Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-11-2014 01
Ran by HP_Administrator (administrator) on YOUR-55E5F9E3D2 on 08-11-2014 19:27:49
Running from C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop
Loaded Profile: HP_Administrator (Available profiles: HP_Administrator & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 6
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe
(Hewlett-Packard Company) C:\WINDOWS\system\hpsysdrv.exe
() C:\Program Files\Canon\IJPLM\ijplmsvc.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jqs.exe
(Agere Systems) C:\WINDOWS\AGRSMMSG.exe
() C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Hewlett-Packard Company) C:\hp\KBD\kbd.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\SOUNDMAN.EXE
(RealTek Semicoductor Corp.) C:\WINDOWS\ALCWZRD.EXE
(Hewlett-Packard Company) C:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe
(ScanSoft, Inc.) C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe
(Alcatel-Lucent) C:\Program Files\Common Files\Motive\McciCMService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ehTray] => C:\WINDOWS\ehome\ehtray.exe [59392 2004-08-10] (Microsoft Corporation)
HKLM\...\Run: [hpsysdrv] => c:\windows\system\hpsysdrv.exe [52736 1998-05-07] (Hewlett-Packard Company)
HKLM\...\Run: [High Definition Audio Property Page Shortcut] => C:\WINDOWS\system32\HDAudPropShortcut.exe [61952 2004-03-17] (Windows ® Server 2003 DDK provider)
HKLM\...\Run: [AGRSMMSG] => C:\WINDOWS\AGRSMMSG.exe [88363 2004-06-29] (Agere Systems)
HKLM\...\Run: [HPHUPD06] => c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe [49152 2004-06-07] (Hewlett-Packard)
HKLM\...\Run: [HPHmon06] => C:\WINDOWS\system32\hphmon06.exe [659456 2004-06-07] (Hewlett-Packard)
HKLM\...\Run: [KBD] => C:\HP\KBD\KBD.EXE [61440 2003-02-11] (Hewlett-Packard Company)
HKLM\...\Run: [Recguard] => C:\WINDOWS\SMINST\RECGUARD.EXE [233472 2004-04-14] ()
HKLM\...\Run: [PS2] => C:\WINDOWS\system32\ps2.exe [90112 2004-10-25] (Hewlett-Packard Company)
HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [77824 2004-10-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AlcWzrd] => C:\WINDOWS\ALCWZRD.EXE [2742272 2004-10-13] (RealTek Semicoductor Corp.)
HKLM\...\Run: [LSBWatcher] => c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe [253952 2004-10-14] (Hewlett-Packard Company)
HKLM\...\Run: [OpwareSE2] => C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe [49152 2003-05-08] (ScanSoft, Inc.)
HKLM\...\Run: [UnlockerAssistant] => C:\Program Files\Unlocker\UnlockerAssistant.exe [15872 2006-09-07] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [34672 2008-06-12] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-10-15] (AVAST Software)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoCDBurning] 1
HKU\S-1-5-21-2060318294-1635822940-3861741363-1008\...\Policies\Explorer: [NoChangeStartMenu] 0
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2060318294-1635822940-3861741363-1008\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
BHO: SnagIt Toolbar Loader -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: EWPBrowseObject Class -> {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} -> C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class -> {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -> C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
Toolbar: HKLM - Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
Toolbar: HKCU - HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF Plugin: @Motive.com/NpMotive,version=1.0 -> C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF Plugin: @real.com/nppl3260;version=6.0.11.1879 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.2.1939 -> C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.872 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2010-04-21]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-01-26]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-19]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-19]
CHR Extension: (Avast Online Security) - C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-19]
CHR Extension: (Google Wallet) - C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-19]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-15]
==================== Services (All) ========================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 Alerter; C:\WINDOWS\system32\alrsvc.dll [17408 2004-08-10] (Microsoft Corporation)
R3 ALG; C:\WINDOWS\System32\alg.exe [44544 2004-08-10] (Microsoft Corporation)
S3 AppMgmt; C:\WINDOWS\System32\appmgmts.dll [167936 2004-08-10] (Microsoft Corporation)
S3 aspnet_state; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [32768 2004-07-15] (Microsoft Corporation) [File not signed]
R2 AudioSrv; C:\WINDOWS\System32\audiosrv.dll [42496 2004-08-10] (Microsoft Corporation)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-15] (AVAST Software)
S3 BITS; C:\WINDOWS\system32\qmgr.dll [382464 2004-08-10] (Microsoft Corporation)
S2 Browser; C:\WINDOWS\System32\browser.dll [77312 2004-08-10] (Microsoft Corporation)
S3 CiSvc; C:\WINDOWS\system32\cisvc.exe [5632 2004-08-10] (Microsoft Corporation)
S3 ClipSrv; C:\WINDOWS\system32\clipsrv.exe [33280 2004-08-10] (Microsoft Corporation)
S3 COMSysApp; C:\WINDOWS\system32\dllhost.exe [5120 2004-08-10] (Microsoft Corporation)
R2 CryptSvc; C:\WINDOWS\System32\cryptsvc.dll [60416 2004-08-10] (Microsoft Corporation)
R2 DcomLaunch; C:\WINDOWS\system32\rpcss.dll [399360 2009-02-09] (Microsoft Corporation)
R2 Dhcp; C:\WINDOWS\System32\dhcpcsvc.dll [111104 2004-08-10] (Microsoft Corporation)
S3 dmadmin; C:\WINDOWS\System32\dmadmin.exe [224768 2004-08-10] (Microsoft Corp., Veritas Software)
R2 dmserver; C:\WINDOWS\System32\dmserver.dll [23552 2004-08-10] (Microsoft Corp.)
R2 Dnscache; C:\WINDOWS\System32\dnsrslvr.dll [45568 2004-08-10] (Microsoft Corporation)
R2 ERSvc; C:\WINDOWS\System32\ersvc.dll [23040 2004-08-10] (Microsoft Corporation)
R2 Eventlog; C:\WINDOWS\system32\services.exe [110592 2009-02-06] (Microsoft Corporation)
R3 EventSystem; C:\WINDOWS\system32\es.dll [253952 2008-07-07] (Microsoft Corporation)
R3 FastUserSwitchingCompatibility; C:\WINDOWS\System32\shsvcs.dll [134656 2004-08-10] (Microsoft Corporation)
S3 Fax; C:\WINDOWS\system32\fxssvc.exe [267776 2004-08-10] (Microsoft Corporation)
S2 gupdate; C:\Program Files\Google\Update\GoogleUpdate.exe [116648 2014-10-15] (Google Inc.)
S3 gupdatem; C:\Program Files\Google\Update\GoogleUpdate.exe [116648 2014-10-15] (Google Inc.)
R2 HidServ; C:\WINDOWS\System32\hidserv.dll [21504 2004-08-04] (Microsoft Corporation)
S3 HTTPFilter; C:\WINDOWS\System32\w3ssl.dll [15872 2004-08-10] (Microsoft Corporation)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] ()
S3 ImapiService; C:\WINDOWS\system32\imapi.exe [150016 2004-08-10] (Microsoft Corporation)
S4 iPodService; C:\Program Files\iPod\bin\iPodService.exe [323584 2006-02-23] (Apple Computer, Inc.) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre6\bin\jqs.exe [153376 2010-04-21] (Sun Microsystems, Inc.)
R2 lanmanserver; C:\WINDOWS\System32\srvsvc.dll [96768 2004-08-10] (Microsoft Corporation)
R2 lanmanworkstation; C:\WINDOWS\System32\wkssvc.dll [132096 2009-06-09] (Microsoft Corporation)
R2 LightScribeService; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [38912 2004-09-23] () [File not signed]
R2 LmHosts; C:\WINDOWS\System32\lmhsvc.dll [13824 2004-08-10] (Microsoft Corporation)
R2 McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [319488 2010-04-30] (Alcatel-Lucent) [File not signed]
R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [322120 2003-06-20] (Microsoft Corporation)
S4 Messenger; C:\WINDOWS\System32\msgsvc.dll [33792 2004-08-10] (Microsoft Corporation)
S3 MHN; C:\WINDOWS\System32\mhn.dll [85504 2004-08-10] (Microsoft Corporation)
S3 mnmsrvc; C:\WINDOWS\system32\mnmsrvc.exe [32768 2004-08-10] (Microsoft Corporation)
S3 MSDTC; C:\WINDOWS\system32\msdtc.exe [6144 2004-08-10] (Microsoft Corporation)
S3 MSIServer; C:\WINDOWS\System32\msiexec.exe [78848 2005-05-04] (Microsoft Corporation)
S4 NetDDE; C:\WINDOWS\system32\netdde.exe [111104 2004-08-10] (Microsoft Corporation)
S4 NetDDEdsdm; C:\WINDOWS\system32\netdde.exe [111104 2004-08-10] (Microsoft Corporation)
S3 Netlogon; C:\WINDOWS\system32\lsass.exe [13312 2004-08-10] (Microsoft Corporation)
R3 Netman; C:\WINDOWS\System32\netman.dll [198144 2004-08-10] (Microsoft Corporation)
R3 Nla; C:\WINDOWS\System32\mswsock.dll [245248 2008-06-20] (Microsoft Corporation)
S3 NtLmSsp; C:\WINDOWS\system32\lsass.exe [13312 2004-08-10] (Microsoft Corporation)
S3 NtmsSvc; C:\WINDOWS\system32\ntmssvc.dll [435200 2004-08-10] (Microsoft Corporation)
S3 odserv; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [440696 2011-07-20] (Microsoft Corporation)
S3 ose; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [145184 2006-10-26] (Microsoft Corporation)
R2 PlugPlay; C:\WINDOWS\system32\services.exe [110592 2009-02-06] (Microsoft Corporation)
R2 PolicyAgent; C:\WINDOWS\system32\lsass.exe [13312 2004-08-10] (Microsoft Corporation)
R2 ProtectedStorage; C:\WINDOWS\system32\lsass.exe [13312 2004-08-10] (Microsoft Corporation)
S4 RasAuto; C:\WINDOWS\System32\rasauto.dll [89088 2004-08-10] (Microsoft Corporation)
R3 RasMan; C:\WINDOWS\System32\rasmans.dll [174080 2004-08-10] (Microsoft Corporation)
S3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [140800 2004-08-10] (Microsoft Corporation)
S4 RemoteAccess; C:\WINDOWS\System32\mprdim.dll [49152 2004-08-10] (Microsoft Corporation)
R2 RemoteRegistry; C:\WINDOWS\system32\regsvc.dll [59904 2004-08-10] (Microsoft Corporation)
S3 RpcLocator; C:\WINDOWS\system32\locator.exe [75264 2004-08-10] (Microsoft Corporation)
R2 RpcSs; C:\WINDOWS\System32\rpcss.dll [399360 2009-02-09] (Microsoft Corporation)
S3 RSVP; C:\WINDOWS\system32\rsvp.exe [132608 2004-08-10] (Microsoft Corporation)
R2 SamSs; C:\WINDOWS\system32\lsass.exe [13312 2004-08-10] (Microsoft Corporation)
S3 SCardSvr; C:\WINDOWS\System32\SCardSvr.exe [95744 2004-08-10] (Microsoft Corporation)
R2 Schedule; C:\WINDOWS\system32\schedsvc.dll [190976 2004-08-10] (Microsoft Corporation)
R2 seclogon; C:\WINDOWS\System32\seclogon.dll [18944 2004-08-10] (Microsoft Corporation)
R2 SENS; C:\WINDOWS\system32\sens.dll [38912 2004-08-10] (Microsoft Corporation)
R2 SharedAccess; C:\WINDOWS\System32\ipnathlp.dll [331264 2004-08-10] (Microsoft Corporation)
R2 ShellHWDetection; C:\WINDOWS\System32\shsvcs.dll [134656 2004-08-10] (Microsoft Corporation)
R2 Spooler; C:\WINDOWS\system32\spoolsv.exe [57856 2004-08-10] (Microsoft Corporation)
R2 srservice; C:\WINDOWS\system32\srsvc.dll [170496 2004-08-10] (Microsoft Corporation)
R3 SSDPSRV; C:\WINDOWS\System32\ssdpsrv.dll [71680 2004-08-10] (Microsoft Corporation)
R2 stisvc; C:\WINDOWS\system32\wiaservc.dll [333312 2004-08-10] (Microsoft Corporation)
S3 SwPrv; C:\WINDOWS\system32\dllhost.exe [5120 2004-08-10] (Microsoft Corporation)
S3 SysmonLog; C:\WINDOWS\system32\smlogsvc.exe [89600 2004-08-10] (Microsoft Corporation)
R3 TapiSrv; C:\WINDOWS\System32\tapisrv.dll [246272 2004-08-10] (Microsoft Corporation)
R3 TermService; C:\WINDOWS\System32\termsrv.dll [295424 2004-08-10] (Microsoft Corporation)
R2 Themes; C:\WINDOWS\System32\shsvcs.dll [134656 2004-08-10] (Microsoft Corporation)
S3 TlntSvr; C:\WINDOWS\system32\tlntsvr.exe [73216 2004-08-10] (Microsoft Corporation)
R2 TrkWks; C:\WINDOWS\system32\trkwks.dll [90624 2004-08-10] (Microsoft Corporation)
S3 UMWdf; C:\WINDOWS\system32\wdfmgr.exe [38912 2004-08-10] (Microsoft Corporation)
S3 upnphost; C:\WINDOWS\System32\upnphost.dll [185344 2004-08-10] (Microsoft Corporation)
S3 UPS; C:\WINDOWS\System32\ups.exe [18432 2004-08-10] (Microsoft Corporation)
S3 VSS; C:\WINDOWS\System32\vssvc.exe [289792 2004-08-10] (Microsoft Corporation)
R2 W32Time; C:\WINDOWS\system32\w32time.dll [174592 2004-08-10] (Microsoft Corporation)
R2 WebClient; C:\WINDOWS\System32\webclnt.dll [67584 2004-08-10] (Microsoft Corporation)
R2 winmgmt; C:\WINDOWS\system32\wbem\WMIsvc.dll [144896 2004-08-10] (Microsoft Corporation)
S3 WmdmPmSN; C:\WINDOWS\system32\mspmsnsv.dll [25088 2004-08-10] (Microsoft Corporation)
S3 Wmi; C:\WINDOWS\System32\advapi32.dll [616960 2009-02-09] (Microsoft Corporation)
S3 WmiApSrv; C:\WINDOWS\system32\wbem\wmiapsrv.exe [126464 2004-08-10] (Microsoft Corporation)
R2 wscsvc; C:\WINDOWS\system32\wscsvc.dll [81408 2004-08-10] (Microsoft Corporation)
R2 wuauserv; C:\WINDOWS\system32\wuauserv.dll [6656 2004-08-10] (Microsoft Corporation)
R2 WZCSVC; C:\WINDOWS\System32\wzcsvc.dll [359936 2004-08-10] (Microsoft Corporation)
S3 xmlprov; C:\WINDOWS\System32\xmlprov.dll [129536 2004-08-10] (Microsoft Corporation)
S2 helpsvc; %WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll [X]
S2 uploadmgr; %WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-10-15] ()
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-10-15] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55112 2014-10-15] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-10-15] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [779536 2014-10-15] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [414520 2014-10-15] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57800 2014-10-15] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [192352 2014-10-15] ()
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2004-08-04] (Microsoft Corporation)
R2 CX23880; C:\WINDOWS\System32\drivers\cx88vid.sys [160256 2004-11-11] (Conexant Systems, Inc.)
R2 CX88ENC; C:\WINDOWS\System32\drivers\cx88enc.sys [297344 2004-11-11] (Conexant Systems, Inc.)
R3 CXAVXBAR; C:\WINDOWS\System32\drivers\cxavxbar.sys [9472 2004-11-11] (Conexant Systems, Inc.)
R2 CXTUNE; C:\WINDOWS\System32\drivers\CX88TUNE.sys [31360 2004-11-11] (Conexant Systems, Inc.)
R0 fasttx2k; C:\WINDOWS\System32\DRIVERS\fasttx2k.sys [142336 2003-12-02] (Promise Technology, Inc.)
S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [113664 2004-03-17] (Windows ® Server 2003 DDK provider)
R3 IrBus; C:\WINDOWS\System32\DRIVERS\IrBus.sys [46208 2004-08-10] (Microsoft Corporation)
R3 Iviaspi; C:\WINDOWS\System32\drivers\iviaspi.sys [21060 2003-09-11] (InterVideo, Inc.) [File not signed]
R3 mf; C:\WINDOWS\System32\DRIVERS\mf.sys [63744 2004-08-03] (Microsoft Corporation)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2010-04-30] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2010-04-30] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2004-08-04] (Microsoft Corporation)
R3 NmPar; C:\WINDOWS\System32\DRIVERS\NmPar.sys [80256 2008-12-24] (Windows ® 2000 DDK provider)
R3 nmserial; C:\WINDOWS\System32\DRIVERS\nmserial.sys [70016 2008-12-16] (Windows ® 2000 DDK provider)
R3 pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [47360 2010-03-03] (VSO Software) [File not signed]
R3 Pfc; C:\WINDOWS\System32\drivers\pfc.sys [10368 2003-09-19] (Padus, Inc.) [File not signed]
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [20576 2005-03-15] (Sonic Solutions) [File not signed]
R3 rtl8139; C:\WINDOWS\System32\DRIVERS\R8139n51.SYS [46976 2002-10-04] (Realtek Semiconductor Corporation )
S3 Secdrv; C:\WINDOWS\System32\DRIVERS\secdrv.sys [27440 2004-08-10] ()
R3 catchme; \??\C:\DOCUME~1\HP_ADM~1.YOU\LOCALS~1\Temp\catchme.sys [X]
S2 MCSTRM; No ImagePath
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96256 2004-08-10] (Microsoft Corporation)
U3 mbr; \??\C:\ComboFix\mbr.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
NETSVC: MHN -> C:\Windows\System32\mhn.dll (Microsoft Corporation)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-08 19:27 - 2014-11-08 19:27 - 00000000 ____D () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\FRST-OlderVersion
2014-11-08 14:53 - 2014-11-08 14:53 - 00013148 _____ () C:\ComboFix.txt
2014-11-08 14:53 - 2014-11-08 14:53 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\temp
2014-11-08 14:53 - 2014-11-08 14:53 - 00000000 ____D () C:\Documents and Settings\LocalService\Local Settings\temp
2014-11-08 14:53 - 2014-11-08 14:53 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\temp
2014-11-05 19:11 - 2014-11-07 19:05 - 00028290 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\Addition.txt
2014-11-05 18:21 - 2014-11-08 19:28 - 00000000 ____D () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Local Settings\temp
2014-11-05 18:21 - 2014-11-05 18:21 - 00008192 ____H () C:\WINDOWS\system32\config\SECURITY.tmp.LOG
2014-11-05 18:21 - 2014-11-05 18:21 - 00000000 ____H () C:\WINDOWS\system32\config\system.tmp.LOG
2014-11-05 18:21 - 2014-11-05 18:21 - 00000000 ____H () C:\WINDOWS\system32\config\software.tmp.LOG
2014-11-05 18:21 - 2014-11-05 18:21 - 00000000 ____H () C:\WINDOWS\system32\config\SAM.tmp.LOG
2014-11-05 18:21 - 2014-11-05 18:21 - 00000000 ____H () C:\WINDOWS\system32\config\default.tmp.LOG
2014-11-05 18:02 - 2011-06-25 22:45 - 00256000 _____ () C:\WINDOWS\PEV.exe
2014-11-05 18:02 - 2010-11-07 09:20 - 00208896 _____ () C:\WINDOWS\MBR.exe
2014-11-05 18:02 - 2009-04-19 20:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2014-11-05 18:02 - 2000-08-30 16:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2014-11-05 18:02 - 2000-08-30 16:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2014-11-05 18:02 - 2000-08-30 16:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2014-11-05 18:02 - 2000-08-30 16:00 - 00098816 _____ () C:\WINDOWS\sed.exe
2014-11-05 18:02 - 2000-08-30 16:00 - 00080412 _____ () C:\WINDOWS\grep.exe
2014-11-05 18:02 - 2000-08-30 16:00 - 00068096 _____ () C:\WINDOWS\zip.exe
2014-11-05 16:45 - 2014-11-08 14:53 - 00000000 ____D () C:\Qoobox
2014-11-05 16:44 - 2014-11-05 18:27 - 00000000 ____D () C:\WINDOWS\erdnt
2014-11-05 16:34 - 2014-11-05 16:35 - 05591672 ____R (Swearware) C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\ComboFix.exe
2014-11-05 13:19 - 2014-11-05 16:31 - 00000302 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\Search.txt
2014-11-04 22:12 - 2014-11-04 22:12 - 00000600 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\JRT.txt
2014-11-04 19:53 - 2014-11-04 19:53 - 02347384 _____ (ESET) C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\esetsmartinstaller_enu.exe
2014-11-04 19:53 - 2014-11-04 19:53 - 00000000 ____D () C:\Program Files\ESET
2014-11-03 22:32 - 2014-11-03 22:32 - 00001077 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\My Documents\malwarescan.txt
2014-11-03 17:57 - 2014-11-03 17:57 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-11-03 17:54 - 2014-11-03 17:55 - 01706359 _____ (Thisisu) C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\JRT.exe
2014-11-03 17:37 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll
2014-11-03 17:36 - 2014-11-03 17:47 - 00000000 ____D () C:\AdwCleaner
2014-11-03 17:32 - 2014-11-03 17:32 - 01375089 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\AdwCleaner.exe
2014-11-02 18:27 - 2014-11-08 19:28 - 00022386 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\FRST.txt
2014-11-02 18:22 - 2014-11-08 19:27 - 01107968 _____ (Farbar) C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\FRST.exe
2014-11-01 20:10 - 2014-11-01 20:10 - 11906416 _____ (OPSWAT, Inc.) C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\AppRemover.exe
2014-10-26 20:51 - 2014-11-08 19:27 - 00000000 ____D () C:\FRST
2014-10-25 18:41 - 2014-10-25 18:41 - 00090112 _____ () C:\WINDOWS\Minidump\Mini102514-01.dmp
2014-10-25 18:25 - 2014-10-25 18:32 - 00001352 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\My Documents\aswMBR.txt
2014-10-23 23:04 - 2014-11-05 18:23 - 00000000 ____D () C:\WINDOWS\pchealth
2014-10-22 14:07 - 2014-10-22 14:07 - 00000142 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\SEARCH.url
2014-10-19 22:11 - 2014-11-03 22:05 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-10-19 22:11 - 2014-10-19 22:11 - 00000788 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-19 22:11 - 2014-10-19 22:11 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-10-19 22:11 - 2014-10-19 22:11 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-19 22:11 - 2014-10-01 10:11 - 00054360 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-10-19 22:11 - 2014-10-01 10:11 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-10-19 16:18 - 2014-10-23 22:16 - 00054156 ____H () C:\WINDOWS\QTFont.qfn
2014-10-19 16:18 - 2014-10-19 16:18 - 00001409 _____ () C:\WINDOWS\QTFont.for
2014-10-19 13:49 - 2014-10-19 13:49 - 00000000 ____D () C:\WINDOWS\jumpshot.com
2014-10-19 13:49 - 2014-10-19 13:49 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
2014-10-18 22:26 - 2014-10-18 22:26 - 00000845 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\Shortcut to 2014 Summer 046.lnk
2014-10-18 22:26 - 2014-10-18 22:26 - 00000845 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\Shortcut to 2014 Summer 045.lnk
2014-10-18 22:26 - 2014-10-18 22:26 - 00000845 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\Shortcut to 2014 Summer 042.lnk
2014-10-15 21:39 - 2014-10-15 21:39 - 00000000 ____D () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Local Settings\Application Data\Temp
2014-10-15 21:33 - 2014-10-29 10:49 - 00001824 _____ () C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2014-10-15 21:31 - 2014-11-08 18:48 - 00000886 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-15 21:31 - 2014-11-08 15:48 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-15 20:15 - 2014-10-15 20:15 - 00000000 ____D () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Application Data\AVAST Software
2014-10-15 20:08 - 2014-10-15 20:07 - 00024184 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2014-10-15 20:07 - 2014-10-15 20:07 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-10-15 20:04 - 2014-10-15 20:07 - 00192352 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-10-15 20:04 - 2014-10-15 20:07 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-10-15 20:04 - 2014-10-15 20:07 - 00049944 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-10-15 20:04 - 2014-10-15 20:04 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\AVAST Software
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-08 18:08 - 2005-01-27 17:33 - 00000282 _____ () C:\WINDOWS\wiadebug.log
2014-11-08 16:23 - 2005-01-28 01:55 - 01473837 _____ () C:\WINDOWS\WindowsUpdate.log
2014-11-08 14:53 - 2005-01-28 01:55 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-08 14:50 - 2005-01-27 17:30 - 00000227 _____ () C:\WINDOWS\system.ini
2014-11-08 14:33 - 2005-01-28 01:55 - 00032576 _____ () C:\WINDOWS\SchedLgU.Txt
2014-11-08 11:26 - 2012-07-12 13:56 - 00000364 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-11-08 11:21 - 2005-04-30 14:53 - 00000248 _____ () C:\WINDOWS\system\hpsysdrv.dat
2014-11-08 11:21 - 2005-01-27 17:33 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2014-11-07 20:39 - 2010-01-14 10:58 - 00000178 ___SH () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\ntuser.ini
2014-11-07 19:55 - 2013-08-01 08:18 - 00002515 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Desktop\Microsoft Office Word 2007.lnk
2014-11-07 19:55 - 2005-03-15 17:46 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp
2014-11-07 19:39 - 2005-05-14 20:30 - 00000116 _____ () C:\WINDOWS\NeroDigital.ini
2014-11-07 18:49 - 2010-01-14 10:58 - 00000000 ____D () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2
2014-11-07 18:48 - 2010-01-29 20:58 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-11-07 18:48 - 2010-01-29 20:58 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-11-06 20:42 - 2010-01-19 12:03 - 00009244 _____ () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Application Data\wklnhst.dat
2014-11-05 21:08 - 2005-03-15 17:28 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2014-11-05 18:22 - 2005-01-28 01:55 - 37224448 _____ () C:\WINDOWS\system32\config\software.bak
2014-11-05 18:22 - 2005-01-28 01:55 - 07077888 _____ () C:\WINDOWS\system32\config\system.bak
2014-11-05 18:22 - 2005-01-28 01:55 - 00524288 _____ () C:\WINDOWS\system32\config\default.bak
2014-11-05 18:22 - 2005-01-28 01:55 - 00053248 _____ () C:\WINDOWS\system32\config\SECURITY.bak
2014-11-05 18:22 - 2005-01-28 01:55 - 00028672 _____ () C:\WINDOWS\system32\config\SAM.bak
2014-11-05 18:20 - 2005-01-27 17:44 - 00000000 ____D () C:\Documents and Settings\Administrator
2014-11-03 17:47 - 2012-08-23 16:11 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-11-02 18:35 - 2005-01-27 13:38 - 00000000 ____D () C:\Documents and Settings\Default User\Local Settings\Temp
2014-11-02 11:33 - 2005-01-28 01:47 - 00441626 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-11-01 13:07 - 2010-12-09 11:35 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2014-10-31 16:33 - 2005-01-28 01:45 - 00001158 _____ () C:\WINDOWS\system32\wpa.dbl
2014-10-25 18:41 - 2006-06-23 12:59 - 00000000 ____D () C:\WINDOWS\Minidump
2014-10-19 22:11 - 2008-12-02 19:21 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2014-10-19 20:19 - 2005-01-27 11:10 - 00000000 ____D () C:\WINDOWS\I386
2014-10-19 17:58 - 2005-01-28 01:41 - 00000653 _____ () C:\WINDOWS\win.ini
2014-10-19 17:58 - 2005-01-27 20:58 - 00000279 __RSH () C:\boot.ini
2014-10-19 17:11 - 2010-01-14 10:58 - 00000000 ____D () C:\Documents and Settings\HP_Administrator.YOUR-55E5F9E3D2\Local Settings\Application Data\Adobe
2014-10-19 13:49 - 2005-10-27 11:02 - 00000000 ____D () C:\Program Files\Google
2014-10-15 20:15 - 2012-01-26 18:11 - 00414520 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2014-10-15 20:08 - 2012-01-26 18:11 - 00001744 _____ () C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
2014-10-15 20:07 - 2012-01-26 18:11 - 00779536 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2014-10-15 20:07 - 2012-01-26 18:11 - 00276432 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-10-15 20:07 - 2012-01-26 18:11 - 00057800 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2014-10-15 20:07 - 2012-01-26 18:11 - 00055112 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2014-10-15 20:04 - 2005-01-28 01:41 - 00002577 _____ () C:\WINDOWS\system32\CONFIG.NT
2014-10-15 12:01 - 2005-03-15 17:28 - 00000000 __SHD () C:\Documents and Settings\LocalService
2014-10-15 12:00 - 2005-01-27 18:16 - 00000000 ____D () C:\WINDOWS\Registration
Some content of TEMP:
====================
C:\Documents and Settings\HP_Administrator\Local Settings\temp\CmdLineExtInstallerExe.exe
C:\Documents and Settings\HP_Administrator\Local Settings\temp\drm_dyndata_7360012.dll
C:\Documents and Settings\HP_Administrator\Local Settings\temp\jre-6u17-windows-i586-iftw-rv.exe
C:\Documents and Settings\HP_Administrator\Local Settings\temp\res271.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================