Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:04-05-2014 Ran by johny (administrator) on JOHNY-16841E98D on 04-05-2014 20:56:56 Running from C:\Documents and Settings\johny\My Documents\Downloads Microsoft Windows XP Home Edition Service Pack 3, v.3264 (X86) OS Language: English(US) Internet Explorer Version 6 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation ) C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe (Agere Systems) C:\WINDOWS\AGRSMMSG.exe (ELANTECH Devices Corp.) C:\Program Files\Elantech\Ktp.exe () C:\WINDOWS\system32\tsnp2std.exe (Sonix) C:\WINDOWS\vsnp2std.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (GG Network S.A.) C:\Documents and Settings\johny\Local Settings\Application Data\GG\Application\gghub.exe (GG Network S.A.) C:\Documents and Settings\johny\Local Settings\Application Data\GG\Application\ggapp.exe (Intel Corporation) C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe (GG Network S.A.) C:\Documents and Settings\johny\Local Settings\Application Data\GG\Application\ggdrive\ggdrive.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (GG Network S.A.) C:\Documents and Settings\johny\Local Settings\Application Data\GG\Application\xulrunner\gghub.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [NvCplDaemon] => C:\WINDOWS\system32\NvCpl.dll [7405568 2006-02-08] (NVIDIA Corporation) HKLM\...\Run: [nwiz] => nwiz.exe /install HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16143872 2006-04-17] (Realtek Semiconductor Corp.) HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [AzMixerSel] => C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [53248 2005-08-25] (Realtek Semiconductor Corp.) HKLM\...\Run: [AGRSMMSG] => C:\WINDOWS\AGRSMMSG.exe [88204 2005-12-12] (Agere Systems) HKLM\...\Run: [KTPWare] => C:\Program Files\Elantech\ktp.exe [512000 2006-03-28] (ELANTECH Devices Corp.) HKLM\...\Run: [tsnp2std] => C:\WINDOWS\system32\tsnp2std.exe [331776 2006-06-14] () HKLM\...\Run: [snp2std] => C:\WINDOWS\vsnp2std.exe [675840 2006-05-15] (Sonix) HKLM\...\Run: [IntelZeroConfig] => C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [667718 2006-04-14] (Intel Corporation) HKLM\...\Run: [IntelWireless] => C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [602182 2006-04-14] (Intel Corporation) HKLM\...\Run: [EOUApp] => C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe [569413 2006-04-14] (Intel Corporation) HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard) HKLM\...\Run: [hpqSRMon] => C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [80896 2007-08-22] (Hewlett-Packard) HKU\S-1-5-21-789336058-113007714-725345543-1004\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [20724384 2014-01-14] (Skype Technologies S.A.) HKU\S-1-5-21-789336058-113007714-725345543-1004\...\Run: [GG] => C:\Documents and Settings\johny\Local Settings\Application Data\GG\Application\gghub.exe [4023360 2014-04-13] (GG Network S.A.) HKU\S-1-5-21-789336058-113007714-725345543-1004\...\Run: [Tiny download manager] => "C:\Documents and Settings\johny\Local Settings\Application Data\DM\TinyDM.exe" /M SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, credssp.dll Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope value is missing. BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.6.6 192.168.1.1 FireFox: ======== FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) ========================== Services (Whitelisted) ================= R2 S24EventMonitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [540745 2006-04-14] (Intel Corporation ) ==================== Drivers (Whitelisted) ==================== R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [21275 2014-02-01] (Meetinghouse Data Communications) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2007-11-30] (Microsoft Corporation) R3 EMSCR; C:\WINDOWS\System32\DRIVERS\EMS7SK.sys [61056 2006-03-23] (ENE Technology Inc.) R3 ESDCR; C:\WINDOWS\System32\DRIVERS\ESD7SK.sys [37888 2006-03-23] (ENE Technology Inc.) R3 Ktp; C:\WINDOWS\System32\DRIVERS\Ktp.sys [27904 2006-03-17] (ELANTECH Devices Corp.) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2007-11-30] (Microsoft Corporation) R2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [13568 2006-04-14] (Intel Corporation) R3 SNP2STD; C:\WINDOWS\System32\DRIVERS\snp2sxp.sys [10304384 2006-05-23] () R3 w39n51; C:\WINDOWS\System32\DRIVERS\w39n51.sys [1429632 2006-04-04] (Intel® Corporation) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S4 IntelIde; No ImagePath U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2007-11-30] (Microsoft Corporation) U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-30 15:19 - 2014-05-02 16:04 - 00000778 _____ () C:\FRST.txt 2014-04-30 15:19 - 2014-04-30 15:19 - 00000814 _____ () C:\Documents and Settings\johny\Desktop\FRST.txt 2014-04-30 15:16 - 2014-04-30 15:16 - 00001274 _____ () C:\WINDOWS\KB2618444-IE8.log 2014-04-30 15:15 - 2014-03-31 03:51 - 88028728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-04-30 15:14 - 2014-04-30 15:14 - 00000883 _____ () C:\WINDOWS\KB932823-v3.log 2014-04-30 15:12 - 2014-04-30 15:13 - 00030054 _____ () C:\WINDOWS\ie8_main.log 2014-04-30 15:09 - 2014-04-30 15:09 - 00000000 ___SD () C:\Documents and Settings\johny\UserData 2014-04-30 15:04 - 2014-04-30 15:04 - 00000000 ____D () C:\FRST-OlderVersion 2014-04-30 15:03 - 2014-04-30 15:03 - 00000076 _____ () C:\New Text Document.txt 2014-04-29 14:54 - 2014-04-29 14:54 - 00000000 ____D () C:\AdwCleaner 2014-04-29 14:54 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll 2014-04-29 14:24 - 2014-05-02 22:12 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-04-29 14:24 - 2014-04-29 14:24 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2014-04-29 14:24 - 2014-04-29 14:24 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2014-04-29 14:24 - 2014-04-29 14:24 - 00000000 ____D () C:\WINDOWS\system32\config\RCCBakup 2014-04-29 14:19 - 2014-04-29 14:22 - 00000000 ____D () C:\Documents and Settings\johny\Local Settings\Application Data\cache 2014-04-29 14:18 - 2014-04-25 17:01 - 01090218 _____ (AnyProtect.com) C:\Documents and Settings\johny\Local Settings\Application Data\AnyProtectScannerSetup.exe 2014-04-29 14:14 - 2014-04-30 15:19 - 00000000 ____D () C:\FRST 2014-04-29 14:13 - 2014-04-30 15:04 - 01050624 _____ (Farbar) C:\FRST.exe 2014-04-29 14:11 - 2014-04-29 14:11 - 00383796 _____ () C:\Documents and Settings\johny\My Documents\windowscodecs.zip 2014-04-29 14:11 - 2008-04-15 08:30 - 00712704 _____ (Microsoft Corporation) C:\windowscodecs.dll 2014-04-29 14:09 - 2014-04-29 14:09 - 01107768 _____ (AnyProtect.com) C:\Documents and Settings\johny\Local Settings\Application Data\nsy127.tmp 2014-04-29 14:08 - 2014-04-30 15:12 - 00000000 ____D () C:\Documents and Settings\johny\Local Settings\Application Data\DM 2014-04-27 23:42 - 2014-04-27 23:42 - 00000670 _____ () C:\Documents and Settings\johny\My Documents\SystemLook.txt 2014-04-27 23:23 - 2014-04-27 23:23 - 00000903 _____ () C:\DelFix.txt 2014-04-27 22:51 - 2014-04-27 23:00 - 00000216 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job 2014-04-24 19:37 - 2014-04-24 19:37 - 00005690 _____ () C:\WINDOWS\KB2934207.log 2014-04-24 19:37 - 2014-04-24 19:37 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2934207$ 2014-04-24 19:18 - 2014-02-26 03:59 - 00013312 ____N (Microsoft Corporation) C:\WINDOWS\system32\xp_eos.exe 2014-04-24 19:18 - 2014-02-26 03:59 - 00013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xp_eos.exe 2014-04-20 21:24 - 2014-05-04 20:52 - 00000000 ____D () C:\Documents and Settings\johny\Application Data\Skype 2014-04-20 21:24 - 2014-04-20 21:24 - 00000000 ____D () C:\Documents and Settings\johny\Local Settings\Application Data\Skype 2014-04-20 21:22 - 2014-04-20 21:22 - 00000269 _____ () C:\WINDOWS\system32\spupdwxp.log 2014-04-20 21:22 - 2014-04-20 21:22 - 00000187 _____ () C:\WINDOWS\spupdsvc.log.1.log 2014-04-20 21:17 - 2014-04-20 21:17 - 00000000 ____D () C:\WINDOWS\system32\bits 2014-04-20 21:17 - 2014-04-20 21:17 - 00000000 ____D () C:\WINDOWS\l2schemas 2014-04-20 21:17 - 2007-12-01 00:27 - 00023040 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ativmvxx.ax 2014-04-20 21:17 - 2007-12-01 00:27 - 00009728 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ativdaxx.ax 2014-04-20 21:17 - 2007-12-01 00:26 - 00346112 ____N (Microsoft Corporation) C:\WINDOWS\system32\windowscodecsext.dll 2014-04-20 21:17 - 2007-12-01 00:26 - 00276992 ____N (Microsoft Corporation) C:\WINDOWS\system32\wmphoto.dll 2014-04-20 21:17 - 2007-12-01 00:26 - 00176640 ____N (Microsoft Corporation) C:\WINDOWS\system32\napstat.exe 2014-04-20 21:17 - 2007-12-01 00:26 - 00121856 ____N (Microsoft Corporation) C:\WINDOWS\system32\xmllite.dll 2014-04-20 21:17 - 2007-12-01 00:26 - 00073796 ____N (Smart Link) C:\WINDOWS\system32\slserv.exe 2014-04-20 21:17 - 2007-12-01 00:26 - 00069120 ____N (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 2014-04-20 21:17 - 2007-12-01 00:26 - 00060416 ____N (Microsoft Corporation) C:\WINDOWS\system32\tzchange.exe 2014-04-20 21:17 - 2007-12-01 00:26 - 00052736 ____N (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 2014-04-20 21:17 - 2007-12-01 00:26 - 00050176 ____N (Microsoft Corporation) C:\WINDOWS\system32\tspkg.dll 2014-04-20 21:17 - 2007-12-01 00:26 - 00033792 ____N (Microsoft Corporation) C:\WINDOWS\system32\mmcperf.exe 2014-04-20 21:17 - 2007-12-01 00:26 - 00032866 ____N (Smart Link) C:\WINDOWS\system32\slrundll.exe 2014-04-20 21:17 - 2007-12-01 00:26 - 00032866 ____N (Smart Link) C:\WINDOWS\slrundll.exe 2014-04-20 21:17 - 2007-12-01 00:26 - 00032768 ____N (Microsoft Corporation) C:\WINDOWS\system32\setupn.exe 2014-04-20 21:17 - 2007-12-01 00:26 - 00028672 ____N (Microsoft Corporation) C:\WINDOWS\system32\verclsid.exe 2014-04-20 21:17 - 2007-12-01 00:25 - 01888992 ____N (ATI Technologies Inc. ) C:\WINDOWS\system32\ati3duag.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 01737856 ____N (Matrox Graphics Inc.) C:\WINDOWS\system32\mtxparhd.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 01306624 ____N (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00870784 ____N (ATI Technologies Inc. ) C:\WINDOWS\system32\ati3d1ag.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00650752 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3ui.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00516768 ____N (ATI Technologies Inc. ) C:\WINDOWS\system32\ativvaxx.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00412160 ____N (Microsoft Corporation) C:\WINDOWS\system32\photometadatahandler.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00397312 ____N (Microsoft Corporation) C:\WINDOWS\system32\mmcex.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00397056 ____N (S3 Graphics, Inc.) C:\WINDOWS\system32\s3gnb.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00377984 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ati2dvaa.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00291328 ____N (Microsoft Corporation) C:\WINDOWS\system32\rhttpaa.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00290816 ____N (Microsoft Corporation) C:\WINDOWS\system32\qagentrt.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00286792 ____N (Smart Link) C:\WINDOWS\system32\slextspk.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00233472 ____N (Microsoft Corporation) C:\WINDOWS\system32\azroles.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00229376 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ati2cqag.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00201728 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ati2dvag.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00193024 ____N (Microsoft Corporation) C:\WINDOWS\system32\napmontr.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00188508 ____N (Smart Link) C:\WINDOWS\system32\slgen.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00184832 ____N (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00184320 ____N (Microsoft Corporation) C:\WINDOWS\system32\microsoft.managementconsole.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00180224 ____N (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00155136 ____N (Microsoft Corporation) C:\WINDOWS\system32\mssha.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00150528 ____N (Microsoft Corporation) C:\WINDOWS\system32\qagent.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00144384 ____N (Microsoft Corporation) C:\WINDOWS\system32\onex.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00136192 ____N (Microsoft Corporation) C:\WINDOWS\system32\aaclient.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00132096 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00126976 ____N (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00106496 ____N (Microsoft Corporation) C:\WINDOWS\system32\mmcfxcommon.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00094208 ____N (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00086016 ____N (Conexant) C:\WINDOWS\system32\mdmxsdk.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00076800 ____N (Microsoft Corporation) C:\WINDOWS\system32\qutil.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00073832 ____N (Smart Link) C:\WINDOWS\system32\slcoinst.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00062464 ____N (Microsoft Corporation) C:\WINDOWS\system32\qcliprov.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00061952 ____N (Microsoft Corporation) C:\WINDOWS\system32\rasqec.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00061440 ____N (Microsoft Corporation) C:\WINDOWS\system32\kmsvc.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00059392 ____N (Microsoft Corporation) C:\WINDOWS\system32\eapqec.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00057856 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3cfg.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00056320 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00048640 ____N (Microsoft Corporation) C:\WINDOWS\system32\dhcpqec.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00040960 ____N (Microsoft Corporation) C:\WINDOWS\system32\eappprxy.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00039936 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3gpclnt.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00039936 ____N (Microsoft Corporation) C:\WINDOWS\system32\dimsroam.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00037376 ____N (Microsoft Corporation) C:\WINDOWS\system32\l2gpstore.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00033792 ____N (Microsoft Corporation) C:\WINDOWS\system32\eapsvc.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00032768 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\ativtmxx.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00032285 ____N (Conexant Systems, Inc.) C:\WINDOWS\system32\hsfcisp2.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00030720 ____N (Microsoft Corporation) C:\WINDOWS\system32\eapolqec.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00030208 ____N (Microsoft Corporation) C:\WINDOWS\system32\napipsec.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00026112 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00019456 ____N (Microsoft Corporation) C:\WINDOWS\system32\dimsntfy.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00012800 ____N (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00009216 ____N (Microsoft Corporation) C:\WINDOWS\system32\dot3dlg.dll 2014-04-20 21:17 - 2007-12-01 00:25 - 00007168 ____N (Microsoft Corporation) C:\WINDOWS\system32\bitsprx4.dll 2014-04-20 21:17 - 2007-12-01 00:22 - 00006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdpash.dll 2014-04-20 21:17 - 2007-12-01 00:22 - 00006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdnepr.dll 2014-04-20 21:17 - 2007-12-01 00:22 - 00006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdiultn.dll 2014-04-20 21:17 - 2007-12-01 00:22 - 00006144 ____N (Microsoft Corporation) C:\WINDOWS\system32\kbdbhc.dll 2014-04-20 21:17 - 2007-11-30 16:38 - 00079872 ____N (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll 2014-04-20 21:17 - 2007-11-30 16:25 - 00675328 ____N (Microsoft Corporation) C:\WINDOWS\system32\xpsp3res.dll 2014-04-20 21:17 - 2007-11-30 15:53 - 00076800 ____N (Microsoft Corporation) C:\WINDOWS\system32\msshavmsg.dll 2014-04-20 21:15 - 2014-04-20 21:15 - 00000000 ____D () C:\WINDOWS\ServicePackFiles 2014-04-20 21:13 - 2007-12-01 00:26 - 00011325 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\vchnt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00025471 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\atv04nt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00021183 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\atv01nt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00017279 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\atv10nt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00015423 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\ch7xxnt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00014143 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\atv06nt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00011359 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\atv02nt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00004255 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv01nt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00003967 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv02nt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00003901 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\siint5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00003775 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv11nt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00003711 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv09nt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00003647 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv07nt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00003615 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv05nt5.dll 2014-04-20 21:13 - 2007-12-01 00:25 - 00003135 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\adv08nt5.dll 2014-04-20 21:13 - 2007-11-30 17:49 - 00030592 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rndismpx.sys 2014-04-20 21:13 - 2007-11-30 17:49 - 00012800 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023x.sys 2014-04-20 21:13 - 2007-11-30 17:42 - 00101120 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthpan.sys 2014-04-20 21:13 - 2007-11-30 17:32 - 00273024 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2014-04-20 21:13 - 2007-11-30 17:32 - 00121984 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys 2014-04-20 21:13 - 2007-11-30 17:32 - 00059136 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys 2014-04-20 21:13 - 2007-11-30 17:32 - 00037888 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthmodem.sys 2014-04-20 21:13 - 2007-11-30 17:32 - 00036480 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthprint.sys 2014-04-20 21:13 - 2007-11-30 17:32 - 00025600 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys 2014-04-20 21:13 - 2007-11-30 17:32 - 00018944 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthusb.sys 2014-04-20 21:13 - 2007-11-30 17:32 - 00017024 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys 2014-04-20 21:13 - 2007-11-30 17:31 - 00046464 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\gagp30kx.sys 2014-04-20 21:13 - 2007-11-30 17:31 - 00044928 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agpcpq.sys 2014-04-20 21:13 - 2007-11-30 17:31 - 00044672 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uagp35.sys 2014-04-20 21:13 - 2007-11-30 17:31 - 00043008 ____N (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\amdagp.sys 2014-04-20 21:13 - 2007-11-30 17:31 - 00042752 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\alim1541.sys 2014-04-20 21:13 - 2007-11-30 17:31 - 00042368 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agp440.sys 2014-04-20 21:13 - 2007-11-30 17:31 - 00042240 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\viaagp.sys 2014-04-20 21:13 - 2007-11-30 17:31 - 00040960 ____N (Silicon Integrated Systems Corporation) C:\WINDOWS\system32\Drivers\sisagp.sys 2014-04-20 21:13 - 2007-11-30 17:31 - 00019200 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidir.sys 2014-04-20 21:13 - 2007-11-30 17:31 - 00005888 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\smbali.sys 2014-04-20 21:13 - 2007-11-30 17:28 - 00014208 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wacompen.sys 2014-04-20 21:13 - 2007-11-30 17:28 - 00012672 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mutohpen.sys 2014-04-20 21:13 - 2007-11-30 17:25 - 00010240 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sffp_mmc.sys 2014-04-20 21:13 - 2007-11-30 17:24 - 00009472 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpdrv.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 01309184 ____N (Smart Link) C:\WINDOWS\system32\Drivers\mtlstrm.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 01041536 ____N (Conexant Systems, Inc.) C:\WINDOWS\system32\Drivers\hsfdpsp2.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 00685056 ____N (Conexant Systems, Inc.) C:\WINDOWS\system32\Drivers\hsfcxts2.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 00404990 ____N (Smart Link) C:\WINDOWS\system32\Drivers\slntamr.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 00220032 ____N (Conexant Systems, Inc.) C:\WINDOWS\system32\Drivers\hsfbs2s2.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 00180360 ____N (Smart Link) C:\WINDOWS\system32\Drivers\ntmtlfax.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 00129535 ____N (Smart Link) C:\WINDOWS\system32\Drivers\slnt7554.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 00126686 ____N (Smart Link) C:\WINDOWS\system32\Drivers\mtlmnt5.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 00095424 ____N (Smart Link) C:\WINDOWS\system32\Drivers\slnthal.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 00013776 ____N (Smart Link) C:\WINDOWS\system32\Drivers\recagent.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 00013240 ____N (Smart Link) C:\WINDOWS\system32\Drivers\slwdmsup.sys 2014-04-20 21:13 - 2007-11-30 16:03 - 00011868 ____N (Conexant) C:\WINDOWS\system32\Drivers\mdmxsdk.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00701440 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati2mtag.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00452736 ____N (Matrox Graphics Inc.) C:\WINDOWS\system32\Drivers\mtxparhm.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00327040 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati2mtaa.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00166912 ____N (S3 Graphics, Inc.) C:\WINDOWS\system32\Drivers\s3gnbm.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00104960 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinrvxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00073216 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atintuxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00063663 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1rvxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00063488 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinxsxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00057856 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinbtxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00056623 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1btxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00052224 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinraxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00036463 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1tuxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00034735 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1xsxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00031744 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinxbxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00030671 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1raxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00029455 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1xbxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00028672 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinsnxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00026367 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1snxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00025471 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\watv10nt.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00022271 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\watv06nt.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00021343 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1ttxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00014336 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinpdxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00013824 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinttxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00013824 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\atinmdxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00012047 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1pdxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00011935 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\wadv11nt.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00011871 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\wadv09nt.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00011807 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\wadv07nt.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00011615 ____N (ATI Technologies Inc.) C:\WINDOWS\system32\Drivers\ati1mdxx.sys 2014-04-20 21:13 - 2007-11-30 15:15 - 00011295 ____N (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\wadv08nt.sys 2014-04-20 21:13 - 2007-04-02 21:36 - 00129045 ____N () C:\WINDOWS\system32\Drivers\cxthsfs2.cty 2014-04-20 21:13 - 2006-12-29 20:21 - 00064352 ____N () C:\WINDOWS\system32\Drivers\ativmc20.cod 2014-04-20 21:13 - 2006-12-29 20:02 - 00067866 ____N () C:\WINDOWS\system32\Drivers\netwlan5.img 2014-04-20 21:10 - 2014-04-20 21:12 - 00000000 __HDC () C:\WINDOWS\$NtServicePackUninstall$ 2014-04-20 21:10 - 2014-04-20 21:10 - 00000557 _____ () C:\WINDOWS\medctroc.Log 2014-04-20 21:08 - 2014-04-20 21:20 - 00455278 _____ () C:\WINDOWS\svcpack.log 2014-04-20 20:19 - 2014-04-20 20:19 - 00000079 _____ () C:\WINDOWS\wininit.ini 2014-04-20 18:00 - 2014-04-20 18:00 - 00026095 _____ () C:\Documents and Settings\johny\My Documents\gmer.txt 2014-04-20 15:35 - 2014-04-20 15:35 - 00049636 _____ () C:\Documents and Settings\johny\My Documents\OTL.Txt 2014-04-20 15:35 - 2014-04-20 15:35 - 00031374 _____ () C:\Documents and Settings\johny\My Documents\Extras.Txt 2014-04-20 15:27 - 2014-04-20 15:27 - 00017282 _____ () C:\Documents and Settings\johny\My Documents\Addition.txt 2014-04-20 15:26 - 2014-04-20 20:26 - 00021378 _____ () C:\Documents and Settings\johny\My Documents\FRST.txt 2014-04-15 20:58 - 2014-04-15 20:58 - 00000000 ____D () C:\Documents and Settings\johny\Start Menu\Programs\Google Chrome 2014-04-13 22:12 - 2014-04-13 22:12 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\GG 2014-04-13 22:10 - 2014-04-20 21:24 - 00030753 _____ () C:\WINDOWS\spupdsvc.log 2014-04-13 22:05 - 2014-04-13 22:05 - 00000000 ____D () C:\Documents and Settings\johny\Application Data\WinRAR 2014-04-13 22:04 - 2014-04-13 22:04 - 00000000 ____D () C:\Program Files\WinRAR 2014-04-13 22:04 - 2014-04-13 22:04 - 00000000 ____D () C:\Documents and Settings\johny\Start Menu\Programs\WinRAR 2014-04-13 22:04 - 2014-04-13 22:04 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR 2014-04-13 21:44 - 2014-04-13 21:45 - 00000970 _____ () C:\WINDOWS\MSCompPackV1Uninst.log 2014-04-13 21:35 - 2014-04-27 23:29 - 00013104 _____ () C:\Documents and Settings\johny\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2014-04-13 21:34 - 2014-04-13 22:06 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard 2014-04-11 19:06 - 2014-04-11 19:06 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack 2014-04-11 19:06 - 2013-08-02 19:29 - 00217176 _____ () C:\WINDOWS\system32\unrar.dll 2014-04-11 19:05 - 2014-04-11 19:06 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack 2014-04-11 19:00 - 2014-04-20 21:17 - 00090083 _____ () C:\WINDOWS\updspapi.log 2014-04-11 18:59 - 2014-04-11 19:00 - 00009266 _____ () C:\WINDOWS\KB926239.log 2014-04-11 18:59 - 2014-04-11 18:59 - 00019672 _____ () C:\WINDOWS\wmp11.log 2014-04-11 18:59 - 2014-04-11 18:59 - 00006758 _____ () C:\WINDOWS\MSCompPackV1.log 2014-04-11 18:59 - 2014-04-11 18:59 - 00000000 __HDC () C:\WINDOWS\$NtUninstallwmp11$ 2014-04-11 18:59 - 2014-04-11 18:59 - 00000000 __HDC () C:\WINDOWS\$NtUninstallMSCompPackV1$ 2014-04-11 18:59 - 2014-04-11 18:59 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB926239$ 2014-04-11 18:59 - 2014-04-11 18:59 - 00000000 ____D () C:\Program Files\Windows Media Connect 2 2014-04-11 18:59 - 2013-09-04 13:28 - 00017272 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsg.dll 2014-04-11 18:58 - 2014-04-11 18:59 - 00029942 _____ () C:\WINDOWS\WMFDist11.log 2014-04-11 18:58 - 2014-04-11 18:58 - 00000000 __HDC () C:\WINDOWS\$NtUninstallWudf01000$ 2014-04-11 18:58 - 2014-04-11 18:58 - 00000000 __HDC () C:\WINDOWS\$NtUninstallWMFDist11$ 2014-04-11 18:58 - 2014-04-11 18:58 - 00000000 ____D () C:\WINDOWS\system32\LogFiles 2014-04-11 18:57 - 2014-04-11 18:58 - 00011013 _____ () C:\WINDOWS\Wudf01000Inst.log 2014-04-11 18:55 - 2014-04-11 18:55 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage 2014-04-11 18:21 - 2014-04-18 16:42 - 00000000 ____D () C:\Documents and Settings\johny\Desktop\foto ==================== One Month Modified Files and Folders ======= 2014-05-04 20:52 - 2014-04-20 21:24 - 00000000 ____D () C:\Documents and Settings\johny\Application Data\Skype 2014-05-04 20:51 - 2014-02-01 22:33 - 00445646 _____ () C:\WINDOWS\WindowsUpdate.log 2014-05-02 22:15 - 2014-02-01 22:58 - 00000884 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-02 22:12 - 2014-04-29 14:24 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-05-02 16:22 - 2014-02-01 23:05 - 00001819 _____ () C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk 2014-05-02 16:04 - 2014-04-30 15:19 - 00000778 _____ () C:\FRST.txt 2014-05-02 16:01 - 2014-02-01 23:19 - 00000000 ____D () C:\Documents and Settings\johny\Application Data\GG 2014-05-02 16:01 - 2014-02-01 22:44 - 00045378 _____ () C:\WINDOWS\system32\nvapps.xml 2014-05-02 16:00 - 2014-02-01 23:28 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-05-02 16:00 - 2014-02-01 23:28 - 00000048 _____ () C:\WINDOWS\wiaservc.log 2014-05-02 16:00 - 2014-02-01 22:58 - 00000880 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-02 16:00 - 2014-02-01 22:38 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-05-02 16:00 - 2004-08-04 14:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl 2014-04-30 15:22 - 2014-02-01 22:39 - 00000178 ___SH () C:\Documents and Settings\johny\ntuser.ini 2014-04-30 15:22 - 2014-02-01 22:38 - 00032640 _____ () C:\WINDOWS\SchedLgU.Txt 2014-04-30 15:19 - 2014-04-30 15:19 - 00000814 _____ () C:\Documents and Settings\johny\Desktop\FRST.txt 2014-04-30 15:19 - 2014-04-29 14:14 - 00000000 ____D () C:\FRST 2014-04-30 15:16 - 2014-04-30 15:16 - 00001274 _____ () C:\WINDOWS\KB2618444-IE8.log 2014-04-30 15:14 - 2014-04-30 15:14 - 00000883 _____ () C:\WINDOWS\KB932823-v3.log 2014-04-30 15:13 - 2014-04-30 15:12 - 00030054 _____ () C:\WINDOWS\ie8_main.log 2014-04-30 15:12 - 2014-04-29 14:08 - 00000000 ____D () C:\Documents and Settings\johny\Local Settings\Application Data\DM 2014-04-30 15:10 - 2014-02-01 23:24 - 00574484 _____ () C:\WINDOWS\setupapi.log 2014-04-30 15:09 - 2014-04-30 15:09 - 00000000 ___SD () C:\Documents and Settings\johny\UserData 2014-04-30 15:09 - 2014-02-01 22:39 - 00000000 ____D () C:\Documents and Settings\johny 2014-04-30 15:04 - 2014-04-30 15:04 - 00000000 ____D () C:\FRST-OlderVersion 2014-04-30 15:04 - 2014-04-29 14:13 - 01050624 _____ (Farbar) C:\FRST.exe 2014-04-30 15:03 - 2014-04-30 15:03 - 00000076 _____ () C:\New Text Document.txt 2014-04-29 14:54 - 2014-04-29 14:54 - 00000000 ____D () C:\AdwCleaner 2014-04-29 14:54 - 2014-02-01 23:05 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome 2014-04-29 14:54 - 2014-02-01 22:39 - 00000869 _____ () C:\Documents and Settings\johny\Start Menu\Programs\Internet Explorer.lnk 2014-04-29 14:24 - 2014-04-29 14:24 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2014-04-29 14:24 - 2014-04-29 14:24 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2014-04-29 14:24 - 2014-04-29 14:24 - 00000000 ____D () C:\WINDOWS\system32\config\RCCBakup 2014-04-29 14:22 - 2014-04-29 14:19 - 00000000 ____D () C:\Documents and Settings\johny\Local Settings\Application Data\cache 2014-04-29 14:19 - 2014-02-01 22:38 - 00000000 __SHD () C:\Documents and Settings\LocalService 2014-04-29 14:11 - 2014-04-29 14:11 - 00383796 _____ () C:\Documents and Settings\johny\My Documents\windowscodecs.zip 2014-04-29 14:09 - 2014-04-29 14:09 - 01107768 _____ (AnyProtect.com) C:\Documents and Settings\johny\Local Settings\Application Data\nsy127.tmp 2014-04-27 23:42 - 2014-04-27 23:42 - 00000670 _____ () C:\Documents and Settings\johny\My Documents\SystemLook.txt 2014-04-27 23:29 - 2014-04-13 21:35 - 00013104 _____ () C:\Documents and Settings\johny\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2014-04-27 23:26 - 2014-02-01 22:32 - 00000000 ____D () C:\WINDOWS\system32\Restore 2014-04-27 23:23 - 2014-04-27 23:23 - 00000903 _____ () C:\DelFix.txt 2014-04-27 23:20 - 2014-02-01 23:19 - 00000000 ____D () C:\Documents and Settings\johny\Local Settings\Application Data\GG 2014-04-27 23:00 - 2014-04-27 22:51 - 00000216 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job 2014-04-25 17:01 - 2014-04-29 14:18 - 01090218 _____ (AnyProtect.com) C:\Documents and Settings\johny\Local Settings\Application Data\AnyProtectScannerSetup.exe 2014-04-24 19:37 - 2014-04-24 19:37 - 00005690 _____ () C:\WINDOWS\KB2934207.log 2014-04-24 19:37 - 2014-04-24 19:37 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2934207$ 2014-04-24 19:37 - 2014-02-01 23:25 - 00073364 _____ () C:\WINDOWS\FaxSetup.log 2014-04-24 19:37 - 2014-02-01 23:25 - 00043794 _____ () C:\WINDOWS\ocgen.log 2014-04-24 19:37 - 2014-02-01 23:25 - 00035568 _____ () C:\WINDOWS\comsetup.log 2014-04-24 19:37 - 2014-02-01 23:25 - 00030981 _____ () C:\WINDOWS\tsoc.log 2014-04-24 19:37 - 2014-02-01 23:25 - 00019559 _____ () C:\WINDOWS\ntdtcsetup.log 2014-04-24 19:37 - 2014-02-01 23:25 - 00009782 _____ () C:\WINDOWS\iis6.log 2014-04-24 19:37 - 2014-02-01 23:25 - 00004124 _____ () C:\WINDOWS\ocmsn.log 2014-04-24 19:37 - 2014-02-01 23:25 - 00003805 _____ () C:\WINDOWS\msgsocm.log 2014-04-24 19:37 - 2014-02-01 23:25 - 00001374 _____ () C:\WINDOWS\imsins.log 2014-04-24 19:16 - 2014-02-01 23:16 - 00000000 ____D () C:\WINDOWS\Help 2014-04-20 21:25 - 2014-02-01 23:25 - 00356120 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-04-20 21:24 - 2014-04-20 21:24 - 00000000 ____D () C:\Documents and Settings\johny\Local Settings\Application Data\Skype 2014-04-20 21:24 - 2014-04-13 22:10 - 00030753 _____ () C:\WINDOWS\spupdsvc.log 2014-04-20 21:24 - 2014-02-01 22:31 - 00018889 _____ () C:\WINDOWS\wmsetup.log 2014-04-20 21:24 - 2014-02-01 22:31 - 00000359 _____ () C:\WINDOWS\DtcInstall.log 2014-04-20 21:23 - 2014-02-01 22:39 - 00000738 _____ () C:\Documents and Settings\johny\Start Menu\Programs\Outlook Express.lnk 2014-04-20 21:22 - 2014-04-20 21:22 - 00000269 _____ () C:\WINDOWS\system32\spupdwxp.log 2014-04-20 21:22 - 2014-04-20 21:22 - 00000187 _____ () C:\WINDOWS\spupdsvc.log.1.log 2014-04-20 21:22 - 2014-02-01 23:24 - 00091888 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-04-20 21:21 - 2014-02-01 23:16 - 00000000 ____D () C:\WINDOWS\security 2014-04-20 21:20 - 2014-04-20 21:08 - 00455278 _____ () C:\WINDOWS\svcpack.log 2014-04-20 21:20 - 2014-02-01 23:25 - 00002675 _____ () C:\WINDOWS\imsins.BAK 2014-04-20 21:17 - 2014-04-20 21:17 - 00000000 ____D () C:\WINDOWS\system32\bits 2014-04-20 21:17 - 2014-04-20 21:17 - 00000000 ____D () C:\WINDOWS\l2schemas 2014-04-20 21:17 - 2014-04-11 19:00 - 00090083 _____ () C:\WINDOWS\updspapi.log 2014-04-20 21:17 - 2014-02-01 23:16 - 00000000 ____D () C:\WINDOWS\system32\usmt 2014-04-20 21:17 - 2014-02-01 23:16 - 00000000 ____D () C:\WINDOWS\system32\mui 2014-04-20 21:17 - 2014-02-01 23:16 - 00000000 ____D () C:\WINDOWS\PeerNet 2014-04-20 21:17 - 2014-02-01 23:16 - 00000000 ____D () C:\WINDOWS\ime 2014-04-20 21:17 - 2014-02-01 22:35 - 00001563 _____ () C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk 2014-04-20 21:17 - 2014-02-01 22:32 - 00000000 ____D () C:\Program Files\Movie Maker 2014-04-20 21:17 - 2014-02-01 22:31 - 00001281 _____ () C:\WINDOWS\sessmgr.setup.log 2014-04-20 21:17 - 2014-02-01 22:31 - 00000000 ____D () C:\Program Files\Messenger 2014-04-20 21:17 - 2014-02-01 22:29 - 00000373 _____ () C:\WINDOWS\cmsetacl.log 2014-04-20 21:17 - 2014-02-01 22:29 - 00000000 ___RD () C:\Documents and Settings\All Users\Start Menu\Programs\Accessories 2014-04-20 21:15 - 2014-04-20 21:15 - 00000000 ____D () C:\WINDOWS\ServicePackFiles 2014-04-20 21:15 - 2014-02-01 23:16 - 00000000 ____D () C:\WINDOWS\system32\npp 2014-04-20 21:15 - 2014-02-01 23:16 - 00000000 ____D () C:\WINDOWS\system 2014-04-20 21:15 - 2014-02-01 23:16 - 00000000 ____D () C:\WINDOWS\msagent 2014-04-20 21:15 - 2014-02-01 22:32 - 00000000 ____D () C:\WINDOWS\srchasst 2014-04-20 21:15 - 2014-02-01 22:32 - 00000000 ____D () C:\Program Files\Outlook Express 2014-04-20 21:15 - 2014-02-01 22:32 - 00000000 ____D () C:\Program Files\NetMeeting 2014-04-20 21:15 - 2014-02-01 22:32 - 00000000 ____D () C:\Program Files\Common Files\System 2014-04-20 21:15 - 2014-02-01 22:30 - 00000000 ____D () C:\WINDOWS\system32\Com 2014-04-20 21:15 - 2014-02-01 22:30 - 00000000 ____D () C:\Program Files\Windows NT 2014-04-20 21:13 - 2004-08-04 14:00 - 00250048 __RSH () C:\ntldr 2014-04-20 21:12 - 2014-04-20 21:10 - 00000000 __HDC () C:\WINDOWS\$NtServicePackUninstall$ 2014-04-20 21:12 - 2014-02-01 22:41 - 00000000 ____D () C:\WINDOWS\system32\ReinstallBackups 2014-04-20 21:10 - 2014-04-20 21:10 - 00000557 _____ () C:\WINDOWS\medctroc.Log 2014-04-20 20:26 - 2014-04-20 15:26 - 00021378 _____ () C:\Documents and Settings\johny\My Documents\FRST.txt 2014-04-20 20:19 - 2014-04-20 20:19 - 00000079 _____ () C:\WINDOWS\wininit.ini 2014-04-20 18:00 - 2014-04-20 18:00 - 00026095 _____ () C:\Documents and Settings\johny\My Documents\gmer.txt 2014-04-20 15:35 - 2014-04-20 15:35 - 00049636 _____ () C:\Documents and Settings\johny\My Documents\OTL.Txt 2014-04-20 15:35 - 2014-04-20 15:35 - 00031374 _____ () C:\Documents and Settings\johny\My Documents\Extras.Txt 2014-04-20 15:27 - 2014-04-20 15:27 - 00017282 _____ () C:\Documents and Settings\johny\My Documents\Addition.txt 2014-04-18 16:42 - 2014-04-11 18:21 - 00000000 ____D () C:\Documents and Settings\johny\Desktop\foto 2014-04-15 20:58 - 2014-04-15 20:58 - 00000000 ____D () C:\Documents and Settings\johny\Start Menu\Programs\Google Chrome 2014-04-13 23:06 - 2014-03-01 17:56 - 00000000 ____D () C:\Program Files\ePub Reader for Windows 2014-04-13 22:12 - 2014-04-13 22:12 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\GG 2014-04-13 22:06 - 2014-04-13 21:34 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard 2014-04-13 22:05 - 2014-04-13 22:05 - 00000000 ____D () C:\Documents and Settings\johny\Application Data\WinRAR 2014-04-13 22:04 - 2014-04-13 22:04 - 00000000 ____D () C:\Program Files\WinRAR 2014-04-13 22:04 - 2014-04-13 22:04 - 00000000 ____D () C:\Documents and Settings\johny\Start Menu\Programs\WinRAR 2014-04-13 22:04 - 2014-04-13 22:04 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR 2014-04-13 21:56 - 2004-08-04 14:00 - 00450543 _____ () C:\WINDOWS\system32\Drivers\etc\hosts.old 2014-04-13 21:45 - 2014-04-13 21:44 - 00000970 _____ () C:\WINDOWS\MSCompPackV1Uninst.log 2014-04-13 21:43 - 2014-02-01 22:39 - 00001599 _____ () C:\Documents and Settings\johny\Start Menu\Programs\Remote Assistance.lnk 2014-04-13 21:41 - 2014-02-01 22:35 - 00001599 _____ () C:\Documents and Settings\Default User\Start Menu\Programs\Remote Assistance.lnk 2014-04-13 21:41 - 2014-02-01 22:35 - 00001507 _____ () C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk 2014-04-12 15:51 - 2014-02-01 23:02 - 00000000 ____D () C:\Program Files\Yahoo! 2014-04-11 19:06 - 2014-04-11 19:06 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack 2014-04-11 19:06 - 2014-04-11 19:05 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack 2014-04-11 19:00 - 2014-04-11 18:59 - 00009266 _____ () C:\WINDOWS\KB926239.log 2014-04-11 19:00 - 2014-02-01 22:39 - 00000788 _____ () C:\Documents and Settings\johny\Start Menu\Programs\Windows Media Player.lnk 2014-04-11 18:59 - 2014-04-11 18:59 - 00019672 _____ () C:\WINDOWS\wmp11.log 2014-04-11 18:59 - 2014-04-11 18:59 - 00006758 _____ () C:\WINDOWS\MSCompPackV1.log 2014-04-11 18:59 - 2014-04-11 18:59 - 00000000 __HDC () C:\WINDOWS\$NtUninstallwmp11$ 2014-04-11 18:59 - 2014-04-11 18:59 - 00000000 __HDC () C:\WINDOWS\$NtUninstallMSCompPackV1$ 2014-04-11 18:59 - 2014-04-11 18:59 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB926239$ 2014-04-11 18:59 - 2014-04-11 18:59 - 00000000 ____D () C:\Program Files\Windows Media Connect 2 2014-04-11 18:59 - 2014-04-11 18:58 - 00029942 _____ () C:\WINDOWS\WMFDist11.log 2014-04-11 18:59 - 2014-02-01 22:34 - 00023392 _____ () C:\WINDOWS\system32\nscompat.tlb 2014-04-11 18:59 - 2014-02-01 22:34 - 00016832 _____ () C:\WINDOWS\system32\amcompat.tlb 2014-04-11 18:59 - 2014-02-01 22:34 - 00000000 __SHD () C:\Documents and Settings\All Users\DRM 2014-04-11 18:59 - 2004-08-04 14:00 - 00000507 _____ () C:\WINDOWS\win.ini 2014-04-11 18:58 - 2014-04-11 18:58 - 00000000 __HDC () C:\WINDOWS\$NtUninstallWudf01000$ 2014-04-11 18:58 - 2014-04-11 18:58 - 00000000 __HDC () C:\WINDOWS\$NtUninstallWMFDist11$ 2014-04-11 18:58 - 2014-04-11 18:58 - 00000000 ____D () C:\WINDOWS\system32\LogFiles 2014-04-11 18:58 - 2014-04-11 18:57 - 00011013 _____ () C:\WINDOWS\Wudf01000Inst.log 2014-04-11 18:55 - 2014-04-11 18:55 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage Some content of TEMP: ==================== C:\Documents and Settings\johny\Local Settings\Temp\ggdrive-menu.exe C:\Documents and Settings\johny\Local Settings\Temp\ggdrive-overlay.exe C:\Documents and Settings\johny\Local Settings\Temp\installstats.exe C:\Documents and Settings\johny\Local Settings\Temp\nsy21.tmp.exe C:\Documents and Settings\johny\Local Settings\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\WINDOWS\explorer.exe [2004-08-04 14:00] - [2007-12-01 00:26] - 1033728 ____A (Microsoft Corporation) e0ee428f4777a3cd8760bad61f87abed C:\WINDOWS\system32\winlogon.exe [2004-08-04 14:00] - [2007-12-01 00:26] - 0507904 ____A (Microsoft Corporation) 45ffe966290b9c4ba659325561de4830 C:\WINDOWS\system32\svchost.exe [2004-08-04 14:00] - [2007-12-01 00:26] - 0014336 ____A (Microsoft Corporation) 0c82b0ae50bb2bc8a96a753f4edc495f C:\WINDOWS\system32\services.exe [2004-08-04 14:00] - [2007-12-01 00:26] - 0108544 ____A (Microsoft Corporation) 76727219614a50b2db29bd0cda4260d5 C:\WINDOWS\system32\User32.dll [2004-08-04 14:00] - [2007-12-01 00:26] - 0578560 ____A (Microsoft Corporation) 6c74c62ecdc3981a7f1f8f1656b27871 C:\WINDOWS\system32\userinit.exe [2004-08-04 14:00] - [2007-12-01 00:26] - 0026112 ____A (Microsoft Corporation) 813b2e9c4caea05fba51a442fab7a95d C:\WINDOWS\system32\rpcss.dll [2004-08-04 14:00] - [2007-12-01 00:25] - 0399360 ____A (Microsoft Corporation) 70aba737c26f576bd04f108e22fe8a8a ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected. C:\WINDOWS\system32\Drivers\volsnap.sys [2004-08-04 14:00] - [2007-11-30 17:25] - 0052352 ____A (Microsoft Corporation) 2abf037f9d447424b58d73706b55b762 ==================== End Of Log ============================