Thanks for response and offer to help. Your requests follow:
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-05-29 17:27:58
—————————–
17:27:58.078 OS Version: Windows 5.1.2600 Service Pack 3
17:27:58.078 Number of processors: 2 586 0x1706
17:27:58.078 ComputerName: OWNER-59AC86FE7 UserName: Administrator
17:27:59.031 Initialize success
17:30:03.890 AVAST engine defs: 13052901
17:30:27.281 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-12
17:30:27.281 Disk 0 Vendor: WDC_WD5000AADS-00M2B0 01.00A01 Size: 476938MB BusType: 3
17:30:27.281 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-1f
17:30:27.281 Disk 1 Vendor: WDC_WD2500JS-00NCB1 10.02E01 Size: 238474MB BusType: 3
17:30:27.390 Disk 1 MBR read successfully
17:30:27.390 Disk 1 MBR scan
17:30:27.421 Disk 1 Windows XP default MBR code
17:30:27.421 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 238472 MB offset 63
17:30:27.437 Disk 1 scanning sectors +488392065
17:30:27.484 Disk 1 scanning C:\WINDOWS\system32\drivers
17:30:33.500 Service scanning
17:30:46.187 Modules scanning
17:30:50.015 Disk 1 trace - called modules:
17:30:50.015 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
17:30:50.031 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8a869030]
17:30:50.031 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> \Device\0000006c[0x8a8961e0]
17:30:50.031 5 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-1f[0x8a7dad98]
17:30:50.968 AVAST engine scan C:\WINDOWS
17:31:03.765 AVAST engine scan C:\WINDOWS\system32
17:32:37.875 AVAST engine scan C:\WINDOWS\system32\drivers
17:32:46.203 AVAST engine scan C:\Documents and Settings\Administrator
19:18:28.890 AVAST engine scan C:\Documents and Settings\All Users
19:19:56.265 Scan finished successfully
19:20:55.359 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\MBR.dat"
19:20:55.359 The log file has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\aswMBR.txt"
OTL logfile created on: 5/29/2013 7:26:31 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 2.42 Gb Available Physical Memory | 69.14% Memory free
6.84 Gb Paging File | 5.97 Gb Available in Paging File | 87.39% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 114.49 Gb Free Space | 49.16% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 268.71 Gb Free Space | 57.69% Space Free | Partition Type: NTFS
Computer Name: OWNER-59AC86FE7 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Ahead\InCD\InCD.exe (Ahead Software AG)
PRC - C:\Program Files\Ahead\InCD\incdsrv.exe (AHEAD Software)
========== Modules (No Company Name) ==========
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_63022737\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_a9db4250\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_6a7af65d\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_ea1855d9\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7eddb414\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqcprsc.resources.dll ()
MOD - c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll ()
MOD - c:\windows\assembly\gac\lead.wrapper\13.0.0.66__9cf889f53ea9b907\lead.wrapper.dll ()
MOD - c:\windows\assembly\gac\lead.drawing\13.0.0.66__9cf889f53ea9b907\lead.drawing.dll ()
MOD - c:\windows\assembly\gac\lead\13.0.0.66__9cf889f53ea9b907\lead.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms\13.0.0.66__9cf889f53ea9b907\lead.windows.forms.dll ()
MOD - c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll ()
MOD - c:\windows\assembly\gac\hpqtray.resources\3.0.0.0_en_a53cf5803f4c3827\hpqtray.resources.dll ()
MOD - c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll ()
MOD - c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll ()
MOD - c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll ()
MOD - c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll ()
MOD - c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll ()
MOD - c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqfmrsc.resources.dll ()
MOD - c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll ()
MOD - c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll ()
MOD - c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll ()
MOD - c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll ()
MOD - c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll ()
MOD - c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll ()
MOD - c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Common Files\Acronis\Common\gc.dll ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (InCDsrv) – C:\Program Files\Ahead\InCD\incdsrv.exe (AHEAD Software)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mrtRate) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (aswMBR) – C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\WINDOWS\system32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (timounter) – C:\WINDOWS\system32\drivers\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\drivers\snapman.sys (Acronis)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\incdpass.sys (Ahead Software)
DRV - (InCDrec) – C:\WINDOWS\System32\drivers\incdrec.sys (Ahead Software AG)
DRV - (InCDfs) – C:\WINDOWS\System32\drivers\incdfs.sys (Ahead Software)
DRV - (USB-100) – C:\WINDOWS\system32\drivers\RTL8150.SYS (Realtek )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.wyff4.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{67BD5838-CB1E-4393-A46F-2CED7C53F8E9}: "URL" =
http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searcerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.wyff4.com/"
FF - prefs.js..extensions.enabledAddons: addon%40defaulttab.com:2.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2013/01/11 19:09:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2013/05/24 00:39:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions
[2013/05/24 00:39:20 | 000,000,000 | —D | M] (DownloadTerms) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions\[removed]
[2013/05/24 00:39:30 | 000,029,621 | —- | M] () (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\extensions\[removed]
[2013/05/29 17:19:52 | 000,001,997 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\se9y2xik.default\searchplugins\search.xml
[2013/05/25 01:51:54 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/05/25 01:51:54 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2008/04/14 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Ahead Software AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKCU..\Run: [ROC_ROC_APR2013_AV] C:\Documents and Settings\Administrator\Application Data\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe /PROMPT –mid bd60c22bbefe5042c4884c1e19ef3768-259577303c4ffd1a0dd2239fbf839e4a4285025a –CMPID ROC_APR2013_AV –CMPIDEXTRA 2013 File not found
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_11_5_502_146_Plugin.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk = C:\Program Files\Quicken\billmind.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE (Intuit)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://windowsupdate.microsoft.com/windows…b?1357777321906 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DBFBB6A8-DCB4-4E08-8E64-F7E27F8D3437}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/01/09 19:32:11 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/11/30 14:58:29 | 000,000,000 | —- | M] () - F:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/05/29 17:22:47 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2013/05/29 17:20:48 | 004,745,728 | —- | C] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2013/05/25 01:51:45 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/05/25 01:32:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2013/05/24 00:45:44 | 000,000,000 | —D | C] – C:\Program Files\Uninstaller
[2013/05/24 00:44:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\player
[2013/05/24 00:41:14 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2013/05/24 00:39:37 | 000,000,000 | —D | C] – C:\Program Files\DefaultTab
[2013/05/24 00:39:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\DefaultTab
[2013/05/24 00:39:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\DownloadTerms
[2013/05/13 13:31:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\MORGAN $6K JULY'13 PROMISSORY NOTE
[2013/05/13 12:57:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Parsons Technology
[2013/05/13 12:40:41 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Parsons
[2013/05/13 12:40:38 | 000,146,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MFCOLEUI.DLL
[2013/05/13 12:40:37 | 000,010,736 | —- | C] (Blue Sky Software Corp.) – C:\WINDOWS\System32\RHMMPLAY.DLL
[2013/05/13 12:40:30 | 000,000,000 | —D | C] – C:\Program Files\Parsons Technology
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/05/29 19:22:12 | 000,000,499 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\MBR.zip
[2013/05/29 19:20:55 | 000,000,512 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\MBR.dat
[2013/05/29 19:17:53 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BF0383E8-AAC2-4B96-BC72-182AF1754472}.job
[2013/05/29 17:22:48 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2013/05/29 17:22:16 | 004,745,728 | —- | M] (AVAST Software) – C:\Documents and Settings\Administrator\Desktop\aswMBR.exe
[2013/05/29 17:19:53 | 000,003,182 | —- | M] () – C:\WINDOWS\System32\nvAppTimestamps
[2013/05/28 20:55:10 | 000,001,178 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2013/05/25 01:32:17 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2013/05/25 01:24:42 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/05/25 01:24:02 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/05/24 14:52:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/05/24 11:12:53 | 000,045,386 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\3G13Na3Hd5I85G55F3d5n0ca9cedf2791186b.jpg
[2013/05/24 00:44:37 | 000,464,474 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/05/24 00:44:37 | 000,079,302 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/05/22 18:04:22 | 000,204,680 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\LATE HAGERTY 21999939-1.PDF
[2013/05/15 03:18:55 | 000,263,024 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/05/15 03:02:24 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/05/14 15:15:21 | 000,000,233 | —- | M] () – C:\WINDOWS\qwimp.ini
[2013/05/13 12:57:51 | 000,000,884 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Quicken Family Lawyer Deluxe.lnk
[2013/05/13 12:57:51 | 000,000,177 | —- | M] () – C:\WINDOWS\PARSONS.INI
[2013/05/10 09:38:33 | 000,000,572 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\spider.sav
[2013/05/07 00:27:31 | 006,015,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/05/29 19:22:12 | 000,000,499 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\MBR.zip
[2013/05/29 19:20:55 | 000,000,512 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\MBR.dat
[2013/05/24 11:12:53 | 000,045,386 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\3G13Na3Hd5I85G55F3d5n0ca9cedf2791186b.jpg
[2013/05/22 18:04:22 | 000,204,680 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\LATE HAGERTY 21999939-1.PDF
[2013/05/13 12:57:51 | 000,000,884 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Quicken Family Lawyer Deluxe.lnk
[2013/05/13 12:57:51 | 000,000,177 | —- | C] () – C:\WINDOWS\PARSONS.INI
[2013/02/28 15:26:39 | 000,003,584 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/02 16:49:25 | 000,000,048 | —- | C] () – C:\WINDOWS\PickList.ini
[2013/02/02 16:49:25 | 000,000,000 | —- | C] () – C:\WINDOWS\od5.ini
[2013/01/23 17:38:37 | 000,000,000 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2013/01/14 10:45:23 | 000,104,549 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2013/01/14 10:45:23 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2013/01/14 10:42:39 | 000,104,156 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2013/01/14 10:42:39 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2013/01/11 18:53:20 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2013/01/11 18:34:57 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2013/01/11 18:09:46 | 000,000,233 | —- | C] () – C:\WINDOWS\qwimp.ini
[2013/01/11 18:07:29 | 000,001,178 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2013/01/11 18:07:29 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2013/01/09 20:36:39 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2013/01/09 20:03:04 | 001,079,188 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2013/01/09 20:03:04 | 001,079,188 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2013/01/09 20:03:04 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2013/01/09 20:02:53 | 002,287,232 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2013/01/09 19:55:00 | 000,025,548 | —- | C] () – C:\WINDOWS\System32\drivers\RTAIODAT.DAT
[2013/01/09 19:33:59 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2013/01/09 19:29:14 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2013/01/09 14:19:56 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2013/01/09 14:18:28 | 000,263,024 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
========== ZeroAccess Check ==========
[2013/01/11 18:24:45 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/14 08:00:00 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 08:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/01/23 19:45:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Acronis
[2013/03/14 06:49:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AVG2013
[2013/05/24 00:39:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\DefaultTab
[2013/05/25 01:20:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\player
[2013/03/14 06:48:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\TuneUp Software
[2013/01/14 03:51:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2013/03/14 06:48:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2013
[2013/03/14 06:37:14 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2013/05/29 00:35:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2013/05/29 16:48:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 08:00:00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
< MD5 for: SVCHOST.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008/04/14 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/14 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/04/14 08:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 08:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 08:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 08:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /rp /s >
< %systemdrive%\$Recycle.Bin|@;true;true;true >
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
========== Base Services ==========
SRV - [2008/04/14 08:00:00 | 000,044,544 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\alg.exe – (ALG)
SRV - [2008/04/14 08:00:00 | 000,006,656 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wuauserv.dll – (wuauserv)
SRV - [2008/04/14 08:00:00 | 000,409,088 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\qmgr.dll – (BITS)
SRV - [2012/07/06 09:58:51 | 000,078,336 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\WINDOWS\system32\browser.dll – (Browser)
SRV - [2008/04/14 08:00:00 | 000,062,464 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\cryptsvc.dll – (CryptSvc)
SRV - [2008/04/14 08:00:00 | 000,126,976 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dhcpcsvc.dll – (Dhcp)
SRV - [2009/04/20 13:17:26 | 000,045,568 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dnsrslvr.dll – (Dnscache)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (Eventlog)
SRV - [2008/04/14 08:00:00 | 000,033,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\eapsvc.dll – (EapHost)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\shsvcs.dll – (FastUserSwitchingCompatibility)
SRV - [2008/04/14 08:00:00 | 000,015,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\w3ssl.dll – (HTTPFilter)
SRV - [2008/04/14 06:41:56 | 000,021,504 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\hidserv.dll – (HidServ)
SRV - [2008/04/14 08:00:00 | 000,150,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\imapi.exe – (ImapiService)
SRV - [2008/04/14 08:00:00 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (PolicyAgent)
SRV - [2008/04/14 08:00:00 | 000,023,552 | —- | M] (Microsoft Corp.) [Auto | Running] – C:\WINDOWS\system32\dmserver.dll – (dmserver)
SRV - [2008/04/14 08:00:00 | 000,224,768 | —- | M] (Microsoft Corp., Veritas Software) [On_Demand | Stopped] – C:\WINDOWS\System32\dmadmin.exe – (dmadmin)
SRV - [2008/04/14 08:00:00 | 000,005,120 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\dllhost.exe – (SwPrv)
SRV - [2008/04/14 08:00:00 | 000,013,312 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\lsass.exe – (Netlogon)
SRV - [2008/04/14 08:00:00 | 000,198,144 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\netman.dll – (Netman)
SRV - [2008/06/20 12:02:47 | 000,245,248 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\mswsock.dll – (Nla)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (PlugPlay)
SRV - [2010/08/17 09:17:06 | 000,058,880 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\spoolsv.exe – (Spooler)
SRV - [2008/04/14 08:00:00 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (ProtectedStorage)
SRV - [2008/04/14 08:00:00 | 000,088,576 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\rasauto.dll – (RasAuto)
SRV - [2008/04/14 08:00:00 | 000,186,368 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\rasmans.dll – (RasMan)
SRV - [2009/02/09 08:10:48 | 000,401,408 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\rpcss.dll – (RpcSs)
SRV - [2008/04/14 08:00:00 | 000,435,200 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\ntmssvc.dll – (NtmsSvc)
SRV - [2008/04/14 08:00:00 | 000,018,944 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\seclogon.dll – (seclogon)
SRV - [2008/04/14 08:00:00 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (SamSs)
SRV - [2008/04/14 08:00:00 | 000,080,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wscsvc.dll – (wscsvc)
SRV - [2010/08/27 01:57:43 | 000,099,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srvsvc.dll – (LanmanServer)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (ShellHWDetection)
SRV - [2008/04/14 08:00:00 | 000,171,008 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srsvc.dll – (srservice)
SRV - [2008/04/14 08:00:00 | 000,192,512 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\schedsvc.dll – (Schedule)
SRV - [2008/04/14 08:00:00 | 000,013,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lmhsvc.dll – (LmHosts)
SRV - [2008/04/14 08:00:00 | 000,249,856 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\tapisrv.dll – (TapiSrv)
SRV - [2008/04/14 08:00:00 | 000,295,424 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\termsrv.dll – (TermService)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (Themes)
SRV - [2008/04/14 08:00:00 | 000,289,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\vssvc.exe – (VSS)
SRV - [2008/04/14 08:00:00 | 000,042,496 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\audiosrv.dll – (AudioSrv)
SRV - [2008/04/14 08:00:00 | 000,331,264 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\ipnathlp.dll – (SharedAccess)
SRV - [2008/04/14 08:00:00 | 000,333,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wiaservc.dll – (stisvc)
SRV - [2008/04/14 08:00:00 | 000,078,848 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\msiexec.exe – (MSIServer)
SRV - [2008/04/14 08:00:00 | 000,144,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wbem\wmisvc.dll – (winmgmt)
SRV - [2009/02/09 08:10:48 | 000,617,472 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\advapi32.dll – (Wmi)
SRV - [2008/04/14 08:00:00 | 000,132,096 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\dot3svc.dll – (Dot3svc)
SRV - [2008/04/14 08:00:00 | 000,483,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wzcsvc.dll – (WZCSVC)
SRV - [2009/06/10 02:14:49 | 000,132,096 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wkssvc.dll – (lanmanworkstation)
========== Drive Information ==========
Physical Drives
—————
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: WDC WD5000AADS-00M2B0
Partitions: 1
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE1 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: WDC WD2500JS-00NCB1
Partitions: 1
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: HP psc 2410 USB Device
Partitions: 0
Status: OK
Status Info: 0
Partitions
—————
DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 32256
Hidden sectors: 0
DeviceID: Disk #1, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 233.00GB
Starting Offset: 32256
Hidden sectors: 0
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Administrator\My Documents\ADDYS VIA 500GB HD ON 1-12-2013.WAB:SummaryInformation
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31780AFE
< End of report >
OTL Extras logfile created on: 5/29/2013 7:26:31 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 2.42 Gb Available Physical Memory | 69.14% Memory free
6.84 Gb Paging File | 5.97 Gb Available in Paging File | 87.39% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 114.49 Gb Free Space | 49.16% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 268.71 Gb Free Space | 57.69% Space Free | Partition Type: NTFS
Computer Name: OWNER-59AC86FE7 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe – (NVIDIA Corporation)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\AVG\AVG2013\avgmfapx.exe" = C:\Program Files\AVG\AVG2013\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgnsx.exe" = C:\Program Files\AVG\AVG2013\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgdiagex.exe" = C:\Program Files\AVG\AVG2013\avgdiagex.exe:*:Enabled:AVG Diagnostics 2013 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgemcx.exe" = C:\Program Files\AVG\AVG2013\avgemcx.exe:*:Enabled:Personal Email Scanner – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{193DD0DC-004A-4545-A301-E4A7335C8E41}" = 2400
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{2405665A-16C9-4D3A-B70E-F006220E1472}" = Overland
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2D974D26-BA8F-4A0B-B7EE-3F563AF79746}" = Quicken 2003 Deluxe
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}" = Acronis True Image Home
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{597D73A8-5FDB-4bc1-9893-40B54459F1BC}" = ProductContext
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72E67064-A144-42A6-BC85-12276B2D5D42}" = 2400_2500Help
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8B957F8D-FBDE-4DB4-99E7-192487575050}" = 23_24_2500Tour
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9AD84892-7664-479C-8F95-7A25B964B04D}" = 2400_2500trb
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 314.07
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 314.07
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 136.53
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.1031
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.12.12
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3A1BF34-A336-450D-BC3E-3A854AD270A0}" = AVG 2013
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{DEE76D44-8D7C-4A32-8FAE-A813817631FC}" = AVG 2013
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AtomTime Pro_is1" = AtomTime Pro 3.1d
"AVG" = AVG 2013
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HP Photo & Imaging" = HP Image Zone 4.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InCD!UninstallKey" = InCD
"InstallShield_{2D974D26-BA8F-4A0B-B7EE-3F563AF79746}" = Quicken 2003 Deluxe
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 20.0.1 (x86 en-US)" = Mozilla Firefox 20.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa 3" = Picasa 3
"Quicken Family Lawyer Deluxe" = Family Lawyer Deluxe 8.0
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/16/2013 1:30:21 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/16/2013 1:30:22 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/16/2013 1:30:23 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/16/2013 1:30:24 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/16/2013 1:30:25 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/16/2013 1:30:26 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 3/16/2013 1:30:28 AM | Computer Name = OWNER-59AC86FE7 | Source = ESENT | ID = 490
Description = svchost (1244) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).
Error - 4/29/2013 8:41:32 PM | Computer Name = OWNER-59AC86FE7 | Source = Application Error | ID = 1000
Description = Faulting application msimn.exe, version 6.0.2900.5512, faulting module
unknown, version 0.0.0.0, fault address 0x007b3265.
Error - 5/13/2013 12:44:31 PM | Computer Name = OWNER-59AC86FE7 | Source = Application Hang | ID = 1002
Description = Hanging application ntvdm.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/13/2013 12:47:37 PM | Computer Name = OWNER-59AC86FE7 | Source = Application Hang | ID = 1002
Description = Hanging application ntvdm.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 5/10/2013 6:57:54 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7038
Description = The nvUpdatusService service was unable to log on as .\UpdatusUser
with the currently configured password due to the following error: %%1330 To ensure
that the service is configured properly, use the Services snap-in in Microsoft Management
Console
(MMC).
Error - 5/10/2013 6:57:54 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Update Service Daemon service failed to start due to the
following error: %%1069
Error - 5/10/2013 6:58:04 AM | Computer Name = OWNER-59AC86FE7 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.
Error - 5/15/2013 3:19:09 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2
Error - 5/15/2013 3:19:09 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7038
Description = The nvUpdatusService service was unable to log on as .\UpdatusUser
with the currently configured password due to the following error: %%1330 To ensure
that the service is configured properly, use the Services snap-in in Microsoft Management
Console
(MMC).
Error - 5/15/2013 3:19:09 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Update Service Daemon service failed to start due to the
following error: %%1069
Error - 5/21/2013 6:45:00 AM | Computer Name = OWNER-59AC86FE7 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.
Error - 5/21/2013 6:45:05 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2
Error - 5/21/2013 6:45:05 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7038
Description = The nvUpdatusService service was unable to log on as .\UpdatusUser
with the currently configured password due to the following error: %%1330 To ensure
that the service is configured properly, use the Services snap-in in Microsoft Management
Console
(MMC).
Error - 5/21/2013 6:45:05 AM | Computer Name = OWNER-59AC86FE7 | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Update Service Daemon service failed to start due to the
following error: %%1069
< End of report >