Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Virus Infection - Programmes Disabled


  • Please log in to reply

#1
elielieli

elielieli

    Member

  • Member
  • PipPipPip
  • 174 posts

hi folks

opened up my computer this morning and found that all the programs were missing.

to begin with they're all listed , but when you drag the cursor onto them it says they're empty.

then everything on the list disappears and so does everything on the desktop.

everything resumes on start up , only to be repeated.

basically , nothing works.

prior to this problem i'd 'd downloaded some programme called Free Ram xp Pro ,  via the cnet website. 

this seemed to do nothing , but i did notice a green rectangular icon on the task bar that wasn't there before.

i removed it via 'add/remove programmes' in control panel. 

it wasn't until restart that the problem manifested.

I've run malwarebytes and spybot in safe mode , with no positive results.

 

OS is XP 

Asus laptop.

 

Please help!

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:18-11-2015
Ran by Asus (administrator) on ASUS-LAPTOP (19-11-2015 12:10:04)
Running from C:\Documents and Settings\Asus\Desktop
Loaded Profiles: Asus (Available Profiles: Asus)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 6 (Default browser: IE)
Boot Mode: Safe Mode (minimal)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [ehTray] => C:\WINDOWS\ehome\ehtray.exe [59392 2004-08-10] (Microsoft Corporation)
HKLM\...\Run: [VersatoMs] => C:\Program Files\MagicMus\MulMouse.exe [282624 2004-06-17] ()
HKLM\...\Run: [SMSERIAL] => C:\WINDOWS\sm56hlpr.exe [544768 2006-01-20] (Motorola Inc.)
HKLM\...\Run: [IntelZeroConfig] => C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe [1400832 2011-01-12] (Intel® Corporation)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1210640 2011-01-12] (Intel® Corporation)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1045720 2015-09-14] (Adobe Systems Incorporated)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [761945 2005-10-21] (Synaptics, Inc.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [15961088 2006-01-11] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [igfxhkcmd] => C:\WINDOWS\system32\hkcmd.exe [77824 2006-02-07] (Intel Corporation)
HKLM\...\Run: [igfxpers] => C:\WINDOWS\system32\igfxpers.exe [118784 2006-02-07] (Intel Corporation)
HKLM\...\Run: [DHAgent] => C:\Program Files\DriverHound\DHAgent.exe
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-07] (AVAST Software)
HKU\S-1-5-21-746137067-2052111302-725345543-1003\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-746137067-2052111302-725345543-1003\...\Run: [AmazonMP3DownloaderHelper] => C:\Documents and Settings\Asus\Local Settings\Application Data\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
HKU\S-1-5-21-746137067-2052111302-725345543-1003\...\Run: [fastclean] => "C:\Program Files\FastClean PRO\fastcleanpro.exe"
HKU\S-1-5-21-746137067-2052111302-725345543-1003\...\Run: [OutfoxTV] => C:\Program Files\OutfoxTV\OutfoxTV\DesktopContainer.exe
HKU\S-1-5-21-746137067-2052111302-725345543-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [9216 2008-04-14] (Microsoft Corporation)
AppInit_DLLs: c:\progra~1\settin~1\systemk\syskldr.dll => No File
IFEO\rjatydimofu.exe: [Debugger] tasklist.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-10-15] (AVAST Software)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk [2014-12-15]
ShortcutTarget: CodecPackUpdateChecker.lnk -> C:\WINDOWS\system32\C2MP\UpdateChecker.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\..\Interfaces\{B65CBEE6-C44B-4AFC-BAA5-B7F2838A178D}: [DhcpNameServer] 192.168.11.1
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-746137067-2052111302-725345543-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-746137067-2052111302-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-746137067-2052111302-725345543-1003\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = www.google.com
www.google.com
URLSearchHook: HKU\S-1-5-21-746137067-2052111302-725345543-1003 - Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "www.google.com" <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = 
SearchScopes: HKLM -> {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = 
SearchScopes: HKU\S-1-5-21-746137067-2052111302-725345543-1003 -> DefaultScope {97BB2AF9-26DA-42C4-8077-CEBFDB665771} URL = 
SearchScopes: HKU\S-1-5-21-746137067-2052111302-725345543-1003 -> {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = 
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2012-10-09] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-30] (AVAST Software)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-10-09] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-746137067-2052111302-725345543-1003 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
 
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default
FF DefaultSearchEngine: Yahoo!
FF SearchEngineOrder.1: default-search.net
FF SelectedSearchEngine: Yahoo!
FF Homepage: about:home
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-22] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [No File]
FF Plugin: @java.com/DTPlugin,version=10.7.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2012-10-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2012-10-09] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll [No File]
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll [No File]
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF user.js: detected! => C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\user.js [2014-11-17]
FF SearchPlugin: C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\searchplugins\firefox-add-ons.xml [2013-09-23]
FF SearchPlugin: C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\searchplugins\startpage-https.xml [2015-11-18]
FF SearchPlugin: C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\searchplugins\youtube-video-search.xml [2014-08-08]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-11-04] [not signed]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-11-04] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-02-17] [not signed]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-10-15] [not signed]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2014-05-25]
 
Chrome: 
=======
CHR Profile: C:\Documents and Settings\Asus\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-06-04]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-06-04]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-15] (AVAST Software)
S2 ehRecvr; C:\WINDOWS\eHome\ehRecvr.exe [194560 2004-08-10] (Microsoft Corporation) [File not signed]
S2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [161768 2012-10-09] (Oracle Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 MHN; C:\WINDOWS\System32\mhn.dll [85504 2004-08-10] (Microsoft Corporation) [File not signed]
S2 Mobile Broadband HL Service; C:\Documents and Settings\All Users\Application Data\MobileBrServ\mbbservice.exe [232288 2012-03-12] ()
S2 S24EventMonitor; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [966656 2011-01-12] (Intel® Corporation) [File not signed]
S2 Skype C2C Service; C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S3 UMWdf; C:\WINDOWS\system32\wdfmgr.exe [38912 2006-03-15] (Microsoft Corporation) [File not signed]
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 OutfoxTvService; C:\Program Files\OutfoxTV\OutfoxTvService.exe [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-10-15] (AVAST Software)
S2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [76000 2015-10-15] (AVAST Software)
S1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-10-15] (AVAST Software)
S0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-10-15] (AVAST Software)
S1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [794952 2015-11-07] (AVAST Software)
S1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [435464 2015-11-07] (AVAST Software)
S3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [157888 2015-10-15] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-10-15] (AVAST Software)
S0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208664 2015-10-15] (AVAST Software)
S3 DUBE100B; C:\WINDOWS\System32\DRIVERS\DUBE100B.sys [18560 2006-05-26] (D-Link Corporation)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MHNDRV; C:\WINDOWS\System32\DRIVERS\mhndrv.sys [11008 2004-08-10] (Microsoft Corporation) [File not signed]
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ATKACPI.sys [5760 2007-08-28] ()
S2 MUsbFltr; C:\WINDOWS\System32\DRIVERS\MUsbFltr.sys [6528 2004-03-22] (Waytech Development, Inc.)
S3 NETwLx32; C:\WINDOWS\System32\DRIVERS\NETwLx32.sys [6609920 2010-10-07] (Intel Corporation)
S3 RTL8023xp; C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys [74496 2005-03-04] (Realtek Semiconductor Corporation                           )
S2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [13952 2010-05-19] (Intel Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S4 IntelIde; no ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
NETSVC: MHN -> C:\Windows\System32\mhn.dll (Microsoft Corporation)
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-11-19 12:10 - 2015-11-19 12:11 - 00015194 _____ C:\Documents and Settings\Asus\Desktop\FRST.txt
2015-11-19 12:07 - 2015-11-19 12:10 - 00000000 ____D C:\FRST
2015-11-19 12:07 - 2015-11-19 11:55 - 01378816 _____ (Farbar) C:\Documents and Settings\Asus\Desktop\FRST.exe
2015-11-19 01:42 - 2015-11-19 01:42 - 00000780 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-18 10:55 - 2015-11-18 10:59 - 117766424 _____ (Apple Inc.) C:\Documents and Settings\Asus\Desktop\iTunesSetup.exe
2015-11-18 10:42 - 2015-11-18 10:42 - 00000000 ___HD C:\WINDOWS\system32\Settings
2015-11-17 20:41 - 2015-11-17 22:19 - 00000000 ____D C:\Documents and Settings\Asus\Local Settings\Application Data\MalwareProtectionLive
2015-11-09 17:52 - 2015-11-09 17:52 - 00000000 ____D C:\Documents and Settings\Asus\Desktop\Walker Brothers - Make It Easy On Yourself
2015-11-09 17:35 - 2015-11-09 17:38 - 00000000 ____D C:\Documents and Settings\Asus\Desktop\2010 - Original Album Classics
2015-11-09 17:22 - 2015-11-09 19:35 - 00000000 ____D C:\Documents and Settings\Asus\Desktop\1966 - Portrait (Remastered 1998)
2015-11-05 18:44 - 2015-11-05 18:45 - 00000000 ____D C:\Documents and Settings\Asus\Desktop\Take it Easy With The Walker Brothers
2015-11-04 19:07 - 2015-11-04 19:55 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-10-26 17:00 - 2015-10-26 17:00 - 00000276 _____ C:\WINDOWS\Tasks\switchShakeIcon.job
2015-10-24 11:40 - 2011-01-24 01:24 - 00000000 ____D C:\Documents and Settings\Asus\Desktop\Tangerine Dream - Mystery Tracks (bootleg)
2015-10-23 11:07 - 2015-10-23 11:12 - 00000000 ____D C:\Program Files\Acro Software
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-11-19 12:11 - 2012-07-21 11:21 - 00000000 ____D C:\Documents and Settings\Asus\Local Settings\temp
2015-11-19 01:48 - 2012-05-25 14:42 - 00000178 ___SH C:\Documents and Settings\Asus\ntuser.ini
2015-11-19 01:48 - 2012-05-25 14:34 - 01732014 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-19 01:43 - 2014-10-28 19:41 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-19 01:42 - 2014-10-28 19:41 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-19 01:42 - 2014-10-28 19:40 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-11-18 23:39 - 2012-05-25 14:40 - 00032638 _____ C:\WINDOWS\SchedLgU.Txt
2015-11-18 23:39 - 2012-05-25 14:40 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-18 23:37 - 2014-12-15 13:04 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2015-11-18 23:32 - 2014-03-30 11:46 - 00000276 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-746137067-2052111302-725345543-1003.job
2015-11-18 23:32 - 2014-03-10 11:18 - 00000220 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-11-18 23:32 - 2013-04-13 21:59 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-18 23:32 - 2012-05-25 16:17 - 00000000 ____D C:\WINDOWS\system32\Lang
2015-11-18 19:03 - 2012-05-25 14:30 - 00000000 ____D C:\WINDOWS\Registration
2015-11-18 18:30 - 2013-04-13 21:59 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-18 18:27 - 2014-03-30 15:11 - 117518336 _____ C:\WINDOWS\MEMORY.DMP
2015-11-18 15:13 - 2013-02-11 14:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2015-11-18 14:28 - 2012-06-01 07:36 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2015-11-18 10:55 - 2012-05-25 14:42 - 00000000 ____D C:\Documents and Settings\Asus
2015-11-18 01:16 - 2014-02-20 12:50 - 00000000 ____D C:\Documents and Settings\Asus\Application Data\vlc
2015-11-18 01:13 - 2013-01-25 00:25 - 00000000 ____D C:\Documents and Settings\Asus\Application Data\Audacity
2015-11-18 01:12 - 2015-10-08 01:47 - 00000000 ____D C:\Program Files\Audacity
2015-11-16 10:44 - 2006-03-15 12:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2015-11-15 23:17 - 2012-05-28 22:31 - 00000000 ____D C:\Documents and Settings\Asus\Application Data\Media Player Classic
2015-11-15 12:51 - 2014-03-30 11:46 - 00000284 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-746137067-2052111302-725345543-1003.job
2015-11-12 20:24 - 2014-12-17 20:24 - 00000656 _____ C:\WINDOWS\Tasks\klcp_update.job
2015-11-09 14:50 - 2015-06-11 12:35 - 00000456 _____ C:\Documents and Settings\Asus\Desktop\jsa.txt
2015-11-08 15:00 - 2014-03-10 11:18 - 00000214 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2015-11-07 21:46 - 2014-12-15 13:03 - 00794952 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2015-11-07 21:46 - 2014-12-15 13:03 - 00435464 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2015-11-05 13:12 - 2012-05-28 16:13 - 00000000 ____D C:\Documents and Settings\Asus\Application Data\Azureus
2015-11-05 12:54 - 2012-07-20 11:44 - 00000754 ____C C:\WINDOWS\WORDPAD.INI
2015-11-05 10:57 - 2012-05-26 10:43 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-10-25 09:16 - 2012-05-25 15:21 - 00559976 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-24 18:22 - 2014-04-01 20:34 - 00000000 ____D C:\Program Files\Vuze
2015-10-23 10:56 - 2012-05-25 15:05 - 00000000 ___SD C:\Documents and Settings\Asus\UserData
2015-10-20 11:28 - 2012-05-26 10:16 - 00000000 ____D C:\Documents and Settings\Asus\My Documents\Life
 
==================== Files in the root of some directories =======
 
2013-06-28 21:24 - 2013-06-28 21:24 - 0000046 ____C () C:\Documents and Settings\Asus\Application Data\Camdata.ini
2013-06-28 21:24 - 2013-06-28 21:24 - 0000408 ____C () C:\Documents and Settings\Asus\Application Data\CamLayout.ini
2013-06-28 21:24 - 2013-06-28 21:24 - 0000408 ____C () C:\Documents and Settings\Asus\Application Data\CamShapes.ini
2013-06-28 21:17 - 2013-06-28 21:24 - 0004511 ____C () C:\Documents and Settings\Asus\Application Data\CamStudio.cfg
2012-08-27 18:19 - 2012-08-27 18:19 - 0027520 ____C () C:\Documents and Settings\Asus\Local Settings\Application Data\dt.dat
2012-07-20 00:15 - 2012-07-20 00:15 - 0000000 ____C () C:\Documents and Settings\Asus\Local Settings\Application Data\egwkduhn.log
2012-07-20 11:40 - 2012-07-21 11:05 - 0000000 ____C () C:\Documents and Settings\Asus\Local Settings\Application Data\gudearyg.log
2012-07-20 00:08 - 2012-07-21 11:05 - 0000024 ____C () C:\Documents and Settings\Asus\Local Settings\Application Data\idtioubt.log
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
==================== End of FRST.txt ============================
 
 
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version:18-11-2015
Ran by Asus (2015-11-19 12:11:51)
Running from C:\Documents and Settings\Asus\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) (2012-05-25 14:39:24)
Boot Mode: Safe Mode (minimal)
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-746137067-2052111302-725345543-500 - Administrator - Enabled)
Asus (S-1-5-21-746137067-2052111302-725345543-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Asus
Guest (S-1-5-21-746137067-2052111302-725345543-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-746137067-2052111302-725345543-1000 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-746137067-2052111302-725345543-1002 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: PC Cleaner Pro (Disabled - Up to date) {737A8864-C2D9-4337-B49A-B5E35815B9BB}
AV: AVG Internet Security 2012 (Enabled - Up to date) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: avast! Antivirus (Enabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Internet Security 2012 (Disabled) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.22beta (HKLM\...\7-Zip) (Version:  - )
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.223 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Advertising Center (Version: 0.0.0.1 - Nero AG) Hidden
Apple Application Support (HKLM\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audacity 2.1.1 (HKLM\...\Audacity®_is1) (Version: 2.1.1 - Audacity Team)
Avast Free Antivirus (HKLM\...\Avast) (Version: 10.4.2233 - AVAST Software)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 3.19 - Piriform)
Google Earth Plug-in (HKLM\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Intel® Graphics Media Accelerator Driver (HKLM\...\{8A708DD8-A5E6-11D4-A706-000629E95E20}) (Version: 6.14.10.4497 - )
Intel® PROSet/Wireless WiFi Software (HKLM\...\{0E95DA08-2514-4399-AD87-349C350FA9DE}) (Version: 13.05.0000 - Intel Corporation)
iTunes (HKLM\...\{0718A90E-93AA-49AF-A4FE-0165ACD91DF0}) (Version: 11.2.2.3 - Apple Inc.)
Java 7 Update 7 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217007FF}) (Version: 7.0.70 - Oracle)
JavaFX 2.1.0 (HKLM\...\{1111706F-666A-4037-7777-210328764D10}) (Version: 2.1.0 - Oracle Corporation)
K-Lite Codec Pack 10.9.0 Full (HKLM\...\KLiteCodecPack_is1) (Version: 10.9.0 - )
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 1.0 Hotfix (KB2604042) (HKLM\...\KB2604042) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB2656378) (HKLM\...\KB2656378) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB979904) (HKLM\...\KB979904) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2698035) (HKLM\...\KB2698035) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2742607) (HKLM\...\KB2742607) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2833951) (HKLM\...\KB2833951) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2904878) (HKLM\...\KB2904878) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mobile Broadband HL Service (HKLM\...\Mobile Broadband HL Service) (Version: 22.001.14.01.105 - Huawei Technologies Co.,Ltd)
Motorola SM56 Data Fax Modem (HKLM\...\SMSERIAL) (Version:  - )
Mozilla Firefox 42.0 (x86 en-US) (HKLM\...\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 9 Essentials (HKLM\...\{289bbce1-edf3-4639-8979-52ba09724f8c}) (Version:  - Nero AG)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
QuickTime (HKLM\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
REALTEK Gigabit and Fast Ethernet NIC Driver (HKLM\...\{94FB906A-CF42-4128-A509-D353026A607E}) (Version: 1.70 - REALTEK Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 2.03 - Realtek Semiconductor Corp.)
RICOH Media Driver ver.2.10.01.01 (HKLM\...\{2B818257-E6C7-4841-8C29-C5C9A982BCE5}) (Version: 2.10.01.01 - RICOH)
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Switch Sound File Converter (HKLM\...\Switch) (Version:  - NCH Software)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 8.2.0.0 - Synaptics)
ViewMate Desktop Mouse CC2201 Uninstaller (HKLM\...\VersatoMs) (Version:  - )
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Vuze (HKLM\...\8461-7759-5462-8226) (Version: 5.3.0.0 - Azureus Software, Inc.)
Vuze Remote Toolbar v8.9 (HKLM\...\{E2BDB56B-464B-49D7-AF12-B34C5E2E284B}) (Version: 8.9 - Spigot, Inc.) <==== ATTENTION
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version:  - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB973768 (HKLM\...\KB973768) (Version:  - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-746137067-2052111302-725345543-1003_Classes\CLSID\{25FB7F49-2278-442E-9482-D1B54E88DA13}\InprocServer32 -> C:\Documents and Settings\All Users\Application Data\{1171BAF0-C6D4-4415-9FE3-88D9119F2F37}\amstream (the data entry has 15 more characters).
 
==================== Restore Points =========================
 
18-11-2015 10:42:14 Software Distribution Service 3.0
18-11-2015 11:26:32 System Checkpoint
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-03-15 12:00 - 2012-07-21 11:15 - 00000027 ____N C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\klcp_update.job => JL pF CMD /C sc create KLCPU binPath CMD /V /C SET \FILE \ ProgramFiles \ Lite Codec Pack Tools CodecTweakTool exe\\ IF EXIST FILE START \CTT\ FILE /verysilent /update /freq 30 type own type interact net start KLCPU sc delete KLCPU CMD Asus
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-746137067-2052111302-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-746137067-2052111302-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\SwitchDowngrade.job => C:\Program Files\NCH Software\Switch\switch.exe
Task: C:\WINDOWS\Tasks\SwitchReminder.job => C:\Program Files\NCH Software\Switch\switch.exe
Task: C:\WINDOWS\Tasks\switchShakeIcon.job => C:\Program Files\NCH Swift Sound\Switch\switch.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="1"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-746137067-2052111302-725345543-1003\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Asus\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
DNS Servers: Media is not connected to internet.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service
StandardProfile\AuthorizedApplications: [C:\Program Files\AVG\AVG2012\avgmfapx.exe] => Enabled:AVG Installer
StandardProfile\AuthorizedApplications: [C:\Program Files\Skype\Phone\Skype.exe] => Enabled:Skype
StandardProfile\AuthorizedApplications: [C:\Program Files\Vuze\Azureus.exe] => Enabled:Vuze Launcher
StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:'Firefox' (C:\Program Files\Mozilla Firefox)
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Asus\Desktop\framxpro-66323830.exe] => Enabled:proinstaller
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/18/2015 11:35:26 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: Recording Disk Monitor failure.
 
Error: (11/18/2015 11:35:26 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: There are zero configured tuners on this machine, scheduling should not occur in this state!!!
 
Error: (11/18/2015 11:35:24 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: Failed to build recording file list for folder.
 
Error: (11/18/2015 11:32:49 PM) (Source: Userenv) (EventID: 1041) (User: NT AUTHORITY)
Description: Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration.
 
Error: (11/18/2015 11:32:49 PM) (Source: Userenv) (EventID: 1041) (User: NT AUTHORITY)
Description: Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration.
 
Error: (11/18/2015 11:32:49 PM) (Source: Userenv) (EventID: 1041) (User: NT AUTHORITY)
Description: Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration.
 
Error: (11/18/2015 11:32:49 PM) (Source: Userenv) (EventID: 1041) (User: NT AUTHORITY)
Description: Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration.
 
Error: (11/18/2015 07:03:28 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: Flush: RecordingFile failed to write Invalid XML Operation.
 
Error: (11/18/2015 07:03:28 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: RecordingHash in file differs from actual file.
 
Error: (11/18/2015 07:03:22 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: Failed to build recording file list for folder.
 
 
System errors:
=============
Error: (11/19/2015 00:07:12 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
 
Error: (11/19/2015 00:07:11 PM) (Source: DCOM) (EventID: 10005) (User: ASUS-LAPTOP)
Description: DCOM got error "%%1084" attempting to start the service netman with arguments ""
in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
 
Error: (11/19/2015 00:07:05 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
AFD
aswRdr
aswRvrt
aswSnx
aswSP
aswVmm
Fips
intelppm
IPSec
MRxSmb
NetBIOS
NetBT
RasAcd
Rdbss
Tcpip
WS2IFSL
 
Error: (11/19/2015 00:07:05 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: 
%%31
 
Error: (11/19/2015 00:07:05 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: 
%%31
 
Error: (11/19/2015 00:07:05 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: 
%%31
 
Error: (11/19/2015 00:07:05 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: 
%%31
 
Error: (11/19/2015 00:07:05 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: 
%%31
 
Error: (11/19/2015 00:07:05 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: 
%%31
 
Error: (11/19/2015 01:48:12 AM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
 
 
==================== Memory info =========================== 
 
Processor: Genuine Intel® CPU T2050 @ 1.60GHz
Percentage of memory in use: 22%
Total physical RAM: 1015.36 MB
Available physical RAM: 785.36 MB
Total Virtual: 2444.53 MB
Available Virtual: 2355.74 MB
 
==================== Drives ================================
 
Drive c: (HDD) (Fixed) (Total:44.77 GB) (Free:0.95 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: (DATA) (Fixed) (Total:29.76 GB) (Free:28.57 GB) NTFS
Drive h: () (Fixed) (Total:74.51 GB) (Free:4.73 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: C455FAB8)
Partition 1: (Active) - (Size=44.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=29.8 GB) - (Type=OF Extended)
 
========================================================
Disk: 1 (Size: 74.5 GB) (Disk ID: 017832F0)
Partition 1: (Not Active) - (Size=74.5 GB) - (Type=0B)
 
==================== End of Addition.txt ============================

Edited by elielieli, 19 November 2015 - 06:48 AM.

  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,012 posts
  • MVP
Download the attached fixlist.txt to the same location as FRST
Run FRST and press Fix
A fix log will be generated please post that.  
 
 
Run FRST again, check the Addition.txt box and the Shortcut.txt box.and then Scan.  You will get 3 logs.  Post all 3

  • 0

#3
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

Hi Rkinner

thanks for your assistance.

here it is.

 

Fix Log:

Fix result of Farbar Recovery Scan Tool (x86) Version:18-11-2015
Ran by Asus (2015-11-21 14:23:37) Run:1
Running from C:\Documents and Settings\Asus\Desktop
Loaded Profiles: Asus (Available Profiles: Asus)
Boot Mode: Safe Mode (minimal)
 
==============================================
 
fixlist content:
*****************
HKU\S-1-5-21-746137067-2052111302-725345543-1003\...\Run: [fastclean] => "C:\Program Files\FastClean PRO\fastcleanpro.exe"
AppInit_DLLs: c:\progra~1\settin~1\systemk\syskldr.dll => No File
IFEO\rjatydimofu.exe: [Debugger] tasklist.exe
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-746137067-2052111302-725345543-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "www.google.com" <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = 
SearchScopes: HKLM -> {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = 
SearchScopes: HKU\S-1-5-21-746137067-2052111302-725345543-1003 -> DefaultScope {97BB2AF9-26DA-42C4-8077-CEBFDB665771} URL = 
SearchScopes: HKU\S-1-5-21-746137067-2052111302-725345543-1003 -> {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = 
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2012-10-09] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-10-09] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-746137067-2052111302-725345543-1003 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
FF SearchEngineOrder.1: default-search.net
FF Plugin: @java.com/DTPlugin,version=10.7.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2012-10-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2012-10-09] (Oracle Corporation)
FF user.js: detected! => C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\user.js [2014-11-17]
FF SearchPlugin: C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\searchplugins\firefox-add-ons.xml [2013-09-23]
FF SearchPlugin: C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\searchplugins\startpage-https.xml [2015-11-18]
FF SearchPlugin: C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\searchplugins\youtube-video-search.xml [2014-08-08]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-11-04] [not signed]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-11-04] [not signed]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2014-05-25]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S4 IntelIde; no ImagePath
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Asus\Desktop\framxpro-66323830.exe] => Enabled:proinstaller
 
 
 
 
 
*****************
 
HKU\S-1-5-21-746137067-2052111302-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\fastclean => value removed successfully.
"c:\progra~1\settin~1\systemk\syskldr.dll" => Value data removed successfully..
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\rjatydimofu.exe" => key removed successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
"HKU\S-1-5-21-746137067-2052111302-725345543-1003\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\Tabs => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}" => key removed successfully.
HKCR\CLSID\{460C3D19-B3D4-4964-A550-77D263B0CCCB} => key not found. 
HKU\S-1-5-21-746137067-2052111302-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
"HKU\S-1-5-21-746137067-2052111302-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}" => key removed successfully.
HKCR\CLSID\{460C3D19-B3D4-4964-A550-77D263B0CCCB} => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" => key removed successfully.
"HKCR\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => key removed successfully.
"HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => key removed successfully.
HKU\S-1-5-21-746137067-2052111302-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. 
Firefox SearchEngineOrder.1 removed successfully.
"HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2" => key removed successfully.
C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll => moved successfully
"HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2" => key removed successfully.
C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll => moved successfully
C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\user.js => moved successfully
C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\searchplugins\firefox-add-ons.xml => moved successfully
C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\searchplugins\startpage-https.xml => moved successfully
C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\searchplugins\youtube-video-search.xml => moved successfully
C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => moved successfully
C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => moved successfully
C:\Program Files\mozilla firefox\defaults\pref\itms.js => moved successfully
catchme => service removed successfully.
esgiguard => service removed successfully.
IntelIde => service removed successfully.
C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => moved successfully
C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => moved successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Documents and Settings\Asus\Desktop\framxpro-66323830.exe => value removed successfully.
 
==== End of Fixlog 14:23:41 ====

  • 0

#4
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

and the rest:

 

 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-746137067-2052111302-725345543-500 - Administrator - Enabled)
Asus (S-1-5-21-746137067-2052111302-725345543-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Asus
Guest (S-1-5-21-746137067-2052111302-725345543-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-746137067-2052111302-725345543-1000 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-746137067-2052111302-725345543-1002 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: PC Cleaner Pro (Disabled - Up to date) {737A8864-C2D9-4337-B49A-B5E35815B9BB}
AV: AVG Internet Security 2012 (Enabled - Up to date) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: avast! Antivirus (Enabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Internet Security 2012 (Disabled) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.22beta (HKLM\...\7-Zip) (Version:  - )
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.223 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Advertising Center (Version: 0.0.0.1 - Nero AG) Hidden
Apple Application Support (HKLM\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audacity 2.1.1 (HKLM\...\Audacity®_is1) (Version: 2.1.1 - Audacity Team)
Avast Free Antivirus (HKLM\...\Avast) (Version: 10.4.2233 - AVAST Software)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 3.19 - Piriform)
Google Earth Plug-in (HKLM\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Intel® Graphics Media Accelerator Driver (HKLM\...\{8A708DD8-A5E6-11D4-A706-000629E95E20}) (Version: 6.14.10.4497 - )
Intel® PROSet/Wireless WiFi Software (HKLM\...\{0E95DA08-2514-4399-AD87-349C350FA9DE}) (Version: 13.05.0000 - Intel Corporation)
iTunes (HKLM\...\{0718A90E-93AA-49AF-A4FE-0165ACD91DF0}) (Version: 11.2.2.3 - Apple Inc.)
Java 7 Update 7 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217007FF}) (Version: 7.0.70 - Oracle)
JavaFX 2.1.0 (HKLM\...\{1111706F-666A-4037-7777-210328764D10}) (Version: 2.1.0 - Oracle Corporation)
K-Lite Codec Pack 10.9.0 Full (HKLM\...\KLiteCodecPack_is1) (Version: 10.9.0 - )
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 1.0 Hotfix (KB2604042) (HKLM\...\KB2604042) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB2656378) (HKLM\...\KB2656378) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB979904) (HKLM\...\KB979904) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2698035) (HKLM\...\KB2698035) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2742607) (HKLM\...\KB2742607) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2833951) (HKLM\...\KB2833951) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2904878) (HKLM\...\KB2904878) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mobile Broadband HL Service (HKLM\...\Mobile Broadband HL Service) (Version: 22.001.14.01.105 - Huawei Technologies Co.,Ltd)
Motorola SM56 Data Fax Modem (HKLM\...\SMSERIAL) (Version:  - )
Mozilla Firefox 42.0 (x86 en-US) (HKLM\...\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 9 Essentials (HKLM\...\{289bbce1-edf3-4639-8979-52ba09724f8c}) (Version:  - Nero AG)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
QuickTime (HKLM\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
REALTEK Gigabit and Fast Ethernet NIC Driver (HKLM\...\{94FB906A-CF42-4128-A509-D353026A607E}) (Version: 1.70 - REALTEK Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 2.03 - Realtek Semiconductor Corp.)
RICOH Media Driver ver.2.10.01.01 (HKLM\...\{2B818257-E6C7-4841-8C29-C5C9A982BCE5}) (Version: 2.10.01.01 - RICOH)
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Switch Sound File Converter (HKLM\...\Switch) (Version:  - NCH Software)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 8.2.0.0 - Synaptics)
ViewMate Desktop Mouse CC2201 Uninstaller (HKLM\...\VersatoMs) (Version:  - )
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Vuze (HKLM\...\8461-7759-5462-8226) (Version: 5.3.0.0 - Azureus Software, Inc.)
Vuze Remote Toolbar v8.9 (HKLM\...\{E2BDB56B-464B-49D7-AF12-B34C5E2E284B}) (Version: 8.9 - Spigot, Inc.) <==== ATTENTION
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version:  - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB973768 (HKLM\...\KB973768) (Version:  - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-746137067-2052111302-725345543-1003_Classes\CLSID\{25FB7F49-2278-442E-9482-D1B54E88DA13}\InprocServer32 -> C:\Documents and Settings\All Users\Application Data\{1171BAF0-C6D4-4415-9FE3-88D9119F2F37}\amstream (the data entry has 15 more characters).
 
==================== Restore Points =========================
 
18-11-2015 10:42:14 Software Distribution Service 3.0
18-11-2015 11:26:32 System Checkpoint
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-03-15 12:00 - 2012-07-21 11:15 - 00000027 ____N C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\klcp_update.job => JL pF CMD /C sc create KLCPU binPath CMD /V /C SET \FILE \ ProgramFiles \ Lite Codec Pack Tools CodecTweakTool exe\\ IF EXIST FILE START \CTT\ FILE /verysilent /update /freq 30 type own type interact net start KLCPU sc delete KLCPU CMD Asus
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-746137067-2052111302-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-746137067-2052111302-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\SwitchDowngrade.job => C:\Program Files\NCH Software\Switch\switch.exe
Task: C:\WINDOWS\Tasks\SwitchReminder.job => C:\Program Files\NCH Software\Switch\switch.exe
Task: C:\WINDOWS\Tasks\switchShakeIcon.job => C:\Program Files\NCH Swift Sound\Switch\switch.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="1"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-746137067-2052111302-725345543-1003\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Asus\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
DNS Servers: Media is not connected to internet.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service
StandardProfile\AuthorizedApplications: [C:\Program Files\AVG\AVG2012\avgmfapx.exe] => Enabled:AVG Installer
StandardProfile\AuthorizedApplications: [C:\Program Files\Skype\Phone\Skype.exe] => Enabled:Skype
StandardProfile\AuthorizedApplications: [C:\Program Files\Vuze\Azureus.exe] => Enabled:Vuze Launcher
StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:'Firefox' (C:\Program Files\Mozilla Firefox)
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/18/2015 11:35:26 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: Recording Disk Monitor failure.
 
Error: (11/18/2015 11:35:26 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: There are zero configured tuners on this machine, scheduling should not occur in this state!!!
 
Error: (11/18/2015 11:35:24 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: Failed to build recording file list for folder.
 
Error: (11/18/2015 11:32:49 PM) (Source: Userenv) (EventID: 1041) (User: NT AUTHORITY)
Description: Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration.
 
Error: (11/18/2015 11:32:49 PM) (Source: Userenv) (EventID: 1041) (User: NT AUTHORITY)
Description: Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration.
 
Error: (11/18/2015 11:32:49 PM) (Source: Userenv) (EventID: 1041) (User: NT AUTHORITY)
Description: Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration.
 
Error: (11/18/2015 11:32:49 PM) (Source: Userenv) (EventID: 1041) (User: NT AUTHORITY)
Description: Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration.
 
Error: (11/18/2015 07:03:28 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: Flush: RecordingFile failed to write Invalid XML Operation.
 
Error: (11/18/2015 07:03:28 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: RecordingHash in file differs from actual file.
 
Error: (11/18/2015 07:03:22 PM) (Source: Media Center Scheduler) (EventID: 0) (User: )
Description: Failed to build recording file list for folder.
 
 
System errors:
=============
Error: (11/21/2015 02:22:19 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
 
Error: (11/21/2015 02:22:14 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
AFD
aswRdr
aswRvrt
aswSnx
aswSP
aswVmm
Fips
intelppm
IPSec
MRxSmb
NetBIOS
NetBT
RasAcd
Rdbss
Tcpip
WS2IFSL
 
Error: (11/21/2015 02:22:14 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: 
%%31
 
Error: (11/21/2015 02:22:14 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: 
%%31
 
Error: (11/21/2015 02:22:14 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: 
%%31
 
Error: (11/21/2015 02:22:14 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: 
%%31
 
Error: (11/21/2015 02:22:14 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: 
%%31
 
Error: (11/21/2015 02:22:14 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: 
%%31
 
Error: (11/21/2015 02:22:14 PM) (Source: DCOM) (EventID: 10005) (User: ASUS-LAPTOP)
Description: DCOM got error "%%1084" attempting to start the service netman with arguments ""
in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
 
Error: (11/19/2015 03:06:24 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
 
 
==================== Memory info =========================== 
 
Processor: Genuine Intel® CPU T2050 @ 1.60GHz
Percentage of memory in use: 23%
Total physical RAM: 1015.36 MB
Available physical RAM: 777.16 MB
Total Virtual: 2444.53 MB
Available Virtual: 2350.71 MB
 
==================== Drives ================================
 
Drive c: (HDD) (Fixed) (Total:44.77 GB) (Free:0.94 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: (DATA) (Fixed) (Total:29.76 GB) (Free:28.57 GB) NTFS
Drive h: () (Fixed) (Total:74.51 GB) (Free:4.73 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: C455FAB8)
Partition 1: (Active) - (Size=44.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=29.8 GB) - (Type=OF Extended)
 
========================================================
Disk: 1 (Size: 74.5 GB) (Disk ID: 017832F0)
Partition 1: (Not Active) - (Size=74.5 GB) - (Type=0B)
 
==================== End of Addition.txt ============================

  • 0

#5
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
 
 
Shortcut: C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk -> C:\WINDOWS\system32\wupdmgr.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk -> C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-AA1000000001}\SC_Reader.ico ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk -> C:\WINDOWS\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Audacity.lnk -> C:\Program Files\Audacity\audacity.exe (The Audacity Team)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk -> C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Switch Sound File Converter.lnk -> C:\Program Files\NCH Swift Sound\Switch\switch.exe (NCH Software)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Vuze.lnk -> C:\Program Files\Vuze\Azureus.exe (Azureus Software, Inc)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk -> C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk -> C:\Program Files\Movie Maker\moviemk.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Windows Digital Media Enhancements\Windows Audio Converter.lnk -> C:\Program Files\Windows Plus\Audio Converter\AudioConverter.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Windows Digital Media Enhancements\Windows CD Label Maker.lnk -> C:\Program Files\Windows Plus\CDLM\CDLM.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Windows Digital Media Enhancements\Windows Dancer.lnk -> C:\Program Files\Windows Plus\Dancer\Dancer.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Windows Digital Media Enhancements\Windows Party Mode.lnk -> C:\Program Files\Windows Plus\Party Mode\PartyMode.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Documentation.lnk -> C:\Program Files\VideoLAN\VLC\Documentation.url ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Release Notes.lnk -> C:\Program Files\VideoLAN\VLC\NEWS.txt ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk -> C:\Program Files\VideoLAN\VLC\VideoLAN Website.url ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\VLC media player.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe (VideoLAN)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk -> C:\WINDOWS\system32\C2MP\UpdateChecker.exe ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy\Spybot - Search & Destroy.lnk -> C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe (Safer Networking Limited)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy\Tutorial.lnk -> C:\Program Files\Spybot - Search & Destroy\Help\English.chm ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy\Uninstall Spybot-S&D.lnk -> C:\Program Files\Spybot - Search & Destroy\unins000.exe ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy\Update Spybot-S&D.lnk -> C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe (Safer Networking Limited)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Skype\Skype.lnk -> C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime\About QuickTime.lnk -> C:\WINDOWS\Installer\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}\RichText.ico ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime\PictureViewer.lnk -> C:\WINDOWS\Installer\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}\PictureViewer.ico ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime\QuickTime Player.lnk -> C:\WINDOWS\Installer\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}\QTPlayer.ico ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero\Nero ControlCenter 4.lnk -> C:\Program Files\Nero\Nero ControlCenter 4\ncc.exe (Nero AG)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero\Nero 9\Nero StartSmart Essentials.lnk -> C:\Program Files\Nero\Nero 9\Nero StartSmart\NeroStartSmart.exe (Nero AG)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\Silverlight.Configuration.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Media Player - Codec Pack\Codec Settings.lnk -> C:\WINDOWS\system32\C2MP\CodecSettings.exe ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Media Player - Codec Pack\Media Player Classic.lnk -> C:\WINDOWS\system32\C2MP\mpc-hc.exe (MPC-HC Team)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Media Player - Codec Pack\Uninstall.lnk -> C:\WINDOWS\system32\C2MP\Uninst.exe (No File)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Media Player - Codec Pack\Helpful Resources\How to play unusual files.lnk -> C:\WINDOWS\system32\C2MP\doc_open_with.pdf (No File)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware\Uninstall Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\unins000.exe ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk -> C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Codec Tweak Tool.lnk -> C:\Program Files\K-Lite Codec Pack\Tools\CodecTweakTool.exe ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Media Player Classic.lnk -> C:\Program Files\K-Lite Codec Pack\MPC-HC\mpc-hc.exe (MPC-HC Team)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Uninstall\Uninstall K-Lite Codec Pack.lnk -> C:\Program Files\K-Lite Codec Pack\unins000.exe ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Tools\GraphStudioNext.lnk -> C:\Program Files\K-Lite Codec Pack\Tools\GraphStudioNext.exe ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Tools\MediaInfo.lnk -> C:\Program Files\K-Lite Codec Pack\Tools\mediainfo.exe ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Tools\Win7DSFilterTweaker.lnk -> C:\Program Files\K-Lite Codec Pack\Tools\CodecTweakTool.exe ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Help\Frequently Asked Questions.lnk -> C:\Program Files\K-Lite Codec Pack\Info\faq.htm ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\iTunes\About iTunes.lnk -> C:\Program Files\iTunes\iTunes.Resources\en_GB.lproj\About iTunes.rtf ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\iTunes\iTunes.lnk -> C:\Program Files\iTunes\iTunes.exe (Apple Inc.)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Freecell.lnk -> C:\WINDOWS\system32\freecell.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Hearts.lnk -> C:\WINDOWS\system32\mshearts.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Backgammon.lnk -> C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Checkers.lnk -> C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Hearts.lnk -> C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Reversi.lnk -> C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Spades.lnk -> C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Minesweeper.lnk -> C:\WINDOWS\system32\winmine.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Pinball.lnk -> C:\Program Files\Windows NT\Pinball\pinball.exe (Cinematronics)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Solitaire.lnk -> C:\WINDOWS\system32\sol.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Spider Solitaire.lnk -> C:\WINDOWS\system32\spider.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner\Uninstall CCleaner.lnk -> C:\Program Files\CCleaner\uninst.exe (Piriform Ltd)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\AVAST Software\Avast Free Antivirus.lnk -> C:\Program Files\AVAST Software\Avast\avastui.exe (AVAST Software)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\WINDOWS\system32\Com\comexp.msc ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\WINDOWS\system32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Calculator.lnk -> C:\WINDOWS\system32\calc.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Paint.lnk -> C:\WINDOWS\system32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\WINDOWS\system32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\WordPad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Backup.lnk -> C:\WINDOWS\system32\ntbackup.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\WINDOWS\system32\charmap.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\WINDOWS\system32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Disk Defragmenter.lnk -> C:\WINDOWS\system32\dfrg.msc ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Files and Settings Transfer Wizard.lnk -> C:\WINDOWS\system32\usmt\migwiz.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\WINDOWS\system32\Restore\rstrui.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Media Center\Media Center.lnk -> C:\WINDOWS\ehome\ehshell.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Sound Recorder.lnk -> C:\WINDOWS\system32\sndrec32.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Volume Control.lnk -> C:\WINDOWS\system32\sndvol32.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\HyperTerminal.lnk -> C:\Program Files\Windows NT\hypertrm.exe (Hilgraeve, Inc.)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Accessibility\Accessibility Wizard.lnk -> C:\WINDOWS\system32\accwiz.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk -> C:\Program Files\7-Zip\7zFM.exe (Igor Pavlov)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\7-Zip\7-Zip Help.lnk -> C:\Program Files\7-Zip\7-zip.chm ()
Shortcut: C:\Documents and Settings\All Users\Desktop\Audacity.lnk -> C:\Program Files\Audacity\audacity.exe (The Audacity Team)
Shortcut: C:\Documents and Settings\All Users\Desktop\iTunes.lnk -> C:\Program Files\iTunes\iTunes.exe (Apple Inc.)
Shortcut: C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes)
Shortcut: C:\Documents and Settings\All Users\Desktop\Media Player Classic.lnk -> C:\Program Files\K-Lite Codec Pack\MPC-HC\mpc-hc.exe (MPC-HC Team)
Shortcut: C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Documents and Settings\All Users\Desktop\VLC media player.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe (VideoLAN)
Shortcut: C:\Documents and Settings\All Users\Desktop\Vuze.lnk -> C:\Program Files\Vuze\Azureus.exe (Azureus Software, Inc)
Shortcut: C:\Documents and Settings\Asus\Start Menu\Programs\Outlook Express.lnk -> C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Asus\Start Menu\Programs\Accessories\Address Book.lnk -> C:\Program Files\Outlook Express\wab.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Asus\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Asus\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Asus\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Asus\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Asus\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Asus\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Asus\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Asus\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Asus\Desktop\My Documents.lnk -> C:\Documents and Settings\Asus\My Documents ()
Shortcut: C:\Documents and Settings\Asus\Desktop\Shortcut to Audacity.lnk -> C:\Program Files\Audacity ()
Shortcut: C:\Documents and Settings\Asus\Desktop\Shortcut to Movies.lnk -> D:\Movies ()
Shortcut: C:\Documents and Settings\Asus\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Asus\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Documents and Settings\Asus\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart Essentials.lnk -> C:\Program Files\Nero\Nero 9\Nero StartSmart\NeroStartSmart.exe (Nero AG)
Shortcut: C:\Documents and Settings\Asus\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk -> C:\Program Files\Vuze\Azureus.exe (Azureus Software, Inc)
Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
 
 
 
 
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\Reset VLC media player preferences and cache files.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe (VideoLAN) -> --reset-config --reset-plugins-cache vlc://quit
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe (VideoLAN) -> --reset-config --reset-plugins-cache vlc://quit
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk -> C:\Program Files\VideoLAN\VLC\vlc.exe (VideoLAN) -> -Iskins
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\REALTEK Gigabit and Fast Ethernet NIC Driver\Uninstall REALTEK Gigabit and Fast Ethernet NIC Driver.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94FB906A-CF42-4128-A509-D353026A607E}\Setup.exe" -l0x9 REMOVE
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime\Uninstall QuickTime.lnk -> C:\WINDOWS\system32\msiexec.exe (Microsoft Corporation) -> /i {AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A} /qf
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero\Nero Online Upgrade.lnk -> C:\Program Files\Nero\Nero 9\Nero Online Upgrade\NeroOnlineUpgrade.exe (Nero AG) -> ShowOffer
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\DirectVobSub.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\vsfilter.dll",DirectVobSub
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow audio decoder.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\ffdshow\ffdshow.ax",configureAudio
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow video decoder.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\ffdshow\ffdshow.ax",configure
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Audio.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\LAV\lavaudio.ax",OpenConfiguration
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Splitter.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\LAV\lavsplitter.ax",OpenConfiguration
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Video.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\LAV\lavvideo.ax",OpenConfiguration
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\Reset to recommended settings.lnk -> C:\Program Files\K-Lite Codec Pack\Tools\CodecTweakTool.exe () -> /resetsettings
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Intel PROSet Wireless\WiFi Connection Utility.lnk -> C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation) -> /af Intel PROSet/Wireless
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth\Uninstall Google Earth Plug-in.lnk -> C:\WINDOWS\system32\msiexec.exe (Microsoft Corporation) -> /x {4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E} FEEDBACK=1
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\WINDOWS\system32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\WINDOWS\system32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Local Security Policy.lnk -> C:\WINDOWS\system32\secpol.msc () -> /s
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Performance.lnk -> C:\WINDOWS\system32\perfmon.msc () -> /s
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk -> C:\WINDOWS\system32\services.msc () -> /s
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Activate Windows.lnk -> C:\WINDOWS\system32\oobe\msoobe.exe (Microsoft Corporation) -> /A
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Scheduled Tasks.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}\::{D6277990-4C6A-11CF-8D87-00AA0060F5BF}
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Network Connections.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}\::{7007acc7-3202-11d1-aad2-00805fc1270e}
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Network Setup Wizard.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> hnetwiz.dll,HomeNetWizardRunDll
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\New Connection Wizard.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> netshell.dll,StartNCW
ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Wireless Network Setup Wizard.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> shell32.dll,Control_RunDLL NetSetup.cpl,@0,WNSW
ShortcutWithArgument: C:\Documents and Settings\Asus\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (Microsoft Corporation) -> -LaunchRA
ShortcutWithArgument: C:\Documents and Settings\Asus\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\Documents and Settings\Asus\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\Documents and Settings\Asus\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (Microsoft Corporation) -> /start
ShortcutWithArgument: C:\Documents and Settings\Asus\SendTo\Skype.lnk -> C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) -> /sendto:
ShortcutWithArgument: C:\Documents and Settings\Asus\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\Documents and Settings\Default User\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (Microsoft Corporation) -> -LaunchRA
ShortcutWithArgument: C:\Documents and Settings\Default User\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (Microsoft Corporation) -> /start
 
 
InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\Media Player - Codec Pack\Package Homepage.url -> hxxp://www.mediaplayercodecpack.com/
InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\Media Player - Codec Pack\Helpful Resources\Clone Copy Protected CD's.url -> hxxp://www.slysoft.com/en/clonecd.html?aid=52056
InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\Media Player - Codec Pack\Helpful Resources\Clone Copy Protected DVD's.url -> hxxp://www.slysoft.com/en/clonedvd.html?aid=52056
InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\Media Player - Codec Pack\Helpful Resources\Play any Copy Protected Disc.url -> hxxp://www.slysoft.com/en/anydvd.html?aid=52056
InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> hxxp://www.piriform.com/ccleaner
InternetURL: C:\Documents and Settings\Asus\Favorites\Amazon.co.uk.url -> hxxp://www.amazon.co.uk/ref=gno_logo_
InternetURL: C:\Documents and Settings\Asus\Favorites\Dictionary, Encyclopedia and Thesaurus - The Free Dictionary.url -> hxxp://www.thefreedictionary.com/
InternetURL: C:\Documents and Settings\Asus\Favorites\Dictionary.com.url -> hxxp://dictionary.reference.com/
InternetURL: C:\Documents and Settings\Asus\Favorites\eBay - The UK's Online Marketplace.url -> hxxp://www.ebay.co.uk/
InternetURL: C:\Documents and Settings\Asus\Favorites\Google.url -> hxxp://www.google.co.uk/webhp?hl=en
InternetURL: C:\Documents and Settings\Asus\Favorites\MSN.com.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=IStart
InternetURL: C:\Documents and Settings\Asus\Favorites\The World Clock – Time Zones.url -> hxxp://www.timeanddate.com/worldclock/
InternetURL: C:\Documents and Settings\Asus\Favorites\Wikipedia, the free encyclopedia.url -> hxxp://en.wikipedia.org/wiki/Main_Page
InternetURL: C:\Documents and Settings\Asus\Favorites\Windows Live Hotmail.url -> hxxp://mail.live.com/default.aspx?wa=wsignin1.0
InternetURL: C:\Documents and Settings\Asus\Favorites\Microsoft Websites\IE Add-on site.url -> hxxp://go.microsoft.com/fwlink/?LinkId=50893
InternetURL: C:\Documents and Settings\Asus\Favorites\Microsoft Websites\IE site on Microsoft.com.url -> hxxp://go.microsoft.com/fwlink/?linkid=44661
InternetURL: C:\Documents and Settings\Asus\Favorites\Microsoft Websites\Microsoft At Home.url -> hxxp://go.microsoft.com/fwlink/?linkid=55424
InternetURL: C:\Documents and Settings\Asus\Favorites\Microsoft Websites\Microsoft At Work.url -> hxxp://go.microsoft.com/fwlink/?linkid=68920
InternetURL: C:\Documents and Settings\Asus\Favorites\Microsoft Websites\Microsoft Store.url -> hxxp://go.microsoft.com/fwlink/?linkid=140813
InternetURL: C:\Documents and Settings\Asus\Favorites\Links\Free Hotmail.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=hotmail
InternetURL: C:\Documents and Settings\Asus\Favorites\Links\Suggested Sites.url -> hxxps://ieonline.microsoft.com/#ieslice
InternetURL: C:\Documents and Settings\Asus\Desktop\www.filmmusic.ru_TQUTWD\Quiet Earth The & Iris (1985)\www.filmmusic.ru - all soundtracks here.url -> hxxp://filmmusic.ru
 
==================== End of Shortcut.txt =============================

  • 0

#6
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [ehTray] => C:\WINDOWS\ehome\ehtray.exe [59392 2004-08-10] (Microsoft Corporation)
HKLM\...\Run: [VersatoMs] => C:\Program Files\MagicMus\MulMouse.exe [282624 2004-06-17] ()
HKLM\...\Run: [SMSERIAL] => C:\WINDOWS\sm56hlpr.exe [544768 2006-01-20] (Motorola Inc.)
HKLM\...\Run: [IntelZeroConfig] => C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe [1400832 2011-01-12] (Intel® Corporation)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1210640 2011-01-12] (Intel® Corporation)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1045720 2015-09-14] (Adobe Systems Incorporated)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [761945 2005-10-21] (Synaptics, Inc.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [15961088 2006-01-11] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [igfxhkcmd] => C:\WINDOWS\system32\hkcmd.exe [77824 2006-02-07] (Intel Corporation)
HKLM\...\Run: [igfxpers] => C:\WINDOWS\system32\igfxpers.exe [118784 2006-02-07] (Intel Corporation)
HKLM\...\Run: [DHAgent] => C:\Program Files\DriverHound\DHAgent.exe
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-07] (AVAST Software)
HKU\S-1-5-21-746137067-2052111302-725345543-1003\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-746137067-2052111302-725345543-1003\...\Run: [AmazonMP3DownloaderHelper] => C:\Documents and Settings\Asus\Local Settings\Application Data\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
HKU\S-1-5-21-746137067-2052111302-725345543-1003\...\Run: [OutfoxTV] => C:\Program Files\OutfoxTV\OutfoxTV\DesktopContainer.exe
HKU\S-1-5-21-746137067-2052111302-725345543-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [9216 2008-04-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-10-15] (AVAST Software)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk [2014-12-15]
ShortcutTarget: CodecPackUpdateChecker.lnk -> C:\WINDOWS\system32\C2MP\UpdateChecker.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\..\Interfaces\{B65CBEE6-C44B-4AFC-BAA5-B7F2838A178D}: [DhcpNameServer] 192.168.11.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-746137067-2052111302-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-746137067-2052111302-725345543-1003\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = www.google.com
www.google.com
URLSearchHook: HKU\S-1-5-21-746137067-2052111302-725345543-1003 - Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-30] (AVAST Software)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
 
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default
FF DefaultSearchEngine: Yahoo!
FF SelectedSearchEngine: Yahoo!
FF Homepage: about:home
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-22] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll [No File]
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll [No File]
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-02-17] [not signed]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-10-15] [not signed]
 
Chrome: 
=======
CHR Profile: C:\Documents and Settings\Asus\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-06-04]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-06-04]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-15] (AVAST Software)
S2 ehRecvr; C:\WINDOWS\eHome\ehRecvr.exe [194560 2004-08-10] (Microsoft Corporation) [File not signed]
S2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [161768 2012-10-09] (Oracle Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 MHN; C:\WINDOWS\System32\mhn.dll [85504 2004-08-10] (Microsoft Corporation) [File not signed]
S2 Mobile Broadband HL Service; C:\Documents and Settings\All Users\Application Data\MobileBrServ\mbbservice.exe [232288 2012-03-12] ()
S2 S24EventMonitor; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [966656 2011-01-12] (Intel® Corporation) [File not signed]
S2 Skype C2C Service; C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S3 UMWdf; C:\WINDOWS\system32\wdfmgr.exe [38912 2006-03-15] (Microsoft Corporation) [File not signed]
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 OutfoxTvService; C:\Program Files\OutfoxTV\OutfoxTvService.exe [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-10-15] (AVAST Software)
S2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [76000 2015-10-15] (AVAST Software)
S1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-10-15] (AVAST Software)
S0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-10-15] (AVAST Software)
S1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [794952 2015-11-07] (AVAST Software)
S1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [435464 2015-11-07] (AVAST Software)
S3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [157888 2015-10-15] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-10-15] (AVAST Software)
S0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208664 2015-10-15] (AVAST Software)
S3 DUBE100B; C:\WINDOWS\System32\DRIVERS\DUBE100B.sys [18560 2006-05-26] (D-Link Corporation)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MHNDRV; C:\WINDOWS\System32\DRIVERS\mhndrv.sys [11008 2004-08-10] (Microsoft Corporation) [File not signed]
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ATKACPI.sys [5760 2007-08-28] ()
S2 MUsbFltr; C:\WINDOWS\System32\DRIVERS\MUsbFltr.sys [6528 2004-03-22] (Waytech Development, Inc.)
S3 NETwLx32; C:\WINDOWS\System32\DRIVERS\NETwLx32.sys [6609920 2010-10-07] (Intel Corporation)
S3 RTL8023xp; C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys [74496 2005-03-04] (Realtek Semiconductor Corporation                           )
S2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [13952 2010-05-19] (Intel Corporation)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
NETSVC: MHN -> C:\Windows\System32\mhn.dll (Microsoft Corporation)
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-11-21 14:25 - 2015-11-21 14:26 - 00012360 _____ C:\Documents and Settings\Asus\Desktop\FRST.txt
2015-11-19 12:07 - 2015-11-21 14:25 - 00000000 ____D C:\FRST
2015-11-19 12:07 - 2015-11-19 11:55 - 01378816 _____ (Farbar) C:\Documents and Settings\Asus\Desktop\FRST.exe
2015-11-19 01:42 - 2015-11-19 01:42 - 00000780 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-18 10:55 - 2015-11-18 10:59 - 117766424 _____ (Apple Inc.) C:\Documents and Settings\Asus\Desktop\iTunesSetup.exe
2015-11-18 10:42 - 2015-11-18 10:42 - 00000000 ___HD C:\WINDOWS\system32\Settings
2015-11-17 20:41 - 2015-11-17 22:19 - 00000000 ____D C:\Documents and Settings\Asus\Local Settings\Application Data\MalwareProtectionLive
2015-11-09 17:52 - 2015-11-09 17:52 - 00000000 ____D C:\Documents and Settings\Asus\Desktop\Walker Brothers - Make It Easy On Yourself
2015-11-09 17:35 - 2015-11-09 17:38 - 00000000 ____D C:\Documents and Settings\Asus\Desktop\2010 - Original Album Classics
2015-11-09 17:22 - 2015-11-09 19:35 - 00000000 ____D C:\Documents and Settings\Asus\Desktop\1966 - Portrait (Remastered 1998)
2015-11-05 18:44 - 2015-11-05 18:45 - 00000000 ____D C:\Documents and Settings\Asus\Desktop\Take it Easy With The Walker Brothers
2015-11-04 19:07 - 2015-11-04 19:55 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-10-26 17:00 - 2015-10-26 17:00 - 00000276 _____ C:\WINDOWS\Tasks\switchShakeIcon.job
2015-10-24 11:40 - 2011-01-24 01:24 - 00000000 ____D C:\Documents and Settings\Asus\Desktop\Tangerine Dream - Mystery Tracks (bootleg)
2015-10-23 11:07 - 2015-10-23 11:12 - 00000000 ____D C:\Program Files\Acro Software
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-11-21 14:26 - 2012-07-21 11:21 - 00000000 ____D C:\Documents and Settings\Asus\Local Settings\temp
2015-11-21 14:21 - 2006-03-15 12:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2015-11-19 15:06 - 2012-05-25 14:42 - 00000178 ___SH C:\Documents and Settings\Asus\ntuser.ini
2015-11-19 15:06 - 2012-05-25 14:34 - 01733955 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-19 01:43 - 2014-10-28 19:41 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-19 01:42 - 2014-10-28 19:41 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-19 01:42 - 2014-10-28 19:40 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-11-18 23:39 - 2012-05-25 14:40 - 00032638 _____ C:\WINDOWS\SchedLgU.Txt
2015-11-18 23:39 - 2012-05-25 14:40 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-18 23:37 - 2014-12-15 13:04 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2015-11-18 23:32 - 2014-03-30 11:46 - 00000276 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-746137067-2052111302-725345543-1003.job
2015-11-18 23:32 - 2013-04-13 21:59 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-18 23:32 - 2012-05-25 16:17 - 00000000 ____D C:\WINDOWS\system32\Lang
2015-11-18 19:03 - 2012-05-25 14:30 - 00000000 ____D C:\WINDOWS\Registration
2015-11-18 18:30 - 2013-04-13 21:59 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-18 18:27 - 2014-03-30 15:11 - 117518336 _____ C:\WINDOWS\MEMORY.DMP
2015-11-18 15:13 - 2013-02-11 14:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2015-11-18 14:28 - 2012-06-01 07:36 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2015-11-18 10:55 - 2012-05-25 14:42 - 00000000 ____D C:\Documents and Settings\Asus
2015-11-18 01:16 - 2014-02-20 12:50 - 00000000 ____D C:\Documents and Settings\Asus\Application Data\vlc
2015-11-18 01:13 - 2013-01-25 00:25 - 00000000 ____D C:\Documents and Settings\Asus\Application Data\Audacity
2015-11-18 01:12 - 2015-10-08 01:47 - 00000000 ____D C:\Program Files\Audacity
2015-11-15 23:17 - 2012-05-28 22:31 - 00000000 ____D C:\Documents and Settings\Asus\Application Data\Media Player Classic
2015-11-15 12:51 - 2014-03-30 11:46 - 00000284 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-746137067-2052111302-725345543-1003.job
2015-11-12 20:24 - 2014-12-17 20:24 - 00000656 _____ C:\WINDOWS\Tasks\klcp_update.job
2015-11-09 14:50 - 2015-06-11 12:35 - 00000456 _____ C:\Documents and Settings\Asus\Desktop\jsa.txt
2015-11-07 21:46 - 2014-12-15 13:03 - 00794952 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2015-11-07 21:46 - 2014-12-15 13:03 - 00435464 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2015-11-05 13:12 - 2012-05-28 16:13 - 00000000 ____D C:\Documents and Settings\Asus\Application Data\Azureus
2015-11-05 12:54 - 2012-07-20 11:44 - 00000754 ____C C:\WINDOWS\WORDPAD.INI
2015-11-05 10:57 - 2012-05-26 10:43 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-10-25 09:16 - 2012-05-25 15:21 - 00559976 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-24 18:22 - 2014-04-01 20:34 - 00000000 ____D C:\Program Files\Vuze
2015-10-23 10:56 - 2012-05-25 15:05 - 00000000 ___SD C:\Documents and Settings\Asus\UserData
 
==================== Files in the root of some directories =======
 
2013-06-28 21:24 - 2013-06-28 21:24 - 0000046 ____C () C:\Documents and Settings\Asus\Application Data\Camdata.ini
2013-06-28 21:24 - 2013-06-28 21:24 - 0000408 ____C () C:\Documents and Settings\Asus\Application Data\CamLayout.ini
2013-06-28 21:24 - 2013-06-28 21:24 - 0000408 ____C () C:\Documents and Settings\Asus\Application Data\CamShapes.ini
2013-06-28 21:17 - 2013-06-28 21:24 - 0004511 ____C () C:\Documents and Settings\Asus\Application Data\CamStudio.cfg
2012-08-27 18:19 - 2012-08-27 18:19 - 0027520 ____C () C:\Documents and Settings\Asus\Local Settings\Application Data\dt.dat
2012-07-20 00:15 - 2012-07-20 00:15 - 0000000 ____C () C:\Documents and Settings\Asus\Local Settings\Application Data\egwkduhn.log
2012-07-20 11:40 - 2012-07-21 11:05 - 0000000 ____C () C:\Documents and Settings\Asus\Local Settings\Application Data\gudearyg.log
2012-07-20 00:08 - 2012-07-21 11:05 - 0000024 ____C () C:\Documents and Settings\Asus\Local Settings\Application Data\idtioubt.log
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
==================== End of FRST.txt ============================

  • 0

#7
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,012 posts
  • MVP
Clear the Java Cache by following the instructions on
 
You do not have the latest Java.
First go into Control Panel, Add/Remove Software (XP) or Programs and Features (Vista/Win 7) and remove any old versions (which may call themselves: Java Runtime, Runtime Environment, Runtime, JRE, Java Virtual Machine, Virtual Machine, Java VM, JVM, VM, J2RE, J2SE)
I see:
Java 7 Update 7 
JavaFX 2.1.0
 
Java has been very vulnerable to infection so unless you absolutely need it you should not reinstall it.
 
If you feel you must have Java:
Get the latest Java at:
 
Save it to your PC then close all browsers and install it.  Do not let it install the yahoo toolbar or other foistware.
Once installed, go into Control Panel, Java, Security and set the slider to the Highest then OK.
 
 
Also uninstall:
 
Skype Click to Call 
Vuze Remote Toolbar v8.9
 
 
If your icons are still unstable then:
 
download ShellExView.
 
 
Use this download:
 
Once you get it installed, run it and look in the third or fourth column from the RIGHT. It should say MICROSOFT. Click once or twice on MICROSOFT so that items with NO are at the top.
Select all of the NO items and then click on the red led looking icon in the upper left. This should disable all of the non-microsoft additions to Explorer. Reboot and see if you still have the problem.

  • 0

#8
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

Im unable to remove java and Skype.This is the message I get  'The windows intaller service could not be accessed.'

Vuze went without any problems.

 

Ignore the above.

I clicked change instead of remove and thats sorted it.


Edited by elielieli, 21 November 2015 - 01:05 PM.

  • 0

#9
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

After restarting the problem still persists.

Also , it will now not reboot in safe mode.

The icons seem stable though.


Edited by elielieli, 21 November 2015 - 02:31 PM.

  • 0

#10
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,012 posts
  • MVP
 
Start, Run, eventvwr.msc, OK to bring up the Event Viewer.  Right click on System and Clear All Events, No (we don't want to save the old log), OK. Repeat for Application. 
 
Reboot. 
 
 
 
1. Please download the Event Viewer Tool by Vino Rosso
and save it to your Desktop:
2. Double-click VEW.exe
3. Under 'Select log to query', select:
 
* System
4. Under 'Select type to list', select:
* Error
* Warning
 
 
Then use the 'Number of events' as follows:
 
 
1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.
 
 
Please post the Output log in your next reply then repeat but select Application.

 
 (Second time you run vew it will overwrite the first log so copy it to a reply or rename it first.)
 
See if any of these will run:

 
Download aswMBR.exe  to your desktop.
Double click aswMBR.exe 
uncheck trace disk IO calls
Click the "Scan" button to start scan (Accept the Avast Engine)
On completion of the scan if the Fix button is enabled (not the FixMBR button) press it and then run a new scan and  click save log, save it to your desktop and post in your next reply
If the Fix button is not enabled then just click save log, save it to your desktop and post in your next reply
 
ComboFix
 
:!: It must be saved to your desktop, do not run it from your browser:!:
 
:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well.  See: http://www.bleepingc...opic114351.html
 
 
Download and Save this file --  to your Desktop -- from either of these two sources:
 
Double click on ComboFix to start the program.  
 
 
 
    * :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.
    
    
    * A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix.  
 
A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.
 
A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.
 
 
Download TDSSKiller:
Save it to your desktop then run it.
Double click on TDSSKiller.exe and to start the program.  
 
If TDSSKiller alerts you that the system needs to reboot, please consent.
 
Run TDSSKiller again but this time:
before you hit the Scan  hit  Change Parameters and check the two items under Additional Options. OK then Scan.
In this mode it is prone to false positives so do not change the SKIP option to DELETE unless it says TDSS.
When done, a log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.
 
 

  • 0

Advertisements


#11
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

i tried  Start, Run, eventvwr.msc , but this did nothing.

so i went ahead and ran system which is below.

application however brought up somekind 

of error message.
 
Report run at 22/11/2015 01:19:18
 
Note: All dates below are in the format dd/mm/yyyy
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 21/11/2015 22:01:01
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\WINDOWS\system32\wuapi.dll. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 21/11/2015 21:37:13
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The OutfoxTvService service failed to start due to the following error:  The system cannot find the file specified.  
 
Log: 'System' Date/Time: 21/11/2015 21:37:03
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Java Quick Starter service failed to start due to the following error:  The system cannot find the file specified.  
 
Log: 'System' Date/Time: 21/11/2015 21:37:03
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Google Update Service (gupdate) service failed to start due to the following error:  The system cannot find the file specified.  
 
Log: 'System' Date/Time: 21/11/2015 21:37:03
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Standard HID Class Driver service failed to start due to the following error:  The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.  
 
Log: 'System' Date/Time: 21/11/2015 21:34:16
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\WINDOWS\system32\logonui.exe.Manifest. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 21/11/2015 21:34:16
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. . 
 
Log: 'System' Date/Time: 21/11/2015 21:34:10
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 21/11/2015 21:34:10
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. . 
 
Log: 'System' Date/Time: 21/11/2015 21:34:07
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\WINDOWS\system32\SHELL32.dll. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 21/11/2015 21:34:07
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. . 
 
Log: 'System' Date/Time: 21/11/2015 21:34:02
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\WINDOWS\system32\WININET.dll. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 21/11/2015 21:34:02
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. . 
 
Log: 'System' Date/Time: 21/11/2015 21:34:01
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\WINDOWS\system32\SHELL32.dll. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 21/11/2015 21:34:01
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. . 
 
Log: 'System' Date/Time: 21/11/2015 21:33:58
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\Documents and Settings\Asus\Desktop\shexview_setup.exe. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 21/11/2015 21:33:58
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. . 
 
Log: 'System' Date/Time: 21/11/2015 21:33:45
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\WINDOWS\system32\TAPI32.dll. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 21/11/2015 21:33:45
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. . 
 
Log: 'System' Date/Time: 21/11/2015 21:33:44
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\WINDOWS\system32\WININET.DLL. Reference error message: The operation completed successfully. . 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 18/11/2015 19:03:45
Type: warning Category: 0
Event: 265 Source: PlugPlayManager
HotPlug notification was not performed because the file "C:\WINDOWS\system32\hotplug.dll" was not found. 
 
Log: 'System' Date/Time: 18/11/2015 01:19:01
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts. 
 
Log: 'System' Date/Time: 17/11/2015 20:38:52
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts. 
 
Log: 'System' Date/Time: 17/11/2015 17:23:18
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts. 
 
Log: 'System' Date/Time: 15/11/2015 14:52:30
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts. 

  • 0

#12
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts
aswMBR version 1.0.1.2290 Copyright© 2014 AVAST Software
Run date: 2015-11-22 01:45:32
-----------------------------
01:45:32.875    OS Version: Windows 5.1.2600 Service Pack 3
01:45:32.875    Number of processors: 2 586 0xE08
01:45:32.875    ComputerName: ASUS-LAPTOP  UserName: Asus
01:45:35.062    Initialze error 5AA 
01:45:47.687    AVAST engine download error: 0
01:46:09.343    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
01:46:09.343    Disk 0 Vendor: Hitachi_HTS541680J9AT00 SB2OA70H Size: 76319MB BusType: 3
01:46:09.375    Disk 0 MBR read successfully
01:46:09.375    Disk 0 MBR scan
01:46:09.375    Disk 0 Windows XP default MBR code
01:46:09.390    Disk 0 Partition 1 80 (A) 07      HPFS/NTFS NTFS        45841 MB offset 63
01:46:09.406    Disk 0 default boot code
01:46:09.406    Disk 0 Partition - 00     0F   Extended LBA             30474 MB offset 93883860
01:46:09.421    Disk 0 Partition 2 00     07      HPFS/NTFS NTFS        30474 MB offset 93883923
01:46:09.421    Disk 0 scanning sectors +156296385
01:46:09.453    Disk 0 scanning C:\WINDOWS\system32\drivers
01:46:09.453    Service scanning
01:46:10.500    Modules scanning
01:46:10.531    Disk 0 statistics 273/0/0 @ 2.12 MB/s
01:46:10.531    Scan finished successfully
01:47:09.609    Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Asus\Desktop\MBR.dat"
01:47:09.609    The log file has been saved successfully to "C:\Documents and Settings\Asus\Desktop\aswMBR.txt"
01:47:20.109    Disk 0 MBR has been saved successfully to "H:\MBR.dat"
01:47:20.125    The log file has been saved successfully to "H:\aswMBR.txt"

  • 0

#13
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

Here is the Combfix log.

TDSSKiller runs for a few seconds then asks 'specify the path to one of encrypted files'

No log is produced.

 

 ComboFix 12-07-20.02 - Asus 21/07/2012  12:07:35.2.2 - x86

Microsoft Windows XP Professional  5.1.2600.3.1252.44.1033.18.1015.419 [GMT 1:00]
Running from: c:\documents and settings\Asus\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Asus\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\documents and settings\Asus\Local Settings\Application Data\ytpdlvag"
"c:\documents and settings\Asus\Start Menu\Programs\Startup\hahpvvgw.exe"
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Asus\Local Settings\Application Data\bdbyasni.log
c:\documents and settings\Asus\Local Settings\Application Data\jtxvkuiq.log
c:\documents and settings\Asus\Local Settings\Application Data\ktnoiclh.log
c:\documents and settings\Asus\Local Settings\Application Data\nmogqmgj.log
c:\documents and settings\Asus\Local Settings\Application Data\uvrmikmh.log
c:\documents and settings\Asus\Local Settings\Application Data\woljuifi.log
c:\documents and settings\Asus\Start Menu\Programs\Startup\hahpvvgw.exe
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MICORSOFT_WINDOWS_SERVICE
.
.
(((((((((((((((((((((((((   Files Created from 2012-06-21 to 2012-07-21  )))))))))))))))))))))))))))))))
.
.
2012-07-20 22:06 . 2012-07-20 22:06 -------- d-----w- C:\_OTL
2012-07-20 20:04 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-20 20:04 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-20 20:04 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-20 20:04 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-20 20:04 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-20 20:04 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-20 20:04 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-20 20:01 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2012-07-20 20:01 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2012-07-20 20:00 . 2012-07-20 20:00 -------- d-----w- c:\program files\Alwil Software
2012-07-20 20:00 . 2012-07-20 20:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2012-07-20 19:09 . 2012-07-20 19:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-07-20 19:09 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-20 18:14 . 2012-07-20 22:56 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-07-20 18:14 . 2012-07-20 18:14 -------- d-----w- c:\documents and settings\Asus\Application Data\Malwarebytes
2012-07-20 18:14 . 2012-07-20 18:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-07-20 11:40 . 2012-07-20 11:40 -------- d-----w- c:\documents and settings\All Users\AVG Secure Search
2012-07-20 11:14 . 2012-07-20 11:14 -------- d-----w- c:\documents and settings\Asus\Application Data\Grisoft
2012-07-20 11:14 . 2007-05-30 12:10 10872 ----a-w- c:\windows\system32\drivers\AvgAsCln.sys
2012-07-20 11:14 . 2012-07-20 11:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Grisoft
2012-07-20 00:08 . 2012-07-20 22:41 -------- d-----w- c:\documents and settings\Asus\Local Settings\Application Data\ytpdlvag
2012-07-12 11:28 . 2012-07-12 11:28 9822920 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-07-05 00:14 . 2012-07-05 00:14 770384 ----a-w- c:\program files\Mozilla Firefox\msvcr100.dll
2012-07-05 00:14 . 2012-07-05 00:14 421200 ----a-w- c:\program files\Mozilla Firefox\msvcp100.dll
2012-06-25 12:11 . 2012-06-25 13:14 -------- d-----w- c:\program files\ZAR
2012-06-24 19:57 . 2012-06-25 11:26 -------- d-----w- c:\program files\Bitmansoft
2012-06-24 19:50 . 2012-06-24 19:50 -------- d-----w- c:\windows\Sun
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 11:29 . 2012-05-26 10:23 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-12 11:29 . 2012-05-26 10:23 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-13 13:19 . 2006-03-15 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2012-05-25 14:58 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2006-03-15 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2006-03-15 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 14:19 . 2009-08-06 18:24 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 14:19 . 2012-05-25 14:33 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 14:19 . 2012-05-25 14:33 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 14:19 . 2012-05-25 14:33 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 14:19 . 2009-08-06 18:24 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 14:19 . 2012-05-25 14:33 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 14:19 . 2012-05-25 14:33 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 14:19 . 2009-08-06 18:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 14:19 . 2009-08-06 18:24 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 14:19 . 2006-03-15 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 14:19 . 2009-08-06 18:24 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 14:19 . 2012-05-25 14:33 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 14:19 . 2012-05-25 14:33 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2006-03-15 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2006-03-15 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2006-03-15 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2006-03-15 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2006-03-15 12:00 385024 ------w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2006-03-15 12:00 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-03 22:59 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2012-05-25 14:26 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-05 00:13 . 2012-05-26 10:43 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((   [email protected]_22.41.43   )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-21 11:16 . 2012-07-21 11:16 16384              c:\windows\Temp\Perflib_Perfdata_ab8.dat
+ 2012-07-21 11:18 . 2012-07-21 11:18 724996              c:\windows\Temp\_asw_aisI.tm~a03036\sig.bin
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Azureus"="c:\program files\Vuze\Azureus.exe" [2011-04-27 232896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"VersatoMs"="c:\program files\MagicMus\MulMouse.exe" [2004-06-17 282624]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-02-07 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"SMSERIAL"="sm56hlpr.exe" [2006-01-20 544768]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2011-01-12 1400832]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-01-12 1210640]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-04-04 05:53 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 10:07 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20/07/2012 21:04 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20/07/2012 21:04 17744]
R2 MUsbFltr;USB WTMouse Filter Service;c:\windows\system32\drivers\MUsbFltr.sys [22/03/2004 13:45 6528]
R3 NETwLx32;    Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [26/05/2012 10:07 6609920]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [26/05/2012 11:23 250056]
S3 DUBE100B;D-Link DUB-E100 USB 2.0 Fast Ethernet Adapter;c:\windows\system32\drivers\DUBE100B.sys [19/04/2012 15:50 18560]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [20/07/2012 19:14 40776]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [26/05/2012 11:43 113120]
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-26 11:29]
.
2012-06-17 c:\windows\Tasks\MixPadReminder.job
- c:\program files\NCH Software\MixPad\mixpad.exe [2012-06-07 11:50]
.
2012-06-17 c:\windows\Tasks\prismShakeIcon.job
- c:\program files\NCH Software\Prism\prism.exe [2012-06-07 11:51]
.
2012-06-20 c:\windows\Tasks\SwitchReminder.job
- c:\program files\NCH Software\Switch\switch.exe [2012-06-07 11:50]
.
2012-07-21 c:\windows\Tasks\User_Feed_Synchronization-{8B2072BF-545A-419E-A66B-9CB2F1668F00}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
2012-06-17 c:\windows\Tasks\WavePadReminder.job
- c:\program files\NCH Software\WavePad\wavepad.exe [2012-06-07 11:50]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://uk.ask.com/?l=dis&o=APN10112&gct=hp
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
FF - ProfilePath - c:\documents and settings\Asus\Application Data\Mozilla\Firefox\Profiles\3uiblgot.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://sn114w.snt114.mail.live.com/mail/InboxLight.aspx?n=1788983327&fid=1&fav=1#n=1466668558&fid=1&fav=1
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B9aae389a-e770-4f1f-a196-7f5ac1298350%7D&mid=bc653f889ea147d0b143d151987802fd-d34c8cfae782fea4cf013a1bd96b68f99ddc7e29&ds=AVG&v=11.0.0.9&lang=en&pr=fr&d=2012-05-28%2009%3A52%3A58&sap=ku&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-21 12:16
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ... 
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]
"value"="?\05\01\1c\10\0c\10?"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(896)
c:\windows\system32\netprovcredman.dll
.
- - - - - - - > 'explorer.exe'(2276)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\sm56hlpr.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2012-07-21  12:21:01 - machine was rebooted
ComboFix-quarantined-files.txt  2012-07-21 11:20
ComboFix2.txt  2012-07-20 22:46
.
Pre-Run: 2,082,713,600 bytes free
Post-Run: 1,898,356,736 bytes free
.
- - End Of File - - 2E8995D62EBECD91AF652F435BF14D60

Edited by elielieli, 21 November 2015 - 08:21 PM.

  • 0

#14
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,012 posts
  • MVP

The Combofix log is very old.  Did you not get a new one this time?


  • 0

#15
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

This was the only file in c drive after running it.

I just tried running it again , but got this message : The drive or network connection that the shortcut 'shortcut to combo fix' refers  to is unavailable.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP