From: Bluemaster on
thanks mate but new account didn;t fix problem . I even restored reg from
backup same error .


"Dave Patrick" wrote:

> Try logging on as another and or new user.
> Try a 'Safe Mode' boot.
>
>
>
> --
>
> Regards,
>
> Dave Patrick ....Please no email replies - reply in newsgroup.
> Microsoft Certified Professional
> Microsoft MVP [Windows]
> http://www.microsoft.com/protect
>
> "bluemaster" wrote:
> >I installed Advanced System Care and after reboot I have blank
> > desktop and I can not run explorer.exe .
> >
> > Logfile of Trend Micro HijackThis v2.0.2
> > Scan saved at 10:28:33 AM, on 22/02/2010
> > Platform: Windows 2003 SP2 (WinNT 5.02.3790)
> > MSIE: Internet Explorer v8.00 (8.00.6001.18702)
> > Boot mode: Normal
> >
> > Running processes:
> > C:\Documents and Settings\Administrator\WINDOWS\System32\smss.exe
> > C:\WINDOWS\system32\winlogon.exe
> > C:\WINDOWS\system32\services.exe
> > C:\WINDOWS\system32\lsass.exe
> > C:\WINDOWS\system32\svchost.exe
> > C:\WINDOWS\System32\svchost.exe
> > C:\WINDOWS\system32\spoolsv.exe
> > C:\WINDOWS\System32\dns.exe
> > C:\WINDOWS\system32\inetsrv\inetinfo.exe
> > C:\WINDOWS\system32\tcpsvcs.exe
> > C:\WINDOWS\System32\snmp.exe
> > C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
> > C:\WINDOWS\system32\svchost.exe
> > C:\WINDOWS\System32\svchost.exe
> > C:\WINDOWS\system32\lserver.exe
> > C:\WINDOWS\System32\tssdis.exe
> > C:\WINDOWS\System32\svchost.exe
> > c:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn
> > \fdhost.exe
> > c:\in\alt-explorer\ghostshell.exe
> > C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
> > C:\WINDOWS\system32\ctfmon.exe
> > C:\WINDOWS\System32\svchost.exe
> > C:\WINDOWS\system32\taskmgr.exe
> > C:\WINDOWS\system32\ntvdm.exe
> > C:\WINDOWS\system32\MRT.exe
> > C:\WINDOWS\system32\wuauclt.exe
> > C:\WINDOWS\System32\logon.scr
> > C:\WINDOWS\system32\winlogon.exe
> > C:\WINDOWS\system32\rdpclip.exe
> > C:\WINDOWS\system32\taskmgr.exe
> > C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
> >
> > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
> > res://shdoclc.dll/softAdmin.htm
> > R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
> > http://go.microsoft.com/fwlink/?LinkId=69157
> > R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL
> > = http://go.microsoft.com/fwlink/?LinkId=54896
> > R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
> > http://go.microsoft.com/fwlink/?LinkId=54896
> > R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
> > http://go.microsoft.com/fwlink/?LinkId=69157
> > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page =
> > res://shdoclc.dll/softAdmin.htm
> > R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:
> > \WINDOWS\system32\blank.htm
> > R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:
> > \WINDOWS\system32\blank.htm
> > F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
> > O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-
> > B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
> > O4 - HKLM\..\Run: [ShutdownEventCheck] %systemroot%\system32\dumprep 0
> > -s
> > O4 - HKLM\..\Run: [IObit Security 360] "C:\Program Files\IObit\IObit
> > Security 360\IS360tray.exe" /autostart
> > O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office
> > \Office12\GrooveMonitor.exe"
> > O4 - HKLM\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW
> > \dwtrig20.exe" -t
> > O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
> > O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
> > (User 'LOCAL SERVICE')
> > O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%
> > \system32\tscupgrd.exe (User 'LOCAL SERVICE')
> > O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
> > (User 'NETWORK SERVICE')
> > O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%
> > \system32\tscupgrd.exe (User 'NETWORK SERVICE')
> > O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
> > (User 'SYSTEM')
> > O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%
> > \system32\tscupgrd.exe (User 'SYSTEM')
> > O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
> > (User 'Default user')
> > O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%
> > \system32\tscupgrd.exe (User 'Default user')
> > O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:
> > \Program Files\Microsoft Office\Office12\ONENOTEM.EXE
> > O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows
> > Desktop Search\WindowsSearch.exe
> > O8 - Extra context menu item: E&xport to Microsoft Excel -
> > res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
> > O9 - Extra button: Send to OneNote -
> > {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:
> > \PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
> > O9 - Extra 'Tools' menuitem: S&end to OneNote -
> > {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:
> > \PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
> > O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
> > C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
> > O10 - Broken Internet access because of LSP provider 'c:\documents and
> > settings\administrator\windows\system32\mswsock.dll' missing
> > O15 - ESC Trusted Zone: http://support.extremenetworks.com.au
> > O15 - ESC Trusted Zone: http://www.google.com.au
> > O15 - ESC Trusted Zone: http://www.pctools.com
> > O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety
> > Center Base Module) -
> > http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
> > O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = belic.local
> > O17 - HKLM\Software\..\Telephony: DomainName = belic.local
> > O17 - HKLM\System\CCS\Services\Tcpip\..\{5D55079C-3D32-4404-B6E3-
> > B3855909959A}: NameServer = 172.16.0.2
> > O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = belic.local
> > O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = belic.local
> > O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = belic.local
> > O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-
> > A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
> > O23 - Service: Kaspersky Anti-Virus (KAVFS) - Unknown owner - C:
> > \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 For Windows
> > Servers Enterprise Edition\kavfs.exe (file missing)
> > O23 - Service: Kaspersky Anti-Virus Management (KAVFSGT) - Unknown
> > owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 For
> > Windows Servers Enterprise Edition\kavfsgt.exe (file missing)
> > O23 - Service: Kaspersky Anti-Virus Script Interceptor Dispatcher
> > (kavfsscs) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky
> > Anti-Virus 6.0 For Windows Servers Enterprise Edition\kavfsscs.exe
> > (file missing)
> >
> > --
> > End of file - 6035 bytes
>
> .
>