TechSpot

Old Windows XP only booting into Safe Mode

By Warbird30
Dec 21, 2013
Post New Reply
  1. Recently I was asked to work on an older Windows XP machine. It was working, then began to constantly reboot. It will only boot into Safe Mode.

    I am running FRST using the OTLPENet boot CD and will post the results.

    Any help would be appreciated.
     
    Last edited: Dec 21, 2013
  2. Warbird30

    Warbird30 TS Rookie Topic Starter

    FRST.txt Part 1

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-12-2013 02
    Ran by SYSTEM on REATOGO on 21-12-2013 20:28:01
    Running from F:\
    Microsoft Windows XP (X86) OS Language: English(US)
    Internet Explorer Version 8
    Boot Mode: Recovery

    The current controlset is ControlSet001
    ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

    ==================== Registry (Whitelisted) ==================

    HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [16010240 2006-03-08] (Realtek Semiconductor Corp.)
    HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    HKLM\...\Run: [nwiz] - nwiz.exe /install
    HKLM\...\Run: [Recguard] - C:\WINDOWS\SMINST\Recguard.exe [237568 2005-07-23] ()
    HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
    HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
    HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
    HKLM\...\Run: [MSConfig] - C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe [169984 2008-04-14] (Microsoft Corporation)
    HKU\Compaq_Owner\...\RunOnce: [TSClientMSIUninstaller] - cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"
    HKU\Compaq_Owner\...\RunOnce: [TSClientAXDisabler] - cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat"
    HKU\Default User\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [ 2008-04-14] (Microsoft Corporation)
    Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Pin.lnk
    ShortcutTarget: Pin.lnk -> C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
    Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\Pin.lnk
    ShortcutTarget: Pin.lnk -> C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
    BootExecute: autocheck autochk * SmartDefragBootTime.exe

    ========================== Services (Whitelisted) =================

    S4 ccEvtMgr; c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [192112 2005-09-17] (Symantec Corporation)
    S4 ccISPwdSvc; c:\Program Files\Norton Internet Security\ccPwdSvc.exe [72280 2005-10-13] (Symantec Corporation)
    S4 ccProxy; c:\Program Files\Common Files\Symantec Shared\ccProxy.exe [202352 2005-09-17] (Symantec Corporation)
    S4 ccSetMgr; c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [169584 2005-09-17] (Symantec Corporation)
    S3 comHost; c:\Program Files\Norton Internet Security\comHost.exe [45744 2006-01-02] (Symantec Corporation)
    S4 navapsvc; c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe [133792 2005-12-31] (Symantec Corporation)
    S4 NSCService; c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE [749696 2005-09-24] (Symantec Corporation)
    S4 SAVScan; c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe [198368 2005-08-26] (Symantec Corporation)
    S4 SNDSrvc; c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [214672 2005-09-19] (Symantec Corporation)
    S4 SPBBCSvc; c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [1160800 2005-09-15] (Symantec Corporation)
    S2 spupdsvc; C:\WINDOWS\system32\spupdsvc.exe [26144 2009-01-07] (Microsoft Corporation)
    S4 Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [1119888 2006-05-25] (Symantec Corporation)
    S2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf"

    ==================== Drivers (Whitelisted) ====================

    S1 AmdK8; C:\Windows\System32\DRIVERS\AmdK8.sys [36352 2005-03-09] (Advanced Micro Devices)
    S0 bb-run; C:\Windows\System32\DRIVERS\bb-run.sys [17408 2003-11-05] (Promise Technology, Inc.)
    S0 ftsata2; C:\Windows\System32\DRIVERS\ftsata2.sys [175104 2005-06-29] (Promise Technology, Inc.)
    S3 NAVENG; C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060216.009\NAVENG.SYS [77864 2006-02-16] (Symantec Corporation)
    S3 NAVEX15; C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060216.009\NAVEX15.SYS [750952 2006-02-16] (Symantec Corporation)
    S3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [34176 2006-03-03] (NVIDIA Corporation)
    S3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [13056 2006-03-03] (NVIDIA Corporation)
    S3 rtl8139; C:\Windows\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation)
    S3 SAVRT; c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS [334984 2005-08-26] (Symantec Corporation)
    S2 SAVRTPEL; c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS [53896 2005-08-26] (Symantec Corporation)
    S0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [14776 2013-05-22] ()
    S3 SPBBCDrv; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [389728 2005-09-15] (Symantec Corporation)
    S3 SymEvent; C:\Program Files\Symantec\SYMEVENT.SYS [108168 2005-09-17] (Symantec Corporation)
    S3 SYMIDSCO; C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050901.036\SymIDSCo.sys [199408 2005-09-01] (Symantec Corporation)
    S2 symlcbrd; C:\WINDOWS\system32\drivers\symlcbrd.sys [10344 2006-05-25] (Symantec Corporation)
    S5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
    S5 SYMTDI; C:\Windows\System32\Drivers\SYMTDI.sys [196240 2005-09-19] (Symantec Corporation)
    S1 WS2IFSL;

    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2013-12-21 20:22 - 2013-12-21 20:22 - 00000000 ____D C:\FRST
    2013-12-21 19:23 - 2013-12-21 19:30 - 00000000 ____D C:\Windows\pss
    2013-12-21 19:21 - 2013-12-21 19:21 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\HPQ
    2013-12-21 19:11 - 2013-12-21 19:11 - 00000000 ____D C:\Program Files\CCleaner
    2013-12-21 19:11 - 2013-11-27 04:18 - 00809976 _____ (Foolish IT LLC ) C:\Documents and Settings\Administrator\Desktop\CryptoPrevent 4.3 (XP-Win8.1).exe
    2013-12-21 19:07 - 2013-12-21 19:15 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
    2013-12-21 19:07 - 2013-12-21 19:07 - 00000000 __SHD C:\Documents and Settings\Administrator\IETldCache
    2013-12-21 19:07 - 2006-05-25 01:22 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Symantec
    2013-12-21 19:07 - 2006-05-25 01:11 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Google
    2013-12-21 19:07 - 2006-05-25 00:57 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Intuit
    2013-12-21 19:07 - 2006-05-25 00:56 - 00000000 ____D C:\Documents and Settings\Administrator\WINDOWS
    2013-12-21 19:07 - 2006-05-25 00:45 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Wildtangent
    2013-12-21 19:07 - 2006-05-25 00:41 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Real
    2013-12-21 19:07 - 2006-05-25 00:22 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150050}
    2013-12-20 22:32 - 2013-12-20 22:32 - 00001693 __RSH C:\Windows\System32\Drivers\103C_HP_CPC_EX310AA-ABA SR1910NX NA630_YC_0Pres_QMXF623_E63NAheREA2_48_INAGAMI2L_SASUSTek Computer INC._V2.00_B3.08_T060510_WXH2_L409_M959_J120_7AMD_8Sempron_91.8_#060812_N_Z11C10620_G10DE0241.MRK
    2013-12-20 22:29 - 2013-12-21 20:15 - 00000178 ___SH C:\Documents and Settings\Compaq_Owner\ntuser.ini
    2013-12-20 22:29 - 2006-05-25 01:22 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\Symantec
    2013-12-20 22:29 - 2006-05-25 01:11 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Google
    2013-12-20 22:29 - 2006-05-25 00:57 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\Intuit
    2013-12-20 22:29 - 2006-05-25 00:56 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\WINDOWS
    2013-12-20 22:29 - 2006-05-25 00:45 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Wildtangent
    2013-12-20 22:29 - 2006-05-25 00:41 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\Real
    2013-12-20 22:29 - 2006-05-25 00:22 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150050}
    2013-12-20 22:27 - 2006-05-25 01:31 - 00000178 ___SH C:\Documents and Settings\Default User\ntuser.ini
    2013-12-20 22:27 - 2006-05-25 01:22 - 00000000 ____D C:\Documents and Settings\Default User\Application Data\Symantec
    2013-12-20 22:27 - 2006-05-25 01:11 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\Application Data\Google
    2013-12-20 22:27 - 2006-05-25 01:09 - 00001905 _____ C:\Documents and Settings\All Users\Desktop\eBay.lnk
    2013-12-20 22:27 - 2006-05-25 01:01 - 00001537 _____ C:\Documents and Settings\All Users\Desktop\HP Extended Service Plans.lnk
    2013-12-20 22:27 - 2006-05-25 00:58 - 00001577 _____ C:\Documents and Settings\All Users\Desktop\Quicken New User Edition 2006.lnk
    2013-12-20 22:27 - 2006-05-25 00:57 - 00000000 ____D C:\Documents and Settings\Default User\Application Data\Intuit
    2013-12-20 22:27 - 2006-05-25 00:56 - 00001878 _____ C:\Documents and Settings\All Users\Desktop\Microsoft Office 2003 Edition 60 Days Trial Welcome Tour.lnk
    2013-12-20 22:27 - 2006-05-25 00:56 - 00000000 ____D C:\Documents and Settings\Default User\WINDOWS
    2013-12-20 22:27 - 2006-05-25 00:48 - 00001872 _____ C:\Documents and Settings\All Users\Desktop\My HP Games.lnk
    2013-12-20 22:27 - 2006-05-25 00:45 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\Application Data\Wildtangent
    2013-12-20 22:27 - 2006-05-25 00:42 - 00000653 _____ C:\Documents and Settings\All Users\Desktop\HP Rhapsody.lnk
    2013-12-20 22:27 - 2006-05-25 00:41 - 00000905 _____ C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
    2013-12-20 22:27 - 2006-05-25 00:41 - 00000000 ____D C:\Documents and Settings\Default User\Application Data\Real
    2013-12-20 22:27 - 2006-05-25 00:22 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150050}
    2013-12-20 22:17 - 2008-04-14 00:15 - 00010368 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
    2013-12-20 22:17 - 2008-04-14 00:09 - 00014592 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\kbdhid.sys
    2013-12-20 22:17 - 2001-08-17 16:48 - 00012160 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mouhid.sys
    2013-12-20 21:38 - 2013-12-21 19:04 - 00000248 _____ C:\Windows\system\hpsysdrv.dat
    2013-12-20 21:32 - 2013-12-20 21:32 - 00000000 ____D C:\Windows\System32\scripting
    2013-12-20 21:32 - 2013-12-20 21:32 - 00000000 ____D C:\Windows\System32\bits
    2013-12-20 21:32 - 2013-12-20 21:32 - 00000000 ____D C:\Windows\l2schemas
    2013-12-20 21:32 - 2008-04-14 05:42 - 01737856 ____N (Matrox Graphics Inc.) C:\Windows\System32\mtxparhd.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 01306624 ____N (Microsoft Corporation) C:\Windows\System32\msxml6.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 01306624 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\msxml6.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 01306624 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\msxml6.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00712704 ____N (Microsoft Corporation) C:\Windows\System32\windowscodecs.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00412160 ____N (Microsoft Corporation) C:\Windows\System32\photometadatahandler.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00397056 ____N (S3 Graphics, Inc.) C:\Windows\System32\s3gnb.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00346112 ____N (Microsoft Corporation) C:\Windows\System32\windowscodecsext.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00291328 ____N (Microsoft Corporation) C:\Windows\System32\qagentrt.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00290304 ____N (Microsoft Corporation) C:\Windows\System32\rhttpaa.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00286792 ____N (Smart Link) C:\Windows\System32\slextspk.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00276992 ____N (Microsoft Corporation) C:\Windows\System32\wmphoto.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00193024 ____N (Microsoft Corporation) C:\Windows\System32\napmontr.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00188508 ____N (Smart Link) C:\Windows\System32\slgen.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00176640 ____N (Microsoft Corporation) C:\Windows\System32\napstat.exe
    2013-12-20 21:32 - 2008-04-14 05:42 - 00155136 ____N (Microsoft Corporation) C:\Windows\System32\mssha.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00150528 ____N (Microsoft Corporation) C:\Windows\System32\qagent.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00144384 ____N (Microsoft Corporation) C:\Windows\System32\onex.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00076800 ____N (Microsoft Corporation) C:\Windows\System32\qutil.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00073832 ____N (Smart Link) C:\Windows\System32\slcoinst.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00073796 ____N (Smart Link) C:\Windows\System32\slserv.exe
    2013-12-20 21:32 - 2008-04-14 05:42 - 00069120 ____N (Microsoft Corporation) C:\Windows\System32\wlanapi.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00062464 ____N (Microsoft Corporation) C:\Windows\System32\qcliprov.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00061952 ____N (Microsoft Corporation) C:\Windows\System32\rasqec.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00060416 ____N (Microsoft Corporation) C:\Windows\System32\tzchange.exe
    2013-12-20 21:32 - 2008-04-14 05:42 - 00053248 ____N (Microsoft Corporation) C:\Windows\System32\tsgqec.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00050688 ____N (Microsoft Corporation) C:\Windows\System32\tspkg.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00033792 ____N (Microsoft Corporation) C:\Windows\System32\mmcperf.exe
    2013-12-20 21:32 - 2008-04-14 05:42 - 00032866 ____N (Smart Link) C:\Windows\System32\slrundll.exe
    2013-12-20 21:32 - 2008-04-14 05:42 - 00032866 ____N (Smart Link) C:\Windows\slrundll.exe
    2013-12-20 21:32 - 2008-04-14 05:42 - 00032768 ____N (Microsoft Corporation) C:\Windows\System32\setupn.exe
    2013-12-20 21:32 - 2008-04-14 05:42 - 00030208 ____N (Microsoft Corporation) C:\Windows\System32\napipsec.dll
    2013-12-20 21:32 - 2008-04-14 05:42 - 00028672 ____N (Microsoft Corporation) C:\Windows\System32\vidcap.ax
    2013-12-20 21:32 - 2008-04-14 05:42 - 00028672 ____N (Microsoft Corporation) C:\Windows\System32\verclsid.exe
    2013-12-20 21:32 - 2008-04-14 05:42 - 00023040 ____N (ATI Technologies Inc.) C:\Windows\System32\ativmvxx.ax
    2013-12-20 21:32 - 2008-04-14 05:42 - 00009728 ____N (ATI Technologies Inc.) C:\Windows\System32\ativdaxx.ax
    2013-12-20 21:32 - 2008-04-14 05:41 - 01888992 ____N (ATI Technologies Inc. ) C:\Windows\System32\ati3duag.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00870784 ____N (ATI Technologies Inc. ) C:\Windows\System32\ati3d1ag.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00650752 ____N (Microsoft Corporation) C:\Windows\System32\dot3ui.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00516768 ____N (ATI Technologies Inc. ) C:\Windows\System32\ativvaxx.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00397312 ____N (Microsoft Corporation) C:\Windows\System32\mmcex.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00377984 ____N (ATI Technologies Inc.) C:\Windows\System32\ati2dvaa.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00233472 ____N (Microsoft Corporation) C:\Windows\System32\azroles.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00229376 ____N (ATI Technologies Inc.) C:\Windows\System32\ati2cqag.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00201728 ____N (ATI Technologies Inc.) C:\Windows\System32\ati2dvag.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00184832 ____N (Microsoft Corporation) C:\Windows\System32\eapp3hst.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00184320 ____N (Microsoft Corporation) C:\Windows\System32\microsoft.managementconsole.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00180224 ____N (Microsoft Corporation) C:\Windows\System32\eapphost.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00136192 ____N (Microsoft Corporation) C:\Windows\System32\aaclient.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00132096 ____N (Microsoft Corporation) C:\Windows\System32\dot3svc.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00126976 ____N (Microsoft Corporation) C:\Windows\System32\eappcfg.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00106496 ____N (Microsoft Corporation) C:\Windows\System32\mmcfxcommon.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00094208 ____N (Microsoft Corporation) C:\Windows\System32\eappgnui.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00086016 ____N (Conexant) C:\Windows\System32\mdmxsdk.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00081920 ____N (Microsoft Corporation) C:\Windows\System32\ieencode.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00061440 ____N (Microsoft Corporation) C:\Windows\System32\kmsvc.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00059392 ____N (Microsoft Corporation) C:\Windows\System32\eapqec.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00057856 ____N (Microsoft Corporation) C:\Windows\System32\dot3cfg.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00056320 ____N (Microsoft Corporation) C:\Windows\System32\dot3msm.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00048640 ____N (Microsoft Corporation) C:\Windows\System32\dhcpqec.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00040960 ____N (Microsoft Corporation) C:\Windows\System32\eappprxy.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00039936 ____N (Microsoft Corporation) C:\Windows\System32\dot3gpclnt.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00039936 ____N (Microsoft Corporation) C:\Windows\System32\dimsroam.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00037376 ____N (Microsoft Corporation) C:\Windows\System32\l2gpstore.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00033792 ____N (Microsoft Corporation) C:\Windows\System32\eapsvc.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00032768 ____N (ATI Technologies Inc.) C:\Windows\System32\ativtmxx.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00032285 ____N (Conexant Systems, Inc.) C:\Windows\System32\hsfcisp2.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00030720 ____N (Microsoft Corporation) C:\Windows\System32\eapolqec.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00026112 ____N (Microsoft Corporation) C:\Windows\System32\dot3api.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00019456 ____N (Microsoft Corporation) C:\Windows\System32\dimsntfy.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00012800 ____N (Microsoft Corporation) C:\Windows\System32\credssp.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00009216 ____N (Microsoft Corporation) C:\Windows\System32\dot3dlg.dll
    2013-12-20 21:32 - 2008-04-14 05:41 - 00007168 ____N (Microsoft Corporation) C:\Windows\System32\bitsprx4.dll
    2013-12-20 21:32 - 2008-04-14 05:39 - 00006144 ____N (Microsoft Corporation) C:\Windows\System32\kbdpash.dll
    2013-12-20 21:32 - 2008-04-14 05:39 - 00006144 ____N (Microsoft Corporation) C:\Windows\System32\kbdnepr.dll
    2013-12-20 21:32 - 2008-04-14 05:39 - 00006144 ____N (Microsoft Corporation) C:\Windows\System32\kbdiultn.dll
    2013-12-20 21:32 - 2008-04-14 05:39 - 00006144 ____N (Microsoft Corporation) C:\Windows\System32\kbdbhc.dll
    2013-12-20 21:32 - 2008-04-13 23:45 - 00076800 ____N (Microsoft Corporation) C:\Windows\System32\msshavmsg.dll
    2013-12-20 21:32 - 2008-04-13 22:57 - 00079872 ____N (Microsoft Corporation) C:\Windows\System32\msxml6r.dll
    2013-12-20 21:32 - 2008-04-13 22:57 - 00079872 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\msxml6r.dll
    2013-12-20 21:32 - 2008-04-13 22:57 - 00079872 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\msxml6r.dll
    2013-12-20 21:30 - 2013-12-20 21:32 - 00000000 ____D C:\Windows\ServicePackFiles
    2013-12-20 21:28 - 2008-04-14 05:42 - 00011325 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\vchnt5.dll
    2013-12-20 21:28 - 2008-04-14 05:42 - 00003901 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\siint5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00025471 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\atv04nt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00021183 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\atv01nt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00017279 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\atv10nt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00015423 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\ch7xxnt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00014143 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\atv06nt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00011359 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\atv02nt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00004255 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv01nt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00003967 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv02nt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00003775 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv11nt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00003711 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv09nt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00003647 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv07nt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00003615 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv05nt5.dll
    2013-12-20 21:28 - 2008-04-14 05:41 - 00003135 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv08nt5.dll
    2013-12-20 21:28 - 2008-04-14 00:26 - 00030592 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\rndismpx.sys
    2013-12-20 21:28 - 2008-04-14 00:26 - 00012800 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023x.sys
    2013-12-20 21:28 - 2008-04-14 00:21 - 00101120 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\bthpan.sys
    2013-12-20 21:28 - 2008-04-14 00:16 - 00273024 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\bthport.sys
    2013-12-20 21:28 - 2008-04-14 00:16 - 00121984 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\usbvideo.sys
    2013-12-20 21:28 - 2008-04-14 00:16 - 00059136 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\rfcomm.sys
    2013-12-20 21:28 - 2008-04-14 00:16 - 00037888 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\bthmodem.sys
    2013-12-20 21:28 - 2008-04-14 00:16 - 00036480 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\bthprint.sys
    2013-12-20 21:28 - 2008-04-14 00:16 - 00025600 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
    2013-12-20 21:28 - 2008-04-14 00:16 - 00018944 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\bthusb.sys
    2013-12-20 21:28 - 2008-04-14 00:16 - 00017024 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\bthenum.sys
    2013-12-20 21:28 - 2008-04-14 00:15 - 00019200 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\hidir.sys
    2013-12-20 21:28 - 2008-04-14 00:13 - 00014208 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\wacompen.sys
    2013-12-20 21:28 - 2008-04-14 00:13 - 00012672 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\mutohpen.sys
    2013-12-20 21:28 - 2008-04-14 00:10 - 00010240 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\sffp_mmc.sys
    2013-12-20 21:28 - 2008-04-14 00:06 - 00046464 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\gagp30kx.sys
    2013-12-20 21:28 - 2008-04-14 00:06 - 00044928 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\agpcpq.sys
    2013-12-20 21:28 - 2008-04-14 00:06 - 00044672 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\uagp35.sys
    2013-12-20 21:28 - 2008-04-14 00:06 - 00043008 ____N (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\amdagp.sys
    2013-12-20 21:28 - 2008-04-14 00:06 - 00042752 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\alim1541.sys
    2013-12-20 21:28 - 2008-04-14 00:06 - 00042368 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\agp440.sys
    2013-12-20 21:28 - 2008-04-14 00:06 - 00042240 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\viaagp.sys
    2013-12-20 21:28 - 2008-04-14 00:06 - 00040960 ____N (Silicon Integrated Systems Corporation) C:\Windows\System32\Drivers\sisagp.sys
    2013-12-20 21:28 - 2008-04-14 00:06 - 00005888 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\smbali.sys
    2013-12-20 21:28 - 2008-04-14 00:01 - 00036352 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\intelppm.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 01309184 ____N (Smart Link) C:\Windows\System32\Drivers\mtlstrm.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 01041536 ____N (Conexant Systems, Inc.) C:\Windows\System32\Drivers\hsfdpsp2.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 00685056 ____N (Conexant Systems, Inc.) C:\Windows\System32\Drivers\hsfcxts2.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 00404990 ____N (Smart Link) C:\Windows\System32\Drivers\slntamr.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 00220032 ____N (Conexant Systems, Inc.) C:\Windows\System32\Drivers\hsfbs2s2.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 00180360 ____N (Smart Link) C:\Windows\System32\Drivers\ntmtlfax.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 00129535 ____N (Smart Link) C:\Windows\System32\Drivers\slnt7554.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 00126686 ____N (Smart Link) C:\Windows\System32\Drivers\mtlmnt5.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 00095424 ____N (Smart Link) C:\Windows\System32\Drivers\slnthal.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 00013776 ____N (Smart Link) C:\Windows\System32\Drivers\recagent.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 00013240 ____N (Smart Link) C:\Windows\System32\Drivers\slwdmsup.sys
    2013-12-20 21:28 - 2008-04-13 23:53 - 00011868 ____N (Conexant) C:\Windows\System32\Drivers\mdmxsdk.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00701440 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati2mtag.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00452736 ____N (Matrox Graphics Inc.) C:\Windows\System32\Drivers\mtxparhm.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00327040 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati2mtaa.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00166912 ____N (S3 Graphics, Inc.) C:\Windows\System32\Drivers\s3gnbm.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00104960 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinrvxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00073216 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atintuxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00063663 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1rvxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00063488 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinxsxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00057856 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinbtxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00056623 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1btxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00052224 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinraxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00036463 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1tuxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00034735 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1xsxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00031744 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinxbxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00030671 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1raxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00029455 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1xbxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00028672 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinsnxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00026367 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1snxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00025471 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\watv10nt.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00022271 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\watv06nt.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00021343 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1ttxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00014336 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinpdxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00013824 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinttxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00013824 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinmdxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00012047 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1pdxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00011935 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\wadv11nt.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00011871 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\wadv09nt.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00011807 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\wadv07nt.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00011615 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1mdxx.sys
    2013-12-20 21:28 - 2008-04-13 22:04 - 00011295 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\wadv08nt.sys
    2013-12-20 21:28 - 2007-04-02 21:36 - 00129045 ____N C:\Windows\System32\Drivers\cxthsfs2.cty
    2013-12-20 21:28 - 2006-12-29 20:21 - 00064352 ____N C:\Windows\System32\Drivers\ativmc20.cod
    2013-12-20 21:28 - 2006-12-29 20:02 - 00067866 ____N C:\Windows\System32\Drivers\netwlan5.img
    2013-12-20 21:27 - 2006-12-29 00:31 - 00019569 _____ C:\Windows\002574_.tmp
    2013-12-20 21:24 - 2013-12-20 21:26 - 00000000 __HDC C:\Windows\$NtServicePackUninstall$
    2013-12-20 21:24 - 2013-12-20 21:24 - 00000573 _____ C:\Windows\medctroc.Log
    2013-12-20 21:22 - 2013-12-20 21:35 - 00000000 __RHD C:\MSOCache
    2013-12-20 21:21 - 2013-12-20 21:35 - 00000000 ___RD C:\Windows\Offline Web Pages
    2013-12-20 21:20 - 2013-12-21 19:04 - 00437081 _____ C:\Windows\svcpack.log
    2013-12-20 21:15 - 2013-12-20 21:15 - 00000000 ____D C:\Program Files\IObit
    2013-12-20 21:15 - 2013-12-20 21:15 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\IObit
    2013-12-20 21:15 - 2013-12-20 21:15 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\IObit
    2013-12-20 21:15 - 2013-05-22 18:49 - 00029528 _____ (IObit) C:\Windows\System32\SmartDefragBootTime.exe
    2013-12-20 21:15 - 2013-05-22 18:49 - 00014776 _____ C:\Windows\System32\Drivers\SmartDefragDriver.sys
    2013-12-20 21:14 - 2013-12-20 21:14 - 00000000 ____D C:\Program Files\QuickTime
    2013-12-20 21:14 - 2013-12-20 21:14 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Apple Computer
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Program Files\Common Files\Java
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Program Files\Common Files\Apple
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Program Files\Apple Software Update
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Apple Computer
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Apple
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Sun
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Apple
    2013-12-20 21:12 - 2013-12-20 21:12 - 00264616 _____ (Oracle Corporation) C:\Windows\System32\javaws.exe
    2013-12-20 21:12 - 2013-12-20 21:12 - 00175016 _____ (Oracle Corporation) C:\Windows\System32\javaw.exe
    2013-12-20 21:12 - 2013-12-20 21:12 - 00174504 _____ (Oracle Corporation) C:\Windows\System32\java.exe
    2013-12-20 21:12 - 2013-12-20 21:12 - 00145408 _____ (Oracle Corporation) C:\Windows\System32\javacpl.cpl
    2013-12-20 21:12 - 2013-12-20 21:12 - 00094632 _____ (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
    2013-12-20 21:11 - 2013-12-20 20:40 - 00001836 _____ C:\Documents and Settings\Compaq_Owner\Desktop\HP Update.lnk
    2013-12-20 21:09 - 2013-12-20 21:09 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Adobe
    2013-12-20 21:07 - 2013-12-20 21:07 - 00001742 _____ C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
    2013-12-20 21:06 - 2013-12-20 21:06 - 00000000 ____D C:\Program Files\Common Files\Adobe
    2013-12-20 21:04 - 2013-12-20 21:04 - 00000762 _____ C:\Documents and Settings\All Users\Desktop\SpywareBlaster.lnk
    2013-12-20 21:04 - 2013-12-20 21:04 - 00000000 ____D C:\Program Files\SpywareBlaster
    2013-12-20 21:04 - 2013-12-20 21:04 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Licenses
    2013-12-20 21:03 - 2013-12-20 21:03 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Package Cache
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000732 _____ C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Program Files\Mozilla Firefox
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Mozilla
    2013-12-20 20:59 - 2013-12-20 20:59 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\Sun
    2013-12-20 20:59 - 2013-08-26 15:44 - 38501472 _____ (RealNetworks, Inc.) C:\Documents and Settings\Compaq_Owner\Desktop\RealPlayer 16.0.3.51 (XP-Win8 & 64bit).exe
    2013-12-20 20:57 - 2012-09-13 15:44 - 50349920 _____ (Microsoft Corporation) C:\Documents and Settings\Compaq_Owner\Desktop\MS .Net 4.5 Full Install (XP-Win7 & 64bit).exe
    2013-12-20 20:56 - 2013-12-19 17:26 - 91412976 _____ (AVAST Software) C:\Documents and Settings\Compaq_Owner\Desktop\Avast Antivirus 9.0.2011 (2000-Win8 & 64bit).exe
    2013-12-20 20:55 - 2008-05-16 02:47 - 331805736 _____ (Microsoft Corporation) C:\Documents and Settings\Compaq_Owner\Desktop\WindowsXP-KB936929-SP3-x86-ENU (XPsp1-sp2).exe
    2013-12-20 20:51 - 2013-12-20 21:09 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\Adobe
    2013-12-20 20:51 - 2013-12-20 21:00 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
    2013-12-20 20:51 - 2013-12-20 21:00 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
    2013-12-20 20:51 - 2013-12-20 20:51 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia
    2013-12-20 20:50 - 2013-12-20 22:27 - 00000211 __RSH C:\BOOT.BAK
    2013-12-20 20:50 - 2013-12-20 20:50 - 00000000 __SHD C:\Documents and Settings\Compaq_Owner\PrivacIE
    2013-12-20 20:50 - 2013-12-20 20:50 - 00000000 __SHD C:\Documents and Settings\Compaq_Owner\IECompatCache
    2013-12-20 20:50 - 2004-08-03 23:00 - 00260272 __RSH C:\cmldr
    2013-12-20 20:49 - 2013-12-20 20:50 - 00015824 _____ C:\Windows\WINNT32.LOG
    2013-12-20 20:49 - 2013-12-20 20:50 - 00000000 _RSHD C:\cmdcons
    2013-12-20 20:49 - 2013-12-20 20:49 - 00000581 _____ C:\Windows\wsdu.log
    2013-12-20 20:49 - 2013-12-20 20:49 - 00000264 _____ C:\Windows\UPGRADE.TXT
    2013-12-20 20:49 - 2013-12-20 20:49 - 00000178 _____ C:\Windows\DHCPUPG.LOG
    2013-12-20 20:49 - 2013-12-20 20:49 - 00000000 ____D C:\Windows\setup.pss
    2013-12-20 20:48 - 2013-12-20 20:48 - 00000000 __SHD C:\Documents and Settings\Compaq_Owner\IETldCache
    2013-12-20 20:46 - 2013-12-20 20:47 - 00065536 _____ C:\Windows\System32\config\Internet.evt
    2013-12-20 20:45 - 2013-12-20 20:47 - 00059014 _____ C:\Windows\ie8.log
    2013-12-20 20:45 - 2013-12-20 20:47 - 00030911 _____ C:\Windows\ie8_main.log
    2013-12-20 20:45 - 2013-12-20 20:46 - 00000000 __HDC C:\Windows\ie8
    2013-12-20 20:42 - 2013-12-20 20:42 - 00000000 __SHD C:\Documents and Settings\Compaq_Owner\UserData
    2013-12-20 20:40 - 2013-12-20 21:11 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\HpUpdate
    2013-12-20 20:40 - 2013-12-20 20:40 - 00000248 _____ C:\Documents and Settings\Compaq_Owner\Desktop\HP Printing Software.url
    2013-12-20 20:40 - 2013-12-20 20:40 - 00000000 ____D C:\Windows\Hewlett-Packard

    ==================== One Month Modified Files and Folders =======

    2013-12-21 20:22 - 2013-12-21 20:22 - 00000000 ____D C:\FRST
    2013-12-21 20:15 - 2013-12-20 22:29 - 00000178 ___SH C:\Documents and Settings\Compaq_Owner\ntuser.ini
    2013-12-21 20:15 - 2005-12-05 02:05 - 00051986 _____ C:\Windows\WindowsUpdate.log
    2013-12-21 20:10 - 2005-12-05 02:04 - 00673603 _____ C:\Windows\setupapi.log
    2013-12-21 19:31 - 2005-12-05 14:31 - 00000281 __RSH C:\boot.ini
    2013-12-21 19:31 - 2005-12-05 01:50 - 00000573 _____ C:\Windows\win.ini
    2013-12-21 19:31 - 2005-12-04 17:44 - 00000227 _____ C:\Windows\system.ini
    2013-12-21 19:30 - 2013-12-21 19:23 - 00000000 ____D C:\Windows\pss
    2013-12-21 19:21 - 2013-12-21 19:21 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\HPQ
    2013-12-21 19:15 - 2013-12-21 19:07 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
    2013-12-21 19:11 - 2013-12-21 19:11 - 00000000 ____D C:\Program Files\CCleaner
    2013-12-21 19:11 - 2005-12-05 01:55 - 00441626 _____ C:\Windows\System32\PerfStringBackup.INI
    2013-12-21 19:09 - 2006-05-25 01:15 - 00000000 ____D C:\Program Files\Symantec
    2013-12-21 19:07 - 2013-12-21 19:07 - 00000000 __SHD C:\Documents and Settings\Administrator\IETldCache
    2013-12-21 19:07 - 2005-12-05 01:53 - 00170688 _____ C:\Windows\System32\FNTCACHE.DAT
    2013-12-21 19:07 - 2005-12-05 01:53 - 00001158 _____ C:\Windows\System32\wpa.dbl
    2013-12-21 19:06 - 2005-12-06 12:19 - 00000000 ____D C:\Program Files\Messenger
    2013-12-21 19:04 - 2013-12-20 21:38 - 00000248 _____ C:\Windows\system\hpsysdrv.dat
    2013-12-21 19:04 - 2013-12-20 21:20 - 00437081 _____ C:\Windows\svcpack.log
    2013-12-21 19:04 - 2005-12-06 12:50 - 00000000 ____D C:\Windows\security
    2013-12-21 19:04 - 2005-12-05 02:05 - 00014376 _____ C:\Windows\SchedLgU.Txt
    2013-12-21 19:04 - 2005-12-05 01:52 - 00088590 _____ C:\Windows\tsoc.log
    2013-12-21 19:04 - 2005-12-05 01:52 - 00082770 _____ C:\Windows\comsetup.log
    2013-12-21 19:04 - 2005-12-05 01:52 - 00049129 _____ C:\Windows\ntdtcsetup.log
    2013-12-21 19:04 - 2005-12-05 01:52 - 00032643 _____ C:\Windows\iis6.log
    2013-12-21 19:04 - 2005-12-05 01:52 - 00012191 _____ C:\Windows\ocmsn.log
    2013-12-21 19:04 - 2005-12-05 01:52 - 00002711 _____ C:\Windows\imsins.log
    2013-12-20 22:32 - 2013-12-20 22:32 - 00001693 __RSH C:\Windows\System32\Drivers\103C_HP_CPC_EX310AA-ABA SR1910NX NA630_YC_0Pres_QMXF623_E63NAheREA2_48_INAGAMI2L_SASUSTek Computer INC._V2.00_B3.08_T060510_WXH2_L409_M959_J120_7AMD_8Sempron_91.8_#060812_N_Z11C10620_G10DE0241.MRK
    2013-12-20 22:32 - 2006-05-25 01:00 - 00000000 ____D C:\Windows\System32\pcintro
    2013-12-20 22:32 - 2005-12-05 01:53 - 00040820 _____ C:\Windows\wmsetup.log
    2013-12-20 22:28 - 2005-12-04 17:43 - 00000399 _____ C:\Windows\setuperr.log
    2013-12-20 22:27 - 2013-12-20 20:50 - 00000211 __RSH C:\BOOT.BAK
    2013-12-20 22:26 - 2005-12-06 12:49 - 00000000 ____D C:\Windows\Registration
    2013-12-20 22:26 - 2005-12-05 01:48 - 00000885 _____ C:\Windows\DtcInstall.log
    2013-12-20 22:25 - 2005-12-04 17:44 - 00003364 _____ C:\Windows\regopt.log
    2013-12-20 22:15 - 2005-12-06 12:50 - 00000000 ____D C:\Windows\repair
    2013-12-20 21:48 - 2006-05-25 01:14 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
    2013-12-20 21:38 - 2005-12-06 12:18 - 00000000 ___HD C:\hp
    2013-12-20 21:36 - 2006-05-25 00:56 - 00000000 ____D C:\Windows\SMINST
    2013-12-20 21:35 - 2013-12-20 21:22 - 00000000 __RHD C:\MSOCache
    2013-12-20 21:35 - 2013-12-20 21:21 - 00000000 ___RD C:\Windows\Offline Web Pages
    2013-12-20 21:35 - 2005-12-05 01:48 - 00235589 _____ C:\Windows\FaxSetup.log
    2013-12-20 21:35 - 2005-12-05 01:48 - 00119361 _____ C:\Windows\ocgen.log
    2013-12-20 21:35 - 2005-12-05 01:48 - 00011171 _____ C:\Windows\msgsocm.log
    2013-12-20 21:33 - 2006-05-25 00:32 - 00008555 _____ C:\Windows\spupdsvc.log
    2013-12-20 21:33 - 2005-12-05 01:46 - 00000373 _____ C:\Windows\cmsetacl.log
    2013-12-20 21:32 - 2013-12-20 21:32 - 00000000 ____D C:\Windows\System32\scripting
    2013-12-20 21:32 - 2013-12-20 21:32 - 00000000 ____D C:\Windows\System32\bits
    2013-12-20 21:32 - 2013-12-20 21:32 - 00000000 ____D C:\Windows\l2schemas
    2013-12-20 21:32 - 2013-12-20 21:30 - 00000000 ____D C:\Windows\ServicePackFiles
    2013-12-20 21:32 - 2006-05-25 00:25 - 00122538 _____ C:\Windows\updspapi.log
    2013-12-20 21:32 - 2005-12-06 13:11 - 00000000 ____D C:\Windows\System32\usmt
    2013-12-20 21:32 - 2005-12-06 12:49 - 00000000 ____D C:\Windows\PeerNet
    2013-12-20 21:32 - 2005-12-06 12:42 - 00000000 ____D C:\Windows\ime
    2013-12-20 21:32 - 2005-12-06 12:23 - 00000000 ____D C:\Windows\Help
    2013-12-20 21:32 - 2005-12-06 12:19 - 00000000 ____D C:\Program Files\Movie Maker
    2013-12-20 21:32 - 2005-12-05 01:47 - 00002998 _____ C:\Windows\sessmgr.setup.log
    2013-12-20 21:30 - 2005-12-06 13:09 - 00000000 ____D C:\Windows\System32\Restore
    2013-12-20 21:30 - 2005-12-06 13:07 - 00000000 ____D C:\Windows\System32\npp
    2013-12-20 21:30 - 2005-12-06 12:51 - 00000000 ____D C:\Windows\System32\Com
    2013-12-20 21:30 - 2005-12-06 12:50 - 00000000 ____D C:\Windows\srchasst
    2013-12-20 21:30 - 2005-12-06 12:46 - 00000000 ____D C:\Windows\msagent
    2013-12-20 21:30 - 2005-12-06 12:20 - 00000000 ____D C:\Program Files\Windows NT
    2013-12-20 21:30 - 2005-12-06 12:20 - 00000000 ____D C:\Program Files\Outlook Express
    2013-12-20 21:30 - 2005-12-06 12:20 - 00000000 ____D C:\Program Files\NetMeeting
    2013-12-20 21:30 - 2005-12-06 12:19 - 00000000 ____D C:\Program Files\Common Files\System
    2013-12-20 21:29 - 2005-12-06 12:50 - 00000000 ____D C:\Windows\system
    2013-12-20 21:27 - 2004-08-04 06:00 - 00250048 __RSH C:\ntldr
    2013-12-20 21:26 - 2013-12-20 21:24 - 00000000 __HDC C:\Windows\$NtServicePackUninstall$
    2013-12-20 21:26 - 2006-05-25 00:33 - 00000000 ____D C:\Windows\System32\ReinstallBackups
    2013-12-20 21:24 - 2013-12-20 21:24 - 00000573 _____ C:\Windows\medctroc.Log
    2013-12-20 21:15 - 2013-12-20 21:15 - 00000000 ____D C:\Program Files\IObit
    2013-12-20 21:15 - 2013-12-20 21:15 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\IObit
    2013-12-20 21:15 - 2013-12-20 21:15 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\IObit
    2013-12-20 21:14 - 2013-12-20 21:14 - 00000000 ____D C:\Program Files\QuickTime
    2013-12-20 21:14 - 2013-12-20 21:14 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Apple Computer
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Program Files\Common Files\Java
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Program Files\Common Files\Apple
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Program Files\Apple Software Update
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Apple Computer
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Apple
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Sun
    2013-12-20 21:13 - 2013-12-20 21:13 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Apple
    2013-12-20 21:12 - 2013-12-20 21:12 - 00264616 _____ (Oracle Corporation) C:\Windows\System32\javaws.exe
    2013-12-20 21:12 - 2013-12-20 21:12 - 00175016 _____ (Oracle Corporation) C:\Windows\System32\javaw.exe
    2013-12-20 21:12 - 2013-12-20 21:12 - 00174504 _____ (Oracle Corporation) C:\Windows\System32\java.exe
    2013-12-20 21:12 - 2013-12-20 21:12 - 00145408 _____ (Oracle Corporation) C:\Windows\System32\javacpl.cpl
    2013-12-20 21:12 - 2013-12-20 21:12 - 00094632 _____ (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
    2013-12-20 21:12 - 2006-05-25 00:22 - 00000000 ____D C:\Program Files\Java
    2013-12-20 21:11 - 2013-12-20 20:40 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\HpUpdate
    2013-12-20 21:09 - 2013-12-20 21:09 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Adobe
    2013-12-20 21:09 - 2013-12-20 20:51 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\Adobe
    2013-12-20 21:07 - 2013-12-20 21:07 - 00001742 _____ C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
    2013-12-20 21:06 - 2013-12-20 21:06 - 00000000 ____D C:\Program Files\Common Files\Adobe
    2013-12-20 21:06 - 2006-05-25 00:50 - 00000000 ____D C:\Program Files\Adobe
    2013-12-20 21:06 - 2006-05-25 00:50 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Adobe
    2013-12-20 21:05 - 2006-05-25 01:05 - 00024978 _____ C:\hpWebHelper.log
    2013-12-20 21:04 - 2013-12-20 21:04 - 00000762 _____ C:\Documents and Settings\All Users\Desktop\SpywareBlaster.lnk
    2013-12-20 21:04 - 2013-12-20 21:04 - 00000000 ____D C:\Program Files\SpywareBlaster
    2013-12-20 21:04 - 2013-12-20 21:04 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Licenses
    2013-12-20 21:03 - 2013-12-20 21:03 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Package Cache
    2013-12-20 21:02 - 2005-12-06 12:18 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000732 _____ C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Program Files\Mozilla Firefox
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla
    2013-12-20 21:01 - 2013-12-20 21:01 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Mozilla
    2013-12-20 21:00 - 2013-12-20 20:51 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
    2013-12-20 21:00 - 2013-12-20 20:51 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
    2013-12-20 20:59 - 2013-12-20 20:59 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\Sun
    2013-12-20 20:51 - 2013-12-20 20:51 - 00000000 ____D C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia
    2013-12-20 20:50 - 2013-12-20 20:50 - 00000000 __SHD C:\Documents and Settings\Compaq_Owner\PrivacIE
    2013-12-20 20:50 - 2013-12-20 20:50 - 00000000 __SHD C:\Documents and Settings\Compaq_Owner\IECompatCache
    2013-12-20 20:50 - 2013-12-20 20:49 - 00015824 _____ C:\Windows\WINNT32.LOG
    2013-12-20 20:50 - 2013-12-20 20:49 - 00000000 _RSHD C:\cmdcons
    2013-12-20 20:50 - 2005-12-05 01:52 - 00212634 _____ C:\Windows\setupact.log
    2013-12-20 20:49 - 2013-12-20 20:49 - 00000581 _____ C:\Windows\wsdu.log
    2013-12-20 20:49 - 2013-12-20 20:49 - 00000264 _____ C:\Windows\UPGRADE.TXT
    2013-12-20 20:49 - 2013-12-20 20:49 - 00000178 _____ C:\Windows\DHCPUPG.LOG
    2013-12-20 20:49 - 2013-12-20 20:49 - 00000000 ____D C:\Windows\setup.pss
    2013-12-20 20:48 - 2013-12-20 20:48 - 00000000 __SHD C:\Documents and Settings\Compaq_Owner\IETldCache
    2013-12-20 20:48 - 2006-05-25 00:36 - 00000000 ____D C:\Windows\System32\Lang
    2013-12-20 20:48 - 2006-05-25 00:33 - 00043531 _____ C:\Windows\System32\nvapps.xml
    2013-12-20 20:48 - 2005-12-06 12:42 - 00000000 ____D C:\Windows\I386
    2013-12-20 20:47 - 2013-12-20 20:46 - 00065536 _____ C:\Windows\System32\config\Internet.evt
    2013-12-20 20:47 - 2013-12-20 20:45 - 00059014 _____ C:\Windows\ie8.log
    2013-12-20 20:47 - 2013-12-20 20:45 - 00030911 _____ C:\Windows\ie8_main.log
    2013-12-20 20:47 - 2005-12-05 01:52 - 00001393 _____ C:\Windows\imsins.BAK
    2013-12-20 20:46 - 2013-12-20 20:45 - 00000000 __HDC C:\Windows\ie8
    2013-12-20 20:46 - 2005-12-06 12:46 - 00000000 ____D C:\Windows\Media
    2013-12-20 20:42 - 2013-12-20 20:42 - 00000000 __SHD C:\Documents and Settings\Compaq_Owner\UserData
    2013-12-20 20:40 - 2013-12-20 21:11 - 00001836 _____ C:\Documents and Settings\Compaq_Owner\Desktop\HP Update.lnk
    2013-12-20 20:40 - 2013-12-20 20:40 - 00000248 _____ C:\Documents and Settings\Compaq_Owner\Desktop\HP Printing Software.url
    2013-12-20 20:40 - 2013-12-20 20:40 - 00000000 ____D C:\Windows\Hewlett-Packard
    2013-12-20 20:40 - 2006-05-25 00:49 - 00000000 ____D C:\Program Files\Hewlett-Packard
    2013-12-20 20:40 - 2006-05-25 00:37 - 00000000 ____D C:\Program Files\HP
     
  3. Warbird30

    Warbird30 TS Rookie Topic Starter

    FRST.txt Part 2

    Some content of TEMP:
    ====================
    C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\IadHide5.dll


    ==================== Known DLLs (Whitelisted) ============


    ==================== Bamital & volsnap Check =================

    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe
    [2004-08-04 06:00] - [2008-04-14 05:42] - 0108544 ____A (Microsoft Corporation) 0e776ed5f7cc9f94299e70461b7b8185

    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points (XP) =====================

    RP: -> 2013-12-20 21:12 - 024576 _restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP9

    RP: -> 2013-12-20 21:06 - 024576 _restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP8

    RP: -> 2013-12-20 21:05 - 024576 _restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP7

    RP: -> 2013-12-20 21:03 - 024576 _restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP6

    RP: -> 2013-12-20 21:02 - 024576 _restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP5

    RP: -> 2013-12-20 20:59 - 024576 _restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP4

    RP: -> 2013-12-20 20:46 - 024576 _restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP3

    RP: -> 2013-12-20 20:40 - 024576 _restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP2

    RP: -> 2013-12-20 21:27 - 024576 _restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP11

    RP: -> 2013-12-20 21:14 - 024576 _restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP10

    RP: -> 2013-12-20 20:40 - 024576 _restore{00EFF98B-5705-4D9A-BA78-7681A60AFB54}\RP1


    ==================== Memory info ===========================

    Percentage of memory in use: 27%
    Total physical RAM: 958.48 MB
    Available physical RAM: 698.69 MB
    Total Pagefile: 858.04 MB
    Available Pagefile: 733.03 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1993.16 MB

    ==================== Drives ================================

    Drive b: (RAMDisk) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS
    Drive c: (PRESARIO) (Fixed) (Total:104.68 GB) (Free:92.58 GB) NTFS ==>[Drive with boot components (Windows XP)]
    Drive d: (PRESARIO_RP) (Fixed) (Total:7.09 GB) (Free:0.36 GB) FAT32 ==>[Drive with boot components (Windows XP)]
    Drive e: (Device Manager) (CDROM) (Total:0.03 GB) (Free:0 GB) CDFS
    Drive f: (KINGSTON) (Removable) (Total:3.73 GB) (Free:3.36 GB) FAT32
    Drive x: (ReatogoPE) (CDROM) (Total:0.43 GB) (Free:0 GB) CDFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 112 GB) (Disk ID: CAB10BEE)
    Partition 1: (Active) - (Size=105 GB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=7 GB) - (Type=0C)

    ========================================================
    Disk: 1 (MBR Code: Windows XP) (Size: 4 GB) (Disk ID: C3072E18)
    Partition 1: (Active) - (Size=4 GB) - (Type=0C)

    ==================== End Of Log ============================
     
  4. Warbird30

    Warbird30 TS Rookie Topic Starter

    Search.txt

    Farbar Recovery Scan Tool (x86) Version: 20-12-2013 02
    Ran by SYSTEM at 2013-12-21 20:25:58
    Running from F:\
    Boot Mode: Recovery

    ================== Search: "services.exe" ===================

    C:\WINDOWS\system32\services.exe
    [2004-08-04 06:00] - [2008-04-14 05:42] - 0108544 ____A (Microsoft Corporation) 0e776ed5f7cc9f94299e70461b7b8185

    C:\WINDOWS\ServicePackFiles\i386\services.exe
    [2013-12-20 21:30] - [2008-04-14 05:42] - 0108544 ____N (Microsoft Corporation) 0e776ed5f7cc9f94299e70461b7b8185

    C:\WINDOWS\$NtServicePackUninstall$\services.exe
    [2013-12-20 21:24] - [2004-08-04 06:00] - 0108032 ____C (Microsoft Corporation) c6ce6eec82f187615d1002bb3bb50ed4

    X:\I386\SYSTEM32\SERVICES.EXE
    [2004-08-03 20:07] - [2004-08-03 20:07] - 0108032 ____R (Microsoft Corporation) c6ce6eec82f187615d1002bb3bb50ed4

    === End Of Search ===
     
  5. Tmagic650

    Tmagic650 TS Ambassador Posts: 17,244   +234

    Have you checked the memory or attempted a clean XP re-install?
     
  6. Warbird30

    Warbird30 TS Rookie Topic Starter

    I tried several memory modules and same results. It boots to safe mode just fine. This was a clean install that I was doing for a friend.
     
  7. Tmagic650

    Tmagic650 TS Ambassador Posts: 17,244   +234

    Booting in the SAFE MODE fine means that a driver might be to blame... video comes to mind first
     

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...