Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-09-2015
Ran by Boz (administrator) on DUBSONE (07-09-2015 20:23:49)
Running from C:\Documents and Settings\Boz\My Documents\Downloads
Loaded Profiles: Boz (Available Profiles: Boz & Guest248 & Administrator)
Platform: Microsoft Windows XP Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\launcher_service.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
(GEMTEKS) C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
(Linksys WPA UI(CA)) C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cavwp.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(SigmaTel, Inc.) C:\WINDOWS\stsystra.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtcmd.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Research In Motion Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cistray.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(BitTorrent Inc.) C:\Documents and Settings\Boz\Application Data\BitTorrent\BitTorrent.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit_manager.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cis.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(PeerBlock, LLC) C:\Program Files\PeerBlock\peerblock.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cmdvirth.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\launcher_service.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SigmatelSysTrayApp] => C:\WINDOWS\stsystra.exe [339968 2005-03-22] (SigmaTel, Inc.)
HKLM\...\Run: [ISUSPM Startup] => c:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-07-27] (InstallShield Software Corporation)
HKLM\...\Run: [dscactivate] => C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe [16384 2007-11-15] ( )
HKLM\...\Run: [dellsupportcenter] => C:\Program Files\Dell Support Center\bin\sprtcmd.exe [206064 2009-05-21] (SupportSoft, Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [267792 2013-01-17] (Research In Motion Limited)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-01-27] (Apple Inc.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1361088 2015-08-20] (COMODO)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2015-02-03] (Adobe Systems Incorporated)
HKLM\...\Run: [tvncontrol] => C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-06-30] (Comodo Security Solutions, Inc.)
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6714136 2015-05-25] (SUPERAntiSpyware)
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\...\Run: [BitTorrent] => C:\Documents and Settings\Boz\Application Data\BitTorrent\BitTorrent.exe [1698152 2015-08-20] (BitTorrent Inc.)
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssstars.scr [14336 2008-04-13] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [RunNarrator] => C:\WINDOWS\system32\Narrator.exe [53760 2008-04-13] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-18] (SuperAdBlocker.com)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2010-01-05]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Start GeekBuddy.lnk [2015-08-20]
ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\Comodo\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [.DEFAULT] => http=127.0.0.1:5555
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{7E27A112-C3D3-4877-86F1-292E9368610A}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{DF22A413-2461-4F28-94D3-D2A401206326}: [DhcpNameServer] 154.11.129.59 154.11.129.187 209.115.152.130
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-21-243343400-2573606588-2901852968-1006 -> {2528085A-2B78-48B2-BBE1-B7A5429C91C7} URL = hxxp://ca.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-17] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-17] (Oracle Corporation)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)
Toolbar: HKU\S-1-5-21-243343400-2573606588-2901852968-1006 -> No Name - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} C:\DOCUME~1\Boz\LOCALS~1\Temp\IXP000.TMP\InstallerControl.cab#-1,-1,-1,-1
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-09-06] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1207148.dll [2013-12-05] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-10-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-10-17] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2012-12-13] ()
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-09-07] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-09-07] (Google Inc.)
FF Plugin: @viewpoint.com/VMP -> C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-01-05]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-08-28]
FF HKU\S-1-5-21-243343400-2573606588-2901852968-1006\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\45.0.2454.85\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Flash) - internal-remoting-viewer
CHR Plugin: (Remoting Viewer) - C:\Program Files\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\45.0.2454.85\pdf.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (QuickTime) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Windows Media Player) - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.330.3) - C:\WINDOWS\system32\npdeployJava1.dll No File
CHR Plugin: (Java) - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
CHR Plugin: (MetaStream 3 Plugin) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (iTunes Application Detector) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Silverlight) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Documents and Settings\Boz\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (F5 Networks Plugin Host) - C:\Documents and Settings\Boz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bfjhelpopbdbnlfmjkbkfkbfmbneaeob [2014-12-23]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\Boz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14]
CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\Boz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-09-21] (SUPERAntiSpyware.com)
U3 Blackberry Device Manager; C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [577536 2013-01-18] (Research In Motion Limited) [File not signed]
U2 ChromodoUpdater; C:\Program Files\Comodo\Chromodo\chromodo_updater.exe [2306248 2015-04-02] (Comodo)
R2 CLPSLauncher; C:\Program Files\Common Files\COMODO\launcher_service.exe [70848 2015-08-13] (Comodo Security Solutions, Inc.)
U2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [4353840 2015-08-20] (COMODO)
U3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [1664704 2015-08-20] (COMODO)
U3 DSBrokerService; C:\Program Files\DellSupport\brkrsvc.exe [76848 2007-03-07] ()
U2 GeekBuddyRSP; C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-06-30] (Comodo Security Solutions, Inc.)
U3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
U2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
U2 IAANTMon; C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe [86140 2005-06-17] (Intel Corporation) [File not signed]
U3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
U2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-10-17] (Oracle Corporation)
U2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-09-07] (Malwarebytes Corporation)
U2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-09-07] (Malwarebytes Corporation)
U2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
U3 NetSvc; C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe [147456 2004-11-19] (Intel(R) Corporation) [File not signed]
U2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
U2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2008-08-13] (SupportSoft, Inc.)
U3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [X]
U2 WUSB54Gv4SVC; "C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe" [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U4 abp480n5; C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS [23552 2001-08-17] (Microsoft Corporation)
U3 BeTwinKeyboard; C:\WINDOWS\System32\drivers\BeTwinKF.sys [16192 2012-01-17] (ThinSoft Pte Ltd.)
U3 BeTwinMouse; C:\WINDOWS\System32\drivers\BeTwinMF.sys [16192 2012-01-17] (ThinSoft Pte Ltd.)
U1 BeTwinSystem; C:\WINDOWS\System32\Drivers\BeTwinSystem.sys [13640 2012-01-17] (ThinSoft Pte Ltd.)
U0 BeTwinVideo; C:\WINDOWS\System32\drivers\BeTwinVF.sys [20800 2012-01-17] (ThinSoft Pte Ltd.)
U1 CFRMD; C:\WINDOWS\System32\DRIVERS\CFRMD.sys [36112 2014-06-25] (Windows (R) Win 7 DDK provider)
U1 cmderd; C:\WINDOWS\System32\DRIVERS\cmderd.sys [15808 2015-08-04] (COMODO)
U1 cmdGuard; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [631872 2015-08-04] (COMODO)
U1 cmdHlp; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [30144 2015-08-04] (COMODO)
U3 DSproct; C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys [4736 2006-10-05] (Gteko Ltd.) [File not signed]
U1 ElRawDisk; C:\WINDOWS\system32\drivers\rsdrv.sys [22312 2009-02-12] (EldoS Corporation)
U3 GTNDIS5; C:\WINDOWS\system32\GTNDIS5.SYS [15872 2003-09-25] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
U3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2008-10-28] (HP)
U3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2008-10-28] (HP)
U3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2008-10-28] (HP)
U0 Inspect; C:\WINDOWS\System32\DRIVERS\inspect.sys [105664 2015-08-04] (COMODO)
U3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-09-07] (Malwarebytes Corporation)
U2 MDC8021X; C:\WINDOWS\System32\DRIVERS\mdc8021x.sys [15781 2004-05-26] (Meetinghouse Data Communications) [File not signed]
U3 mferkdk; C:\WINDOWS\System32\drivers\mferkdk.sys [34248 2009-09-16] (McAfee, Inc.)
U3 mfesmfk; C:\WINDOWS\System32\drivers\mfesmfk.sys [40552 2009-09-16] (McAfee, Inc.)
U3 Netaapl; C:\WINDOWS\System32\DRIVERS\netaapl.sys [18432 2010-04-19] (Apple Inc.) [File not signed]
U3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [19016 2014-01-14] ()
U3 pfc; C:\WINDOWS\System32\drivers\pfc.sys [9856 2002-10-01] (Padus, Inc.) [File not signed]
U1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
U1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
U1 sdcplh; C:\WINDOWS\System32\drivers\sdcplh.sys [55168 2005-10-18] (Macrovision Europe Ltd) [File not signed]
U3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [180864 2005-06-14] (SigmaTel, Inc.)
U3 WUSB54GV4SRV; C:\WINDOWS\System32\DRIVERS\rt2500usb.sys [79616 2004-05-07] (Ralink Technology Inc.)
U3 bvrp_pci; no ImagePath
U1 SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U3 TlntSvr; no ImagePath
U3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
U3 wanatw; system32\DRIVERS\wanatw4.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-07 20:23 - 2015-09-07 20:24 - 00000000 ____D C:\FRST
2015-09-07 19:49 - 2015-09-07 19:49 - 00001813 _____ C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2015-09-07 19:49 - 2015-09-07 19:49 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
2015-09-07 19:41 - 2015-09-07 19:46 - 00000876 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0e9d76a98ab18.job
2015-09-07 19:41 - 2015-09-07 19:46 - 00000876 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-20 13:00 - 2015-08-20 13:00 - 00001780 _____ C:\Documents and Settings\All Users\Desktop\GeekBuddy.lnk
2015-08-20 13:00 - 2015-08-20 13:00 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Comodo Security Solutions Inc
2015-08-20 12:59 - 2015-08-20 12:59 - 00000000 ____D C:\Program Files\Common Files\COMODO
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-07 20:26 - 2012-09-03 19:05 - 00000000 ____D C:\Documents and Settings\Boz\Local Settings\temp
2015-09-07 20:26 - 2008-10-23 22:17 - 00000000 ____D C:\Documents and Settings\Boz\Application Data\BitTorrent
2015-09-07 20:25 - 2015-02-03 21:49 - 01218032 _____ C:\WINDOWS\system32\Drivers\sfi.dat
2015-09-07 20:24 - 2013-11-14 04:19 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-07 20:22 - 2015-05-25 12:30 - 00004410 _____ C:\WINDOWS\system32\Drivers\fvstore.dat
2015-09-07 20:05 - 2015-02-03 21:51 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job
2015-09-07 19:49 - 2012-08-29 23:34 - 00000000 ____D C:\Program Files\Google
2015-09-07 19:48 - 2012-02-11 18:28 - 00000000 ____D C:\Program Files\PeerBlock
2015-09-07 19:37 - 2009-01-17 16:46 - 00841891 _____ C:\WINDOWS\setupapi.log
2015-09-07 19:36 - 2004-08-10 12:02 - 01504836 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-07 19:28 - 2014-07-28 23:04 - 00098520 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-07 19:27 - 2004-08-10 11:51 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-09-07 19:25 - 2015-02-03 21:51 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}.job
2015-09-07 19:25 - 2015-02-03 21:51 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22}.job
2015-09-07 19:25 - 2015-02-03 21:51 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9}.job
2015-09-07 19:25 - 2005-10-25 21:01 - 00000178 ___SH C:\Documents and Settings\Boz\ntuser.ini
2015-09-07 19:25 - 2004-08-10 12:08 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-07 19:25 - 2004-08-10 11:59 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-09-07 19:25 - 2004-08-10 11:59 - 00000048 _____ C:\WINDOWS\wiaservc.log
2015-09-07 19:24 - 2004-08-10 12:08 - 00032402 _____ C:\WINDOWS\SchedLgU.Txt
2015-09-07 19:24 - 2004-08-10 12:08 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Temp
2015-09-07 02:07 - 2014-07-28 23:04 - 00121560 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-09-07 02:07 - 2014-07-28 23:04 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-09-07 02:07 - 2014-07-28 23:04 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-07 02:07 - 2012-09-01 21:51 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-09-07 02:07 - 2012-09-01 21:51 - 00000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-06 13:59 - 2005-10-26 17:22 - 00120320 _____ C:\Documents and Settings\Boz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-09-06 12:45 - 2012-04-04 22:23 - 00778440 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-09-06 12:45 - 2011-10-05 09:45 - 00142536 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-09-01 13:19 - 2015-02-02 19:04 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2015-08-20 21:49 - 2015-02-03 21:46 - 00001878 _____ C:\Documents and Settings\All Users\Desktop\COMODO Internet Security.lnk
2015-08-20 13:00 - 2015-02-03 21:43 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Comodo
2015-08-13 03:18 - 2013-07-16 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-13 03:01 - 2005-10-27 19:47 - 129304528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-08 15:00 - 2014-04-09 20:38 - 00000212 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
==================== Files in the root of some directories =======
2010-08-16 00:00 - 2010-08-16 00:00 - 10864104 _____ (PokerStars) C:\Program Files\PokerStarsInstall.exe
2010-01-12 23:32 - 2010-01-12 23:38 - 0010584 _____ () C:\Documents and Settings\Boz\Application Data\docXConverter (3).ini
2010-01-12 23:35 - 2010-01-12 23:36 - 0000132 ____H () C:\Documents and Settings\Boz\Application Data\lakerda1967.sys
2005-10-26 17:27 - 2005-10-26 17:27 - 0012358 _____ () C:\Documents and Settings\Boz\Application Data\PFP120JCM.{PB
2005-10-26 17:27 - 2005-10-26 17:27 - 0061678 _____ () C:\Documents and Settings\Boz\Application Data\PFP120JPR.{PB
2011-08-28 15:26 - 2013-12-26 22:33 - 0000154 _____ () C:\Documents and Settings\Boz\Application Data\Rim.Desktop.Exception.log
2011-08-28 15:18 - 2013-12-28 20:07 - 0002161 _____ () C:\Documents and Settings\Boz\Application Data\Rim.Desktop.HttpServerSetup.log
2011-08-28 15:27 - 2013-12-26 22:32 - 0000231 _____ () C:\Documents and Settings\Boz\Application Data\Rim.DesktopHelper.Exception.log
2005-10-26 17:22 - 2015-09-06 13:59 - 0120320 _____ () C:\Documents and Settings\Boz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2008-01-23 22:33 - 2008-01-23 22:33 - 0000126 _____ () C:\Documents and Settings\Boz\Local Settings\Application Data\fusioncache.dat
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
Ran by Boz (administrator) on DUBSONE (07-09-2015 20:23:49)
Running from C:\Documents and Settings\Boz\My Documents\Downloads
Loaded Profiles: Boz (Available Profiles: Boz & Guest248 & Administrator)
Platform: Microsoft Windows XP Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\launcher_service.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
(GEMTEKS) C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
(Linksys WPA UI(CA)) C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cavwp.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(SigmaTel, Inc.) C:\WINDOWS\stsystra.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtcmd.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Research In Motion Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cistray.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(BitTorrent Inc.) C:\Documents and Settings\Boz\Application Data\BitTorrent\BitTorrent.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit_manager.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cis.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(PeerBlock, LLC) C:\Program Files\PeerBlock\peerblock.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(Comodo) C:\Program Files\Comodo\Chromodo\chromodo.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cmdvirth.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\launcher_service.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SigmatelSysTrayApp] => C:\WINDOWS\stsystra.exe [339968 2005-03-22] (SigmaTel, Inc.)
HKLM\...\Run: [ISUSPM Startup] => c:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-07-27] (InstallShield Software Corporation)
HKLM\...\Run: [dscactivate] => C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe [16384 2007-11-15] ( )
HKLM\...\Run: [dellsupportcenter] => C:\Program Files\Dell Support Center\bin\sprtcmd.exe [206064 2009-05-21] (SupportSoft, Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [267792 2013-01-17] (Research In Motion Limited)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-01-27] (Apple Inc.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1361088 2015-08-20] (COMODO)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2015-02-03] (Adobe Systems Incorporated)
HKLM\...\Run: [tvncontrol] => C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-06-30] (Comodo Security Solutions, Inc.)
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6714136 2015-05-25] (SUPERAntiSpyware)
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\...\Run: [BitTorrent] => C:\Documents and Settings\Boz\Application Data\BitTorrent\BitTorrent.exe [1698152 2015-08-20] (BitTorrent Inc.)
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssstars.scr [14336 2008-04-13] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [RunNarrator] => C:\WINDOWS\system32\Narrator.exe [53760 2008-04-13] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-18] (SuperAdBlocker.com)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2010-01-05]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Start GeekBuddy.lnk [2015-08-20]
ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\Comodo\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [.DEFAULT] => http=127.0.0.1:5555
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{7E27A112-C3D3-4877-86F1-292E9368610A}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{DF22A413-2461-4F28-94D3-D2A401206326}: [DhcpNameServer] 154.11.129.59 154.11.129.187 209.115.152.130
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKU\S-1-5-21-243343400-2573606588-2901852968-1006\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-21-243343400-2573606588-2901852968-1006 -> {2528085A-2B78-48B2-BBE1-B7A5429C91C7} URL = hxxp://ca.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-17] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-17] (Oracle Corporation)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)
Toolbar: HKU\S-1-5-21-243343400-2573606588-2901852968-1006 -> No Name - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} C:\DOCUME~1\Boz\LOCALS~1\Temp\IXP000.TMP\InstallerControl.cab#-1,-1,-1,-1
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-09-06] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1207148.dll [2013-12-05] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-10-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-10-17] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2012-12-13] ()
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-09-07] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-09-07] (Google Inc.)
FF Plugin: @viewpoint.com/VMP -> C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-01-05]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-08-28]
FF HKU\S-1-5-21-243343400-2573606588-2901852968-1006\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\45.0.2454.85\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Flash) - internal-remoting-viewer
CHR Plugin: (Remoting Viewer) - C:\Program Files\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\45.0.2454.85\pdf.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (QuickTime) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Windows Media Player) - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.330.3) - C:\WINDOWS\system32\npdeployJava1.dll No File
CHR Plugin: (Java) - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
CHR Plugin: (MetaStream 3 Plugin) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (iTunes Application Detector) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Silverlight) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Documents and Settings\Boz\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (F5 Networks Plugin Host) - C:\Documents and Settings\Boz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bfjhelpopbdbnlfmjkbkfkbfmbneaeob [2014-12-23]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\Boz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14]
CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\Boz\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-09-21] (SUPERAntiSpyware.com)
U3 Blackberry Device Manager; C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [577536 2013-01-18] (Research In Motion Limited) [File not signed]
U2 ChromodoUpdater; C:\Program Files\Comodo\Chromodo\chromodo_updater.exe [2306248 2015-04-02] (Comodo)
R2 CLPSLauncher; C:\Program Files\Common Files\COMODO\launcher_service.exe [70848 2015-08-13] (Comodo Security Solutions, Inc.)
U2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [4353840 2015-08-20] (COMODO)
U3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [1664704 2015-08-20] (COMODO)
U3 DSBrokerService; C:\Program Files\DellSupport\brkrsvc.exe [76848 2007-03-07] ()
U2 GeekBuddyRSP; C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-06-30] (Comodo Security Solutions, Inc.)
U3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
U2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
U2 IAANTMon; C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe [86140 2005-06-17] (Intel Corporation) [File not signed]
U3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
U2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-10-17] (Oracle Corporation)
U2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-09-07] (Malwarebytes Corporation)
U2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-09-07] (Malwarebytes Corporation)
U2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
U3 NetSvc; C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe [147456 2004-11-19] (Intel(R) Corporation) [File not signed]
U2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
U2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2008-08-13] (SupportSoft, Inc.)
U3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [X]
U2 WUSB54Gv4SVC; "C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe" [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U4 abp480n5; C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS [23552 2001-08-17] (Microsoft Corporation)
U3 BeTwinKeyboard; C:\WINDOWS\System32\drivers\BeTwinKF.sys [16192 2012-01-17] (ThinSoft Pte Ltd.)
U3 BeTwinMouse; C:\WINDOWS\System32\drivers\BeTwinMF.sys [16192 2012-01-17] (ThinSoft Pte Ltd.)
U1 BeTwinSystem; C:\WINDOWS\System32\Drivers\BeTwinSystem.sys [13640 2012-01-17] (ThinSoft Pte Ltd.)
U0 BeTwinVideo; C:\WINDOWS\System32\drivers\BeTwinVF.sys [20800 2012-01-17] (ThinSoft Pte Ltd.)
U1 CFRMD; C:\WINDOWS\System32\DRIVERS\CFRMD.sys [36112 2014-06-25] (Windows (R) Win 7 DDK provider)
U1 cmderd; C:\WINDOWS\System32\DRIVERS\cmderd.sys [15808 2015-08-04] (COMODO)
U1 cmdGuard; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [631872 2015-08-04] (COMODO)
U1 cmdHlp; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [30144 2015-08-04] (COMODO)
U3 DSproct; C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys [4736 2006-10-05] (Gteko Ltd.) [File not signed]
U1 ElRawDisk; C:\WINDOWS\system32\drivers\rsdrv.sys [22312 2009-02-12] (EldoS Corporation)
U3 GTNDIS5; C:\WINDOWS\system32\GTNDIS5.SYS [15872 2003-09-25] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
U3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2008-10-28] (HP)
U3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2008-10-28] (HP)
U3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2008-10-28] (HP)
U0 Inspect; C:\WINDOWS\System32\DRIVERS\inspect.sys [105664 2015-08-04] (COMODO)
U3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-09-07] (Malwarebytes Corporation)
U2 MDC8021X; C:\WINDOWS\System32\DRIVERS\mdc8021x.sys [15781 2004-05-26] (Meetinghouse Data Communications) [File not signed]
U3 mferkdk; C:\WINDOWS\System32\drivers\mferkdk.sys [34248 2009-09-16] (McAfee, Inc.)
U3 mfesmfk; C:\WINDOWS\System32\drivers\mfesmfk.sys [40552 2009-09-16] (McAfee, Inc.)
U3 Netaapl; C:\WINDOWS\System32\DRIVERS\netaapl.sys [18432 2010-04-19] (Apple Inc.) [File not signed]
U3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [19016 2014-01-14] ()
U3 pfc; C:\WINDOWS\System32\drivers\pfc.sys [9856 2002-10-01] (Padus, Inc.) [File not signed]
U1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
U1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
U1 sdcplh; C:\WINDOWS\System32\drivers\sdcplh.sys [55168 2005-10-18] (Macrovision Europe Ltd) [File not signed]
U3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [180864 2005-06-14] (SigmaTel, Inc.)
U3 WUSB54GV4SRV; C:\WINDOWS\System32\DRIVERS\rt2500usb.sys [79616 2004-05-07] (Ralink Technology Inc.)
U3 bvrp_pci; no ImagePath
U1 SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U3 TlntSvr; no ImagePath
U3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
U3 wanatw; system32\DRIVERS\wanatw4.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-07 20:23 - 2015-09-07 20:24 - 00000000 ____D C:\FRST
2015-09-07 19:49 - 2015-09-07 19:49 - 00001813 _____ C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2015-09-07 19:49 - 2015-09-07 19:49 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
2015-09-07 19:41 - 2015-09-07 19:46 - 00000876 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0e9d76a98ab18.job
2015-09-07 19:41 - 2015-09-07 19:46 - 00000876 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-20 13:00 - 2015-08-20 13:00 - 00001780 _____ C:\Documents and Settings\All Users\Desktop\GeekBuddy.lnk
2015-08-20 13:00 - 2015-08-20 13:00 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Comodo Security Solutions Inc
2015-08-20 12:59 - 2015-08-20 12:59 - 00000000 ____D C:\Program Files\Common Files\COMODO
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-07 20:26 - 2012-09-03 19:05 - 00000000 ____D C:\Documents and Settings\Boz\Local Settings\temp
2015-09-07 20:26 - 2008-10-23 22:17 - 00000000 ____D C:\Documents and Settings\Boz\Application Data\BitTorrent
2015-09-07 20:25 - 2015-02-03 21:49 - 01218032 _____ C:\WINDOWS\system32\Drivers\sfi.dat
2015-09-07 20:24 - 2013-11-14 04:19 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-07 20:22 - 2015-05-25 12:30 - 00004410 _____ C:\WINDOWS\system32\Drivers\fvstore.dat
2015-09-07 20:05 - 2015-02-03 21:51 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job
2015-09-07 19:49 - 2012-08-29 23:34 - 00000000 ____D C:\Program Files\Google
2015-09-07 19:48 - 2012-02-11 18:28 - 00000000 ____D C:\Program Files\PeerBlock
2015-09-07 19:37 - 2009-01-17 16:46 - 00841891 _____ C:\WINDOWS\setupapi.log
2015-09-07 19:36 - 2004-08-10 12:02 - 01504836 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-07 19:28 - 2014-07-28 23:04 - 00098520 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-07 19:27 - 2004-08-10 11:51 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-09-07 19:25 - 2015-02-03 21:51 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}.job
2015-09-07 19:25 - 2015-02-03 21:51 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22}.job
2015-09-07 19:25 - 2015-02-03 21:51 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9}.job
2015-09-07 19:25 - 2005-10-25 21:01 - 00000178 ___SH C:\Documents and Settings\Boz\ntuser.ini
2015-09-07 19:25 - 2004-08-10 12:08 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-07 19:25 - 2004-08-10 11:59 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-09-07 19:25 - 2004-08-10 11:59 - 00000048 _____ C:\WINDOWS\wiaservc.log
2015-09-07 19:24 - 2004-08-10 12:08 - 00032402 _____ C:\WINDOWS\SchedLgU.Txt
2015-09-07 19:24 - 2004-08-10 12:08 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Temp
2015-09-07 02:07 - 2014-07-28 23:04 - 00121560 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-09-07 02:07 - 2014-07-28 23:04 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-09-07 02:07 - 2014-07-28 23:04 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-07 02:07 - 2012-09-01 21:51 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-09-07 02:07 - 2012-09-01 21:51 - 00000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-06 13:59 - 2005-10-26 17:22 - 00120320 _____ C:\Documents and Settings\Boz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-09-06 12:45 - 2012-04-04 22:23 - 00778440 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-09-06 12:45 - 2011-10-05 09:45 - 00142536 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-09-01 13:19 - 2015-02-02 19:04 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2015-08-20 21:49 - 2015-02-03 21:46 - 00001878 _____ C:\Documents and Settings\All Users\Desktop\COMODO Internet Security.lnk
2015-08-20 13:00 - 2015-02-03 21:43 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Comodo
2015-08-13 03:18 - 2013-07-16 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-13 03:01 - 2005-10-27 19:47 - 129304528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-08 15:00 - 2014-04-09 20:38 - 00000212 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
==================== Files in the root of some directories =======
2010-08-16 00:00 - 2010-08-16 00:00 - 10864104 _____ (PokerStars) C:\Program Files\PokerStarsInstall.exe
2010-01-12 23:32 - 2010-01-12 23:38 - 0010584 _____ () C:\Documents and Settings\Boz\Application Data\docXConverter (3).ini
2010-01-12 23:35 - 2010-01-12 23:36 - 0000132 ____H () C:\Documents and Settings\Boz\Application Data\lakerda1967.sys
2005-10-26 17:27 - 2005-10-26 17:27 - 0012358 _____ () C:\Documents and Settings\Boz\Application Data\PFP120JCM.{PB
2005-10-26 17:27 - 2005-10-26 17:27 - 0061678 _____ () C:\Documents and Settings\Boz\Application Data\PFP120JPR.{PB
2011-08-28 15:26 - 2013-12-26 22:33 - 0000154 _____ () C:\Documents and Settings\Boz\Application Data\Rim.Desktop.Exception.log
2011-08-28 15:18 - 2013-12-28 20:07 - 0002161 _____ () C:\Documents and Settings\Boz\Application Data\Rim.Desktop.HttpServerSetup.log
2011-08-28 15:27 - 2013-12-26 22:32 - 0000231 _____ () C:\Documents and Settings\Boz\Application Data\Rim.DesktopHelper.Exception.log
2005-10-26 17:22 - 2015-09-06 13:59 - 0120320 _____ () C:\Documents and Settings\Boz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2008-01-23 22:33 - 2008-01-23 22:33 - 0000126 _____ () C:\Documents and Settings\Boz\Local Settings\Application Data\fusioncache.dat
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================