OTL logfile created on: 4/28/2014 3:36:25 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE (Version = .) - Type = Internet Explorer (Version = 7.0.5730.13) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 89.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 97.00% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 149.04 Gb Total Space | 86.98 Gb Free Space | 58.36% Space Free | Partition Type: NTFS Drive X: | 284.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled] -- -- (HidServ) SRV - [2014/03/20 03:58:07 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2014/03/12 10:13:08 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014/02/14 17:09:53 | 000,182,696 | ---- | M] (Oracle Corporation) [Auto] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2013/02/14 07:43:42 | 000,183,944 | ---- | M] (ESET) [On_Demand] -- C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe -- (ESHASRV) SRV - [2013/02/14 07:43:30 | 000,033,136 | ---- | M] (ESET) [On_Demand] -- C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe -- (EhttpSrv) SRV - [2013/02/14 07:42:46 | 001,020,304 | ---- | M] (ESET) [Auto] -- C:\Program Files\ESET\ESET Endpoint Antivirus\ekrn.exe -- (ekrn) SRV - [2010/04/13 12:29:54 | 000,455,168 | ---- | M] (Rimage Corp) [Auto] -- C:\Program Files\Rimage\Imaging Server\eis.exe -- (Rimage_eIS) SRV - [2010/04/01 07:17:52 | 004,211,200 | ---- | M] (Rimage Corporation) [Auto] -- C:\Program Files\Rimage\Production Server\eps.exe -- (Rimage_ePS) SRV - [2009/04/07 10:18:50 | 000,123,904 | ---- | M] (Rimage Corp) [Auto] -- C:\Program Files\Rimage\ers\ers.exe -- (Rimage_eRS) SRV - [2009/04/07 09:16:30 | 000,549,376 | ---- | M] () [Auto] -- C:\Program Files\Rimage\DiscoveryServer\RmDiscoverSrv.exe -- (Rimage_DS) SRV - [2009/04/07 09:11:18 | 000,006,144 | ---- | M] () [Auto] -- C:\Program Files\Rimage\Messaging\RmsSrv.exe -- (Rimage_eMS) SRV - [2009/03/25 06:00:00 | 000,237,625 | ---- | M] (AE) [Disabled] -- C:\AERimage\rimage.exe -- (AERimageCDR) SRV - [2009/03/25 06:00:00 | 000,237,625 | ---- | M] (AE) [Disabled] -- C:\AERimage\rimage.exe -- (AERimage) SRV - [2008/10/15 11:13:58 | 000,439,632 | ---- | M] (RealVNC Ltd.) [Auto] -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe -- (WinVNC4) SRV - [2007/08/07 04:59:50 | 000,540,184 | ---- | M] (PDF Complete Inc) [Auto] -- C:\Program Files\PDF Complete\pdfsvc.exe -- (pdfcDispatcher) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand] -- -- (WDICA) DRV - File not found [Kernel | On_Demand] -- -- (slabser) DRV - File not found [Kernel | On_Demand] -- -- (slabbus) CP210x USB Composite Device driver (WDM) DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP) DRV - File not found [Kernel | System] -- -- (PCIDump) DRV - File not found [Kernel | System] -- -- (lbrtfdc) DRV - File not found [Kernel | System] -- -- (i2omgmt) DRV - File not found [Kernel | System] -- -- (Changer) DRV - [2013/11/26 06:34:35 | 000,025,200 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ggsemc.sys -- (ggsemc) DRV - [2013/11/26 06:34:35 | 000,012,400 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ggflt.sys -- (ggflt) DRV - [2013/02/04 09:48:58 | 000,124,848 | ---- | M] (ESET) [Kernel | System] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv) DRV - [2013/02/04 09:48:58 | 000,107,856 | ---- | M] (ESET) [Kernel | System] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir) DRV - [2013/02/04 09:48:56 | 000,164,488 | ---- | M] (ESET) [File_System | System] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon) DRV - [2009/07/13 11:51:12 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\winusb.sys -- (WinUSB) DRV - [2008/07/15 12:09:16 | 000,060,544 | ---- | M] (Silicon Laboratories) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\silabser.sys -- (silabser) DRV - [2008/07/15 12:09:16 | 000,017,920 | ---- | M] (Silicon Laboratories, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\silabenm.sys -- (silabenm) DRV - [2008/05/02 04:58:28 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2008/05/02 04:58:14 | 000,020,864 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2008/05/02 04:58:12 | 000,017,536 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2007/11/06 13:23:56 | 004,622,848 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2007/08/07 12:40:38 | 000,098,944 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2004/08/03 20:29:50 | 000,019,455 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wVchNTxx.sys -- (iAimFP4) DRV - [2004/08/03 20:29:48 | 000,012,063 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wSiINTxx.sys -- (iAimFP3) DRV - [2004/08/03 20:29:46 | 000,025,471 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV10nt.sys -- (iAimTV5) DRV - [2004/08/03 20:29:46 | 000,023,615 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys -- (iAimTV4) DRV - [2004/08/03 20:29:46 | 000,022,271 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV06nt.sys -- (iAimTV6) DRV - [2004/08/03 20:29:44 | 000,033,599 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV04nt.sys -- (iAimTV3) DRV - [2004/08/03 20:29:44 | 000,019,551 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV02NT.sys -- (iAimTV1) DRV - [2004/08/03 20:29:42 | 000,029,311 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV01nt.sys -- (iAimTV0) DRV - [2004/08/03 20:29:42 | 000,011,871 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV09NT.sys -- (iAimFP7) DRV - [2004/08/03 20:29:40 | 000,011,807 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV07nt.sys -- (iAimFP5) DRV - [2004/08/03 20:29:40 | 000,011,295 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV08NT.sys -- (iAimFP6) DRV - [2004/08/03 20:29:38 | 000,161,020 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x) DRV - [2004/08/03 20:29:38 | 000,012,415 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV01nt.sys -- (iAimFP0) DRV - [2004/08/03 20:29:38 | 000,012,127 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV02NT.sys -- (iAimFP1) DRV - [2004/08/03 20:29:38 | 000,011,775 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV05NT.sys -- (iAimFP2) DRV - [2002/04/04 01:32:06 | 000,028,416 | R--- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\DRIVERS\symmpi.sys -- (Symmpi) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 28.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 28.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014/03/20 03:57:57 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird [2013/05/17 04:15:31 | 000,000,000 | ---D | M] [2014/03/20 03:57:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions [2014/03/20 03:58:08 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} O1 HOSTS File: ([2006/03/02 03:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe (ESET) O4 - HKLM..\Run: [Rimage License Manager] File not found O4 - HKLM..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe (Hewlett-Packard Company) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1224668008953 (WUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.51.2) O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab (Java Plug-in 1.5.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.51.2) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O20 - HKLM Winlogon: Shell - ( ) - (Registry key not found) O20 - HKLM Winlogon: UserInit - ( ) - (Registry key not found) O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 0 O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014/04/28 10:06:36 | 000,000,485 | RHS- | M] () -- C:\boot.ini [2014/04/09 07:14:40 | 000,002,048 | --S- | M] () -- C:\Windows\bootstat.dat [2014/04/03 03:25:22 | 000,001,963 | ---- | M] () -- C:\jobq.psMsg [2014/04/03 03:24:42 | 094,261,792 | ---- | M] () -- C:\tmpcache0 [2014/04/03 03:21:28 | 000,001,158 | ---- | M] () -- C:\Windows\System32\wpa.dbl [2014/04/03 03:21:12 | 000,000,240 | ---- | M] () -- C:\Windows\tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job [2014/04/02 10:13:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014/04/03 03:24:21 | 094,261,792 | ---- | C] () -- C:\tmpcache0 [2013/07/12 03:44:39 | 000,000,031 | ---- | C] () -- C:\Windows\QuickDisc.INI [2012/02/16 01:23:58 | 000,003,072 | ---- | C] () -- C:\Windows\System32\iacenc.dll [2011/11/18 09:41:23 | 000,032,768 | ---- | C] () -- C:\Windows\System32\rmlmk14O.dll [2011/11/18 09:39:55 | 000,000,000 | ---- | C] () -- C:\Windows\cddesign.INI [2009/05/28 06:22:54 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2008/11/26 07:38:52 | 000,126,976 | ---- | C] () -- C:\Windows\System32\RmSpsDcl.dll [2008/10/23 05:18:58 | 000,176,235 | ---- | C] () -- C:\Windows\System32\Primomonnt.dll [2008/10/23 05:18:58 | 000,000,129 | ---- | C] () -- C:\Windows\primopdf.ini [2008/10/22 13:53:49 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v4885.dll [2008/10/22 13:51:49 | 000,004,569 | ---- | C] () -- C:\Windows\System32\secupd.dat [2008/10/22 13:51:46 | 000,004,605 | ---- | C] () -- C:\Windows\System32\oembios.dat [2008/10/22 13:51:45 | 013,107,200 | ---- | C] () -- C:\Windows\System32\oembios.bin [2008/10/22 13:51:44 | 000,000,741 | ---- | C] () -- C:\Windows\System32\noise.dat [2008/10/22 13:51:30 | 000,001,804 | ---- | C] () -- C:\Windows\System32\dcache.bin [2008/10/22 13:40:50 | 000,000,827 | ---- | C] () -- C:\Windows\System32\oeminfo.ini [2008/10/22 05:05:23 | 000,000,061 | ---- | C] () -- C:\Windows\smscfg.ini [2008/10/22 05:00:35 | 000,049,152 | ---- | C] () -- C:\Windows\System32\ChCfg.exe [2006/05/16 15:28:48 | 000,002,048 | --S- | C] () -- C:\Windows\bootstat.dat [2006/05/04 19:50:52 | 000,500,738 | ---- | C] () -- C:\Windows\System32\perfh015.dat [2006/05/04 19:50:52 | 000,441,696 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006/05/04 19:50:52 | 000,089,274 | ---- | C] () -- C:\Windows\System32\perfc015.dat [2006/05/04 19:50:52 | 000,071,632 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006/05/04 19:46:46 | 000,145,216 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006/05/04 19:39:16 | 000,004,293 | ---- | C] () -- C:\Windows\ODBCINST.INI [2006/05/04 19:34:22 | 000,021,856 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat [2001/10/26 19:15:18 | 000,313,828 | ---- | C] () -- C:\Windows\System32\perfi015.dat [2001/10/26 19:15:18 | 000,034,990 | ---- | C] () -- C:\Windows\System32\perfd015.dat [2001/08/18 00:30:26 | 000,272,128 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2001/08/18 00:30:26 | 000,028,626 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2001/08/18 00:15:40 | 000,046,258 | ---- | C] () -- C:\Windows\System32\mib.bin [2001/07/22 01:36:50 | 000,218,003 | ---- | C] () -- C:\Windows\System32\dssec.dat [2001/07/22 01:36:06 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [color=#E56717]========== LOP Check ==========[/color] [2013/05/17 04:15:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ESET [2011/11/18 09:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Rimage [2013/11/26 06:30:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Sony [2014/01/22 05:39:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Sony Mobile [2014/03/27 08:02:14 | 000,000,234 | ---- | M] () -- C:\Windows\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job [2014/04/03 03:21:12 | 000,000,240 | ---- | M] () -- C:\Windows\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job [color=#E56717]========== Purity Check ==========[/color] < End of report >