Here is the FRST txt file
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:16-06-2014
Ran by SYSTEM on REATOGO on 19-06-2014 19:46:59
Running from E:\
Platform: Microsoft Windows XP (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo...very-scan-tool/
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [vProt] => C:\Program Files\AVG SafeGuard toolbar\vprot.exe [2561560 2014-05-09] ()
HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1404928 2004-10-14] (Analog Devices, Inc.)
HKLM\...\Run: [GameDrive] => C:\Program Files\FarStone\GameDrive\gdtask.exe [94208 2003-07-06] (FarStone Technology Inc.)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [98304 2006-01-03] (Apple Computer, Inc.)
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\Default User\...\Run: [DellSupport] => C:\Program Files\Dell Support\DSAgnt.exe [332800 2005-05-15] (Gteko Ltd.)
BootExecute: autocheck autochk * C:\PROGRA~1\AVG\AVG2014\avgrsx.exe /sync /restart
========================== Services (Whitelisted) =================
S2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [104960 2008-02-22] (ArcSoft Inc.)
S2 AOL ACS; C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [1135728 2004-04-07] (America Online, Inc.)
S2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
S2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [106248 2014-06-17] (SurfRight B.V.)
S2 JavaQuickStarterService; C:\Program Files\Java\jre6\bin\jqs.exe [154032 2013-01-15] (Sun Microsystems, Inc.)
S2 LexBceS; C:\WINDOWS\system32\LEXBCES.EXE [303104 2003-02-25] (Lexmark International, Inc.)
S4 McComponentHostService; C:\Program Files\McAfee Security Scan\2.1.121\McCHSvc.exe [227232 2010-09-03] (McAfee, Inc.)
S2 MyWebSearchService; C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE [28739 2008-06-13] (MyWebSearch.com)
S3 NetSvc; C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe [143360 2003-12-17] (Intel® Corporation)
S4 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S2 vToolbarUpdater18.1.5; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe [1801752 2014-05-09] (AVG Secure Search)
S2 AfaService; C:\WINDOWS\system32\afasrv32.exe [X]
==================== Drivers (Whitelisted) ====================
S4 abp480n5; C:\Windows\system32\DRIVERS\ABP480N5.SYS [23552 2001-08-17] (Microsoft Corporation)
S3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
S2 ASCTRM; C:\Windows\System32\Drivers\ASCTRM.sys [8552 2006-01-03] (Windows ® 2000 DDK provider)
S1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [122136 2014-05-13] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [198936 2014-05-13] (AVG Technologies CZ, s.r.o.)
S0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [149784 2014-05-13] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-05-13] (AVG Technologies CZ, s.r.o.)
S1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [192280 2014-05-13] (AVG Technologies CZ, s.r.o.)
S0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [237848 2014-05-13] (AVG Technologies CZ, s.r.o.)
S0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [107288 2014-05-13] (AVG Technologies CZ, s.r.o.)
S0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-05-13] (AVG Technologies CZ, s.r.o.)
S1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [210200 2014-05-13] (AVG Technologies CZ, s.r.o.)
S1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [42784 2014-05-09] (AVG Technologies)
S2 drvnddm; C:\Windows\System32\drivers\drvnddm.sys [40480 2004-11-23] (Sonic Solutions)
S1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [7936 2014-04-13] (FNet Co., Ltd.)
S3 FreshIO; C:\Program Files\FreshDevices\FreshDiagnose\FreshIO.sys [2410 2004-10-26] ()
S1 gdxwdm; C:\Windows\System32\DRIVERS\GDXWDM.sys [59977 2003-06-12] (FarStone Inc.)
S3 IntelC51; C:\Windows\System32\DRIVERS\IntelC51.sys [1233525 2004-03-06] (Intel Corporation)
S3 IntelC52; C:\Windows\System32\DRIVERS\IntelC52.sys [647929 2004-03-06] (Intel Corporation)
S3 IntelC53; C:\Windows\System32\DRIVERS\IntelC53.sys [61157 2004-06-16] (Intel Corporation)
S3 mohfilt; C:\Windows\System32\DRIVERS\mohfilt.sys [37048 2004-03-06] (Intel Corporation)
S1 sscdbhk5; C:\Windows\System32\drivers\sscdbhk5.sys [5627 2004-07-14] (Sonic Solutions)
S1 ssrtln; C:\Windows\System32\drivers\ssrtln.sys [23545 2004-07-14] (Sonic Solutions)
S2 tfsnboio; C:\Windows\System32\dla\tfsnboio.sys [25883 2004-12-06] (Sonic Solutions)
S2 tfsncofs; C:\Windows\System32\dla\tfsncofs.sys [34843 2004-12-06] (Sonic Solutions)
S2 tfsndrct; C:\Windows\System32\dla\tfsndrct.sys [4123 2004-12-06] (Sonic Solutions)
S2 tfsndres; C:\Windows\System32\dla\tfsndres.sys [2239 2004-12-06] (Sonic Solutions)
S2 tfsnifs; C:\Windows\System32\dla\tfsnifs.sys [86586 2004-12-06] (Sonic Solutions)
S2 tfsnopio; C:\Windows\System32\dla\tfsnopio.sys [15227 2004-12-06] (Sonic Solutions)
S2 tfsnpool; C:\Windows\System32\dla\tfsnpool.sys [6363 2004-12-06] (Sonic Solutions)
S2 tfsnudf; C:\Windows\System32\dla\tfsnudf.sys [98714 2004-12-06] (Sonic Solutions)
S2 tfsnudfa; C:\Windows\System32\dla\tfsnudfa.sys [100603 2004-12-06] (Sonic Solutions)
S3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2003-01-10] (America Online, Inc.)
S3 bvrp_pci; No ImagePath
S5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 TlntSvr;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-18 16:11 - 2014-06-19 19:46 - 00000000 ____D () C:\frst
2014-06-17 22:27 - 2014-06-17 22:27 - 00001610 _____ () C:\Documents and Settings\All Users\Desktop\HitmanPro.lnk
2014-06-17 22:27 - 2014-06-17 22:27 - 00000000 ____D () C:\Program Files\HitmanPro
2014-06-17 22:26 - 2014-06-17 22:26 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\HitmanPro
2014-06-04 00:10 - 2014-06-04 00:10 - 00000713 _____ () C:\Documents and Settings\All Users\Desktop\Vega Strike.lnk
2014-06-04 00:03 - 2014-06-04 00:21 - 00000000 ____D () C:\Program Files\Vega Strike
2014-06-03 21:32 - 2014-06-03 21:32 - 00090112 _____ () C:\Windows\Minidump\Mini060314-01.dmp
2014-06-01 15:47 - 2014-06-01 15:47 - 00090112 _____ () C:\Windows\Minidump\Mini060114-02.dmp
2014-06-01 13:50 - 2014-06-01 13:50 - 00090112 _____ () C:\Windows\Minidump\Mini060114-01.dmp
2014-05-23 01:08 - 2014-05-26 22:12 - 00001670 _____ () C:\Documents and Settings\All Users\Desktop\NetZero Quick Help.lnk
==================== One Month Modified Files and Folders =======
2014-06-19 19:46 - 2014-06-18 16:11 - 00000000 ____D () C:\frst
2014-06-19 16:52 - 2004-08-10 15:08 - 00032398 _____ () C:\Windows\SchedLgU.Txt
2014-06-19 16:52 - 2004-08-10 15:02 - 01861831 _____ () C:\Windows\WindowsUpdate.log
2014-06-19 10:01 - 2013-03-28 00:00 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MFAData
2014-06-19 10:01 - 2006-01-08 13:41 - 00000178 ___SH () C:\Documents and Settings\Nancy Langston\ntuser.ini
2014-06-19 10:01 - 2006-01-08 13:41 - 00000000 ____D () C:\Documents and Settings\Nancy Langston\Local Settings\Temp
2014-06-19 09:58 - 2004-08-10 14:51 - 00002206 _____ () C:\Windows\System32\wpa.dbl
2014-06-19 09:54 - 2010-01-29 10:35 - 00734835 _____ () C:\Windows\setupapi.log
2014-06-17 22:27 - 2014-06-17 22:27 - 00001610 _____ () C:\Documents and Settings\All Users\Desktop\HitmanPro.lnk
2014-06-17 22:27 - 2014-06-17 22:27 - 00000000 ____D () C:\Program Files\HitmanPro
2014-06-17 22:27 - 2004-08-10 15:02 - 00000000 ____D () C:\Windows\System32\Restore
2014-06-17 22:26 - 2014-06-17 22:26 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\HitmanPro
2014-06-05 15:31 - 2012-08-29 19:25 - 00000000 ____D () C:\Documents and Settings\Nancy Langston\Application Data\Free Download Manager
2014-06-04 00:21 - 2014-06-04 00:03 - 00000000 ____D () C:\Program Files\Vega Strike
2014-06-04 00:10 - 2014-06-04 00:10 - 00000713 _____ () C:\Documents and Settings\All Users\Desktop\Vega Strike.lnk
2014-06-04 00:10 - 2012-05-18 20:48 - 00444952 _____ (Creative Labs) C:\Windows\System32\wrap_oal.dll
2014-06-04 00:10 - 2012-05-18 20:48 - 00109080 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2014-06-03 22:30 - 2013-12-31 02:04 - 00000000 ____D () C:\Documents and Settings\Nancy Langston\Desktop\Games
2014-06-03 21:32 - 2014-06-03 21:32 - 00090112 _____ () C:\Windows\Minidump\Mini060314-01.dmp
2014-06-03 21:32 - 2006-11-23 19:48 - 00000000 ____D () C:\Windows\Minidump
2014-06-03 19:36 - 2004-08-10 14:59 - 00000159 ____C () C:\Windows\wiadebug.log
2014-06-03 19:36 - 2004-08-10 14:59 - 00000048 ____C () C:\Windows\wiaservc.log
2014-06-02 21:48 - 2004-08-10 15:01 - 00125780 ____C () C:\Windows\wmsetup.log
2014-06-02 01:47 - 2012-06-27 06:27 - 00000000 ____D () C:\Documents and Settings\Nancy Langston\Application Data\Audacity
2014-06-01 16:07 - 2007-01-26 15:30 - 00097792 _____ () C:\Documents and Settings\Nancy Langston\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-01 15:47 - 2014-06-01 15:47 - 00090112 _____ () C:\Windows\Minidump\Mini060114-02.dmp
2014-06-01 13:50 - 2014-06-01 13:50 - 00090112 _____ () C:\Windows\Minidump\Mini060114-01.dmp
2014-05-26 22:12 - 2014-05-23 01:08 - 00001670 _____ () C:\Documents and Settings\All Users\Desktop\NetZero Quick Help.lnk
2014-05-26 22:12 - 2014-05-09 20:56 - 00001589 _____ () C:\Documents and Settings\All Users\Desktop\NetZero Internet.lnk
2014-05-26 22:12 - 2011-10-30 01:13 - 00000000 ____D () C:\Program Files\NetZero
2014-05-22 18:37 - 2012-08-29 19:25 - 00000000 ____D () C:\Free Download Manager
Some content of TEMP:
====================
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\CmdLineExt02.dll
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\dlLogic.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\dltr.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\exec.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\NullsoftHelper.dll
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\Tsu4F4A87A4.dll
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\uires.dll
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\verifier.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\{013D9DD8-06B8-401E-B647-C69CC66F1D4C}-35.0.1916.114_chrome_installer.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\{0573569C-A58D-4F2B-8011-71B6ECE3C7F3}-35.0.1916.114_34.0.1847.137_chrome_updater.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\{38863E87-278A-4E0B-B9FB-02759F537E9D}-35.0.1916.114_chrome_installer.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\{56F7B9B9-0BAC-4D1F-8FC9-B2659556E242}-35.0.1916.114_chrome_installer.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\{7D98C18B-7439-4618-A8BE-8AE0E3E7EC7B}-35.0.1916.114_chrome_installer.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\{92962532-FE87-410D-881C-3BE600D298ED}-35.0.1916.114_chrome_installer.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\{946224C8-068C-43D2-BC4F-0EF5B028D71E}-35.0.1916.114_chrome_installer.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\{A19306CE-DC2A-4236-A955-E99942A45554}-35.0.1916.114_chrome_installer.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\{B1F9B67A-7265-4A32-9850-ED09F5DCD949}-35.0.1916.114_chrome_installer.exe
C:\Documents and Settings\Nancy Langston\Local Settings\Temp\{FEAFA339-D6C6-445B-A7A3-34B8B2D83463}-35.0.1916.114_chrome_installer.exe
==================== Known DLLs (Whitelisted) ============
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll
[2004-08-10 14:51] - [2012-10-03 00:58] - 0617984 ____A (Microsoft Corporation) 1cf4ff12f6ae7adad82ca4ae55bd8b46
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Restore Points (XP) =====================
RP: -> 2014-06-17 22:27 - 024576 _restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1
==================== Memory info ===========================
Percentage of memory in use: 18%
Total physical RAM: 1277.98 MB
Available physical RAM: 1035.79 MB
Total Pagefile: 1113.13 MB
Available Pagefile: 1055.21 MB
Total Virtual: 2047.88 MB
Available Virtual: 1999.79 MB
==================== Drives ================================
Drive b: (RAMDisk) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS
Drive c: () (Fixed) (Total:34.21 GB) (Free:15.91 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:18.64 GB) (Free:11.3 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive e: (HITMANPRO) (Removable) (Total:3.68 GB) (Free:3.66 GB) FAT32
Drive x: (ReatogoPE) (CDROM) (Total:0.43 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 37 GB) (Disk ID: D0F4738C)
Partition 1: (Not Active) - (Size=31 MB) - (Type=DE)
Partition 2: (Active) - (Size=34 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=3 GB) - (Type=DB)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 19 GB) (Disk ID: C78FC78F)
Partition 1: (Active) - (Size=19 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (Size: 4 GB) (Disk ID: C7EE53AE)
Partition 1: (Active) - (Size=4 GB) - (Type=0B)
==================== End Of Log ============================
And here is the Result txt log
ListParts by Farbar Version: 17-04-2014
Ran by SYSTEM (administrator) on 19-06-2014 at 19:48:42
Windows XP (X86)
Running From: E:\
Language: 0409
************************************************************
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 1277.98 MB
Available physical RAM: 1077.29 MB
Total Pagefile: 1113.13 MB
Available Pagefile: 1064.24 MB
Total Virtual: 2047.88 MB
Available Virtual: 2010.1 MB
======================= Partitions =========================
1 Drive b: (RAMDisk) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS
2 Drive c: () (Fixed) (Total:34.21 GB) (Free:15.91 GB) NTFS ==>[Drive with boot components (Windows XP)]
3 Drive d: () (Fixed) (Total:18.64 GB) (Free:11.3 GB) NTFS ==>[Drive with boot components (Windows XP)]
4 Drive e: (HITMANPRO) (Removable) (Total:3.68 GB) (Free:3.66 GB) FAT32
5 Drive x: (ReatogoPE) (CDROM) (Total:0.43 GB) (Free:0 GB) CDFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 37 GB 0 B
Disk 1 Online 19 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 31 MB 32 KB
Partition 2 Primary 34 GB 31 MB
Partition 3 Unknown 3075 MB 34 GB
======================================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No