Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-09-2014 01 Ran by [removed] (administrator) on HP-ONE on 28-09-2014 17:12:00 Running from C:\Documents and Settings\[removed]\Desktop [removed] Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English (United States) Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Hewlett-Packard Company) C:\WINDOWS\system\hpsysdrv.exe (Hewlett-Packard Company) C:\hp\KBD\kbd.exe (Agere Systems) C:\WINDOWS\AGRSMMSG.exe (Realtek Semiconductor Corp.) C:\WINDOWS\ALCMTR.EXE (Lavasoft) C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy2\TeaTimer.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe (Alcatel-Lucent) C:\Program Files\Common Files\Motive\McciCMService.exe (Symantec Corporation) C:\Program Files\Norton AntiVirus\Engine\21.6.0.32\nav.exe (Symantec Corporation) C:\Program Files\Norton Safe Web Lite\Engine\1.0.1.8\ccSvcHst.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Symantec Corporation) C:\Program Files\Norton AntiVirus\Engine\21.6.0.32\nav.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [hpsysdrv] => c:\windows\system\hpsysdrv.exe [52736 1998-05-08] (Hewlett-Packard Company) HKLM\...\Run: [KBD] => C:\HP\KBD\KBD.EXE [61440 2003-02-12] (Hewlett-Packard Company) HKLM\...\Run: [Recguard] => C:\WINDOWS\SMINST\RECGUARD.EXE [233472 2004-04-14] () HKLM\...\Run: [AGRSMMSG] => C:\WINDOWS\AGRSMMSG.exe [88363 2004-06-29] (Agere Systems) HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [57344 2004-04-27] (Realtek Semiconductor Corp.) HKLM\...\Run: [PS2] => C:\WINDOWS\system32\ps2.exe [81920 2002-10-16] (Hewlett-Packard Company) HKLM\...\Run: [Ad-Aware Browsing Protection] => C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe [198032 2011-10-21] (Lavasoft) HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2014-01-17] (Apple Inc.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe [440632 2014-08-29] (Malwarebytes Corporation) Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation) Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X] HKLM\...\Policies\Explorer: [NoCDBurning] 0 HKU\S-1-5-21-765943430-1787625549-695394895-1003\...\Run: [SpybotSD TeaTimer] => C:\Program Files\Spybot - Search & Destroy2\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk.disabled ShortcutTarget: HP Digital Imaging Monitor.lnk.disabled -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk.disabled ShortcutTarget: Microsoft Office.lnk.disabled -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk.disabled ShortcutTarget: Quicken Scheduled Updates.lnk.disabled -> C:\Program Files\Quicken\bagent.exe (No File) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk.disabled ShortcutTarget: Updates from HP.lnk.disabled -> C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe (No File) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk.disabled ShortcutTarget: Windows Search.lnk.disabled -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation) Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk.disabled ShortcutTarget: BBC iPlayer Desktop.lnk.disabled -> C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe () Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\HP Organize.lnk.disabled ShortcutTarget: HP Organize.lnk.disabled -> C:\Program Files\Hewlett-Packard\HP Organize\bin\displayAgent.exe (NeoPlanet) Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\IMStart.lnk.disabled ShortcutTarget: IMStart.lnk.disabled -> C:\Program Files\InterMute\IMStart.exe (No File) Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Lotus QuickStart.lnk.disabled ShortcutTarget: Lotus QuickStart.lnk.disabled -> C:\lotus\wordpro\ltsstart.exe (Lotus Development Corporation) Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Lotus SmartCenter 97.lnk.disabled ShortcutTarget: Lotus SmartCenter 97.lnk.disabled -> C:\lotus\smartctr\smartctr.exe (Lotus Development Corporation.) Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Lotus SuiteStart 97.lnk.disabled ShortcutTarget: Lotus SuiteStart 97.lnk.disabled -> C:\lotus\smartctr\suitest.exe (Lotus Development Corporation.) Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk.disabled ShortcutTarget: OpenOffice.org 3.3.lnk.disabled -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk.disabled ShortcutTarget: OpenOffice.org 3.4.1.lnk.disabled -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/en-us/srchasst/srchasst.htm HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x001C403E00D0CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html URLSearchHook: HKCU - (No Name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File SearchScopes: HKCU - DefaultScope {086DAB07-3DCE-40A4-98D9-2D120DA4C84F} URL = http://search.zonealarm.com/search?src=sp&tbid=HFA5&Lan=EN&q={searchTerms}&gu=955d1378495044bb9da50606d409f5ef&tu=10Gpy00FG2D30q0&sku=&tstsId=&ver=&&r=0 SearchScopes: HKCU - {086DAB07-3DCE-40A4-98D9-2D120DA4C84F} URL = http://search.zonealarm.com/search?src=sp&tbid=HFA5&Lan=EN&q={searchTerms}&gu=955d1378495044bb9da50606d409f5ef&tu=10Gpy00FG2D30q0&sku=&tstsId=&ver=&&r=0 SearchScopes: HKCU - {32C5C3B5-8F2F-4831-9305-57C47B323786} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 SearchScopes: HKCU - {7219660F-EBBB-BDCF-159B-1D09FC0C20C8} URL = http://www.mirostart.com/s/?q={searchTerms}&iesrc={referrer:source?}&cfg=2-73-0-g6GW SearchScopes: HKCU - {ABD5E0E2-1848-48FA-ACCF-F55B1249A1D3} URL = http://www.google.co.uk/search?hl=en&q={searchTerms}&meta= SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = http://uk.ask.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=SWL&chn=&geo=GB&ver=1 SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2611275 SearchScopes: HKCU - {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://uk.search.yahoo.com/search?p={searchTerms} BHO: No Name -> {02478D38-C3F9-4EFB-9B51-7695ECA05670} -> No File BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files\Spybot - Search & Destroy2\SDHelper.dll (Safer Networking Limited) BHO: Ad-Aware Security Toolbar -> {6c97a91e-4524-4019-86af-2aa2d567bf5c} -> C:\Program Files\adawaretb\adawareDx.dll () BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton AntiVirus\Engine\21.6.0.32\IPS\IPSBHO.DLL (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Norton Safe Web Lite BHO -> {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} -> C:\Program Files\Norton Safe Web Lite\Engine\1.0.1.8\coIEPlg.dll (Symantec Corporation) BHO: No Name -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> No File Toolbar: HKLM - HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll (Hewlett-Packard Company) Toolbar: HKLM - No Name - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File Toolbar: HKLM - Norton Safe Web Lite - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files\Norton Safe Web Lite\Engine\1.0.1.8\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM - Ad-Aware Security Toolbar - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll () Toolbar: HKLM - No Name - {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - No File Toolbar: HKCU - HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll (Hewlett-Packard Company) Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) Toolbar: HKCU - Norton Safe Web Lite - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files\Norton Safe Web Lite\Engine\1.0.1.8\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default FF DefaultSearchEngine: Ask FF SelectedSearchEngine: Ask FF Homepage: https://ixquick.com/ FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1213153.dll (Adobe Systems, Inc.) FF Plugin: @checkpoint.com/FFApi -> C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll No File FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @macromedia.com/FlashPlayer10 -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files\Virtual Earth 3D\ () FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @Motive.com/NpMotive,version=1.0 -> C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.) FF Plugin: @nosltd.com/getPlus+(R),version=1.6.2.102 -> C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @macromedia.com/FlashPlayer10 -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File FF user.js: detected! => C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npBTEmailConfig.dll (British Telecommunications Plc) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np_gp.dll (NOS Microsystems Ltd.) FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\searchplugins\ask.uk.xml FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\searchplugins\duckduckgo-ssl.xml FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\searchplugins\ixquick-https.xml FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\searchplugins\safesearch.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazon-en-GB.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\chambers-en-GB.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-en-GB.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-en-GB.xml FF Extension: No Name - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\Access Privileges Test [2010-07-02] FF Extension: British English Dictionary - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\[removed] [2010-12-11] FF Extension: No Name - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\nostmp [2011-03-26] FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-04-29] FF Extension: EPUBReader - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F} [2014-08-21] FF Extension: Ad-Aware Security Add-on - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2011-12-23] FF Extension: DownloadHelper - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-06] FF Extension: Adobe DLM (powered by getPlus(R)) - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2010-12-11] FF Extension: SearchPreview - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}(2) [2010-11-12] FF Extension: Save Images - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\[removed] [2013-05-30] FF Extension: Print Edit - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\[removed] [2012-04-26] FF Extension: Bluhell Firewall - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\{6BB5760D-F97E-421B-AF5B-8457A90C3CED}.xpi [2014-08-12] FF Extension: Search By Image (by Google) - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gzu4ievc.default\Extensions\{ce7e73df-6a44-4028-8079-5927a588c948}.xpi [2013-05-15] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-03-29] FF HKLM\...\Firefox\Extensions: [{203FB6B2-2E1E-4474-863B-4C483ECCE78E}] - C:\Documents and Settings\All Users\Application Data\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.0.1.8\coFFNST FF Extension: Norton Safe Web Lite Toolbar - C:\Documents and Settings\All Users\Application Data\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.0.1.8\coFFNST [2010-08-05] Chrome: ======= ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 MbaeSvc; C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe [441144 2014-08-29] (Malwarebytes Corporation) R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [319488 2009-08-24] (Alcatel-Lucent) [File not signed] R2 NAV; C:\Program Files\Norton AntiVirus\Engine\21.6.0.32\NAV.exe [262968 2014-09-21] (Symantec Corporation) R2 NSL; C:\Program Files\Norton Safe Web Lite\Engine\1.0.1.8\ccSvcHst.exe [126904 2010-05-23] (Symantec Corporation) R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) S4 Usmsaud; No ImagePath ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 AFS2K; C:\WINDOWS\system32\Drivers\AFS2K.sys [43672 2004-05-12] (Oak Technology Inc.) R1 BHDrvx86; C:\Program Files\Norton AntiVirus\NortonData\21.4.0.13\Definitions\BASHDefs\20140912.003\BHDrvx86.sys [1137368 2014-09-12] (Symantec Corporation) R1 ccSet_NAV; C:\WINDOWS\system32\drivers\NAV\1506000.020\ccSetx86.sys [127064 2014-02-21] (Symantec Corporation) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2014-09-09] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [111408 2014-09-09] (Symantec Corporation) R1 ESProtectionDriver; C:\Program Files\Malwarebytes Anti-Exploit\mbae.sys [47896 2014-08-30] () R0 fasttx2k; C:\WINDOWS\System32\DRIVERS\fasttx2k.sys [142336 2003-12-03] (Promise Technology, Inc.) R3 IDSxpx86; C:\Program Files\Norton AntiVirus\NortonData\21.4.0.13\Definitions\IPSDefs\20140926.003\IDSxpx86.sys [448664 2014-08-29] (Symantec Corporation) R1 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [53208 2014-05-12] (Malwarebytes Corporation) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [110296 2014-09-28] (Malwarebytes Corporation) S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2009-12-07] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed] S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2009-12-07] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed] R3 NAVENG; C:\Program Files\Norton AntiVirus\NortonData\21.4.0.13\Definitions\VirusDefs\20140927.001\NAVENG.SYS [95704 2014-08-21] (Symantec Corporation) R3 NAVEX15; C:\Program Files\Norton AntiVirus\NortonData\21.4.0.13\Definitions\VirusDefs\20140927.001\NAVEX15.SYS [1636696 2014-08-21] (Symantec Corporation) R3 rtl8139; C:\WINDOWS\System32\DRIVERS\R8139n51.SYS [46976 2002-10-05] (Realtek Semiconductor Corporation ) S3 scsiscan; C:\WINDOWS\System32\DRIVERS\scsiscan.sys [11520 2008-04-13] (Microsoft Corporation) S3 SiS315; C:\WINDOWS\System32\DRIVERS\sisgrp.sys [432000 2004-01-03] (Silicon Integrated Systems Corporation) R1 SiSkp; C:\WINDOWS\System32\DRIVERS\srvkp.sys [11520 2004-01-03] (Silicon Integrated Systems Corporation) R3 SRTSP; C:\WINDOWS\System32\Drivers\NAV\1506000.020\SRTSP.SYS [664792 2014-08-26] (Symantec Corporation) R1 SRTSPX; C:\WINDOWS\system32\drivers\NAV\1506000.020\SRTSPX.SYS [32984 2014-08-26] (Symantec Corporation) R0 SymDS; C:\WINDOWS\System32\drivers\NAV\1506000.020\SYMDS.SYS [367704 2013-10-30] (Symantec Corporation) R0 SymEFA; C:\WINDOWS\System32\drivers\NAV\1506000.020\SYMEFA.SYS [936152 2014-03-04] (Symantec Corporation) R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT.SYS [142936 2014-07-31] (Symantec Corporation) R1 SymIRON; C:\WINDOWS\system32\drivers\NAV\1506000.020\Ironx86.SYS [209624 2014-08-06] (Symantec Corporation) R1 SYMTDI; C:\WINDOWS\System32\Drivers\NAV\1506000.020\SYMTDI.SYS [423256 2014-02-18] (Symantec Corporation) R0 viaagp1; C:\WINDOWS\System32\DRIVERS\viaagp1.sys [27904 2003-07-02] (VIA Technologies, Inc.) S3 viagfx; C:\WINDOWS\System32\DRIVERS\vtmini.sys [134144 2004-02-05] (Copyright (C) VIA/S3 Graphics, Inc.) S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X] S0 Lbd; system32\DRIVERS\Lbd.sys [X] S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X] S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X] S1 SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys [X] U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation) U3 aswMBR; \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\aswMBR.sys [X] U3 aswVmm; \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\aswVmm.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-28 17:12 - 2014-09-28 17:12 - 00026321 _____ () C:\Documents and Settings\Owner\Desktop\FRST.txt 2014-09-28 17:11 - 2014-09-28 17:12 - 00000000 ____D () C:\FRST 2014-09-28 17:10 - 2014-09-28 17:10 - 01100288 _____ (Farbar) C:\Documents and Settings\Owner\Desktop\FRST.exe 2014-09-28 17:02 - 2014-09-28 17:07 - 00002550 _____ () C:\Documents and Settings\Owner\My Documents\aswMBR.txt 2014-09-28 17:02 - 2014-09-28 17:07 - 00000512 _____ () C:\Documents and Settings\Owner\My Documents\MBR.dat 2014-09-28 16:51 - 2014-09-28 16:59 - 05185536 _____ (AVAST Software) C:\Documents and Settings\Owner\Desktop\aswMBR.exe 2014-09-25 21:02 - 2014-09-25 21:15 - 00000000 ____D () C:\Documents and Settings\Administrator.HP-ONE\Local Settings\Application Data\NPE 2014-09-25 21:02 - 2014-09-25 21:02 - 00069720 _____ () C:\Documents and Settings\Administrator.HP-ONE\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2014-09-25 21:02 - 2014-09-25 21:02 - 00001186 _____ () C:\Documents and Settings\Administrator.HP-ONE\My Documents\norton.txt 2014-09-25 18:17 - 2014-09-25 18:17 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-09-21 13:31 - 2014-09-21 14:00 - 00000000 ____D () C:\vandy1 2014-09-20 10:38 - 2014-09-20 10:38 - 00059325 _____ () C:\Diecast Models _ Buy Diecast Models & Plastic Hobby Kits _ KH Norton.htm 2014-09-20 10:38 - 2014-09-20 10:38 - 00000000 ____D () C:\Diecast Models _ Buy Diecast Models & Plastic Hobby Kits _ KH Norton_files 2014-09-20 02:20 - 2014-09-28 12:25 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes Anti-Exploit 2014-09-20 02:20 - 2014-09-20 02:20 - 00000788 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Exploit.lnk 2014-09-20 02:20 - 2014-09-20 02:20 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Exploit 2014-09-20 02:20 - 2014-09-20 02:20 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Exploit 2014-09-18 20:22 - 2014-09-25 21:15 - 00000178 ___SH () C:\Documents and Settings\Administrator.HP-ONE\ntuser.ini 2014-09-18 20:22 - 2014-09-25 21:15 - 00000000 ____D () C:\Documents and Settings\Administrator.HP-ONE\Local Settings\Temp 2014-09-18 20:22 - 2014-09-18 20:22 - 00000000 ____D () C:\Documents and Settings\Administrator.HP-ONE 2014-09-18 20:22 - 2010-01-22 12:28 - 00000000 ____D () C:\Documents and Settings\Administrator.HP-ONE\Application Data\Macromedia 2014-09-18 20:22 - 2009-12-09 18:59 - 00000000 __SHD () C:\Documents and Settings\Administrator.HP-ONE\IETldCache 2014-09-18 20:22 - 2004-05-31 20:24 - 00000000 ___RD () C:\Documents and Settings\Administrator.HP-ONE\Start Menu\Programs\Accessories 2014-09-18 20:22 - 2004-05-13 07:03 - 00000847 _____ () C:\Documents and Settings\Administrator.HP-ONE\Start Menu\Programs\Internet Explorer.lnk 2014-09-18 20:22 - 2004-05-13 06:57 - 00000000 ____D () C:\Documents and Settings\Administrator.HP-ONE\Application Data\Symantec 2014-09-18 20:22 - 2004-05-12 13:28 - 00000000 ____D () C:\Documents and Settings\Administrator.HP-ONE\Start Menu\Programs\Online Services 2014-09-18 20:22 - 2004-05-12 13:23 - 00000128 _____ () C:\Documents and Settings\Administrator.HP-ONE\Local Settings\Application Data\fusioncache.dat 2014-09-18 20:22 - 2004-05-12 13:05 - 00000000 ____D () C:\Documents and Settings\Administrator.HP-ONE\Application Data\SampleView 2014-09-18 20:22 - 2004-05-12 12:29 - 00000000 ____D () C:\Documents and Settings\Administrator.HP-ONE\WINDOWS 2014-09-18 20:22 - 2004-05-12 11:59 - 00000000 ____D () C:\Documents and Settings\Administrator.HP-ONE\Application Data\Real 2014-09-18 20:22 - 2004-05-12 08:27 - 00000000 ____D () C:\Documents and Settings\Administrator.HP-ONE\Application Data\Sun 2014-09-18 20:22 - 2004-05-12 08:26 - 00000000 ____D () C:\Documents and Settings\Administrator.HP-ONE\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030} 2014-09-18 20:22 - 2004-05-12 07:44 - 00015619 _____ () C:\Documents and Settings\Administrator.HP-ONE\ml1.srt 2014-09-18 20:22 - 2004-05-12 07:44 - 00015420 _____ () C:\Documents and Settings\Administrator.HP-ONE\ml2.srt 2014-09-18 20:22 - 2004-05-12 07:44 - 00007593 _____ () C:\Documents and Settings\Administrator.HP-ONE\tempdiff.txt 2014-09-18 20:22 - 2004-05-12 07:28 - 00000738 _____ () C:\Documents and Settings\Administrator.HP-ONE\Start Menu\Programs\Outlook Express.lnk 2014-09-18 20:22 - 2004-05-12 07:25 - 00001599 _____ () C:\Documents and Settings\Administrator.HP-ONE\Start Menu\Programs\Remote Assistance.lnk 2014-09-18 19:57 - 2014-09-18 19:57 - 00001336 _____ () C:\Documents and Settings\Owner\My Documents\cc_20140918_195703.reg 2014-09-12 21:56 - 2014-09-12 21:56 - 00000000 ____D () C:\Documents and Settings\Owner\My Documents\My Received Files 2014-09-12 18:08 - 2014-09-27 17:45 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird 2014-09-09 21:27 - 2014-09-09 21:27 - 00058892 ____H () C:\WINDOWS\system32\mlfcache.dat 2014-09-07 15:35 - 2014-09-07 15:35 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MSN6 2014-09-07 14:29 - 2014-09-07 14:29 - 00000704 _____ () C:\Documents and Settings\Owner\My Documents\cc_20140907_142940.reg 2014-09-04 20:17 - 2014-08-19 18:00 - 00451148 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140904-201733.backup 2014-09-03 21:31 - 2014-09-03 21:31 - 00000000 ____D () C:\Malwarebytes Online Store_files 2014-09-03 21:19 - 2014-09-28 16:15 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-09-03 21:18 - 2014-09-03 21:18 - 00000788 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk 2014-09-03 21:18 - 2014-09-03 21:18 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-09-03 21:18 - 2014-09-03 21:18 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware 2014-09-03 21:18 - 2014-05-12 07:26 - 00053208 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-09-03 21:18 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-09-02 20:44 - 2014-09-02 20:44 - 00063694 _____ () C:\Checkout - Flying Tigerssr71.htm 2014-09-02 20:44 - 2014-09-02 20:44 - 00000000 ____D () C:\Checkout - Flying Tigerssr71_files 2014-09-01 19:00 - 2014-09-01 19:00 - 00013441 _____ () C:\Thank you - Art Fund.htm 2014-09-01 19:00 - 2014-09-01 19:00 - 00000000 ____D () C:\Thank you - Art Fund_files ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-28 17:12 - 2008-02-19 15:46 - 00000000 ____D () C:\Documents and Settings\Owner\Local Settings\Temp 2014-09-28 12:18 - 2007-04-12 18:29 - 01450729 _____ () C:\WINDOWS\WindowsUpdate.log 2014-09-28 12:16 - 2005-12-13 19:53 - 00178108 _____ () C:\WINDOWS\system32\nvapps.xml 2014-09-28 12:16 - 2005-02-21 18:40 - 00000188 _____ () C:\WINDOWS\system\hpsysdrv.DAT 2014-09-28 12:16 - 2004-05-12 00:22 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-09-28 12:16 - 2004-05-12 00:22 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-09-28 12:15 - 2004-05-12 07:25 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-09-28 02:53 - 2014-03-21 21:49 - 00524288 _____ () C:\WINDOWS\system32\config\SpybotSD.evt 2014-09-28 02:53 - 2004-05-12 07:28 - 00000178 ___SH () C:\Documents and Settings\Owner\ntuser.ini 2014-09-28 02:53 - 2004-05-12 07:27 - 00032634 _____ () C:\WINDOWS\SchedLgU.Txt 2014-09-27 20:49 - 2012-05-04 13:54 - 00000000 ____D () C:\free 2014-09-27 20:44 - 2012-08-13 10:10 - 00000000 ____D () C:\Ryder 2014-09-27 19:10 - 2012-04-25 21:07 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-09-27 16:44 - 2009-02-22 14:51 - 00000000 ____D () C:\Documents and Settings\Owner\My Documents\Aircraft 2014-09-27 11:49 - 2007-10-08 14:54 - 00002473 _____ () C:\Documents and Settings\Owner\Desktop\Microsoft Word (2).lnk 2014-09-27 10:06 - 2004-05-12 07:27 - 00000000 ____D () C:\Documents and Settings\Owner 2014-09-27 00:38 - 2010-12-24 16:53 - 00000000 ____D () C:\Scarlett 2014-09-26 20:49 - 1997-05-13 02:23 - 00000980 ____C () C:\WINDOWS\acroread.ini 2014-09-26 18:52 - 2012-02-16 11:54 - 00000000 ____D () C:\KRitchie6 2014-09-26 18:41 - 2011-10-29 12:59 - 00000000 ____D () C:\janehill 2014-09-25 21:15 - 2004-05-12 07:16 - 00000281 _____ () C:\boot.ini 2014-09-25 17:57 - 2009-06-18 19:43 - 00000000 ____D () C:\WINDOWS\system32\Drivers\NAV 2014-09-25 17:56 - 2014-07-31 01:16 - 00001896 _____ () C:\Documents and Settings\All Users\Desktop\Norton AntiVirus.LNK 2014-09-25 17:56 - 2014-07-31 01:15 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Norton AntiVirus 2014-09-23 21:41 - 2004-05-12 07:24 - 00000000 ____D () C:\WINDOWS\system32\Restore 2014-09-23 19:35 - 2004-05-12 07:16 - 00001158 _____ () C:\WINDOWS\system32\wpa.dbl 2014-09-21 13:53 - 2007-04-09 12:03 - 00000102 ____C () C:\WINDOWS\vuepro32.ini 2014-09-21 11:54 - 2011-12-27 17:05 - 00000000 ____D () C:\jenkins 2014-09-20 20:30 - 2012-03-09 14:41 - 00000000 ____D () C:\Nigella 2014-09-20 13:08 - 2012-03-09 15:15 - 00000000 ____D () C:\CarolKirkwood 2014-09-17 00:31 - 2014-03-21 21:49 - 00000616 _____ () C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job 2014-09-14 11:06 - 2004-05-12 07:23 - 00000000 ____D () C:\Program Files\MSN 2014-09-13 17:47 - 2014-07-30 23:37 - 00000000 ____D () C:\Documents and Settings\Owner\Local Settings\Application Data\NPE 2014-09-13 14:53 - 2012-03-29 16:00 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2014-09-13 14:53 - 2012-03-29 16:00 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-09-13 14:53 - 2011-05-19 11:13 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2014-09-12 18:12 - 2013-10-11 10:30 - 00000000 ____D () C:\pay 2014-09-12 18:09 - 2011-11-01 23:30 - 00000000 ____D () C:\X 2014-09-11 21:15 - 2014-03-21 21:49 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2 2014-09-10 21:51 - 2013-08-14 13:40 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-09-10 21:39 - 2009-02-24 20:03 - 98758480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-09-07 15:36 - 2007-08-14 12:53 - 00000000 ____D () C:\Documents and Settings\Owner\Application Data\MSN6 2014-09-07 15:35 - 2004-05-12 08:08 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Online Services 2014-08-30 19:08 - 2008-06-24 11:36 - 00000000 ____D () C:\Documents and Settings\Owner\.gimp-2.4 ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================