For my friend Sugartooth,
Thanks for helping me out. My kids are the ones who use this computer and they complain that it's slow.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-05-2015 02
Ran by Compaq_Owner (administrator) on YOUR-4F1261A8E5 on 18-05-2015 18:39:32
Running from C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Desktop
Loaded Profiles: Compaq_Owner (Available profiles: Compaq_Owner)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Hewlett-Packard Company) C:\WINDOWS\system\hpsysdrv.exe
(Agere Systems) C:\WINDOWS\AGRSMMSG.exe
(Hewlett-Packard Company) C:\hp\KBD\kbd.exe
(Apple Computer, Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\ALCXMNTR.EXE
(Apple Computer, Inc.) C:\Program Files\QuickTime\qttask.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Sony Corporation) C:\Program Files\Sony\PlayMemories Home\PMBVolumeWatcher.exe
(Mindspark) C:\PROGRA~1\MAPSGA~2\bar\1.bin\APPINTEGRATOR.EXE
(Mindspark) C:\PROGRA~1\ONLINE~3\bar\1.bin\APPINTEGRATOR.EXE
(Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe
() C:\Program Files\Sony\PlayMemories Home\dfs.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Sony Corporation) C:\Program Files\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
(HP) C:\WINDOWS\system32\HPZipm12.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimCleaner Plus\SlimServiceFactory.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Apple Computer, Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimCleaner Plus\SlimService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Mindspark) C:\Program Files\MapsGalaxy_39\bar\1.bin\CrExtP39.exe
(Mindspark) C:\Program Files\MapsGalaxy_39\bar\1.bin\CrExtP39.exe
(Mindspark) C:\Program Files\MapsGalaxy_39\bar\1.bin\CrExtP39.exe
(Mindspark) C:\Program Files\MapsGalaxy_39\bar\1.bin\CrExtP39.exe
(Mindspark) C:\Program Files\OnlineMapFinder_9p\bar\1.bin\CrExtP9p.exe
(Mindspark) C:\Program Files\OnlineMapFinder_9p\bar\1.bin\CrExtP9p.exe
(Mindspark) C:\Program Files\OnlineMapFinder_9p\bar\1.bin\CrExtP9p.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [hpsysdrv] => c:\windows\system\hpsysdrv.exe [52736 1998-05-07] (Hewlett-Packard Company)
HKLM\...\Run: [AGRSMMSG] => C:\WINDOWS\AGRSMMSG.exe [88363 2004-06-29] (Agere Systems)
HKLM\...\Run: [KBD] => C:\HP\KBD\KBD.EXE [61440 2003-02-11] (Hewlett-Packard Company)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [278528 2004-10-14] (Apple Computer, Inc.)
HKLM\...\Run: [AlcxMonitor] => C:\WINDOWS\ALCXMNTR.EXE [57344 2004-09-07] (Realtek Semiconductor Corp.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [98304 2005-02-15] (Apple Computer, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM\...\Run: [TkBellExe] => C:\program files\real\realplayer\update\realsched.exe [296056 2011-12-02] (RealNetworks, Inc.)
HKLM\...\Run: [PMBVolumeWatcher] => C:\Program Files\Sony\PlayMemories Home\PMBVolumeWatcher.exe [740888 2013-04-24] (Sony Corporation)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [MapsGalaxy AppIntegrator 32-bit] => C:\Program Files\MapsGalaxy_39\bar\1.bin\AppIntegrator.exe [225864 2014-09-20] (Mindspark)
HKLM\...\Run: [MapsGalaxy Search Scope Monitor] => C:\Program Files\MapsGalaxy_39\bar\1.bin\39SrchMn.exe [55880 2014-09-20] (Mindspark)
HKLM\...\Run: [OnlineMapFinder AppIntegrator 32-bit] => C:\Program Files\OnlineMapFinder_9p\bar\1.bin\AppIntegrator.exe [225864 2014-09-20] (Mindspark)
HKLM\...\Run: [OnlineMapFinder Search Scope Monitor] => C:\Program Files\OnlineMapFinder_9p\bar\1.bin\9pSrchMn.exe [55880 2014-09-20] (Mindspark)
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-3036499068-691177906-837026766-1009\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-13] (Microsoft Corporation)
HKU\S-1-5-21-3036499068-691177906-837026766-1009\...\Run: [SlimCleaner Plus] => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe [26163008 2014-08-04] (SlimWare Utilities, Inc.)
HKU\S-1-5-21-3036499068-691177906-837026766-1009\...\MountPoints2: {946850c5-1e27-11d9-baf0-806d6172696f} - D:\setup.exe
HKU\S-1-5-21-3036499068-691177906-837026766-1009\...\MountPoints2: {c7eaf834-7138-11d9-a02f-806d6172696f} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3036499068-691177906-837026766-1009\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/
HKU\S-1-5-21-3036499068-691177906-837026766-1009\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
HKU\S-1-5-21-3036499068-691177906-837026766-1009\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...ario&pf=desktop
URLSearchHook: [S-1-5-21-3036499068-691177906-837026766-1009] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKU\S-1-5-21-3036499068-691177906-837026766-1009 - (No Name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - C:\Program Files\MapsGalaxy_39\bar\1.bin\39SrcAs.dll (Mindspark)
URLSearchHook: HKU\S-1-5-21-3036499068-691177906-837026766-1009 - (No Name) - {6d010537-9e99-400b-b652-b0d5a5757e5d} - C:\Program Files\OnlineMapFinder_9p\bar\1.bin\9pSrcAs.dll (Mindspark)
SearchScopes: HKLM -> DefaultScope {b0441a0e-a49a-4e16-afc1-74ecced1921f} URL = http://search.tb.ask...or={searchTerms}
SearchScopes: HKLM -> {274daec0-c4e8-4f30-9e5c-9424990769b9} URL = http://search.mywebs...or={searchTerms}
SearchScopes: HKLM -> {b0441a0e-a49a-4e16-afc1-74ecced1921f} URL = http://search.tb.ask...or={searchTerms}
SearchScopes: HKU\S-1-5-21-3036499068-691177906-837026766-1009 -> DefaultScope {5AD266E2-AF0D-4069-8443-5B8F21633EE8} URL = http://search.yahoo....f-8&fr=chr-yie8
SearchScopes: HKU\S-1-5-21-3036499068-691177906-837026766-1009 -> {274daec0-c4e8-4f30-9e5c-9424990769b9} URL = http://search.mywebs...or={searchTerms}
SearchScopes: HKU\S-1-5-21-3036499068-691177906-837026766-1009 -> {5AD266E2-AF0D-4069-8443-5B8F21633EE8} URL = http://search.yahoo....f-8&fr=chr-yie8
SearchScopes: HKU\S-1-5-21-3036499068-691177906-837026766-1009 -> {5B17CE5D-73D2-4EA9-9390-F90B47B4089B} URL = http://delicious.com...?p={searchTerms}
SearchScopes: HKU\S-1-5-21-3036499068-691177906-837026766-1009 -> {73198342-D752-4CDF-BB3E-27DC07C8E311} URL = http://rover.ebay.co...le={searchTerms}
SearchScopes: HKU\S-1-5-21-3036499068-691177906-837026766-1009 -> {A91EBEC7-F573-499F-9B03-FE32465A8802} URL = http://www.flickr.co...?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3036499068-691177906-837026766-1009 -> {b0441a0e-a49a-4e16-afc1-74ecced1921f} URL = http://search.tb.ask...or={searchTerms}
BHO: Toolbar BHO -> {1e91a655-bb4b-4693-a05e-2edebc4c9d89} -> C:\Program Files\MapsGalaxy_39\bar\1.bin\39bar.dll [2014-09-20] (Mindspark)
BHO: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-12-02] (RealPlayer)
BHO: Search Assistant BHO -> {6a79cdac-f710-4996-842b-fdc33b785a35} -> C:\Program Files\OnlineMapFinder_9p\bar\1.bin\9pSrcAs.dll [2014-09-20] (Mindspark)
BHO: Search Assistant BHO -> {71c1d63a-c944-428a-a5bd-ba513190e5d2} -> C:\Program Files\MapsGalaxy_39\bar\1.bin\39SrcAs.dll [2014-09-20] (Mindspark)
BHO: CNavExtBho Class -> {BDF3E430-B101-42AD-A544-FADC6B084872} -> c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll No File
BHO: Toolbar BHO -> {d9f16d8b-81b5-4667-af4d-25365bbf7fc9} -> C:\Program Files\OnlineMapFinder_9p\bar\1.bin\9pbar.dll [2014-09-20] (Mindspark)
BHO: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll [2010-03-23] (Yahoo! Inc)
Toolbar: HKLM - MapsGalaxy - {364ea597-e728-4ce4-bb4a-ed846ef47970} - C:\Program Files\MapsGalaxy_39\bar\1.bin\39bar.dll [2014-09-20] (Mindspark)
Toolbar: HKLM - OnlineMapFinder - {f41a56d2-7b52-4d16-812c-a63c6ca9d4c5} - C:\Program Files\OnlineMapFinder_9p\bar\1.bin\9pbar.dll [2014-09-20] (Mindspark)
Toolbar: HKU\S-1-5-21-3036499068-691177906-837026766-1009 -> Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll No File
Toolbar: HKU\S-1-5-21-3036499068-691177906-837026766-1009 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-3036499068-691177906-837026766-1009 -> MapsGalaxy - {364EA597-E728-4CE4-BB4A-ED846EF47970} - C:\Program Files\MapsGalaxy_39\bar\1.bin\39bar.dll [2014-09-20] (Mindspark)
Toolbar: HKU\S-1-5-21-3036499068-691177906-837026766-1009 -> OnlineMapFinder - {F41A56D2-7B52-4D16-812C-A63C6CA9D4C5} - C:\Program Files\OnlineMapFinder_9p\bar\1.bin\9pbar.dll [2014-09-20] (Mindspark)
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
ShellExecuteHooks: - {FA010552-4A27-4cb1-A1BB-3E2D697F1639} - No File [ ]
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 192.168.1.1
FireFox:
========
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=15.0.0.198 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll [2011-12-02] (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=15.0.0.198 -> c:\program files\real\realplayer\Netscape6\nprjplug.dll [2011-12-02] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.0.198 -> C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2011-12-02] (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.0.198 -> C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2011-12-02] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=15.0.0.198 -> c:\program files\real\realplayer\Netscape6\nprpjplug.dll [2011-12-02] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-12-02]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-10-17]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR DefaultSearchKeyword: Default -> inbox.com
CHR DefaultSearchURL: Default -> http://www2.inbox.co...id=82116&lng=en
CHR DefaultSuggestURL: Default -> http://www.inbox.com...?q={searchTerms}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\41.0.2272.101\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\41.0.2272.101\pdf.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\41.0.2272.101\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat 6.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (RealNetworks Chrome Background Extension Plug-In (32-bit) ) - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer HTML5VideoShim Plug-In (32-bit) ) - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (My Web Search Plugin Stub) - C:\Program Files\MyWebSearch\bar\3.bin\NPMyWebS.dll No File
CHR Plugin: (RealJukebox NS Plugin) - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
CHR Profile: C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2011-12-02]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-23]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-02]
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2011-12-02]
CHR HKLM\...\Chrome\Extension: [odbbfaealmlpnodchplhdomkgpdkeeal] - C:\Program Files\RebateInformer\Chrome\rebateinformer_c.crx [Not Found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 DeviceFinderService; C:\Program Files\Sony\PlayMemories Home\dfs.exe [149528 2013-04-24] ()
R3 iPodService; C:\Program Files\iPod\bin\iPodService.exe [327680 2004-10-14] (Apple Computer, Inc.) [File not signed]
S2 MapsGalaxy_39Service; C:\Program Files\MapsGalaxy_39\bar\1.bin\39barsvc.exe [90696 2014-09-20] (Mindspark)
S2 OnlineMapFinder_9pService; C:\Program Files\OnlineMapFinder_9p\bar\1.bin\9pbarsvc.exe [90696 2014-09-20] (Mindspark)
R2 PMBDeviceInfoProvider; C:\Program Files\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [483864 2013-04-24] (Sony Corporation)
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [73728 2007-08-09] (HP) [File not signed]
R2 SlimService; C:\Program Files\SlimCleaner Plus\SlimServiceFactory.exe [222016 2014-08-04] (SlimWare Utilities, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [2317696 2005-04-20] (Realtek Semiconductor Corp.)
R3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [51120 2004-12-14] (HP)
R3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2004-12-14] (HP)
R3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21744 2004-12-14] (HP)
R3 Iviaspi; C:\WINDOWS\System32\drivers\iviaspi.sys [21060 2003-09-11] (InterVideo, Inc.) [File not signed]
R3 Pfc; C:\WINDOWS\System32\drivers\pfc.sys [10368 2003-09-19] (Padus, Inc.) [File not signed]
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [20576 2005-02-15] (Sonic Solutions) [File not signed]
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-04] (Realtek Semiconductor Corporation)
R3 SiS315; C:\WINDOWS\System32\DRIVERS\sisgrp.sys [247296 2005-04-12] (Silicon Integrated Systems Corporation)
R1 SiSkp; C:\WINDOWS\System32\DRIVERS\srvkp.sys [11904 2005-04-12] (Silicon Integrated Systems Corporation)
R3 SISNIC; C:\WINDOWS\System32\DRIVERS\sisnic.sys [32768 2003-07-11] (SiS Corporation)
S3 HSFHWBS2; system32\DRIVERS\HSFHWBS2.sys [X]
S3 HSF_DP; system32\DRIVERS\HSF_DP.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 smserial; system32\DRIVERS\smserial.sys [X]
S3 winachsf; system32\DRIVERS\HSF_CNXT.sys [X]
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-18 18:39 - 2015-05-18 18:39 - 00020454 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Desktop\FRST.txt
2015-05-18 18:39 - 2015-05-18 18:39 - 00000000 ____D () C:\FRST
2015-05-18 18:36 - 2015-05-18 18:36 - 01146368 _____ (Farbar) C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Desktop\FRST.exe
2015-05-18 18:23 - 2015-05-18 18:23 - 00000000 ____D () C:\WINDOWS\LastGood
2015-05-17 17:47 - 2015-05-18 17:50 - 00013824 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Desktop\Argumentative essay off campus eating.wps
2015-05-14 16:29 - 2015-05-14 16:29 - 00009728 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Desktop\con hear part 2.wps
2015-05-14 15:41 - 2015-05-14 15:41 - 00009728 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Desktop\congreesinal hear part one.wps
2015-05-07 10:53 - 2015-05-07 10:53 - 00105238 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Desktop\adam
2015-04-28 16:06 - 2015-04-28 16:06 - 00686232 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Desktop\debra
2015-04-21 21:10 - 2015-04-21 21:10 - 00010240 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Desktop\mike silo bag.wps
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-18 18:39 - 2011-05-20 14:51 - 00000000 ____D () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Temp
2015-05-18 18:24 - 2013-04-29 20:16 - 08320378 _____ () C:\WINDOWS\KB978542.log
2015-05-18 18:24 - 2004-10-15 10:52 - 01183870 _____ () C:\WINDOWS\WindowsUpdate.log
2015-05-18 18:17 - 2014-09-23 17:37 - 00000380 _____ () C:\WINDOWS\Tasks\SlimCleaner Plus (Scheduled Scan - Compaq_Owner).job
2015-05-18 18:17 - 2012-05-24 07:16 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-05-18 18:17 - 2004-10-15 03:33 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-05-18 18:17 - 2004-10-15 03:33 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2015-05-18 18:16 - 2015-02-06 19:44 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0427ffd7a7e0c.job
2015-05-18 18:16 - 2014-11-13 16:43 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cfff9bab2ab3f0.job
2015-05-18 18:16 - 2014-10-23 08:20 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cfeed4da8d847e.job
2015-05-18 18:16 - 2011-07-21 09:07 - 00000292 _____ () C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-3036499068-691177906-837026766-1009.job
2015-05-18 18:16 - 2011-07-16 22:07 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cc443f6f4a153a.job
2015-05-18 18:16 - 2011-01-15 01:51 - 00000400 _____ () C:\WINDOWS\Tasks\Final Media Player Update Checker.job
2015-05-18 18:16 - 2005-07-19 14:09 - 00000248 _____ () C:\WINDOWS\system\hpsysdrv.dat
2015-05-18 18:16 - 2004-10-15 10:51 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-18 17:54 - 2004-10-15 10:51 - 00031922 _____ () C:\WINDOWS\SchedLgU.Txt
2015-05-18 17:50 - 2011-07-12 19:45 - 00015152 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Application Data\wklnhst.dat
2015-05-18 17:43 - 2011-07-16 22:07 - 00000898 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cc443f6fa710f0.job
2015-05-18 17:29 - 2005-02-15 17:22 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp
2015-05-18 17:27 - 2004-10-15 10:41 - 00001158 _____ () C:\WINDOWS\system32\wpa.dbl
2015-05-17 16:46 - 2014-09-08 16:51 - 00027136 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Desktop\Agenda.Template.wps
2015-05-14 16:50 - 2013-08-19 12:55 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-05-14 16:39 - 2011-05-20 16:23 - 137310008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-05-08 15:00 - 2014-03-05 16:10 - 00000230 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
==================== Files in the root of some directories =======
2011-07-12 19:45 - 2015-05-18 17:50 - 0015152 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Application Data\wklnhst.dat
2012-03-06 04:22 - 2014-02-19 14:51 - 0016384 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-05-20 14:51 - 2011-05-20 15:46 - 0000151 _____ () C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Application Data\fusioncache.dat
Some content of TEMP:
====================
C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Temp\lowproc.exe
C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Temp\SlimCleanerPlus.x86.exe
C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Temp\stubhelper.dll
C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Temp\{0E98DF01-042F-4B6D-B8B0-5D1B5FF90BFF}-28.0.1500.95_chrome_installer.exe
C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Temp\{817F96D7-D4BE-483E-8A1A-28E90104474D}-33.0.1750.146_chrome_installer.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 16-05-2015 02
Ran by Compaq_Owner at 2015-05-18 18:40:31
Running from C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3036499068-691177906-837026766-500 - Administrator - Enabled)
ASPNET (S-1-5-21-3036499068-691177906-837026766-1010 - Limited - Enabled)
Compaq_Owner (S-1-5-21-3036499068-691177906-837026766-1009 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5
Guest (S-1-5-21-3036499068-691177906-837026766-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-3036499068-691177906-837026766-1008 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-3036499068-691177906-837026766-1002 - Limited - Disabled)
SUPPORT_fddfa904 (S-1-5-21-3036499068-691177906-837026766-1007 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
1600 (Version: 47.0.1.000 - Hewlett-Packard) Hidden
1600_Help (Version: 47.0.1.000 - Hewlett-Packard) Hidden
1600Trb (Version: 47.0.1.000 - Hewlett-Packard) Hidden
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Agere Systems PCI Soft Modem (HKLM\...\Agere Systems Soft Modem) (Version: - )
AiO_Scan (Version: 47.0.1.000 - Hewlett-Packard) Hidden
AiOSoftware (Version: 47.0.1.000 - Hewlett-Packard) Hidden
Blackhawk Striker 2 from Compaq (remove only) (HKLM\...\BFAF1EEC-E987-415B-BCB8-80CDB0BC6CDF) (Version: - )
Blasterball 2 from Compaq (remove only) (HKLM\...\75528D5F-DD82-402E-BA7C-045B7DC6A712) (Version: - )
Blasterball 2 Remix from Compaq (remove only) (HKLM\...\9D7E7CDA-051E-4B0D-8CEE-58F41F449CF9) (Version: - )
Bounce Symphony from Compaq (remove only) (HKLM\...\29FF6D07-4A15-41F1-9D5E-E0F3A58012C6) (Version: - )
BufferChm (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Cisco Connect (HKLM\...\Cisco Connect) (Version: 1.4.11245.0 - Cisco Consumer Products LLC)
Compaq Connections (HKLM\...\BackWeb-6750491 Uninstaller) (Version: - )
Compaq Organize (HKLM\...\{D0122362-6333-4DE4-93F6-A5A2F3CC101A}) (Version: - )
Copy (Version: 45.4.157.000 - Hewlett-Packard) Hidden
CP_AtenaShokunin1Config (Version: 45.4.131.000 - Hewlett-Packard) Hidden
cp_dwShrek2Albums1 (Version: 45.4.157.000 - Hewlett-Packard) Hidden
cp_dwShrek2Cards1 (Version: 45.4.157.000 - Hewlett-Packard) Hidden
CreativeProjects (Version: 45.4.157.000 - Hewlett-Packard) Hidden
CreativeProjectsTemplates (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Crystal Maze from Compaq (remove only) (HKLM\...\C43D84CD-EBFC-48D3-A330-7868C8AD415A) (Version: - )
CueTour (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Destinations (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Director (Version: 45.4.157.000 - Hewlett-Packard) Hidden
DocProc (Version: 4.5.0.0 - Hewlett-Packard) Hidden
DocumentViewer (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Easy Internet Sign-up (HKLM\...\InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}) (Version: FE UI-3.1.0.1288 - Hewlett-Packard)
Easy Internet Sign-up (Version: FE UI-3.1.0.1288 - Hewlett-Packard) Hidden
Fax (Version: 47.0.1.000 - Hewlett-Packard) Hidden
Google Chrome (HKLM\...\Google Chrome) (Version: 42.0.2311.152 - Google Inc.)
Google Earth Plug-in (HKLM\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
Help and Support Additions (HKLM\...\Help and Support Additions) (Version: - )
HP Image Zone 4.7 (HKLM\...\HP Photo & Imaging) (Version: 4.7 - HP)
HP PSC & OfficeJet 4.7 (HKLM\...\{342C7C88-D335-4bc2-8CF1-281857629CE2}) (Version: - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HpSdpAppCoreApp (Version: 3.00.0000 - Hewlett-Packard) Hidden
HPSystemDiagnostics (Version: 1.6.0.0 - Your Company Name) Hidden
InstantShare (Version: 45.4.157.000 - Hewlett-Packard) Hidden
InstantShareAlert (Version: 1.00.0000 - HP) Hidden
InterVideo DiscLabel (HKLM\...\{C3F058C0-A21C-452D-8D99-95B1A45F417D}) (Version: - )
InterVideo WinDVD Creator (HKLM\...\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}) (Version: 2.5.14.426 - InterVideo Inc.)
InterVideo WinDVD Creator (HKLM\...\{6B350CA4-0031-0002-3757-34999AD85AEC}) (Version: - )
InterVideo WinDVD Player (HKLM\...\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}) (Version: 5.0-B11.668 - InterVideo Inc.)
iTunes (HKLM\...\InstallShield_{BE20E2F5-1903-4AAE-B1AF-2046E586C925}) (Version: 4.7.0.42 - Apple Computer, Inc.)
iTunes (Version: 4.7.0.42 - Apple Computer, Inc.) Hidden
Java 2 Runtime Environment, SE v1.4.2_03 (HKLM\...\{7148F0A8-6813-11D6-A77B-00B0D0142030}) (Version: 1.4.2_03 - Sun Microsystems, Inc.)
KBD (HKLM\...\KBD) (Version: - )
LP_Flash (Version: 1.00.0000 - Hewlett-Packard) Hidden
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
MapsGalaxy Internet Explorer Toolbar (HKLM\...\MapsGalaxy_39bar Uninstall Internet Explorer) (Version: - Mindspark Interactive Network) <==== ATTENTION
MapsGalaxy Toolbar (HKLM\...\MapsGalaxy_39bar Uninstall) (Version: - Mindspark Interactive Network) <==== ATTENTION
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Standard Edition 2003 (HKLM\...\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Plus! Dancer LE (HKLM\...\{1A103D70-5C9B-4E1A-B306-5106C68F9914}) (Version: 1.1.0.3522 - Microsoft Corporation)
Microsoft Plus! Digital Media Edition Installer (HKLM\...\{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}) (Version: 1.1.0.3500 - Microsoft Corporation)
Microsoft Plus! Photo Story 2 LE (HKLM\...\{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}) (Version: 1.1.0.3463 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation)
Microsoft Works (HKLM\...\{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}) (Version: 08.04.0623 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
OnlineMapFinder Internet Explorer Toolbar (HKLM\...\OnlineMapFinder_9pbar Uninstall Internet Explorer) (Version: - Mindspark Interactive Network) <==== ATTENTION
Orbital from Compaq (remove only) (HKLM\...\26DC0ED6-93A7-43C1-8DC5-EC16079580F9) (Version: - )
Overball from Compaq (remove only) (HKLM\...\FA7F5211-C629-4711-BD82-7DFFB08CB518) (Version: - )
PanoStandAlone (Version: 45.4.157.000 - Hewlett-Packard) Hidden
PC-Doctor for Windows (HKLM\...\InstallShield_{0C66761E-497A-4BE3-AE0D-8EC30FC9A9AA}) (Version: 1.06.002 - PC-Doctor, Inc.)
PC-Doctor for Windows (Version: 1.06.002 - PC-Doctor, Inc.) Hidden
PhotoGallery (Version: 45.4.157.000 - Hewlett-Packard) Hidden
PlayMemories Home (HKLM\...\{0657DE52-8F5C-4073-B70C-ED4F3F7FA076}) (Version: 7.0.03.04240 - Sony Corporation)
Polar Bowler from Compaq (remove only) (HKLM\...\05E21449-3BA3-42BF-BBDA-95205F4EA40A) (Version: - )
Polar Golfer from Compaq (remove only) (HKLM\...\3330A279-CC39-4A17-AE19-DA464B26AD9A) (Version: - )
ProductContext (Version: 47.0.1.000 - Hewlett-Packard) Hidden
PS2 (HKLM\...\PS2) (Version: - )
Python 2.2 pywin32 extensions (build 203) (HKLM\...\pywin32-py2.2) (Version: - )
Python 2.2.3 (HKLM\...\Python 2.2.3) (Version: 2.2.3 - PythonLabs at Zope Corporation)
QFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
QuickTime (HKLM\...\QuickTime) (Version: - )
Readme (Version: 47.0.1.000 - Hewlett-Packard) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\...\RealPlayer 15.0) (Version: - RealNetworks)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Road Ready Streetwise from Compaq (remove only) (HKLM\...\A2E85A38-C2D9-4EDF-AFDA-F76BCBFEBBC4) (Version: - )
Scan (Version: 4.5.0.0 - Hewlett-Packard) Hidden
ScannerCopy (Version: 4.5.0.0 - Hewlett-Packard) Hidden
SereneScreen Marine Aquarium Lite (HKLM\...\SereneScreen Marine Aquarium Lite_is1) (Version: 3.0 - Prolific Publishing, Inc.) <==== ATTENTION
Shrek 2 Ogre Bowler from Compaq (remove only) (HKLM\...\BBCBAA5D-AC5A-4098-A53E-EC60A68F38F9) (Version: - )
SiS VGA Utilities (HKLM\...\SiS VGA Driver) (Version: - )
SkinsHP1 (Version: 45.4.157.000 - Hewlett-Packard) Hidden
SlimCleaner Plus (HKLM\...\{1451E1D4-6AFA-44C9-B43D-B25247321205}) (Version: 1.0.22723 - SlimWare Utilities, Inc.)
Sonic Express Labeler (HKLM\...\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 1.0.0 - Sonic Solutions)
Sonic RecordNow! (HKLM\...\{9541FED0-327F-4DF0-8B96-EF57EF622F19}) (Version: 7.22 - Hewlett-Packard)
SpySubtract (HKLM\...\SpySubtract) (Version: - interMute, Inc.)
Super Granny from Compaq (remove only) (HKLM\...\DE87FA96-7840-420C-86F9-33F3B7B3CED1) (Version: - )
Tradewinds from Compaq (remove only) (HKLM\...\66195170-D19D-46C5-8FB7-8A4630071ADC) (Version: - )
TrayApp (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Unload (Version: 4.5.0 - Hewlett-Packard) Hidden
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
WebReg (Version: 45.4.157.000 - Hewlett-Packard) Hidden
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version: - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - )
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version: - )
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
Yahoo! Software Update (HKLM\...\Yahoo! Software Update) (Version: - )
Yahoo! Toolbar (HKLM\...\Yahoo! Companion) (Version: - Yahoo! Inc.)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3036499068-691177906-837026766-1009_Classes\CLSID\{26842a09-ffa8-4e2c-ae12-0c80f01c3295}\InprocServer32 -> C:\Program Files\MapsGalaxy_39\bar\1.bin\39SrcAs.dll (Mindspark)
CustomCLSID: HKU\S-1-5-21-3036499068-691177906-837026766-1009_Classes\CLSID\{6d010537-9e99-400b-b652-b0d5a5757e5d}\InprocServer32 -> C:\Program Files\OnlineMapFinder_9p\bar\1.bin\9pSrcAs.dll (Mindspark)
==================== Restore Points =========================
12-02-2015 20:02:28 Software Distribution Service 3.0
16-02-2015 20:43:37 Software Distribution Service 3.0
19-02-2015 19:44:55 Software Distribution Service 3.0
20-02-2015 21:54:17 Software Distribution Service 3.0
21-02-2015 11:30:19 Software Distribution Service 3.0
22-02-2015 10:42:31 Software Distribution Service 3.0
23-02-2015 16:41:28 Software Distribution Service 3.0
23-02-2015 20:29:15 Software Distribution Service 3.0
24-02-2015 10:49:42 Software Distribution Service 3.0
24-02-2015 14:46:03 Software Distribution Service 3.0
24-02-2015 18:31:22 Software Distribution Service 3.0
27-02-2015 11:17:56 Software Distribution Service 3.0
01-03-2015 17:18:23 Software Distribution Service 3.0
02-03-2015 20:22:16 Software Distribution Service 3.0
03-03-2015 17:57:22 Software Distribution Service 3.0
05-03-2015 21:08:56 Software Distribution Service 3.0
06-03-2015 17:10:59 Software Distribution Service 3.0
06-03-2015 20:19:54 Software Distribution Service 3.0
08-03-2015 09:41:19 Software Distribution Service 3.0
08-03-2015 09:56:20 Software Distribution Service 3.0
08-03-2015 12:59:35 Software Distribution Service 3.0
08-03-2015 19:14:07 Software Distribution Service 3.0
08-03-2015 20:56:46 Software Distribution Service 3.0
11-03-2015 16:59:15 Software Distribution Service 3.0
15-03-2015 19:32:27 Software Distribution Service 3.0
16-03-2015 12:59:43 Software Distribution Service 3.0
16-03-2015 13:21:51 Software Distribution Service 3.0
16-03-2015 20:11:52 Software Distribution Service 3.0
17-03-2015 18:42:02 Software Distribution Service 3.0
18-03-2015 18:34:57 Software Distribution Service 3.0
23-03-2015 17:15:02 Software Distribution Service 3.0
24-03-2015 10:23:26 Software Distribution Service 3.0
24-03-2015 20:03:23 Software Distribution Service 3.0
02-04-2015 17:45:50 Software Distribution Service 3.0
03-04-2015 10:48:23 Software Distribution Service 3.0
06-04-2015 16:35:03 System Checkpoint
06-04-2015 16:58:15 Software Distribution Service 3.0
06-04-2015 19:41:21 Software Distribution Service 3.0
07-04-2015 17:48:14 Software Distribution Service 3.0
16-04-2015 16:45:57 System Checkpoint
16-04-2015 17:15:43 Software Distribution Service 3.0
21-04-2015 17:31:30 Software Distribution Service 3.0
21-04-2015 21:15:17 Software Distribution Service 3.0
22-04-2015 18:19:07 Software Distribution Service 3.0
23-04-2015 18:48:30 Software Distribution Service 3.0
28-04-2015 12:13:20 Software Distribution Service 3.0
28-04-2015 18:33:14 Software Distribution Service 3.0
07-05-2015 10:58:24 Software Distribution Service 3.0
08-05-2015 13:44:16 System Checkpoint
08-05-2015 16:05:11 Software Distribution Service 3.0
10-05-2015 11:45:59 System Checkpoint
10-05-2015 12:04:15 Software Distribution Service 3.0
10-05-2015 13:50:13 Software Distribution Service 3.0
10-05-2015 16:19:22 Software Distribution Service 3.0
10-05-2015 18:21:51 Software Distribution Service 3.0
14-05-2015 16:37:07 Software Distribution Service 3.0
14-05-2015 18:08:07 Software Distribution Service 3.0
17-05-2015 17:53:10 Software Distribution Service 3.0
18-05-2015 17:53:30 Software Distribution Service 3.0
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2004-08-04 18:00 - 2004-08-04 18:00 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\Final Media Player Update Checker.job => C:\Program Files\FinalMediaPlayer\FMPCheckForUpdates.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cc443f6f4a153a.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cfeed4da8d847e.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cfff9bab2ab3f0.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0427ffd7a7e0c.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cc443f6fa710f0.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-3036499068-691177906-837026766-1009.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-3036499068-691177906-837026766-1009.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\ReclaimerResumeInstall_Compaq_Owner.job => C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Application Data\Real\Update\UpgradeHelper\RealPlayer\11.02\agent\rnupgagent.exe
Task: C:\WINDOWS\Tasks\SlimCleaner Plus (Scheduled Scan - Compaq_Owner).job => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe
==================== Loaded Modules (Whitelisted) ==============
2004-08-04 11:00 - 2008-04-13 17:11 - 00059904 _____ () C:\WINDOWS\system32\devenum.dll
2004-08-04 11:00 - 2008-04-13 17:11 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll
2013-04-24 05:31 - 2013-04-24 05:31 - 00149528 _____ () C:\Program Files\Sony\PlayMemories Home\dfs.exe
2014-08-04 14:19 - 2014-08-04 14:19 - 00671040 _____ () C:\Program Files\SlimCleaner Plus\MyDefragDll.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3036499068-691177906-837026766-1009\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Compaq_Owner.YOUR-4F1261A8E5\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: 75.75.75.75 - 75.75.76.76
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk => C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk => C:\WINDOWS\pss\Compaq Connections.lnkCommon Startup
MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk => C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk => C:\WINDOWS\pss\SpySubtract.lnkCommon Startup
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
DomainProfile\AuthorizedApplications: [%ProgramFiles%\iTunes\iTunes.exe] => enabled:iTunes
StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes
StandardProfile\AuthorizedApplications: [C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe] => Enabled:BackWeb for Presario
StandardProfile\AuthorizedApplications: [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe] => Enabled:Earthlink
StandardProfile\AuthorizedApplications: [C:\Program Files\Messenger\msmsgs.exe] => Enabled:Windows Messenger
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:Google Chrome
StandardProfile\AuthorizedApplications: [C:\Program Files\AVG\AVG2014\avgmfapx.exe] => Enabled:AVG Installer
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/16/2015 04:19:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (03/01/2015 05:14:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.23588, fault address 0x00231ccc.
Processing media-specific event for [iexplore.exe!ws!]
Error: (02/22/2015 04:29:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application svchost.exe, version 5.1.2600.5512, faulting module msi.dll, version 3.1.4001.5512, fault address 0x000ffbde.
Processing media-specific event for [svchost.exe!ws!]
Error: (02/21/2015 11:29:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (02/21/2015 11:29:13 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module flash32_16_0_0_305.ocx, version 16.0.0.305, fault address 0x000e7be9.
Processing media-specific event for [iexplore.exe!ws!]
Error: (02/20/2015 09:53:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (02/20/2015 09:52:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module unknown, version 0.0.0.0, fault address 0x1715d6d1.
Processing media-specific event for [iexplore.exe!ws!]
Error: (01/18/2015 11:33:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (01/18/2015 11:33:48 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (01/18/2015 11:33:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module flash32_16_0_0_257.ocx, version 16.0.0.257, fault address 0x005eec59.
Processing media-specific event for [iexplore.exe!ws!]
System errors:
=============
Error: (05/18/2015 05:54:19 PM) (Source: Windows Update Agent) (EventID: 20) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070008: Security Update for Windows XP (KB978542).
Error: (05/18/2015 05:54:17 PM) (Source: NtServicePack) (EventID: 4373) (User: NT AUTHORITY)
Description: Windows XP KB978542 installation failed.
Not enough storage is available to process this command.
Error: (05/17/2015 05:53:55 PM) (Source: Windows Update Agent) (EventID: 20) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070008: Security Update for Windows XP (KB978542).
Error: (05/17/2015 05:53:53 PM) (Source: NtServicePack) (EventID: 4373) (User: NT AUTHORITY)
Description: Windows XP KB978542 installation failed.
Not enough storage is available to process this command.
Error: (05/14/2015 06:08:56 PM) (Source: Windows Update Agent) (EventID: 20) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070008: Security Update for Windows XP (KB978542).
Error: (05/14/2015 06:08:54 PM) (Source: NtServicePack) (EventID: 4373) (User: NT AUTHORITY)
Description: Windows XP KB978542 installation failed.
Not enough storage is available to process this command.
Error: (05/14/2015 05:45:22 PM) (Source: W32Time) (EventID: 29) (User: )
Description: The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 14 minutes.
NtpClient has no source of accurate time.
Error: (05/14/2015 05:45:22 PM) (Source: W32Time) (EventID: 17) (User: )
Description: Time Provider NtpClient: An error occurred during DNS lookup of the manually
configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15
minutes.
The error was: A socket operation was attempted to an unreachable host. (0x80072751)
Error: (05/14/2015 05:45:22 PM) (Source: W32Time) (EventID: 29) (User: )
Description: The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 14 minutes.
NtpClient has no source of accurate time.
Error: (05/14/2015 05:45:22 PM) (Source: W32Time) (EventID: 17) (User: )
Description: Time Provider NtpClient: An error occurred during DNS lookup of the manually
configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15
minutes.
The error was: A socket operation was attempted to an unreachable host. (0x80072751)
Microsoft Office Sessions:
=========================
Error: (04/16/2015 04:19:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000
Error: (03/01/2015 05:14:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe8.0.6001.18702mshtml.dll8.0.6001.2358800231ccc
Error: (02/22/2015 04:29:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe5.1.2600.5512msi.dll3.1.4001.5512000ffbde
Error: (02/21/2015 11:29:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000
Error: (02/21/2015 11:29:13 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe8.0.6001.18702flash32_16_0_0_305.ocx16.0.0.305000e7be9
Error: (02/20/2015 09:53:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000
Error: (02/20/2015 09:52:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe8.0.6001.18702unknown0.0.0.01715d6d1
Error: (01/18/2015 11:33:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000
Error: (01/18/2015 11:33:48 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000
Error: (01/18/2015 11:33:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe8.0.6001.18702flash32_16_0_0_257.ocx16.0.0.257005eec59
==================== Memory info ===========================
Processor: AMD Athlon 64 Processor 3300+
Percentage of memory in use: 46%
Total physical RAM: 1983.48 MB
Available physical RAM: 1063 MB
Total Pagefile: 2502.92 MB
Available Pagefile: 1721.3 MB
Total Virtual: 2047.88 MB
Available Virtual: 1926.64 MB
==================== Drives ================================
Drive c: (PRESARIO) (Fixed) (Total:143.79 GB) (Free:77.61 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: (PRESARIO_RP) (Fixed) (Total:5.25 GB) (Free:0.55 GB) FAT32 ==>[Drive with boot components (Windows XP)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 149.1 GB) (Disk ID: 6B1E6B1E)
Partition 1: (Not Active) - (Size=5.3 GB) - (Type=0C)
Partition 2: (Active) - (Size=143.8 GB) - (Type=07 NTFS)
==================== End Of Log ============================