Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-09-2013 01 Ran by Administrator (administrator) on COMPAQ-NC2400 on 13-09-2013 20:58:21 Running from C:\Documents and Settings\Administrator\Desktop\Fixitpc2 Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US) Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\WINDOWS\System32\SCardSvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe (Hewlett-Packard Corporation) C:\WINDOWS\system32\AccelerometerSt.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe () C:\WINDOWS\SMINST\Scheduler.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE (Microsoft Corporation) C:\WINDOWS\system32\mqtgsvc.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MsmqIntCert] - regsvr32 /s mqrt.dll HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\Core\smax4pnp.exe [925696 2005-05-20] (Analog Devices, Inc.) HKLM\...\Run: [SoundMAX] - C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [716800 2005-05-07] (Analog Devices, Inc.) HKLM\...\Run: [AccelerometerSysTrayApplet] - C:\WINDOWS\system32\AccelerometerSt.exe [53248 2006-01-17] (Hewlett-Packard Corporation) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [761946 2006-03-31] (Synaptics, Inc.) HKLM\...\Run: [igfxhkcmd] - C:\WINDOWS\system32\hkcmd.exe [ ] () HKLM\...\Run: [igfxpers] - C:\WINDOWS\system32\igfxpers.exe [118784 2006-03-14] (Intel Corporation) HKLM\...\Run: [QlbCtrl] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [131072 2006-05-08] ( Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [Cpqset] - C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe [40960 2006-05-02] () HKLM\...\Run: [Recguard] - C:\WINDOWS\Sminst\Recguard.exe [1187840 2005-12-21] () HKLM\...\Run: [Reminder] - C:\WINDOWS\Creator\Remind_XP.exe [806912 2006-03-10] () HKLM\...\Run: [Scheduler] - C:\WINDOWS\SMINST\Scheduler.exe [892928 2006-02-15] () HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-11] (Avira Operations GmbH & Co. KG) Winlogon\Notify\crypt32chain: C:\Windows\system32\crypt32.dll (Microsoft Corporation) Winlogon\Notify\cryptnet: C:\Windows\system32\cryptnet.dll (Microsoft Corporation) Winlogon\Notify\cscdll: C:\Windows\system32\cscdll.dll (Microsoft Corporation) Winlogon\Notify\dimsntfy: C:\Windows\System32\dimsntfy.dll (Microsoft Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\ScCertProp: C:\Windows\system32\wlnotify.dll (Microsoft Corporation) Winlogon\Notify\Schedule: C:\Windows\system32\wlnotify.dll (Microsoft Corporation) Winlogon\Notify\sclgntfy: C:\Windows\system32\sclgntfy.dll (Microsoft Corporation) Winlogon\Notify\SensLogn: C:\Windows\system32\WlNotify.dll (Microsoft Corporation) Winlogon\Notify\termsrv: C:\Windows\system32\wlnotify.dll (Microsoft Corporation) Winlogon\Notify\WgaLogon: C:\Windows\system32\WgaLogon.dll (Microsoft Corporation) Winlogon\Notify\wlballoon: C:\Windows\system32\wlnotify.dll (Microsoft Corporation) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ==================== Internet (Whitelisted) ==================== ProxyServer: 10.10.30.40:8080 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 24 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 10.0.0.2 Tcpip\..\Interfaces\{CE60A2E6-D776-4D34-8770-A13B0015DD8B}: [NameServer]192.168.1.254 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q63hkmob.default FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ========================== Services (Whitelisted) ================= S3 AddFiltr; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe [98304 2006-05-08] (Hewlett-Packard Development Company, L.P.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-11] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-11] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-11] (Avira Operations GmbH & Co. KG) R2 MSMQ; C:\WINDOWS\system32\mqsvc.exe [4608 2008-04-14] (Microsoft Corporation) R2 MSMQTriggers; C:\WINDOWS\system32\mqtgsvc.exe [117248 2008-04-14] (Microsoft Corporation) S2 PCA; C:\WINDOWS\SMINST\PCAngel.exe [294912 2006-01-12] (SoftThinks) R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" ==================== Drivers (Whitelisted) ==================== R3 AEAudioService; C:\Windows\System32\drivers\AEAudio.sys [152960 2005-06-07] (Andrea Electronics Corporation) R3 ATSWPDRV; C:\Windows\System32\DRIVERS\ATSwpDrv.sys [130432 2006-03-30] (AuthenTec, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-11] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-11] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-09-11] (Avira Operations GmbH & Co. KG) R3 b57w2k; C:\Windows\System32\DRIVERS\b57xp32.sys [142720 2006-01-12] (Broadcom Corporation) R3 BTKRNL; C:\Windows\System32\DRIVERS\btkrnl.sys [1342602 2006-02-27] (Broadcom Corporation.) R3 BTWUSB; C:\Windows\System32\Drivers\btwusb.sys [57096 2006-02-27] (Broadcom Corporation.) S3 BulkUsb; C:\Windows\System32\Drivers\VoIPUSBDriver.sys [149504 2005-09-16] (Windows (R) Server 2003 DDK provider) S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2011-06-02] () R1 eabfiltr; C:\Windows\System32\DRIVERS\eabfiltr.sys [7808 2005-09-19] (Hewlett-Packard Development Company, L.P.) S3 eabusb; C:\Windows\System32\DRIVERS\eabusb.sys [5760 2005-09-19] (Hewlett-Packard Development Company, L.P.) R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () R3 GTIPCI21; C:\Windows\System32\DRIVERS\gtipci21.sys [87808 2006-02-28] (Texas Instruments) R3 HSFHWAZL; C:\Windows\System32\DRIVERS\HSFHWAZL.sys [201600 2006-01-30] (Conexant Systems, Inc.) R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.sys [1035008 2006-01-30] (Conexant Systems, Inc.) R3 ialm; C:\Windows\System32\DRIVERS\ialmnt5.sys [1402559 2006-03-14] (Intel Corporation) R3 IFXTPM; C:\Windows\System32\DRIVERS\IFXTPM.SYS [36608 2006-04-25] (Infineon Technologies AG) S3 ivusb; C:\Windows\System32\DRIVERS\ivusb.sys [25112 2010-07-29] (Initio Corporation) R3 MQAC; C:\WINDOWS\system32\drivers\mqac.sys [92544 2008-04-14] (Microsoft Corporation) R3 NETwLx32; C:\Windows\System32\DRIVERS\NETwLx32.sys [6609920 2010-10-07] (Intel Corporation) S3 PortTalk; C:\Windows\System32\Drivers\PortTalk.sys [3567 2002-01-12] (Beyond Logic http://www.beyondlogic.org) S3 prwntdrv; C:\WINDOWS\system32\prwntdrv.sys [13064 2010-08-25] () S3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation) S3 SMCIRDA; C:\Windows\System32\DRIVERS\smcirda.sys [35913 2001-08-17] (SMC) R0 speedfan; C:\Windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-11] (Avira GmbH) S3 w39n51; C:\Windows\System32\DRIVERS\w39n51.sys [1428096 2006-01-19] (Intel® Corporation) U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-13 20:55 - 2013-09-13 20:55 - 00000000 ____D C:\FRST 2013-09-11 15:57 - 2013-09-13 20:54 - 00000000 ____D C:\Documents and Settings\Administrator\Desktop\Fixitpc2 2013-09-11 09:40 - 2013-09-11 09:40 - 00114688 _____ (SoftThinks) C:\WINDOWS\system32\chg.exe 2013-09-11 08:49 - 2013-09-11 08:52 - 00012734 _____ C:\WINDOWS\KB2870699-IE8.log 2013-09-11 08:48 - 2013-09-11 08:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876315$ 2013-09-11 08:48 - 2013-09-11 08:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876217$ 2013-09-11 08:47 - 2013-09-11 08:47 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2864063$ 2013-09-11 08:36 - 2013-09-11 08:36 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\TeamViewer 8 2013-09-11 08:35 - 2013-09-11 08:36 - 00000815 _____ C:\Documents and Settings\All Users\Desktop\TeamViewer 8.lnk 2013-09-11 07:50 - 2013-09-11 07:50 - 97063418 _____ C:\WINDOWS\system32\䰎ɻ咜7 2013-09-11 03:13 - 2013-09-11 08:49 - 00170284 _____ C:\WINDOWS\KB2876315.log 2013-09-11 03:11 - 2013-09-11 08:48 - 00169295 _____ C:\WINDOWS\KB2876217.log 2013-09-11 03:07 - 2013-09-11 08:47 - 00172276 _____ C:\WINDOWS\KB2864063.log 2013-09-11 01:52 - 2013-09-11 01:52 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Avira 2013-09-11 01:49 - 2013-09-11 01:49 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\APN 2013-09-11 01:44 - 2013-09-11 01:44 - 00001707 _____ C:\Documents and Settings\All Users\Desktop\Avira Control Center.lnk 2013-09-11 01:44 - 2013-09-11 01:44 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Avira 2013-09-11 01:41 - 2013-09-11 01:39 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys 2013-09-11 01:41 - 2013-09-11 01:39 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys 2013-09-11 01:40 - 2013-09-11 01:40 - 00000000 ____D C:\Program Files\Avira 2013-09-11 01:40 - 2013-09-11 01:39 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2013-09-11 01:40 - 2013-09-11 01:39 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2013-09-04 19:00 - 2013-09-04 19:00 - 00010874 _____ C:\UsbFix [Listing 4 ] COMPAQ-NC2400.txt 2013-09-04 18:20 - 2013-09-04 18:20 - 95863165 _____ C:\WINDOWS\system32\墠咤7 2013-09-03 22:35 - 2013-09-05 22:25 - 00000000 ____D C:\Documents and Settings\Administrator\Desktop\Fixitpc 2013-09-03 19:37 - 2013-09-03 19:41 - 00004743 _____ C:\UsbFix [Scan 1] COMPAQ-NC2400.txt 2013-09-03 19:30 - 2013-09-03 19:31 - 00004737 _____ C:\UsbFix [Listing 2 ] COMPAQ-NC2400.txt 2013-09-03 19:27 - 2013-09-03 19:27 - 00004659 _____ C:\UsbFix [Listing 1 ] COMPAQ-NC2400.txt 2013-08-28 08:40 - 2013-08-28 08:41 - 00004954 _____ C:\WINDOWS\KB2834902-v2.log 2013-08-28 08:40 - 2013-08-28 08:40 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834902-v2_WM10$ 2013-08-20 21:29 - 2013-08-20 21:30 - 00020379 _____ C:\WINDOWS\KB2862772-IE8.log 2013-08-20 21:24 - 2013-08-20 21:24 - 00013178 _____ C:\WINDOWS\KB2863058.log 2013-08-20 21:24 - 2013-08-20 21:24 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$ 2013-08-20 21:24 - 2013-08-20 21:24 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$ 2013-08-20 21:24 - 2013-08-20 21:24 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$ 2013-08-20 21:23 - 2013-08-20 21:23 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$ 2013-08-19 01:45 - 2013-08-20 20:22 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-19 00:52 - 2013-08-20 21:24 - 00026431 _____ C:\WINDOWS\KB2859537.log 2013-08-19 00:52 - 2013-08-20 21:24 - 00025527 _____ C:\WINDOWS\KB2850869.log 2013-08-14 01:22 - 2013-08-14 01:22 - 06090842 _____ C:\Documents and Settings\Administrator\My Documents\2013-08-14_01_21_DRW_CR.rsf ==================== One Month Modified Files and Folders ======= 2013-09-13 20:55 - 2013-09-13 20:55 - 00000000 ____D C:\FRST 2013-09-13 20:55 - 2012-11-03 14:01 - 00000424 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{096449AF-03CB-43F4-A146-141A58EEE1DB}.job 2013-09-13 20:54 - 2013-09-11 15:57 - 00000000 ____D C:\Documents and Settings\Administrator\Desktop\Fixitpc2 2013-09-13 20:53 - 2004-08-07 15:19 - 01904836 _____ C:\WINDOWS\WindowsUpdate.log 2013-09-13 20:52 - 2012-06-13 21:10 - 00000438 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{0529E6A0-E2E3-4B3B-B4CA-CDF602251560}.job 2013-09-13 20:48 - 2012-06-13 22:49 - 00000000 ____D C:\Documents and Settings\Administrator\My Documents\Pobieranie 2013-09-11 15:25 - 2012-06-14 00:01 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-09-11 15:15 - 2004-08-07 15:19 - 00031938 _____ C:\WINDOWS\SchedLgU.Txt 2013-09-11 09:46 - 2004-08-07 15:19 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl 2013-09-11 09:41 - 2006-07-05 12:39 - 00000000 ____D C:\WINDOWS\SMINST 2013-09-11 09:40 - 2013-09-11 09:40 - 00114688 _____ (SoftThinks) C:\WINDOWS\system32\chg.exe 2013-09-11 09:39 - 2004-08-07 15:19 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-09-11 09:38 - 2004-08-07 15:07 - 00160344 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-09-11 09:03 - 2006-07-05 11:58 - 00000000 ____D C:\Documents and Settings\Administrator 2013-09-11 09:03 - 2004-08-07 15:19 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini 2013-09-11 08:52 - 2013-09-11 08:49 - 00012734 _____ C:\WINDOWS\KB2870699-IE8.log 2013-09-11 08:52 - 2004-08-07 15:18 - 01527639 _____ C:\WINDOWS\iis6.log 2013-09-11 08:52 - 2004-08-07 15:18 - 00634912 _____ C:\WINDOWS\tsoc.log 2013-09-11 08:52 - 2004-08-07 15:07 - 00470939 _____ C:\WINDOWS\comsetup.log 2013-09-11 08:52 - 2004-08-07 15:07 - 00285391 _____ C:\WINDOWS\ntdtcsetup.log 2013-09-11 08:52 - 2004-08-07 15:07 - 00076145 _____ C:\WINDOWS\ocmsn.log 2013-09-11 08:52 - 2004-08-07 15:07 - 00069559 _____ C:\WINDOWS\tabletoc.log 2013-09-11 08:52 - 2004-08-07 15:07 - 00001374 _____ C:\WINDOWS\imsins.log 2013-09-11 08:52 - 2004-08-07 15:00 - 01370498 _____ C:\WINDOWS\FaxSetup.log 2013-09-11 08:52 - 2004-08-07 15:00 - 00671867 _____ C:\WINDOWS\ocgen.log 2013-09-11 08:52 - 2004-08-07 15:00 - 00240719 _____ C:\WINDOWS\netfxocm.log 2013-09-11 08:52 - 2004-08-07 15:00 - 00095874 _____ C:\WINDOWS\MedCtrOC.log 2013-09-11 08:52 - 2004-08-07 15:00 - 00068954 _____ C:\WINDOWS\msgsocm.log 2013-09-11 08:52 - 2004-08-07 14:59 - 00378518 _____ C:\WINDOWS\msmqinst.log 2013-09-11 08:51 - 2006-07-05 12:19 - 00175850 _____ C:\WINDOWS\updspapi.log 2013-09-11 08:50 - 2012-06-13 22:08 - 00000000 ____D C:\WINDOWS\ie8updates 2013-09-11 08:49 - 2013-09-11 03:13 - 00170284 _____ C:\WINDOWS\KB2876315.log 2013-09-11 08:49 - 2004-08-07 15:07 - 00001374 _____ C:\WINDOWS\imsins.BAK 2013-09-11 08:48 - 2013-09-11 08:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876315$ 2013-09-11 08:48 - 2013-09-11 08:48 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876217$ 2013-09-11 08:48 - 2013-09-11 03:11 - 00169295 _____ C:\WINDOWS\KB2876217.log 2013-09-11 08:47 - 2013-09-11 08:47 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2864063$ 2013-09-11 08:47 - 2013-09-11 03:07 - 00172276 _____ C:\WINDOWS\KB2864063.log 2013-09-11 08:45 - 2013-07-23 01:11 - 00000000 ____D C:\WINDOWS\system32\MRT 2013-09-11 08:36 - 2013-09-11 08:36 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\TeamViewer 8 2013-09-11 08:36 - 2013-09-11 08:35 - 00000815 _____ C:\Documents and Settings\All Users\Desktop\TeamViewer 8.lnk 2013-09-11 08:30 - 2012-06-13 22:17 - 76725432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2013-09-11 07:50 - 2013-09-11 07:50 - 97063418 _____ C:\WINDOWS\system32\䰎ɻ咜7 2013-09-11 06:38 - 2013-03-24 18:47 - 00000000 ____D C:\Documents and Settings\Administrator\Doctor Web 2013-09-11 02:28 - 2012-06-14 00:01 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2013-09-11 02:28 - 2012-06-14 00:01 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2013-09-11 01:52 - 2013-09-11 01:52 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Avira 2013-09-11 01:49 - 2013-09-11 01:49 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\APN 2013-09-11 01:44 - 2013-09-11 01:44 - 00001707 _____ C:\Documents and Settings\All Users\Desktop\Avira Control Center.lnk 2013-09-11 01:44 - 2013-09-11 01:44 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Avira 2013-09-11 01:40 - 2013-09-11 01:40 - 00000000 ____D C:\Program Files\Avira 2013-09-11 01:40 - 2012-11-03 13:55 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Avira 2013-09-11 01:39 - 2013-09-11 01:41 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys 2013-09-11 01:39 - 2013-09-11 01:41 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys 2013-09-11 01:39 - 2013-09-11 01:40 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2013-09-11 01:39 - 2013-09-11 01:40 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2013-09-05 22:29 - 2004-08-07 07:57 - 00000216 _____ C:\WINDOWS\wiadebug.log 2013-09-05 22:28 - 2004-08-07 15:19 - 00983455 _____ C:\WINDOWS\setupapi.log 2013-09-05 22:25 - 2013-09-03 22:35 - 00000000 ____D C:\Documents and Settings\Administrator\Desktop\Fixitpc 2013-09-05 22:11 - 2004-08-07 07:57 - 00000048 _____ C:\WINDOWS\wiaservc.log 2013-09-05 18:14 - 2006-07-05 11:58 - 00000000 ____D C:\WINDOWS\system32\Restore 2013-09-04 19:00 - 2013-09-04 19:00 - 00010874 _____ C:\UsbFix [Listing 4 ] COMPAQ-NC2400.txt 2013-09-04 18:20 - 2013-09-04 18:20 - 95863165 _____ C:\WINDOWS\system32\墠咤7 2013-09-03 19:41 - 2013-09-03 19:37 - 00004743 _____ C:\UsbFix [Scan 1] COMPAQ-NC2400.txt 2013-09-03 19:31 - 2013-09-03 19:30 - 00004737 _____ C:\UsbFix [Listing 2 ] COMPAQ-NC2400.txt 2013-09-03 19:27 - 2013-09-03 19:27 - 00004659 _____ C:\UsbFix [Listing 1 ] COMPAQ-NC2400.txt 2013-08-31 14:33 - 2013-07-29 23:47 - 00000000 ____D C:\Documents and Settings\All Users\Documents\FreeBurner 2013-08-31 14:33 - 2013-07-29 23:47 - 00000000 ____D C:\Documents and Settings\All Users\Documents\FreeBurner 2013-08-31 14:33 - 2013-07-29 23:47 - 00000000 ____D C:\Documents and Settings\All Users\Documents\FreeBurner 2013-08-31 14:33 - 2013-07-29 23:47 - 00000000 ____D C:\Documents and Settings\All Users\Documents\FreeBurner 2013-08-31 14:33 - 2013-07-29 23:47 - 00000000 ____D C:\Documents and Settings\All Users\Documents\FreeBurner 2013-08-31 14:33 - 2013-07-29 23:47 - 00000000 ____D C:\Documents and Settings\All Users\Documents\FreeBurner 2013-08-28 08:41 - 2013-08-28 08:40 - 00004954 _____ C:\WINDOWS\KB2834902-v2.log 2013-08-28 08:40 - 2013-08-28 08:40 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834902-v2_WM10$ 2013-08-27 08:45 - 2013-05-07 21:10 - 00001720 ____H C:\Documents and Settings\Administrator\My Documents\Default.rdp 2013-08-23 17:36 - 2013-04-02 20:45 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\CallingID 2013-08-23 02:17 - 2012-09-24 02:45 - 00000793 _____ C:\Documents and Settings\Administrator\.Xauthority 2013-08-23 02:17 - 2012-09-24 02:43 - 00000000 ____D C:\Documents and Settings\Administrator\.nx 2013-08-20 21:47 - 2006-07-05 11:58 - 00000000 ____D C:\WINDOWS\Microsoft.NET 2013-08-20 21:36 - 2012-06-13 19:06 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-20 21:30 - 2013-08-20 21:29 - 00020379 _____ C:\WINDOWS\KB2862772-IE8.log 2013-08-20 21:24 - 2013-08-20 21:24 - 00013178 _____ C:\WINDOWS\KB2863058.log 2013-08-20 21:24 - 2013-08-20 21:24 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$ 2013-08-20 21:24 - 2013-08-20 21:24 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$ 2013-08-20 21:24 - 2013-08-20 21:24 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$ 2013-08-20 21:24 - 2013-08-19 00:52 - 00026431 _____ C:\WINDOWS\KB2859537.log 2013-08-20 21:24 - 2013-08-19 00:52 - 00025527 _____ C:\WINDOWS\KB2850869.log 2013-08-20 21:24 - 2012-06-13 22:10 - 00023522 _____ C:\WINDOWS\system32\TZLog.log 2013-08-20 21:23 - 2013-08-20 21:23 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$ 2013-08-20 21:21 - 2004-08-07 15:14 - 00516642 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2013-08-20 20:22 - 2013-08-19 01:45 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-20 20:19 - 2013-03-24 16:55 - 00000000 ____D C:\WINDOWS\system32\NtmsData 2013-08-20 20:18 - 2006-07-05 11:58 - 00000000 ____D C:\WINDOWS\Registration 2013-08-14 01:22 - 2013-08-14 01:22 - 06090842 _____ C:\Documents and Settings\Administrator\My Documents\2013-08-14_01_21_DRW_CR.rsf Some content of TEMP: ==================== C:\Documents and Settings\Administrator\Local Settings\Temp\Checkupdate.exe C:\Documents and Settings\Administrator\Local Settings\Temp\Foxit Reader Updater.exe C:\Documents and Settings\Administrator\Local Settings\Temp\gcapi_dll.dll C:\Documents and Settings\Administrator\Local Settings\Temp\gtapi_signed.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== End Of Log ============================