Additional scan result of Farbar Recovery Scan Tool (x86) Version: 25-01-2017 Ran by Dr. Schnellinger (27-01-2017 00:52:56) Running from C:\Documents and Settings\Dr. Schnellinger\Configuración local\Temp\scoped_dir3196_7368 Microsoft Windows XP Professional Service Pack 3 (X86) (2016-12-24 19:09:49) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrador (S-1-5-21-1409082233-308236825-1606980848-500 - Administrator - Enabled) Asistente de ayuda (S-1-5-21-1409082233-308236825-1606980848-1000 - Limited - Disabled) ASPNET (S-1-5-21-1409082233-308236825-1606980848-1005 - Limited - Enabled) Dr. Schnellinger (S-1-5-21-1409082233-308236825-1606980848-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Dr. Schnellinger Invitado (S-1-5-21-1409082233-308236825-1606980848-501 - Limited - Disabled) SUPPORT_388945a0 (S-1-5-21-1409082233-308236825-1606980848-1002 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Panda Free Antivirus (Enabled - Up to date) {5AD27692-540A-464E-B625-78275FA38393} FW: Panda Firewall (Disabled) {1337562C-110A-4AF8-B12B-750C0B30E802} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 3D Box Shot Maker - freeware v1.0 (HKLM\...\3D Box Shot Maker - freeware v1.0) (Version: 1.0 - BossEye Inc.) 3DAce 2.72 EN (HKU\S-1-5-21-1409082233-308236825-1606980848-1003\...\3DAce 2.72 EN) (Version: - ) 6.25 (HKLM\...\{79D592A0-B75B-4E02-B5A9-FA40999C5FD2}_is1) (Version: 6.25 - ) 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) Adobe Audition 1.5 (HKLM\...\{86EF9FC4-F209-4520-B7E1-C7FF0EEBDFFF}) (Version: 1.5 - Adobe Systems) Adobe Flash Player 23 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 23.0.0.162 - Adobe Systems Incorporated) Adobe Reader 9.1 - Español (HKLM\...\{AC76BA86-7AD7-1034-7B44-A91000000001}) (Version: 9.1.0 - Adobe Systems Incorporated) Advanced Batch Image Converter x86 (HKLM\...\ABIC64) (Version: 1.2.2 - Roman Hiestand) AIMP2 (HKLM\...\AIMP2) (Version: - ) AIMP3 (HKLM\...\AIMP3) (Version: v3.60.1470, 16.01.2015 - AIMP DevTeam) Analizador de MSXML 6.0 (HKLM\...\{624810C7-02AA-4964-8A2F-AA07251259BF}) (Version: 6.00.3883.15 - Microsoft Corporation) Battlefield 2(TM) (HKLM\...\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}) (Version: - ) Calculator Powertoy for Windows XP (HKLM\...\{B37C842A-B624-46B8-A727-654E72F1C91A}) (Version: 1.00.0001 - Microsoft Corporation) Camtasia Studio 7 (HKLM\...\{49471DB8-7F3C-42DB-89C2-AC50FA0C5290}) (Version: 7.1.0 - TechSmith Corporation) CCleaner (HKLM\...\CCleaner) (Version: 5.13 - Piriform) CharacterFX (remove only) (HKLM\...\CharacterFX) (Version: - ) Cheat Engine 6.5.1 (HKLM\...\Cheat Engine 6.5.1_is1) (Version: - Cheat Engine) C-Media 3D Audio (HKLM\...\C-Media Audio) (Version: - ) CopperCube 5.4 (remove only) (HKLM\...\CopperCube 5.4) (Version: - Ambiera) DAEMON Tools Pro (HKLM\...\DAEMON Tools Pro) (Version: 5.2.0.0348 - DT Soft Ltd) DeleD 3D Editor 2.45 CE (HKLM\...\DeleD 3D Editor_is1) (Version: 2.45 - Delgine) Eassos PartitionGuru 4.7.1 (HKLM\...\{FC4FF5F4-2265-4E18-8BBC-12CBA9794388}_is1) (Version: - Eassos Co., Ltd.) Escritorio movistar Latam (HKLM\...\movistarLATAM) (Version: - Escritorio movistar Latam) FateItemCreator (HKLM\...\ST6UNST #1) (Version: - ) Fraps (remove only) (HKLM\...\Fraps) (Version: - ) Free Hide IP (HKLM\...\FreeHideIP) (Version: 4.0.7.2 - ) FSX_Screensaver (HKLM\...\FSX_Screensaver) (Version: - ) Google Chrome versión 48.0.2564.103 (HKLM\...\{CA40478A-838B-4CF5-8DC1-5E89C491BB42}_is1) (Version: 48.0.2564.103 - Google, Inc.) Greenshot 1.2.8.12 (HKLM\...\Greenshot_is1) (Version: 1.2.8.12 - Greenshot) HUAWEI DataCard Driver 4.05.00.00 (HKLM\...\HUAWEI DataCard Driver) (Version: 4.05.00.00 - Huawei technologies Co., Ltd.) Image Resizer Powertoy for Windows XP (HKLM\...\{1CB92574-96F2-467B-B793-5CEB35C40C29}) (Version: 1.00.0001 - Microsoft Corporation) Inno Setup versión 5.5.9 (HKLM\...\Inno Setup 5_is1) (Version: 5.5.9 - jrsoftware.org) IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.40 - Irfan Skiljan) ISO Recorder (HKLM\...\{0F6A7971-0F11-4A79-A0E9-133D0963A570}) (Version: 1.0.0 - Alex Feinman) Java 7 Update 7 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217007FF}) (Version: 7.0.70 - Oracle) K-Lite Mega Codec Pack 12.8.0 (HKLM\...\KLiteCodecPack_is1) (Version: 12.8.0 - KLCP) L&H TTS3000 Español (HKLM\...\LHTTSSPE) (Version: - ) Los Sims 2 (HKLM\...\{6E7DD182-9FC6-4651-0095-2E666CC6AF35}) (Version: - ) Los Sims 2 Universitarios (HKLM\...\{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}) (Version: - ) Microangelo Toolset 6 (HKLM\...\{71414EC2-0684-4A15-A85A-E0E259D117AF}) (Version: 6.10.8 - Eclipsit) Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation) Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation) Microsoft Office FrontPage 2003 (HKLM\...\{90170C0A-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation) Microsoft Office Labs Ribbon Hero 2, Clippy's Second Chance (HKLM\...\{EB933DE5-A25D-48F5-8CB2-A43E47CF761E}) (Version: 2.1.615.0 - Microsoft Office Labs) Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft RAW Image Thumbnailer and Viewer for Windows XP (HKLM\...\{B94AA0EE-8F75-4773-A25C-E986D94134B2}) (Version: 01.00.0309.00 - Microsoft) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60831.0 - Microsoft Corporation) Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{09C0A8D5-EEC1-369D-8C7A-2E2DD17DCA5E}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{e6edaf4d-f9a1-4023-be00-d6189343feb9}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{246dcb72-b18c-4ab9-9de9-8a996296b01d}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation) MiniTool Partition Wizard Home Edition 5.2 (HKLM\...\{12FEC00C-027C-4A34-9AAB-562EDA43DC18}_is1) (Version: - MiniTool Solution Ltd.) mIRC (HKLM\...\mIRC) (Version: 6.2 - mIRC Co. Ltd.) Moorhuhn Kart 2 (HKLM\...\{80C999A1-A94C-44AA-AF44-C85026F690B1}) (Version: 1.00.0000 - ) MSXML4 Parser (HKLM\...\{01501EBA-EC35-4F9F-8889-3BE346E5DA13}) (Version: 1.0.0 - Microsoft Game Studios) Notepad++ (HKLM\...\Notepad++) (Version: 6.9.1 - Notepad++ Team) NSO Deadline Mod (HKU\S-1-5-21-1409082233-308236825-1606980848-1003\...\NSO Deadline Mod) (Version: - ) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) NVIDIA PhysX v8.10.29 (HKLM\...\{D56B0E27-4A3E-46C9-B5C1-D93D580C099C}) (Version: 8.10.29 - NVIDIA Corporation) Opera Stable 36.0.2130.80 (HKLM\...\Opera 36.0.2130.80) (Version: 36.0.2130.80 - Opera Software) Panda Devices Agent (Version: 1.03.08 - Panda Security) Hidden Panda Devices Agent (Version: 1.08.00 - Panda Security) Hidden Panda Free Antivirus (HKLM\...\Panda Universal Agent Endpoint) (Version: 17.00.01.0000 - Panda Security) Panda Free Antivirus (Version: 8.31.00 - Panda Security) Hidden Platform (Version: 1.1 - VIA Technologies, Inc.) Hidden Process Explorer XP versión 16.05 (HKLM\...\{F1C768B9-5F6D-428C-856F-DC7B3AF085F2}_is1) (Version: 16.05 - Dr. Schnellinger) Real Horror Stories (HKLM\...\Real Horror Stories_is1) (Version: - BlizzBoyGames - hxxp://www.blizzboygames.net) RealityFactory (HKLM\...\RealityFactory) (Version: - ) RealWorld Icon Editor (HKLM\...\{3143DA02-D491-4C34-B7D2-0F9EA76486CB}) (Version: 8.1.0 - RealWorld Graphics) Reproductor de Windows Media 11 (HKLM\...\Windows Media Player) (Version: - ) resident evil 4 (HKLM\...\{DFFCDB41-C2DA-47D6-96FF-03C05C0BEA22}) (Version: 1.00.0000 - CAPCOM) Resource Hacker Version 3.6.0 (HKLM\...\ResourceHacker_is1) (Version: - ) Revo Uninstaller Pro 2.2.3 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 2.2.3 - VS Revo Group, Ltd.) S3GSetup (Version: 2.00.07.0709 - S3 Graphics) Hidden Sanny Builder 3.2.2 (HKLM\...\Sanny Builder 3_is1) (Version: - ) Send To Toys v2.71 (HKLM\...\Send To Toys_is1) (Version: - Gabriele Ponti) SharpKeys (HKLM\...\{636E94DA-99C0-448F-A931-3DAD83B4975F}) (Version: 3.5.0000 - RandyRants.com) Simple Sticky Notes 3.4 (HKLM\...\Simple Sticky Notes_is1) (Version: - Simnet Ltd.) Slideshow Generator Powertoy for Windows XP (HKLM\...\{C39DE425-6CCF-4B12-A101-3CB5CF3AF3AD}) (Version: 1.00.0001 - Microsoft Corporation) TeraCopy 2.3 (HKLM\...\TeraCopy_is1) (Version: - Code Sector) Theme Park World Fix (HKLM\...\{42082D6A-7C60-4CD9-B6FC-81E6F1FA96EF}) (Version: 1.0.0 - Adam Hearn) TorchED (HKLM\...\Runic Games TorchED) (Version: 1.0.68.226 - ) Tweak UI (HKLM\...\Tweak UI 2.10) (Version: - ) UltraISO Premium V9.33 (HKLM\...\UltraISO_is1) (Version: - ) Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) USB PnP Sound Device (HKLM\...\Generic USB 108 Sound) (Version: - ) VIA Administrador de dispositivos de plataforma (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.1 - VIA Technologies, Inc.) VIA/S3G Display Driver (HKLM\...\VIA/S3G UniChrome Family Win2K/XP Display) (Version: - ) VibrateGameDeviceDriver (HKLM\...\{DBB7F606-0C13-4182-AD7F-427A4773580E}) (Version: 4.0.09.1130 - Nombre de su organizacion) WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - ) WinRAR versión 3.93 (HKLM\...\{BFE3098C-00B0-4657-8576-901914123AED}_is1) (Version: 3.93 - Dr. Schnellinger) WinUHA 2.0 RC1 (2005.02.27) (HKLM\...\WinUHA_is1) (Version: - Klaimsoft) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1409082233-308236825-1606980848-1003_Classes\CLSID\{0B5F2CC8-5E1E-44F9-899B-3B789705AFCA}\InprocServer32 -> C:\Archivos de programa\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\wiaaut.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1409082233-308236825-1606980848-1003_Classes\CLSID\{0C5672F9-3EDC-4B24-95B5-A6C54C0B79AD}\InprocServer32 -> C:\Archivos de programa\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\wiaaut.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1409082233-308236825-1606980848-1003_Classes\CLSID\{4DD1D1C3-B36A-4EB4-AAEF-815891A58A30}\InprocServer32 -> C:\Archivos de programa\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\wiaaut.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1409082233-308236825-1606980848-1003_Classes\CLSID\{850D1D11-70F3-4BE5-9A11-77AA6B2BB201}\InprocServer32 -> C:\Archivos de programa\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\wiaaut.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1409082233-308236825-1606980848-1003_Classes\CLSID\{A2E6DDA0-06EF-4DF3-B7BD-5AA224BB06E8}\InprocServer32 -> C:\Archivos de programa\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\wiaaut.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1409082233-308236825-1606980848-1003_Classes\CLSID\{BD0D38E4-74C8-4904-9B5A-269F8E9994E9}\InprocServer32 -> C:\Archivos de programa\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\wiaaut.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1409082233-308236825-1606980848-1003_Classes\CLSID\{E1C5D730-7E97-4D8A-9E42-BBAE87C2059F}\InprocServer32 -> C:\Archivos de programa\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\wiaaut.dll (Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1485265251.job => C:\Archivos de programa\Opera\launcher.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Memory info =========================== Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz Percentage of memory in use: 61% Total physical RAM: 2047.23 MB Available physical RAM: 791.31 MB Total Virtual: 1897.61 MB Available Virtual: 707.43 MB ==================== Drives ================================ Drive c: (Saschendorf) (Fixed) (Total:149.03 GB) (Free:70.21 GB) NTFS ==>[drive with boot components (Windows XP)] Drive e: (ClusterX) (Fixed) (Total:74.53 GB) (Free:6.83 GB) NTFS Drive f: (Lorelai 512B) (Fixed) (Total:19.14 GB) (Free:0.24 GB) NTFS Drive g: (Dodge Ram) (Removable) (Total:3.77 GB) (Free:1.61 GB) NTFS Drive h: (Sims2EP1_1) (CDROM) (Total:0.58 GB) (Free:0 GB) CDFS Drive n: (HBCD 15.2) (CDROM) (Total:0.58 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 149.1 GB) (Disk ID: 44ADB122) Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 74.5 GB) (Disk ID: 4C634C62) Partition 1: (Not Active) - (Size=74.5 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 3.8 GB) (Disk ID: 00000001) Partition 1: (Not Active) - (Size=3.8 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (Size: 19.1 GB) (Disk ID: 8FD248FC) Partition 1: (Active) - (Size=19.1 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================