these are the results of the FRST listed below...
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by RAUL_104 (administrator) on RAUL-104 on 28-03-2015 19:50:54
Running from C:\Documents and Settings\RAUL_104\My Documents\Downloads
Loaded Profiles: RAUL_104 (Available profiles: RAUL_104 & RAUL_106 & AMY_106 & AMY_1061 & Administrator & Guest)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2015\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcsrvx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ABBYY) C:\Program Files\Common Files\ABBYY\FineReader\11.00\Licensing\CE\NetworkLicenseServer.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Creative Technology Ltd) C:\WINDOWS\system32\CTSVCCDA.EXE
() C:\WINDOWS\system32\spool\drivers\w32x86\3\dleaserv.exe
( ) C:\WINDOWS\system32\dleacoms.exe
() C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgemcx.exe
(iolo technologies, LLC) C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
(Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe
(iolo technologies, LLC) C:\Program Files\iolo\System Mechanic\LiveBoost.exe
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
(Creative Technology Ltd) C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
(Creative Technology Ltd) C:\WINDOWS\system32\CTHELPER.EXE
(Memeo) C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe
(CyberLink Corp.) C:\Program Files\Dell\Media Experience\PCMService.exe
() C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
(WDC) C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
() C:\Program Files\Dell V310-V510 Series\dleamon.exe
() C:\Program Files\Dell V310-V510 Series\ezprint.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
(McAfee, Inc.) C:\WINDOWS\system32\mfevtps.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\Kies\KiesTrayAgent.exe
() C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
(iolo technologies, LLC) C:\Program Files\iolo\System Mechanic\ioloGovernor.exe
() C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\Platform\McUICnt.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe
(Nero AG) C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
() C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
(Prolific Technology Inc.) C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
(Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
(Viewpoint Corporation) C:\Program Files\Viewpoint\Common\ViewpointService.exe
(WDC) C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\MsPMSPSv.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(GEMTEKS) C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
(Linksys) C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\AMCore\mcshield.exe
(Logitech Inc.) C:\Program Files\Logitech\Vid HD\Vid.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
(Samsung) C:\Program Files\SAMSUNG\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Samsung Electronics) C:\Program Files\SAMSUNG\Kies\KiesAirMessage.exe
(Dell) C:\Documents and Settings\RAUL_104\Local Settings\Apps\2.0\POD3HEHV.4EL\OAXDQMD5.Q3D\dell..tion_0f612f649c4a10af_0005.0006_f9e15713f5aac8ac\DellSystemDetect.exe
(Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe
(ArcSoft, Inc.) C:\Program Files\My Book\WD Backup\uBBMonitor.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\WZQKPICK.EXE
(BackWeb Technologies Inc. ) C:\DOCUME~1\RAUL_104\LOCALS~1\Temp\bwgo0003a7ab.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\WINDOWS\system32\windowspowershell\v1.0\powershell.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(NathanScott Apps) C:\Documents and Settings\RAUL_104\Local Settings\Application Data\IDTool\IDTool.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [PDVDDXSrv] => C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [124200 2007-09-17] (CyberLink Corp.)
HKLM\...\Run: [CTSysVol] => C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe [49152 2002-10-29] (Creative Technology Ltd)
HKLM\...\Run: [CTHelper] => C:\WINDOWS\system32\CTHELPER.EXE [28672 2003-02-20] (Creative Technology Ltd)
HKLM\...\Run: [AsioReg] => "REGSVR32.EXE" /S CTASIO.DLL
HKLM\...\Run: [UpdReg] => C:\WINDOWS\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM\...\Run: [PCMService] => C:\Program Files\Dell\Media Experience\PCMService.exe [290816 2004-04-11] (CyberLink Corp.)
HKLM\...\Run: [Share-to-Web Namespace Daemon] => C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe [69632 2002-04-17] (Hewlett-Packard)
HKLM\...\Run: [WD Button Manager] => "WDBtnMgr.exe"
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [866584 2006-11-03] (Microsoft Corporation)
HKLM\...\Run: [LogitechQuickCamRibbon] => C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2793304 2009-10-14] ()
HKLM\...\Run: [WD Drive Manager] => C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe [450560 2009-05-27] (WDC)
HKLM\...\Run: [WD Anywhere Backup] => C:\Program Files\WD\WD Anywhere Backup\MemeoLauncher2.exe [197856 2009-04-17] (Memeo Inc.)
HKLM\...\Run: [NBKeyScan] => C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe [2254120 2008-09-24] (Nero AG)
HKLM\...\Run: [IntelliPoint] => C:\Program Files\Microsoft IntelliPoint\ipoint.exe [1468296 2009-05-26] (Microsoft Corporation)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-05-27] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [dleamon.exe] => C:\Program Files\Dell V310-V510 Series\dleamon.exe [770728 2011-01-23] ()
HKLM\...\Run: [EzPrint] => C:\Program Files\Dell V310-V510 Series\ezprint.exe [139944 2011-01-23] ()
HKLM\...\Run: [AppleSyncNotifier] => C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [47904 2010-12-14] (Apple Inc.)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-28] ()
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [PMBVolumeWatcher] => C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [600928 2010-06-01] (Sony Corporation)
HKLM\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [517392 2014-04-25] (McAfee, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [151952 2012-11-29] (Apple Inc.)
HKLM\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [517392 2014-04-25] (McAfee, Inc.)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [309688 2012-10-11] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [ioloGovernor] => C:\Program Files\iolo\System Mechanic\ioloGovernor.exe [870224 2014-08-13] (iolo technologies, LLC)
HKLM\...\Run: [Bonus.SSR.FR11] => C:\Program Files\ABBYY FineReader 11\Bonus.ScreenshotReader.exe [933640 2012-01-19] (ABBYY.)
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2012-10-25] (Apple Inc.)
HKLM\...\Run: [UserFaultCheck] => %systemroot%\system32\dumprep 0 -u
HKLM\...\Run: [atolpphm] => C:\WINDOWS\System32\atolpphm.exe
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3710416 2015-02-19] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKLM\...99B7938DA9E4}\LocalServer32: [Default-wmiprvse] rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 224 more characters). <==== ATTENTION!
HKLM\...99B7938DA9E4}\LocalServer32: [a] #@~^A4EAAA==n{
[email protected]#@&l{xAPzmOk7+p6(L+1O`r?1.rwDRUtnVsE*
[email protected]#@&S4k^+cne'
[email protected]#@&`@#@&
[email protected]#@&i @#@&di (the data entry has 32951 more characters). <==== ATTENTION!
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [Google Update] => C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [107912 2014-10-21] (Google Inc.)
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [SB Audigy 2 Startup Menu] => /L:ENG
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [AnyDVD] => C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe [3193792 2009-12-11] (SlySoft, Inc.)
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [Logitech Vid] => C:\Program Files\Logitech\Vid HD\Vid.exe [5915480 2010-10-29] (Logitech Inc.)
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [842680 2012-10-11] (Samsung)
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [966072 2012-10-11] (Samsung)
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [KiesAirMessage] => C:\Program Files\Samsung\Kies\KiesAirMessage.exe [580096 2012-10-09] (Samsung Electronics)
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [DellSystemDetect] => C:\Documents and Settings\RAUL_104\Local Settings\Apps\2.0\POD3HEHV.4EL\OAXDQMD5.Q3D\dell..tion_0f612f649c4a10af_0005.0006_f9e15713f5aac8ac\DellSystemDetect.exe [258160 2014-04-05] (Dell)
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-13] (Microsoft Corporation)
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [atolpphm] => C:\Documents and Settings\RAUL_104\atolpphm.exe
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [msnmsgr] => C:\Program Files\MSN Messenger\msnmsgr.exe [6856704 2007-09-04] (Microsoft Corporation)
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [AgentUpdate] => C:\WINDOWS\system32\regsvr32.exe /s "C:\Documents and Settings\RAUL_104\Application Data\Microsoft\Crypto\RSA\S-1-5-21-3915684212-1830115506-383142685-1006\cert_v95_0.tpa"
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Run: [CryptoUpdate] => C:\WINDOWS\system32\regsvr32.exe /s "C:\Documents and Settings\RAUL_104\Application Data\Microsoft\Crypto\RSA\cert_v95_0.tpl"
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Policies\Explorer\Run: [2096056239] => C:\DOCUME~1\RAUL_104\APPLIC~1\msitsxr.exe
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Policies\Explorer: [TaskbarNoNotification] 1
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\MountPoints2: {2ed4db3c-0410-11df-be50-00226ba62c8c} - H:\LaunchU3.exe -a
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\MountPoints2: {2ed4db3e-0410-11df-be50-00226ba62c8c} - G:\Setup_FlipShare.exe
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\MountPoints2: {4f6dfe74-57ca-11de-bd66-00226ba62c8c} - I:\LaunchU3.exe -a
HKU\S-1-5-21-515967899-117609710-839522115-1004\...\MountPoints2: {dffbf3f7-2974-11e2-949a-00226ba62c8c} - I:\setup.exe -a
HKU\S-1-5-18\...\Run: [DWQueuedReporting] => C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [434080 2011-07-27] (Microsoft Corporation)
HKU\S-1-5-18\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoControlPanel] 0
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
ShortcutTarget: Logitech Desktop Messenger.lnk -> C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WD Backup Monitor.lnk
ShortcutTarget: WD Backup Monitor.lnk -> C:\Program Files\My Book\WD Backup\uBBMonitor.exe (ArcSoft, Inc.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
ShortcutTarget: WinZip Quick Pick.lnk -> C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
Startup: C:\Documents and Settings\AMY_106\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\AMY_1061\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\RAUL_106\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * C:\PROGRA~1\AVG\AVG2015\avgrsx.exe /sync /restart
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-515967899-117609710-839522115-1004\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-515967899-117609710-839522115-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/?ocid=iehp
BHO: Dell Toolbar -> {09B71986-2AC5-482d-B6CB-42EA34F4F85B} -> C:\Program Files\Dell Toolbar\toolband.dll [2008-12-10] ()
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18] (Adobe Systems Incorporated)
BHO: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-12-12] (DivX, LLC)
BHO: No Name -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> No File
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-09-08] (Oracle Corporation)
BHO: No Name -> {9CB65201-89C4-402c-BA80-02D8C59F9B1D} -> No File
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll [2015-03-03] (Google Inc.)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-03-11] (McAfee, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-09-08] (Oracle Corporation)
BHO: No Name -> {FE063DB1-4EC0-403e-8DD8-394C54984B2C} -> No File
Toolbar: HKLM - No Name - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - No File
Toolbar: HKLM - Dell Toolbar - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Toolbar\toolband.dll [2008-12-10] ()
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-03-11] (McAfee, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-515967899-117609710-839522115-1004 -> No Name - {FE063DB9-4EC0-403E-8DD8-394C54984B2C} - No File
Toolbar: HKU\S-1-5-21-515967899-117609710-839522115-1004 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-515967899-117609710-839522115-1004 -> Dell Toolbar - {09B71986-2AC5-482D-B6CB-42EA34F4F85B} - C:\Program Files\Dell Toolbar\toolband.dll [2008-12-10] ()
Toolbar: HKU\S-1-5-21-515967899-117609710-839522115-1004 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {16F67783-7E72-4C39-99C4-4780A8335484}
http://www.syncmyride.com/Own/Modules/UpdateCenter/applets/sync.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/downl...-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6}
https://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E534E95D-4D69-4209-9DD0-D95BD20F9246} file:///F:/GxWebClient.cab
DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} file:///E:/CDVIEWER/CdViewer.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll [2011-05-28] (Logitech Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-03-11] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-03-11] (McAfee, Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll [2014-04-25] (McAfee, Inc.)
ShellExecuteHooks: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll [83224 2006-11-03] (Microsoft Corporation)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
FireFox:
========
FF ProfilePath: C:\Documents and Settings\RAUL_104\Application Data\Mozilla\Firefox\Profiles\ksds0365.default
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-24] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2012-10-31] ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2011-12-13] (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2011-06-20] (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\WINDOWS\system32\npDeployJava1.dll [2013-09-08] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-09-08] (Oracle Corporation)
FF Plugin: @logitech.com/HarmonyRemote,version=1.0.0 -> C:\Program Files\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll [2012-09-28] (Logitech Inc.)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
FF Plugin: @mcafee.com/MVT -> C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll [2013-02-05] (McAfee, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @movenetworks.com/Quantum Media Player -> C:\Documents and Settings\RAUL_104\Application Data\Move Networks\plugins\npqmp071701000002.dll [2009-12-06] (Move Networks)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: @viewpoint.com/VMP -> C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll [2007-04-16] ()
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-515967899-117609710-839522115-1004: @movenetworks.com/Quantum Media Player -> C:\Documents and Settings\RAUL_104\Application Data\Move Networks\plugins\npqmp071701000002.dll [2009-12-06] (Move Networks)
FF Plugin HKU\S-1-5-21-515967899-117609710-839522115-1004: @tools.google.com/Google Update;version=3 -> C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-515967899-117609710-839522115-1004: @tools.google.com/Google Update;version=9 -> C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll [2009-05-18] (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdnu.dll [2009-07-07] (AOL LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdnupdater2.dll [2009-07-07] (AOL LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2012-12-18] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2012-12-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2012-12-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2012-12-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2012-12-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2012-12-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2012-12-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2012-12-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npViewpoint.dll [2007-04-16] ()
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2014-12-20]
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\RAUL_104\Application Data\Mozilla\Firefox\Profiles\ksds0365.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012-02-28]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-03-24]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-03-24]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-07]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files\McAfee\SiteAdvisor [2012-06-24]
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: No Name - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-08-29]
FF HKU\S-1-5-21-515967899-117609710-839522115-1004\...\Firefox\Extensions: [
[email protected]] - C:\Documents and Settings\RAUL_104\Application Data\Move Networks
FF Extension: Move Media Player - C:\Documents and Settings\RAUL_104\Application Data\Move Networks [2009-03-27]
Chrome:
=======
CHR Profile: C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-16]
CHR Extension: (Google Search) - C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-16]
CHR Extension: (SiteAdvisor) - C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-02-26]
CHR Extension: (Skype Click to Call) - C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-08-20]
CHR Extension: (Google Wallet) - C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-26]
CHR Extension: (MyHarmony Chrome Plugin) - C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf [2015-02-26]
CHR Extension: (Gmail) - C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-16]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx [2012-06-24]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - No Path Or update_url value
CHR HKLM\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files\Logitech\Harmony Remote Driver\harmony_chrome.crx [2014-01-28]
StartMenuInternet: chrome.exe - C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ABBYY.Licensing.FineReader.Corporate.11.0; C:\Program Files\Common Files\ABBYY\FineReader\11.00\Licensing\CE\NetworkLicenseServer.exe [818952 2011-12-22] (ABBYY)
S4 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S4 Alerter; C:\WINDOWS\system32\alrsvc.dll [17408 2008-04-13] (Microsoft Corporation) [File not signed]
R3 ALG; C:\WINDOWS\System32\alg.exe [44544 2008-04-13] (Microsoft Corporation) [File not signed]
R2 Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [602112 2010-05-27] (ATI Technologies Inc.) [File not signed]
R2 AudioSrv; C:\WINDOWS\System32\audiosrv.dll [42496 2008-04-13] (Microsoft Corporation) [File not signed]
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3411408 2015-02-19] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [308720 2015-02-19] (AVG Technologies CZ, s.r.o.)
S4 BITS; C:\WINDOWS\system32\qmgr.dll [409088 2008-04-13] (Microsoft Corporation) [File not signed]
S2 Browser; C:\WINDOWS\System32\browser.dll [78336 2012-07-06] (Microsoft Corporation) [File not signed]
S2 ccEvtMgr; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [255136 2003-10-20] () [File not signed]
S3 ccPwdSvc; C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [87200 2003-10-20] () [File not signed]
S2 ccSetMgr; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [234656 2003-10-20] () [File not signed]
S3 CiSvc; C:\WINDOWS\system32\cisvc.exe [5632 2008-04-13] (Microsoft Corporation) [File not signed]
S4 ClipSrv; C:\WINDOWS\system32\clipsrv.exe [33280 2008-04-13] (Microsoft Corporation) [File not signed]
R2 Creative Service for CDROM Access; C:\WINDOWS\system32\CTSvcCDA.EXE [44032 1999-12-13] (Creative Technology Ltd) [File not signed]
R2 CryptSvc; C:\WINDOWS\System32\cryptsvc.dll [62464 2008-04-13] (Microsoft Corporation) [File not signed]
R2 DcomLaunch; C:\WINDOWS\system32\rpcss.dll [401408 2009-02-09] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\WINDOWS\System32\dhcpcsvc.dll [126976 2008-04-13] (Microsoft Corporation) [File not signed]
R2 dleaCATSCustConnectService; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\dleaserv.exe [98984 2010-01-07] ()
R2 dlea_device; C:\WINDOWS\system32\dleacoms.exe [598696 2010-01-07] ( )
S3 dmadmin; C:\WINDOWS\System32\dmadmin.exe [224768 2008-04-13] (Microsoft Corp., Veritas Software) [File not signed]
S3 dmserver; C:\WINDOWS\System32\dmserver.dll [23552 2008-04-13] (Microsoft Corp.) [File not signed]
R2 Dnscache; C:\WINDOWS\System32\dnsrslvr.dll [45568 2009-04-20] (Microsoft Corporation) [File not signed]
S3 Dot3svc; C:\WINDOWS\System32\dot3svc.dll [132096 2008-04-13] (Microsoft Corporation) [File not signed]
S3 EapHost; C:\WINDOWS\System32\eapsvc.dll [33792 2008-04-13] (Microsoft Corporation) [File not signed]
S4 ERSvc; C:\WINDOWS\System32\ersvc.dll [23040 2008-04-13] (Microsoft Corporation) [File not signed]
R2 Eventlog; C:\WINDOWS\system32\services.exe [110592 2009-02-06] (Microsoft Corporation) [File not signed]
R3 EventSystem; C:\WINDOWS\system32\es.dll [253952 2008-07-07] (Microsoft Corporation) [File not signed]
R3 FastUserSwitchingCompatibility; C:\WINDOWS\System32\shsvcs.dll [135168 2009-07-27] (Microsoft Corporation) [File not signed]
R2 FlipShare Service; C:\Program Files\Flip Video\FlipShare\FlipShareService.exe [455944 2010-05-14] ()
R2 helpsvc; C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [38400 2008-04-13] (Microsoft Corporation) [File not signed]
R2 HidServ; C:\WINDOWS\System32\hidserv.dll [21504 2008-04-13] (Microsoft Corporation) [File not signed]
S3 hkmsvc; C:\WINDOWS\System32\kmsvc.dll [61440 2008-04-13] (Microsoft Corporation) [File not signed]
R2 HomeNetSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R3 HTTPFilter; C:\WINDOWS\System32\w3ssl.dll [15872 2008-04-13] (Microsoft Corporation) [File not signed]
S3 ImapiService; C:\WINDOWS\system32\imapi.exe [150528 2008-04-13] (Microsoft Corporation) [File not signed]
R2 ioloSystemService; C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe [4700872 2014-08-12] (iolo technologies, LLC)
S4 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182184 2013-09-08] (Oracle Corporation)
R2 lanmanserver; C:\WINDOWS\System32\srvsvc.dll [99840 2010-08-27] (Microsoft Corporation) [File not signed]
R2 lanmanworkstation; C:\WINDOWS\System32\wkssvc.dll [132096 2009-06-10] (Microsoft Corporation) [File not signed]
R2 LmHosts; C:\WINDOWS\System32\lmhsvc.dll [13824 2008-04-13] (Microsoft Corporation) [File not signed]
R2 McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [132160 2015-03-11] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [145568 2014-04-25] (McAfee, Inc.)
U2 mcbootdelaystartsvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [472072 2014-09-04] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 MemeoBackgroundService; C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe [25824 2009-04-17] (Memeo)
S4 Messenger; C:\WINDOWS\System32\msgsvc.dll [33792 2008-04-13] (Microsoft Corporation) [File not signed]
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [655936 2014-08-20] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [169800 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\WINDOWS\system32\mfevtps.exe [179600 2015-02-11] (McAfee, Inc.)
S3 mnmsrvc; C:\WINDOWS\system32\mnmsrvc.exe [32768 2008-04-13] (Microsoft Corporation) [File not signed]
R2 MotoHelper; C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe [223088 2011-04-26] ()
S3 MSDTC; C:\WINDOWS\system32\msdtc.exe [6144 2008-04-13] (Microsoft Corporation) [File not signed]
S3 MSIServer; C:\WINDOWS\System32\msiexec.exe [78848 2008-04-13] (Microsoft Corporation) [File not signed]
S3 napagent; C:\WINDOWS\System32\qagentrt.dll [291328 2008-04-13] (Microsoft Corporation) [File not signed]
S4 NetDDE; C:\WINDOWS\system32\netdde.exe [111104 2008-04-13] (Microsoft Corporation) [File not signed]
S4 NetDDEdsdm; C:\WINDOWS\system32\netdde.exe [111104 2008-04-13] (Microsoft Corporation) [File not signed]
S3 Netlogon; C:\WINDOWS\system32\lsass.exe [13312 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Netman; C:\WINDOWS\System32\netman.dll [198144 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Nla; C:\WINDOWS\System32\mswsock.dll [245248 2008-06-20] (Microsoft Corporation) [File not signed]
S3 NtLmSsp; C:\WINDOWS\system32\lsass.exe [13312 2008-04-13] (Microsoft Corporation) [File not signed]
S3 NtmsSvc; C:\WINDOWS\system32\ntmssvc.dll [435200 2008-04-13] (Microsoft Corporation) [File not signed]
R2 PLFlash DeviceIoControl Service; C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe [81920 2008-09-24] (Prolific Technology Inc.) [File not signed]
R2 PlugPlay; C:\WINDOWS\system32\services.exe [110592 2009-02-06] (Microsoft Corporation) [File not signed]
R2 PolicyAgent; C:\WINDOWS\system32\lsass.exe [13312 2008-04-13] (Microsoft Corporation) [File not signed]
R2 ProtectedStorage; C:\WINDOWS\system32\lsass.exe [13312 2008-04-13] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\WINDOWS\System32\rasauto.dll [88576 2008-04-13] (Microsoft Corporation) [File not signed]
R3 RasMan; C:\WINDOWS\System32\rasmans.dll [186368 2008-04-13] (Microsoft Corporation) [File not signed]
S3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [141312 2008-04-13] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\WINDOWS\System32\mprdim.dll [53248 2008-04-13] (Microsoft Corporation) [File not signed]
S3 RpcLocator; C:\WINDOWS\system32\locator.exe [75264 2008-04-13] (Microsoft Corporation) [File not signed]
R2 RpcSs; C:\WINDOWS\system32\rpcss.dll [401408 2009-02-09] (Microsoft Corporation) [File not signed]
S3 RSVP; C:\WINDOWS\system32\rsvp.exe [132608 2004-08-04] (Microsoft Corporation) [File not signed]
R2 SamSs; C:\WINDOWS\system32\lsass.exe [13312 2008-04-13] (Microsoft Corporation) [File not signed]
S3 SCardSvr; C:\WINDOWS\System32\SCardSvr.exe [95744 2008-04-13] (Microsoft Corporation) [File not signed]
R2 Schedule; C:\WINDOWS\system32\schedsvc.dll [192512 2008-04-13] (Microsoft Corporation) [File not signed]
R2 seclogon; C:\WINDOWS\System32\seclogon.dll [18944 2008-04-13] (Microsoft Corporation) [File not signed]
R2 SENS; C:\WINDOWS\system32\sens.dll [39424 2008-04-13] (Microsoft Corporation) [File not signed]
R2 SharedAccess; C:\WINDOWS\System32\ipnathlp.dll [331264 2008-04-13] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\WINDOWS\System32\shsvcs.dll [135168 2009-07-27] (Microsoft Corporation) [File not signed]
S4 Skype C2C Service; C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
R2 Spooler; C:\WINDOWS\system32\spoolsv.exe [58880 2010-08-17] (Microsoft Corporation) [File not signed]
R2 srservice; C:\WINDOWS\system32\srsvc.dll [171008 2008-04-13] (Microsoft Corporation) [File not signed]
R3 SSDPSRV; C:\WINDOWS\System32\ssdpsrv.dll [71680 2008-04-13] (Microsoft Corporation) [File not signed]
R2 stisvc; C:\WINDOWS\system32\wiaservc.dll [333824 2008-04-13] (Microsoft Corporation) [File not signed]
R2 svcboot_tdcreqqfu; C:\WINDOWS\system32\iherf\svcboot_tdcreqqfu.dll [239944 2013-09-26] ()
S3 SysmonLog; C:\WINDOWS\system32\smlogsvc.exe [89600 2008-04-13] (Microsoft Corporation) [File not signed]
R3 TapiSrv; C:\WINDOWS\System32\tapisrv.dll [249856 2008-04-13] (Microsoft Corporation) [File not signed]
R3 TermService; C:\WINDOWS\System32\termsrv.dll [295424 2008-04-13] (Microsoft Corporation) [File not signed]
R2 Themes; C:\WINDOWS\System32\shsvcs.dll [135168 2009-07-27] (Microsoft Corporation) [File not signed]
R2 TrkWks; C:\WINDOWS\system32\trkwks.dll [90112 2008-04-13] (Microsoft Corporation) [File not signed]
R3 upnphost; C:\WINDOWS\System32\upnphost.dll [185856 2008-04-13] (Microsoft Corporation) [File not signed]
S3 UPS; C:\WINDOWS\System32\ups.exe [18432 2008-04-13] (Microsoft Corporation) [File not signed]
R2 Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [24652 2007-01-04] (Viewpoint Corporation) [File not signed]
S3 VSS; C:\WINDOWS\System32\vssvc.exe [289792 2008-04-13] (Microsoft Corporation) [File not signed]
R2 W32Time; C:\WINDOWS\system32\w32time.dll [175104 2008-04-13] (Microsoft Corporation) [File not signed]
R2 WDBtnMgrSvc.exe; C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [102400 2009-05-27] (WDC) [File not signed]
R2 WebClient; C:\WINDOWS\System32\webclnt.dll [68096 2008-04-13] (Microsoft Corporation) [File not signed]
S4 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [13592 2006-11-03] (Microsoft Corporation)
R2 winmgmt; C:\WINDOWS\system32\wbem\WMIsvc.dll [144896 2008-04-13] (Microsoft Corporation) [File not signed]
S3 WiselinkPro; C:\Program Files\SAMSUNG\SAMSUNG PC Share Manager\WiselinkPro.exe [6795333 2008-03-03] () [File not signed]
R2 WMDM PMSP Service; C:\WINDOWS\system32\MsPMSPSv.exe [53520 2000-06-26] (Microsoft Corporation) [File not signed]
S3 WmdmPmSN; C:\WINDOWS\system32\MsPMSNSv.dll [27136 2006-10-18] (Microsoft Corporation) [File not signed]
S3 WmiApSrv; C:\WINDOWS\system32\wbem\wmiapsrv.exe [126464 2008-04-13] (Microsoft Corporation) [File not signed]
S3 WMPNetworkSvc; C:\Program Files\Windows Media Player\WMPNetwk.exe [913408 2006-10-18] (Microsoft Corporation) [File not signed]
S4 wscsvc; C:\WINDOWS\system32\wscsvc.dll [80896 2008-04-13] (Microsoft Corporation) [File not signed]
S4 wuauserv; C:\WINDOWS\system32\wuauserv.dll [6656 2008-04-13] (Microsoft Corporation) [File not signed]
R2 WudfSvc; C:\WINDOWS\System32\WUDFSvc.dll [55808 2006-09-28] (Microsoft Corporation) [File not signed]
S2 WZCSVC; C:\WINDOWS\System32\wzcsvc.dll [483840 2008-04-13] (Microsoft Corporation) [File not signed]
S3 xmlprov; C:\WINDOWS\System32\xmlprov.dll [129024 2008-04-13] (Microsoft Corporation) [File not signed]
R2 WUSB54GCSVC; "C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 61883; C:\WINDOWS\System32\DRIVERS\61883.sys [48128 2008-04-13] (Microsoft Corporation) [File not signed]
R0 ACPI; C:\WINDOWS\System32\DRIVERS\ACPI.sys [187776 2008-04-13] (Microsoft Corporation) [File not signed]
S4 ACPIEC; C:\WINDOWS\system32\Drivers\ACPIEC.sys [11648 2004-08-04] (Microsoft Corporation) [File not signed]
S3 aec; C:\WINDOWS\System32\drivers\aec.sys [142592 2008-04-13] (Microsoft Corporation) [File not signed]
R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [20747 2009-03-26] (Meetinghouse Data Communications) [File not signed]
R3 Afc; C:\WINDOWS\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
R1 AFD; C:\WINDOWS\System32\drivers\afd.sys [138496 2011-08-17] (Microsoft Corporation) [File not signed]
R0 agp440; C:\WINDOWS\System32\DRIVERS\agp440.sys [42368 2008-04-13] (Microsoft Corporation) [File not signed]
R3 AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [104512 2009-12-08] (SlySoft, Inc.)
R3 Arp1394; C:\WINDOWS\System32\DRIVERS\arp1394.sys [60800 2008-04-13] (Microsoft Corporation) [File not signed]
S3 AsyncMac; C:\WINDOWS\System32\DRIVERS\asyncmac.sys [14336 2008-04-13] (Microsoft Corporation) [File not signed]
R0 atapi; C:\WINDOWS\System32\DRIVERS\atapi.sys [96512 2008-04-13] (Microsoft Corporation) [File not signed]
R3 ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [4830720 2010-05-27] (ATI Technologies Inc.) [File not signed]
S3 Atmarpc; C:\WINDOWS\System32\DRIVERS\atmarpc.sys [59904 2008-04-13] (Microsoft Corporation) [File not signed]
R3 audstub; C:\WINDOWS\System32\DRIVERS\audstub.sys [3072 2001-08-17] (Microsoft Corporation) [File not signed]
S3 Avc; C:\WINDOWS\System32\DRIVERS\avc.sys [38912 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [121624 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriverl; C:\WINDOWS\System32\DRIVERS\avgidsdriverlx.sys [202208 2015-02-19] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [154904 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [192792 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [265184 2015-02-03] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [107488 2015-01-23] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [27416 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\WINDOWS\System32\DRIVERS\avgtdix.sys [210400 2015-01-16] (AVG Technologies CZ, s.r.o.)
S3 BCM42RLY; C:\WINDOWS\System32\BCM42RLY.SYS [17992 2005-02-01] (Broadcom Corporation) [File not signed]
R1 Beep; C:\WINDOWS\system32\Drivers\Beep.sys [4224 2004-08-04] (Microsoft Corporation) [File not signed]
S3 BTCFilterService; C:\WINDOWS\System32\DRIVERS\motfilt.sys [6016 2009-01-29] (Motorola Inc) [File not signed]
S4 cbidf2k; C:\WINDOWS\system32\Drivers\cbidf2k.sys [13952 2004-08-04] (Microsoft Corporation) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation) [File not signed]
S1 Cdaudio; C:\WINDOWS\system32\Drivers\Cdaudio.sys [18688 2004-08-04] (Microsoft Corporation) [File not signed]
R4 Cdfs; C:\WINDOWS\system32\Drivers\Cdfs.sys [63744 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Cdrom; C:\WINDOWS\System32\DRIVERS\cdrom.sys [62976 2008-04-13] (Microsoft Corporation) [File not signed]
S0 cercsr6; C:\WINDOWS\system32\Drivers\cercsr6.sys [39904 2004-12-13] (Adaptec, Inc.) [File not signed]
R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [62832 2014-06-20] (McAfee, Inc.)
R3 ctac32k; C:\WINDOWS\System32\drivers\ctac32k.sys [135040 2003-02-20] (Creative Technology Ltd) [File not signed]
R3 ctaud2k; C:\WINDOWS\System32\drivers\ctaud2k.sys [498688 2003-03-26] (Creative Technology Ltd) [File not signed]
S3 ctdvda2k; C:\WINDOWS\System32\drivers\ctdvda2k.sys [287920 2003-03-27] (Creative Technology Ltd) [File not signed]
R3 ctprxy2k; C:\WINDOWS\System32\drivers\ctprxy2k.sys [6144 2003-02-20] (Creative Technology Ltd) [File not signed]
R3 ctsfm2k; C:\WINDOWS\System32\drivers\ctsfm2k.sys [135248 2003-02-20] (Creative Technology Ltd) [File not signed]
R0 Disk; C:\WINDOWS\System32\DRIVERS\disk.sys [36352 2008-04-13] (Microsoft Corporation) [File not signed]
S4 dmboot; C:\WINDOWS\System32\drivers\dmboot.sys [799744 2008-04-13] (Microsoft Corp., Veritas Software) [File not signed]
S4 dmio; C:\WINDOWS\System32\drivers\dmio.sys [153344 2008-04-13] (Microsoft Corp., Veritas Software) [File not signed]
S4 dmload; C:\WINDOWS\System32\drivers\dmload.sys [5888 2004-08-04] (Microsoft Corp., Veritas Software.) [File not signed]
S3 DMusic; C:\WINDOWS\System32\drivers\DMusic.sys [52864 2008-04-13] (Microsoft Corporation) [File not signed]
S3 drmkaud; C:\WINDOWS\System32\drivers\drmkaud.sys [2944 2008-04-13] (Microsoft Corporation) [File not signed]
R3 E1000; C:\WINDOWS\System32\DRIVERS\e1000325.sys [164352 2006-04-27] (Intel Corporation) [File not signed]
R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [25768 2009-09-26] (Elaborate Bytes AG)
R3 emupia; C:\WINDOWS\System32\drivers\emupia2k.sys [116000 2003-02-20] (Creative Technology Ltd) [File not signed]
R4 Fastfat; C:\WINDOWS\system32\Drivers\Fastfat.sys [143744 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Fdc; C:\WINDOWS\System32\DRIVERS\fdc.sys [27392 2008-04-13] (Microsoft Corporation) [File not signed]
S3 FilterService; C:\WINDOWS\System32\DRIVERS\lvuvcflt.sys [23832 2009-10-07] (Logitech Inc.)
R1 Fips; C:\WINDOWS\system32\Drivers\Fips.sys [44544 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Flpydisk; C:\WINDOWS\System32\DRIVERS\flpydisk.sys [20480 2008-04-13] (Microsoft Corporation) [File not signed]
R0 FltMgr; C:\WINDOWS\System32\drivers\fltmgr.sys [129792 2008-04-13] (Microsoft Corporation) [File not signed]
U1 Fs_Rec; C:\WINDOWS\system32\Drivers\Fs_Rec.sys [7936 2004-08-04] (Microsoft Corporation) [File not signed]
R0 Ftdisk; C:\WINDOWS\System32\DRIVERS\ftdisk.sys [125056 2004-08-04] (Microsoft Corporation) [File not signed]
R3 Gpc; C:\WINDOWS\System32\DRIVERS\msgpc.sys [35072 2008-04-13] (Microsoft Corporation) [File not signed]
R3 GTNDIS5; C:\WINDOWS\system32\GTNDIS5.SYS [15872 2003-09-25] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R3 ha10kx2k; C:\WINDOWS\System32\drivers\ha10kx2k.sys [823616 2003-03-26] (Creative Technology Ltd) [File not signed]
R3 hap16v2k; C:\WINDOWS\System32\drivers\hap16v2k.sys [141536 2003-03-26] (Creative Technology Ltd) [File not signed]
R3 hidusb; C:\WINDOWS\System32\DRIVERS\hidusb.sys [10368 2008-04-13] (Microsoft Corporation) [File not signed]
S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [147912 2013-09-23] (McAfee, Inc.)
R3 HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys [212224 2003-11-17] (Conexant Systems, Inc.) [File not signed]
R3 HSF_DP; C:\WINDOWS\System32\DRIVERS\HSF_DP.sys [1042432 2003-11-17] (Conexant Systems, Inc.) [File not signed]
R3 HTTP; C:\WINDOWS\System32\Drivers\HTTP.sys [265728 2009-10-20] (Microsoft Corporation) [File not signed]
R1 i8042prt; C:\WINDOWS\System32\DRIVERS\i8042prt.sys [52480 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Imapi; C:\WINDOWS\System32\DRIVERS\imapi.sys [42112 2008-04-13] (Microsoft Corporation) [File not signed]
R0 IntelIde; C:\WINDOWS\System32\DRIVERS\intelide.sys [5504 2008-04-13] (Microsoft Corporation) [File not signed]
R1 intelppm; C:\WINDOWS\System32\DRIVERS\intelppm.sys [36352 2008-04-13] (Microsoft Corporation) [File not signed]
S3 Ip6Fw; C:\WINDOWS\System32\drivers\ip6fw.sys [36608 2008-04-13] (Microsoft Corporation) [File not signed]
S3 IpFilterDriver; C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys [32896 2004-08-04] (Microsoft Corporation) [File not signed]
S3 IpInIp; C:\WINDOWS\System32\DRIVERS\ipinip.sys [20864 2008-04-13] (Microsoft Corporation) [File not signed]
R3 IpNat; C:\WINDOWS\System32\DRIVERS\ipnat.sys [152832 2008-04-13] (Microsoft Corporation) [File not signed]
R1 IPSec; C:\WINDOWS\System32\DRIVERS\ipsec.sys [75264 2008-04-13] (Microsoft Corporation) [File not signed]
S3 IRENUM; C:\WINDOWS\System32\DRIVERS\irenum.sys [11264 2008-04-13] (Microsoft Corporation) [File not signed]
R0 isapnp; C:\WINDOWS\System32\DRIVERS\isapnp.sys [37248 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Kbdclass; C:\WINDOWS\System32\DRIVERS\kbdclass.sys [24576 2008-04-13] (Microsoft Corporation) [File not signed]
R1 kbdhid; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [14592 2008-04-13] (Microsoft Corporation) [File not signed]
R3 kmixer; C:\WINDOWS\System32\drivers\kmixer.sys [172416 2008-04-13] (Microsoft Corporation) [File not signed]
R0 KSecDD; C:\WINDOWS\system32\Drivers\KSecDD.sys [92928 2009-06-24] (Microsoft Corporation) [File not signed]
S3 libusb0; C:\WINDOWS\System32\DRIVERS\libusb0.sys [42592 2012-07-31] (
http://libusb-win32.sourceforge.net)
R3 LVPr2Mon; C:\WINDOWS\System32\Drivers\LVPr2Mon.sys [25752 2009-10-07] ()
R2 mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [11043 2003-04-09] (Conexant) [File not signed]
R3 mfeapfk; C:\WINDOWS\System32\drivers\mfeapfk.sys [135968 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [238176 2014-06-20] (McAfee, Inc.)
S3 mfebopk; C:\WINDOWS\System32\drivers\mfebopk.sys [67816 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [369248 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [575984 2015-02-11] (McAfee, Inc.)
R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [350240 2014-08-20] (McAfee, Inc.)
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [81296 2014-08-20] (McAfee, Inc.)
S3 mfendisk; C:\WINDOWS\System32\DRIVERS\mfendisk.sys [87520 2014-06-20] (McAfee, Inc.)
R3 mfendiskmp; C:\WINDOWS\System32\DRIVERS\mfendisk.sys [87520 2014-06-20] (McAfee, Inc.)
R1 mfetdi2k; C:\WINDOWS\System32\drivers\mfetdi2k.sys [93624 2014-06-20] (McAfee, Inc.)
R1 mnmdd; C:\WINDOWS\system32\Drivers\mnmdd.sys [4224 2004-08-04] (Microsoft Corporation) [File not signed]
R3 Modem; C:\WINDOWS\system32\Drivers\Modem.sys [30080 2008-04-13] (Microsoft Corporation) [File not signed]
S3 MODEMCSA; C:\WINDOWS\System32\drivers\MODEMCSA.sys [16128 2001-08-17] (Microsoft Corporation) [File not signed]
S3 motccgp; C:\WINDOWS\System32\DRIVERS\motccgp.sys [20480 2011-04-04] (Motorola) [File not signed]
S3 motccgpfl; C:\WINDOWS\System32\DRIVERS\motccgpfl.sys [8320 2009-01-29] (Motorola) [File not signed]
S3 motmodem; C:\WINDOWS\System32\DRIVERS\motmodem.sys [24064 2011-03-31] (Motorola) [File not signed]
S3 MotoSwitchService; C:\WINDOWS\System32\DRIVERS\motswch.sys [6400 2007-11-02] (Motorola) [File not signed]
S3 Motousbnet; C:\WINDOWS\System32\DRIVERS\Motousbnet.sys [23424 2010-04-01] (Motorola) [File not signed]
S3 motusbdevice; C:\WINDOWS\System32\DRIVERS\motusbdevice.sys [9472 2010-01-25] (Motorola Inc) [File not signed]
R1 Mouclass; C:\WINDOWS\System32\DRIVERS\mouclass.sys [23040 2008-04-13] (Microsoft Corporation) [File not signed]
R3 mouhid; C:\WINDOWS\System32\DRIVERS\mouhid.sys [12160 2004-08-04] (Microsoft Corporation) [File not signed]
R0 MountMgr; C:\WINDOWS\system32\Drivers\MountMgr.sys [42368 2008-04-13] (Microsoft Corporation) [File not signed]
R3 MRxDAV; C:\WINDOWS\System32\DRIVERS\mrxdav.sys [180608 2008-04-13] (Microsoft Corporation) [File not signed]
R1 MRxSmb; C:\WINDOWS\System32\DRIVERS\mrxsmb.sys [456320 2011-07-15] (Microsoft Corporation) [File not signed]
S3 MSDV; C:\WINDOWS\System32\DRIVERS\msdv.sys [51200 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Msfs; C:\WINDOWS\system32\Drivers\Msfs.sys [19072 2008-04-13] (Microsoft Corporation) [File not signed]
S3 MSKSSRV; C:\WINDOWS\System32\drivers\MSKSSRV.sys [7552 2008-04-13] (Microsoft Corporation) [File not signed]
S3 MSPCLOCK; C:\WINDOWS\System32\drivers\MSPCLOCK.sys [5376 2008-04-13] (Microsoft Corporation) [File not signed]
S3 MSPQM; C:\WINDOWS\System32\drivers\MSPQM.sys [4992 2008-04-13] (Microsoft Corporation) [File not signed]
R3 mssmbios; C:\WINDOWS\System32\DRIVERS\mssmbios.sys [15488 2008-04-13] (Microsoft Corporation) [File not signed]
S3 MSTEE; C:\WINDOWS\System32\drivers\MSTEE.sys [5504 2008-04-13] (Microsoft Corporation) [File not signed]
R0 Mup; C:\WINDOWS\system32\Drivers\Mup.sys [105472 2011-04-21] (Microsoft Corporation) [File not signed]
R3 MxlW2k; C:\WINDOWS\system32\Drivers\MxlW2k.sys [28352 2010-01-12] (MusicMatch, Inc.) [File not signed]
S3 NABTSFEC; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-13] (Microsoft Corporation) [File not signed]
R0 NDIS; C:\WINDOWS\system32\Drivers\NDIS.sys [182656 2008-04-13] (Microsoft Corporation) [File not signed]
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation) [File not signed]
R3 NdisTapi; C:\WINDOWS\System32\DRIVERS\ndistapi.sys [10496 2011-07-08] (Microsoft Corporation) [File not signed]
R3 Ndisuio; C:\WINDOWS\System32\DRIVERS\ndisuio.sys [14592 2008-04-13] (Microsoft Corporation) [File not signed]
R3 NdisWan; C:\WINDOWS\System32\DRIVERS\ndiswan.sys [91520 2008-04-13] (Microsoft Corporation) [File not signed]
R3 NDProxy; C:\WINDOWS\system32\Drivers\NDProxy.sys [40960 2013-11-27] (Microsoft Corporation) [File not signed]
R1 NetBIOS; C:\WINDOWS\System32\DRIVERS\netbios.sys [34688 2008-04-13] (Microsoft Corporation) [File not signed]
R1 NetBT; C:\WINDOWS\System32\DRIVERS\netbt.sys [162816 2008-04-13] (Microsoft Corporation) [File not signed]
R3 NIC1394; C:\WINDOWS\System32\DRIVERS\nic1394.sys [61824 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Npfs; C:\WINDOWS\system32\Drivers\Npfs.sys [30848 2008-04-13] (Microsoft Corporation) [File not signed]
R4 Ntfs; C:\WINDOWS\system32\Drivers\Ntfs.sys [574976 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Null; C:\WINDOWS\system32\Drivers\Null.sys [2944 2004-08-04] (Microsoft Corporation) [File not signed]
R3 nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [1897408 2004-08-04] (NVIDIA Corporation) [File not signed]
S3 NwlnkFlt; C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys [12416 2004-08-04] (Microsoft Corporation) [File not signed]
S3 NwlnkFwd; C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys [32512 2004-08-04] (Microsoft Corporation) [File not signed]
R0 ohci1394; C:\WINDOWS\System32\DRIVERS\ohci1394.sys [61696 2008-04-13] (Microsoft Corporation) [File not signed]
R1 OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [13632 2001-08-22] (Dell Computer Corporation) [File not signed]
R3 ossrv; C:\WINDOWS\System32\drivers\ctoss2k.sys [189504 2003-03-26] (Creative Technology Ltd.) [File not signed]
R3 Parport; C:\WINDOWS\System32\DRIVERS\parport.sys [80128 2008-04-13] (Microsoft Corporation) [File not signed]
R0 PartMgr; C:\WINDOWS\system32\Drivers\PartMgr.sys [19712 2008-04-13] (Microsoft Corporation) [File not signed]
R2 ParVdm; C:\WINDOWS\system32\Drivers\ParVdm.sys [6784 2004-08-04] (Microsoft Corporation) [File not signed]
R0 PCI; C:\WINDOWS\System32\DRIVERS\pci.sys [68224 2008-04-13] (Microsoft Corporation) [File not signed]
R0 PCIIde; C:\WINDOWS\System32\DRIVERS\pciide.sys [3328 2001-08-17] (Microsoft Corporation) [File not signed]
S4 Pcmcia; C:\WINDOWS\system32\Drivers\Pcmcia.sys [120192 2008-04-13] (Microsoft Corporation) [File not signed]
R3 pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [47360 2010-09-17] (VSO Software) [File not signed]
R2 PDFsFilter; C:\WINDOWS\System32\DRIVERS\PDFsFilter.sys [68464 2013-12-03] (Raxco Software, Inc.)
R2 PfModNT; C:\WINDOWS\system32\drivers\PfModNT.sys [15840 2003-03-06] (Creative Technology Ltd.) [File not signed]
R3 PptpMiniport; C:\WINDOWS\System32\DRIVERS\raspptp.sys [48384 2008-04-13] (Microsoft Corporation) [File not signed]
R3 PSched; C:\WINDOWS\System32\DRIVERS\psched.sys [69120 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Ptilink; C:\WINDOWS\System32\DRIVERS\ptilink.sys [17792 2004-08-04] (Parallel Technologies, Inc.) [File not signed]
R1 RasAcd; C:\WINDOWS\System32\DRIVERS\rasacd.sys [8832 2004-08-04] (Microsoft Corporation) [File not signed]
R3 Rasl2tp; C:\WINDOWS\System32\DRIVERS\rasl2tp.sys [51328 2008-04-13] (Microsoft Corporation) [File not signed]
R3 RasPppoe; C:\WINDOWS\System32\DRIVERS\raspppoe.sys [41472 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Raspti; C:\WINDOWS\System32\DRIVERS\raspti.sys [16512 2004-08-04] (Microsoft Corporation) [File not signed]
R1 Rdbss; C:\WINDOWS\System32\DRIVERS\rdbss.sys [175744 2008-04-13] (Microsoft Corporation) [File not signed]
R1 RDPCDD; C:\WINDOWS\System32\DRIVERS\RDPCDD.sys [4224 2004-08-04] (Microsoft Corporation) [File not signed]
R1 redbook; C:\WINDOWS\System32\DRIVERS\redbook.sys [57600 2008-04-13] (Microsoft Corporation) [File not signed]
S3 RemoteControl-USBLAN; C:\WINDOWS\System32\DRIVERS\rcblan.sys [39704 2007-01-24] (Belcarra Technologies)
R3 RT73; C:\WINDOWS\System32\DRIVERS\rt73.sys [245248 2005-11-24] (Ralink Technology, Corp.) [File not signed]
S3 Secdrv; C:\WINDOWS\System32\DRIVERS\secdrv.sys [20480 2008-04-13] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
R3 serenum; C:\WINDOWS\System32\DRIVERS\serenum.sys [15744 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Serial; C:\WINDOWS\System32\DRIVERS\serial.sys [64512 2008-04-13] (Microsoft Corporation) [File not signed]
S3 SLIP; C:\WINDOWS\System32\DRIVERS\SLIP.sys [11136 2008-04-13] (Microsoft Corporation) [File not signed]
S3 splitter; C:\WINDOWS\System32\drivers\splitter.sys [6272 2008-04-13] (Microsoft Corporation) [File not signed]
R0 sr; C:\WINDOWS\System32\DRIVERS\sr.sys [73472 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Srv; C:\WINDOWS\System32\DRIVERS\srv.sys [357888 2011-02-17] (Microsoft Corporation) [File not signed]
S3 SSKBFD; C:\WINDOWS\System32\Drivers\sskbfd.sys [20848 2008-05-28] (Webroot Software Inc (
www.webroot.com))
R1 StarOpen; C:\WINDOWS\system32\Drivers\StarOpen.sys [5632 2011-07-25] () [File not signed]
S3 streamip; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [15232 2008-04-13] (Microsoft Corporation) [File not signed]
R3 swenum; C:\WINDOWS\System32\DRIVERS\swenum.sys [4352 2008-04-13] (Microsoft Corporation) [File not signed]
S3 swmidi; C:\WINDOWS\System32\drivers\swmidi.sys [56576 2008-04-13] (Microsoft Corporation) [File not signed]
S3 SymEvent; C:\Program Files\Symantec\SYMEVENT.SYS [82136 2003-08-15] (Symantec Corporation)
R3 sysaudio; C:\WINDOWS\System32\drivers\sysaudio.sys [60800 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Tcpip; C:\WINDOWS\System32\DRIVERS\tcpip.sys [361600 2008-06-20] (Microsoft Corporation) [File not signed]
S3 TDPIPE; C:\WINDOWS\system32\Drivers\TDPIPE.sys [12040 2008-04-13] (Microsoft Corporation) [File not signed]
S3 TDTCP; C:\WINDOWS\system32\Drivers\TDTCP.sys [21896 2008-04-13] (Microsoft Corporation) [File not signed]
R1 TermDD; C:\WINDOWS\System32\DRIVERS\termdd.sys [40840 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Update; C:\WINDOWS\System32\DRIVERS\update.sys [384768 2008-04-13] (Microsoft Corporation) [File not signed]
S3 USBAAPL; C:\WINDOWS\System32\Drivers\usbaapl.sys [44544 2012-09-28] (Apple, Inc.) [File not signed]
S3 usbaudio; C:\WINDOWS\System32\drivers\usbaudio.sys [60160 2013-07-16] (Microsoft Corporation) [File not signed]
R3 usbccgp; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [32384 2013-08-08] (Microsoft Corporation) [File not signed]
R3 usbehci; C:\WINDOWS\System32\DRIVERS\usbehci.sys [30336 2009-03-18] (Microsoft Corporation) [File not signed]
R3 usbhub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [59520 2008-04-13] (Microsoft Corporation) [File not signed]
R3 usbprint; C:\WINDOWS\System32\DRIVERS\usbprint.sys [25856 2008-04-13] (Microsoft Corporation) [File not signed]
R3 usbscan; C:\WINDOWS\System32\DRIVERS\usbscan.sys [14976 2013-07-02] (Microsoft Corporation) [File not signed]
R3 USBSTOR; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [26368 2008-04-13] (Microsoft Corporation) [File not signed]
R3 usbuhci; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [20608 2008-04-13] (Microsoft Corporation) [File not signed]
S3 usbvideo; C:\WINDOWS\System32\Drivers\usbvideo.sys [123008 2013-07-16] (Microsoft Corporation) [File not signed]
R1 VgaSave; C:\WINDOWS\System32\drivers\vga.sys [20992 2008-04-13] (Microsoft Corporation) [File not signed]
R0 VolSnap; C:\WINDOWS\system32\Drivers\VolSnap.sys [52352 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Wanarp; C:\WINDOWS\System32\DRIVERS\wanarp.sys [34560 2008-04-13] (Microsoft Corporation) [File not signed]
R3 wdmaud; C:\WINDOWS\System32\drivers\wdmaud.sys [83072 2008-04-13] (Microsoft Corporation) [File not signed]
R3 winachsf; C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys [680704 2003-11-17] (Conexant Systems, Inc.) [File not signed]
S3 WpdUsb; C:\WINDOWS\System32\DRIVERS\wpdusb.sys [38528 2006-10-18] (Microsoft Corporation) [File not signed]
R2 Wpsnuio; C:\WINDOWS\System32\DRIVERS\wpsnuio.sys [13696 2013-05-31] (Skyhook Wireless) [File not signed]
S3 WSTCODEC; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-13] (Microsoft Corporation) [File not signed]
R0 WudfPf; C:\WINDOWS\System32\DRIVERS\WudfPf.sys [77568 2006-09-28] (Microsoft Corporation) [File not signed]
S3 WudfRd; C:\WINDOWS\System32\DRIVERS\wudfrd.sys [82944 2006-09-28] (Microsoft Corporation) [File not signed]
U0 mfewfpk; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) [File not signed]
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-28 19:49 - 2015-03-28 19:51 - 00000000 ____D () C:\FRST
2015-03-28 19:40 - 2015-03-28 19:40 - 00000000 ____D () C:\Documents and Settings\RAUL_104\Local Settings\Application Data\IDTool
2015-03-28 17:53 - 2015-03-28 17:53 - 00000000 ____D () C:\Documents and Settings\RAUL_104\Desktop\idtool
2015-03-24 21:37 - 2015-03-24 21:37 - 00074703 _____ () C:\WINDOWS\system32\mfc45.dat
2015-03-24 12:25 - 2015-03-24 12:27 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-22 23:32 - 2015-03-23 23:53 - 00000000 ____D () C:\Documents and Settings\RAUL_104\Desktop\AMY S3
2015-03-12 09:57 - 2015-03-12 09:57 - 00000000 _____ () C:\avenger.txt
2015-03-12 09:55 - 2015-03-12 09:55 - 00052440 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\imtmeaq.sys
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-28 19:55 - 2009-03-26 12:27 - 00000000 ____D () C:\Documents and Settings\RAUL_104\Local Settings\Temp
2015-03-28 19:38 - 2009-06-30 04:45 - 00000990 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-117609710-839522115-1004UA.job
2015-03-28 19:35 - 2012-08-28 00:18 - 00000886 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-28 19:30 - 2009-03-26 07:12 - 00647862 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-28 19:27 - 2013-05-10 23:06 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
2015-03-28 19:22 - 2014-02-24 18:57 - 00524288 _____ () C:\WINDOWS\system32\config\ACEEvent.evt
2015-03-28 19:20 - 2009-03-26 07:14 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-03-28 19:19 - 2010-12-16 01:45 - 00783804 _____ () C:\Documents and Settings\All Users\dleascan.log
2015-03-28 19:19 - 2009-03-28 00:33 - 00000000 ____D () C:\MDT
2015-03-28 19:19 - 2009-03-26 07:14 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2015-03-28 19:18 - 2015-01-16 18:19 - 00000254 ____H () C:\WINDOWS\Tasks\dluddia.job
2015-03-28 19:18 - 2014-03-23 18:55 - 00000228 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-03-28 19:18 - 2012-08-28 00:18 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-28 19:18 - 2010-08-08 00:34 - 00000616 ____H () C:\WINDOWS\Tasks\ConfigExec.job
2015-03-28 19:18 - 2009-03-26 12:23 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-03-28 19:17 - 2009-03-26 16:49 - 00001080 _____ () C:\WINDOWS\system32\settingsbkup.sfm
2015-03-28 19:17 - 2009-03-26 16:49 - 00001080 _____ () C:\WINDOWS\system32\settings.sfm
2015-03-28 19:17 - 2009-03-26 16:49 - 00000288 _____ () C:\WINDOWS\system32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2015-03-28 19:17 - 2009-03-26 16:49 - 00000288 _____ () C:\WINDOWS\system32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2015-03-28 19:16 - 2014-04-13 01:41 - 01048576 _____ () C:\WINDOWS\system32\config\iolo App.evt
2015-03-28 19:16 - 2014-01-19 02:28 - 00178066 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2015-03-28 19:16 - 2013-10-14 00:56 - 00593344 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2015-03-28 19:16 - 2010-08-07 23:59 - 15728640 _____ () C:\WINDOWS\system32\config\WindowsPowerShell.evt
2015-03-28 19:16 - 2009-03-26 12:27 - 00000178 ___SH () C:\Documents and Settings\RAUL_104\ntuser.ini
2015-03-28 19:16 - 2009-03-26 12:23 - 00032564 _____ () C:\WINDOWS\SchedLgU.Txt
2015-03-28 19:16 - 2009-03-26 12:20 - 02041696 _____ () C:\WINDOWS\WindowsUpdate.log
2015-03-28 19:13 - 2009-03-26 14:46 - 04481358 _____ () C:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.CDF
2015-03-28 19:09 - 2014-09-26 19:45 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-03-28 18:57 - 2009-03-26 07:10 - 00000211 ___SH () C:\boot.ini
2015-03-28 18:57 - 2004-08-04 06:00 - 00000687 _____ () C:\WINDOWS\win.ini
2015-03-28 18:57 - 2004-08-04 06:00 - 00000227 _____ () C:\WINDOWS\system.ini
2015-03-28 16:52 - 2015-02-01 00:28 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MFAData
2015-03-27 20:34 - 2010-08-08 00:34 - 00000580 ____H () C:\WINDOWS\Tasks\DataUpload.job
2015-03-27 13:01 - 2014-04-05 13:35 - 00000458 _____ () C:\WINDOWS\Tasks\SystemToolsDailyTest.job
2015-03-27 12:38 - 2009-06-30 04:45 - 00000938 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-117609710-839522115-1004Core.job
2015-03-27 02:04 - 2015-01-27 20:14 - 00000412 ____H () C:\WINDOWS\Tasks\CryptoUpdate.job
2015-03-26 13:13 - 2012-04-29 19:25 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-03-24 23:25 - 2012-04-07 03:32 - 00778928 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-03-24 23:25 - 2011-05-15 18:00 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-03-24 23:25 - 2009-03-27 11:50 - 00000000 ____D () C:\Documents and Settings\RAUL_104\Local Settings\Application Data\Adobe
2015-03-24 21:59 - 2012-08-04 22:57 - 00015414 _____ () C:\WINDOWS\wmsetup.log
2015-03-24 21:57 - 2010-03-16 23:31 - 00000069 _____ () C:\WINDOWS\NeroDigital.ini
2015-03-24 21:57 - 2010-02-18 15:12 - 00000128 _____ () C:\Documents and Settings\RAUL_104\Application Data\default.rss
2015-03-24 04:44 - 2011-08-19 23:54 - 00000000 ____D () C:\Documents and Settings\RAUL_104\Application Data\FileZilla
2015-03-21 13:39 - 2009-03-27 00:28 - 00002309 _____ () C:\Documents and Settings\RAUL_104\Desktop\Google Chrome.lnk
2015-03-21 04:00 - 2010-09-10 16:07 - 00000330 ____H () C:\WINDOWS\Tasks\MP Scheduled Scan.job
2015-03-21 04:00 - 2009-03-26 12:23 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Temp
2015-03-19 10:13 - 2009-03-26 12:27 - 00000000 ____D () C:\Documents and Settings\RAUL_104
2015-03-19 09:38 - 2004-08-04 06:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2015-03-13 11:52 - 2015-01-25 21:09 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-03-12 09:55 - 2009-12-08 21:20 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB970430$
2015-03-09 12:47 - 2015-02-01 00:49 - 00000702 _____ () C:\Documents and Settings\All Users\Desktop\AVG 2015.lnk
2015-03-09 12:47 - 2015-02-01 00:49 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\AVG
2015-03-09 12:40 - 2015-02-01 00:42 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\AVG2015
2015-03-09 10:09 - 2014-03-23 18:55 - 00000222 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2015-03-08 17:51 - 2010-09-15 20:25 - 00000000 ____D () C:\Documents and Settings\AMY_1061\Local Settings\Temp
2015-03-01 11:01 - 2014-04-05 13:35 - 00000520 _____ () C:\WINDOWS\Tasks\PCDoctorBackgroundMonitorTask.job
2015-02-26 17:05 - 2010-02-01 18:16 - 00002187 _____ () C:\Documents and Settings\All Users\Desktop\Safari.lnk
2015-02-26 17:04 - 2010-09-19 00:39 - 00002397 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Safari.lnk
==================== Files in the root of some directories =======
2010-02-18 15:12 - 2015-03-24 21:57 - 0000128 _____ () C:\Documents and Settings\RAUL_104\Application Data\default.rss
2015-01-27 22:42 - 2015-01-27 22:42 - 0045601 _____ () C:\Documents and Settings\RAUL_104\Application Data\HELP_DECRYPT.PNG
2015-01-27 22:42 - 2015-01-27 22:42 - 0000276 _____ () C:\Documents and Settings\RAUL_104\Application Data\HELP_DECRYPT.URL
2010-09-17 23:40 - 2010-09-17 23:40 - 0087608 _____ () C:\Documents and Settings\RAUL_104\Application Data\inst.exe
2010-09-17 23:40 - 2010-09-17 23:40 - 0007887 _____ () C:\Documents and Settings\RAUL_104\Application Data\pcouffin.cat
2010-09-17 23:40 - 2010-09-17 23:40 - 0001144 _____ () C:\Documents and Settings\RAUL_104\Application Data\pcouffin.inf
2010-09-17 23:41 - 2010-09-17 23:41 - 0000034 _____ () C:\Documents and Settings\RAUL_104\Application Data\pcouffin.log
2010-09-17 23:40 - 2010-09-17 23:40 - 0047360 _____ (VSO Software) C:\Documents and Settings\RAUL_104\Application Data\pcouffin.sys
2011-09-03 20:36 - 2011-09-03 20:36 - 0000338 _____ () C:\Documents and Settings\RAUL_104\Application Data\settings.dat
2010-09-17 23:30 - 2013-08-31 01:36 - 0001057 _____ () C:\Documents and Settings\RAUL_104\Application Data\vso_ts_preview.xml
2015-01-27 20:15 - 2015-01-27 20:15 - 0000480 ____H () C:\Documents and Settings\RAUL_104\Application Data\麽鎒駓覜
2011-01-26 16:37 - 2014-11-13 17:57 - 0038912 _____ () C:\Documents and Settings\RAUL_104\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-28 10:50 - 2015-01-28 10:50 - 0045601 _____ () C:\Documents and Settings\RAUL_104\Local Settings\Application Data\HELP_DECRYPT.PNG
2015-01-28 10:50 - 2015-01-28 10:50 - 0000276 _____ () C:\Documents and Settings\RAUL_104\Local Settings\Application Data\HELP_DECRYPT.URL
2012-04-27 13:38 - 2012-04-27 13:38 - 0000600 _____ () C:\Documents and Settings\RAUL_104\Local Settings\Application Data\PUTTY.RND
2010-12-16 11:18 - 2010-12-16 11:18 - 0000000 _____ () C:\Documents and Settings\All Users\cmn_upld.log
2011-01-07 14:36 - 2014-12-28 19:29 - 0144468 _____ () C:\Documents and Settings\All Users\dlea.log
2014-11-19 17:09 - 2014-11-19 17:23 - 0000248 _____ () C:\Documents and Settings\All Users\dleaDiagnostics.log
2010-12-20 22:02 - 2014-11-19 16:03 - 0048470 _____ () C:\Documents and Settings\All Users\dleaJSW.log
2010-12-16 01:45 - 2015-03-28 19:19 - 0783804 _____ () C:\Documents and Settings\All Users\dleascan.log
2010-12-16 11:30 - 2013-05-30 17:27 - 0000756 _____ () C:\Documents and Settings\All Users\FastPics.log
2010-12-16 11:18 - 2010-12-16 11:18 - 0000000 _____ () C:\Documents and Settings\All Users\LxWbGwLog.log
2015-01-25 10:44 - 2015-01-25 10:44 - 0241664 ____N () C:\Documents and Settings\All Users\qicswp.exe
2010-12-16 01:31 - 2010-12-16 01:31 - 0000000 _____ () C:\Documents and Settings\All Users\UpdaterLog.txt
Files to move or delete:
====================
C:\Documents and Settings\All Users\qicswp.exe
C:\Documents and Settings\AMY_106\hpothb07.dat
C:\Documents and Settings\RAUL_104\msndata.dat
C:\Documents and Settings\RAUL_104\SIMRecoveryPro.exe
Some content of TEMP:
====================
C:\Documents and Settings\AMY_106\Local Settings\Temp\GLF3F02.tmp.tbZyng.dll
C:\Documents and Settings\AMY_106\Local Settings\Temp\Zynga.exe
C:\Documents and Settings\AMY_1061\Local Settings\Temp\bwgo0004f4bc.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\ARS.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0003a7ab.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0003c209.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000463c7.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00046965.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000519e8.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00051e4d.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000543d6.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000557bc.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0005a010.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0005c54b.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0005f60f.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00063367.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000636d2.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00063ad9.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000655d3.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000661f8.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00066d82.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00069770.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0006ac6f.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0006c035.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0006d6ab.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00072a59.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00076724.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0007707a.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00077bd5.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0007a7d6.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0007e898.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0007eb29.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0007f0b7.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00083f73.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0008723b.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00088342.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0008c80c.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0008f8e0.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00090b4e.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00090d42.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00092752.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00097bbc.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00099648.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000b6404.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000b971a.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000c7360.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000de82e.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000e0fca.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000e9110.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo000e9e20.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo001011f3.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00102c23.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00103078.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00114999.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0013e15b.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo001739dc.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0018c59d.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo002e4d74.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo0030a4e1.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo00b5f6e2.exe
C:\Documents and Settings\RAUL_104\Local Settings\Temp\bwgo01b15fb9.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => MD5 is legit
C:\WINDOWS\system32\winlogon.exe => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
C:\WINDOWS\system32\User32.dll => MD5 is legit
C:\WINDOWS\system32\userinit.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================