Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

constant pop up redirection page to: statsyndication.com


  • Please log in to reply

#1
Chypra

Chypra

    New Member

  • Member
  • Pip
  • 1 posts
I believe my problem started when I visited a web site that claimed to have a song that I couldn't find anywhere else. I used my search engine and on the top of the search list was the song and artist and it claimed to be free. I went to the site and have been having computer problems ever since. That same day is when my computer started having multiple pop-ups and commands that I had never had before.

One of the key frustraters is the relentless "statsyndication redirect" which causes me to multi-attempt and find round-about ways to do usually the most simplest of tasks. Things like sending email, browsing websites (even those in my favorites), downloading software, etc.; are exhausting to perform and require multiple tries. I had found that my usual web browser (yahoo) was unable to do a legitimate search so I used aol and that helped for quite a while but not so much now.

I've resorted to doing most web related things on my 3g phone now. It's fair yet limited to work with. It definately isn't as stressful as working on my computer. LoL

I would be super-grateful with any help for my problem. Thank you.

Here is my OTL.Txt from Notepad (and following is the Extras.Txt that also came up in Notepad):
OTL logfile created on: 1/11/2011 2:50:40 PM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Kotoole\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 140.00 Mb Available Physical Memory | 28.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.48 Gb Total Space | 1.31 Gb Free Space | 3.93% Space Free | Partition Type: NTFS

Computer Name: CBMWRK03 | User Name: KOtoole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/11 14:50:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kotoole\Desktop\OTL.com
PRC - [2010/09/16 15:04:06 | 001,164,584 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/09/14 07:52:44 | 000,972,728 | ---- | M] (MusicLab, LLC) -- C:\Program Files\BearShare Applications\MediaBar\Datamngr\datamngrUI.exe
PRC - [2010/09/02 10:38:28 | 000,176,408 | ---- | M] (iWin Inc.) -- C:\Program Files\IWINGA~1\iWinTrusted.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/01/23 01:27:22 | 000,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe


========== Modules (SafeList) ==========

MOD - [2011/01/11 14:50:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kotoole\Desktop\OTL.com
MOD - [2008/01/12 15:50:17 | 000,106,768 | ---- | M] (Microsoft Corporation) -- C:\Program Files\J River\Media Jukebox 12\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state)
SRV - [2010/09/02 10:38:28 | 000,176,408 | ---- | M] (iWin Inc.) [Auto | Running] -- C:\Program Files\IWINGA~1\iWinTrusted.exe -- (iWinTrusted)
SRV - [2008/12/18 10:17:58 | 000,124,208 | ---- | M] (RapidSolution Software AG) [Disabled | Stopped] -- C:\Program Files\RapidSolution\Tunebite\vcdw\VCDAudioService.exe -- (Virtual CDAudio Service)
SRV - [2007/10/25 14:27:54 | 000,266,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc)
SRV - [2005/04/30 17:02:26 | 000,086,016 | ---- | M] (B.H.A Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\bgsvcgen.exe -- (bgsvcgen)
SRV - [2005/04/17 11:31:18 | 001,726,656 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2005/04/17 11:30:42 | 000,124,608 | ---- | M] (symantec) [Disabled | Stopped] -- C:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam)
SRV - [2005/04/17 11:30:32 | 000,019,648 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch)
SRV - [2005/04/08 14:54:52 | 000,161,392 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr)
SRV - [2005/04/08 14:54:50 | 000,083,568 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc)
SRV - [2005/04/08 14:52:32 | 000,185,968 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr)
SRV - [2005/04/05 10:17:22 | 000,206,552 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc)
SRV - [2005/03/30 20:48:22 | 000,992,864 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys -- (SASKUTIL)
DRV - [2008/11/04 10:37:28 | 000,043,552 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2008/11/04 10:37:26 | 000,027,680 | ---- | M] (RapidSolution Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\rsvcdwdr.sys -- (rsvcdwdr)
DRV - [2008/04/14 00:06:40 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/14 00:06:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2007/11/07 04:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF) WinPcap Packet Driver (NPF)
DRV - [2006/08/23 19:39:08 | 000,828,872 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060828.003\NAVEX15.SYS -- (NAVEX15)
DRV - [2006/08/23 19:39:08 | 000,384,360 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2006/08/23 19:39:08 | 000,079,240 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060828.003\NAVENG.SYS -- (NAVENG)
DRV - [2005/04/05 10:17:02 | 000,267,192 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2005/04/05 10:17:00 | 000,017,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2005/04/01 19:36:04 | 000,123,200 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent)
DRV - [2005/03/30 20:48:20 | 000,372,832 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2005/02/04 19:14:32 | 000,053,896 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL)
DRV - [2005/02/04 19:14:30 | 000,324,232 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT)
DRV - [2004/12/06 01:05:00 | 000,100,603 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudfa.sys -- (tfsnudfa)
DRV - [2004/12/06 01:05:00 | 000,098,714 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnudf.sys -- (tfsnudf)
DRV - [2004/12/06 01:05:00 | 000,086,586 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnifs.sys -- (tfsnifs)
DRV - [2004/12/06 01:05:00 | 000,034,843 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsncofs.sys -- (tfsncofs)
DRV - [2004/12/06 01:05:00 | 000,025,883 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnboio.sys -- (tfsnboio)
DRV - [2004/12/06 01:05:00 | 000,015,227 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnopio.sys -- (tfsnopio)
DRV - [2004/12/06 01:05:00 | 000,006,363 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsnpool.sys -- (tfsnpool)
DRV - [2004/12/06 01:05:00 | 000,004,123 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndrct.sys -- (tfsndrct)
DRV - [2004/12/06 01:05:00 | 000,002,239 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\dla\tfsndres.sys -- (tfsndres)
DRV - [2004/12/01 03:22:00 | 000,087,488 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb)
DRV - [2004/11/23 02:56:00 | 000,040,480 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\drvnddm.sys -- (drvnddm)
DRV - [2004/09/17 14:02:54 | 000,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
DRV - [2004/08/03 22:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004/07/14 11:29:04 | 000,005,627 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\sscdbhk5.sys -- (sscdbhk5)
DRV - [2004/07/14 11:28:50 | 000,023,545 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\ssrtln.sys -- (ssrtln)
DRV - [2001/08/17 14:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 14:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 14:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 14:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 14:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 13:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 13:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 13:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 13:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 13:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 13:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 13:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 13:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 13:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 13:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
DRV - [2001/08/17 12:53:32 | 000,003,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\qv2kux.sys -- (QV2KUX)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/
IE - HKCU\..\URLSearchHook: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "BearShare Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo....ch?fr=ffsp1&p="
FF - prefs.js..browser.search.selectedEngine: "BearShare Web Search"
FF - prefs.js..browser.startup.homepage: "http://search.bearshare.com/"
FF - prefs.js..keyword.URL: "http://search.bearsh...tml?src=ffb&q="
FF - prefs.js..browser.search.order.1: "BearShare Web Search"
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/01/23 01:27:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\RapidSolution\Tunebite\plugins\GeckoBased\[email protected]\ [2008/12/28 16:58:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{98e34367-8df7-42b4-837b-20b892ff0848}: C:\PROGRA~1\IWINGA~1\firefox\ [2010/09/07 16:09:11 | 000,000,000 | ---D | M]

[2008/12/27 10:59:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kotoole\Application Data\Mozilla\Firefox\Profiles\jed7765e.default\extensions
[2009/11/25 20:10:53 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Kotoole\Application Data\Mozilla\Firefox\Profiles\jed7765e.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/11/06 10:43:41 | 000,001,490 | ---- | M] () -- C:\Documents and Settings\Kotoole\Application Data\Mozilla\Firefox\Profiles\jed7765e.default\searchplugins\AIM Search.xml
[2009/07/17 18:02:48 | 000,002,476 | ---- | M] () -- C:\Documents and Settings\Kotoole\Application Data\Mozilla\Firefox\Profiles\jed7765e.default\searchplugins\BearShareWebSearch.xml
[2010/01/01 16:13:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2008/07/25 21:38:22 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/01/18 09:28:33 | 000,000,000 | ---D | M] (iMesh MediaBar) -- C:\Program Files\Mozilla Firefox\extensions\{B7D3E479-CC68-42B5-A338-938ECE35F419}
[2010/09/07 16:09:11 | 000,000,000 | ---D | M] (iWinGames Plugin) -- C:\PROGRA~1\IWINGA~1\FIREFOX
[2008/12/28 12:47:29 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2008/12/28 16:58:04 | 000,000,000 | ---D | M] (Tunebite Firefox Surf and Catch Plugin) -- C:\PROGRAM FILES\RAPIDSOLUTION\TUNEBITE\PLUGINS\GECKOBASED\[email protected]
[2008/01/23 01:27:45 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD
[2008/03/24 19:21:00 | 002,889,088 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
[2009/11/06 10:43:41 | 000,001,490 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\AIM Search.xml
[2009/07/17 18:02:48 | 000,002,476 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml

O1 HOSTS File: ([2009/10/26 23:12:09 | 000,000,807 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 89.149.210.105 us.search.yahoo.com
O1 - Hosts: 89.149.210.105 uk.search.yahoo.com
O1 - Hosts: 89.149.210.105 search.yahoo.com
O1 - Hosts: 89.149.210.105 www.google.com.br
O1 - Hosts: 89.149.210.105 www.google.it
O1 - Hosts: 89.149.210.105 www.google.es
O1 - Hosts: 89.149.210.105 www.google.co.jp
O1 - Hosts: 89.149.210.105 www.google.com.mx
O1 - Hosts: 89.149.210.105 www.google.ca
O1 - Hosts: 89.149.210.105 www.google.com.au
O1 - Hosts: 89.149.210.105 www.google.nl
O1 - Hosts: 89.149.210.105 www.google.co.za
O1 - Hosts: 89.149.210.105 www.google.be
O1 - Hosts: 89.149.210.105 www.google.gr
O1 - Hosts: 89.149.210.105 www.google.at
O1 - Hosts: 89.149.210.105 www.google.se
O1 - Hosts: 89.149.210.105 www.google.ch
O1 - Hosts: 89.149.210.105 www.google.pt
O1 - Hosts: 89.149.210.105 www.google.dk
O1 - Hosts: 89.149.210.105 www.google.fi
O1 - Hosts: 89.149.210.105 www.google.ie
O1 - Hosts: 89.149.210.105 www.google.no
O1 - Hosts: 89.149.210.105 www.google.com
O1 - Hosts: 89.149.210.105 www.google.de
O1 - Hosts: 89.149.210.105 www.google.fr
O1 - Hosts: 2 more lines...
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll ()
O2 - BHO: (UrlHelper Class) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\IEBHO.dll (MusicLab, LLC)
O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\IWINGA~1\iWinGamesHookIE.dll (iWin Inc.)
O2 - BHO: (no name) - rsion - No CLSID value found.
O3 - HKLM\..\Toolbar: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll ()
O3 - HKLM\..\Toolbar: (iMesh MediaBar) - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll (iMesh)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (iMesh MediaBar) - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll (iMesh)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\BearShare Applications\MediaBar\Datamngr\datamngrUI.exe (MusicLab, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [gesutikuya] File not found
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [tukekifav] C:\WINDOWS\System32\yenonoje.DLL File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: &AOL Toolbar Search - c:\Program Files\AOL\AOL Toolbar 2.0\resources\en-us\local\search.html ()
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: topitservice.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: topitservice.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: toptogo.net ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: toptopgo.net ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: toptopgo.net ([]https in Trusted sites)
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} http://www.uproar.co...pside_web18.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1292007650861 (WUWebControl Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = CreationsByMarzilli.local
O20 - AppInit_DLLs: (C:\PROGRA~1\BEARSH~4\MediaBar\Datamngr\datamngr.dll C:\PROGRA~1\BEARSH~4\MediaBar\Datamngr\IEBHO.dll) - C:\Program Files\BearShare Applications\MediaBar\Datamngr\datamngr.dll (MusicLab, LLC)
O20 - AppInit_DLLs: (C:\DOCUME~1\Kotoole\LOCALS~1\Temp\1831xxx.dll c:\windows\system32\yenonoje.dll) - C:\DOCUME~1\Kotoole\LOCALS~1\Temp\1831xxx.dll File not found
O20 - AppInit_DLLs: (panosuba.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O22 - SharedTaskScheduler: ThreadingModel - Apartment - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Kotoole\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kotoole\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 17:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/11 14:50:12 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kotoole\Desktop\OTL.com
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/11 14:50:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kotoole\Desktop\OTL.com
[2011/01/11 10:34:21 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/01/11 10:32:24 | 000,000,000 | ---- | M] () -- C:\WINDOWS\win32k.sys
[2011/01/11 10:32:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/11 10:32:14 | 534,827,008 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/03 12:03:15 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/12/22 22:02:40 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Kotoole\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2009/11/05 10:58:52 | 000,076,407 | ---- | C] () -- C:\Documents and Settings\Kotoole\Application Data\Smiley.ico
[2009/10/26 22:41:26 | 000,019,939 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\resocy.pif
[2009/10/26 22:41:26 | 000,019,746 | ---- | C] () -- C:\Documents and Settings\Kotoole\Application Data\obomiru.lib
[2009/10/26 22:41:26 | 000,018,114 | ---- | C] () -- C:\Documents and Settings\Kotoole\Local Settings\Application Data\sopubuq.db
[2009/10/26 22:41:26 | 000,017,991 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\qiqezi.dll
[2009/10/26 22:41:26 | 000,014,848 | ---- | C] () -- C:\Program Files\Common Files\hukijagu._sy
[2009/10/26 22:41:26 | 000,014,159 | ---- | C] () -- C:\Documents and Settings\Kotoole\Local Settings\Application Data\eqeqa.bin
[2009/10/26 22:41:26 | 000,014,064 | ---- | C] () -- C:\Documents and Settings\Kotoole\Application Data\ytefo.dat
[2009/10/26 22:41:26 | 000,014,018 | ---- | C] () -- C:\Documents and Settings\Kotoole\Application Data\iwyhehit.dl
[2009/10/26 22:41:26 | 000,012,908 | ---- | C] () -- C:\Documents and Settings\Kotoole\Application Data\owevysi.vbs
[2009/10/26 22:41:26 | 000,012,674 | ---- | C] () -- C:\Program Files\Common Files\ikizabygeg.bin
[2009/10/26 22:41:26 | 000,012,013 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\owadyhab.pif
[2009/10/26 22:41:26 | 000,011,080 | ---- | C] () -- C:\Documents and Settings\Kotoole\Local Settings\Application Data\ibikubymop.dl
[2009/10/26 22:23:19 | 000,019,709 | ---- | C] () -- C:\Program Files\Common Files\qabuvok.db
[2009/10/26 22:23:19 | 000,019,162 | ---- | C] () -- C:\Documents and Settings\Kotoole\Local Settings\Application Data\icajur.scr
[2009/10/26 22:23:19 | 000,018,848 | ---- | C] () -- C:\Program Files\Common Files\axedaweku.com
[2009/10/26 22:23:19 | 000,018,747 | ---- | C] () -- C:\Documents and Settings\Kotoole\Local Settings\Application Data\syvoma.bin
[2009/10/26 22:23:19 | 000,018,739 | ---- | C] () -- C:\Program Files\Common Files\uzubynyly.inf
[2009/10/26 22:23:19 | 000,014,762 | ---- | C] () -- C:\Documents and Settings\Kotoole\Application Data\atobuvo.ban
[2009/10/26 22:23:19 | 000,014,517 | ---- | C] () -- C:\Program Files\Common Files\ideryloti.dl
[2009/10/26 22:23:19 | 000,014,414 | ---- | C] () -- C:\Documents and Settings\Kotoole\Local Settings\Application Data\ynop.lib
[2009/10/26 22:23:19 | 000,014,108 | ---- | C] () -- C:\Program Files\Common Files\utugurul.bat
[2009/10/26 22:23:19 | 000,013,237 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\axacyx._sy
[2009/10/26 22:23:19 | 000,013,228 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ufifihejef.lib
[2009/10/26 22:23:19 | 000,011,217 | ---- | C] () -- C:\Documents and Settings\Kotoole\Application Data\ufegiqa.dll
[2009/10/26 22:23:19 | 000,010,639 | ---- | C] () -- C:\Documents and Settings\Kotoole\Local Settings\Application Data\udybawuke.bin
[2009/10/26 21:55:43 | 000,018,839 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ewepy._dl
[2009/10/26 21:55:43 | 000,017,564 | ---- | C] () -- C:\Documents and Settings\Kotoole\Application Data\ipaqizozi.db
[2009/10/26 21:55:43 | 000,016,509 | ---- | C] () -- C:\Program Files\Common Files\cogenuli.bin
[2009/10/26 21:55:43 | 000,015,261 | ---- | C] () -- C:\Documents and Settings\Kotoole\Local Settings\Application Data\kitaroqore._sy
[2009/10/26 21:55:43 | 000,014,942 | ---- | C] () -- C:\Documents and Settings\Kotoole\Application Data\akavy.dl
[2009/10/26 21:55:43 | 000,013,289 | ---- | C] () -- C:\WINDOWS\edyxetek.sys
[2009/10/26 21:55:43 | 000,013,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ukerecabon.sys
[2009/10/26 21:55:43 | 000,010,433 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\zidoz.ban
[2009/10/26 21:55:43 | 000,010,277 | ---- | C] () -- C:\Program Files\Common Files\xiloriqub.dll
[2009/10/26 21:40:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\win32k.sys
[2009/07/26 21:46:45 | 000,039,424 | -HS- | C] () -- C:\WINDOWS\System32\kemituba.dll
[2009/01/22 09:07:47 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2009/01/18 14:11:04 | 000,041,327 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/01/11 14:33:35 | 000,000,038 | ---- | C] () -- C:\WINDOWS\System32\net32gdilib.dll
[2008/09/01 13:34:49 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2008/09/01 13:33:26 | 000,000,888 | ---- | C] () -- C:\WINDOWS\disney.ini
[2008/06/23 02:40:32 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\Kotoole\Local Settings\Application Data\fusioncache.dat
[2008/06/18 14:59:56 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/05/22 17:22:18 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/04/03 23:22:18 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/01/27 01:07:18 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2006/02/23 12:14:20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2005/09/08 08:43:44 | 000,016,384 | ---- | C] () -- C:\Documents and Settings\Kotoole\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/07/15 13:34:46 | 000,000,385 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2005/07/15 13:34:44 | 000,001,020 | ---- | C] () -- C:\WINDOWS\hpbvnstp.ini
[2005/07/15 13:34:34 | 000,192,512 | R--- | C] () -- C:\WINDOWS\System32\HPB1320V.DLL
[2005/06/24 00:33:13 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/06/24 00:23:58 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/06/24 00:09:55 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/06/23 23:46:58 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2005/06/23 23:46:36 | 000,000,375 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/04/09 17:04:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/11 17:24:19 | 000,000,831 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/11 17:07:24 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/11 17:00:18 | 000,024,317 | ---- | C] () -- C:\WINDOWS\System32\llbycq.dll
[2004/08/11 17:00:13 | 000,061,952 | ---- | C] () -- C:\WINDOWS\System32\eventlog.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/31 05:17:12 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL

========== LOP Check ==========

[2008/12/27 07:35:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1037B
[2009/01/24 12:27:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\106D
[2009/07/06 10:48:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\128C
[2009/01/09 00:04:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\133E
[2009/04/03 05:45:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\152E3
[2008/12/24 10:36:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\16BB
[2009/07/12 09:01:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\17313
[2009/02/21 12:10:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1A372
[2008/12/28 11:26:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1B24
[2009/07/06 14:29:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1B31F
[2009/02/04 23:42:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1C209
[2009/01/05 23:22:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1C26F
[2009/01/25 19:45:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1E11
[2009/08/04 09:47:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1E55
[2008/12/26 08:15:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\20103
[2009/08/30 07:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\20234
[2009/07/12 08:16:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\222B8
[2009/05/03 05:43:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\23301
[2009/04/14 02:28:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\23337
[2009/06/08 12:14:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\23399
[2009/01/08 23:54:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\23B9
[2009/06/26 13:06:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\261E5
[2009/04/09 07:40:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2A157
[2009/06/12 02:18:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2A158
[2009/04/15 07:42:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2A255
[2009/04/04 09:33:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2A2DF
[2009/08/09 12:49:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2B1F2
[2008/12/25 18:46:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2BA7
[2009/08/03 21:03:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2C2A
[2009/04/03 06:18:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2D1EC
[2008/12/25 07:36:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2F88
[2009/02/16 07:36:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\3023D
[2009/03/11 18:17:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\3119
[2008/12/28 17:19:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\3119C
[2009/01/02 22:33:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\31253
[2009/03/22 06:15:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\3160
[2009/03/12 10:54:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\31F2
[2009/02/20 09:51:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\34196
[2009/07/06 14:58:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\34380
[2009/03/03 10:15:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\359C
[2009/03/07 14:13:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\3720B
[2009/07/12 08:28:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\38252
[2009/04/23 09:10:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\3A2F1
[2009/04/05 04:23:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\3A364
[2009/05/07 18:53:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\3ABB
[2009/07/06 14:26:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\427
[2009/07/12 21:38:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\437A
[2009/01/18 09:29:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\7323
[2009/01/03 10:19:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\81AD
[2009/10/02 17:40:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\8213
[2009/03/15 11:43:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\837C
[2009/02/04 16:50:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\855
[2008/12/28 08:27:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\A10F
[2008/12/25 08:34:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\A202
[2009/05/06 19:44:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\A3D9
[2010/02/10 14:33:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Blue Box Network
[2009/07/06 14:43:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\C226
[2009/07/12 09:00:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\D42
[2009/11/13 06:14:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eGames
[2009/07/04 17:21:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iWin Games
[2005/09/26 10:25:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2010/02/06 11:23:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2008/12/28 16:59:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RapidSolution
[2010/02/06 11:30:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/11/16 18:56:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/02/16 10:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2006/10/20 19:29:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\Aim
[2010/10/06 17:42:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\bearsharemediabartb
[2010/10/06 19:05:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\BitComet
[2009/11/13 06:12:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\eGames
[2007/02/17 16:18:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\FUJIFILM
[2010/02/06 11:28:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\iWin
[2008/06/12 22:24:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\iWinArcade
[2009/01/11 14:29:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\J River
[2005/09/23 08:09:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\Leadertech
[2009/04/02 11:17:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\MP3Rocket
[2005/10/01 14:35:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\MSNInstaller
[2010/02/06 11:23:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\PlayFirst
[2010/02/06 11:26:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\Pogo Games
[2007/06/07 13:45:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kotoole\Application Data\Viewpoint
[2009/07/26 09:50:39 | 000,000,426 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{9C57934C-9C89-4D52-9547-AE0E0B15620C}.job
[2009/07/26 09:57:53 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:77413142
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E3E01C22
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9CAC5FE6
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:67F0F865
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4F31D675
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >



Extras.Txt:

OTL Extras logfile created on: 1/11/2011 2:50:40 PM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Kotoole\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 140.00 Mb Available Physical Memory | 28.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.48 Gb Total Space | 1.31 Gb Free Space | 3.93% Space Free | Partition Type: NTFS

Computer Name: CBMWRK03 | User Name: KOtoole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] -- "C:\Program Files\FinePixViewer\FinePixViewer.exe" "%1" (FUJI PHOTO FILM CO.,LTD.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableSR" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 4

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
"135:TCP:*:Enabled:Offer Remote Assistance - Port" = 135:TCP:*:Enabled:Offer Remote Assistance - Port

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
"Enabled" = 1
"RemoteAddresses" = LocalSubnet

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
"Enabled" = 1
"RemoteAddresses" = *

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\AuthorizedApplications]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\GloballyOpenPorts]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger -- (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1129042353\ee\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1129042353\ee\AOLServiceHost.exe:*:Enabled:AOL Services -- File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- File not found
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- File not found
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) -- File not found
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe" = C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare -- File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger -- (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1129042353\ee\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1129042353\ee\AOLServiceHost.exe:*:Enabled:AOL Services -- File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- File not found
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server -- File not found
"C:\Program Files\Adobe Media Player\Adobe Media Player.exe" = C:\Program Files\Adobe Media Player\Adobe Media Player.exe:*:Enabled:Adobe Media Player -- ()
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- File not found
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) -- File not found
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh -- File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\iWin Games\iWinGames.exe" = C:\Program Files\iWin Games\iWinGames.exe:*:Enabled:iWin Games application. -- File not found
"C:\Program Files\iWin Games\WebUpdater.exe" = C:\Program Files\iWin Games\WebUpdater.exe:*:Enabled:iWin Games updater. -- File not found
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe" = C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare -- File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{98B6FB8A-8638-4037-AD44-CF7D0EEAB874}_is1" = TypingMaster TypingTest
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC}" = PixiePack Codec Pack
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}" = iTunes
"{FDC0EF71-939A-4D28-ACBC-C6364B5FCB1D}" = Tunebite
"Active Security" = Active Security
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"BearShare MediaBar" = MediaBar
"DivX Setup.divx.com" = DivX Setup
"iMesh MediaBar" = MediaBar 2.0
"iWinArcade" = iWin Games (remove only)
"Jewel Quest Online Party" = Jewel Quest Online Party (remove only)
"Media Jukebox 12" = Media Jukebox 12
"MP3 Rocket" = MP3 Rocket
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/3/2011 11:54:22 AM | Computer Name = CBMWRK03 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 1/3/2011 11:54:23 AM | Computer Name = CBMWRK03 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 1/3/2011 11:57:58 AM | Computer Name = CBMWRK03 | Source = Userenv | ID = 1521
Description = Windows cannot locate the server copy of your roaming profile and
is attempting to log you on with your local profile. Changes to the profile will
not be copied to the server when you logoff. Possible causes of this error include
network problems or insufficient security rights. If this problem persists, contact
your network administrator. DETAIL - The network path was not found.

Error - 1/3/2011 11:58:01 AM | Computer Name = CBMWRK03 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 1/11/2011 11:32:43 AM | Computer Name = CBMWRK03 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 1/11/2011 11:32:43 AM | Computer Name = CBMWRK03 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 1/11/2011 11:34:00 AM | Computer Name = CBMWRK03 | Source = Userenv | ID = 1521
Description = Windows cannot locate the server copy of your roaming profile and
is attempting to log you on with your local profile. Changes to the profile will
not be copied to the server when you logoff. Possible causes of this error include
network problems or insufficient security rights. If this problem persists, contact
your network administrator. DETAIL - The network path was not found.

Error - 1/11/2011 11:34:04 AM | Computer Name = CBMWRK03 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 1/11/2011 12:07:14 PM | Computer Name = CBMWRK03 | Source = Application Hang | ID = 1002
Description = Hanging application iWinGames.exe, version 2.86.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/11/2011 12:12:24 PM | Computer Name = CBMWRK03 | Source = Application Hang | ID = 1001
Description = Fault bucket 2011665127.

[ System Events ]
Error - 1/11/2011 11:34:40 AM | Computer Name = CBMWRK03 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/11/2011 11:34:40 AM | Computer Name = CBMWRK03 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/11/2011 11:34:46 AM | Computer Name = CBMWRK03 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/11/2011 11:36:31 AM | Computer Name = CBMWRK03 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/11/2011 11:36:31 AM | Computer Name = CBMWRK03 | Source = rsvcdwdr | ID = 262153
Description = The device, \Device\Scsi\rsvcdwdr1, did not respond within the timeout
period.

Error - 1/11/2011 11:45:05 AM | Computer Name = CBMWRK03 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/11/2011 11:45:05 AM | Computer Name = CBMWRK03 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/11/2011 11:45:05 AM | Computer Name = CBMWRK03 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/11/2011 11:45:05 AM | Computer Name = CBMWRK03 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 1/11/2011 1:04:47 PM | Computer Name = CBMWRK03 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}


< End of report >
  • 0

Advertisements


#2
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix.. Please visit HERE if you don't know how.. Please re-enable them back after performing all steps given..

Please download ComboFix by sUBs from HERE or HERE and save it to your Desktop.

During the download, rename Combofix to Combo-Fix as follows:

Posted Image

Posted Image


It is important you rename Combofix during the download, but not after.

**NOTE: If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


After that, double-click and run Combo-Fix. Let it finish its job and post the log here

If ComboFix asked you to install Recovery Console, please do so.. It will be your best interest..

Note: DON'T do anything with your computer while ComboFix is running.. Let ComboFix finishes its job..
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP