System: XP Pro x64 Edition
Ver 2003
Service Pack 2
hello, again my comp is infected
the symptoms are that is really really slow when in full mode & the hard drives never stop working even when i have not used it for a long time. the green light never stops blinking also, right now im running it on safe mode
ran avg, spybot & malware but nothing found
here are the Farbar Recovery Scan Tool and aswMBR logs
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-08-2014 01
Ran by DJ RAC (administrator) on DJ-RAC-PUTTER on 13-08-2014 17:36:37
Running from C:\Documents and Settings\DJ RAC\Desktop
Platform: Microsoft Windows XP Service Pack 2 (X64) OS Language: English (United States)
Internet Explorer Version 7
Boot Mode: Safe Mode (with Networking)
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [577536 2006-08-03] (Realtek Semiconductor Corp.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5187088 2014-07-10] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2640408 2014-08-11] ()
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Winlogon: [Userinit] userinit, [X]
HKLM\...\Winlogon: [UIHost] C:\Windows\system32\logonui.exe [662016 2007-02-17] ( (Microsoft Corporation))
Winlogon\Notify\crypt32chain: C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
Winlogon\Notify\cryptnet: C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
Winlogon\Notify\cscdll: C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
Winlogon\Notify\dimsntfy: C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
Winlogon\Notify\ScCertProp: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\Schedule: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\sclgntfy: C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\SensLogn: C:\WINDOWS\system32\WlNotify.dll (Microsoft Corporation)
Winlogon\Notify\termsrv: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\wlballoon: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\crypt32chain-x32: C:\WINDOWS\SysWOW64\crypt32.dll (Microsoft Corporation)
Winlogon\Notify\cryptnet-x32: C:\WINDOWS\SysWOW64\cryptnet.dll (Microsoft Corporation)
Winlogon\Notify\cscdll-x32: C:\WINDOWS\SysWOW64\cscdll.dll (Microsoft Corporation)
Winlogon\Notify\dimsntfy-x32: C:\WINDOWS\SysWOW64\dimsntfy.dll (Microsoft Corporation)
Winlogon\Notify\EFS-x32: C:\WINDOWS\SysWOW64\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\ScCertProp-x32: wlnotify.dll [X]
Winlogon\Notify\Schedule-x32: wlnotify.dll [X]
Winlogon\Notify\sclgntfy-x32: C:\WINDOWS\SysWOW64\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
Winlogon\Notify\SensLogn-x32: WlNotify.dll [X]
Winlogon\Notify\wlballoon-x32: wlnotify.dll [X]
HKLM\...\Command Processor: <======= ATTENTION
HKLM-x32\...\Command Processor: <======= ATTENTION
HKU\.DEFAULT\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-19\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-21-2799395484-3895304042-2403659751-1002\...\MountPoints2: {2d27d8a5-3283-11e3-8e94-00e04d1c5274} - E:\LGAutoRun.exe
HKU\S-1-5-21-2799395484-3895304042-2403659751-1002\...\MountPoints2: {e39d701f-90fe-11e2-9c15-00e04d1c5274} - D:\LaunchU3.exe -a
IFEO\Your Image File Name Here without a path: [Debugger] ntsd -d
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
SSODL-x32: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\syswow64\SHELL32.dll (Microsoft Corporation)
SSODL-x32: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\syswow64\SHELL32.dll (Microsoft Corporation)
SSODL-x32: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\SysWOW64\stobject.dll (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean64.exeC:\PROGRA~2\AVG\AVG2014\avgrsa.exe /sync /restart
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={78CBEA97-1813-44AE-A46F-4CD435A77274}&mid=63957768860347d38e83d1a90bf8bb87-8d758629d5135f4470f57152dc116841b6490bd7&lang=en&ds=AVG&pr=fr&d=2013-05-25 00:51:20&v=15.3.0.11&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
Toolbar: HKLM-x32 - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
DPF: HKLM-x32 {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1363890949984
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\Windows\system32\mshtml.dll (Microsoft Corporation)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\Windows\SysWow64\mshtml.dll (Microsoft Corporation)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search)
Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Filter-x32: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Filter-x32: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Filter-x32: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\Windows\SysWow64\SHELL32.dll (Microsoft Corporation)
ShellExecuteHooks: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [10508288 2009-02-10] (Microsoft Corporation)
ShellExecuteHooks-x32: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\SysWOW64\shell32.dll [8360960 2009-02-10] (Microsoft Corporation)
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\mswsock.dll [233472] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 03 %SystemRoot%\System32\mswsock.dll [492544] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.3.25
FireFox:
========
FF ProfilePath: C:\Documents and Settings\DJ RAC\Application Data\Mozilla\Firefox\Profiles\afjw053j.default
FF Homepage: about:newtab
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VLC Media Player 2 0 8 win32\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49
FF Extension: AVG SafeGuard toolbar - C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49 [2014-01-05]
Chrome:
=======
CHR NewTab: "chrome-extension://dpjamkmjmigaoobjbekmfgabipmfilij/empty_ntp.html"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2003) - C:\Program Files (x86)\Firefox Mozilla Ver 19 0 2\plugins\NPOFFICE.DLL No File
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Firefox Mozilla Ver 19 0 2\plugins\npwachk.dll No File
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.0.0\\npsitesafety.dll (AVG Technologies)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Extension: (Google Drive) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-23]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-02]
CHR Extension: (YouTube) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-23]
CHR Extension: (Google Search) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-23]
CHR Extension: (Empty New Tab Page) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dpjamkmjmigaoobjbekmfgabipmfilij [2013-12-03]
CHR Extension: (Google Wallet) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Gmail) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-23]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AeLookupSvc; C:\Windows\SysWOW64\aelupsvc.dll [26624 2006-03-29] (Microsoft Corporation)
S4 Alerter; C:\Windows\system32\alrsvc.dll [29696 2006-03-29] (Microsoft Corporation)
S3 ALG; C:\Windows\SysWOW64\alg.exe [45056 2006-03-29] (Microsoft Corporation)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3244048 2014-07-10] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-07-10] (AVG Technologies CZ, s.r.o.)
S2 Browser; C:\Windows\SysWOW64\browser.dll [78336 2007-02-18] (Microsoft Corporation)
S3 ClipSrv; C:\Windows\system32\clipsrv.exe [49664 2006-03-29] (Microsoft Corporation)
S3 ClipSrv; C:\Windows\SysWOW64\clipsrv.exe [32256 2006-03-29] (Microsoft Corporation)
R2 dmadmin; C:\Windows\System32\dmadmin.exe [399872 2007-02-17] (Microsoft Corporation)
R2 dmserver; C:\Windows\System32\dmserver.dll [37376 2007-02-17] (Microsoft Corporation)
S2 ERSvc; C:\Windows\System32\ersvc.dll [31744 2006-03-29] (Microsoft Corporation)
R2 helpsvc; C:\Windows\PCHealth\HelpCtr\Binaries\pchsvc.dll [77312 2007-02-17] (Microsoft Corporation)
S3 HTTPFilter; C:\Windows\System32\w3ssl.dll [21504 2006-03-29] (Microsoft Corporation)
S3 IASJet; C:\Windows\SysWOW64\iasrecst.dll [162816 2006-03-29] (Microsoft Corporation)
S3 ImapiService; C:\WINDOWS\system32\imapi.exe [265728 2007-02-17] (Microsoft Corporation)
S4 Messenger; C:\Windows\System32\msgsvc.dll [57344 2007-02-17] (Microsoft Corporation)
S3 mnmsrvc; C:\WINDOWS\SysWOW64\mnmsrvc.exe [32768 2006-03-29] (Microsoft Corporation)
S3 NetDDE; C:\Windows\system32\netdde.exe [160768 2007-02-17] (Microsoft Corporation)
S3 NetDDEdsdm; C:\Windows\system32\netdde.exe [160768 2007-02-17] (Microsoft Corporation)
R3 Netman; C:\Windows\SysWOW64\netman.dll [263680 2007-02-18] (Microsoft Corporation)
S3 Nla; C:\Windows\System32\mswsock.dll [492544 2008-06-21] (Microsoft Corporation)
S3 Nla; C:\Windows\SysWOW64\mswsock.dll [233472 2008-06-21] (Microsoft Corporation)
S3 NtLmSsp; C:\Windows\system32\lsass.exe [14336 2006-03-29] (Microsoft Corporation)
S2 NtmsSvc; C:\Windows\system32\ntmssvc.dll [794112 2007-02-17] (Microsoft Corporation)
S2 NVSvc; C:\Windows\system32\nvsvc64.exe [135680 2006-03-31] (NVIDIA Corporation)
R2 PlugPlay; C:\Windows\system32\services.exe [227840 2009-03-19] (Microsoft Corporation)
S2 PolicyAgent; C:\Windows\system32\lsass.exe [14336 2006-03-29] (Microsoft Corporation)
S3 RasAuto; C:\Windows\SysWOW64\rasauto.dll [91648 2007-02-18] (Microsoft Corporation)
S3 RasMan; C:\Windows\SysWOW64\rasmans.dll [181760 2007-02-18] (Microsoft Corporation)
S3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [212480 2007-02-17] (Microsoft Corporation)
S3 RpcLocator; C:\Windows\SysWOW64\locator.exe [71680 2006-03-29] (Microsoft Corporation)
S3 SCardSvr; C:\Windows\System32\SCardSvr.exe [166400 2007-02-17] (Microsoft Corporation)
S2 Schedule; C:\Windows\SysWOW64\schedsvc.dll [202240 2007-02-18] (Microsoft Corporation)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
S2 seclogon; C:\Windows\SysWOW64\seclogon.dll [18432 2007-02-18] (Microsoft Corporation)
R2 srservice; C:\WINDOWS\system32\srsvc.dll [231424 2007-02-17] (Microsoft Corporation)
S2 SysmonLog; C:\Windows\system32\smlogsvc.exe [133120 2007-02-17] (Microsoft Corporation)
S2 SysmonLog; C:\Windows\SysWOW64\smlogsvc.exe [96256 2007-02-18] (Microsoft Corporation)
S4 TlntSvr; C:\WINDOWS\system32\tlntsvr.exe [113152 2007-02-17] (Microsoft Corporation)
S2 TrkWks; C:\Windows\SysWOW64\trkwks.dll [86528 2007-02-18] (Microsoft Corporation)
S2 UMWdf; C:\WINDOWS\system32\wdfmgr.exe [62976 2006-03-29] (Microsoft Corporation)
S2 UMWdf; C:\WINDOWS\SysWOW64\wdfmgr.exe [39424 2006-03-29] (Microsoft Corporation)
S3 UPS; C:\Windows\System32\ups.exe [34816 2006-03-29] (Microsoft Corporation)
S3 UPS; C:\Windows\SysWOW64\ups.exe [16896 2006-03-29] (Microsoft Corporation)
S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-11] (AVG Secure Search)
S3 WmdmPmSN; C:\WINDOWS\system32\mspmsnsv.dll [36352 2007-02-17] (Microsoft Corporation)
S3 Wmi; C:\Windows\System32\advapi32.dll [1052160 2009-03-19] (Microsoft Corporation)
S3 Wmi; C:\Windows\SysWOW64\advapi32.dll [619008 2009-03-19] (Microsoft Corporation)
S2 wuauserv; C:\WINDOWS\system32\wuauserv.dll [12288 2006-03-29] (Microsoft Corporation)
R2 WZCSVC; C:\Windows\System32\wzcsvc.dll [659968 2007-02-17] (Microsoft Corporation)
R2 WZCSVC; C:\Windows\SysWOW64\wzcsvc.dll [489472 2007-02-18] (Microsoft Corporation)
S3 xmlprov; C:\Windows\System32\xmlprov.dll [326144 2007-02-17] (Microsoft Corporation)
S3 xmlprov; C:\Windows\SysWOW64\xmlprov.dll [131584 2007-02-18] (Microsoft Corporation)
R2 Eventlog; [X]
S4 HidServ; %SystemRoot%\System32\hidserv.dll [X]
S3 WinHttpAutoProxySvc; winhttp.dll [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 Abiosdsk; No ImagePath
S4 ACPIEC; C:\Windows\System32\Drivers\ACPIEC.sys [18432 2006-03-29] (Microsoft Corporation)
S4 adpu160m; No ImagePath
S4 adpu320; No ImagePath
S3 aec; C:\Windows\System32\drivers\aec.sys [188928 2005-03-24] (Microsoft Corporation)
S4 aic78u2; No ImagePath
S4 aic78xx; No ImagePath
S3 ALCXWDM; C:\Windows\System32\drivers\ALCWDM64.SYS [3304448 2006-10-13] (Realtek Semiconductor Corp.)
S4 AliIde; No ImagePath
S4 AmdIde; No ImagePath
S1 AmdK8; C:\Windows\System32\DRIVERS\amdk8.sys [51200 2006-05-10] (Advanced Micro Devices)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2013-04-18] (Google Inc)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S4 arc; No ImagePath
S4 Atdisk; No ImagePath
S3 Atmarpc; C:\Windows\System32\DRIVERS\atmarpc.sys [106496 2007-02-17] (Microsoft Corporation)
S3 audstub; C:\Windows\System32\DRIVERS\audstub.sys [5632 2005-03-24] (Microsoft Corporation)
S1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriverl; C:\Windows\System32\DRIVERS\avgidsdriverla.sys [227608 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx64.sys [50976 2014-08-11] (AVG Technologies)
S1 BIOS; C:\WINDOWS\system32\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
S1 BIOS; C:\WINDOWS\SysWOW64\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
S2 CdaC15BA; C:\Windows\System32\DRIVERS\CdaC15BA.sys [13312 2006-03-29] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
S2 CdaD10BA; C:\Windows\System32\DRIVERS\CdaD10BA.sys [13312 2006-03-29] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
S1 Changer; No ImagePath
S4 CmdIde; No ImagePath
S4 dmboot; C:\Windows\System32\drivers\dmboot.sys [415232 2007-02-17] (Microsoft Corporation)
R0 dmio; C:\Windows\System32\drivers\dmio.sys [244224 2007-02-17] (Microsoft Corporation)
R0 dmload; C:\Windows\System32\drivers\dmload.sys [9216 2006-03-29] (Microsoft Corporation)
S4 dpti2o; No ImagePath
S1 Fips; C:\Windows\System32\Drivers\Fips.sys [50176 2007-02-17] (Microsoft Corporation)
R0 Ftdisk; C:\Windows\System32\DRIVERS\ftdisk.sys [240128 2007-02-17] (Microsoft Corporation)
R3 Gpc; C:\Windows\System32\DRIVERS\msgpc.sys [71168 2007-02-17] (Microsoft Corporation)
S1 i2omgmt; No ImagePath
S4 iirsp; No ImagePath
R1 imapi; C:\Windows\System32\DRIVERS\imapi.sys [72704 2006-03-29] (Microsoft Corporation)
S4 IntelIde; No ImagePath
S3 Ip6Fw; C:\Windows\System32\drivers\ip6fw.sys [57856 2007-02-17] (Microsoft Corporation)
S3 IpInIp; No ImagePath
R1 IPSec; C:\Windows\System32\DRIVERS\ipsec.sys [156672 2007-02-17] (Microsoft Corporation)
S3 kmixer; C:\Windows\System32\drivers\kmixer.sys [204288 2005-03-24] (Microsoft Corporation)
S1 mnmdd; C:\Windows\System32\Drivers\mnmdd.sys [8192 2006-03-29] (Microsoft Corporation)
S4 mraid35x; No ImagePath
S3 MxlW2k; C:\Windows\SysWow64\Drivers\MxlW2k.sys [28276 2013-03-18] (MusicMatch, Inc.) [File not signed]
S3 nv; C:\Windows\System32\DRIVERS\nv4_mini.sys [4818944 2006-03-31] (NVIDIA Corporation)
R0 nvata64; C:\Windows\System32\DRIVERS\nvata64.sys [164864 2006-04-24] (NVIDIA Corporation)
R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [52736 2006-02-17] (NVIDIA Corporation)
R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [22016 2006-02-17] (NVIDIA Corporation)
S3 PDCOMP; No ImagePath
S3 PDFRAME; No ImagePath
S3 PDRELI; No ImagePath
S3 PDRFRAME; No ImagePath
R3 PSched; C:\Windows\System32\DRIVERS\psched.sys [106496 2007-02-17] (Microsoft Corporation)
R3 Ptilink; C:\Windows\System32\DRIVERS\ptilink.sys [31232 2006-03-29] (Parallel Technologies, Inc.)
S0 PxHelp64; C:\Windows\SysWOW64\DRIVERS\PxHelp64.sys [47872 2003-07-30] (Sonic Solutions) [File not signed]
R3 Raspti; C:\Windows\System32\DRIVERS\raspti.sys [31232 2006-03-29] (Microsoft Corporation)
R1 redbook; C:\Windows\System32\DRIVERS\redbook.sys [64000 2005-03-24] (Microsoft Corporation)
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [171008 2007-02-17] (Microsoft Corporation)
S4 Simbad; No ImagePath
S3 splitter; C:\Windows\System32\drivers\splitter.sys [10240 2007-02-17] (Microsoft Corporation)
R0 sr; C:\Windows\System32\DRIVERS\sr.sys [123904 2006-03-29] (Microsoft Corporation)
S3 swmidi; C:\Windows\System32\drivers\swmidi.sys [86528 2005-03-24] (Microsoft Corporation)
S4 symc8xx; No ImagePath
S4 symmpi; No ImagePath
S4 sym_hi; No ImagePath
S4 sym_u3; No ImagePath
S3 sysaudio; C:\Windows\System32\drivers\sysaudio.sys [147456 2007-02-17] (Microsoft Corporation)
S4 TosIde; No ImagePath
S4 ultra; No ImagePath
R3 Update; C:\Windows\System32\DRIVERS\update.sys [81920 2007-02-17] (Microsoft Corporation)
S4 ViaIde; No ImagePath
S3 WDICA; No ImagePath
S3 wdmaud; C:\Windows\System32\drivers\wdmaud.sys [187904 2007-02-17] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
NETSVCx32: Browser -> C:\Windows\SysWOW64\browser.dll (Microsoft Corporation)
NETSVCx32: CryptSvc -> C:\Windows\SysWOW64\cryptsvc.dll (Microsoft Corporation)
NETSVCx32: DMServer -> C:\Windows\SysWOW64\dmserver.dll ==> No File.
NETSVCx32: EventSystem -> C:\WINDOWS\SysWOW64\es.dll (Microsoft Corporation)
NETSVCx32: HidServ -> C:\Windows\SysWOW64\hidserv.dll ==> No File.
NETSVCx32: Iprip -> No ServiceDLL Path.
NETSVCx32: LanmanWorkstation -> C:\Windows\SysWOW64\wkssvc.dll ==> No File.
NETSVCx32: Messenger -> C:\Windows\SysWOW64\msgsvc.dll ==> No File.
NETSVCx32: Netman -> C:\Windows\SysWOW64\netman.dll (Microsoft Corporation)
NETSVCx32: Seclogon -> C:\Windows\SysWOW64\seclogon.dll (Microsoft Corporation)
NETSVCx32: TrkWks -> C:\Windows\SysWOW64\trkwks.dll (Microsoft Corporation)
NETSVCx32: WZCSVC -> C:\Windows\SysWOW64\wzcsvc.dll (Microsoft Corporation)
NETSVCx32: wscsvc -> C:\Windows\SysWOW64\wscsvc.dll ==> No File.
NETSVCx32: xmlprov -> C:\Windows\SysWOW64\xmlprov.dll (Microsoft Corporation)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-13 17:36 - 2014-08-13 17:36 - 00027090 _____ () C:\Documents and Settings\DJ RAC\Desktop\FRST.txt
2014-08-13 17:35 - 2014-08-13 17:36 - 00000000 ____D () C:\FRST
2014-08-13 17:30 - 2014-08-13 17:30 - 02100224 _____ (Farbar) C:\Documents and Settings\DJ RAC\Desktop\FRST64.exe
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\RegBackup
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com
2014-08-13 17:27 - 2014-08-13 17:27 - 04057608 _____ () C:\Documents and Settings\DJ RAC\Desktop\tweaking.com_registry_backup_setup.exe
2014-08-13 17:27 - 2014-08-13 17:27 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-08-13 17:00 - 2014-08-13 17:00 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\hijackthis 08 13 14 17 00 PM .log
2014-08-13 14:02 - 2014-08-13 14:02 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 14 02 pm after all scans hijackthis.log
2014-08-13 11:25 - 2014-08-13 11:25 - 00006894 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 11 25 am after malware scan hijackthis.log
2014-08-13 09:32 - 2014-08-13 09:32 - 00006893 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 09 32 am after spy scan hijackthis.log
2014-08-13 08:27 - 2014-06-19 12:47 - 00450613 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140813-082716.backup
2014-08-13 08:12 - 2014-08-13 08:12 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 08 12 am after avg scan hijackthis.log
2014-08-13 07:10 - 2014-08-13 07:10 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 07 09 am b4 scans hijackthis.log
2014-08-13 07:08 - 2014-08-13 16:58 - 00000000 ____D () C:\Program Files (x86)\Trend Micro HijackThis Ver 2 0 2
2014-08-13 07:08 - 2014-08-13 07:08 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis
2014-08-13 06:51 - 2014-08-13 17:03 - 00000000 _____ () C:\WINDOWS\0.log
2014-08-13 03:18 - 2014-08-13 17:00 - 00005115 _____ () C:\WINDOWS\WindowsUpdate.log
2014-08-11 21:22 - 2014-08-13 02:26 - 00000199 _____ () C:\Documents and Settings\DJ RAC\Desktop\major crimes.txt
2014-07-29 22:17 - 2014-07-31 15:16 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Desktop\priscillas
2014-07-25 03:02 - 2014-08-13 17:00 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-07-25 00:48 - 2014-07-26 22:41 - 00002049 _____ () C:\Documents and Settings\DJ RAC\Desktop\disco music mix.txt
2014-07-16 23:18 - 2014-07-19 15:04 - 00000078 _____ () C:\Documents and Settings\DJ RAC\Desktop\baladas 70s.txt
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-13 17:36 - 2014-08-13 17:36 - 00027090 _____ () C:\Documents and Settings\DJ RAC\Desktop\FRST.txt
2014-08-13 17:36 - 2014-08-13 17:35 - 00000000 ____D () C:\FRST
2014-08-13 17:36 - 2013-03-20 20:30 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Local Settings\Temp
2014-08-13 17:30 - 2014-08-13 17:30 - 02100224 _____ (Farbar) C:\Documents and Settings\DJ RAC\Desktop\FRST64.exe
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\RegBackup
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com
2014-08-13 17:27 - 2014-08-13 17:27 - 04057608 _____ () C:\Documents and Settings\DJ RAC\Desktop\tweaking.com_registry_backup_setup.exe
2014-08-13 17:27 - 2014-08-13 17:27 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-08-13 17:18 - 2006-03-29 06:00 - 00002422 _____ () C:\WINDOWS\system32\wpa.dbl
2014-08-13 17:03 - 2014-08-13 06:51 - 00000000 _____ () C:\WINDOWS\0.log
2014-08-13 17:00 - 2014-08-13 17:00 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\hijackthis 08 13 14 17 00 PM .log
2014-08-13 17:00 - 2014-08-13 03:18 - 00005115 _____ () C:\WINDOWS\WindowsUpdate.log
2014-08-13 17:00 - 2014-07-25 03:02 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-08-13 17:00 - 2013-03-20 20:30 - 00000178 ___SH () C:\Documents and Settings\DJ RAC\ntuser.ini
2014-08-13 17:00 - 2013-03-20 12:12 - 00524288 _____ () C:\WINDOWS\system32\config\SpybotSD.evt
2014-08-13 17:00 - 2013-03-19 14:13 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2014-08-13 17:00 - 2013-03-18 07:24 - 00032470 _____ () C:\WINDOWS\Tasks\SchedLgU.Txt
2014-08-13 17:00 - 2013-03-18 07:24 - 00000216 _____ () C:\Documents and Settings\LocalService\wiadebug.log
2014-08-13 17:00 - 2013-03-18 07:24 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-08-13 16:58 - 2014-08-13 07:08 - 00000000 ____D () C:\Program Files (x86)\Trend Micro HijackThis Ver 2 0 2
2014-08-13 16:08 - 2013-10-09 18:28 - 00000898 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-13 14:39 - 2014-06-18 14:13 - 00000442 _____ () C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1403122415.job
2014-08-13 14:02 - 2014-08-13 14:02 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 14 02 pm after all scans hijackthis.log
2014-08-13 13:29 - 2014-02-05 23:44 - 00000374 _____ () C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rmv.job
2014-08-13 13:29 - 2014-02-05 23:44 - 00000372 _____ () C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rel.job
2014-08-13 13:29 - 2013-10-09 18:28 - 00000894 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-13 13:29 - 2013-03-20 12:12 - 00000632 _____ () C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
2014-08-13 13:29 - 2013-03-18 07:35 - 00050257 _____ () C:\WINDOWS\system32\nvapps.xml
2014-08-13 13:28 - 2013-03-18 13:22 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MFAData
2014-08-13 11:25 - 2014-08-13 11:25 - 00006894 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 11 25 am after malware scan hijackthis.log
2014-08-13 09:32 - 2014-08-13 09:32 - 00006893 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 09 32 am after spy scan hijackthis.log
2014-08-13 08:13 - 2013-03-20 12:12 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-08-13 08:12 - 2014-08-13 08:12 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 08 12 am after avg scan hijackthis.log
2014-08-13 07:10 - 2014-08-13 07:10 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 07 09 am b4 scans hijackthis.log
2014-08-13 07:08 - 2014-08-13 07:08 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis
2014-08-13 02:45 - 2013-03-20 20:30 - 00000000 ____D () C:\Documents and Settings\DJ RAC
2014-08-13 02:26 - 2014-08-11 21:22 - 00000199 _____ () C:\Documents and Settings\DJ RAC\Desktop\major crimes.txt
2014-08-13 00:30 - 2013-03-20 12:12 - 00000628 _____ () C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2014-08-12 14:39 - 2014-06-18 14:13 - 00000000 ____D () C:\Program Files (x86)\Opera 22 0 1471 70
2014-08-11 20:41 - 2014-03-15 10:18 - 00000000 ____D () C:\Program Files (x86)\AVG SafeGuard toolbar
2014-08-11 20:41 - 2013-05-20 17:57 - 00000000 ____D () C:\WINDOWS\SysWOW64\cache
2014-08-11 20:41 - 2013-03-18 13:31 - 00050976 _____ (AVG Technologies) C:\WINDOWS\system32\Drivers\avgtpx64.sys
2014-08-11 15:09 - 2013-03-20 20:30 - 00000265 _____ () C:\Documents and Settings\DJ RAC\wiadebug.log
2014-08-11 14:42 - 2014-04-03 13:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 30 0
2014-08-06 15:37 - 2013-03-18 16:22 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\DVD Shrink
2014-08-04 15:12 - 2013-03-20 20:52 - 00000178 ___SH () C:\Documents and Settings\Lety\ntuser.ini
2014-08-04 15:11 - 2013-03-20 20:52 - 00000000 ____D () C:\Documents and Settings\Lety\Local Settings\Temp
2014-08-04 15:03 - 2013-03-24 14:56 - 00000000 ____D () C:\Documents and Settings\Lety\Desktop\SAVE IT HERE
2014-08-04 15:03 - 2013-03-20 20:52 - 00000265 _____ () C:\Documents and Settings\Lety\wiadebug.log
2014-08-04 10:17 - 2014-05-01 09:12 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2014 Ver 2014 0 4744
2014-08-01 00:30 - 2013-03-20 12:12 - 00000458 _____ () C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
2014-07-31 15:32 - 2013-03-18 17:32 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\TEMP
2014-07-31 15:16 - 2014-07-29 22:17 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Desktop\priscillas
2014-07-29 19:22 - 2013-03-23 19:44 - 00000178 ___SH () C:\Documents and Settings\Prisc & Vane\ntuser.ini
2014-07-29 19:12 - 2013-03-23 19:44 - 00000000 ____D () C:\Documents and Settings\Prisc & Vane\Local Settings\Temp
2014-07-26 22:41 - 2014-07-25 00:48 - 00002049 _____ () C:\Documents and Settings\DJ RAC\Desktop\disco music mix.txt
2014-07-25 03:02 - 2013-03-18 13:20 - 00699056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-07-25 03:02 - 2013-03-18 13:20 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-25 00:03 - 2013-03-23 03:32 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\YTD Video Downloader
2014-07-19 15:04 - 2014-07-16 23:18 - 00000078 _____ () C:\Documents and Settings\DJ RAC\Desktop\baladas 70s.txt
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
C:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!.
==================== End Of Log
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-08-2014 01
Ran by DJ RAC at 2014-08-13 17:37:13
Running from C:\Documents and Settings\DJ RAC\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
1-Click YouTube Downloader 9.0 (HKLM-x32\...\1-Click YouTube Downloader_is1) (Version: - )
Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.7.700.224 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
AoA Audio Extractor (HKLM-x32\...\{D1725D54-279A-40C5-A70D-23C1785DB920}_is1) (Version: - AoAMedia.com)
Asoftech Data Recovery (HKLM-x32\...\{1AED6EB7-8FEA-4021-B8FD-EBAA6B21679F}) (Version: 1.00 - )
Auslogics Disk Defrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 3.6 - Auslogics Software Pty Ltd)
Auslogics Duplicate File Finder (HKLM-x32\...\{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1) (Version: 2.5 - Auslogics Software Pty Ltd)
Auslogics Registry Cleaner (HKLM-x32\...\{8D8024F1-2945-49A5-9B78-5AB7B11D7942}_is1) (Version: 2.5 - Auslogics Software Pty Ltd)
Auslogics Registry Defrag (HKLM-x32\...\{D627784F-B3EE-44E8-96B1-9509B991EA34}_is1) (Version: 6.5 - Auslogics Software Pty Ltd)
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4744 - AVG Technologies)
AVG 2014 (Version: 14.0.4007 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4744 - AVG Technologies) Hidden
AVG SafeGuard toolbar (HKLM-x32\...\AVG SafeGuard toolbar) (Version: 18.1.9.786 - AVG Technologies)
Brother MFL-Pro Suite MFC-250C (HKLM-x32\...\{3A08B59E-A9F0-4F4D-B7E5-6875D7F13327}) (Version: 1.1.8.0 - Brother Industries, Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 3.28 - Piriform)
DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version: - DVD Shrink)
DVDFab 8.2.2.8 (26/02/2013) Qt (HKLM-x32\...\DVDFab 8 Qt_is1) (Version: - Fengtao Software Inc.)
EaseUS Data Recovery Wizard 5.8.5 (HKLM-x32\...\EaseUS Data Recovery Wizard 5.8.5_is1) (Version: - EaseUS)
Everio MediaBrowser 4 (HKLM-x32\...\{548F12A2-BD2E-4B5A-9B62-BBC0AA8EB3DD}) (Version: 4.00.214 - PIXELA)
FaceFilter Studio Brother Edition (HKLM-x32\...\{F59205C8-E5FB-43F5-AAB2-16C1760D4F59}) (Version: 1.0 - )
FastStone Photo Resizer 3.1 (HKLM-x32\...\FastStone Photo Resizer) (Version: 3.1 - FastStone Soft.)
Gamers Unite! Snag Bar (HKCU\...\Gamers Unite! Snag Bar) (Version: - )
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.1.50.5145 - Gretech Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
GS Auto Clicker (HKLM-x32\...\GS Auto Clicker_is1) (Version: V3.1.2 - goldensoft.org)
HijackThis 2.0.2 (HKLM-x32\...\HijackThis) (Version: 2.0.2 - TrendMicro)
InstaCodecs (HKLM-x32\...\InstaCodecs_is1) (Version: 1.0 - )
LG PC Suite (HKLM-x32\...\LG PC Suite) (Version: 5.3.03.20130809 - LG Electronics)
LG United Mobile Drivers (HKLM-x32\...\{55031CEF-CE75-4A5C-8DEA-60577820529B}) (Version: 3.10.1.0 - LG Electronics)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft Internationalized Domain Names Mitigation APIs (Version: - Microsoft Corporation) Hidden
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 (Version: - Microsoft Corporation) Hidden
Microsoft National Language Support Downlevel APIs (Version: - Microsoft Corporation) Hidden
Microsoft Office Professional Edition 2003 (HKLM-x32\...\{91110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft XML Parser (x32 Version: 8.0.7820.0 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 6.0 Parser (HKLM\...\{633F3A7E-471D-4C08-A643-C184A2EE19AB}) (Version: 6.10.1129.0 - Microsoft Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - )
Opera Stable 23.0.1522.75 (HKLM-x32\...\Opera 23.0.1522.75) (Version: 23.0.1522.75 - Opera Software ASA)
PaperPort Image Printer 64-bit (HKLM\...\{ABA4FAF1-6389-45F9-92CE-3914A4E5C471}) (Version: 1.00.0000 - Nuance Communications, Inc.)
PicaJet Photo Recovery 1.0.1 Beta (HKLM-x32\...\PicaJet Photo Recovery) (Version: 1.0.1 Beta - PicaJet.Com)
PowerDVD (HKLM-x32\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: - )
Realtek AC'97 Audio (HKLM-x32\...\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version: 5.28 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.46 - Piriform)
ScanSoft PaperPort 11 (HKLM-x32\...\{7A8FF745-BBC5-482B-88E4-18D3178249A9}) (Version: 11.1.0000 - Nuance Communications, Inc.)
Sonic RecordNow! (HKLM-x32\...\{9541FED0-327F-4DF0-8B96-EF57EF622F19}) (Version: 6.5.1 - Sonic Solutions)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.0.12 - Safer-Networking Ltd.)
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 1.9.0 - Tweaking.com)
Update for Windows XP (KB927891) (HKLM\...\KB927891) (Version: 5 - Microsoft Corporation)
Update for Windows XP (KB955839) (HKLM\...\KB955839) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB967715) (HKLM\...\KB967715) (Version: 1 - Microsoft Corporation)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc)
Winamp Detector Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (04/28/2006 1.3.1.0) (HKLM\...\9E140F48C9836B9B78539C08FB2B17146BDB3F65) (Version: 04/28/2006 1.3.1.0 - Advanced Micro Devices)
Windows XP Service Pack 2 (HKLM\...\Windows x64 Service Pack) (Version: 20070217.000042 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Wondershare Photo Recovery (build 3.0.3) (HKLM-x32\...\Wondershare Photo Recovery_is1) (Version: - Wondershare Software Co., Ltd.)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
23-07-2014 16:19:04 System Checkpoint
24-07-2014 01:20:58 System Checkpoint
26-07-2014 18:42:42 System Checkpoint
29-07-2014 21:09:51 System Checkpoint
01-08-2014 20:54:19 System Checkpoint
06-08-2014 14:18:44 System Checkpoint
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-03-29 06:00 - 2014-08-13 08:27 - 00450613 ____R C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 www.123fporn.info
127.0.0.1 123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
There are 1000 more lines.
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rel.job => C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rmv.job => C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe
Task: C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job.bak => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job.bak => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1403122415.job => C:\Program Files (x86)\Opera 22 0 1471 70\launcher.exe
Task: C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
==================== Loaded Modules (whitelisted) =============
2014-08-12 14:39 - 2014-08-12 14:39 - 00957048 _____ () C:\Program Files (x86)\Opera 22 0 1471 70\23.0.1522.75\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:8CE646EE
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UploadMgr => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/13/2014 05:29:55 PM) (Source: VSS) (EventID: 18) (User: )
Description: Volume Shadow Copy Service error: The Volume Shadow Copy infrastructure cannot be used during Safe Mode.
Error: (08/13/2014 05:02:34 PM) (Source: VSS) (EventID: 8211) (User: )
Description: Volume Shadow Copy Service error: Writer with name WMI Writer and ID {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} attempted to subscribe in safe mode.
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
System errors:
=============
Error: (08/13/2014 05:18:58 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Error: (08/13/2014 05:03:56 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
AmdK8
Avgdiska
AVGIDSDriverl
Avgldx64
BIOS
Fips
Error: (08/13/2014 05:03:56 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The AVGIDSAgent service depends on the AVGIDSDriverl service which failed to start because of the following error:
%%31
Error: (08/13/2014 05:02:36 PM) (Source: 0) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\Drivers\MxlW2k.SYS
Error: (08/13/2014 04:36:36 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {E60687F7-01A1-40AA-86AC-DB1CBF673334} did not register with DCOM within the required timeout.
Error: (08/13/2014 01:29:07 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generate Activation Context failed for C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe.
Reference error message: The referenced assembly is not installed on your system.
.
Error: (08/13/2014 01:29:07 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls.
Reference error message: The referenced assembly is not installed on your system.
.
Error: (08/13/2014 01:29:07 PM) (Source: SideBySide) (EventID: 32) (User: )
Description: Dependent Assembly Microsoft.Windows.Common-Controls could not be found and Last Error was The referenced assembly is not installed on your system.
Error: (08/13/2014 01:25:50 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Automatic Updates service hung on starting.
Error: (08/13/2014 01:23:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
%%1053
Microsoft Office Sessions:
=========================
Error: (08/13/2014 05:29:55 PM) (Source: VSS) (EventID: 18) (User: )
Description:
Error: (08/13/2014 05:02:34 PM) (Source: VSS) (EventID: 8211) (User: )
Description: WMI Writer{a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
==================== Memory info ===========================
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+
Percentage of memory in use: 18%
Total physical RAM: 3774.23 MB
Available physical RAM: 3092.71 MB
Total Pagefile: 5578.73 MB
Available Pagefile: 5236.39 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:279.47 GB) (Free:7.81 GB) NTFS
Drive d: () (Fixed) (Total:465.75 GB) (Free:342.63 GB) NTFS
==================== MBR & Partition Table ==================
Disk: 0 (MBR Code: Windows XP) (Size: 466 GB) (Disk ID: 0A210A21)
Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 279 GB) (Disk ID: 29632963)
Partition 1: (Active) - (Size=279 GB) - (Type=07 NTFS)
==================== End Of Log
aswMBR version 1.0.1.2041 Copyright(c) 2014 AVAST Software
Run date: 2014-08-13 17:39:22
-----------------------------
17:39:22.953 OS Version: Windows x64 5.2.3790 Service Pack 2
17:39:22.953 Number of processors: 2 586 0x2B01
17:39:22.953 ComputerName: DJ-RAC-PUTTER UserName: DJ RAC
17:39:23.750 Initialize success
17:39:23.843 VM: driver load error: 2
17:50:28.109 AVAST engine defs: 14081301
18:01:39.265 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-f
18:01:39.265 Disk 0 Vendor: WDC_WD5000AAKB-00H8A0 05.04E05 Size: 476940MB BusType: 3
18:01:39.281 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T1L0-17
18:01:39.296 Disk 1 Vendor: Maxtor_6L300R0 BAH41G10 Size: 286188MB BusType: 3
18:01:39.437 Disk 1 MBR read successfully
18:01:39.437 Disk 1 MBR scan
18:01:39.500 Disk 1 Windows XP default MBR code
18:01:39.515 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 286179 MB offset 63
18:01:39.546 Disk 1 scanning C:\WINDOWS\system32\drivers
18:01:45.890 Service scanning
18:01:58.968 Modules scanning
18:01:59.000 Disk 1 trace - called modules:
18:02:01.750 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys atapi.sys pciide.sys PCIIDEX.SYS hal.dll
18:02:01.906 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffadfa377b770]
18:02:02.062 3 CLASSPNP.SYS[fffffadf98e0a8c9] -> nt!IofCallDriver -> \Device\00000066[0xfffffadfa377ca30]
18:02:02.218 5 ACPI.sys[fffffadf98fa9e69] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T1L0-17[0xfffffadfa377d060]
18:02:03.000 AVAST engine scan C:\WINDOWS
18:02:05.531 AVAST engine scan C:\WINDOWS\system32
18:03:47.265 AVAST engine scan C:\WINDOWS\system32\drivers
18:04:00.593 AVAST engine scan C:\Documents and Settings\DJ RAC
18:14:20.312 AVAST engine scan C:\Documents and Settings\All Users
18:16:15.843 Scan finished successfully
18:18:25.906 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\DJ RAC\Desktop\New logs frst64\MBR.dat"
18:18:25.921 The log file has been saved successfully to "C:\Documents and Settings\DJ RAC\Desktop\New logs frst64\aswMBR.txt"
ran
System: XP Pro x64 Edition
Ver 2003
Service Pack 2
not sure if i had to turn of or not
please let me know if more info is needed
thanks
Ver 2003
Service Pack 2
hello, again my comp is infected
the symptoms are that is really really slow when in full mode & the hard drives never stop working even when i have not used it for a long time. the green light never stops blinking also, right now im running it on safe mode
ran avg, spybot & malware but nothing found
here are the Farbar Recovery Scan Tool and aswMBR logs
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-08-2014 01
Ran by DJ RAC (administrator) on DJ-RAC-PUTTER on 13-08-2014 17:36:37
Running from C:\Documents and Settings\DJ RAC\Desktop
Platform: Microsoft Windows XP Service Pack 2 (X64) OS Language: English (United States)
Internet Explorer Version 7
Boot Mode: Safe Mode (with Networking)
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [577536 2006-08-03] (Realtek Semiconductor Corp.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5187088 2014-07-10] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2640408 2014-08-11] ()
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Winlogon: [Userinit] userinit, [X]
HKLM\...\Winlogon: [UIHost] C:\Windows\system32\logonui.exe [662016 2007-02-17] ( (Microsoft Corporation))
Winlogon\Notify\crypt32chain: C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
Winlogon\Notify\cryptnet: C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
Winlogon\Notify\cscdll: C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
Winlogon\Notify\dimsntfy: C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
Winlogon\Notify\ScCertProp: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\Schedule: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\sclgntfy: C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\SensLogn: C:\WINDOWS\system32\WlNotify.dll (Microsoft Corporation)
Winlogon\Notify\termsrv: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\wlballoon: C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Winlogon\Notify\crypt32chain-x32: C:\WINDOWS\SysWOW64\crypt32.dll (Microsoft Corporation)
Winlogon\Notify\cryptnet-x32: C:\WINDOWS\SysWOW64\cryptnet.dll (Microsoft Corporation)
Winlogon\Notify\cscdll-x32: C:\WINDOWS\SysWOW64\cscdll.dll (Microsoft Corporation)
Winlogon\Notify\dimsntfy-x32: C:\WINDOWS\SysWOW64\dimsntfy.dll (Microsoft Corporation)
Winlogon\Notify\EFS-x32: C:\WINDOWS\SysWOW64\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\ScCertProp-x32: wlnotify.dll [X]
Winlogon\Notify\Schedule-x32: wlnotify.dll [X]
Winlogon\Notify\sclgntfy-x32: C:\WINDOWS\SysWOW64\sclgntfy.dll (Microsoft Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
Winlogon\Notify\SensLogn-x32: WlNotify.dll [X]
Winlogon\Notify\wlballoon-x32: wlnotify.dll [X]
HKLM\...\Command Processor: <======= ATTENTION
HKLM-x32\...\Command Processor: <======= ATTENTION
HKU\.DEFAULT\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-19\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [tscuninstall] => C:\Windows\system32\tscupgrd.exe [62464 2006-03-29] (Microsoft Corporation)
HKU\S-1-5-21-2799395484-3895304042-2403659751-1002\...\MountPoints2: {2d27d8a5-3283-11e3-8e94-00e04d1c5274} - E:\LGAutoRun.exe
HKU\S-1-5-21-2799395484-3895304042-2403659751-1002\...\MountPoints2: {e39d701f-90fe-11e2-9c15-00e04d1c5274} - D:\LaunchU3.exe -a
IFEO\Your Image File Name Here without a path: [Debugger] ntsd -d
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
SSODL-x32: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\syswow64\SHELL32.dll (Microsoft Corporation)
SSODL-x32: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\syswow64\SHELL32.dll (Microsoft Corporation)
SSODL-x32: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\SysWOW64\stobject.dll (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean64.exeC:\PROGRA~2\AVG\AVG2014\avgrsa.exe /sync /restart
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={78CBEA97-1813-44AE-A46F-4CD435A77274}&mid=63957768860347d38e83d1a90bf8bb87-8d758629d5135f4470f57152dc116841b6490bd7&lang=en&ds=AVG&pr=fr&d=2013-05-25 00:51:20&v=15.3.0.11&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
Toolbar: HKLM-x32 - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
DPF: HKLM-x32 {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1363890949984
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\Windows\system32\mshtml.dll (Microsoft Corporation)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\Windows\SysWow64\mshtml.dll (Microsoft Corporation)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search)
Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Filter-x32: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Filter-x32: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SysWOW64\urlmon.dll (Microsoft Corporation)
Filter-x32: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\Windows\SysWow64\SHELL32.dll (Microsoft Corporation)
ShellExecuteHooks: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [10508288 2009-02-10] (Microsoft Corporation)
ShellExecuteHooks-x32: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\SysWOW64\shell32.dll [8360960 2009-02-10] (Microsoft Corporation)
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\mswsock.dll [233472] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 03 %SystemRoot%\System32\mswsock.dll [492544] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.3.25
FireFox:
========
FF ProfilePath: C:\Documents and Settings\DJ RAC\Application Data\Mozilla\Firefox\Profiles\afjw053j.default
FF Homepage: about:newtab
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VLC Media Player 2 0 8 win32\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49
FF Extension: AVG SafeGuard toolbar - C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49 [2014-01-05]
Chrome:
=======
CHR NewTab: "chrome-extension://dpjamkmjmigaoobjbekmfgabipmfilij/empty_ntp.html"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2003) - C:\Program Files (x86)\Firefox Mozilla Ver 19 0 2\plugins\NPOFFICE.DLL No File
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Firefox Mozilla Ver 19 0 2\plugins\npwachk.dll No File
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.0.0\\npsitesafety.dll (AVG Technologies)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Extension: (Google Drive) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-23]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-02]
CHR Extension: (YouTube) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-23]
CHR Extension: (Google Search) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-23]
CHR Extension: (Empty New Tab Page) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dpjamkmjmigaoobjbekmfgabipmfilij [2013-12-03]
CHR Extension: (Google Wallet) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Gmail) - C:\Documents and Settings\DJ RAC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-23]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AeLookupSvc; C:\Windows\SysWOW64\aelupsvc.dll [26624 2006-03-29] (Microsoft Corporation)
S4 Alerter; C:\Windows\system32\alrsvc.dll [29696 2006-03-29] (Microsoft Corporation)
S3 ALG; C:\Windows\SysWOW64\alg.exe [45056 2006-03-29] (Microsoft Corporation)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3244048 2014-07-10] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-07-10] (AVG Technologies CZ, s.r.o.)
S2 Browser; C:\Windows\SysWOW64\browser.dll [78336 2007-02-18] (Microsoft Corporation)
S3 ClipSrv; C:\Windows\system32\clipsrv.exe [49664 2006-03-29] (Microsoft Corporation)
S3 ClipSrv; C:\Windows\SysWOW64\clipsrv.exe [32256 2006-03-29] (Microsoft Corporation)
R2 dmadmin; C:\Windows\System32\dmadmin.exe [399872 2007-02-17] (Microsoft Corporation)
R2 dmserver; C:\Windows\System32\dmserver.dll [37376 2007-02-17] (Microsoft Corporation)
S2 ERSvc; C:\Windows\System32\ersvc.dll [31744 2006-03-29] (Microsoft Corporation)
R2 helpsvc; C:\Windows\PCHealth\HelpCtr\Binaries\pchsvc.dll [77312 2007-02-17] (Microsoft Corporation)
S3 HTTPFilter; C:\Windows\System32\w3ssl.dll [21504 2006-03-29] (Microsoft Corporation)
S3 IASJet; C:\Windows\SysWOW64\iasrecst.dll [162816 2006-03-29] (Microsoft Corporation)
S3 ImapiService; C:\WINDOWS\system32\imapi.exe [265728 2007-02-17] (Microsoft Corporation)
S4 Messenger; C:\Windows\System32\msgsvc.dll [57344 2007-02-17] (Microsoft Corporation)
S3 mnmsrvc; C:\WINDOWS\SysWOW64\mnmsrvc.exe [32768 2006-03-29] (Microsoft Corporation)
S3 NetDDE; C:\Windows\system32\netdde.exe [160768 2007-02-17] (Microsoft Corporation)
S3 NetDDEdsdm; C:\Windows\system32\netdde.exe [160768 2007-02-17] (Microsoft Corporation)
R3 Netman; C:\Windows\SysWOW64\netman.dll [263680 2007-02-18] (Microsoft Corporation)
S3 Nla; C:\Windows\System32\mswsock.dll [492544 2008-06-21] (Microsoft Corporation)
S3 Nla; C:\Windows\SysWOW64\mswsock.dll [233472 2008-06-21] (Microsoft Corporation)
S3 NtLmSsp; C:\Windows\system32\lsass.exe [14336 2006-03-29] (Microsoft Corporation)
S2 NtmsSvc; C:\Windows\system32\ntmssvc.dll [794112 2007-02-17] (Microsoft Corporation)
S2 NVSvc; C:\Windows\system32\nvsvc64.exe [135680 2006-03-31] (NVIDIA Corporation)
R2 PlugPlay; C:\Windows\system32\services.exe [227840 2009-03-19] (Microsoft Corporation)
S2 PolicyAgent; C:\Windows\system32\lsass.exe [14336 2006-03-29] (Microsoft Corporation)
S3 RasAuto; C:\Windows\SysWOW64\rasauto.dll [91648 2007-02-18] (Microsoft Corporation)
S3 RasMan; C:\Windows\SysWOW64\rasmans.dll [181760 2007-02-18] (Microsoft Corporation)
S3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [212480 2007-02-17] (Microsoft Corporation)
S3 RpcLocator; C:\Windows\SysWOW64\locator.exe [71680 2006-03-29] (Microsoft Corporation)
S3 SCardSvr; C:\Windows\System32\SCardSvr.exe [166400 2007-02-17] (Microsoft Corporation)
S2 Schedule; C:\Windows\SysWOW64\schedsvc.dll [202240 2007-02-18] (Microsoft Corporation)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
S2 seclogon; C:\Windows\SysWOW64\seclogon.dll [18432 2007-02-18] (Microsoft Corporation)
R2 srservice; C:\WINDOWS\system32\srsvc.dll [231424 2007-02-17] (Microsoft Corporation)
S2 SysmonLog; C:\Windows\system32\smlogsvc.exe [133120 2007-02-17] (Microsoft Corporation)
S2 SysmonLog; C:\Windows\SysWOW64\smlogsvc.exe [96256 2007-02-18] (Microsoft Corporation)
S4 TlntSvr; C:\WINDOWS\system32\tlntsvr.exe [113152 2007-02-17] (Microsoft Corporation)
S2 TrkWks; C:\Windows\SysWOW64\trkwks.dll [86528 2007-02-18] (Microsoft Corporation)
S2 UMWdf; C:\WINDOWS\system32\wdfmgr.exe [62976 2006-03-29] (Microsoft Corporation)
S2 UMWdf; C:\WINDOWS\SysWOW64\wdfmgr.exe [39424 2006-03-29] (Microsoft Corporation)
S3 UPS; C:\Windows\System32\ups.exe [34816 2006-03-29] (Microsoft Corporation)
S3 UPS; C:\Windows\SysWOW64\ups.exe [16896 2006-03-29] (Microsoft Corporation)
S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-11] (AVG Secure Search)
S3 WmdmPmSN; C:\WINDOWS\system32\mspmsnsv.dll [36352 2007-02-17] (Microsoft Corporation)
S3 Wmi; C:\Windows\System32\advapi32.dll [1052160 2009-03-19] (Microsoft Corporation)
S3 Wmi; C:\Windows\SysWOW64\advapi32.dll [619008 2009-03-19] (Microsoft Corporation)
S2 wuauserv; C:\WINDOWS\system32\wuauserv.dll [12288 2006-03-29] (Microsoft Corporation)
R2 WZCSVC; C:\Windows\System32\wzcsvc.dll [659968 2007-02-17] (Microsoft Corporation)
R2 WZCSVC; C:\Windows\SysWOW64\wzcsvc.dll [489472 2007-02-18] (Microsoft Corporation)
S3 xmlprov; C:\Windows\System32\xmlprov.dll [326144 2007-02-17] (Microsoft Corporation)
S3 xmlprov; C:\Windows\SysWOW64\xmlprov.dll [131584 2007-02-18] (Microsoft Corporation)
R2 Eventlog; [X]
S4 HidServ; %SystemRoot%\System32\hidserv.dll [X]
S3 WinHttpAutoProxySvc; winhttp.dll [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 Abiosdsk; No ImagePath
S4 ACPIEC; C:\Windows\System32\Drivers\ACPIEC.sys [18432 2006-03-29] (Microsoft Corporation)
S4 adpu160m; No ImagePath
S4 adpu320; No ImagePath
S3 aec; C:\Windows\System32\drivers\aec.sys [188928 2005-03-24] (Microsoft Corporation)
S4 aic78u2; No ImagePath
S4 aic78xx; No ImagePath
S3 ALCXWDM; C:\Windows\System32\drivers\ALCWDM64.SYS [3304448 2006-10-13] (Realtek Semiconductor Corp.)
S4 AliIde; No ImagePath
S4 AmdIde; No ImagePath
S1 AmdK8; C:\Windows\System32\DRIVERS\amdk8.sys [51200 2006-05-10] (Advanced Micro Devices)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2013-04-18] (Google Inc)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
S4 arc; No ImagePath
S4 Atdisk; No ImagePath
S3 Atmarpc; C:\Windows\System32\DRIVERS\atmarpc.sys [106496 2007-02-17] (Microsoft Corporation)
S3 audstub; C:\Windows\System32\DRIVERS\audstub.sys [5632 2005-03-24] (Microsoft Corporation)
S1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriverl; C:\Windows\System32\DRIVERS\avgidsdriverla.sys [227608 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx64.sys [50976 2014-08-11] (AVG Technologies)
S1 BIOS; C:\WINDOWS\system32\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
S1 BIOS; C:\WINDOWS\SysWOW64\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
S2 CdaC15BA; C:\Windows\System32\DRIVERS\CdaC15BA.sys [13312 2006-03-29] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
S2 CdaD10BA; C:\Windows\System32\DRIVERS\CdaD10BA.sys [13312 2006-03-29] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
S1 Changer; No ImagePath
S4 CmdIde; No ImagePath
S4 dmboot; C:\Windows\System32\drivers\dmboot.sys [415232 2007-02-17] (Microsoft Corporation)
R0 dmio; C:\Windows\System32\drivers\dmio.sys [244224 2007-02-17] (Microsoft Corporation)
R0 dmload; C:\Windows\System32\drivers\dmload.sys [9216 2006-03-29] (Microsoft Corporation)
S4 dpti2o; No ImagePath
S1 Fips; C:\Windows\System32\Drivers\Fips.sys [50176 2007-02-17] (Microsoft Corporation)
R0 Ftdisk; C:\Windows\System32\DRIVERS\ftdisk.sys [240128 2007-02-17] (Microsoft Corporation)
R3 Gpc; C:\Windows\System32\DRIVERS\msgpc.sys [71168 2007-02-17] (Microsoft Corporation)
S1 i2omgmt; No ImagePath
S4 iirsp; No ImagePath
R1 imapi; C:\Windows\System32\DRIVERS\imapi.sys [72704 2006-03-29] (Microsoft Corporation)
S4 IntelIde; No ImagePath
S3 Ip6Fw; C:\Windows\System32\drivers\ip6fw.sys [57856 2007-02-17] (Microsoft Corporation)
S3 IpInIp; No ImagePath
R1 IPSec; C:\Windows\System32\DRIVERS\ipsec.sys [156672 2007-02-17] (Microsoft Corporation)
S3 kmixer; C:\Windows\System32\drivers\kmixer.sys [204288 2005-03-24] (Microsoft Corporation)
S1 mnmdd; C:\Windows\System32\Drivers\mnmdd.sys [8192 2006-03-29] (Microsoft Corporation)
S4 mraid35x; No ImagePath
S3 MxlW2k; C:\Windows\SysWow64\Drivers\MxlW2k.sys [28276 2013-03-18] (MusicMatch, Inc.) [File not signed]
S3 nv; C:\Windows\System32\DRIVERS\nv4_mini.sys [4818944 2006-03-31] (NVIDIA Corporation)
R0 nvata64; C:\Windows\System32\DRIVERS\nvata64.sys [164864 2006-04-24] (NVIDIA Corporation)
R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [52736 2006-02-17] (NVIDIA Corporation)
R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [22016 2006-02-17] (NVIDIA Corporation)
S3 PDCOMP; No ImagePath
S3 PDFRAME; No ImagePath
S3 PDRELI; No ImagePath
S3 PDRFRAME; No ImagePath
R3 PSched; C:\Windows\System32\DRIVERS\psched.sys [106496 2007-02-17] (Microsoft Corporation)
R3 Ptilink; C:\Windows\System32\DRIVERS\ptilink.sys [31232 2006-03-29] (Parallel Technologies, Inc.)
S0 PxHelp64; C:\Windows\SysWOW64\DRIVERS\PxHelp64.sys [47872 2003-07-30] (Sonic Solutions) [File not signed]
R3 Raspti; C:\Windows\System32\DRIVERS\raspti.sys [31232 2006-03-29] (Microsoft Corporation)
R1 redbook; C:\Windows\System32\DRIVERS\redbook.sys [64000 2005-03-24] (Microsoft Corporation)
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [171008 2007-02-17] (Microsoft Corporation)
S4 Simbad; No ImagePath
S3 splitter; C:\Windows\System32\drivers\splitter.sys [10240 2007-02-17] (Microsoft Corporation)
R0 sr; C:\Windows\System32\DRIVERS\sr.sys [123904 2006-03-29] (Microsoft Corporation)
S3 swmidi; C:\Windows\System32\drivers\swmidi.sys [86528 2005-03-24] (Microsoft Corporation)
S4 symc8xx; No ImagePath
S4 symmpi; No ImagePath
S4 sym_hi; No ImagePath
S4 sym_u3; No ImagePath
S3 sysaudio; C:\Windows\System32\drivers\sysaudio.sys [147456 2007-02-17] (Microsoft Corporation)
S4 TosIde; No ImagePath
S4 ultra; No ImagePath
R3 Update; C:\Windows\System32\DRIVERS\update.sys [81920 2007-02-17] (Microsoft Corporation)
S4 ViaIde; No ImagePath
S3 WDICA; No ImagePath
S3 wdmaud; C:\Windows\System32\drivers\wdmaud.sys [187904 2007-02-17] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
NETSVCx32: Browser -> C:\Windows\SysWOW64\browser.dll (Microsoft Corporation)
NETSVCx32: CryptSvc -> C:\Windows\SysWOW64\cryptsvc.dll (Microsoft Corporation)
NETSVCx32: DMServer -> C:\Windows\SysWOW64\dmserver.dll ==> No File.
NETSVCx32: EventSystem -> C:\WINDOWS\SysWOW64\es.dll (Microsoft Corporation)
NETSVCx32: HidServ -> C:\Windows\SysWOW64\hidserv.dll ==> No File.
NETSVCx32: Iprip -> No ServiceDLL Path.
NETSVCx32: LanmanWorkstation -> C:\Windows\SysWOW64\wkssvc.dll ==> No File.
NETSVCx32: Messenger -> C:\Windows\SysWOW64\msgsvc.dll ==> No File.
NETSVCx32: Netman -> C:\Windows\SysWOW64\netman.dll (Microsoft Corporation)
NETSVCx32: Seclogon -> C:\Windows\SysWOW64\seclogon.dll (Microsoft Corporation)
NETSVCx32: TrkWks -> C:\Windows\SysWOW64\trkwks.dll (Microsoft Corporation)
NETSVCx32: WZCSVC -> C:\Windows\SysWOW64\wzcsvc.dll (Microsoft Corporation)
NETSVCx32: wscsvc -> C:\Windows\SysWOW64\wscsvc.dll ==> No File.
NETSVCx32: xmlprov -> C:\Windows\SysWOW64\xmlprov.dll (Microsoft Corporation)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-13 17:36 - 2014-08-13 17:36 - 00027090 _____ () C:\Documents and Settings\DJ RAC\Desktop\FRST.txt
2014-08-13 17:35 - 2014-08-13 17:36 - 00000000 ____D () C:\FRST
2014-08-13 17:30 - 2014-08-13 17:30 - 02100224 _____ (Farbar) C:\Documents and Settings\DJ RAC\Desktop\FRST64.exe
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\RegBackup
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com
2014-08-13 17:27 - 2014-08-13 17:27 - 04057608 _____ () C:\Documents and Settings\DJ RAC\Desktop\tweaking.com_registry_backup_setup.exe
2014-08-13 17:27 - 2014-08-13 17:27 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-08-13 17:00 - 2014-08-13 17:00 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\hijackthis 08 13 14 17 00 PM .log
2014-08-13 14:02 - 2014-08-13 14:02 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 14 02 pm after all scans hijackthis.log
2014-08-13 11:25 - 2014-08-13 11:25 - 00006894 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 11 25 am after malware scan hijackthis.log
2014-08-13 09:32 - 2014-08-13 09:32 - 00006893 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 09 32 am after spy scan hijackthis.log
2014-08-13 08:27 - 2014-06-19 12:47 - 00450613 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140813-082716.backup
2014-08-13 08:12 - 2014-08-13 08:12 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 08 12 am after avg scan hijackthis.log
2014-08-13 07:10 - 2014-08-13 07:10 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 07 09 am b4 scans hijackthis.log
2014-08-13 07:08 - 2014-08-13 16:58 - 00000000 ____D () C:\Program Files (x86)\Trend Micro HijackThis Ver 2 0 2
2014-08-13 07:08 - 2014-08-13 07:08 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis
2014-08-13 06:51 - 2014-08-13 17:03 - 00000000 _____ () C:\WINDOWS\0.log
2014-08-13 03:18 - 2014-08-13 17:00 - 00005115 _____ () C:\WINDOWS\WindowsUpdate.log
2014-08-11 21:22 - 2014-08-13 02:26 - 00000199 _____ () C:\Documents and Settings\DJ RAC\Desktop\major crimes.txt
2014-07-29 22:17 - 2014-07-31 15:16 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Desktop\priscillas
2014-07-25 03:02 - 2014-08-13 17:00 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-07-25 00:48 - 2014-07-26 22:41 - 00002049 _____ () C:\Documents and Settings\DJ RAC\Desktop\disco music mix.txt
2014-07-16 23:18 - 2014-07-19 15:04 - 00000078 _____ () C:\Documents and Settings\DJ RAC\Desktop\baladas 70s.txt
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-13 17:36 - 2014-08-13 17:36 - 00027090 _____ () C:\Documents and Settings\DJ RAC\Desktop\FRST.txt
2014-08-13 17:36 - 2014-08-13 17:35 - 00000000 ____D () C:\FRST
2014-08-13 17:36 - 2013-03-20 20:30 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Local Settings\Temp
2014-08-13 17:30 - 2014-08-13 17:30 - 02100224 _____ (Farbar) C:\Documents and Settings\DJ RAC\Desktop\FRST64.exe
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\RegBackup
2014-08-13 17:29 - 2014-08-13 17:29 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com
2014-08-13 17:27 - 2014-08-13 17:27 - 04057608 _____ () C:\Documents and Settings\DJ RAC\Desktop\tweaking.com_registry_backup_setup.exe
2014-08-13 17:27 - 2014-08-13 17:27 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-08-13 17:18 - 2006-03-29 06:00 - 00002422 _____ () C:\WINDOWS\system32\wpa.dbl
2014-08-13 17:03 - 2014-08-13 06:51 - 00000000 _____ () C:\WINDOWS\0.log
2014-08-13 17:00 - 2014-08-13 17:00 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\hijackthis 08 13 14 17 00 PM .log
2014-08-13 17:00 - 2014-08-13 03:18 - 00005115 _____ () C:\WINDOWS\WindowsUpdate.log
2014-08-13 17:00 - 2014-07-25 03:02 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-08-13 17:00 - 2013-03-20 20:30 - 00000178 ___SH () C:\Documents and Settings\DJ RAC\ntuser.ini
2014-08-13 17:00 - 2013-03-20 12:12 - 00524288 _____ () C:\WINDOWS\system32\config\SpybotSD.evt
2014-08-13 17:00 - 2013-03-19 14:13 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2014-08-13 17:00 - 2013-03-18 07:24 - 00032470 _____ () C:\WINDOWS\Tasks\SchedLgU.Txt
2014-08-13 17:00 - 2013-03-18 07:24 - 00000216 _____ () C:\Documents and Settings\LocalService\wiadebug.log
2014-08-13 17:00 - 2013-03-18 07:24 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-08-13 16:58 - 2014-08-13 07:08 - 00000000 ____D () C:\Program Files (x86)\Trend Micro HijackThis Ver 2 0 2
2014-08-13 16:08 - 2013-10-09 18:28 - 00000898 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-13 14:39 - 2014-06-18 14:13 - 00000442 _____ () C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1403122415.job
2014-08-13 14:02 - 2014-08-13 14:02 - 00007451 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 14 02 pm after all scans hijackthis.log
2014-08-13 13:29 - 2014-02-05 23:44 - 00000374 _____ () C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rmv.job
2014-08-13 13:29 - 2014-02-05 23:44 - 00000372 _____ () C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rel.job
2014-08-13 13:29 - 2013-10-09 18:28 - 00000894 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-13 13:29 - 2013-03-20 12:12 - 00000632 _____ () C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
2014-08-13 13:29 - 2013-03-18 07:35 - 00050257 _____ () C:\WINDOWS\system32\nvapps.xml
2014-08-13 13:28 - 2013-03-18 13:22 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MFAData
2014-08-13 11:25 - 2014-08-13 11:25 - 00006894 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 11 25 am after malware scan hijackthis.log
2014-08-13 09:32 - 2014-08-13 09:32 - 00006893 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 09 32 am after spy scan hijackthis.log
2014-08-13 08:13 - 2013-03-20 12:12 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-08-13 08:12 - 2014-08-13 08:12 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 08 12 am after avg scan hijackthis.log
2014-08-13 07:10 - 2014-08-13 07:10 - 00006828 _____ () C:\Documents and Settings\DJ RAC\Desktop\08 13 14 07 09 am b4 scans hijackthis.log
2014-08-13 07:08 - 2014-08-13 07:08 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis
2014-08-13 02:45 - 2013-03-20 20:30 - 00000000 ____D () C:\Documents and Settings\DJ RAC
2014-08-13 02:26 - 2014-08-11 21:22 - 00000199 _____ () C:\Documents and Settings\DJ RAC\Desktop\major crimes.txt
2014-08-13 00:30 - 2013-03-20 12:12 - 00000628 _____ () C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2014-08-12 14:39 - 2014-06-18 14:13 - 00000000 ____D () C:\Program Files (x86)\Opera 22 0 1471 70
2014-08-11 20:41 - 2014-03-15 10:18 - 00000000 ____D () C:\Program Files (x86)\AVG SafeGuard toolbar
2014-08-11 20:41 - 2013-05-20 17:57 - 00000000 ____D () C:\WINDOWS\SysWOW64\cache
2014-08-11 20:41 - 2013-03-18 13:31 - 00050976 _____ (AVG Technologies) C:\WINDOWS\system32\Drivers\avgtpx64.sys
2014-08-11 15:09 - 2013-03-20 20:30 - 00000265 _____ () C:\Documents and Settings\DJ RAC\wiadebug.log
2014-08-11 14:42 - 2014-04-03 13:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 30 0
2014-08-06 15:37 - 2013-03-18 16:22 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\DVD Shrink
2014-08-04 15:12 - 2013-03-20 20:52 - 00000178 ___SH () C:\Documents and Settings\Lety\ntuser.ini
2014-08-04 15:11 - 2013-03-20 20:52 - 00000000 ____D () C:\Documents and Settings\Lety\Local Settings\Temp
2014-08-04 15:03 - 2013-03-24 14:56 - 00000000 ____D () C:\Documents and Settings\Lety\Desktop\SAVE IT HERE
2014-08-04 15:03 - 2013-03-20 20:52 - 00000265 _____ () C:\Documents and Settings\Lety\wiadebug.log
2014-08-04 10:17 - 2014-05-01 09:12 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2014 Ver 2014 0 4744
2014-08-01 00:30 - 2013-03-20 12:12 - 00000458 _____ () C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
2014-07-31 15:32 - 2013-03-18 17:32 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\TEMP
2014-07-31 15:16 - 2014-07-29 22:17 - 00000000 ____D () C:\Documents and Settings\DJ RAC\Desktop\priscillas
2014-07-29 19:22 - 2013-03-23 19:44 - 00000178 ___SH () C:\Documents and Settings\Prisc & Vane\ntuser.ini
2014-07-29 19:12 - 2013-03-23 19:44 - 00000000 ____D () C:\Documents and Settings\Prisc & Vane\Local Settings\Temp
2014-07-26 22:41 - 2014-07-25 00:48 - 00002049 _____ () C:\Documents and Settings\DJ RAC\Desktop\disco music mix.txt
2014-07-25 03:02 - 2013-03-18 13:20 - 00699056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-07-25 03:02 - 2013-03-18 13:20 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-25 00:03 - 2013-03-23 03:32 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\YTD Video Downloader
2014-07-19 15:04 - 2014-07-16 23:18 - 00000078 _____ () C:\Documents and Settings\DJ RAC\Desktop\baladas 70s.txt
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!.
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
C:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!.
==================== End Of Log
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-08-2014 01
Ran by DJ RAC at 2014-08-13 17:37:13
Running from C:\Documents and Settings\DJ RAC\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
1-Click YouTube Downloader 9.0 (HKLM-x32\...\1-Click YouTube Downloader_is1) (Version: - )
Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.7.700.224 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
AoA Audio Extractor (HKLM-x32\...\{D1725D54-279A-40C5-A70D-23C1785DB920}_is1) (Version: - AoAMedia.com)
Asoftech Data Recovery (HKLM-x32\...\{1AED6EB7-8FEA-4021-B8FD-EBAA6B21679F}) (Version: 1.00 - )
Auslogics Disk Defrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 3.6 - Auslogics Software Pty Ltd)
Auslogics Duplicate File Finder (HKLM-x32\...\{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1) (Version: 2.5 - Auslogics Software Pty Ltd)
Auslogics Registry Cleaner (HKLM-x32\...\{8D8024F1-2945-49A5-9B78-5AB7B11D7942}_is1) (Version: 2.5 - Auslogics Software Pty Ltd)
Auslogics Registry Defrag (HKLM-x32\...\{D627784F-B3EE-44E8-96B1-9509B991EA34}_is1) (Version: 6.5 - Auslogics Software Pty Ltd)
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4744 - AVG Technologies)
AVG 2014 (Version: 14.0.4007 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4744 - AVG Technologies) Hidden
AVG SafeGuard toolbar (HKLM-x32\...\AVG SafeGuard toolbar) (Version: 18.1.9.786 - AVG Technologies)
Brother MFL-Pro Suite MFC-250C (HKLM-x32\...\{3A08B59E-A9F0-4F4D-B7E5-6875D7F13327}) (Version: 1.1.8.0 - Brother Industries, Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 3.28 - Piriform)
DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version: - DVD Shrink)
DVDFab 8.2.2.8 (26/02/2013) Qt (HKLM-x32\...\DVDFab 8 Qt_is1) (Version: - Fengtao Software Inc.)
EaseUS Data Recovery Wizard 5.8.5 (HKLM-x32\...\EaseUS Data Recovery Wizard 5.8.5_is1) (Version: - EaseUS)
Everio MediaBrowser 4 (HKLM-x32\...\{548F12A2-BD2E-4B5A-9B62-BBC0AA8EB3DD}) (Version: 4.00.214 - PIXELA)
FaceFilter Studio Brother Edition (HKLM-x32\...\{F59205C8-E5FB-43F5-AAB2-16C1760D4F59}) (Version: 1.0 - )
FastStone Photo Resizer 3.1 (HKLM-x32\...\FastStone Photo Resizer) (Version: 3.1 - FastStone Soft.)
Gamers Unite! Snag Bar (HKCU\...\Gamers Unite! Snag Bar) (Version: - )
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.1.50.5145 - Gretech Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
GS Auto Clicker (HKLM-x32\...\GS Auto Clicker_is1) (Version: V3.1.2 - goldensoft.org)
HijackThis 2.0.2 (HKLM-x32\...\HijackThis) (Version: 2.0.2 - TrendMicro)
InstaCodecs (HKLM-x32\...\InstaCodecs_is1) (Version: 1.0 - )
LG PC Suite (HKLM-x32\...\LG PC Suite) (Version: 5.3.03.20130809 - LG Electronics)
LG United Mobile Drivers (HKLM-x32\...\{55031CEF-CE75-4A5C-8DEA-60577820529B}) (Version: 3.10.1.0 - LG Electronics)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft Internationalized Domain Names Mitigation APIs (Version: - Microsoft Corporation) Hidden
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 (Version: - Microsoft Corporation) Hidden
Microsoft National Language Support Downlevel APIs (Version: - Microsoft Corporation) Hidden
Microsoft Office Professional Edition 2003 (HKLM-x32\...\{91110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft XML Parser (x32 Version: 8.0.7820.0 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 6.0 Parser (HKLM\...\{633F3A7E-471D-4C08-A643-C184A2EE19AB}) (Version: 6.10.1129.0 - Microsoft Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - )
Opera Stable 23.0.1522.75 (HKLM-x32\...\Opera 23.0.1522.75) (Version: 23.0.1522.75 - Opera Software ASA)
PaperPort Image Printer 64-bit (HKLM\...\{ABA4FAF1-6389-45F9-92CE-3914A4E5C471}) (Version: 1.00.0000 - Nuance Communications, Inc.)
PicaJet Photo Recovery 1.0.1 Beta (HKLM-x32\...\PicaJet Photo Recovery) (Version: 1.0.1 Beta - PicaJet.Com)
PowerDVD (HKLM-x32\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: - )
Realtek AC'97 Audio (HKLM-x32\...\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version: 5.28 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.46 - Piriform)
ScanSoft PaperPort 11 (HKLM-x32\...\{7A8FF745-BBC5-482B-88E4-18D3178249A9}) (Version: 11.1.0000 - Nuance Communications, Inc.)
Sonic RecordNow! (HKLM-x32\...\{9541FED0-327F-4DF0-8B96-EF57EF622F19}) (Version: 6.5.1 - Sonic Solutions)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.0.12 - Safer-Networking Ltd.)
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 1.9.0 - Tweaking.com)
Update for Windows XP (KB927891) (HKLM\...\KB927891) (Version: 5 - Microsoft Corporation)
Update for Windows XP (KB955839) (HKLM\...\KB955839) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB967715) (HKLM\...\KB967715) (Version: 1 - Microsoft Corporation)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc)
Winamp Detector Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (04/28/2006 1.3.1.0) (HKLM\...\9E140F48C9836B9B78539C08FB2B17146BDB3F65) (Version: 04/28/2006 1.3.1.0 - Advanced Micro Devices)
Windows XP Service Pack 2 (HKLM\...\Windows x64 Service Pack) (Version: 20070217.000042 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Wondershare Photo Recovery (build 3.0.3) (HKLM-x32\...\Wondershare Photo Recovery_is1) (Version: - Wondershare Software Co., Ltd.)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
23-07-2014 16:19:04 System Checkpoint
24-07-2014 01:20:58 System Checkpoint
26-07-2014 18:42:42 System Checkpoint
29-07-2014 21:09:51 System Checkpoint
01-08-2014 20:54:19 System Checkpoint
06-08-2014 14:18:44 System Checkpoint
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-03-29 06:00 - 2014-08-13 08:27 - 00450613 ____R C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 www.123fporn.info
127.0.0.1 123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
There are 1000 more lines.
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rel.job => C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0214b_rmv.job => C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe
Task: C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job.bak => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job.bak => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1403122415.job => C:\Program Files (x86)\Opera 22 0 1471 70\launcher.exe
Task: C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
==================== Loaded Modules (whitelisted) =============
2014-08-12 14:39 - 2014-08-12 14:39 - 00957048 _____ () C:\Program Files (x86)\Opera 22 0 1471 70\23.0.1522.75\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:8CE646EE
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UploadMgr => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/13/2014 05:29:55 PM) (Source: VSS) (EventID: 18) (User: )
Description: Volume Shadow Copy Service error: The Volume Shadow Copy infrastructure cannot be used during Safe Mode.
Error: (08/13/2014 05:02:34 PM) (Source: VSS) (EventID: 8211) (User: )
Description: Volume Shadow Copy Service error: Writer with name WMI Writer and ID {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} attempted to subscribe in safe mode.
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll (948) SUS20ClientDataStore: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 367, PgnoRoot: 2441) of database C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb (0 => 2441, wuaueng.dll0).
System errors:
=============
Error: (08/13/2014 05:18:58 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Error: (08/13/2014 05:03:56 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
AmdK8
Avgdiska
AVGIDSDriverl
Avgldx64
BIOS
Fips
Error: (08/13/2014 05:03:56 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The AVGIDSAgent service depends on the AVGIDSDriverl service which failed to start because of the following error:
%%31
Error: (08/13/2014 05:02:36 PM) (Source: 0) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\Drivers\MxlW2k.SYS
Error: (08/13/2014 04:36:36 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {E60687F7-01A1-40AA-86AC-DB1CBF673334} did not register with DCOM within the required timeout.
Error: (08/13/2014 01:29:07 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generate Activation Context failed for C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe.
Reference error message: The referenced assembly is not installed on your system.
.
Error: (08/13/2014 01:29:07 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls.
Reference error message: The referenced assembly is not installed on your system.
.
Error: (08/13/2014 01:29:07 PM) (Source: SideBySide) (EventID: 32) (User: )
Description: Dependent Assembly Microsoft.Windows.Common-Controls could not be found and Last Error was The referenced assembly is not installed on your system.
Error: (08/13/2014 01:25:50 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Automatic Updates service hung on starting.
Error: (08/13/2014 01:23:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
%%1053
Microsoft Office Sessions:
=========================
Error: (08/13/2014 05:29:55 PM) (Source: VSS) (EventID: 18) (User: )
Description:
Error: (08/13/2014 05:02:34 PM) (Source: VSS) (EventID: 8211) (User: )
Description: WMI Writer{a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
Error: (08/13/2014 05:00:37 PM) (Source: ESENT) (EventID: 447) (User: )
Description: wuaueng.dll948SUS20ClientDataStore: -3383672441C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb02441366
==================== Memory info ===========================
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+
Percentage of memory in use: 18%
Total physical RAM: 3774.23 MB
Available physical RAM: 3092.71 MB
Total Pagefile: 5578.73 MB
Available Pagefile: 5236.39 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:279.47 GB) (Free:7.81 GB) NTFS
Drive d: () (Fixed) (Total:465.75 GB) (Free:342.63 GB) NTFS
==================== MBR & Partition Table ==================
Disk: 0 (MBR Code: Windows XP) (Size: 466 GB) (Disk ID: 0A210A21)
Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 279 GB) (Disk ID: 29632963)
Partition 1: (Active) - (Size=279 GB) - (Type=07 NTFS)
==================== End Of Log
aswMBR version 1.0.1.2041 Copyright(c) 2014 AVAST Software
Run date: 2014-08-13 17:39:22
-----------------------------
17:39:22.953 OS Version: Windows x64 5.2.3790 Service Pack 2
17:39:22.953 Number of processors: 2 586 0x2B01
17:39:22.953 ComputerName: DJ-RAC-PUTTER UserName: DJ RAC
17:39:23.750 Initialize success
17:39:23.843 VM: driver load error: 2
17:50:28.109 AVAST engine defs: 14081301
18:01:39.265 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-f
18:01:39.265 Disk 0 Vendor: WDC_WD5000AAKB-00H8A0 05.04E05 Size: 476940MB BusType: 3
18:01:39.281 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T1L0-17
18:01:39.296 Disk 1 Vendor: Maxtor_6L300R0 BAH41G10 Size: 286188MB BusType: 3
18:01:39.437 Disk 1 MBR read successfully
18:01:39.437 Disk 1 MBR scan
18:01:39.500 Disk 1 Windows XP default MBR code
18:01:39.515 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 286179 MB offset 63
18:01:39.546 Disk 1 scanning C:\WINDOWS\system32\drivers
18:01:45.890 Service scanning
18:01:58.968 Modules scanning
18:01:59.000 Disk 1 trace - called modules:
18:02:01.750 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys atapi.sys pciide.sys PCIIDEX.SYS hal.dll
18:02:01.906 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffadfa377b770]
18:02:02.062 3 CLASSPNP.SYS[fffffadf98e0a8c9] -> nt!IofCallDriver -> \Device\00000066[0xfffffadfa377ca30]
18:02:02.218 5 ACPI.sys[fffffadf98fa9e69] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T1L0-17[0xfffffadfa377d060]
18:02:03.000 AVAST engine scan C:\WINDOWS
18:02:05.531 AVAST engine scan C:\WINDOWS\system32
18:03:47.265 AVAST engine scan C:\WINDOWS\system32\drivers
18:04:00.593 AVAST engine scan C:\Documents and Settings\DJ RAC
18:14:20.312 AVAST engine scan C:\Documents and Settings\All Users
18:16:15.843 Scan finished successfully
18:18:25.906 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\DJ RAC\Desktop\New logs frst64\MBR.dat"
18:18:25.921 The log file has been saved successfully to "C:\Documents and Settings\DJ RAC\Desktop\New logs frst64\aswMBR.txt"
ran
System: XP Pro x64 Edition
Ver 2003
Service Pack 2
not sure if i had to turn of or not
please let me know if more info is needed
thanks