Ran FRST fix. TFC removed 146MB of files. On reboot File Checker ran itself prior to Windows starting. Ran FRST scan. Installed MBAM and ran quick scan. See all logs below.
FRST FIX LOGFix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 10-02-2014
Ran by Administrator at 2014-02-10 16:39:15 Run:4
Running from C:\Documents and Settings\Administrator\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKLM\...\Run: [yxxa.exe] - "C:\DOCUME~1\jprice\LOCALS~1\Temp\yxxa.exe" <===== ATTENTION
HKLM\...\Run: [yxxa .exe] - "C:\DOCUME~1\jprice\LOCALS~1\Temp\yxxa .exe" <===== ATTENTION
HKLM\...\Run: [yxxa .exe] - "C:\DOCUME~1\jprice\LOCALS~1\Temp\yxxa .exe" <===== ATTENTION
HKLM\...\Run: [yxxa .exe] - "C:\DOCUME~1\jprice\LOCALS~1\Temp\yxxa .exe" <===== ATTENTION
HKLM\...\Run: [yxxa .exe] - "C:\DOCUME~1\jprice\LOCALS~1\Temp\yxxa .exe" <===== ATTENTION
HKLM\...\Run: [yxxa .exe] - "C:\DOCUME~1\jprice\LOCALS~1\Temp\yxxa .exe" <===== ATTENTION
HKLM\...\Run: [uPc+MV0NKNaXms] - rundll32.exe C:\WINDOWS\system32\c84h1m.dll, SystemServer
HKLM\...\Run: [Tyizoqibuz] - C:\WINDOWS\owugihaji.dll [205312 2008-04-14] ()
HKLM\...\Run: [MKfsZK] - C:\WINDOWS\winlogon .exe
HKLM\...\Run: [MKfsZj] - C:\WINDOWS\winlogon .exe
HKLM\...\Run: [MKfsZgK] - C:\WINDOWS\winlogon .exe
HKLM\...\Run: [MKfsZgj] - C:\WINDOWS\winlogon .exe
HKLM\...\Run: [MKfsZgc] - C:\WINDOWS\winlogon .exe
HKLM\...\Run: [MKfsZg0] - C:\WINDOWS\winlogon .exe
HKLM\...\Run: [MKfsZc] - C:\WINDOWS\winlogon .exe
HKLM\...\Run: [MKfsZ0] - C:\WINDOWS\winlogon .exe
HKLM\...\Run: [MKfJ] - C:\WINDOWS\win .exe
HKLM\...\Run: [MKfFc] - C:\WINDOWS\win .exe
HKLM\...\Run: [MKeuN] - C:\WINDOWS\spoolsv .exe
HKLM\...\Run: [MKeuKK] - C:\WINDOWS\spoolsv .exe
HKLM\...\Run: [MKeuKj] - C:\WINDOWS\spoolsv .exe
HKLM\...\Run: [MKeuKgK] - C:\WINDOWS\spoolsv .exe
HKLM\...\Run: [MKeuKgj] - C:\WINDOWS\spoolsv .exe
HKLM\...\Run: [MKeuKggc] - C:\WINDOWS\spoolsv .exe
HKLM\...\Run: [MKeuKgc] - C:\WINDOWS\spoolsv .exe
HKLM\...\Run: [MKeuKg0] - C:\WINDOWS\spoolsv .exe
HKLM\...\Run: [MKeuKc] - C:\WINDOWS\spoolsv .exe
HKLM\...\Run: [MKeuK0] - C:\WINDOWS\spoolsv .exe
HKLM\...\Run: [MKetWK] - C:\WINDOWS\services .exe
HKLM\...\Run: [MKetWj] - C:\WINDOWS\services .exe
HKLM\...\Run: [MKetWgK] - C:\WINDOWS\services .exe
HKLM\...\Run: [MKetWgj] - C:\WINDOWS\services .exe
HKLM\...\Run: [MKetWggK] - C:\WINDOWS\services .exe
HKLM\...\Run: [MKetWggc] - C:\WINDOWS\services .exe
HKLM\...\Run: [MKetWgg0] - C:\WINDOWS\services .exe
HKLM\...\Run: [MKetWgc] - C:\WINDOWS\services .exe
HKLM\...\Run: [MKetWg0] - C:\WINDOWS\services .exe
HKLM\...\Run: [MKetWc] - C:\WINDOWS\services .exe
HKLM\...\Run: [MKetW0] - C:\WINDOWS\services .exe
HKLM\...\Run: [MKdws] - C:\WINDOWS\nvsvc32 .exe
HKLM\...\Run: [MKdwpc] - C:\WINDOWS\nvsvc32 .exe
HKLM\...\Run: [MKcuK] - C:\WINDOWS\lsass .exe
HKLM\...\Run: [MKcuj] - C:\WINDOWS\lsass .exe [94732 2010-09-26] ()
HKLM\...\Run: [MKcugK] - C:\WINDOWS\lsass .exe [94728 2010-09-26] ()
HKLM\...\Run: [MKcugj] - C:\WINDOWS\lsass .exe [94728 2010-09-26] ()
HKLM\...\Run: [MKcuggK] - C:\WINDOWS\lsass .exe [94728 2010-09-26] ()
HKLM\...\Run: [MKcuggc] - C:\WINDOWS\lsass .exe [94732 2010-09-26] ()
HKLM\...\Run: [MKcugc] - C:\WINDOWS\lsass .exe [94728 2010-09-26] ()
HKLM\...\Run: [MKcug0] - C:\WINDOWS\lsass .exe [94732 2010-09-26] ()
HKLM\...\Run: [MKcu0] - C:\WINDOWS\lsass .exe [94732 2010-09-26] ()
HKLM\...\Run: [MKayK] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKayj] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKaygK] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKaygj] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKayggK] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKayggj] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKaygggK] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKaygggc] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKayggc] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKaygg0] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKaygc] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKayg0] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [MKay0] - C:\WINDOWS\csrss .exe
HKLM\...\Run: [HNUtcHXlrxK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrxj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrxgK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrxgj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrxggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrxggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrxgggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrxggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrxgg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrxgc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrxg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrxc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv.exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrx0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\spoolsv .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrJ] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlrf] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss.exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr4] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0K] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0j] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0ggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0gc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0g0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr0c] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlr00] - C:\DOCUME~1\jprice\LOCALS~1\Temp\smss .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvgc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqvc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst.exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqv0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\wininst .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqgc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlqc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win.exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlq0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\win .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdQ] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5.exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdo] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggggggggK] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggggggggj] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlggc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlgc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlg0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdlc] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfdl0] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
HKLM\...\Run: [HNUtcHXlfd6] - C:\DOCUME~1\jprice\LOCALS~1\Temp\q8xpb6n5 .exe <===== ATTENTION
SearchScopes: HKLM - DefaultScope value is missing.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Q2aRNUk5.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\{84ED3979-6E30-4DF7-89EB-0C7FF0627D09}
C:\Documents and Settings\jprice\Local Settings\Temp\win .exe
C:\WINDOWS\system32\c84h1m.dll
C:\WINDOWS\owugihaji.dll [205312 2008-04-14] ()C:\WINDOWS\winlogon .exe
C:\WINDOWS\win .exe
C:\WINDOWS\spoolsv .exe
C:\WINDOWS\services .exe
C:\WINDOWS\nvsvc32 .exe
C:\WINDOWS\lsass .exe
C:\WINDOWS\csrss .exe
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\yxxa.exe => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\yxxa .exe => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\yxxa .exe => Unable to delete value
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\yxxa .exe => Unable to delete value
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\yxxa .exe => Unable to delete value
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\yxxa .exe => Unable to delete value
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\uPc+MV0NKNaXms => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Tyizoqibuz => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKfsZK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKfsZj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKfsZgK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKfsZgj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKfsZgc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKfsZg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKfsZc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKfsZ0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKfJ => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKfFc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKeuN => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKeuKK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKeuKj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKeuKgK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKeuKgj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKeuKggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKeuKgc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKeuKg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKeuKc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKeuK0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKetWK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKetWj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKetWgK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKetWgj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKetWggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKetWggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKetWgg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKetWgc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKetWg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKetWc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKetW0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKdws => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKdwpc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKcuK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKcuj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKcugK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKcugj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKcuggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKcuggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKcugc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKcug0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKcu0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKayK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKayj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKaygK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKaygj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKayggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKayggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKaygggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKaygggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKayggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKaygg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKaygc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKayg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MKay0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxgK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxgj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxgggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxgg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxgc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrxc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrx0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrJ => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlrf => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr4 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0K => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0j => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0ggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0gc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0g0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr0c => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlr00 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvgc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqvc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqv0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqgc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlqc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlq0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdQ => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdo => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggggggggK => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggggggggj => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlggc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlgc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlg0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdlc => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfdl0 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HNUtcHXlfd6 => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Q2aRNUk5.exe => Moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\{84ED3979-6E30-4DF7-89EB-0C7FF0627D09} => Moved successfully.
"C:\Documents and Settings\jprice\Local Settings\Temp\win .exe" => File/Directory not found.
"C:\WINDOWS\system32\c84h1m.dll" => File/Directory not found.
"C:\WINDOWS\owugihaji.dll [205312 2008-04-14] ()C:\WINDOWS\winlogon .exe" => File/Directory not found.
"C:\WINDOWS\win .exe" => File/Directory not found.
"C:\WINDOWS\spoolsv .exe" => File/Directory not found.
"C:\WINDOWS\services .exe" => File/Directory not found.
"C:\WINDOWS\nvsvc32 .exe" => File/Directory not found.
"C:\WINDOWS\lsass .exe" => File/Directory not found.
"C:\WINDOWS\csrss .exe" => File/Directory not found.
==== End of Fixlog ====
FRST SCAN LOGScan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-02-2014
Ran by Administrator (administrator) on JPRICELAP on 10-02-2014 16:52:18
Running from C:\Documents and Settings\Administrator\Desktop
Microsoft Windows XP Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingc...can-tool/dl/81/ Download link for 64-Bit Version:
http://www.bleepingc...can-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo...very-scan-tool/==================== Processes (Whitelisted) =================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
(SUPERAntiSpyware.com) C:\AdwCleaner\newsas\SASCORE.EXE
(Agere Systems) C:\WINDOWS\system32\agrsmsvc.exe
(Symantec Corporation) C:\Program Files\Symantec AntiVirus\DefWatch.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Hewlett-Packard) C:\WINDOWS\system32\hphmon06.exe
(HP) C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb13.exe
(symantec) C:\Program Files\Symantec AntiVirus\SavRoam.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE
() C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
() C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Hewlett-Packard Corporation) C:\WINDOWS\system32\AccelerometerSt.exe
() C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Hewlett-Packard Co.) C:\Program Files\Hp\HP Software Update\HPWuSchd2 .exe
(Symantec Corporation) C:\Program Files\SYMANT~1\VPTray .exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp .exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Symantec Corporation) C:\Program Files\Symantec AntiVirus\Rtvscan.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Hewlett-Packard Co.) C:\Program Files\Hewlett-Packard\digital imaging\bin\hpqtra08.exe
() C:\Program Files\RealVNC\VNC4\WinVNC4.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\mqtgsvc.exe
(Hewlett-Packard Co.) C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
() C:\Program Files\InterVideo\DVD Check\DVDCheck .exe
(Farbar) C:\Documents and Settings\Administrator\Desktop\tea.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Scheduler] - C:\WINDOWS\SMINST\Scheduler.exe [94736 2014-01-30] ()
HKLM\...\Run: [Reminder] - C:\WINDOWS\Creator\Remind_XP.exe [94736 2014-01-30] ()
HKLM\...\Run: [Recguard] - C:\WINDOWS\Sminst\Recguard.exe [94736 2014-01-30] ()
HKLM\...\Run: [MsmqIntCert] - regsvr32 /s mqrt.dll
HKLM\...\Run: [hpWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [94736 2014-01-30] ()
HKLM\...\Run: [Cpqset] - C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe [94736 2014-01-30] ()
HKLM\...\Run: [CognizanceTS] - C:\Program Files\HEWLET~1\IAM\Bin\ASTSVCC.dll [17920 2003-12-22] (Cognizance Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [94736 2014-01-30] ()
HKLM\...\Run: [HPHmon06] - C:\WINDOWS\system32\hphmon06.exe [622592 2004-12-16] (Hewlett-Packard)
HKLM\...\Run: [HPDJ Taskbar Utility] - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb13.exe [172032 2004-11-24] (HP)
HKLM\...\Run: [yxxa .exe] - "C:\DOCUME~1\jprice\LOCALS~1\Temp\yxxa .exe" <===== ATTENTION
HKLM\...\Run: [yxxa .exe] - "C:\DOCUME~1\jprice\LOCALS~1\Temp\yxxa .exe" <===== ATTENTION
HKLM\...\Run: [yxxa .exe] - "C:\DOCUME~1\jprice\LOCALS~1\Temp\yxxa .exe" <===== ATTENTION
HKLM\...\Run: [yxxa .exe] - "C:\DOCUME~1\jprice\LOCALS~1\Temp\yxxa .exe" <===== ATTENTION
HKLM\...\Run: [WatchDog] - C:\Program Files\InterVideo\DVD Check\DVDCheck .exe [94736 2014-02-10] ()
HKLM\...\Run: [vptray] - C:\Program Files\SYMANT~1\VPTray.exe [94724 2010-09-26] ()
HKLM\...\Run: [SynTPStart] - C:\Program Files\Synaptics\SynTP\SynTPStart.exe
HKLM\...\Run: [SunJavaUpdateSched] - "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
HKLM\...\Run: [SSBkgdUpdate] - C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [94724 2010-09-26] ()
HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\Core\smax4pnp.exe [94736 2014-01-30] ()
HKLM\...\Run: [SoundMAX] - C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [729088 2006-07-13] (Analog Devices, Inc.)
HKLM\...\Run: [QlbCtrl] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [163840 2007-05-02] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [PTHOSTTR] - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [145184 2007-01-09] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [PDF Complete] - "C:\Program Files\PDF Complete\pdfsty.exe"
HKLM\...\Run: [HPHUPD06] - C:\Program Files\Hewlett-Packard\{BA2D9411-DBB4-43e4-9421-780413650A67}\hphupd06.exe
HKLM\...\Run: [HP Software Update] - c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [94736 2014-01-30] ()
HKLM\...\Run: [ccApp] - "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [94724 2010-09-26] ()
HKLM\...\Run: [AccelerometerSysTrayApplet] - C:\WINDOWS\system32\AccelerometerSt.exe [124928 2007-01-24] (Hewlett-Packard Corporation)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\NavLogon: C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
Winlogon\Notify\OneCard: C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll (Cognizance Corporation)
HKLM\...\Policies\Explorer: [NoSetActiveDesktop] 1
HKU\.DEFAULT\...\Run: [DWQueuedReporting] - C:\Program Files\COMMON~1\Microsoft Shared\DW\dwtrig20.exe [94724 2010-09-26] ()
HKU\.DEFAULT\...\Run: [SE11] - C:\Program Files\SecEss\SE11.exe
HKU\.DEFAULT\...\RunOnce: [TSClientMSIUninstaller] - cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"
HKU\.DEFAULT\...\RunOnce: [TSClientAXDisabler] - cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat"
HKU\.DEFAULT\...\Policies\Explorer: [NoFolderOptions] 1
HKU\.DEFAULT\...\Policies\Explorer: [NoSetActiveDesktop] 1
HKU\S-1-5-21-2700236382-4009610293-4285289237-500\...\Run: [SUPERAntiSpyware] - C:\AdwCleaner\newsas\SUPERAntiSpyware.exe [5625624 2014-01-06] ()
HKU\S-1-5-21-2700236382-4009610293-4285289237-500\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [94728 2010-09-26] ()
HKU\S-1-5-21-2700236382-4009610293-4285289237-500\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [484904 2007-04-19] (Hewlett-Packard Company)
HKU\S-1-5-21-2700236382-4009610293-4285289237-500\...\Policies\Explorer: [NoFolderOptions] 1
HKU\S-1-5-21-2700236382-4009610293-4285289237-500\...\Policies\Explorer: [NoSetActiveDesktop] 1
HKU\S-1-5-21-2700236382-4009610293-4285289237-500\...\MountPoints2: E - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
Lsa: [Notification Packages] scecli ASWLNPkg
Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\CCC.lnk
ShortcutTarget: CCC.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
Startup: C:\Documents and Settings\Administrator.IDI\Start Menu\Programs\Startup\CCC.lnk
ShortcutTarget: CCC.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DVD Check.lnk
ShortcutTarget: DVD Check.lnk -> C:\Program Files\InterVideo\DVD Check\DVDCheck.exe ()
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
ShortcutTarget: HotSync Manager.lnk -> C:\Program Files\palmOne\Hotsync.exe (No File)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\Hewlett-Packard\digital imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
ShortcutTarget: HP Image Zone Fast Start.lnk -> C:\Program Files\Hewlett-Packard\digital imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (No File)
Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\CCC.lnk
ShortcutTarget: CCC.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
Startup: C:\Documents and Settings\jprice\Start Menu\Programs\Startup\CCC.lnk
ShortcutTarget: CCC.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
Startup: C:\Documents and Settings\jprice\Start Menu\Programs\Startup\palmOne Registration.lnk
ShortcutTarget: palmOne Registration.lnk -> C:\Program Files\palmOne\register.exe (No File)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.h...d=smb&pf=laptopHKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft...=ie&ar=iesearchHKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...d=smb&pf=laptopDPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.ma...t/ultrashim.cabDPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB}
http://tools.ebayimg...l_v1-0-27-0.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cabDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cabShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll No File [ ]
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\AdwCleaner\newsas\SASSEH.DLL [115440 2013-05-07] (SuperAdBlocker.com)
========================== Services (Whitelisted) =================
R2 !SASCORE; C:\AdwCleaner\newsas\SASCORE.EXE [120088 2013-10-10] (SUPERAntiSpyware.com)
R2 ASBroker; C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll [74240 2007-02-06] (Cognizance Corporation)
R2 ASChannel; C:\Program Files\Hewlett-Packard\IAM\Bin\ASChnl.dll [131584 2006-06-21] (Cognizance Corporation)
R2 ccEvtMgr; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [185968 2005-10-04] (Symantec Corporation)
S3 ccPwdSvc; C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [83568 2005-10-04] (Symantec Corporation)
R2 ccSetMgr; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [177776 2005-10-04] (Symantec Corporation)
R2 DefWatch; C:\Program Files\Symantec AntiVirus\DefWatch.exe [20208 2005-11-15] (Symantec Corporation)
S3 HP Port Resolver; C:\WINDOWS\system32\hpbpro.exe [77824 2004-06-02] (Hewlett-Packard Company)
S3 HP Status Server; C:\WINDOWS\system32\hpboid.exe [73728 2004-06-02] (Hewlett-Packard Company)
R2 msftesql$PROPHETSQL; C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe [92952 2006-08-28] (Microsoft Corporation)
S3 MSIServer; C:\WINDOWS\System32\msiexec.exe [78848 2008-04-14] ()
R2 MSMQ; C:\WINDOWS\system32\mqsvc.exe [4608 2008-04-14] (Microsoft Corporation)
R2 MSMQTriggers; C:\WINDOWS\system32\mqtgsvc.exe [117248 2008-04-14] (Microsoft Corporation)
R2 MSSQL$PROPHETSQL; C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29181272 2008-12-18] (Microsoft Corporation)
S2 PCA; C:\WINDOWS\SMINST\PCAngel.exe [294912 2006-01-12] (SoftThinks)
R2 SavRoam; C:\Program Files\Symantec AntiVirus\SavRoam.exe [169200 2005-11-15] (symantec)
S3 SNDSrvc; C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [214672 2005-10-19] (Symantec Corporation)
S3 SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2008-01-17] (SolidWorks)
S3 SPBBCSvc; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [992864 2005-03-30] (Symantec Corporation)
R2 Symantec AntiVirus; C:\Program Files\Symantec AntiVirus\Rtvscan.exe [1756912 2005-11-15] (Symantec Corporation)
S4 MSSQLServerADHelper; "C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" [X]
R2 SQLBrowser; "C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" [X]
R2 SQLWriter; "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [X]
R2 WinVNC4; "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service [X]
==================== Drivers (Whitelisted) ====================
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [36864 2006-07-01] (Advanced Micro Devices)
S3 ATSWPDRV; C:\WINDOWS\System32\DRIVERS\ATSwpDrv.sys [140808 2007-04-10] (AuthenTec, Inc.)
S3 BCM43XX; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [604928 2006-11-01] (Broadcom Corporation)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [868298 2007-02-14] (Broadcom Corporation.)
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [67960 2007-02-14] (Broadcom Corporation.)
R1 eabfiltr; C:\WINDOWS\System32\DRIVERS\eabfiltr.sys [8192 2006-11-30] (Hewlett-Packard Development Company, L.P.)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [371248 2010-05-27] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [102448 2010-05-27] (Symantec Corporation)
S3 gfiark; C:\WINDOWS\System32\drivers\gfiark.sys [43368 2013-05-23] (ThreatTrack Security)
S3 gfiutil; C:\WINDOWS\System32\drivers\gfiutil.sys [24040 2013-09-04] (ThreatTrack Security)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2005-10-21] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2005-10-21] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2005-10-21] (HP)
R3 IFXTPM; C:\WINDOWS\System32\DRIVERS\IFXTPM.SYS [36608 2006-09-19] (Infineon Technologies AG)
R3 MQAC; C:\WINDOWS\system32\drivers\mqac.sys [92544 2008-04-14] (Microsoft Corporation)
R3 NAVENG; C:\Program Files\COMMON~1\Symantec Shared\VirusDefs\20100924.004\naveng.sys [85424 2010-07-15] (Symantec Corporation)
R3 NAVEX15; C:\Program Files\COMMON~1\Symantec Shared\VirusDefs\20100924.004\navex15.sys [1362608 2010-07-15] (Symantec Corporation)
S3 PalmUSBD; C:\WINDOWS\System32\drivers\PalmUSBD.sys [16694 2004-06-09] (PalmSource, Inc.)
S3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R1 SASDIFSV; C:\AdwCleaner\newsas\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\AdwCleaner\newsas\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SAVRT; C:\Program Files\Symantec AntiVirus\savrt.sys [334984 2005-08-26] (Symantec Corporation)
R1 SAVRTPEL; C:\Program Files\Symantec AntiVirus\Savrtpel.sys [53896 2005-08-26] (Symantec Corporation)
S3 slabbus; C:\WINDOWS\System32\DRIVERS\slabbus.sys [66672 2007-03-01] (MCCI)
S3 slabser; C:\WINDOWS\System32\DRIVERS\slabser.sys [100400 2007-03-01] (MCCI)
S3 SMCIRDA; C:\WINDOWS\System32\DRIVERS\smcirda.sys [35913 2001-08-17] (SMC)
S3 SPBBCDrv; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [372832 2005-03-30] (Symantec Corporation)
R3 SymEvent; C:\Program Files\Symantec\SYMEVENT.SYS [108168 2005-09-16] (Symantec Corporation)
S3 SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [24720 2005-10-19] (Symantec Corporation)
R1 SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [195728 2005-10-19] (Symantec Corporation)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S3 VPROEVENTMONITOR; \??\C:\WINDOWS\system32\drivers\VProEventMonitor.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-10 16:52 - 2014-02-10 16:52 - 00017784 _____ () C:\Documents and Settings\Administrator\Desktop\FRST.txt
2014-02-10 12:20 - 2014-02-10 11:58 - 01139200 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\tea.exe
2014-02-10 11:45 - 2014-02-10 11:45 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\HP
2014-02-10 11:42 - 2014-02-10 11:42 - 00000136 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
2014-02-06 15:37 - 2014-02-06 15:40 - 00000000 ___SD () C:\Machiavelli
2014-02-06 14:50 - 2011-06-26 00:45 - 00256000 _____ () C:\WINDOWS\PEV.exe
2014-02-06 14:50 - 2010-11-07 11:20 - 00208896 _____ () C:\WINDOWS\MBR.exe
2014-02-06 14:50 - 2009-04-19 22:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2014-02-06 14:50 - 2000-08-30 18:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2014-02-06 14:50 - 2000-08-30 18:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2014-02-06 14:50 - 2000-08-30 18:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2014-02-06 14:50 - 2000-08-30 18:00 - 00098816 _____ () C:\WINDOWS\sed.exe
2014-02-06 14:50 - 2000-08-30 18:00 - 00080412 _____ () C:\WINDOWS\grep.exe
2014-02-06 14:50 - 2000-08-30 18:00 - 00068096 _____ () C:\WINDOWS\zip.exe
2014-02-06 14:44 - 2014-02-06 14:49 - 00000000 ____D () C:\Qoobox
2014-02-06 14:44 - 2014-02-06 14:44 - 00000000 ____D () C:\WINDOWS\erdnt
2014-02-06 14:43 - 2014-02-06 14:27 - 05180173 ____R (Swearware) C:\Documents and Settings\Administrator\Desktop\Machiavelli.exe
2014-02-06 14:42 - 2014-02-06 14:28 - 01136640 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\apples.exe
2014-02-06 11:09 - 2014-02-06 10:56 - 00602112 _____ () C:\Documents and Settings\Administrator\Desktop\oldmantimer.exe
2014-02-06 10:42 - 2014-02-06 10:13 - 01139200 _____ () C:\Documents and Settings\Administrator\Desktop\farapple.exe
2014-02-06 10:24 - 2014-02-06 10:13 - 01139200 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\TSRF.exe
2014-02-06 10:22 - 2014-02-06 10:22 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\tripping
2014-02-05 13:02 - 2014-02-10 16:52 - 00000000 ____D () C:\FRST
2014-02-05 13:01 - 2014-02-05 12:21 - 01139200 _____ () C:\Documents and Settings\Administrator\Desktop\FRST.exe
2014-02-04 15:02 - 2014-02-03 22:50 - 00602112 _____ () C:\Documents and Settings\Administrator\Desktop\LOT.exe
2014-02-04 14:49 - 2014-02-04 14:50 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\gummy
2014-02-04 00:39 - 2014-02-04 00:39 - 00000000 ____D () C:\pukingsoft
2014-02-04 00:34 - 2014-02-04 00:34 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2014-02-04 00:33 - 2014-02-04 00:33 - 00001543 _____ () C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
2014-02-04 00:33 - 2014-02-04 00:33 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
2014-02-04 00:33 - 2014-02-04 00:33 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2014-02-04 00:27 - 2014-02-03 23:24 - 17946224 _____ (SUPERAntiSpyware) C:\Documents and Settings\Administrator\Desktop\SAS_634F563.EXE
2014-02-04 00:14 - 2014-02-04 00:14 - 00000000 _____ () C:\WINDOWS\system32\SBRC.dat
2014-02-04 00:13 - 2013-09-04 13:57 - 00024040 _____ (ThreatTrack Security) C:\WINDOWS\system32\Drivers\gfiutil.sys
2014-02-04 00:13 - 2013-05-23 07:39 - 00043368 _____ (ThreatTrack Security) C:\WINDOWS\system32\Drivers\gfiark.sys
2014-02-04 00:11 - 2014-02-04 00:13 - 00000000 ____D () C:\VIPRERESCUE
2014-02-03 23:54 - 2014-02-10 15:57 - 10285040 _____ (Malwarebytes Corporation ) C:\Documents and Settings\Administrator\Desktop\mbam-setup-1.75.0.1300.exe
2014-02-03 23:50 - 2014-02-03 23:50 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\rkill
2014-02-03 23:49 - 2014-02-03 23:19 - 01933048 _____ () C:\Documents and Settings\Administrator\Desktop\rkill.exe
2014-02-03 23:21 - 2014-02-03 23:09 - 00602112 _____ () C:\Documents and Settings\Administrator\Desktop\OTL.scr
2014-02-03 23:21 - 2014-02-03 23:09 - 00602112 _____ () C:\Documents and Settings\Administrator\Desktop\OTL.com
2014-02-03 23:08 - 2014-02-03 22:50 - 00602112 _____ () C:\Documents and Settings\Administrator\Desktop\OTL.exe
2014-02-03 20:44 - 2014-02-03 23:55 - 00000989 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-03 20:44 - 2014-02-03 23:55 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
2014-02-03 20:43 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-02-03 19:23 - 2014-02-03 19:23 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2014-02-03 19:22 - 2014-02-03 19:22 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2014-02-03 19:19 - 2014-02-03 19:19 - 00000000 ____D () C:\Tech Support
2014-02-03 19:17 - 2014-02-03 16:42 - 10285040 _____ (Malwarebytes Corporation ) C:\Documents and Settings\Administrator\Desktop\9e5tusxsw1.exe
2014-02-03 18:39 - 2014-02-03 18:39 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Zeon
2014-02-03 18:13 - 2014-02-10 15:55 - 00448512 _____ (OldTimer Tools) C:\Documents and Settings\Administrator\Desktop\TFC.exe
2014-02-03 18:13 - 2010-06-28 14:37 - 00963827 _____ () C:\Documents and Settings\Administrator\Desktop\Eusing Free Registry Cleaner.exe
2014-02-03 16:57 - 2014-02-04 00:32 - 00000000 ____D () C:\AdwCleaner
2014-02-03 16:57 - 2014-02-03 16:41 - 01037068 _____ (Thisisu) C:\Documents and Settings\Administrator\Desktop\JRT.exe
2014-02-03 16:57 - 2014-02-03 16:40 - 01166132 _____ () C:\Documents and Settings\Administrator\Desktop\AdwCleaner.exe
2014-02-03 16:55 - 2014-02-03 18:59 - 00005127 _____ () C:\WINDOWS\setupapi.log
2014-01-30 14:44 - 2010-09-26 17:45 - 00094748 ____H () C:\Documents and Settings\Administrator\Q2aRNUk5.com
2014-01-30 12:20 - 2014-01-30 12:20 - 00000811 _____ () C:\Documents and Settings\Administrator\Start Menu\Programs\Internet Explorer.lnk
2014-01-30 11:56 - 2014-01-30 11:56 - 00000097 _____ () C:\Documents and Settings\Administrator\LuResult.txt
2014-01-30 11:12 - 2014-01-30 11:12 - 00000000 __SHD () C:\Documents and Settings\Administrator\IETldCache
==================== One Month Modified Files and Folders =======
2014-02-10 16:52 - 2014-02-10 16:52 - 00017784 _____ () C:\Documents and Settings\Administrator\Desktop\FRST.txt
2014-02-10 16:52 - 2014-02-05 13:02 - 00000000 ____D () C:\FRST
2014-02-10 16:51 - 2010-09-26 21:28 - 00677795 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-10 16:49 - 2004-08-07 07:14 - 00678654 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-10 16:47 - 2010-09-26 13:47 - 00000416 _____ () C:\WINDOWS\Tasks\Updater.job
2014-02-10 16:46 - 2010-09-26 21:35 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-02-10 16:44 - 2010-09-26 21:38 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-02-10 16:44 - 2010-09-26 21:38 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-02-10 16:44 - 2007-10-04 11:06 - 00000000 ____D () C:\WINDOWS\SMINST
2014-02-10 16:43 - 2010-09-26 21:36 - 00032466 _____ () C:\WINDOWS\SchedLgU.Txt
2014-02-10 16:43 - 2009-04-18 11:09 - 00000260 _____ () C:\WINDOWS\Tasks\WGASetup.job
2014-02-10 16:42 - 2004-08-07 07:19 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-10 16:40 - 2007-10-04 10:31 - 00524288 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
2014-02-10 15:57 - 2014-02-03 23:54 - 10285040 _____ (Malwarebytes Corporation ) C:\Documents and Settings\Administrator\Desktop\mbam-setup-1.75.0.1300.exe
2014-02-10 15:55 - 2014-02-03 18:13 - 00448512 _____ (OldTimer Tools) C:\Documents and Settings\Administrator\Desktop\TFC.exe
2014-02-10 11:58 - 2014-02-10 12:20 - 01139200 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\tea.exe
2014-02-10 11:45 - 2014-02-10 11:45 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\HP
2014-02-10 11:44 - 2007-12-03 22:08 - 00135864 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2014-02-10 11:42 - 2014-02-10 11:42 - 00000136 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
2014-02-10 11:36 - 2004-08-07 07:19 - 00000178 ___SH () C:\Documents and Settings\Administrator\ntuser.ini
2014-02-10 11:36 - 2004-08-07 07:03 - 00000603 _____ () C:\WINDOWS\win.ini
2014-02-10 11:36 - 2004-08-07 06:57 - 00000223 ___SH () C:\boot.ini
2014-02-10 11:36 - 2004-08-06 23:53 - 00000227 _____ () C:\WINDOWS\system.ini
2014-02-06 15:40 - 2014-02-06 15:37 - 00000000 ___SD () C:\Machiavelli
2014-02-06 15:37 - 2007-10-04 09:36 - 00000000 ____D () C:\WINDOWS\system32\Restore
2014-02-06 14:49 - 2014-02-06 14:44 - 00000000 ____D () C:\Qoobox
2014-02-06 14:44 - 2014-02-06 14:44 - 00000000 ____D () C:\WINDOWS\erdnt
2014-02-06 14:28 - 2014-02-06 14:42 - 01136640 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\apples.exe
2014-02-06 14:27 - 2014-02-06 14:43 - 05180173 ____R (Swearware) C:\Documents and Settings\Administrator\Desktop\Machiavelli.exe
2014-02-06 10:56 - 2014-02-06 11:09 - 00602112 _____ () C:\Documents and Settings\Administrator\Desktop\oldmantimer.exe
2014-02-06 10:22 - 2014-02-06 10:22 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\tripping
2014-02-06 10:13 - 2014-02-06 10:42 - 01139200 _____ () C:\Documents and Settings\Administrator\Desktop\farapple.exe
2014-02-06 10:13 - 2014-02-06 10:24 - 01139200 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\TSRF.exe
2014-02-05 12:21 - 2014-02-05 13:01 - 01139200 _____ () C:\Documents and Settings\Administrator\Desktop\FRST.exe
2014-02-04 14:50 - 2014-02-04 14:49 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\gummy
2014-02-04 14:39 - 2007-12-03 22:12 - 00000000 __SHD () C:\WINDOWS\CSC
2014-02-04 00:39 - 2014-02-04 00:39 - 00000000 ____D () C:\pukingsoft
2014-02-04 00:34 - 2014-02-04 00:34 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2014-02-04 00:33 - 2014-02-04 00:33 - 00001543 _____ () C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
2014-02-04 00:33 - 2014-02-04 00:33 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
2014-02-04 00:33 - 2014-02-04 00:33 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2014-02-04 00:32 - 2014-02-03 16:57 - 00000000 ____D () C:\AdwCleaner
2014-02-04 00:14 - 2014-02-04 00:14 - 00000000 _____ () C:\WINDOWS\system32\SBRC.dat
2014-02-04 00:13 - 2014-02-04 00:11 - 00000000 ____D () C:\VIPRERESCUE
2014-02-03 23:55 - 2014-02-03 20:44 - 00000989 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-03 23:55 - 2014-02-03 20:44 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
2014-02-03 23:50 - 2014-02-03 23:50 - 00000000 ____D () C:\Documents and Settings\Administrator\Desktop\rkill
2014-02-03 23:24 - 2014-02-04 00:27 - 17946224 _____ (SUPERAntiSpyware) C:\Documents and Settings\Administrator\Desktop\SAS_634F563.EXE
2014-02-03 23:19 - 2014-02-03 23:49 - 01933048 _____ () C:\Documents and Settings\Administrator\Desktop\rkill.exe
2014-02-03 23:09 - 2014-02-03 23:21 - 00602112 _____ () C:\Documents and Settings\Administrator\Desktop\OTL.scr
2014-02-03 23:09 - 2014-02-03 23:21 - 00602112 _____ () C:\Documents and Settings\Administrator\Desktop\OTL.com
2014-02-03 22:50 - 2014-02-04 15:02 - 00602112 _____ () C:\Documents and Settings\Administrator\Desktop\LOT.exe
2014-02-03 22:50 - 2014-02-03 23:08 - 00602112 _____ () C:\Documents and Settings\Administrator\Desktop\OTL.exe
2014-02-03 20:55 - 2007-12-03 21:48 - 00000000 ____D () C:\WINDOWS\pss
2014-02-03 19:23 - 2014-02-03 19:23 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2014-02-03 19:22 - 2014-02-03 19:22 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2014-02-03 19:19 - 2014-02-03 19:19 - 00000000 ____D () C:\Tech Support
2014-02-03 18:59 - 2014-02-03 16:55 - 00005127 _____ () C:\WINDOWS\setupapi.log
2014-02-03 18:39 - 2014-02-03 18:39 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Zeon
2014-02-03 16:42 - 2014-02-03 19:17 - 10285040 _____ (Malwarebytes Corporation ) C:\Documents and Settings\Administrator\Desktop\9e5tusxsw1.exe
2014-02-03 16:41 - 2014-02-03 16:57 - 01037068 _____ (Thisisu) C:\Documents and Settings\Administrator\Desktop\JRT.exe
2014-02-03 16:40 - 2014-02-03 16:57 - 01166132 _____ () C:\Documents and Settings\Administrator\Desktop\AdwCleaner.exe
2014-01-30 14:44 - 2007-10-04 09:36 - 00000000 ____D () C:\Documents and Settings\Administrator
2014-01-30 12:27 - 2007-10-04 11:06 - 00000000 ____D () C:\WINDOWS\CREATOR
2014-01-30 12:20 - 2014-01-30 12:20 - 00000811 _____ () C:\Documents and Settings\Administrator\Start Menu\Programs\Internet Explorer.lnk
2014-01-30 12:20 - 2007-10-04 09:36 - 00000000 ___RD () C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
2014-01-30 12:19 - 2004-08-07 07:08 - 00000744 _____ () C:\Documents and Settings\Administrator\Start Menu\Programs\Outlook Express.lnk
2014-01-30 11:56 - 2014-01-30 11:56 - 00000097 _____ () C:\Documents and Settings\Administrator\LuResult.txt
2014-01-30 11:55 - 2008-02-18 22:19 - 00000000 ____D () C:\Documents and Settings\jprice\Start Menu\Programs\Index Dat Spy
2014-01-30 11:12 - 2014-01-30 11:12 - 00000000 __SHD () C:\Documents and Settings\Administrator\IETldCache
Some content of TEMP:
====================
C:\Documents and Settings\jprice\Local Settings\Temp\win .exe
C:\Documents and Settings\jprice\Local Settings\Temp\win .exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe => MD5 is legit
C:\WINDOWS\system32\winlogon.exe => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
C:\WINDOWS\system32\User32.dll => MD5 is legit
C:\WINDOWS\system32\userinit.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================
FRST ADDITIONS LOGAdditional scan result of Farbar Recovery Scan Tool (x86) Version: 10-02-2014
Ran by Administrator at 2014-02-10 16:53:43
Running from C:\Documents and Settings\Administrator\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Symantec AntiVirus Corporate Edition (Disabled - Up to date) {FB06448E-52B8-493A-90F3-E43226D3305C}
==================== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 2 (SP2) (Version: - Microsoft)
2007 Microsoft Office Suite Service Pack 2 (SP2) (Version: - Microsoft) Hidden
2007 Microsoft Office system (Version: 12.0.6425.1000 - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adobe Flash Player 10 ActiveX (Version: 10.0.42.34 - Adobe Systems Incorporated)
Adobe Illustrator 8.0 (Version: 8.0 - Adobe Systems, Inc.)
Adobe Photoshop v4.0 (Version: - )
Adobe Reader 8.1.2 (Version: 8.1.2 - Adobe Systems Incorporated)
Agere Systems HDA Modem (Version: - Agere Systems)
Application Installer 4.00.B14 (Version: 4.00.B14 - Hewlett-Packard Company)
ATI Catalyst Control Center (Version: 1.007.2007.0202 - )
ATI Display Driver (Version: 8.342.2-070202a-044973C-HP - )
AutoCAD LT 2004 (Version: 16.0.0.086 - Autodesk)
Autodesk Express Viewer (Version: 3.1 - Autodesk, Inc.)
Broadcom 802.11 Wireless LAN Adapter (Version: 4.100.15.5 - Broadcom Corporation)
Broadcom NetXtreme Ethernet Controller (Version: 10.15.15 - Broadcom Corporation)
BufferChm (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Canon MF Drivers (Version: - )
Canon MP150 (Version: - )
Catalyst Control Center Core Implementation (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Graphics Full New (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Graphics Light (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Chinese Standard (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Chinese Traditional (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Czech (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Danish (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Dutch (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Finnish (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization French (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization German (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Greek (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Hungarian (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Italian (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Japanese (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Korean (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Norwegian (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Polish (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Portuguese (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Russian (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Spanish (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Swedish (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Thai (Version: 2007.0202.1934.34870 - ATI) Hidden
Catalyst Control Center Localization Turkish (Version: 2007.0202.1934.34870 - ATI) Hidden
CCC Help Chinese Standard (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Chinese Traditional (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Czech (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Danish (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Dutch (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help English (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Finnish (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help French (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help German (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Greek (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Hungarian (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Italian (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Japanese (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Korean (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Norwegian (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Polish (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Portuguese (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Russian (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Spanish (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Swedish (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Thai (Version: 2007.0202.1933.34870 - ATI) Hidden
CCC Help Turkish (Version: 2007.0202.1933.34870 - ATI) Hidden
ccc-Branding (Version: 1.00.0000 - ATI)
ccc-core-static (Version: 2007.0202.1934.34870 - ATI) Hidden
ccc-utility (Version: 2007.0202.1934.34870 - ATI) Hidden
CreativeProjects (Version: 45.4.157.000 - Hewlett-Packard) Hidden
CreativeProjectsTemplates (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Credential Manager for HP ProtectTools (Version: 2.5.0.880.13 - Hewlett-Packard )
Critical Update for Windows Media Player 11 (KB959772) (Version: - Microsoft Corporation)
CueTour (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Destinations (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Director (Version: 45.4.157.000 - Hewlett-Packard) Hidden
eDrawings 2008 (Version: 8.2.122 - SolidWorks)
GDR 3077 for SQL Server Database Services 2005 ENU (KB960089) (Version: 9.2.3077 - Microsoft Corporation)
Google Earth (Version: 4.2.205.5730 - Google)
HP 3D DriveGuard (Version: 1.00 A4 - )
HP Backup and Recovery Manager Installer (Version: 2.4 - Hewlett-Packard Company)
HP BIOS Configuration for ProtectTools (Version: 3.00 C1 - Hewlett-Packard)
HP Deskjet 3740 Series (Version: - )
HP Doc Viewer (Version: 1.01.0005 - Hewlett-Packard)
HP Help and Support (Version: 4.4.0002 - HPQ)
HP Image Zone 4.7 (Version: 4.7 - HP)
HP Integrated Module with Bluetooth wireless technology (Version: 5.1.0.3000 - HP)
HP Notebook Accessories Product Tour (Version: 13.0.0 - Hewlett-Packard)
HP Photosmart 8700 Series (Version: - )
HP Product Assistant (Version: 2.0.0.0 - Hewlett-Packard) Hidden
HP ProtectTools Security Manager (Version: 3.00 A10 - Hewlett-Packard)
HP Quick Launch Buttons 6.20 F2 (Version: 6.20 F2 - Hewlett-Packard)
HP Update (Version: 4.000.005.007 - Hewlett-Packard)
HP User Guide Bluetooth Addendum 0062 (Version: 1.01.0000 - Hewlett-Packard)
HP User Guides 0064 (Version: 1.03.0000 - Hewlett-Packard)
HP Wireless Assistant (Version: 3.00 F1 - Hewlett-Packard)
HpSdpAppCoreApp (Version: 3.00.0000 - Hewlett-Packard) Hidden
HPSystemDiagnostics (Version: 1.6.0.0 - Your Company Name) Hidden
InstantShare (Version: 45.4.157.000 - Hewlett-Packard) Hidden
InterVideo DVD Check (Version: - )
InterVideo Register Manager (Version: 1.0.4.0 - InterVideo Inc.) Hidden
InterVideo WinDVD (Version: - )
InterVideo WinDVD (Version: 5.0-B11.1164 - InterVideo Inc.)
KRW's Periodic Table Software (2002-02-25) (Version: - )
LightScribe 1.6.43.1 (Version: 1.6.43.1 -
http://www.lightscribe.com) Hidden
LiveUpdate 2.6 (Symantec Corporation) (Version: 2.6.18.0 - Symantec Corporation)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 1.1 (Version: - )
Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 1.1 Security Update (KB979906) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft Base Smart Card Cryptographic Service Provider Package (Version: - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1 - Microsoft Corporation)
Microsoft Internationalized Domain Names Mitigation APIs (Version: - Microsoft Corporation) Hidden
Microsoft National Language Support Downlevel APIs (Version: - Microsoft Corporation) Hidden
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Hybrid 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2007 (Version: 12.0.6425.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft Report Viewer Redistributable 2005 (Version: - Microsoft Corporation)
Microsoft Report Viewer Redistributable 2005 (Version: 8.0.55129 - Microsoft Corporation) Hidden
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Silverlight (Version: 4.0.50826.0 - Microsoft Corporation)
Microsoft Software Update for Web Folders (English) 12 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden
Microsoft SQL Server 2005 (PROPHETSQL) (Version: 9.2.3042.00 - Microsoft Corporation) Hidden
Microsoft SQL Server 2005 (Version: - Microsoft Corporation)
Microsoft SQL Server Native Client (Version: 9.00.4035.00 - Microsoft Corporation)
Microsoft SQL Server Setup Support Files (English) (Version: 9.00.4035.00 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (Version: 9.00.4035.00 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (Version: - Microsoft Corporation)
Microsoft Visio Professional 2002 [English] (Version: 10.0.525 - Microsoft Corporation)
Microsoft Visual SourceSafe V5.0 (Version: - )
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 6 Service Pack 2 (KB954459) (Version: 6.20.1099.0 - Microsoft Corporation)
palmOne (Version: 4.1.0420 - palmOne, Inc.)
PanoStandAlone (Version: 45.4.157.000 - Hewlett-Packard) Hidden
PhotoGallery (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Photosmart 320,370,7400,8100,8400,8700 Series (Version: 6.2 - HP)
PS8700 (Version: 1.01.0000 - Hewlett-Packard) Hidden
PSPrinters06 (Version: 1.01.0000 - HP) Hidden
QFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
QwikQuote 6.0 Node (Version: - )
Roxio Creator Audio (Version: 3.3.0 - Roxio)
Roxio Creator Basic v9 (Version: 3.3.0 - Roxio)
Roxio Creator Copy (Version: 3.3.0 - Roxio)
Roxio Creator Data (Version: 3.3.0 - Roxio)
Roxio Creator Tools (Version: 3.3.0 - Roxio)
Roxio Express Labeler 3 (Version: 2.1.0 - Roxio)
Roxio MyDVD Basic v9 (Version: 9.0.116 - Roxio)
ScanSoft PDF Create! 4 (Version: 4.00.0000 - Nuance, Inc.)
SIM Recovery Pro v1.2.2 (Version: - )
SkinsHP1 (Version: 45.4.157.000 - Hewlett-Packard) Hidden
SMC InfiniLink 2007.1213 (Version: - SMC)
Sonic Activation Module (Version: 1.0 - Sonic Solutions) Hidden
SoundMAX (Version: 5.10.01.5161 - Analog Devices)
SUPERAntiSpyware (Version: 5.7.1018 - SUPERAntiSpyware.com)
Symantec AntiVirus (Version: 10.0.2000.2 - Symantec Corporation)
Synaptics Pointing Device Driver (Version: 10.0.13.2 - Synaptics)
TrayApp (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Unload (Version: 4.5.0 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (Version: - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (Version: - Microsoft)
Update for Microsoft Office Access 2007 Help (KB963663) (Version: - Microsoft)
Update for Microsoft Office Excel 2007 Help (KB963678) (Version: - Microsoft)
Update for Microsoft Office Infopath 2007 Help (KB963662) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 Help (KB957246) (Version: - Microsoft)
Update for Microsoft Office Powerpoint 2007 Help (KB963669) (Version: - Microsoft)
Update for Microsoft Office Publisher 2007 Help (KB963667) (Version: - Microsoft)
Update for Microsoft Office Script Editor Help (KB963671) (Version: - Microsoft)
Update for Microsoft Office Word 2007 Help (KB963665) (Version: - Microsoft)
Update for Outlook 2007 Junk Email Filter (kb2291599) (Version: - Microsoft)
Update for Windows Internet Explorer 8 (KB968220) (Version: 1 - Microsoft Corporation)
Update for Windows Internet Explorer 8 (KB969497) (Version: 1 - Microsoft Corporation)
Update for Windows Internet Explorer 8 (KB976662) (Version: 1 - Microsoft Corporation)
Update for Windows Internet Explorer 8 (KB976749) (Version: 1 - Microsoft Corporation)
Update for Windows Internet Explorer 8 (KB980182) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2141007) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB943729) (Version: - Microsoft Corporation)
Update for Windows XP (KB951072-v2) (Version: 2 - Microsoft Corporation)
Update for Windows XP (KB951978) (Version: 1 - Microsoft Corporation) Hidden
Update for Windows XP (KB955759) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB955839) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB967715) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB968389) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB971737) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB973687) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB973815) (Version: 1 - Microsoft Corporation)
Virtual Pool 3 Preview (Version: - )
VNC Enterprise Edition E4.3-K1 (Version: E4.3-K1 - RealVNC Ltd.)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
WebReg (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) (Version: 05/27/2006 1.3.2.0 - Advanced Micro Devices)
Windows Genuine Advantage Notifications (KB905474) (Version: 1.8.0031.9 - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (Version: - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Imaging Component (Version: 3.0.0.0 - Microsoft Corporation)
Windows Internet Explorer 7 (Version: 20070813.185237 - Microsoft Corporation) Hidden
Windows Internet Explorer 8 (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Format 11 runtime (Version: - )
Windows Media Format 11 runtime (Version: - Microsoft Corporation) Hidden
Windows Media Player 11 (Version: - )
Windows Media Player 11 (Version: - Microsoft Corporation) Hidden
Windows PowerShell 1.0 (Version: 2 - Microsoft Corporation)
Windows PowerShell 1.0 MUI pack (Version: 2 - Microsoft Corporation)
Windows Presentation Foundation (Version: 3.0.6920.0 - Microsoft Corporation) Hidden
Windows Search 4.0 (Version: 04.00.6001.503 - Microsoft Corporation)
Windows XP Service Pack 3 (Version: 20080414.031525 - Microsoft Corporation)
XML Paper Specification Shared Components Pack 1.0 (Version: - Microsoft Corporation) Hidden
==================== Restore Points =========================
Could not list Restore Points. Check "winmgmt" service or repair WMI.
==================== Hosts content: ==========================
2004-08-04 02:00 - 2014-02-06 10:24 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: C:\WINDOWS\Tasks\Updater.job => C:\Documents and Settings\All Users\Application Data\Update\seupd.exe
Task: C:\WINDOWS\Tasks\WGASetup.job => C:\WINDOWS\system32\KB905474\wgasetup.exe
==================== Loaded Modules (whitelisted) =============
2007-12-04 04:12 - 2014-01-30 12:27 - 00094736 _____ () C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
2007-02-16 18:40 - 2007-02-16 18:40 - 01466368 _____ () C:\Program Files\Common Files\LightScribe\QtCore4.dll
2007-02-16 18:40 - 2007-02-16 18:40 - 05521408 _____ () C:\Program Files\Common Files\LightScribe\QtGui4.dll
2007-02-06 15:20 - 2007-02-06 15:20 - 02842624 _____ () C:\WINDOWS\system32\btwicons.dll
2007-02-06 15:16 - 2007-02-06 15:16 - 00053248 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2010-07-11 02:46 - 2010-07-11 02:46 - 03391488 _____ () c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_acd21e23\mscorlib.dll
2010-07-11 02:45 - 2010-07-11 02:45 - 03018752 _____ () c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_743421a4\system.windows.forms.dll
2010-07-11 02:45 - 2010-07-11 02:45 - 01966080 _____ () c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_9c1f7762\system.dll
2010-07-11 02:46 - 2010-07-11 02:46 - 00835584 _____ () c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_bd844bfd\system.drawing.dll
2010-07-11 02:45 - 2010-07-11 02:45 - 02088960 _____ () c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_facfb624\system.xml.dll
2007-12-04 04:12 - 2014-02-10 16:46 - 00094736 _____ () C:\Program Files\InterVideo\DVD Check\DVDCheck .exe
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
==================== Faulty Device Manager Devices =============
Could not list Devices. Check "winmgmt" service or repair WMI.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/10/2014 04:47:03 PM) (Source: Application Error) (User: )
Description: Faulting application scheduler .exe, version 1.0.6.7, faulting module oleaut32.dll, version 5.1.2600.5512, fault address 0x00004ee9.
Processing media-specific event for [scheduler .exe!ws!]
Error: (02/10/2014 04:43:01 PM) (Source: AutoEnrollment) (User: )
Description: Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.
Error: (02/10/2014 04:42:59 PM) (Source: Userenv) (User: NT AUTHORITY)
Description: Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.
Error: (02/10/2014 04:34:11 PM) (Source: Application Error) (User: )
Description: Faulting application hpqtra08.exe, version 45.4.157.0, faulting module unknown, version 0.0.0.0, fault address 0x7ca28c16.
Processing media-specific event for [hpqtra08.exe!ws!]
Error: (02/10/2014 04:30:37 PM) (Source: Application Error) (User: )
Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module owugihaji.dll, version 0.0.0.0, fault address 0x000126d7.
Processing media-specific event for [explorer.exe!ws!]
Error: (02/10/2014 04:30:01 PM) (Source: Application Error) (User: )
Description: Faulting application scheduler .exe, version 1.0.6.7, faulting module oleaut32.dll, version 5.1.2600.5512, fault address 0x00004ee9.
Processing media-specific event for [scheduler .exe!ws!]
Error: (02/10/2014 04:27:24 PM) (Source: AutoEnrollment) (User: )
Description: Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.
Error: (02/10/2014 04:27:22 PM) (Source: Userenv) (User: NT AUTHORITY)
Description: Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.
Error: (02/10/2014 00:09:06 PM) (Source: Application Error) (User: )
Description: Faulting application scheduler .exe, version 1.0.6.7, faulting module oleaut32.dll, version 5.1.2600.5512, fault address 0x00004ee9.
Processing media-specific event for [scheduler .exe!ws!]
Error: (02/10/2014 00:06:00 PM) (Source: AutoEnrollment) (User: )
Description: Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.
System errors:
=============
Error: (02/10/2014 04:54:07 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The error:
"%%5"
Happened while starting this command:
C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding
Error: (02/10/2014 04:53:48 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The error:
"%%5"
Happened while starting this command:
C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding
Error: (02/10/2014 04:52:12 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The error:
"%%5"
Happened while starting this command:
C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding
Error: (02/10/2014 04:52:12 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The error:
"%%5"
Happened while starting this command:
C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding
Error: (02/10/2014 04:49:03 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}.
The error:
"%%5"
Happened while starting this command:
C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding
Error: (02/10/2014 04:49:03 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}.
The error:
"%%5"
Happened while starting this command:
C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding
Error: (02/10/2014 04:49:03 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}.
The error:
"%%5"
Happened while starting this command:
C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding
Error: (02/10/2014 04:47:46 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The error:
"%%5"
Happened while starting this command:
C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding
Error: (02/10/2014 04:47:46 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The error:
"%%5"
Happened while starting this command:
C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding
Error: (02/10/2014 04:47:46 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}.
The error:
"%%5"
Happened while starting this command:
C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding
Microsoft Office Sessions:
=========================
Error: (12/29/2009 03:26:59 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 12574 seconds with 1500 seconds of active time. This session ended with a crash.
Error: (04/13/2009 02:44:13 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 792 seconds with 780 seconds of active time. This session ended with a crash.
Error: (04/13/2009 02:30:44 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 610 seconds with 480 seconds of active time. This session ended with a crash.
Error: (12/11/2008 03:11:42 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 11570 seconds with 1020 seconds of active time. This session ended with a crash.
Error: (04/30/2008 10:08:31 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 4521 seconds with 600 seconds of active time. This session ended with a crash.
Error: (04/30/2008 02:16:53 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 954 seconds with 720 seconds of active time. This session ended with a crash.
Error: (04/30/2008 02:00:34 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 17125 seconds with 1020 seconds of active time. This session ended with a crash.
Error: (02/19/2008 08:00:38 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 8, Application Name: Microsoft Office Publisher, Application Version: 12.0.6023.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 2866 seconds with 1020 seconds of active time. This session ended with a crash.
Error: (02/11/2008 08:55:52 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6024.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 413 seconds with 0 seconds of active time. This session ended with a crash.
Error: (02/04/2008 11:06:36 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6024.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 6484 seconds with 1920 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Percentage of memory in use: 81%
Total physical RAM: 447.23 MB
Available physical RAM: 80.66 MB
Total Pagefile: 1053.5 MB
Available Pagefile: 596.72 MB
Total Virtual: 2047.88 MB
Available Virtual: 1962.29 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:64.78 GB) (Free:27.45 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive e: (HP_RECOVERY) (Fixed) (Total:9.74 GB) (Free:9.48 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive f: (USB DISK) (Removable) (Total:3.61 GB) (Free:3.58 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 75 GB) (Disk ID: 95AA95AA)
Partition 1: (Active) - (Size=65 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 4 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=4 GB) - (Type=0C)
==================== End Of Log ============================
MBAM LOGMalwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.04.04.07
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: JPRICELAP [administrator]
2/10/2014 4:56:59 PM
mbam-log-2014-02-10 (16-56-59).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 250765
Time elapsed: 13 minute(s), 44 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B1BA40A1-75F2-51BD-F313-04B03A2C8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
Registry Values Detected: 5
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler|{B1BA40A1-75F2-51BD-F313-04B03A2C8953} (Trojan.Ertfor) -> Data: jsfsue98jfi8dfjijse -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{B1BA40A1-75F2-51BD-F313-04B03A2C8953} (Trojan.Ertfor) -> Data: -> Quarantined and deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SE11 (Rogue.SecurityEssentials) -> Data: C:\Program Files\SecEss\SE11.exe -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer|WINID (Malware.Trace) -> Data: 1CF1DECEE9DDB26 -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoFolderOptions (Hijack.FolderOptions) -> Data: 1 -> Quarantined and deleted successfully.
Registry Data Items Detected: 13
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|StartMenuLogoff (PUM.Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop|NoChangingWallpaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoSetActiveDesktop (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-soft-package.com|http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and repaired successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-software-package.com|http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and repaired successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\get-key-se10.com|http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and repaired successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\is-software-download.com|http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoSetActiveDesktop (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop|NoChangingWallpaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\get-key-se10.com|http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 20
C:\WINDOWS\system32\rpk5dkg.dl$ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\c84h1m.dl$ (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\mvb35316.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\jprice\local settings\temp\win .exe (Trojan.Downloader) -> Delete on reboot.
C:\WINDOWS\SMPDLA.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\WINDOWS\win .exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\winlogon .exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\lsass .exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\nvsvc32 .exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\owugihaji.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\WINDOWS\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\csrss .exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\spoolsv .exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\services .exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\6to4ex.dll (Trojan.Backdoor) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Update\seupd.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\SecEss\SE11.exe (Rogue.SecurityEssentials) -> Quarantined and deleted successfully.
C:\Documents and Settings\jprice\Application Data\Microsoft\Internet Explorer\Quick Launch\Antimalware Doctor.lnk (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
C:\SE11.lnk (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\Q2aRNUk5.com (Malware.Generic) -> Quarantined and deleted successfully.
(end)