HP Officejet Pro All-In-One Series
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8C5FAD77-F678-4758-A296-C12F08D179E0}" = Microsoft IntelliPoint 6.2
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{91793EA9-4AA4-4AC4-9AAF-3A6E15FBA723}" = FastManager
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.85
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C1D1FC57-3EB9-4B21-BCA3-F1C927508200}" = VIPRE Antivirus Premium
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C94E45B0-6AA6-4FB9-9AAE-22085F631880}" = VBA
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}" = Update Manager
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F7F23DFB-31E1-B7EC-7A6D-7668B595ADAE}" = FlipShare
"{F843FCA5-5AF8-4080-88A8-652453FBC841}" = CardScan 8.0.5
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only)
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"FastManager Updates" = FastManager Updates
"Google Updater" = Google Updater
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"PROPLUS" = Microsoft Office Professional Plus 2007
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YTdetect" = Yahoo! Detect
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/29/2011 11:21:00 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {201C41F9-7586-4D18-8DFE-A86D2F5B1107}.
Error - 8/29/2011 11:21:15 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {201C41F9-7586-4D18-8DFE-A86D2F5B1107}.
Error - 8/29/2011 11:21:15 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {2C877784-DD57-4336-B4DB-1D6AC39B43D2}.
Error - 8/29/2011 11:21:15 AM | Computer Name = RICK | Source = MsiInstaller | ID = 11935
Description = Product: ESScore – Error 1935.An error occurred during the installation
of assembly component {26D149B5-DE47-41A1-89B3-121769423104}. HRESULT: 0x8002802F.
assembly interface: , function: CreateAssemblyCache, assembly name: VirtualCollectionBase-Defs-PlatReq,Version="1.0.5227.4054",PublicKeyToken="B0CFD8589C27B05F",Culture="neutral",FileVersion="1.0.0.0",ProcessorArchitecture="MSIL"
Error - 9/2/2011 9:25:56 AM | Computer Name = RICK | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x016f2655.
Error - 9/2/2011 9:30:32 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {26D149B5-DE47-41A1-89B3-121769423104}.
Error - 9/2/2011 9:31:41 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {26D149B5-DE47-41A1-89B3-121769423104}.
Error - 9/2/2011 9:31:48 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {201C41F9-7586-4D18-8DFE-A86D2F5B1107}.
Error - 9/2/2011 9:31:48 AM | Computer Name = RICK | Source = MsiInstaller | ID = 10005
Description = Product: ESScore – Error 2908.Could not register component {2C877784-DD57-4336-B4DB-1D6AC39B43D2}.
Error - 9/2/2011 9:31:48 AM | Computer Name = RICK | Source = MsiInstaller | ID = 11935
Description = Product: ESScore – Error 1935.An error occurred during the installation
of assembly component {26D149B5-DE47-41A1-89B3-121769423104}. HRESULT: 0x8002802F.
assembly interface: , function: CreateAssemblyCache, assembly name: VirtualCollectionBase-Defs-PlatReq,Version="1.0.5227.4054",PublicKeyToken="B0CFD8589C27B05F",Culture="neutral",FileVersion="1.0.0.0",ProcessorArchitecture="MSIL"
[ System Events ]
Error - 8/26/2011 5:44:38 PM | Computer Name = RICK | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{6742BB89-A2A6-4C30-A689-6C997F12A218}. The
backup browser is stopping.
Error - 8/29/2011 6:52:29 AM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
Error - 8/30/2011 7:01:42 AM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
Error - 8/31/2011 7:28:59 AM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
Error - 8/31/2011 7:31:24 AM | Computer Name = RICK | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{6742BB89-A2A6-4C30-A689-6C997F12A218}. The
backup browser is stopping.
Error - 8/31/2011 12:17:01 PM | Computer Name = RICK | Source = NetBT | ID = 4321
Description = The name "OFFICE :1d" could not be registered on the Interface
with IP address 192.168.1.100. The machine with the IP address 192.168.1.107 did
not allow the name to be claimed by this machine.
Error - 9/1/2011 7:18:29 AM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
Error - 9/2/2011 7:19:04 AM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
Error - 9/2/2011 7:41:46 AM | Computer Name = RICK | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{6742BB89-A2A6-4C30-A689-6C997F12A218}. The
backup browser is stopping.
Error - 9/5/2011 12:36:30 PM | Computer Name = RICK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Microsoft .NET Framework
NGEN v4.0.30319_X86 service to connect.
< End of report >
Here is the OTL "OTL Log"
OTL logfile created on: 9/5/2011 12:38:11 PM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.38 Gb Available Physical Memory | 79.27% Memory free
6.75 Gb Paging File | 6.39 Gb Available in Paging File | 94.63% Paging File free
Paging file location(s): C:\pagefile.sys 4000 5000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.51 Gb Total Space | 889.19 Gb Free Space | 95.46% Space Free | Partition Type: NTFS
Drive D: | 473.56 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 1.87 Gb Total Space | 1.82 Gb Free Space | 97.44% Space Free | Partition Type: FAT
Computer Name: RICK | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
PRC - C:\Program Files\CardScan\CardScan\CardScanAgent.exe (CardScan, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (Macrovision Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\vcore.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\remediation.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libZip.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libVvs.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libtd.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libRTF.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libOleA.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libRar.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libNSIS.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libMsCab.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libMsi.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libMachoUniv.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libEmail.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\libBase64.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\lgpl.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\Definitions\lib7zip.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\vipre.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
MOD - C:\Program Files\Flip Video\FlipShare\Core.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\qca2.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtGui4.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtXml4.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtSql4.dll ()
MOD - C:\Program Files\Flip Video\FlipShare\QtCore4.dll ()
MOD - C:\Program Files\Common Files\Acronis\Common\gc.dll ()
MOD - C:\Program Files\Sunbelt Software\VIPRE\unrar.dll ()
MOD - C:\WINDOWS\system32\P17.dll ()
MOD - C:\WINDOWS\system32\hpgt34.dll ()
========== Win32 Services (SafeList) ==========
SRV - (NetTcpPortSharing) – File not found
SRV - (idsvc) – File not found
SRV - (FontCache3.0.0.0) – File not found
SRV - (clr_optimization_v2.0.50727_32) – File not found
SRV - (aspnet_state) – File not found
SRV - (SBAMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
SRV - (SBPIMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (FlipShare Service) – C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
========== Driver Services (SafeList) ==========
DRV - (sbapifs) – C:\WINDOWS\system32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (sbaphd) – C:\WINDOWS\system32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (SBRE) – C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (SbFw) – C:\WINDOWS\system32\drivers\SbFw.sys (Sunbelt Software, Inc.)
DRV - (SbTis) – C:\WINDOWS\system32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (SbHips) – C:\WINDOWS\system32\drivers\sbhips.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCL) – C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvgts) – C:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D8 25 33 DD 8F 66 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll File not found
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files\Google\Google Updater\2.4.1691.8062\npCIDetect13.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2011/08/22 16:25:51 | 000,435,780 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15023 more lines…
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [CardScanAgent] C:\Program Files\CardScan\CardScan\CardScanAgent.exe (CardScan, Inc.)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.dll ()
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://sanford.webex.com/client/T27L10NSP1…ort/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1 192.168.1.1 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6742BB89-A2A6-4C30-A689-6C997F12A218}: DhcpNameServer = 192.168.15.1 192.168.1.1 192.168.15.1
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/06 18:52:01 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/08/23 07:00:00 | 000,000,110 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{1cb00aae-f3c9-11de-8da4-00221546b5c3}\Shell\AutoRun\command - "" = K:\Setup_FlipShare.exe
O33 - MountPoints2\{1cb00aae-f3c9-11de-8da4-00221546b5c3}\Shell\Setup FlipShare\command - "" = K:\Setup_FlipShare.exe
O33 - MountPoints2\{45cef042-82a8-11de-a766-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{45cef042-82a8-11de-a766-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{45cef042-82a8-11de-a766-806d6172696f}\Shell\AutoRun\command - "" = D:\CTRun\Start.EXE
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\SETUP.EXE – [2001/08/23 07:00:00 | 001,310,720 | R— | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/09/05 12:37:10 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2011/09/05 12:37:07 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/08/22 16:36:20 | 000,000,000 | —D | C] – C:\Program Files\Windows Installer Clean Up
[2011/08/22 16:36:09 | 000,000,000 | —D | C] – C:\Program Files\MSECACHE
[2011/08/22 16:17:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2011/08/22 15:22:33 | 015,338,952 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\windows-kb890830-v3.22.exe
[2011/08/22 14:23:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2011/08/22 14:23:12 | 000,335,872 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsar.dll
[2011/08/22 14:23:12 | 000,331,776 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrshe.dll
[2011/08/22 14:23:12 | 000,286,720 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsfr.dll
[2011/08/22 14:23:12 | 000,282,624 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsit.dll
[2011/08/22 14:23:12 | 000,282,624 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrses.dll
[2011/08/22 14:23:12 | 000,282,624 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsel.dll
[2011/08/22 14:23:12 | 000,278,528 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsde.dll
[2011/08/22 14:23:12 | 000,274,432 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrspt.dll
[2011/08/22 14:23:12 | 000,274,432 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsnl.dll
[2011/08/22 14:23:12 | 000,274,432 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsesm.dll
[2011/08/22 14:23:12 | 000,270,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsru.dll
[2011/08/22 14:23:12 | 000,270,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsptb.dll
[2011/08/22 14:23:12 | 000,270,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsja.dll
[2011/08/22 14:23:12 | 000,266,240 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsko.dll
[2011/08/22 14:23:12 | 000,262,144 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrshu.dll
[2011/08/22 14:23:12 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrstr.dll
[2011/08/22 14:23:12 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssl.dll
[2011/08/22 14:23:12 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssk.dll
[2011/08/22 14:23:12 | 000,258,048 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrspl.dll
[2011/08/22 14:23:12 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsth.dll
[2011/08/22 14:23:12 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrssv.dll
[2011/08/22 14:23:12 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsno.dll
[2011/08/22 14:23:12 | 000,253,952 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsda.dll
[2011/08/22 14:23:12 | 000,249,856 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrsfi.dll
[2011/08/22 14:23:12 | 000,249,856 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrseng.dll
[2011/08/22 14:23:12 | 000,249,856 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrscs.dll
[2011/08/22 14:23:12 | 000,229,376 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrszhc.dll
[2011/08/22 14:23:12 | 000,126,976 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvrszht.dll
[2011/08/22 14:23:11 | 000,543,336 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\easyupdatusapiu.dll
[2011/08/22 14:21:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/08/22 14:20:17 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Administrator\My Documents\spybotsd162.exe
[2011/08/22 13:48:43 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/08/22 13:48:43 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/08/22 13:48:43 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/08/22 13:32:50 | 000,000,000 | —D | C] – C:\WINDOWS\System32\system
[2011/08/22 13:22:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Recent
[2011/08/22 10:28:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2011/08/22 10:28:39 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/08/22 10:28:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/08/22 10:28:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/08/22 10:28:35 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/08/22 10:28:35 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2002/04/10 20:41:06 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/05 12:37:24 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2011/09/05 12:37:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/05 12:34:14 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/09/05 11:36:44 | 000,013,736 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/09/05 11:36:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/09/02 11:28:23 | 012,429,824 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\073009.cdb
[2011/09/02 09:36:17 | 000,002,828 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/09/02 08:32:27 | 000,002,525 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\FastManager.lnk
[2011/09/02 06:37:01 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/22 17:13:36 | 000,000,960 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to EasyShare.lnk
[2011/08/22 17:11:28 | 000,000,764 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to Card Scan.lnk
[2011/08/22 16:25:51 | 000,435,780 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/08/22 16:24:02 | 000,000,793 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to mbam.lnk
[2011/08/22 16:19:12 | 000,001,743 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/08/22 16:13:17 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/08/22 16:07:49 | 000,000,237 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Windows Update.url
[2011/08/22 15:42:22 | 000,000,115 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\netstat.bat
[2011/08/22 15:22:33 | 015,338,952 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\windows-kb890830-v3.22.exe
[2011/08/22 14:34:28 | 000,436,514 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.old
[2011/08/22 14:29:18 | 000,475,466 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/22 14:29:18 | 000,076,374 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/22 14:23:30 | 000,273,344 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/08/22 14:23:30 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/08/22 14:22:45 | 000,273,344 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/08/22 14:21:37 | 000,000,960 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/08/22 14:21:37 | 000,000,942 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Spybot - Search & Destroy.lnk
[2011/08/22 14:20:17 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Administrator\My Documents\spybotsd162.exe
[2011/08/10 08:38:00 | 000,288,816 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Rebel.pdf
[2011/08/10 08:38:00 | 000,280,306 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Bulldog.pdf
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/08/22 17:13:36 | 000,000,960 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to EasyShare.lnk
[2011/08/22 17:11:28 | 000,000,764 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to Card Scan.lnk
[2011/08/22 16:36:20 | 000,002,343 | —- | C] () – C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Install Clean Up.lnk
[2011/08/22 16:24:02 | 000,000,793 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to mbam.lnk
[2011/08/22 16:19:12 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/08/22 16:19:12 | 000,001,743 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/08/22 15:42:22 | 000,000,115 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\netstat.bat
[2011/08/22 14:21:37 | 000,000,960 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/08/22 14:21:37 | 000,000,942 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Spybot - Search & Destroy.lnk
[2011/08/22 14:13:24 | 000,000,237 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Windows Update.url
[2011/08/10 10:38:29 | 000,288,816 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Rebel.pdf
[2011/08/10 10:38:29 | 000,280,306 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Bulldog.pdf
[2011/05/21 06:01:00 | 002,123,582 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/01/31 16:27:59 | 000,273,344 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/01/31 16:27:58 | 000,273,344 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/01/31 16:27:58 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2009/12/29 16:15:43 | 000,023,452 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\{BE6C4EE5-8015-4479-89B2-EBD1E205A93E}.jpg
[2009/12/11 13:40:12 | 000,016,896 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/30 09:12:02 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/08/20 13:29:54 | 000,101,376 | —- | C] () – C:\WINDOWS\System32\hpgt34.dll
[2009/08/18 12:05:26 | 000,150,228 | —- | C] () – C:\WINDOWS\hpwins05.dat
[2009/08/18 12:04:51 | 000,016,050 | —- | C] () – C:\WINDOWS\hpwscr05.dat
[2009/08/18 12:04:51 | 000,004,785 | —- | C] () – C:\WINDOWS\hpwmdl05.dat
[2009/08/16 16:19:40 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/08/16 16:19:40 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD2140.DAT
[2009/08/14 12:20:08 | 000,274,432 | —- | C] () – C:\WINDOWS\System32\Carcla40.dll
[2009/08/14 08:49:07 | 000,002,828 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/08/07 10:11:51 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2009/08/07 10:08:47 | 000,005,627 | R— | C] () – C:\WINDOWS\System32\Ludap17.ini
[2009/08/07 10:08:47 | 000,000,039 | R— | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2009/08/07 10:01:44 | 000,003,636 | R— | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2009/08/07 10:01:41 | 000,000,962 | R— | C] () – C:\WINDOWS\System32\AsusSetup.ini
[2009/08/07 10:01:41 | 000,000,400 | R— | C] () – C:\WINDOWS\System32\raidmgmt.ini
[2009/08/06 18:57:51 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/08/06 18:57:48 | 000,024,921 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/08/06 18:57:36 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/08/06 18:53:26 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/08/06 18:49:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/08/06 11:44:36 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/08/06 11:43:40 | 000,321,136 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2008/10/07 11:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 11:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 11:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/04/14 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 07:00:00 | 000,475,466 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 07:00:00 | 000,076,374 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2008/02/19 01:33:34 | 000,446,352 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2005/05/03 06:38:42 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\P17.dll
[2003/10/02 05:48:18 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
========== LOP Check ==========
[2011/01/31 13:44:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AMPSoft
[2011/01/31 13:44:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\CardScan
[2011/01/31 13:45:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Skinux
[2011/01/31 14:02:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/01/31 14:02:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CardScan
[2011/01/31 14:02:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Flip Video
[2011/01/31 14:02:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JCWSoftwareLLC
[2011/01/31 14:02:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/10/31 17:46:49 | 000,000,452 | —- | M] () – C:\WINDOWS\Tasks\EasyShare Registration Task.job
[2010/03/31 09:09:02 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
========== Purity Check ==========
< End of report >
Here is the HIJackThis Log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:46:37 PM, on 9/5/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\CardScan\CardScan\CardScanAgent.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [CardScanAgent] "C:\Program Files\CardScan\CardScan\CardScanAgent.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SBAMTray] "C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://sanford.webex.com/client/T27L10NSP1…ort/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) - Unknown owner - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (file missing)
O23 - Service: Google Update Service (gupdate1ca241a9f03aee) (gupdate1ca241a9f03aee) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows CardSpace (idsvc) - Unknown owner - c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VIPRE Antivirus Premium (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: SB Recovery Service (SBPIMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe
–
End of file - 8677 bytes
I tried to run the aswMBR.exe file but when I double clicked on it it would not run.
Thanks,
Ectexas