Please observe forum rules...
All logs have to be pasted not attached.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-04-2014
Ran by UA43931 (administrator) on V0065191 on 12-04-2014 18:10:52
Running from G:\
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Safe Mode (with Networking)
The only official download link for FRST:
Download link for 32-Bit version:
https://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.html
Download link for 64-Bit Version:
https://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.html
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
==================== Processes (Whitelisted) =================
() C:\Program Files\seguridad\rto\IBM\rtosesflow.exe
() C:\Program Files\Vintegris\VinPassLogout\VinPassLogout.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [MSConfig] - C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [169984 2008-04-14] (Microsoft Corporation)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\rtonotify: C:\Program Files\seguridad\rto\IBM\rtonotify.dll ()
Winlogon\Notify\VinPassLogout: C:\Program Files\Vintegris\VinPassLogout\DLLVinLogout.dll ()
HKLM\...\Policies\Explorer: [NoMSAppLogo5ChannelNotify] 0
HKLM\...\Policies\Explorer: [NoToolbarCustomize] 0
HKLM\...\Policies\Explorer: [NoBandCustomize] 0
HKLM\...\Policies\Explorer: [NoWelcomeScreen] 1
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\.DEFAULT\...\Policies\Explorer: [Btn_Home] 0
HKU\.DEFAULT\...\Policies\Explorer: [Btn_Fullscreen] 0
HKU\.DEFAULT\...\Policies\Explorer: [Btn_Tools] 0
HKU\.DEFAULT\...\Policies\Explorer: [Btn_Print] 0
HKU\.DEFAULT\...\Policies\Explorer: [Btn_Edit] 0
HKU\.DEFAULT\...\Policies\Explorer: [Btn_Cut] 0
HKU\.DEFAULT\...\Policies\Explorer: [Btn_Copy] 0
HKU\.DEFAULT\...\Policies\Explorer: [Btn_Paste] 0
HKU\.DEFAULT\...\Policies\Explorer: [Btn_Encoding] 0
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [NoSimpleStartMenu] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [SpecifyDefaultButtons] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Back] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Forward] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Stop] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Refresh] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Home] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Search] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Favorites] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_History] 2
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Folders] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Fullscreen] 2
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Tools] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_MailNews] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Size] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Print] 1
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Edit] 2
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Discussions] 2
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Cut] 2
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Copy] 2
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Paste] 2
HKU\S-1-5-21-1292428093-343818398-839522115-29857\...\Policies\Explorer: [Btn_Encoding] 2
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\FixExcel2010XP.cmd ()
Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\FixExcel2010XP.cmd ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://intranetbbva.es.igrupobbva/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
http://feed.snapdo.com/?publisher=S...ype=ds&q={searchTerms}&installDate=13/04/2013
BHO: CSignonExplorerBHO Object - {118589B1-A016-4FC4-AB36-02EEE550CA9A} - C:\WINDOWS\system32\SignonBuHO.dll (Vintegris S.L.)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll No File
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1361000746125
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 04 C:\WINDOWS\system32\pnrpnsp.dll [58880] (Microsoft Corporation)
Winsock: Catalog5 05 C:\WINDOWS\system32\pnrpnsp.dll [58880] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\UA43931.BBVA.002\Application Data\Mozilla\Firefox\Profiles\snvolgxe.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\nationzoom.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\drae.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-es.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-es.xml
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-07-22]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-07-22]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
Chrome:
=======
CHR HomePage: hxxp://
www.google.com/
CHR Extension: (backgroundPage) - C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2014-03-24]
CHR Extension: (Google Wallet) - C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-06]
CHR HKLM\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Documents and Settings\ua43931\Local Settings\Application Data\Torch\Plugins\TorchPlugin.crx [2014-02-06]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
CHR HKLM\...\Chrome\Extension: [pgafcinpmmpklohkojmllohdhomoefph] - C:\Documents and Settings\All Users\Application Data\Browser Manager\2.3.762.17\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.crx [2013-10-09]
========================== Services (Whitelisted) =================
S2 6to4; C:\WINDOWS\System32\6to4svc.dll [100352 2008-04-14] (Microsoft Corporation)
S4 AVGIDSAgent; D:\Program Files\AVG\avgidsagent.exe [3782672 2014-02-23] (AVG Technologies CZ, s.r.o.)
S4 avgwd; D:\Program Files\AVG\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
S4 BlackICE; C:\Archivos de programa\ISS\issSensors\DesktopProtection\blackd.exe [851968 2004-03-16] (Internet Security Systems, Inc.)
S4 dsNcService; C:\Program Files\Juniper Networks\Common Files\dsNcService.exe [669040 2011-04-25] (Juniper Networks)
S4 EPA_GPO_PMService; C:\WINDOWS\system32\PMService.exe [81920 2005-01-21] (TerraNovum)
S2 Iprip; C:\WINDOWS\System32\iprip.dll [35328 2008-04-14] (Microsoft Corporation)
S4 JavaQuickStarterService; C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [161664 2012-05-04] (Oracle Corporation)
S4 JuniperAccessService; C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe [198000 2011-04-25] (Juniper Networks, Inc.)
S4 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation)
S2 McAfeeEngineService; C:\Program Files\Network Associates\VirusScan\EngineServer.exe [22816 2010-10-22] (McAfee, Inc.)
S2 McAfeeFramework; C:\Program Files\Network Associates\Common Framework\FrameworkService.exe [120128 2011-01-12] (McAfee, Inc.)
S2 McShield; C:\Program Files\Network Associates\VirusScan\Mcshield.exe [147984 2010-10-22] (McAfee, Inc.)
S2 McTaskManager; C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe [66880 2010-10-22] (McAfee, Inc.)
S2 mfevtp; C:\WINDOWS\system32\mfevtps.exe [69192 2010-10-22] (McAfee, Inc.)
S3 p2pgasvc; C:\WINDOWS\system32\p2pgasvc.dll [105472 2008-04-14] (Microsoft Corporation)
S4 PCToolsSSDMonitorSvc; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [794272 2012-08-21] (PC Tools)
S4 RapApp; C:\Archivos de programa\ISS\issSensors\DesktopProtection\RapApp.exe [688128 2003-06-20] (Internet Security Systems, Inc.)
S4 rtofirewall; C:\Program Files\seguridad\rto\IBM\rtofirewallsvc.exe [93184 2011-02-18] ()
S4 RtoSecStart; C:\Program Files\seguridad\rto\IBM\rtosecstartsrv.exe [86016 2011-02-18] ()
S4 RtoSysLog; C:\Program Files\seguridad\rto\IBM\rtosyslogservice.exe [145408 2011-02-18] ()
S4 rtousb; C:\Program Files\seguridad\rto\IBM\rtousbservice.exe [90624 2011-02-18] ()
S4 S24EventMonitor; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [915728 2010-12-23] (Intel(R) Corporation)
S4 Skype C2C Service; C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S4 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [282709 2011-05-27] (IDT, Inc.)
S4 tunnelguardservice; C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe [53248 2003-10-03] (Alexandria Software Consulting)
S4 WLANKEEPER; C:\Program Files\Intel\WiFi\bin\WLKeeper.exe [375056 2010-12-23] (Intel(R) Corporation)
S4 WMCoreService; C:\Program Files\Ericsson\Mobile Broadband Drivers\WMCore\WMCore.exe [842280 2011-03-03] (Ericsson AB)
==================== Drivers (Whitelisted) ====================
S3 AESTAud; C:\WINDOWS\System32\drivers\AESTAud.sys [113664 2009-04-21] (Andrea Electronics Corporation)
S3 AtiHDAudioService; C:\WINDOWS\System32\drivers\AtihdXP3.sys [101392 2011-03-30] (Advanced Micro Devices)
S1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [120600 2013-11-25] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdriverx.sys [210712 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [149272 2013-11-25] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSShim; C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [22808 2014-01-19] (AVG Technologies CZ, s.r.o.)
S1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [176952 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [222520 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [102712 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [27448 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\WINDOWS\System32\DRIVERS\avgtdix.sys [193848 2013-08-01] (AVG Technologies CZ, s.r.o.)
S4 black; C:\WINDOWS\System32\drivers\BlackDrv.sys [228837 2004-04-09] (Internet Security Systems, Inc.)
S3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [556200 2009-11-18] (Broadcom Corporation.)
S3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37160 2010-01-14] (Broadcom Corporation.)
S3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [932136 2010-07-23] (Broadcom Corporation.)
S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [118440 2009-11-18] (Broadcom Corporation.)
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [51752 2010-07-23] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R3 dsNcAdpt; C:\WINDOWS\System32\DRIVERS\dsNcAdpt.sys [26624 2011-04-25] (Juniper Networks)
R3 e1cexpress; C:\WINDOWS\System32\DRIVERS\e1c5132.sys [192168 2011-05-04] (Intel Corporation)
S3 e1yexpress; C:\WINDOWS\System32\DRIVERS\e1y5132.sys [244368 2008-03-27] (Intel Corporation)
R3 Eacfilt; C:\WINDOWS\System32\DRIVERS\eacfilt.sys [11113 2004-09-30] (Nortel Networks)
S3 h36wgps; C:\WINDOWS\System32\DRIVERS\h36wgps.sys [87592 2011-02-28] (Ericsson AB)
S0 HpCISSm2; C:\WINDOWS\System32\drivers\HpCISSm2.sys [29224 2010-01-26] (Hewlett-Packard Company)
R3 IFXTPM; C:\WINDOWS\System32\DRIVERS\IFXTPM.SYS [44800 2007-12-18] (Infineon Technologies AG)
S3 IPSECEXT; C:\WINDOWS\System32\DRIVERS\ipsecw2k.sys [216459 2004-09-30] (Nortel Networks NA, Inc.)
R3 IPSECSHM; C:\WINDOWS\System32\DRIVERS\ipsecw2k.sys [216459 2004-09-30] (Nortel Networks NA, Inc.)
S3 libusb0; C:\WINDOWS\System32\DRIVERS\libusb0.sys [28160 2009-07-07] (
http://libusb-win32.sourceforge.net)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-03-05] (Malwarebytes Corporation)
R3 Mbm4bus; C:\WINDOWS\System32\DRIVERS\Mbm4bus.sys [122824 2011-02-11] (MCCI Corporation)
S3 Mbm4mdfl; C:\WINDOWS\System32\DRIVERS\Mbm4mdfl.sys [14920 2011-02-11] (MCCI Corporation)
S3 Mbm4mdm; C:\WINDOWS\System32\DRIVERS\Mbm4mdm.sys [138952 2011-02-11] (MCCI Corporation)
S3 Mbm4mgmt; C:\WINDOWS\System32\DRIVERS\Mbm4mgmt.sys [132808 2011-02-11] (MCCI Corporation)
R3 Mbm4NNd5; C:\WINDOWS\System32\DRIVERS\Mbm4NNd5.sys [24904 2011-02-11] (MCCI Corporation)
R3 Mbm4NUn; C:\WINDOWS\System32\DRIVERS\Mbm4NUn.sys [149960 2011-02-11] (MCCI Corporation)
R3 MEI; C:\WINDOWS\System32\DRIVERS\HECI.sys [41088 2010-10-19] (Intel Corporation)
S3 mfeapfk; C:\WINDOWS\System32\drivers\mfeapfk.sys [76024 2010-10-22] (McAfee, Inc.)
S3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [91896 2010-10-22] (McAfee, Inc.)
S3 mfebopk; C:\WINDOWS\System32\drivers\mfebopk.sys [43192 2010-10-22] (McAfee, Inc.)
S0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [344712 2010-10-22] (McAfee, Inc.)
S3 mferkdet; C:\WINDOWS\System32\drivers\mferkdet.sys [66536 2010-10-22] (McAfee, Inc.)
R1 mfetdik; C:\WINDOWS\System32\drivers\mfetdik.sys [64208 2010-10-22] (McAfee, Inc.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 NETwNx32; C:\WINDOWS\System32\DRIVERS\NETwNx32.sys [7391104 2010-12-21] (Intel Corporation)
R3 nusb3hub; C:\WINDOWS\System32\DRIVERS\nusb3hub.sys [62336 2010-12-10] (Renesas Electronics Corporation)
R3 nusb3xhc; C:\WINDOWS\System32\DRIVERS\nusb3xhc.sys [141440 2010-12-10] (Renesas Electronics Corporation)
S3 RapFile; C:\WINDOWS\system32\drivers\RapFile.sys [36676 2003-06-20] (Internet Security Systems, Inc.)
S3 RapNet; C:\WINDOWS\system32\drivers\RapNet.sys [24344 2003-06-20] (Internet Security Systems, Inc.)
S2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [13952 2010-05-19] (Intel Corporation)
S3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1970726 2011-05-27] (IDT, Inc.)
S3 swivsp; C:\WINDOWS\System32\DRIVERS\swivspnt.sys [20352 2007-09-18] (Sierra Wireless Inc.)
R1 Tcpip6; C:\WINDOWS\System32\DRIVERS\tcpip6.sys [225856 2008-06-20] (Microsoft Corporation)
S0 VMSCSI; C:\WINDOWS\System32\drivers\vmscsi.sys [10880 2005-11-30] (VMware, Inc.)
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S4 IntelIde; No ImagePath
S1 iSafeNetFilter; \??\C:\Program Files\iSafe\iSafeNetFilter.sys [X]
S3 smsmdd; system32\DRIVERS\smsmdm.sys [X]
U%8Faq%09 T8267;
U2 TMAgent;
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-12 18:10 - 2014-04-12 18:10 - 00000000 ___DC () C:\FRST
2014-04-11 17:07 - 2014-04-12 18:04 - 00000000 ____D () C:\WINDOWS\pss
2014-04-11 16:11 - 2014-04-11 16:11 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\Sun
2014-04-11 16:11 - 2014-04-11 16:11 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\SystemRequirementsLab
2014-04-11 16:11 - 2014-04-11 16:11 - 00000000 ____D () C:\Program Files\SystemRequirementsLab
2014-04-11 15:50 - 2014-04-11 15:50 - 00000597 ____C () C:\Documents and Settings\UA43931.BBVA.002\Desktop\WinDirStat.lnk
2014-04-09 14:50 - 2014-04-09 15:24 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\vlc
2014-04-09 14:50 - 2014-04-09 14:50 - 00000726 _____ () C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
2014-04-09 14:50 - 2014-04-09 14:50 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
2014-04-09 14:48 - 2014-04-09 14:48 - 00000000 ____D () C:\Program Files\VideoLAN
2014-04-07 20:18 - 2014-04-09 13:04 - 00024064 ____C () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-04-07 11:13 - 2014-04-07 11:13 - 00000876 ____C () C:\Documents and Settings\UA43931.BBVA.002\Desktop\µTorrent.lnk
2014-04-07 11:12 - 2014-04-11 16:29 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\uTorrent
2014-04-06 16:26 - 2014-04-06 16:26 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\Hewlett-Packard_Developme
2014-04-06 16:20 - 2014-04-06 21:20 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\Skype
2014-04-05 12:40 - 2014-04-05 12:42 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Desktop\Holiday_Work_M2
2014-04-03 13:24 - 2014-04-06 16:25 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-03 13:23 - 2014-04-03 13:23 - 00000784 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-03 13:23 - 2014-04-03 13:23 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2014-04-03 13:23 - 2014-04-03 13:23 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-03 13:23 - 2014-04-03 13:23 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-03 13:23 - 2014-03-05 09:26 - 00050648 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-04-03 13:23 - 2014-03-05 09:26 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-04-03 12:46 - 2014-04-03 12:46 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\TuneUp Software
2014-04-03 12:46 - 2014-04-03 12:46 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\AVG2014
2014-04-03 12:46 - 2014-04-03 12:46 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\AVG
2014-04-03 12:45 - 2014-04-03 12:46 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\AVG2014
2014-04-03 12:45 - 2014-04-03 12:45 - 00000000 __HDC () C:\$AVG
2014-04-03 12:40 - 2014-04-11 13:27 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\MFAData
2014-04-03 12:40 - 2014-04-03 12:51 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\Avg2014
2014-04-03 12:40 - 2014-04-03 12:40 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\MFAData
2014-04-01 18:25 - 2014-04-01 18:25 - 00000059 ____C () C:\Documents and Settings\UA43931.BBVA.002\Start Menu\Importar contactos....url
2014-03-31 16:47 - 2014-03-31 16:47 - 00102400 _____ () C:\WINDOWS\Minidump\Mini033114-01.dmp
2014-03-24 17:10 - 2014-04-03 13:18 - 00000000 ____D () C:\Program Files\MediaWatchV1
2014-03-20 14:29 - 2014-03-20 14:29 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\Microsoft Help
2014-03-16 17:12 - 2014-03-16 17:12 - 00000000 _SHDC () C:\Documents and Settings\UA43931.BBVA.002\IECompatCache
2014-03-16 17:12 - 2014-03-16 17:12 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\Google
==================== One Month Modified Files and Folders =======
2014-04-12 18:10 - 2014-04-12 18:10 - 00000000 ___DC () C:\FRST
2014-04-12 18:06 - 2013-02-16 09:45 - 60671130 _____ () C:\WINDOWS\setupapi.log
2014-04-12 18:06 - 2011-04-07 19:20 - 00221494 _____ () C:\WINDOWS\setupact.log
2014-04-12 18:06 - 2011-04-07 17:26 - 01535139 _____ () C:\WINDOWS\WindowsUpdate.log
2014-04-12 18:05 - 2011-04-08 03:15 - 00000582 _____ () C:\WINDOWS\win.ini
2014-04-12 18:05 - 2011-04-08 03:15 - 00000227 _____ () C:\WINDOWS\system.ini
2014-04-12 18:05 - 2011-04-08 03:15 - 00000212 _RSHC () C:\boot.ini
2014-04-12 18:04 - 2014-04-11 17:07 - 00000000 ____D () C:\WINDOWS\pss
2014-04-12 18:00 - 2012-05-31 07:21 - 00000000 __SHD () C:\WINDOWS\CSC
2014-04-12 17:50 - 2011-04-07 19:24 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-04-12 17:50 - 2011-04-07 19:24 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-04-12 17:50 - 2011-04-07 17:30 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-04-11 20:37 - 2014-02-06 13:47 - 00000178 __SHC () C:\Documents and Settings\UA43931.BBVA.002\ntuser.ini
2014-04-11 19:35 - 2012-05-31 06:39 - 00000460 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{36657E7A-DB41-4A05-8160-C2C88A5694DE}.job
2014-04-11 18:25 - 2012-05-31 06:24 - 00524288 _____ () C:\WINDOWS\system32\config\HP Conne.evt
2014-04-11 18:22 - 2013-07-01 20:20 - 00001324 _____ () C:\WINDOWS\system32\d3d9caps.dat
2014-04-11 18:01 - 2013-05-11 14:19 - 00000336 _____ () C:\WINDOWS\Tasks\HP Photo Creations Messager.job
2014-04-11 17:59 - 2014-02-05 15:55 - 00000374 _____ () C:\WINDOWS\Tasks\SelectionTool Update.job
2014-04-11 17:59 - 2013-07-29 19:00 - 00000276 _____ () C:\WINDOWS\Tasks\RMAutoUpdate.job
2014-04-11 17:59 - 2013-07-24 15:49 - 00000000 ____D () C:\Program Files\PC Tools Registry Mechanic
2014-04-11 17:59 - 2012-11-17 20:51 - 00001086 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-11 17:42 - 2012-11-17 20:51 - 00001090 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-11 17:41 - 2011-04-07 17:30 - 00032356 _____ () C:\WINDOWS\SchedLgU.Txt
2014-04-11 17:24 - 2013-09-01 13:24 - 00000416 _____ () C:\WINDOWS\Tasks\At6.job
2014-04-11 16:29 - 2014-04-07 11:12 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\uTorrent
2014-04-11 16:29 - 2012-05-31 16:07 - 00131072 _____ () C:\WINDOWS\system32\config\OAlerts.evt
2014-04-11 16:11 - 2014-04-11 16:11 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\Sun
2014-04-11 16:11 - 2014-04-11 16:11 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\SystemRequirementsLab
2014-04-11 16:11 - 2014-04-11 16:11 - 00000000 ____D () C:\Program Files\SystemRequirementsLab
2014-04-11 15:50 - 2014-04-11 15:50 - 00000597 ____C () C:\Documents and Settings\UA43931.BBVA.002\Desktop\WinDirStat.lnk
2014-04-11 14:18 - 2013-05-11 14:18 - 00000466 _____ () C:\WINDOWS\Tasks\At4.job
2014-04-11 14:00 - 2013-05-11 14:18 - 00000466 _____ () C:\WINDOWS\Tasks\At5.job
2014-04-11 13:27 - 2014-04-03 12:40 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\MFAData
2014-04-11 10:10 - 2013-05-11 14:18 - 00000466 _____ () C:\WINDOWS\Tasks\At2.job
2014-04-10 22:12 - 2013-07-24 15:49 - 00000276 _____ () C:\WINDOWS\Tasks\RMSchedule.job
2014-04-10 20:40 - 2013-05-11 14:18 - 00000466 _____ () C:\WINDOWS\Tasks\At3.job
2014-04-10 19:00 - 2013-07-29 19:00 - 00000272 _____ () C:\WINDOWS\system32\AppLog.log
2014-04-10 17:35 - 2013-09-01 13:24 - 00000000 ____D () C:\Quarantine
2014-04-10 17:33 - 2011-04-08 03:15 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-04-09 15:24 - 2014-04-09 14:50 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\vlc
2014-04-09 14:50 - 2014-04-09 14:50 - 00000726 _____ () C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
2014-04-09 14:50 - 2014-04-09 14:50 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
2014-04-09 14:48 - 2014-04-09 14:48 - 00000000 ____D () C:\Program Files\VideoLAN
2014-04-09 13:04 - 2014-04-07 20:18 - 00024064 ____C () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-04-07 11:13 - 2014-04-07 11:13 - 00000876 ____C () C:\Documents and Settings\UA43931.BBVA.002\Desktop\µTorrent.lnk
2014-04-07 09:34 - 2012-11-20 22:02 - 02059880 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2014-04-06 21:20 - 2014-04-06 16:20 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\Skype
2014-04-06 17:01 - 2014-02-10 20:04 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\CUSTPDF Writer
2014-04-06 16:26 - 2014-04-06 16:26 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\Hewlett-Packard_Developme
2014-04-06 16:25 - 2014-04-03 13:24 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-06 16:24 - 2013-02-03 11:18 - 00002265 _____ () C:\Documents and Settings\All Users\Desktop\Skype.lnk
2014-04-06 16:20 - 2013-02-03 11:18 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Skype
2014-04-06 16:20 - 2012-11-27 22:30 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Skype
2014-04-05 12:42 - 2014-04-05 12:40 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Desktop\Holiday_Work_M2
2014-04-05 10:47 - 2014-01-30 19:22 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\WPM
2014-04-05 10:47 - 2014-01-30 19:21 - 00000000 ____D () C:\Program Files\fst_es_43
2014-04-03 16:37 - 2012-11-17 20:52 - 00001818 _____ () C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2014-04-03 16:18 - 2014-01-30 19:21 - 00000000 ____D () C:\Documents and Settings\ua43931\Application Data\nationzoom
2014-04-03 16:18 - 2013-06-29 14:54 - 00000000 ____D () C:\Program Files\Movies Toolbar
2014-04-03 14:15 - 2013-01-12 23:40 - 00000284 _____ () C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2014-04-03 14:00 - 2014-02-05 15:55 - 00000000 ____D () C:\Program Files\SelectionTool
2014-04-03 13:57 - 2014-01-30 19:21 - 00000000 ____D () C:\Program Files\Mobogenie
2014-04-03 13:23 - 2014-04-03 13:23 - 00000784 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-03 13:23 - 2014-04-03 13:23 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2014-04-03 13:23 - 2014-04-03 13:23 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-03 13:23 - 2014-04-03 13:23 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-03 13:20 - 2014-02-06 13:47 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\Google
2014-04-03 13:19 - 2014-02-24 18:00 - 00000000 ____D () C:\Program Files\MediaViewerV1
2014-04-03 13:19 - 2014-01-30 19:23 - 00000000 ____D () C:\Documents and Settings\ua43931\Local Settings\Application Data\genienext
2014-04-03 13:18 - 2014-03-24 17:10 - 00000000 ____D () C:\Program Files\MediaWatchV1
2014-04-03 13:18 - 2014-02-27 20:55 - 00000000 ____D () C:\Program Files\MediaViewV1
2014-04-03 13:17 - 2014-02-23 14:54 - 00000000 ____D () C:\Program Files\MediaPlayerV1
2014-04-03 13:11 - 2013-09-01 13:24 - 00000000 ____D () C:\Program Files\DealPly
2014-04-03 12:51 - 2014-04-03 12:40 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\Avg2014
2014-04-03 12:46 - 2014-04-03 12:46 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\TuneUp Software
2014-04-03 12:46 - 2014-04-03 12:46 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\AVG2014
2014-04-03 12:46 - 2014-04-03 12:46 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\AVG
2014-04-03 12:46 - 2014-04-03 12:45 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\AVG2014
2014-04-03 12:45 - 2014-04-03 12:45 - 00000000 __HDC () C:\$AVG
2014-04-03 12:40 - 2014-04-03 12:40 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\MFAData
2014-04-03 12:37 - 2013-07-22 14:13 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Norton
2014-04-03 12:31 - 2013-07-22 14:13 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared
2014-04-02 14:41 - 2013-11-11 14:39 - 00528020 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-04-01 18:59 - 2012-09-08 13:35 - 00000838 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-04-01 18:25 - 2014-04-01 18:25 - 00000059 ____C () C:\Documents and Settings\UA43931.BBVA.002\Start Menu\Importar contactos....url
2014-04-01 14:59 - 2012-09-08 13:35 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-04-01 14:59 - 2012-05-31 06:40 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-03-31 16:47 - 2014-03-31 16:47 - 00102400 _____ () C:\WINDOWS\Minidump\Mini033114-01.dmp
2014-03-31 16:47 - 2012-07-03 15:20 - 00000000 ____D () C:\WINDOWS\Minidump
2014-03-31 14:24 - 2013-12-19 10:24 - 00000133 _____ () C:\Documents and Settings\NetworkService\Application Data\WB.CFG
2014-03-20 14:29 - 2014-03-20 14:29 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Application Data\Microsoft Help
2014-03-16 17:12 - 2014-03-16 17:12 - 00000000 _SHDC () C:\Documents and Settings\UA43931.BBVA.002\IECompatCache
2014-03-16 17:12 - 2014-03-16 17:12 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002\Application Data\Google
2014-03-16 17:12 - 2014-02-06 13:47 - 00000000 ___DC () C:\Documents and Settings\UA43931.BBVA.002
2014-03-16 16:36 - 2012-11-20 22:25 - 00000000 ____D () C:\Program Files\SAMSUNG
2014-03-16 16:35 - 2011-04-07 19:21 - 00639330 ____C () C:\WINDOWS\iis6.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00553780 ____C () C:\WINDOWS\FaxSetup.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00275820 ____C () C:\WINDOWS\ocgen.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00255774 ____C () C:\WINDOWS\tsoc.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00187895 ____C () C:\WINDOWS\comsetup.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00174732 ____C () C:\WINDOWS\msmqinst.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00113922 ____C () C:\WINDOWS\ntdtcsetup.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00094775 ____C () C:\WINDOWS\netfxocm.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00038132 ____C () C:\WINDOWS\MedCtrOC.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00029892 ____C () C:\WINDOWS\ocmsn.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00027589 ____C () C:\WINDOWS\tabletoc.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00026909 ____C () C:\WINDOWS\msgsocm.log
2014-03-16 16:35 - 2011-04-07 19:21 - 00001917 _____ () C:\WINDOWS\imsins.log
Files to move or delete:
====================
C:\Windows\Tasks\At1.job
C:\Windows\Tasks\At2.job
C:\Windows\Tasks\At3.job
C:\Windows\Tasks\At4.job
C:\Windows\Tasks\At5.job
C:\Windows\Tasks\At6.job
Some content of TEMP:
====================
C:\Documents and Settings\UA43931.BBVA.000\Local Settings\Temp\Uninstall.exe
C:\Documents and Settings\UA43931.BBVA.002\Local Settings\Temp\SRLDetectionLibrary3695500547527255027.dll
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe => MD5 is legit
C:\WINDOWS\system32\winlogon.exe => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
C:\WINDOWS\system32\User32.dll => MD5 is legit
C:\WINDOWS\system32\userinit.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================