System: XP Pro x64 Edition
Ver 2003
Service Pack 2

hello, again my comp is infected

the symptoms are that is really really slow when in full mode & the hard drives never stop working even when i have not used it for a long time. the green light never stops blinking also, right now im running it on safe mode

ran avg, spybot & malware but nothing found

here are the Farbar Recovery Scan Tool and aswMBR logs

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-08-2014 01
Ran by DJ RAC (administrator) on DJ-RAC-PUTTER on 13-08-2014 17:36:37
Running from C:\Documents and Settings\DJ RAC\Desktop
Platform: Microsoft Windows XP Service Pack 2 (X64) OS Language: English (United States)
Internet Explorer Version 7
Boot Mode: Safe Mode (with Networking)

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [577536 2006-08-03] (Realtek Semiconductor Corp.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5187088 2014-07-10] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2640408 2014-08-11] ()
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Winlogon: [Userinit] userinit, [X]
HKLM\...\Winlogon: [UIHost] C:\Windows\system32\logonui.exe [662016 2007-02-17] ( (Microsoft Corporation))
Winlogon\Notify\crypt32chain: C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
Winlogon\Notify\cryptnet: C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
Winlogon\Notify\cscdll: C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
Winlogon\Notify\dimsntfy: C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
Winlogon\Notify\ScCertProp: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\Schedule: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\sclgntfy: C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\SensLogn: C:\WINDOWS\system32\WlNotify.dll (Microsoft Corporation)
Winlogon\Notify\termsrv: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\wlballoon: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\crypt32chain-x32: C:\WINDOWS\SysWOW64\crypt32.dll (Microsoft Corporation)
Winlogon\Notify\cryptnet-x32: C:\WINDOWS\SysWOW64\cryptnet.dll (Microsoft Corporation)
Winlogon\Notify\cscdll-x32: C:\WINDOWS\SysWOW64\cscdll.dll (Microsoft Corporation)
Winlogon\Notify\dimsntfy-x32: C:\WINDOWS\SysWOW64\dimsntfy.dll (Microsoft Corporation)
Winlogon\Notify\EFS-x32: C:\WINDOWS\SysWOW64\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\ScCertProp-x32: wlnotify.dll [X]
Winlogon\Notify\Schedule-x32: wlnotify.dll [X]
Winlogon\Notify\sclgntfy-x32: C:\WINDOWS\SysWOW64\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
Winlogon\Notify\SensLogn-x32: WlNotify.dll [X]
Winlogon\Notify\wlballoon-x32: wlnotify.dll [X]
HKLM\...\Command Processor: <======= ATTENTION
HKLM-x32\...\Command Processor: <======= ATTENTION
HKU\.DEFAULT\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-19\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-21-2799395484-3895304042-2403659751-1002\...\MountPoints2: {2d27d8a5-3283-11e3-8e94-00e04d1c5274} - E:\LGAutoRun.exe
HKU\S-1-5-21-2799395484-3895304042-2403659751-1002\...\MountPoints2: {e39d701f-90fe-11e2-9c15-00e04d1c5274} - D:\LaunchU3.exe -a
IFEO\Your Image File Name Here without a path: [Debugger] ntsd -d
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
SSODL-x32: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\syswow64\SHELL32.dll (Microsoft Corporation)
SSODL-x32: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\syswow64\SHELL32.dll (Microsoft Corporation)
SSODL-x32: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\SysWOW64\stobject.dll (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean64.exeC:\PROGRA~2\AVG\AVG2014\avgrsa.exe /sync /restart

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={78CBEA97-1813-44AE-A46F-4CD435A77274}&mid=63957768860347d38e83d1a90bf8bb87-8d758629d5135f4470f57152dc116841b6490bd7&lang=en&ds=AVG&pr=fr&d=2013-05-25 00:51:20&v={searchTerms}
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
Toolbar: HKLM-x32 - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
DPF: HKLM-x32 {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1363890949984
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\Windows\system32\mshtml.dll (Microsoft Corporation)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\Windows\SysWow64\mshtml.dll (Microsoft Corporation)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search)
Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Filter-x32: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Filter-x32: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Filter-x32: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\Windows\SysWow64\SHELL32.dll (Microsoft Corporation)
ShellExecuteHooks: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [10508288 2009-02-10] (Microsoft Corporation)
ShellExecuteHooks-x32: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\SysWOW64\shell32.dll [8360960 2009-02-10] (Microsoft Corporation)
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\mswsock.dll [233472] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 03 %SystemRoot%\System32\mswsock.dll [492544] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Documents and Settings\DJ RAC\Application Data\Mozilla\Firefox\Profiles\afjw053j.default
FF Homepage: about:newtab
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VLC Media Player 2 0 8 win32\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar\FireFoxExt\
FF Extension: AVG SafeGuard toolbar - C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar\FireFoxExt\ [2014-01-05]

CHR NewTab: "chrome-extension://dpjamkmjmigaoobjbekmfgabipmfilij/empty_ntp.html"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2003) - C:\Program Files (x86)\Firefox Mozilla Ver 19 0 2\plugins\NPOFFICE.DLL No File
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Firefox Mozilla Ver 19 0 2\plugins\npwachk.dll No File
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.0.0\\npsitesafety.dll (AVG Technologies)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File
CHR Extension: (Google Drive) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-23]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-02]
CHR Extension: (YouTube) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-23]
CHR Extension: (Google Search) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-23]
CHR Extension: (Empty New Tab Page) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dpjamkmjmigaoobjbekmfgabipmfilij [2013-12-03]
CHR Extension: (Google Wallet) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Gmail) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-23]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AeLookupSvc; C:\Windows\SysWOW64\aelupsvc.dll [26624 2006-03-29] (Microsoft Corporation)
S4 Alerter; C:\Windows\system32\alrsvc.dll [29696 2006-03-29] (Microsoft Corporation)
S3 ALG; C:\Windows\SysWOW64\alg.exe [45056 2006-03-29] (Microsoft Corporation)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3244048 2014-07-10] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-07-10] (AVG Technologies CZ, s.r.o.)
S2 Browser; C:\Windows\SysWOW64\browser.dll [78336 2007-02-18] (Microsoft Corporation)
S3 ClipSrv; C:\Windows\system32\clipsrv.exe [49664 2006-03-29] (Microsoft Corporation)
S3 ClipSrv; C:\Windows\SysWOW64\clipsrv.exe [32256 2006-03-29] (Microsoft Corporation)
R2 dmadmin; C:\Windows\System32\dmadmin.exe [399872 2007-02-17] (Microsoft Corporation)
R2 dmserver; C:\Windows\System32\dmserver.dll [37376 2007-02-17] (Microsoft Corporation)
S2 ERSvc; C:\Windows\System32\ersvc.dll [31744 2006-03-29] (Microsoft Corporation)
R2 helpsvc; C:\Windows\PCHealth\HelpCtr\Binaries\pchsvc.dll [77312 2007-02-17] (Microsoft Corporation)
S3 HTTPFilter; C:\Windows\System32\w3ssl.dll [21504 2006-03-29] (Microsoft Corporation)
S3 IASJet; C:\Windows\SysWOW64\iasrecst.dll [162816 2006-03-29] (Microsoft Corporation)
S3 ImapiService; C:\WINDOWS\system32\imapi.exe [265728 2007-02-17] (Microsoft Corporation)
S4 Messenger; C:\Windows\System32\msgsvc.dll [57344 2007-02-17] (Microsoft Corporation)
S3 mnmsrvc; C:\WINDOWS\SysWOW64\mnmsrvc.exe [32768 2006-03-29] (Microsoft Corporation)
S3 NetDDE; C:\Windows\system32\netdde.exe [160768 2007-02-17] (Microsoft Corporation)
S3 NetDDEdsdm; C:\Windows\system32\netdde.exe [160768 2007-02-17] (Microsoft Corporation)
R3 Netman; C:\Windows\SysWOW64\netman.dll [263680 2007-02-18] (Microsoft Corporation)
S3 Nla; C:\Windows\System32\mswsock.dll [492544 2008-06-21] (Microsoft Corporation)
S3 Nla; C:\Windows\SysWOW64\mswsock.dll [233472 2008-06-21] (Microsoft Corporation)
S3 NtLmSsp; C:\Windows\system32\lsass.exe [14336 2006-03-29] (Microsoft Corporation)
S2 NtmsSvc; C:\Windows\system32\ntmssvc.dll [794112 2007-02-17] (Microsoft Corporation)
S2 NVSvc; C:\Windows\system32\nvsvc64.exe [135680 2006-03-31] (NVIDIA Corporation)
R2 PlugPlay; C:\Windows\system32\services.exe [227840 2009-03-19] (Microsoft Corporation)
S2 PolicyAgent; C:\Windows\system32\lsass.exe [14336 2006-03-29] (Microsoft Corporation)
S3 RasAuto; C:\Windows\SysWOW64\rasauto.dll [91648 2007-02-18] (Microsoft Corporation)
S3 RasMan; C:\Windows\SysWOW64\rasmans.dll [181760 2007-02-18] (Microsoft Corporation)
S3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [212480 2007-02-17] (Microsoft Corporation)
S3 RpcLocator; C:\Windows\SysWOW64\locator.exe [71680 2006-03-29] (Microsoft Corporation)
S3 SCardSvr; C:\Windows\System32\SCardSvr.exe [166400 2007-02-17] (Microsoft Corporation)
S2 Schedule; C:\Windows\SysWOW64\schedsvc.dll [202240 2007-02-18] (Microsoft Corporation)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
S2 seclogon; C:\Windows\SysWOW64\seclogon.dll [18432 2007-02-18] (Microsoft Corporation)
R2 srservice; C:\WINDOWS\system32\srsvc.dll [231424 2007-02-17] (Microsoft Corporation)
S2 SysmonLog; C:\Windows\system32\smlogsvc.exe [133120 2007-02-17] (Microsoft Corporation)
S2 SysmonLog; C:\Windows\SysWOW64\smlogsvc.exe [96256 2007-02-18] (Microsoft Corporation)
S4 TlntSvr; C:\WINDOWS\system32\tlntsvr.exe [113152 2007-02-17] (Microsoft Corporation)
S2 TrkWks; C:\Windows\SysWOW64\trkwks.dll [86528 2007-02-18] (Microsoft Corporation)
S2 UMWdf; C:\WINDOWS\system32\wdfmgr.exe [62976 2006-03-29] (Microsoft Corporation)
S2 UMWdf; C:\WINDOWS\SysWOW64\wdfmgr.exe [39424 2006-03-29] (Microsoft Corporation)
S3 UPS; C:\Windows\System32\ups.exe [34816 2006-03-29] (Microsoft Corporation)
S3 UPS; C:\Windows\SysWOW64\ups.exe [16896 2006-03-29] (Microsoft Corporation)
S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-11] (AVG Secure Search)
S3 WmdmPmSN; C:\WINDOWS\system32\mspmsnsv.dll [36352 2007-02-17] (Microsoft Corporation)
S3 Wmi; C:\Windows\System32\advapi32.dll [1052160 2009-03-19] (Microsoft Corporation)
S3 Wmi; C:\Windows\SysWOW64\advapi32.dll [619008 2009-03-19] (Microsoft Corporation)
S2 wuauserv; C:\WINDOWS\system32\wuauserv.dll [12288 2006-03-29] (Microsoft Corporation)
R2 WZCSVC; C:\Windows\System32\wzcsvc.dll [659968 2007-02-17] (Microsoft Corporation)
R2 WZCSVC; C:\Windows\SysWOW64\wzcsvc.dll [489472 2007-02-18] (Microsoft Corporation)
S3 xmlprov; C:\Windows\System32\xmlprov.dll [326144 2007-02-17] (Microsoft Corporation)
S3 xmlprov; C:\Windows\SysWOW64\xmlprov.dll [131584 2007-02-18] (Microsoft Corporation)
R2 Eventlog; [X]
S4 HidServ; %SystemRoot%\System32\hidserv.dll [X]
S3 WinHttpAutoProxySvc; winhttp.dll [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 Abiosdsk; No ImagePath
S4 ACPIEC; C:\Windows\System32\Drivers\ACPIEC.sys [18432 2006-03-29] (Microsoft Corporation)
S4 adpu160m; No ImagePath
S4 adpu320; No ImagePath
S3 aec; C:\Windows\System32\drivers\aec.sys [188928 2005-03-24] (Microsoft Corporation)
S4 aic78u2; No ImagePath
S4 aic78xx; No ImagePath
S3 ALCXWDM; C:\Windows\System32\drivers\ALCWDM64.SYS [3304448 2006-10-13] (Realtek Semiconductor Corp.)
S4 AliIde; No ImagePath
S4 AmdIde; No ImagePath
S1 AmdK8; C:\Windows\System32\DRIVERS\amdk8.sys [51200 2006-05-10] (Advanced Micro Devices)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2013-04-18] (Google Inc)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S4 arc; No ImagePath
S4 Atdisk; No ImagePath
S3 Atmarpc; C:\Windows\System32\DRIVERS\atmarpc.sys [106496 2007-02-17] (Microsoft Corporation)
S3 audstub; C:\Windows\System32\DRIVERS\audstub.sys [5632 2005-03-24] (Microsoft Corporation)
S1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriverl; C:\Windows\System32\DRIVERS\avgidsdriverla.sys [227608 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx64.sys [50976 2014-08-11] (AVG Technologies)
S1 BIOS; C:\WINDOWS\system32\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
S1 BIOS; C:\WINDOWS\SysWOW64\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
S2 CdaC15BA; C:\Windows\System32\DRIVERS\CdaC15BA.sys [13312 2006-03-29] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
S2 CdaD10BA; C:\Windows\System32\DRIVERS\CdaD10BA.sys [13312 2006-03-29] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
S1 Changer; No ImagePath
S4 CmdIde; No ImagePath
S4 dmboot; C:\Windows\System32\drivers\dmboot.sys [415232 2007-02-17] (Microsoft Corporation)
R0 dmio; C:\Windows\System32\drivers\dmio.sys [244224 2007-02-17] (Microsoft Corporation)
R0 dmload; C:\Windows\System32\drivers\dmload.sys [9216 2006-03-29] (Microsoft Corporation)
S4 dpti2o; No ImagePath
S1 Fips; C:\Windows\System32\Drivers\Fips.sys [50176 2007-02-17] (Microsoft Corporation)
R0 Ftdisk; C:\Windows\System32\DRIVERS\ftdisk.sys [240128 2007-02-17] (Microsoft Corporation)
R3 Gpc; C:\Windows\System32\DRIVERS\msgpc.sys [71168 2007-02-17] (Microsoft Corporation)
S1 i2omgmt; No ImagePath
S4 iirsp; No ImagePath
R1 imapi; C:\Windows\System32\DRIVERS\imapi.sys [72704 2006-03-29] (Microsoft Corporation)
S4 IntelIde; No ImagePath
S3 Ip6Fw; C:\Windows\System32\drivers\ip6fw.sys [57856 2007-02-17] (Microsoft Corporation)
S3 IpInIp; No ImagePath
R1 IPSec; C:\Windows\System32\DRIVERS\ipsec.sys [156672 2007-02-17] (Microsoft Corporation)
S3 kmixer; C:\Windows\System32\drivers\kmixer.sys [204288 2005-03-24] (Microsoft Corporation)
S1 mnmdd; C:\Windows\System32\Drivers\mnmdd.sys [8192 2006-03-29] (Microsoft Corporation)
S4 mraid35x; No ImagePath
S3 MxlW2k; C:\Windows\SysWow64\Drivers\MxlW2k.sys [28276 2013-03-18] (MusicMatch, Inc.) [File not signed]
S3 nv; C:\Windows\System32\DRIVERS\nv4_mini.sys [4818944 2006-03-31] (NVIDIA Corporation)
R0 nvata64; C:\Windows\System32\DRIVERS\nvata64.sys [164864 2006-04-24] (NVIDIA Corporation)
R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [52736 2006-02-17] (NVIDIA Corporation)
R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [22016 2006-02-17] (NVIDIA Corporation)
S3 PDCOMP; No ImagePath
S3 PDFRAME; No ImagePath
S3 PDRELI; No ImagePath
S3 PDRFRAME; No ImagePath
R3 PSched; C:\Windows\System32\DRIVERS\psched.sys [106496 2007-02-17] (Microsoft Corporation)
R3 Ptilink; C:\Windows\System32\DRIVERS\ptilink.sys [31232 2006-03-29] (Parallel Technologies, Inc.)
S0 PxHelp64; C:\Windows\SysWOW64\DRIVERS\PxHelp64.sys [47872 2003-07-30] (Sonic Solutions) [File not signed]
R3 Raspti; C:\Windows\System32\DRIVERS\raspti.sys [31232 2006-03-29] (Microsoft Corporation)
R1 redbook; C:\Windows\System32\DRIVERS\redbook.sys [64000 2005-03-24] (Microsoft Corporation)
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [171008 2007-02-17] (Microsoft Corporation)
S4 Simbad; No ImagePath
S3 splitter; C:\Windows\System32\drivers\splitter.sys [10240 2007-02-17] (Microsoft Corporation)
R0 sr; C:\Windows\System32\DRIVERS\sr.sys [123904 2006-03-29] (Microsoft Corporation)
S3 swmidi; C:\Windows\System32\drivers\swmidi.sys [86528 2005-03-24] (Microsoft Corporation)
S4 symc8xx; No ImagePath
S4 symmpi; No ImagePath
S4 sym_hi; No ImagePath
S4 sym_u3; No ImagePath
S3 sysaudio; C:\Windows\System32\drivers\sysaudio.sys [147456 2007-02-17] (Microsoft Corporation)
S4 TosIde; No ImagePath
S4 ultra; No ImagePath
R3 Update; C:\Windows\System32\DRIVERS\update.sys [81920 2007-02-17] (Microsoft Corporation)
S4 ViaIde; No ImagePath
S3 WDICA; No ImagePath
S3 wdmaud; C:\Windows\System32\drivers\wdmaud.sys [187904 2007-02-17] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

NETSVCx32: Browser -> C:\Windows\SysWOW64\browser.dll (Microsoft Corporation)
NETSVCx32: CryptSvc -> C:\Windows\SysWOW64\cryptsvc.dll (Microsoft Corporation)
NETSVCx32: DMServer -> C:\Windows\SysWOW64\dmserver.dll ==> No File.
NETSVCx32: EventSystem -> C:\WINDOWS\SysWOW64\es.dll (Microsoft Corporation)
NETSVCx32: HidServ -> C:\Windows\SysWOW64\hidserv.dll ==> No File.
NETSVCx32: Iprip -> No ServiceDLL Path.
NETSVCx32: LanmanWorkstation -> C:\Windows\SysWOW64\wkssvc.dll ==> No File.
NETSVCx32: Messenger -> C:\Windows\SysWOW64\msgsvc.dll ==> No File.
NETSVCx32: Netman -> C:\Windows\SysWOW64\netman.dll (Microsoft Corporation)
NETSVCx32: Seclogon -> C:\Windows\SysWOW64\seclogon.dll (Microsoft Corporation)
NETSVCx32: TrkWks -> C:\Windows\SysWOW64\trkwks.dll (Microsoft Corporation)
NETSVCx32: WZCSVC -> C:\Windows\SysWOW64\wzcsvc.dll (Microsoft Corporation)
NETSVCx32: wscsvc -> C:\Windows\SysWOW64\wscsvc.dll ==> No File.
NETSVCx32: xmlprov -> C:\Windows\SysWOW64\xmlprov.dll (Microsoft Corporation)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-13 17:36 - 2014-08-13 17:36 - 00027090 _____ () C:\Documents and Settings\DJ RAC\Desktop\FRST.txt
2014-08-13 17:35 - 2014-08-13 17:36 - 00000000 ____D () C:\FRST
2014-08-13 17:30 - 2014-08-13 17:30 - 02100224 _____ (Farbar) C:\Documents and Settings\DJ RAC\Desktop\FRST64.exe
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\RegBackup
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com
2014-08-13 17:27 - 2014-08-13 17:27 - 04057608 _____ () C:\Documents and Settings\DJ RAC\Desktop\tweaking.com_registry_backup_setup.exe
2014-08-13 17:27 - 2014-08-13 17:27 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-08-13 17:00 - 2014-08-13 17:00 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\hijackthis 08 13 14 17 00 PM .log
2014-08-13 14:02 - 2014-08-13 14:02 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 14 02 pm after all scans hijackthis.log
2014-08-13 11:25 - 2014-08-13 11:25 - 00006894 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 11 25 am after malware scan hijackthis.log
2014-08-13 09:32 - 2014-08-13 09:32 - 00006893 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 09 32 am after spy scan hijackthis.log
2014-08-13 08:27 - 2014-06-19 12:47 - 00450613 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140813-082716.backup
2014-08-13 08:12 - 2014-08-13 08:12 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 08 12 am after avg scan hijackthis.log
2014-08-13 07:10 - 2014-08-13 07:10 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 07 09 am b4 scans hijackthis.log
2014-08-13 07:08 - 2014-08-13 16:58 - 00000000 ____D () C:\Program Files (x86)\Trend Micro HijackThis Ver 2 0 2
2014-08-13 07:08 - 2014-08-13 07:08 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis
2014-08-13 06:51 - 2014-08-13 17:03 - 00000000 _____ () C:\WINDOWS\0.log
2014-08-13 03:18 - 2014-08-13 17:00 - 00005115 _____ () C:\WINDOWS\WindowsUpdate.log
2014-08-11 21:22 - 2014-08-13 02:26 - 00000199 _____ () C:\Documents and Settings\DJ RAC\Desktop\major crimes.txt
2014-07-29 22:17 - 2014-07-31 15:16 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Desktop\priscillas
2014-07-25 03:02 - 2014-08-13 17:00 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-07-25 00:48 - 2014-07-26 22:41 - 00002049 _____ () C:\Documents and Settings\DJ RAC\Desktop\disco music mix.txt
2014-07-16 23:18 - 2014-07-19 15:04 - 00000078 _____ () C:\Documents and Settings\DJ RAC\Desktop\baladas 70s.txt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-13 17:36 - 2014-08-13 17:36 - 00027090 _____ () C:\Documents and Settings\DJ RAC\Desktop\FRST.txt
2014-08-13 17:36 - 2014-08-13 17:35 - 00000000 ____D () C:\FRST
2014-08-13 17:36 - 2013-03-20 20:30 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Local Settings\Temp
2014-08-13 17:30 - 2014-08-13 17:30 - 02100224 _____ (Farbar) C:\Documents and Settings\DJ RAC\Desktop\FRST64.exe
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\RegBackup
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com
2014-08-13 17:27 - 2014-08-13 17:27 - 04057608 _____ () C:\Documents and Settings\DJ RAC\Desktop\tweaking.com_registry_backup_setup.exe
2014-08-13 17:27 - 2014-08-13 17:27 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-08-13 17:18 - 2006-03-29 06:00 - 00002422 _____ () C:\WINDOWS\system32\wpa.dbl
2014-08-13 17:03 - 2014-08-13 06:51 - 00000000 _____ () C:\WINDOWS\0.log
2014-08-13 17:00 - 2014-08-13 17:00 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\hijackthis 08 13 14 17 00 PM .log
2014-08-13 17:00 - 2014-08-13 03:18 - 00005115 _____ () C:\WINDOWS\WindowsUpdate.log
2014-08-13 17:00 - 2014-07-25 03:02 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-08-13 17:00 - 2013-03-20 20:30 - 00000178 ___SH () C:\Documents and Settings\DJ RAC\ntuser.ini
2014-08-13 17:00 - 2013-03-20 12:12 - 00524288 _____ () C:\WINDOWS\system32\config\SpybotSD.evt
2014-08-13 17:00 - 2013-03-19 14:13 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2014-08-13 17:00 - 2013-03-18 07:24 - 00032470 _____ () C:\WINDOWS\Tasks\SchedLgU.Txt
2014-08-13 17:00 - 2013-03-18 07:24 - 00000216 _____ () C:\Documents and Settings\LocalService\wiadebug.log
2014-08-13 17:00 - 2013-03-18 07:24 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-08-13 16:58 - 2014-08-13 07:08 - 00000000 ____D () C:\Program Files (x86)\Trend Micro HijackThis Ver 2 0 2
2014-08-13 16:08 - 2013-10-09 18:28 - 00000898 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-13 14:39 - 2014-06-18 14:13 - 00000442 _____ () C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1403122415.job
2014-08-13 14:02 - 2014-08-13 14:02 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 14 02 pm after all scans hijackthis.log
2014-08-13 13:29 - 2014-02-05 23:44 - 00000374 _____ () C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rmv.job
2014-08-13 13:29 - 2014-02-05 23:44 - 00000372 _____ () C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rel.job
2014-08-13 13:29 - 2013-10-09 18:28 - 00000894 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-13 13:29 - 2013-03-20 12:12 - 00000632 _____ () C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
2014-08-13 13:29 - 2013-03-18 07:35 - 00050257 _____ () C:\WINDOWS\system32\nvapps.xml
2014-08-13 13:28 - 2013-03-18 13:22 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MFAData
2014-08-13 11:25 - 2014-08-13 11:25 - 00006894 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 11 25 am after malware scan hijackthis.log
2014-08-13 09:32 - 2014-08-13 09:32 - 00006893 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 09 32 am after spy scan hijackthis.log
2014-08-13 08:13 - 2013-03-20 12:12 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-08-13 08:12 - 2014-08-13 08:12 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 08 12 am after avg scan hijackthis.log
2014-08-13 07:10 - 2014-08-13 07:10 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 07 09 am b4 scans hijackthis.log
2014-08-13 07:08 - 2014-08-13 07:08 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis
2014-08-13 02:45 - 2013-03-20 20:30 - 00000000 ____D () C:\Documents and Settings\DJ RAC
2014-08-13 02:26 - 2014-08-11 21:22 - 00000199 _____ () C:\Documents and Settings\DJ RAC\Desktop\major crimes.txt
2014-08-13 00:30 - 2013-03-20 12:12 - 00000628 _____ () C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2014-08-12 14:39 - 2014-06-18 14:13 - 00000000 ____D () C:\Program Files (x86)\Opera 22 0 1471 70
2014-08-11 20:41 - 2014-03-15 10:18 - 00000000 ____D () C:\Program Files (x86)\AVG SafeGuard toolbar
2014-08-11 20:41 - 2013-05-20 17:57 - 00000000 ____D () C:\WINDOWS\SysWOW64\cache
2014-08-11 20:41 - 2013-03-18 13:31 - 00050976 _____ (AVG Technologies) C:\WINDOWS\system32\Drivers\avgtpx64.sys
2014-08-11 15:09 - 2013-03-20 20:30 - 00000265 _____ () C:\Documents and Settings\DJ RAC\wiadebug.log
2014-08-11 14:42 - 2014-04-03 13:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 30 0
2014-08-06 15:37 - 2013-03-18 16:22 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\DVD Shrink
2014-08-04 15:12 - 2013-03-20 20:52 - 00000178 ___SH () C:\Documents and Settings\Lety\ntuser.ini
2014-08-04 15:11 - 2013-03-20 20:52 - 00000000 ____D () C:\Documents and Settings\Lety\Local Settings\Temp
2014-08-04 15:03 - 2013-03-24 14:56 - 00000000 ____D () C:\Documents and Settings\Lety\Desktop\SAVE IT HERE
2014-08-04 15:03 - 2013-03-20 20:52 - 00000265 _____ () C:\Documents and Settings\Lety\wiadebug.log
2014-08-04 10:17 - 2014-05-01 09:12 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2014 Ver 2014 0 4744
2014-08-01 00:30 - 2013-03-20 12:12 - 00000458 _____ () C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
2014-07-31 15:32 - 2013-03-18 17:32 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\TEMP
2014-07-31 15:16 - 2014-07-29 22:17 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Desktop\priscillas
2014-07-29 19:22 - 2013-03-23 19:44 - 00000178 ___SH () C:\Documents and Settings\Prisc & Vane\ntuser.ini
2014-07-29 19:12 - 2013-03-23 19:44 - 00000000 ____D () C:\Documents and Settings\Prisc & Vane\Local Settings\Temp
2014-07-26 22:41 - 2014-07-25 00:48 - 00002049 _____ () C:\Documents and Settings\DJ RAC\Desktop\disco music mix.txt
2014-07-25 03:02 - 2013-03-18 13:20 - 00699056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-07-25 03:02 - 2013-03-18 13:20 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-25 00:03 - 2013-03-23 03:32 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\YTD Video Downloader
2014-07-19 15:04 - 2014-07-16 23:18 - 00000078 _____ () C:\Documents and Settings\DJ RAC\Desktop\baladas 70s.txt

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
C:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!.
==================== End Of Log

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-08-2014 01
Ran by DJ RAC at 2014-08-13 17:37:13
Running from C:\Documents and Settings\DJ RAC\Desktop
Boot Mode: Safe Mode (with Networking)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

1-Click YouTube Downloader 9.0 (HKLM-x32\...\1-Click YouTube Downloader_is1) (Version: - )
Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.7.700.224 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
AoA Audio Extractor (HKLM-x32\...\{D1725D54-279A-40C5-A70D-23C1785DB920}_is1) (Version: - AoAMedia.com)
Asoftech Data Recovery (HKLM-x32\...\{1AED6EB7-8FEA-4021-B8FD-EBAA6B21679F}) (Version: 1.00 - )
Auslogics Disk Defrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 3.6 - Auslogics Software Pty Ltd)
Auslogics Duplicate File Finder (HKLM-x32\...\{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1) (Version: 2.5 - Auslogics Software Pty Ltd)
Auslogics Registry Cleaner (HKLM-x32\...\{8D8024F1-2945-49A5-9B78-5AB7B11D7942}_is1) (Version: 2.5 - Auslogics Software Pty Ltd)
Auslogics Registry Defrag (HKLM-x32\...\{D627784F-B3EE-44E8-96B1-9509B991EA34}_is1) (Version: 6.5 - Auslogics Software Pty Ltd)
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4744 - AVG Technologies)
AVG 2014 (Version: 14.0.4007 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4744 - AVG Technologies) Hidden
AVG SafeGuard toolbar (HKLM-x32\...\AVG SafeGuard toolbar) (Version: - AVG Technologies)
Brother MFL-Pro Suite MFC-250C (HKLM-x32\...\{3A08B59E-A9F0-4F4D-B7E5-6875D7F13327}) (Version: - Brother Industries, Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 3.28 - Piriform)
DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version: - DVD Shrink)
DVDFab (26/02/2013) Qt (HKLM-x32\...\DVDFab 8 Qt_is1) (Version: - Fengtao Software Inc.)
EaseUS Data Recovery Wizard 5.8.5 (HKLM-x32\...\EaseUS Data Recovery Wizard 5.8.5_is1) (Version: - EaseUS)
Everio MediaBrowser 4 (HKLM-x32\...\{548F12A2-BD2E-4B5A-9B62-BBC0AA8EB3DD}) (Version: 4.00.214 - PIXELA)
FaceFilter Studio Brother Edition (HKLM-x32\...\{F59205C8-E5FB-43F5-AAB2-16C1760D4F59}) (Version: 1.0 - )
FastStone Photo Resizer 3.1 (HKLM-x32\...\FastStone Photo Resizer) (Version: 3.1 - FastStone Soft.)
Gamers Unite! Snag Bar (HKCU\...\Gamers Unite! Snag Bar) (Version: - )
GOM Player (HKLM-x32\...\GOM Player) (Version: - Gretech Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google Update Helper (x32 Version: - Google Inc.) Hidden
GS Auto Clicker (HKLM-x32\...\GS Auto Clicker_is1) (Version: V3.1.2 - goldensoft.org)
HijackThis 2.0.2 (HKLM-x32\...\HijackThis) (Version: 2.0.2 - TrendMicro)
InstaCodecs (HKLM-x32\...\InstaCodecs_is1) (Version: 1.0 - )
LG PC Suite (HKLM-x32\...\LG PC Suite) (Version: - LG Electronics)
LG United Mobile Drivers (HKLM-x32\...\{55031CEF-CE75-4A5C-8DEA-60577820529B}) (Version: - LG Electronics)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft Internationalized Domain Names Mitigation APIs (Version: - Microsoft Corporation) Hidden
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 (Version: - Microsoft Corporation) Hidden
Microsoft National Language Support Downlevel APIs (Version: - Microsoft Corporation) Hidden
Microsoft Office Professional Edition 2003 (HKLM-x32\...\{91110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft XML Parser (x32 Version: 8.0.7820.0 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 6.0 Parser (HKLM\...\{633F3A7E-471D-4C08-A643-C184A2EE19AB}) (Version: 6.10.1129.0 - Microsoft Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - )
Opera Stable 23.0.1522.75 (HKLM-x32\...\Opera 23.0.1522.75) (Version: 23.0.1522.75 - Opera Software ASA)
PaperPort Image Printer 64-bit (HKLM\...\{ABA4FAF1-6389-45F9-92CE-3914A4E5C471}) (Version: 1.00.0000 - Nuance Communications, Inc.)
PicaJet Photo Recovery 1.0.1 Beta (HKLM-x32\...\PicaJet Photo Recovery) (Version: 1.0.1 Beta - PicaJet.Com)
PowerDVD (HKLM-x32\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: - )
Realtek AC'97 Audio (HKLM-x32\...\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version: 5.28 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.46 - Piriform)
ScanSoft PaperPort 11 (HKLM-x32\...\{7A8FF745-BBC5-482B-88E4-18D3178249A9}) (Version: 11.1.0000 - Nuance Communications, Inc.)
Sonic RecordNow! (HKLM-x32\...\{9541FED0-327F-4DF0-8B96-EF57EF622F19}) (Version: 6.5.1 - Sonic Solutions)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.0.12 - Safer-Networking Ltd.)
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 1.9.0 - Tweaking.com)
Update for Windows XP (KB927891) (HKLM\...\KB927891) (Version: 5 - Microsoft Corporation)
Update for Windows XP (KB955839) (HKLM\...\KB955839) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB967715) (HKLM\...\KB967715) (Version: 1 - Microsoft Corporation)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc)
Winamp Detector Plug-in (HKCU\...\Winamp Detect) (Version: - Nullsoft, Inc)
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (04/28/2006 (HKLM\...\9E140F48C9836B9B78539C08FB2B17146BDB3F65) (Version: 04/28/2006 - Advanced Micro Devices)
Windows XP Service Pack 2 (HKLM\...\Windows x64 Service Pack) (Version: 20070217.000042 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Wondershare Photo Recovery (build 3.0.3) (HKLM-x32\...\Wondershare Photo Recovery_is1) (Version: - Wondershare Software Co., Ltd.)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

==================== Restore Points =========================

23-07-2014 16:19:04 System Checkpoint
24-07-2014 01:20:58 System Checkpoint
26-07-2014 18:42:42 System Checkpoint
29-07-2014 21:09:51 System Checkpoint
01-08-2014 20:54:19 System Checkpoint
06-08-2014 14:18:44 System Checkpoint

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-03-29 06:00 - 2014-08-13 08:27 - 00450613 ____R C:\WINDOWS\system32\Drivers\etc\hosts localhost www.007guard.com 007guard.com 008i.com www.008k.com 008k.com www.00hq.com 00hq.com 010402.com www.032439.com 032439.com www.0scan.com 0scan.com www.1000gratisproben.com 1000gratisproben.com 1001namen.com www.1001namen.com 100888290cs.com www.100888290cs.com www.100sexlinks.com 100sexlinks.com www.10sek.com 10sek.com www.1-2005-search.com 1-2005-search.com www.123fporn.info 123fporn.info 123haustiereundmehr.com www.123haustiereundmehr.com

There are 1000 more lines.

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rel.job => C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rmv.job => C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe
Task: C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job.bak => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job.bak => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1403122415.job => C:\Program Files (x86)\Opera 22 0 1471 70\launcher.exe
Task: C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe

==================== Loaded Modules (whitelisted) =============

2014-08-12 14:39 - 2014-08-12 14:39 - 00957048 _____ () C:\Program Files (x86)\Opera 22 0 1471 70\23.0.1522.75\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:8CE646EE

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UploadMgr => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
Error: (08/13/2014 05:29:55 PM) (Source: VSS) (EventID: 18) (User: )
Description: Volume Shadow Copy Service error: The Volume Shadow Copy infrastructure cannot be used during Safe Mode.

Error: (08/13/2014 05:02:34 PM) (Source: VSS) (EventID: 8211) (User: )
Description: Volume Shadow Copy Service error: Writer with name WMI Writer and ID {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} attempted to subscribe in safe mode.

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).

System errors:
Error: (08/13/2014 05:18:58 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:

Error: (08/13/2014 05:03:56 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:

Error: (08/13/2014 05:03:56 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The AVGIDSAgent service depends on the AVGIDSDriverl service which failed to start because of the following error:

Error: (08/13/2014 05:02:36 PM) (Source: 0) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\Drivers\MxlW2k.SYS

Error: (08/13/2014 04:36:36 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {E60687F7-01A1-40AA-86AC-DB1CBF673334} did not register with DCOM within the required timeout.

Error: (08/13/2014 01:29:07 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generate Activation Context failed for C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe.
Reference error message: The referenced assembly is not installed on your system.

Error: (08/13/2014 01:29:07 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls.
Reference error message: The referenced assembly is not installed on your system.

Error: (08/13/2014 01:29:07 PM) (Source: SideBySide) (EventID: 32) (User: )
Description: Dependent Assembly Microsoft.Windows.Common-Controls could not be found and Last Error was The referenced assembly is not installed on your system.

Error: (08/13/2014 01:25:50 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Automatic Updates service hung on starting.

Error: (08/13/2014 01:23:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:

Microsoft Office Sessions:
Error: (08/13/2014 05:29:55 PM) (Source: VSS) (EventID: 18) (User: )

Error: (08/13/2014 05:02:34 PM) (Source: VSS) (EventID: 8211) (User: )
Description: WMI Writer{a6ad56c2-b509-4e6c-bb19-49d8f43532f0}

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366

Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366

==================== Memory info ===========================

Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+
Percentage of memory in use: 18%
Total physical RAM: 3774.23 MB
Available physical RAM: 3092.71 MB
Total Pagefile: 5578.73 MB
Available Pagefile: 5236.39 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:279.47 GB) (Free:7.81 GB) NTFS
Drive d: () (Fixed) (Total:465.75 GB) (Free:342.63 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows XP) (Size: 466 GB) (Disk ID: 0A210A21)
Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS)

Disk: 1 (MBR Code: Windows XP) (Size: 279 GB) (Disk ID: 29632963)
Partition 1: (Active) - (Size=279 GB) - (Type=07 NTFS)

==================== End Of Log

aswMBR version Copyright(c) 2014 AVAST Software
Run date: 2014-08-13 17:39:22
17:39:22.953 OS Version: Windows x64 5.2.3790 Service Pack 2
17:39:22.953 Number of processors: 2 586 0x2B01
17:39:22.953 ComputerName: DJ-RAC-PUTTER UserName: DJ RAC
17:39:23.750 Initialize success
17:39:23.843 VM: driver load error: 2
17:50:28.109 AVAST engine defs: 14081301
18:01:39.265 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-f
18:01:39.265 Disk 0 Vendor: WDC_WD5000AAKB-00H8A0 05.04E05 Size: 476940MB BusType: 3
18:01:39.281 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T1L0-17
18:01:39.296 Disk 1 Vendor: Maxtor_6L300R0 BAH41G10 Size: 286188MB BusType: 3
18:01:39.437 Disk 1 MBR read successfully
18:01:39.437 Disk 1 MBR scan
18:01:39.500 Disk 1 Windows XP default MBR code
18:01:39.515 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 286179 MB offset 63
18:01:39.546 Disk 1 scanning C:\WINDOWS\system32\drivers
18:01:45.890 Service scanning
18:01:58.968 Modules scanning
18:01:59.000 Disk 1 trace - called modules:
18:02:01.750 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys atapi.sys pciide.sys PCIIDEX.SYS hal.dll
18:02:01.906 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffadfa377b770]
18:02:02.062 3 CLASSPNP.SYS[fffffadf98e0a8c9] -> nt!IofCallDriver -> \Device\00000066[0xfffffadfa377ca30]
18:02:02.218 5 ACPI.sys[fffffadf98fa9e69] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T1L0-17[0xfffffadfa377d060]
18:02:03.000 AVAST engine scan C:\WINDOWS
18:02:05.531 AVAST engine scan C:\WINDOWS\system32
18:03:47.265 AVAST engine scan C:\WINDOWS\system32\drivers
18:04:00.593 AVAST engine scan C:\Documents and Settings\DJ RAC
18:14:20.312 AVAST engine scan C:\Documents and Settings\All Users
18:16:15.843 Scan finished successfully
18:18:25.906 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\DJ RAC\Desktop\New logs frst64\MBR.dat"
18:18:25.921 The log file has been saved successfully to "C:\Documents and Settings\DJ RAC\Desktop\New logs frst64\aswMBR.txt"

System: XP Pro x64 Edition
Ver 2003
Service Pack 2

not sure if i had to turn of or not

please let me know if more info is needed


Hi joselepiu,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for the issues on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.
Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.


Important information regarding Windows XP

Microsoft will no longer offer support for Windows XP beginning on April 8, 2014

If you are running Windows XP, please take the time to read the information provided at these links.

Windows XP - The Elephant In The Room (http://www.malwareremoval.com/forum/viewtopic.php?p=630064#p630064)[/*]
Windows XP - The end of the road (http://techpageone.dell.com/technology/windows-xp-end-road/?dgc=BA&cid=272099&lid=5049884&acd=12309189674467600#.UxUoP4W9Is3)[/*]


Please run these tools in Normal Mode unless instructed otherwise.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Uninstall via Add/Remove Programs

Please go to Start > Control Panel > Add Remove Programs.
Locate the following programs: (if present)

AVG Secure Search
AVG SafeGuard toolbar

Click Remove and allow Windows to completely remove each one in turn.
Then reboot your computer to complete this part of the process.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye2_zpse2245433.png.html) Disable Plug-ins in Google Chrome

Click the Chrome menu http://i1269.photobucket.com/albums/jj590/OCD-WTT/chromebrowsertoolbar.png on the browser toolbar.
Select Settings.
Scroll down to Show advanced settings...
Locate the Privacy Section, select Content Settings
In the pop up window scoll to Plug-Ins, select Disable individual plug-ins...
Locate the following plug-ins and set them to Disable:

AVG SiteSafety plugin

Exit Chrome settings menu.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) FRST Fix Script

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the desktop as fixlist.txt

HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2640408 2014-08-11] ()
HKLM\...\Command Processor: <======= ATTENTION
HKLM-x32\...\Command Processor: <======= ATTENTION
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={78CBEA97-1813-44AE-A46F-4CD435A77274}&mid=63957768860347d38e83d1a90bf8bb87-8d758629d5135f4470f57152dc116841b6490bd7&lang=en&ds=AVG&pr=fr&d=2013-05-25 00:51:20&v={searchTerms}
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
Toolbar: HKLM-x32 - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search)
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.0.0\\npsitesafety.dll (AVG Technologies)
S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-11] (AVG Secure Search)
C:\Windows\System32\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!.
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rel.job => C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rmv.job => C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST and press the Fix button just once and wait.
The tool will make a log (Fixlog.txt) please post it to your reply.


In your next post please provide the following:


i found the avg safeguard toolbar program and i did removed it...

i did not find the avg secure search program there...

i did not find the avg sitesafety plugin, attached is a pic of the plugins listed there...

and here is the FRST log:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-08-2014
Ran by DJ RAC at 2014-08-15 11:17:31 Run:2
Running from C:\Documents and Settings\DJ RAC\Desktop
Boot Mode: Normal

Content of fixlist:
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2640408 2014-08-11] ()
HKLM\...\Command Processor: <======= ATTENTION
HKLM-x32\...\Command Processor: <======= ATTENTION
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={78CBEA97-1813-44AE-A46F-4CD435A77274}&mid=63957768860347d38e83d1a90bf8bb87-8d758629d5135f4470f57152dc116841b6490bd7&lang=en&ds=AVG&pr=fr&d=2013-05-25 00:51:20&v={searchTerms}
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
Toolbar: HKLM-x32 - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search)
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.0.0\\npsitesafety.dll (AVG Technologies)
S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-11] (AVG Secure Search)
C:\Windows\System32\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!.
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rel.job => C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rmv.job => C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\vProt => Value not found.
HKLM\Software\Microsoft\Command Processor\\AutoRun => Value not found.
HKLM\Software\Wow6432Node\Microsoft\Command Processor\\AutoRun => Value not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found.
"HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found.
"HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} => Value not found.
"HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => value deleted successfully.
"HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}" => Key not found.
"HKCR\Wow6432Node\PROTOCOLS\Handler\viprotocol" => Key not found.
"HKCR\Wow6432Node\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}" => Key not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=,application/x-avg-sitesafety-plugin" => Key not found.
C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll not found.
C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.0.0\\npsitesafety.dll not found.
vToolbarUpdater18.1.9 => Service not found.
"C:\Windows\System32\wininit.exe IS MISSING <==== ATTENTION!." => File/Directory not found.
"C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!." => File/Directory not found.
"C:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!." => File/Directory not found.
C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rel.job => Moved successfully.
C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rmv.job => Moved successfully.

==== End of Fixlog ====

Hi joselepiu,

http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) SystemLook

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1 (http://jpshortstuff.247fixes.com/SystemLook.exe)
Download Mirror #2 (http://images.malwareremoval.com/jpshortstuff/SystemLook.exe)

Double-click SystemLook.exe to run it.
Copy the content of the following codebox into the main textfield:


Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) AdwCleaner v3: Scan & Clean (http://www.bleepingcomputer.com/download/adwcleaner/)

Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"

Click on the Scan button.
AdwCleaner will begin to scan your computer like it did before.
After the scan has finished...
Click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
After rebooting, a log file report (AdwCleaner[S0].txt) will open automatically.
Copy and paste the contents of that log file in your next reply.
A copy of that log file will also be saved in the C:\AdwCleaner folder.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Junkware Removal Tool

Download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.

Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"

Shut down your protection software now to avoid potential conflicts.
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Re-run Farbar Recovery Scan Tool it should be on your desktop.

Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"

When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.

In your next post please provide the following:


hello again

i ran the systemLook program & copied the requested text on it...

and it says "" Use SystemLook_x64 for accurate results ""...

ran the adwcleaner v3: Scan & Clean program...

on your instructions it says "" adwcleaner will begin to scan your computer like it did before.""...

it was the 1st time i ran it...

ran the junkware removal tool program...

turn off svg & spybot 2 and reboot comp to turn them on after this scan...

ran the farbar recovery scan tool program again & it updated itself...

i been getting a pop up message that adobe reader needs to update i have not updated it...

avg updated itself could not stop it...

here are all the scan logs (systemlook, adwcleaner, junkware removal tool, farbar recovery scan tool)...


SystemLook 30.07.11 by jpshortstuff
Log created at 15:47 on 16/08/2014 by DJ RAC
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.

========== filefind ==========

Searching for "wininit.exe "
No files found.

Searching for "Bootcat.cache"
No files found.

-= EOF =-



# AdwCleaner v3.306 - Report created 16/08/2014 at 15:57:16
# Updated 15/08/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 2 (64 bits)
# Username : DJ RAC
# Running from : C:\Documents and Settings\DJ RAC\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\apn
Folder Deleted : C:\Program Files (x86)\AVG SafeGuard toolbar
Folder Deleted : C:\Documents and Settings\Administrator\Application Data\AVG SafeGuard toolbar
Folder Deleted : C:\Documents and Settings\Lety\Application Data\AVG SafeGuard toolbar
Folder Deleted : C:\Documents and Settings\Prisc & Vane\Application Data\AVG SafeGuard toolbar
[!] Folder Deleted : C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dpjamkmjmigaoobjbekmfgabipmfilij
[!] Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
File Deleted : C:\WINDOWS\System32\GroupPolicy\User\Registry.pol
File Deleted : C:\DOCUME~1\DJRAC~1\LOCALS~1\Temp\Uninstall.exe

***** [ Scheduled Tasks ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe]

***** [ Browsers ] *****

-\\ Internet Explorer v7.0.5730.13

-\\ Mozilla Firefox v30.0 (en-US)

[ File : C:\Documents and Settings\DJ RAC\Application Data\Mozilla\Firefox\Profiles\afjw053j.default\prefs.js ]

-\\ Google Chrome v36.0.1985.143

[ File : C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]

Deleted [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej
Deleted [Extension] : kincjchfokkeneeofpeefomkikfkiedl
Deleted [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof

[ File : C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Deleted [Extension] : dpjamkmjmigaoobjbekmfgabipmfilij
Deleted [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof

[ File : C:\Documents and Settings\Lety\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Deleted [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof

[ File : C:\Documents and Settings\Prisc & Vane\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]

Deleted [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo
Deleted [Extension] : fbmimoidopbghbcmdmpkjaffffmcbmbg
Deleted [Extension] : hphibigbodkkohoglgfkddblldpfohjl
Deleted [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej
Deleted [Extension] : kincjchfokkeneeofpeefomkikfkiedl
Deleted [Extension] : kkkeikdkpjenmoiicggnnodbkebafgpc
Deleted [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
Deleted [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc


AdwCleaner[R0].txt - [4024 octets] - [16/08/2014 15:51:57]
AdwCleaner[S0].txt - [4167 octets] - [16/08/2014 15:57:16]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4227 octets] ##########


junkware removal tool:

Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Microsoft Windows XP x64
Ran by DJ RAC on Sat 08/16/2014 at 16:06:20.20

~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

Scan was completed on Sat 08/16/2014 at 16:12:19.85
End of JRT log


farbar recovery scan tool:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-08-2014 04
Ran by DJ RAC (administrator) on DJ-RAC-PUTTER on 16-08-2014 16:53:12
Running from C:\Documents and Settings\DJ RAC\Desktop
Platform: Microsoft Windows XP Service Pack 2 (X64) OS Language: English (United States)
Internet Explorer Version 7
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [577536 2006-08-03] (Realtek Semiconductor Corp.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5187088 2014-07-10] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Winlogon: [Userinit] userinit, [X]
HKLM\...\Winlogon: [UIHost] C:\Windows\system32\logonui.exe [662016 2007-02-17] ( (Microsoft Corporation))
Winlogon\Notify\crypt32chain: C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
Winlogon\Notify\cryptnet: C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
Winlogon\Notify\cscdll: C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
Winlogon\Notify\dimsntfy: C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
Winlogon\Notify\ScCertProp: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\Schedule: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\sclgntfy: C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\SensLogn: C:\WINDOWS\system32\WlNotify.dll (Microsoft Corporation)
Winlogon\Notify\termsrv: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\wlballoon: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\crypt32chain-x32: C:\WINDOWS\SysWOW64\crypt32.dll (Microsoft Corporation)
Winlogon\Notify\cryptnet-x32: C:\WINDOWS\SysWOW64\cryptnet.dll (Microsoft Corporation)
Winlogon\Notify\cscdll-x32: C:\WINDOWS\SysWOW64\cscdll.dll (Microsoft Corporation)
Winlogon\Notify\dimsntfy-x32: C:\WINDOWS\SysWOW64\dimsntfy.dll (Microsoft Corporation)
Winlogon\Notify\EFS-x32: C:\WINDOWS\SysWOW64\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\ScCertProp-x32: wlnotify.dll [X]
Winlogon\Notify\Schedule-x32: wlnotify.dll [X]
Winlogon\Notify\sclgntfy-x32: C:\WINDOWS\SysWOW64\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
Winlogon\Notify\SensLogn-x32: WlNotify.dll [X]
Winlogon\Notify\wlballoon-x32: wlnotify.dll [X]
HKU\.DEFAULT\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-19\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-21-2799395484-3895304042-2403659751-1002\...\MountPoints2: {2d27d8a5-3283-11e3-8e94-00e04d1c5274} - E:\LGAutoRun.exe
HKU\S-1-5-21-2799395484-3895304042-2403659751-1002\...\MountPoints2: {e39d701f-90fe-11e2-9c15-00e04d1c5274} - D:\LaunchU3.exe -a
IFEO\Your Image File Name Here without a path: [Debugger] ntsd -d
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
SSODL-x32: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\syswow64\SHELL32.dll (Microsoft Corporation)
SSODL-x32: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\syswow64\SHELL32.dll (Microsoft Corporation)
SSODL-x32: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\SysWOW64\stobject.dll (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean64.exeC:\PROGRA~2\AVG\AVG2014\avgrsa.exe /sync /restart

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
DPF: HKLM-x32 {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1363890949984
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\Windows\system32\mshtml.dll (Microsoft Corporation)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\Windows\SysWow64\mshtml.dll (Microsoft Corporation)
Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Filter-x32: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Filter-x32: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Filter-x32: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\Windows\SysWow64\SHELL32.dll (Microsoft Corporation)
ShellExecuteHooks: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [10508288 2009-02-10] (Microsoft Corporation)
ShellExecuteHooks-x32: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\SysWOW64\shell32.dll [8360960 2009-02-10] (Microsoft Corporation)
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\mswsock.dll [233472] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 03 %SystemRoot%\System32\mswsock.dll [492544] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Documents and Settings\DJ RAC\Application Data\Mozilla\Firefox\Profiles\afjw053j.default
FF Homepage: about:newtab
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VLC Media Player 2 0 8 win32\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

CHR HomePage:
CHR Plugin: (Widevine Content Decryption Module) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\WidevineCDM\\_platform_specific\win_x86\widevinecdmadapter.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VLC Media Player 2 0 8 win32\npvlc.dll (VideoLAN)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
CHR Extension: (Google Drive) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-23]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-02]
CHR Extension: (YouTube) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-23]
CHR Extension: (Google Search) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-23]
CHR Extension: (Google Wallet) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Gmail) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-23]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AeLookupSvc; C:\Windows\SysWOW64\aelupsvc.dll [26624 2006-03-29] (Microsoft Corporation)
S4 Alerter; C:\Windows\system32\alrsvc.dll [29696 2006-03-29] (Microsoft Corporation)
R3 ALG; C:\Windows\SysWOW64\alg.exe [45056 2006-03-29] (Microsoft Corporation)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3244048 2014-07-10] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-07-10] (AVG Technologies CZ, s.r.o.)
S2 Browser; C:\Windows\SysWOW64\browser.dll [78336 2007-02-18] (Microsoft Corporation)
S3 ClipSrv; C:\Windows\system32\clipsrv.exe [49664 2006-03-29] (Microsoft Corporation)
S3 ClipSrv; C:\Windows\SysWOW64\clipsrv.exe [32256 2006-03-29] (Microsoft Corporation)
R2 dmadmin; C:\Windows\System32\dmadmin.exe [399872 2007-02-17] (Microsoft Corporation)
R2 dmserver; C:\Windows\System32\dmserver.dll [37376 2007-02-17] (Microsoft Corporation)
R2 ERSvc; C:\Windows\System32\ersvc.dll [31744 2006-03-29] (Microsoft Corporation)
R2 helpsvc; C:\Windows\PCHealth\HelpCtr\Binaries\pchsvc.dll [77312 2007-02-17] (Microsoft Corporation)
S3 HTTPFilter; C:\Windows\System32\w3ssl.dll [21504 2006-03-29] (Microsoft Corporation)
S3 IASJet; C:\Windows\SysWOW64\iasrecst.dll [162816 2006-03-29] (Microsoft Corporation)
S3 ImapiService; C:\WINDOWS\system32\imapi.exe [265728 2007-02-17] (Microsoft Corporation)
S4 Messenger; C:\Windows\System32\msgsvc.dll [57344 2007-02-17] (Microsoft Corporation)
S3 mnmsrvc; C:\WINDOWS\SysWOW64\mnmsrvc.exe [32768 2006-03-29] (Microsoft Corporation)
S3 NetDDE; C:\Windows\system32\netdde.exe [160768 2007-02-17] (Microsoft Corporation)
S3 NetDDEdsdm; C:\Windows\system32\netdde.exe [160768 2007-02-17] (Microsoft Corporation)
R3 Netman; C:\Windows\SysWOW64\netman.dll [263680 2007-02-18] (Microsoft Corporation)
R3 Nla; C:\Windows\System32\mswsock.dll [492544 2008-06-21] (Microsoft Corporation)
R3 Nla; C:\Windows\SysWOW64\mswsock.dll [233472 2008-06-21] (Microsoft Corporation)
S3 NtLmSsp; C:\Windows\system32\lsass.exe [14336 2006-03-29] (Microsoft Corporation)
R2 NtmsSvc; C:\Windows\system32\ntmssvc.dll [794112 2007-02-17] (Microsoft Corporation)
R2 NVSvc; C:\Windows\system32\nvsvc64.exe [135680 2006-03-31] (NVIDIA Corporation)
R2 PlugPlay; C:\Windows\system32\services.exe [227840 2009-03-19] (Microsoft Corporation)
R2 PolicyAgent; C:\Windows\system32\lsass.exe [14336 2006-03-29] (Microsoft Corporation)
S3 RasAuto; C:\Windows\SysWOW64\rasauto.dll [91648 2007-02-18] (Microsoft Corporation)
R3 RasMan; C:\Windows\SysWOW64\rasmans.dll [181760 2007-02-18] (Microsoft Corporation)
S3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [212480 2007-02-17] (Microsoft Corporation)
S3 RpcLocator; C:\Windows\SysWOW64\locator.exe [71680 2006-03-29] (Microsoft Corporation)
S3 SCardSvr; C:\Windows\System32\SCardSvr.exe [166400 2007-02-17] (Microsoft Corporation)
R2 Schedule; C:\Windows\SysWOW64\schedsvc.dll [202240 2007-02-18] (Microsoft Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
R2 seclogon; C:\Windows\SysWOW64\seclogon.dll [18432 2007-02-18] (Microsoft Corporation)
R2 srservice; C:\WINDOWS\system32\srsvc.dll [231424 2007-02-17] (Microsoft Corporation)
S2 SysmonLog; C:\Windows\system32\smlogsvc.exe [133120 2007-02-17] (Microsoft Corporation)
S2 SysmonLog; C:\Windows\SysWOW64\smlogsvc.exe [96256 2007-02-18] (Microsoft Corporation)
S4 TlntSvr; C:\WINDOWS\system32\tlntsvr.exe [113152 2007-02-17] (Microsoft Corporation)
R2 TrkWks; C:\Windows\SysWOW64\trkwks.dll [86528 2007-02-18] (Microsoft Corporation)
R2 UMWdf; C:\WINDOWS\system32\wdfmgr.exe [62976 2006-03-29] (Microsoft Corporation)
R2 UMWdf; C:\WINDOWS\SysWOW64\wdfmgr.exe [39424 2006-03-29] (Microsoft Corporation)
S3 UPS; C:\Windows\System32\ups.exe [34816 2006-03-29] (Microsoft Corporation)
S3 UPS; C:\Windows\SysWOW64\ups.exe [16896 2006-03-29] (Microsoft Corporation)
S3 WmdmPmSN; C:\WINDOWS\system32\mspmsnsv.dll [36352 2007-02-17] (Microsoft Corporation)
S3 Wmi; C:\Windows\System32\advapi32.dll [1052160 2009-03-19] (Microsoft Corporation)
S3 Wmi; C:\Windows\SysWOW64\advapi32.dll [619008 2009-03-19] (Microsoft Corporation)
U2 wuauserv; C:\WINDOWS\system32\wuauserv.dll [12288 2006-03-29] (Microsoft Corporation)
R2 WZCSVC; C:\Windows\System32\wzcsvc.dll [659968 2007-02-17] (Microsoft Corporation)
R2 WZCSVC; C:\Windows\SysWOW64\wzcsvc.dll [489472 2007-02-18] (Microsoft Corporation)
S3 xmlprov; C:\Windows\System32\xmlprov.dll [326144 2007-02-17] (Microsoft Corporation)
S3 xmlprov; C:\Windows\SysWOW64\xmlprov.dll [131584 2007-02-18] (Microsoft Corporation)
R2 Eventlog; [X]
S4 HidServ; %SystemRoot%\System32\hidserv.dll [X]
S3 WinHttpAutoProxySvc; winhttp.dll [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 Abiosdsk; No ImagePath
S4 ACPIEC; C:\Windows\System32\Drivers\ACPIEC.sys [18432 2006-03-29] (Microsoft Corporation)
S4 adpu160m; No ImagePath
S4 adpu320; No ImagePath
R3 aec; C:\Windows\System32\drivers\aec.sys [188928 2005-03-24] (Microsoft Corporation)
S4 aic78u2; No ImagePath
S4 aic78xx; No ImagePath
R3 ALCXWDM; C:\Windows\System32\drivers\ALCWDM64.SYS [3304448 2006-10-13] (Realtek Semiconductor Corp.)
S4 AliIde; No ImagePath
S4 AmdIde; No ImagePath
R1 AmdK8; C:\Windows\System32\DRIVERS\amdk8.sys [51200 2006-05-10] (Advanced Micro Devices)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2013-04-18] (Google Inc)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S4 arc; No ImagePath
S4 Atdisk; No ImagePath
S3 Atmarpc; C:\Windows\System32\DRIVERS\atmarpc.sys [106496 2007-02-17] (Microsoft Corporation)
R3 audstub; C:\Windows\System32\DRIVERS\audstub.sys [5632 2005-03-24] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriverl; C:\Windows\System32\DRIVERS\avgidsdriverla.sys [227608 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 BIOS; C:\WINDOWS\system32\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
R1 BIOS; C:\WINDOWS\SysWOW64\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
R2 CdaC15BA; C:\Windows\System32\DRIVERS\CdaC15BA.sys [13312 2006-03-29] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
R2 CdaD10BA; C:\Windows\System32\DRIVERS\CdaD10BA.sys [13312 2006-03-29] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
S1 Changer; No ImagePath
S4 CmdIde; No ImagePath
S4 dmboot; C:\Windows\System32\drivers\dmboot.sys [415232 2007-02-17] (Microsoft Corporation)
R0 dmio; C:\Windows\System32\drivers\dmio.sys [244224 2007-02-17] (Microsoft Corporation)
R0 dmload; C:\Windows\System32\drivers\dmload.sys [9216 2006-03-29] (Microsoft Corporation)
S4 dpti2o; No ImagePath
R1 Fips; C:\Windows\System32\Drivers\Fips.sys [50176 2007-02-17] (Microsoft Corporation)
R0 Ftdisk; C:\Windows\System32\DRIVERS\ftdisk.sys [240128 2007-02-17] (Microsoft Corporation)
R3 Gpc; C:\Windows\System32\DRIVERS\msgpc.sys [71168 2007-02-17] (Microsoft Corporation)
S1 i2omgmt; No ImagePath
S4 iirsp; No ImagePath
R1 imapi; C:\Windows\System32\DRIVERS\imapi.sys [72704 2006-03-29] (Microsoft Corporation)
S4 IntelIde; No ImagePath
S3 Ip6Fw; C:\Windows\System32\drivers\ip6fw.sys [57856 2007-02-17] (Microsoft Corporation)
S3 IpInIp; No ImagePath
R1 IPSec; C:\Windows\System32\DRIVERS\ipsec.sys [156672 2007-02-17] (Microsoft Corporation)
R3 kmixer; C:\Windows\System32\drivers\kmixer.sys [204288 2005-03-24] (Microsoft Corporation)
R1 mnmdd; C:\Windows\System32\Drivers\mnmdd.sys [8192 2006-03-29] (Microsoft Corporation)
S4 mraid35x; No ImagePath
S3 MxlW2k; C:\Windows\SysWow64\Drivers\MxlW2k.sys [28276 2013-03-18] (MusicMatch, Inc.) [File not signed]
R3 nv; C:\Windows\System32\DRIVERS\nv4_mini.sys [4818944 2006-03-31] (NVIDIA Corporation)
R0 nvata64; C:\Windows\System32\DRIVERS\nvata64.sys [164864 2006-04-24] (NVIDIA Corporation)
R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [52736 2006-02-17] (NVIDIA Corporation)
R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [22016 2006-02-17] (NVIDIA Corporation)
S3 PDCOMP; No ImagePath
S3 PDFRAME; No ImagePath
S3 PDRELI; No ImagePath
S3 PDRFRAME; No ImagePath
R3 PSched; C:\Windows\System32\DRIVERS\psched.sys [106496 2007-02-17] (Microsoft Corporation)
R3 Ptilink; C:\Windows\System32\DRIVERS\ptilink.sys [31232 2006-03-29] (Parallel Technologies, Inc.)
S0 PxHelp64; C:\Windows\SysWOW64\DRIVERS\PxHelp64.sys [47872 2003-07-30] (Sonic Solutions) [File not signed]
R3 Raspti; C:\Windows\System32\DRIVERS\raspti.sys [31232 2006-03-29] (Microsoft Corporation)
R1 redbook; C:\Windows\System32\DRIVERS\redbook.sys [64000 2005-03-24] (Microsoft Corporation)
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [171008 2007-02-17] (Microsoft Corporation)
S4 Simbad; No ImagePath
R3 splitter; C:\Windows\System32\drivers\splitter.sys [10240 2007-02-17] (Microsoft Corporation)
R0 sr; C:\Windows\System32\DRIVERS\sr.sys [123904 2006-03-29] (Microsoft Corporation)
R3 swmidi; C:\Windows\System32\drivers\swmidi.sys [86528 2005-03-24] (Microsoft Corporation)
S4 symc8xx; No ImagePath
S4 symmpi; No ImagePath
S4 sym_hi; No ImagePath
S4 sym_u3; No ImagePath
R3 sysaudio; C:\Windows\System32\drivers\sysaudio.sys [147456 2007-02-17] (Microsoft Corporation)
S4 TosIde; No ImagePath
S4 ultra; No ImagePath
R3 Update; C:\Windows\System32\DRIVERS\update.sys [81920 2007-02-17] (Microsoft Corporation)
S4 ViaIde; No ImagePath
S3 WDICA; No ImagePath
R3 wdmaud; C:\Windows\System32\drivers\wdmaud.sys [187904 2007-02-17] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

NETSVCx32: Browser -> C:\Windows\SysWOW64\browser.dll (Microsoft Corporation)
NETSVCx32: CryptSvc -> C:\Windows\SysWOW64\cryptsvc.dll (Microsoft Corporation)
NETSVCx32: DMServer -> C:\Windows\SysWOW64\dmserver.dll ==> No File.
NETSVCx32: EventSystem -> C:\WINDOWS\SysWOW64\es.dll (Microsoft Corporation)
NETSVCx32: HidServ -> C:\Windows\SysWOW64\hidserv.dll ==> No File.
NETSVCx32: Iprip -> No ServiceDLL Path.
NETSVCx32: LanmanWorkstation -> C:\Windows\SysWOW64\wkssvc.dll ==> No File.
NETSVCx32: Messenger -> C:\Windows\SysWOW64\msgsvc.dll ==> No File.
NETSVCx32: Netman -> C:\Windows\SysWOW64\netman.dll (Microsoft Corporation)
NETSVCx32: Seclogon -> C:\Windows\SysWOW64\seclogon.dll (Microsoft Corporation)
NETSVCx32: TrkWks -> C:\Windows\SysWOW64\trkwks.dll (Microsoft Corporation)
NETSVCx32: WZCSVC -> C:\Windows\SysWOW64\wzcsvc.dll (Microsoft Corporation)
NETSVCx32: wscsvc -> C:\Windows\SysWOW64\wscsvc.dll ==> No File.
NETSVCx32: xmlprov -> C:\Windows\SysWOW64\xmlprov.dll (Microsoft Corporation)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-16 16:53 - 2014-08-16 16:53 - 00024680 _____ () C:\Documents and Settings\DJ RAC\Desktop\FRST.txt
2014-08-16 16:52 - 2014-08-16 16:52 - 02101760 _____ (Farbar) C:\Documents and Settings\DJ RAC\Desktop\FRST64.exe
2014-08-16 16:15 - 2014-08-16 16:17 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Desktop\FRST-OlderVersion
2014-08-16 16:12 - 2014-08-16 16:12 - 00000590 _____ () C:\Documents and Settings\DJ RAC\Desktop\JRT.txt
2014-08-16 16:06 - 2014-08-16 16:06 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-08-16 16:04 - 2014-08-16 16:04 - 01016261 _____ (Thisisu) C:\Documents and Settings\DJ RAC\Desktop\JRT.exe
2014-08-16 16:03 - 2014-08-16 16:03 - 00000019 _____ () C:\Documents and Settings\DJ RAC\Desktop\adobe reader update.txt
2014-08-16 16:02 - 2014-08-16 16:02 - 00004291 _____ () C:\Documents and Settings\DJ RAC\Desktop\AdwCleaner[S0].txt
2014-08-16 15:59 - 2014-08-16 15:59 - 00001286 _____ () C:\WINDOWS\PFRO.log
2014-08-16 15:53 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll
2014-08-16 15:51 - 2014-08-16 15:57 - 00000000 ____D () C:\AdwCleaner
2014-08-16 15:50 - 2014-08-16 15:51 - 01361203 _____ () C:\Documents and Settings\DJ RAC\Desktop\AdwCleaner.exe
2014-08-16 15:47 - 2014-08-16 15:48 - 00000696 _____ () C:\Documents and Settings\DJ RAC\Desktop\SystemLook.txt
2014-08-16 15:46 - 2014-08-16 16:29 - 00000000 _____ () C:\WINDOWS\0.log
2014-08-16 15:27 - 2014-08-16 15:27 - 00139264 _____ () C:\Documents and Settings\DJ RAC\Desktop\SystemLook.exe
2014-08-16 14:03 - 2014-08-16 16:27 - 00006005 _____ () C:\WINDOWS\WindowsUpdate.log
2014-08-15 11:13 - 2014-08-15 11:13 - 02100224 _____ (Farbar) C:\Documents and Settings\DJ RAC\Desktop\Farbar Recovery Scan Tool - FRST64.exe
2014-08-13 17:35 - 2014-08-16 16:53 - 00000000 ____D () C:\FRST
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\RegBackup
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com
2014-08-13 17:27 - 2014-08-13 17:27 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-08-13 08:27 - 2014-06-19 12:47 - 00450613 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140813-082716.backup
2014-07-25 03:02 - 2014-08-16 16:02 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-16 16:53 - 2014-08-16 16:53 - 00024680 _____ () C:\Documents and Settings\DJ RAC\Desktop\FRST.txt
2014-08-16 16:53 - 2014-08-13 17:35 - 00000000 ____D () C:\FRST
2014-08-16 16:53 - 2013-03-20 20:30 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Local Settings\Temp
2014-08-16 16:52 - 2014-08-16 16:52 - 02101760 _____ (Farbar) C:\Documents and Settings\DJ RAC\Desktop\FRST64.exe
2014-08-16 16:40 - 2014-06-18 14:13 - 00000442 _____ () C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1403122415.job
2014-08-16 16:40 - 2013-10-09 18:28 - 00000894 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-16 16:40 - 2013-03-20 12:12 - 00000632 _____ () C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
2014-08-16 16:40 - 2013-03-18 07:35 - 00050257 _____ () C:\WINDOWS\system32\nvapps.xml
2014-08-16 16:40 - 2013-03-18 07:24 - 00032514 _____ () C:\WINDOWS\Tasks\SchedLgU.Txt
2014-08-16 16:40 - 2006-03-29 06:00 - 00002422 _____ () C:\WINDOWS\system32\wpa.dbl
2014-08-16 16:29 - 2014-08-16 15:46 - 00000000 _____ () C:\WINDOWS\0.log
2014-08-16 16:27 - 2014-08-16 14:03 - 00006005 _____ () C:\WINDOWS\WindowsUpdate.log
2014-08-16 16:27 - 2013-03-19 14:13 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2014-08-16 16:27 - 2013-03-18 07:24 - 00000157 _____ () C:\Documents and Settings\LocalService\wiadebug.log
2014-08-16 16:27 - 2013-03-18 07:24 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-08-16 16:26 - 2013-03-20 12:12 - 00524288 _____ () C:\WINDOWS\system32\config\SpybotSD.evt
2014-08-16 16:25 - 2013-03-20 20:30 - 00000178 ___SH () C:\Documents and Settings\DJ RAC\ntuser.ini
2014-08-16 16:17 - 2014-08-16 16:15 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Desktop\FRST-OlderVersion
2014-08-16 16:12 - 2014-08-16 16:12 - 00000590 _____ () C:\Documents and Settings\DJ RAC\Desktop\JRT.txt
2014-08-16 16:07 - 2013-10-09 18:28 - 00000898 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-16 16:06 - 2014-08-16 16:06 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-08-16 16:04 - 2014-08-16 16:04 - 01016261 _____ (Thisisu) C:\Documents and Settings\DJ RAC\Desktop\JRT.exe
2014-08-16 16:03 - 2014-08-16 16:03 - 00000019 _____ () C:\Documents and Settings\DJ RAC\Desktop\adobe reader update.txt
2014-08-16 16:02 - 2014-08-16 16:02 - 00004291 _____ () C:\Documents and Settings\DJ RAC\Desktop\AdwCleaner[S0].txt
2014-08-16 16:02 - 2014-07-25 03:02 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-08-16 15:59 - 2014-08-16 15:59 - 00001286 _____ () C:\WINDOWS\PFRO.log
2014-08-16 15:57 - 2014-08-16 15:51 - 00000000 ____D () C:\AdwCleaner
2014-08-16 15:51 - 2014-08-16 15:50 - 01361203 _____ () C:\Documents and Settings\DJ RAC\Desktop\AdwCleaner.exe
2014-08-16 15:48 - 2014-08-16 15:47 - 00000696 _____ () C:\Documents and Settings\DJ RAC\Desktop\SystemLook.txt
2014-08-16 15:42 - 2013-03-20 20:30 - 00000000 ____D () C:\Documents and Settings\DJ RAC
2014-08-16 15:27 - 2014-08-16 15:27 - 00139264 _____ () C:\Documents and Settings\DJ RAC\Desktop\SystemLook.exe
2014-08-16 14:15 - 2014-04-03 13:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 30 0
2014-08-16 13:33 - 2013-03-20 20:30 - 00000265 _____ () C:\Documents and Settings\DJ RAC\wiadebug.log
2014-08-16 13:29 - 2013-03-18 13:22 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MFAData
2014-08-15 12:15 - 2013-09-10 02:18 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Application Data\vlc
2014-08-15 11:13 - 2014-08-15 11:13 - 02100224 _____ (Farbar) C:\Documents and Settings\DJ RAC\Desktop\Farbar Recovery Scan Tool - FRST64.exe
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\RegBackup
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com
2014-08-13 17:27 - 2014-08-13 17:27 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-08-13 08:13 - 2013-03-20 12:12 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-08-13 00:30 - 2013-03-20 12:12 - 00000628 _____ () C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2014-08-12 14:39 - 2014-06-18 14:13 - 00000000 ____D () C:\Program Files (x86)\Opera 22 0 1471 70
2014-08-11 20:41 - 2013-05-20 17:57 - 00000000 ____D () C:\WINDOWS\SysWOW64\cache
2014-08-04 15:12 - 2013-03-20 20:52 - 00000178 ___SH () C:\Documents and Settings\Lety\ntuser.ini
2014-08-04 15:11 - 2013-03-20 20:52 - 00000000 ____D () C:\Documents and Settings\Lety\Local Settings\Temp
2014-08-04 15:03 - 2013-03-20 20:52 - 00000265 _____ () C:\Documents and Settings\Lety\wiadebug.log
2014-08-04 10:17 - 2014-05-01 09:12 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2014 Ver 2014 0 4744
2014-08-01 00:30 - 2013-03-20 12:12 - 00000458 _____ () C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
2014-07-31 15:32 - 2013-03-18 17:32 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\TEMP
2014-07-25 03:02 - 2013-03-18 13:20 - 00699056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-07-25 03:02 - 2013-03-18 13:20 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

Some content of TEMP:
C:\Documents and Settings\DJ RAC\Local Settings\Temp\Quarantine.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
C:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!.

==================== End Of Log ============================

Hi joselepiu,

i ran the systemLook program & copied the requested text on it...

and it says "" Use SystemLook_x64 for accurate results ""...

Try this version and re-run SystemLook

http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) SystemLook

Please download SystemLook (http://images.malwareremoval.com/jpshortstuff/SystemLook_x64.exe) and save it to your Desktop.

Double-click SystemLook.exe to run it.
Copy the content of the following codebox into the main textfield:


Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


In your next post please provide the following:

Any change in performance?
Do you have your XP installation disks?

the performance is still the same i think...

the sound from the hard drives is still there & the green light does not go away...

and yes i do have the original installation disks...

here is the systemlook_x64 scan log:

SystemLook 30.07.11 by jpshortstuff
Log created at 20:42 on 16/08/2014 by DJ RAC
Administrator - Elevation successful

========== filefind ==========

Searching for "wininit.exe "
No files found.

Searching for "Bootcat.cache"
No files found.

-= EOF =-

Hi joselepiu,

You have a few files that are missing. Although I doubt they are causing the issues you are encountering let's see if we can fix the issue. Please have your Windows XP installation CD available when you proceed with this next step, you may be requested to insert a disk in the drive bay.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) System File Checker

Click Start, in the run box:
Type: sfc /scannow (There's a space between sfc and /scannow.)
Allow the scan to complete.
Type: exit to close the command prompt window
Include the findings in your next reply


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Reboot


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Re-run Farbar Recovery Scan Tool it should be on your desktop.

Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"

When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.

In your next post please provide the following:

sfc scan results
new FRST.txt

did the system file checker scan...

it did asked me for the disk...

but it closed & reboot the comp by itself...

did not produce any logs...

did not showed where to type ""exit""...

here is the new FRST scan log:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-08-2014 04
Ran by DJ RAC (administrator) on DJ-RAC-PUTTER on 16-08-2014 23:11:34
Running from C:\Documents and Settings\DJ RAC\Desktop
Platform: Microsoft Windows XP Service Pack 2 (X64) OS Language: English (United States)
Internet Explorer Version 7
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [577536 2006-08-03] (Realtek Semiconductor Corp.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5187088 2014-08-11] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Winlogon: [Userinit] userinit, [X]
HKLM\...\Winlogon: [UIHost] C:\Windows\system32\logonui.exe [662016 2007-02-17] ( (Microsoft Corporation))
Winlogon\Notify\crypt32chain: C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
Winlogon\Notify\cryptnet: C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
Winlogon\Notify\cscdll: C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
Winlogon\Notify\dimsntfy: C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
Winlogon\Notify\ScCertProp: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\Schedule: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\sclgntfy: C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\SensLogn: C:\WINDOWS\system32\WlNotify.dll (Microsoft Corporation)
Winlogon\Notify\termsrv: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\wlballoon: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\crypt32chain-x32: C:\WINDOWS\SysWOW64\crypt32.dll (Microsoft Corporation)
Winlogon\Notify\cryptnet-x32: C:\WINDOWS\SysWOW64\cryptnet.dll (Microsoft Corporation)
Winlogon\Notify\cscdll-x32: C:\WINDOWS\SysWOW64\cscdll.dll (Microsoft Corporation)
Winlogon\Notify\dimsntfy-x32: C:\WINDOWS\SysWOW64\dimsntfy.dll (Microsoft Corporation)
Winlogon\Notify\EFS-x32: C:\WINDOWS\SysWOW64\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\ScCertProp-x32: wlnotify.dll [X]
Winlogon\Notify\Schedule-x32: wlnotify.dll [X]
Winlogon\Notify\sclgntfy-x32: C:\WINDOWS\SysWOW64\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
Winlogon\Notify\SensLogn-x32: WlNotify.dll [X]
Winlogon\Notify\wlballoon-x32: wlnotify.dll [X]
HKU\.DEFAULT\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-19\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-21-2799395484-3895304042-2403659751-1002\...\MountPoints2: {2d27d8a5-3283-11e3-8e94-00e04d1c5274} - E:\LGAutoRun.exe
HKU\S-1-5-21-2799395484-3895304042-2403659751-1002\...\MountPoints2: {e39d701f-90fe-11e2-9c15-00e04d1c5274} - D:\LaunchU3.exe -a
IFEO\Your Image File Name Here without a path: [Debugger] ntsd -d
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
SSODL-x32: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\syswow64\SHELL32.dll (Microsoft Corporation)
SSODL-x32: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\syswow64\SHELL32.dll (Microsoft Corporation)
SSODL-x32: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\SysWOW64\stobject.dll (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean64.exeC:\PROGRA~2\AVG\AVG2014\avgrsa.exe /sync /restart

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
DPF: HKLM-x32 {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1363890949984
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\Windows\system32\mshtml.dll (Microsoft Corporation)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\Windows\SysWow64\mshtml.dll (Microsoft Corporation)
Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Filter-x32: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Filter-x32: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Filter-x32: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\Windows\SysWow64\SHELL32.dll (Microsoft Corporation)
ShellExecuteHooks: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [10505728 2007-02-17] (Microsoft Corporation)
ShellExecuteHooks-x32: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\SysWOW64\shell32.dll [8359936 2007-02-18] (Microsoft Corporation)
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\mswsock.dll [233472] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 03 %SystemRoot%\System32\mswsock.dll [492544] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Documents and Settings\DJ RAC\Application Data\Mozilla\Firefox\Profiles\afjw053j.default
FF Homepage: about:newtab
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VLC Media Player 2 0 8 win32\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

CHR HomePage:
CHR Plugin: (Widevine Content Decryption Module) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\WidevineCDM\\_platform_specific\win_x86\widevinecdmadapter.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VLC Media Player 2 0 8 win32\npvlc.dll (VideoLAN)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
CHR Extension: (Google Drive) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-23]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-02]
CHR Extension: (YouTube) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-23]
CHR Extension: (Google Search) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-23]
CHR Extension: (Google Wallet) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Gmail) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-23]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AeLookupSvc; C:\Windows\SysWOW64\aelupsvc.dll [26624 2006-03-29] (Microsoft Corporation)
S4 Alerter; C:\Windows\system32\alrsvc.dll [29696 2006-03-29] (Microsoft Corporation)
R3 ALG; C:\Windows\SysWOW64\alg.exe [45056 2006-03-29] (Microsoft Corporation)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3244048 2014-08-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-11] (AVG Technologies CZ, s.r.o.)
S2 Browser; C:\Windows\SysWOW64\browser.dll [78336 2007-02-18] (Microsoft Corporation)
S3 ClipSrv; C:\Windows\system32\clipsrv.exe [49664 2006-03-29] (Microsoft Corporation)
S3 ClipSrv; C:\Windows\SysWOW64\clipsrv.exe [32256 2006-03-29] (Microsoft Corporation)
R2 dmadmin; C:\Windows\System32\dmadmin.exe [399872 2007-02-17] (Microsoft Corporation)
R2 dmserver; C:\Windows\System32\dmserver.dll [37376 2007-02-17] (Microsoft Corporation)
R2 ERSvc; C:\Windows\System32\ersvc.dll [31744 2006-03-29] (Microsoft Corporation)
R2 helpsvc; C:\Windows\PCHealth\HelpCtr\Binaries\pchsvc.dll [77312 2007-02-17] (Microsoft Corporation)
S3 HTTPFilter; C:\Windows\System32\w3ssl.dll [21504 2006-03-29] (Microsoft Corporation)
S3 IASJet; C:\Windows\SysWOW64\iasrecst.dll [162816 2006-03-29] (Microsoft Corporation)
S3 ImapiService; C:\WINDOWS\system32\imapi.exe [265728 2007-02-17] (Microsoft Corporation)
S4 Messenger; C:\Windows\System32\msgsvc.dll [57344 2007-02-17] (Microsoft Corporation)
S3 mnmsrvc; C:\WINDOWS\SysWOW64\mnmsrvc.exe [32768 2006-03-29] (Microsoft Corporation)
S3 NetDDE; C:\Windows\system32\netdde.exe [160768 2007-02-17] (Microsoft Corporation)
S3 NetDDEdsdm; C:\Windows\system32\netdde.exe [160768 2007-02-17] (Microsoft Corporation)
R3 Netman; C:\Windows\SysWOW64\netman.dll [263680 2007-02-18] (Microsoft Corporation)
R3 Nla; C:\Windows\System32\mswsock.dll [492544 2008-06-21] (Microsoft Corporation)
R3 Nla; C:\Windows\SysWOW64\mswsock.dll [233472 2008-06-21] (Microsoft Corporation)
S3 NtLmSsp; C:\Windows\system32\lsass.exe [14336 2006-03-29] (Microsoft Corporation)
R2 NtmsSvc; C:\Windows\system32\ntmssvc.dll [794112 2007-02-17] (Microsoft Corporation)
R2 NVSvc; C:\Windows\system32\nvsvc64.exe [135680 2006-03-31] (NVIDIA Corporation)
R2 PlugPlay; C:\Windows\system32\services.exe [227840 2009-03-19] (Microsoft Corporation)
R2 PolicyAgent; C:\Windows\system32\lsass.exe [14336 2006-03-29] (Microsoft Corporation)
S3 RasAuto; C:\Windows\SysWOW64\rasauto.dll [91648 2007-02-18] (Microsoft Corporation)
R3 RasMan; C:\Windows\SysWOW64\rasmans.dll [181760 2007-02-18] (Microsoft Corporation)
S3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [212480 2007-02-17] (Microsoft Corporation)
S3 RpcLocator; C:\Windows\SysWOW64\locator.exe [71680 2006-03-29] (Microsoft Corporation)
S3 SCardSvr; C:\Windows\System32\SCardSvr.exe [166400 2007-02-17] (Microsoft Corporation)
R2 Schedule; C:\Windows\SysWOW64\schedsvc.dll [202240 2007-02-18] (Microsoft Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
R2 seclogon; C:\Windows\SysWOW64\seclogon.dll [18432 2007-02-18] (Microsoft Corporation)
R2 srservice; C:\WINDOWS\system32\srsvc.dll [231424 2007-02-17] (Microsoft Corporation)
S2 SysmonLog; C:\Windows\system32\smlogsvc.exe [133120 2007-02-17] (Microsoft Corporation)
S2 SysmonLog; C:\Windows\SysWOW64\smlogsvc.exe [96256 2007-02-18] (Microsoft Corporation)
S4 TlntSvr; C:\WINDOWS\system32\tlntsvr.exe [113152 2007-02-17] (Microsoft Corporation)
R2 TrkWks; C:\Windows\SysWOW64\trkwks.dll [86528 2007-02-18] (Microsoft Corporation)
R2 UMWdf; C:\WINDOWS\system32\wdfmgr.exe [62976 2006-03-29] (Microsoft Corporation)
R2 UMWdf; C:\WINDOWS\SysWOW64\wdfmgr.exe [39424 2006-03-29] (Microsoft Corporation)
S3 UPS; C:\Windows\System32\ups.exe [34816 2006-03-29] (Microsoft Corporation)
S3 UPS; C:\Windows\SysWOW64\ups.exe [16896 2006-03-29] (Microsoft Corporation)
S3 WmdmPmSN; C:\WINDOWS\system32\mspmsnsv.dll [36352 2007-02-17] (Microsoft Corporation)
S3 Wmi; C:\Windows\System32\advapi32.dll [1052160 2009-03-19] (Microsoft Corporation)
S3 Wmi; C:\Windows\SysWOW64\advapi32.dll [619008 2009-03-19] (Microsoft Corporation)
U2 wuauserv; C:\WINDOWS\system32\wuauserv.dll [12288 2006-03-29] (Microsoft Corporation)
R2 WZCSVC; C:\Windows\System32\wzcsvc.dll [659968 2007-02-17] (Microsoft Corporation)
R2 WZCSVC; C:\Windows\SysWOW64\wzcsvc.dll [489472 2007-02-18] (Microsoft Corporation)
S3 xmlprov; C:\Windows\System32\xmlprov.dll [326144 2007-02-17] (Microsoft Corporation)
S3 xmlprov; C:\Windows\SysWOW64\xmlprov.dll [131584 2007-02-18] (Microsoft Corporation)
R2 Eventlog; [X]
S4 HidServ; %SystemRoot%\System32\hidserv.dll [X]
S3 WinHttpAutoProxySvc; winhttp.dll [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 Abiosdsk; No ImagePath
S4 ACPIEC; C:\Windows\System32\Drivers\ACPIEC.sys [18432 2006-03-29] (Microsoft Corporation)
S4 adpu160m; No ImagePath
S4 adpu320; No ImagePath
S3 aec; C:\Windows\System32\drivers\aec.sys [188928 2005-03-24] (Microsoft Corporation)
S4 aic78u2; No ImagePath
S4 aic78xx; No ImagePath
R3 ALCXWDM; C:\Windows\System32\drivers\ALCWDM64.SYS [3304448 2006-10-13] (Realtek Semiconductor Corp.)
S4 AliIde; No ImagePath
S4 AmdIde; No ImagePath
R1 AmdK8; C:\Windows\System32\DRIVERS\amdk8.sys [51200 2006-05-10] (Advanced Micro Devices)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2013-04-18] (Google Inc)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S4 arc; No ImagePath
S4 Atdisk; No ImagePath
S3 Atmarpc; C:\Windows\System32\DRIVERS\atmarpc.sys [106496 2007-02-17] (Microsoft Corporation)
R3 audstub; C:\Windows\System32\DRIVERS\audstub.sys [5632 2005-03-24] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriverl; C:\Windows\System32\DRIVERS\avgidsdriverla.sys [227608 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
2014-08-17, 18:27
Hi joselepiu,

I was hoping that would replace the missing files, but it did not. Let's continue to make sure there is no malware on your system then we can redirect our efforts to correcting the file issue.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Malwarebytes' Anti-Malware

Download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam-download.php) (save it to your desktop).

Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"

Select Scan tab.
http://i1269.photobucket.com/albums/jj590/OCD-WTT/MBAMDashboard_zpsddef9b5f.gif (http://s1269.photobucket.com/user/OCD-WTT/media/MBAMDashboard_zpsddef9b5f.gif.html)
Select type of scan to perform:
http://i1269.photobucket.com/albums/jj590/OCD-WTT/MBAMScanTab_zps2c5e74bd.gif (http://s1269.photobucket.com/user/OCD-WTT/media/MBAMScanTab_zps2c5e74bd.gif.html)

Threat Scan < --- Select this type of scan
Custom Scan
Hyper Scan

Next click the Scan button.
When the scan is complete, if no malicious items are found you can close the program.
If malicious items are found be sure that everything is checked, and click Quarantine .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) ESET Online Scanner


It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.

** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner (http://www.eset.eu/online-scanner)

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Disable your Antivirus software. You can usually do this with its Notification Tray icon near the clock
Click Start
Make sure that the option "Remove found threats" is Checked, and the option "Scan unwanted applications" is Checked.
Click Scan.
Wait for the scan to finish.
When the scan completes, click List of found threats
click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
Include the contents of this report in your next reply

Note - when ESET doesn't find any threats, no report will be created.
Push the back button.
Push Finish
Re-enable your Antivirus software.


In your next post please provide the following:

MBAM log
ESET's log.txt
How's the computer running?

2014-08-18, 00:21
should i disable avg & spybot before running Malwarebytes Anti-Malware?...

2014-08-18, 04:23
Hi joselepiu,

should i disable avg & spybot before running Malwarebytes Anti-Malware?...

It's not necessary for MBAM, but it is for the ESET scan. :bigthumb:

2014-08-18, 04:36
scanning now...

2014-08-18, 06:03
Malwarebytes Anti-Malware

Scan Date: 8/17/2014
Scan Time: 7:30:34 PM
Administrator: Yes

Malware Database: v2014.08.17.05
Rootkit Database: v2014.08.16.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows XP Service Pack 2
CPU: x64
File System: NTFS
User: DJ RAC

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 388343
Time Elapsed: 12 min, 36 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)



ESET Online Scanner scan log:

C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Application Data\apn\APN-Stub\W3IV6-G\APNIC.7z.vir Win32/Bundled.Toolbar.Ask.B potentially unsafe application deleted - quarantined
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Application Data\apn\APN-Stub\W3IV6-G\APNIC.dll.vir Win32/Bundled.Toolbar.Ask.B potentially unsafe application deleted - quarantined
C:\Documents and Settings\DJ RAC\Desktop\Files & Folders\Tools\Installed\1-Click YouTube Downloader Ver 9 0 Setup.exe Win32/DownWare.W potentially unwanted application deleted - quarantined
C:\Documents and Settings\DJ RAC\Desktop\Files & Folders\Tools\Installed\AoA Audio Extractor Basic Ver 2 3 6 Setup.exe Win32/InstallMonetizer.AU potentially unwanted application deleted - quarantined
C:\Documents and Settings\DJ RAC\Desktop\Files & Folders\Tools\Installed\Auslogics Duplicate File Finder Ver 2 5 1 0 Setup.exe a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application deleted - quarantined
C:\Documents and Settings\DJ RAC\Desktop\Files & Folders\Tools\Installed\Auslogics Registry Cleaner Ver 2 5 1 0 Setup.exe a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application deleted - quarantined
C:\Documents and Settings\DJ RAC\Desktop\Files & Folders\Tools\Installed\Auslogics Registry Defrag Ver 6 5 1 0 Setup.exe a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application deleted - quarantined
C:\Documents and Settings\DJ RAC\Desktop\Files & Folders\Tools\Installed\CCleaner Ver 3 28 1913 Setup.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application deleted - quarantined
C:\Documents and Settings\DJ RAC\Desktop\Files & Folders\Tools\Installed\recuva 1 46 setup146.exe Win32/Bundled.Toolbar.Google.E potentially unsafe application deleted - quarantined
C:\Documents and Settings\DJ RAC\Desktop\Files & Folders\Tools\Not Installed\FormatFactory Video Converter Ver 3 0 1 1 Setup.zip a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application deleted - quarantined
C:\Documents and Settings\DJ RAC\Desktop\Files & Folders\Tools\Not Installed\Media Player Codec Pack Ver 4 2 5 Setup.exe a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application deleted - quarantined
C:\System Volume Information\_restore{1F140895-6C24-408C-96C4-86D1960E9760}\RP159\A0174964.dll Win32/Bundled.Toolbar.Ask.B potentially unsafe application deleted - quarantined

2014-08-20, 07:57
hello, ocd are you still helping me?...,

2014-08-20, 08:18
Hi joselepiu,

I apologize. I didn't get a notification that you replied to the thread.

Both MBAM & ESET scans look good. How does the computer seem to be running?

2014-08-20, 12:24
still the same...
very slow & sluggish...
the hard drives noises & the green light are the same. ...

2014-08-20, 18:13
Hi joselepiu,

Some of your performance issues could be a result of the age of your machine. Although I am not well versed in the hardware area of the computer here is some information you might need to take into account.

Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+

Random Access Memory
Total physical RAM: 3774.23 MB
Available physical RAM: 3092.71 MB

Minimal by today's standards.

Primary Hard Drive
Drive c: () (Fixed) (Total:279.47 GB) (Free:7.81 GB) NTFS
It is recommended that you keep a minimum of 20% free space on your primary hard drive.

= = = = = = = = = = = = = = = = = = = =

Download Security Check by screen317 from here (http://screen317.spywareinfoforum.org/SecurityCheck.exe) or here (http://screen317.changelog.fr/SecurityCheck.exe).
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.

= = = = = = = = = = = = = = = = = = = =

In your next post please provide the following:

Thoughts on the information I provided.

2014-08-20, 20:20
thanks for the links...

very interesting info...

did not realized its that old & may be obsolete by todays standars...

here is the checkup scan log:...

Results of screen317's Security Check version 0.99.87
Windows XP x64
Out of date service pack!! (http://windows.microsoft.com/en-us/windows/help/learn-how-to-install-windows-xp-service-pack-3-sp3)
Internet Explorer 7 Out of date!
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Please wait while WMIC is being installed.d
ECHO is off.
ECHO is off.
ECHO is off.
ECHO is off.
ECHO is off.
ECHO is off.
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
MVPS Hosts File
Out of date HijackThis installed!
Spybot - Search & Destroy
HijackThis 2.0.2
Auslogics Registry Cleaner
Adobe Flash Player
Adobe Reader XI
Google Chrome 36.0.1985.125
Google Chrome 36.0.1985.143
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Spybot Teatimer.exe is disabled!
AVG avgwdsvc.exe
Malwarebytes Anti-Malware 2 0 2 1012 mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````

2014-08-21, 05:17
Hi joselepiu,

Windows XP x64 - Out of date service pack!!
Internet Explorer 7 - Out of date!

As you can see by the above from the Security Check scan you need to update Windows XP and Internet Explorer.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Windows Automatic Updates

Open Windows Update by clicking the Start button http://i1269.photobucket.com/albums/jj590/OCD-WTT/start.jpg (http://s1269.photobucket.com/user/OCD-WTT/media/start.jpg.html), clicking All Programs, and then clicking Windows Update.
Download and Install the Important Updates.
In the left pane, click Change settings.
Choose the option that you want.
Under Recommended updates, select the Include recommended updates when downloading, installing, or notifying me about updates check box, and then click OK. http://i1269.photobucket.com/albums/jj590/OCD-WTT/windowsshield_zps565f3936.png (http://s1269.photobucket.com/user/OCD-WTT/media/windowsshield_zps565f3936.png.html) Administrator permission required If you are prompted for an administrator password or confirmation, type the password or provide confirmation.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Reboot & test

2014-08-21, 08:14
every time i clicked on an option the comp frezees and it takes up to 4 mins to open the next page...

please reference pics...

start ==> all programs ==> windows update


then on this page with these 2 options:

==> [ ] express: Get high-priority updates (recommended)

==> [ ] custom: Select from optional and high-priority updates for Windows and other programs

it dont matter what i pick it takes me to another page with these options:

==> [ ] Register or reinstall the files for me now (Recommended)

==> [ ] Let me read about more steps that might be required to solve the problem

[ continue ]

if a pick [ ] Register or reinstall the files for me now (Recommended) it takes me to:(http://update.microsoft.com/windowsupdate/v6/default.aspx?ln=en-us)

and it shows this:

[X] The website has encountered a problem and cannot display the page you are trying to view. The options provided below might help you solve the problem.
For self-help options:

Frequently Asked Questions

Find Solutions

Windows Update Newsgroup
For assisted support options:

Microsoft Online Assisted Support (no-cost for Windows Update issues)

[Error number: 0x80070420]

if a pick [ ] Let me read about more steps that might be required to solve the problem

it takes me to:

[X] HTTP Error 404 - File or directory not found.

Cannot find the page you are looking for. It might have been removed, had its name changed, or is temporarily unavailable.

Please try the following:

Ensure that the Web site address displayed in the address bar of your browser is spelled and formatted correctly.
If you reached this page by clicking a link, contact the Web site administrator to alert them that the link is incorrectly formatted.
Click the Back button to try another link.

[Error number: 0x8DDD000F]

2014-08-21, 09:03
Hi joselepiu,

I can't say for certain but, being that you are running Windows XP (which is no longer supported by Microsoft) that might be contributing to the issues you are encountering.


Let's check the hard drive for issues:

Click the Start menu http://i1269.photobucket.com/albums/jj590/OCD-WTT/start.jpg (http://s1269.photobucket.com/user/OCD-WTT/media/start.jpg.html), in the search box type "cmd" (without the quotes)
Next you will see a menu that has a small black DOS icon http://i1269.photobucket.com/albums/jj590/OCD-WTT/Dosicon_zps3944e344.gif (http://s1269.photobucket.com/user/OCD-WTT/media/Dosicon_zps3944e344.gif.html) with the text cmd next to it.
Double click on the DOS icon to run, OR
Right click on the DOS icon and select "Run as Administrator".
Select Yes if presented with the UAC prompt.
Next the larger DOS window will open with c:windows\system32>
Type or copy and paste (if it will allow) chkdsk /r, then hit Enter (make sure there is space between chkdsk and the /r)
You will see a warning:
Chkdsk cannot run because the volume is in use by another process. Would you like to schedule this volume to be checked the next time the system restarts? (Y/N)
Press the Y key, then hit Enter
You will see the following:
This volume will be checked the next time the system restarts.

http://i1269.photobucket.com/albums/jj590/OCD-WTT/chkdskgui_zps1cc21043.gif (http://s1269.photobucket.com/user/OCD-WTT/media/chkdskgui_zps1cc21043.gif.html)

Close the window, or type Exit, then press Enter.
Now restart your computer to allow the chkdsk scan to be performed.

In your next post please provide the following:

Report back with the results.

2014-08-21, 16:20
after typing "cmd" (no quotes) i get this:

2014-08-21, 17:31
Hi joselepiu,

Try this method instead:

http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye2_zpse2245433.png.html) chkdsk scan

Click Start and My Computer.
Right-click the hard drive you want to check, and click Properties.
Select the Tools tab in the Error Checking section click Check Now. Check both boxes. Click Start.

You'll get a message that the computer must be rebooted to run a complete check.

Click Yes and reboot. Chkdsk will take a while, so run it when you don't need to use the computer for something else.

http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye2_zpse2245433.png.html) To view results log:

Go to Start - Run and type in eventvwr.msc, and hit enter.
When Event Viewer opens, click on "Application", then scroll down to "Winlogon" and double-click on it to open it up.
This is the log created after running chkdsk. Click on the icon that looks like two pieces of paper to copy it and then paste it here please.


In your next post please provide the following:

chkdsk results

2014-08-22, 01:02
all 24,385 are the same...

2014-08-22, 01:05
forgot to mention that there was no "Winlogon"...

2014-08-22, 07:15
Hi joselepiu,

Hmmm ... OK then let's try another approach.

Download Tweaking.com Windows Repair from here (http://www.bleepingcomputer.com/download/windows-repair-all-in-one/) or here (http://www.tweaking.com/files/setups/tweaking.com_windows_repair_aio_setup.exe) and save it to your desktop.

Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"

Once the program opens you will be at the Welcome tab.

http://i1269.photobucket.com/albums/jj590/OCD-WTT/TweakingMainGUI_zps5a2aae6e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/TweakingMainGUI_zps5a2aae6e.gif.html)


Step 3: Check File System

http://i1269.photobucket.com/albums/jj590/OCD-WTT/Tweeking/TweakingStep3chkdsk_zpsc9039974.gif (http://s1269.photobucket.com/user/OCD-WTT/media/Tweeking/TweakingStep3chkdsk_zpsc9039974.gif.html)

Check File System:
Select the Do It button (option #3) to scan and repair the system files.
Follow the onscreen instructions.
Reboot when finished


In your next post please provide the following:

System File Check results

2014-08-22, 17:59
do i do steps 1 & 2?...

or just step 3?...

2014-08-22, 18:22

Only the highlighted step. (Step #3)

2014-08-22, 18:44
i got this after clicking:

2. check disk (if needed)...

should i restart manually?...

2014-08-22, 19:46
here is the log of the step 1 of step 3...

i did restart the comp manually by closing the message window by clicking on the X...

the restart the comp by ===> start ===> turn off computer ===> restart ...

step 2 did not produce a log...

Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\DJ RAC\Desktop>CD /D C:\

C:\>chkdsk C:
The type of the file system is NTFS.
The volume is in use by another process. Chkdsk
might report errors when no corruption is present.

WARNING! F parameter not specified.
Running CHKDSK in read-only mode.

CHKDSK is verifying files (stage 1 of 3)...
9 percent complete. (87772 of 91968 file records processed)
91968 file records processed.

File verification completed.
10 percent complete. (1 of 1363 large file records processed)
1363 large file records processed.

0 bad file records processed.

0 EA records processed.

2 reparse records processed.

CHKDSK is verifying indexes (stage 2 of 3)...
55 percent complete. (304875 of 305163 index entries processed)
305163 index entries processed.

Index verification completed.
5 unindexed files processed.

CHKDSK is verifying security descriptors (stage 3 of 3)...
59 percent complete. (89943 of 91968 descriptors processed)
91968 security descriptors processed.

Security descriptor verification completed.
6590 data files processed.

CHKDSK is verifying Usn Journal...
100 percent complete. (9166848 of 9170704 USN bytes processed)
9170704 USN bytes processed.

Usn Journal verification completed.
Correcting errors in the master file table's (MFT) BITMAP attribute.
Correcting errors in the Volume Bitmap.
Windows found problems with the file system.
Run CHKDSK with the /F (fix) option to correct these.

293048248 KB total disk space.
281098396 KB in 70829 files.
30072 KB in 6591 indexes.
4 KB in bad sectors.
179968 KB in use by the system.
65536 KB occupied by the log file.
11739808 KB available on disk.

4096 bytes in each allocation unit.
73262062 total allocation units on disk.
2934952 allocation units available on disk.


2014-08-23, 06:08
Hi joselepiu,

Windows found problems with the file system.

You stated that when you previously tried this step you encountered the path below:

What you will need to do is change directories before you can enter the correct command to have check disk complete.

Click the Start menu http://i1269.photobucket.com/albums/jj590/OCD-WTT/start.jpg (http://s1269.photobucket.com/user/OCD-WTT/media/start.jpg.html), in the search box type "cmd" (without the quotes)
Next you will see a menu that has a small black DOS icon http://i1269.photobucket.com/albums/jj590/OCD-WTT/Dosicon_zps3944e344.gif (http://s1269.photobucket.com/user/OCD-WTT/media/Dosicon_zps3944e344.gif.html) with the text cmd next to it.
Double click on the DOS icon to run, OR
Right click on the DOS icon and select "Run as Administrator".
Select Yes if presented with the UAC prompt.
Next the larger DOS window will open with C:\WINDOWS\$NtServicePackUninstall$>

Here is where you will have to change directories:
Next to the above entry type: cd.. >> Enter
You should see in the DOS windows that the line now reads C:\WINDOWS\
Next type: cd system32 >> Enter
You should now see C:\WINDOWS\system32>
Next we will type our check disk command (shown below)

Type or copy and paste (if it will allow) chkdsk /f, then hit Enter (make sure there is space between chkdsk and the /r)
You will see a warning:
Chkdsk cannot run because the volume is in use by another process. Would you like to schedule this volume to be checked the next time the system restarts? (Y/N)
Press the Y key, then hit Enter
You will see the following:
This volume will be checked the next time the system restarts.

http://i1269.photobucket.com/albums/jj590/OCD-WTT/chkdskgui_zps1cc21043.gif (http://s1269.photobucket.com/user/OCD-WTT/media/chkdskgui_zps1cc21043.gif.html)

Close the window, or type Exit, then press Enter.
Now restart your computer to allow the chkdsk scan to be performed.

Post the results when completed.

2014-08-23, 10:21
i ran the check scan but did bo produce any logs...

you asked me to do this:

""To view results log:

Go to Start - Run and type in eventvwr.msc, and hit enter.
When Event Viewer opens, click on "Application", then scroll down to "Winlogon" and double-click on it to open it up.
This is the log created after running chkdsk. Click on the icon that looks like two pieces of paper to copy it and then paste it here please.""

i did not find the ""Winlogon"" there...

i posted some pics of what i found there on my post ""??? 14-08-21, 16:02...

bit ill run the ""chkdsk /f"" comand again...

2014-08-23, 10:54
i just noticed that in your institutions there is a confusing typo...

Type or copy and paste (if it will allow) ===chkdsk /f=== , then hit Enter (make sure there is space between === chkdsk and the /r===)

which one is the correct one?...

2014-08-24, 04:09
i just noticed that in your institutions there is a confusing typo...

Type or copy and paste (if it will allow) ===chkdsk /f=== , then hit Enter (make sure there is space between === chkdsk and the /r===)

which one is the correct one?...

My oversite, chkdsk /r is the correct entry.

Go to Start - Run and type in eventvwr.msc, and hit enter.
When Event Viewer opens, click on "Application", then scroll down to "Winlogon" and double-click on it to open it up.
This is the log created after running chkdsk. Click on the icon that looks like two pieces of paper to copy it and then paste it here please.""

Double click "Application" to expand the menu.

2014-08-24, 05:32
i get this again...

start ===> run ===> type: "eventvwr.msc" ===> click "OK" ===>


and after clicking on "Application" i get this:...


when i try to scroll down all disappears...


but at the top of the window it still shows 24,385 events...


2014-08-24, 05:34
in another note...

by error i clicked on security instead of application...

and i saw this...


are those anonymous logons normal?...

2014-08-24, 05:42
here is another pic of those ""anonymous logons"" with todays date...

11752 ...

2014-08-24, 06:38
Hi joselepiu,

Please do not attach the images, it makes it time consuming to review your answers. :bigthumb:

We have removed all the malware that was found on your computer.

As far as the errors messages and the anonymous logons contained within the event viewer are concerned, unfortunately, this is not my area of expertise. My primary focus is on malware removal, and as stated in my opening introduction " I will be working on your Malware issues, this may or may not, solve other issues you have with your machine."

We may have come to the point where you best course of action would be to either reformat and reinstall the current version of your OS. Or option two, which would be to upgrade to a newer version. I would strongly recommend the second option since Microsoft no longer offers support for Windows XP.

Either option would resolve the current missing or corrupt files that are present on your computer and may be contributing to the problems we are encountering.

Please let me know how you would like to proceed.

2014-08-24, 07:22
sorry about the pics...

just try to do what you did...

tried to include the pics with the text but it did not work out...

could not edit it after posted (do not think is even possible in this site)...

thought it would be easier for you to understand what i meant...

a pic is worth more than 1,000 words... and all that...

in regards to the anonymous logons...

i think that that says that my computer is indeed infected with something unless that is normal...

2014-08-24, 08:00
Hi joselepiu,

in regards to the anonymous logons...

i think that that says that my computer is indeed infected with something unless that is normal...

Could you cut and paste an anonymous logon message (click the little copy button after double clicking the event)

Are you on a network?

"Some network applications use the ANONYMOUS LOGON process to create a communication channel with your computer. Anonymous logon means that it is a null session. NT Auth/Anonymous is just a pseudonym for a Null Session. The NTAuth/Anonymous isn't really an account; it just means that no credentials were supplied. There are many conditions known to cause a null session connection which makes it difficult to tell the exact cause of these particular events. "

2014-08-24, 09:36
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 8/23/2014
Time: 7:58:50 PM
Successful Network Logon:
User Name:
Logon ID: (0x0,0x1437E)
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name:
Logon GUID: -
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: -
Source Port: -

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

2014-08-24, 09:39
forgot to answer your question...

im not in any network...

2014-08-24, 16:46
forgot to answer your question...

im not in any network...

How do you connect to the internet?
Who is you ISP?

2014-08-24, 20:15
my isp provider is century link...

and i get dsl...

2014-08-25, 09:37
Hi joselepiu,

Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 8/23/2014
Time: 7:58:50 PM
Successful Network Logon:
User Name:
Logon ID: (0x0,0x1437E)
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name:
Logon GUID: -
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: -
Source Port: -

An excerpt from the information I previously provided:
"The NTAuth/Anonymous isn't really an account; it just means that no credentials were supplied."

my isp provider is century link...

and i get dsl...

This type of connection is considered a network.

So these entries appear to be legitimate, and not malware related as you suspected.

2014-08-27, 06:52
ok thanks...

is there any other place i can get help for the problem?...

what do you recommend?...

2014-08-27, 08:16
Hi joselepiu,

There is another forum that I volunteer at that has a Tech Team that might be able to help with your issues.

Go to WhatTheTech.com (http://forums.whatthetech.com/index.php?) you will need to create an account, the start a new thread in the General Hardware Forum.

Give a brief description of the problem along with a link to this thread so the Tech Team helper can see what we have done already.
Also, let them know that the thread is at Safer-Networking Forum (http://www.safer-networking.org/)

Include this link in your post:http://forums.spybot.info/showthread.php?70963-System-XP-Pro-x64-Edition

2014-08-28, 17:58
i will do that...
thanks for all your help...

2014-08-29, 05:38
You're very welcome. Glad I was able to help. :bigthumb:

Since this issue appears to be resolved ... this Topic has been closed.

If you still require help, please start a new topic and include fresh FRST and aswMBR logs, along with a link to your previous thread.

Please do not add any logs that might have been requested previously, you would be starting fresh.

Applies only to the original poster, anyone else with similar problems please start your own topic.