Results of screen317's Security Check version 0.99.64
Windows XP Service Pack 3 x86
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
ESET Online Scanner v3
Microsoft Security Essentials
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.75.0.1300
CCleaner
Java 7 Update 21
Adobe Flash Player 11.7.700.224
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Spybot Teatimer.exe is disabled!
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 3%
````````````````````End of Log``````````````````````
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-06-15 09:07:46
—————————–
09:07:46.640 OS Version: Windows 5.1.2600 Service Pack 3
09:07:46.640 Number of processors: 1 586 0x2F02
09:07:46.640 ComputerName: LEW-0CCC0E88CE3 UserName: Lew
09:07:47.625 Initialize success
09:17:40.015 AVAST engine defs: 13061300
09:18:41.203 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
09:18:41.203 Disk 0 Vendor: WDC_WD5000AAKX-001CA0 15.01H15 Size: 476940MB BusType: 3
09:18:41.359 Disk 0 MBR read successfully
09:18:41.359 Disk 0 MBR scan
09:18:41.406 Disk 0 Windows XP default MBR code
09:18:41.406 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476929 MB offset 63
09:18:41.484 Disk 0 scanning sectors +976752000
09:18:41.578 Disk 0 scanning C:\WINDOWS\system32\drivers
09:19:04.375 Service scanning
09:19:13.562 Service MpKsl90c41d88 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3FA619F5-BF93-469A-A1A6-508803A0779C}\MpKsl90c41d88.sys **LOCKED** 32
09:19:25.609 Modules scanning
09:19:29.343 Disk 0 trace - called modules:
09:19:29.343 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
09:19:29.843 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x858a9ab8]
09:19:29.843 3 CLASSPNP.SYS[f75d0fd7] -> nt!IofCallDriver -> \Device\00000067[0x85973f18]
09:19:29.843 5 ACPI.sys[f7447620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-e[0x858aad98]
09:19:30.515 AVAST engine scan C:\WINDOWS
09:19:46.625 AVAST engine scan C:\WINDOWS\system32
09:24:03.406 AVAST engine scan C:\WINDOWS\system32\drivers
09:24:30.875 AVAST engine scan C:\Documents and Settings\Lew
09:37:37.656 AVAST engine scan C:\Documents and Settings\All Users
09:39:09.078 Scan finished successfully
09:41:42.859 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Lew\Desktop\MBR.dat"
09:41:42.890 The log file has been saved successfully to "C:\Documents and Settings\Lew\Desktop\aswMBR.log"
OTL logfile created on: 6/15/2013 9:44:04 AM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Lew\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
958.48 Mb Total Physical Memory | 512.76 Mb Available Physical Memory | 53.50% Memory free
2.26 Gb Paging File | 1.88 Gb Available in Paging File | 83.04% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 398.70 Gb Free Space | 85.60% Space Free | Partition Type: NTFS
Drive D: | 202.83 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: LEW-0CCC0E88CE3 | User Name: Lew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Lew\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\honestech Audio Recorder 3.0 Plus\HTARLauncher.exe (Honest Technology)
PRC - C:\Documents and Settings\Lew\My Documents\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll ()
MOD - C:\WINDOWS\system32\nvshell.dll ()
========== Services (SafeList) ==========
SRV - (SDWSCService) – C:\Program Files\Spybot File not found
SRV - (SDUpdateService) – C:\Program Files\Spybot File not found
SRV - (SDScannerService) – C:\Program Files\Spybot File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (!SASCORE) – C:\Documents and Settings\Lew\My Documents\SASCore.exe (SUPERAntiSpyware.com)
SRV - (BBUpdate) – C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (aswMBR) – C:\DOCUME~1\Lew\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (MpKsl90c41d88) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3FA619F5-BF93-469A-A1A6-508803A0779C}\MpKsl90c41d88.sys (Microsoft Corporation)
DRV - (SASKUTIL) – C:\Documents and Settings\Lew\My Documents\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Documents and Settings\Lew\My Documents\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (LSI Corporation)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (FETNDISB) – C:\WINDOWS\system32\drivers\dlkfet5b.sys (D-Link )
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://aol.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 52 84 B8 B5 E2 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@nds.com/PCShowPlugin: C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPCShowPlugin.dll File not found
FF - HKCU\Software\MozillaPlugins\@nds.com/PlayerPlugin: C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll (NDS)
FF - HKCU\Software\MozillaPlugins\NDS.com/PlayerPlugin: C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll (NDS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/09/12 14:56:42 | 000,000,000 | —D | M]
[2012/09/14 17:47:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
========== Chrome ==========
CHR - homepage:
http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://www.google.com/
CHR - Extension: YouTube = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Coupon Companion = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.18.12_0\crossrider
CHR - Extension: Coupon Companion = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.18.12_0\
CHR - Extension: Gmail = C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/09/20 10:30:46 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Spybot-S&D Cleaning] C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\honestech Audio Recorder 3.0 Plus Launcher.lnk = C:\Program Files\honestech Audio Recorder 3.0 Plus\HTARLauncher.exe (Honest Technology)
O4 - Startup: C:\Documents and Settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O15 - HKCU\..Trusted Domains: coastalbankofga.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: ebay.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: extendhealth.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: extendhealth.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: fisherbuggies.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: hulu.com ([www] http in Local intranet)
O15 - HKCU\..Trusted Domains: msn.com ([www] http in Local intranet)
O15 - HKCU\..Trusted Domains: shoptalkforums.com ([www] http in Local intranet)
O15 - HKCU\..Trusted Domains: thebrunswicknews.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: usps.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: usps.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: whatthetech.com ([forums] http in Local intranet)
O15 - HKCU\..Trusted Domains: yahoo.com ([www] http in Local intranet)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/windowsupd…b?1347465718176 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1347978180406 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2E5072BA-3DCD-43F1-A347-7B3E0450AF88}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Documents and Settings\Lew\My Documents\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/09/11 18:13:41 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/06/15 09:06:05 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lew\Desktop\OTL.exe
[2013/06/15 09:05:41 | 004,745,728 | —- | C] (AVAST Software) – C:\Documents and Settings\Lew\Desktop\aswMBR.exe
[2013/06/10 19:06:18 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Lew\Recent
[2013/06/10 14:11:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Lew\My Documents\Makita LS1440 Miter Saw
========== Files - Modified Within 30 Days ==========
[2013/06/15 09:41:42 | 000,000,512 | —- | M] () – C:\Documents and Settings\Lew\Desktop\MBR.dat
[2013/06/15 09:40:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/06/15 09:06:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lew\Desktop\OTL.exe
[2013/06/15 09:05:45 | 004,745,728 | —- | M] (AVAST Software) – C:\Documents and Settings\Lew\Desktop\aswMBR.exe
[2013/06/15 08:59:18 | 000,000,274 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
[2013/06/15 08:59:17 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
[2013/06/15 08:59:16 | 000,043,531 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2013/06/15 08:59:08 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/06/15 08:59:02 | 000,000,366 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2013/06/14 21:28:45 | 000,000,211 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Google.url
[2013/06/14 21:24:41 | 000,000,620 | —- | M] () – C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/06/14 20:40:02 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2013/06/14 19:21:41 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/06/14 19:11:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/06/14 19:06:29 | 000,000,279 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Virus, Spyware & Malware Removal - What the Tech.url
[2013/06/14 18:56:56 | 000,000,208 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Yahoo Mail Login.url
[2013/06/14 15:21:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2013/06/14 14:00:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2013/06/14 13:37:02 | 000,001,793 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Rain Alarm.url
[2013/06/14 10:10:12 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2013/06/13 08:29:43 | 000,000,253 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Contact Brunswick Radio Station.url
[2013/06/12 14:41:03 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/06/12 14:41:03 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/06/12 11:25:08 | 000,000,241 | —- | M] () – C:\Documents and Settings\Lew\Desktop\craigslist Brunswick, GA.url
[2013/06/12 03:00:56 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/06/12 00:30:00 | 000,000,616 | —- | M] () – C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2013/06/11 12:30:56 | 000,000,473 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Guy Noir - 2-9-2013 - YouTube.url
[2013/06/11 12:11:15 | 000,000,473 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Café Boeuf - 9-15-2012 - YouTube.url
[2013/06/10 19:07:10 | 000,001,062 | —- | M] () – C:\Documents and Settings\Lew\My Documents\cc_20130610_190704.reg
[2013/06/08 16:08:11 | 000,000,353 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Real American Airlines Boeing 767 cockpit JFK to LAX (not a simulator or reenactment) - YouTube.url
[2013/06/08 12:04:36 | 004,760,816 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Lew\My Documents\SUPERANTISPYWARE.EXE
[2013/06/06 08:26:45 | 000,004,578 | —- | M] () – C:\Documents and Settings\Lew\Application Data\wklnhst.dat
[2013/06/03 14:34:56 | 000,001,630 | —- | M] () – C:\Documents and Settings\Lew\Desktop\The Farmhouse Cottage in Memphis.url
[2013/06/03 13:25:14 | 000,010,752 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Funeral Letter to Robin Deason.wps
[2013/06/03 07:07:25 | 000,001,212 | —- | M] () – C:\Documents and Settings\Lew\Desktop\ 7-Day Forecast for Latitude 31.21°N and Longitude 81.36°W.url
[2013/06/01 08:55:33 | 000,002,846 | —- | M] () – C:\Documents and Settings\Lew\Desktop\How to Use Environment Variables in Windows XP.url
[2013/06/01 08:54:55 | 000,002,138 | —- | M] () – C:\Documents and Settings\Lew\Desktop\98 Volkswagen beetle my radio is in safe mode - JustAnswer.url
[2013/06/01 00:30:00 | 000,000,446 | —- | M] () – C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job
[2013/05/25 08:53:05 | 000,000,294 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Controlling Bahiagrass in Warm-Season Turf.url
[2013/05/25 07:48:06 | 000,000,241 | —- | M] () – C:\Documents and Settings\Lew\Desktop\TDIClub.url
[2013/05/23 16:48:01 | 000,000,735 | —- | M] () – C:\Documents and Settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK
[2013/05/18 13:40:47 | 000,050,925 | —- | M] () – C:\Documents and Settings\Lew\My Documents\Genuine Nissan Parts - Search by Nissan VIN, Car Model or Nissan Part Number.htm
[2013/05/18 07:01:32 | 000,062,272 | —- | M] () – C:\Documents and Settings\Lew\My Documents\GEELY SERVICE MANUALS.mht
[2013/05/18 07:00:21 | 002,712,100 | —- | M] () – C:\Documents and Settings\Lew\My Documents\Geely Manual.pdf
[2013/05/17 18:34:56 | 000,000,353 | —- | M] () – C:\Documents and Settings\Lew\Desktop\Imax - Fires of Kuwait - FULL - 9 subtitles - YouTube.url
[2013/05/17 18:07:22 | 006,014,976 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2013/05/17 09:05:50 | 000,000,361 | RHS- | M] () – C:\boot.ini
[2013/05/16 16:39:19 | 000,006,054 | —- | M] () – C:\Documents and Settings\Lew\My Documents\cc_20130516_163913.reg
========== Files Created - No Company Name ==========
[2013/06/15 09:41:42 | 000,000,512 | —- | C] () – C:\Documents and Settings\Lew\Desktop\MBR.dat
[2013/06/14 19:06:29 | 000,000,279 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Virus, Spyware & Malware Removal - What the Tech.url
[2013/06/12 03:00:55 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2013/06/11 12:30:56 | 000,000,473 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Guy Noir - 2-9-2013 - YouTube.url
[2013/06/10 19:07:09 | 000,001,062 | —- | C] () – C:\Documents and Settings\Lew\My Documents\cc_20130610_190704.reg
[2013/06/08 16:08:11 | 000,000,353 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Real American Airlines Boeing 767 cockpit JFK to LAX (not a simulator or reenactment) - YouTube.url
[2013/06/04 16:32:30 | 000,001,793 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Rain Alarm.url
[2013/05/30 16:41:52 | 000,001,630 | —- | C] () – C:\Documents and Settings\Lew\Desktop\The Farmhouse Cottage in Memphis.url
[2013/05/30 11:25:08 | 000,010,752 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Funeral Letter to Robin Deason.wps
[2013/05/25 08:53:05 | 000,000,294 | —- | C] () – C:\Documents and Settings\Lew\Desktop\Controlling Bahiagrass in Warm-Season Turf.url
[2013/05/23 16:48:01 | 000,000,735 | —- | C] () – C:\Documents and Settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK
[2013/05/18 13:40:47 | 000,050,925 | —- | C] () – C:\Documents and Settings\Lew\My Documents\Genuine Nissan Parts - Search by Nissan VIN, Car Model or Nissan Part Number.htm
[2013/05/18 07:01:31 | 000,062,272 | —- | C] () – C:\Documents and Settings\Lew\My Documents\GEELY SERVICE MANUALS.mht
[2013/05/18 07:00:21 | 002,712,100 | —- | C] () – C:\Documents and Settings\Lew\My Documents\Geely Manual.pdf
[2013/05/16 16:39:17 | 000,006,054 | —- | C] () – C:\Documents and Settings\Lew\My Documents\cc_20130516_163913.reg
[2013/03/05 09:55:19 | 000,000,089 | —- | C] () – C:\WINDOWS\Taxact07.ini
[2013/02/27 11:43:26 | 000,000,076 | —- | C] () – C:\WINDOWS\Taxact10.ini
[2013/02/13 10:13:53 | 000,000,105 | —- | C] () – C:\WINDOWS\Taxact06.ini
[2013/01/28 16:08:55 | 000,098,008 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2013/01/09 11:35:43 | 000,000,061 | —- | C] () – C:\WINDOWS\TaxACT12.ini
[2012/10/07 11:14:25 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2012/10/03 09:41:29 | 000,000,000 | —- | C] () – C:\Documents and Settings\Lew\PROGDA.TA
[2012/09/20 16:50:07 | 000,013,312 | —- | C] () – C:\Documents and Settings\Lew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/18 14:28:55 | 000,000,028 | —- | C] () – C:\WINDOWS\QFNOA.INI
[2012/09/18 14:28:50 | 000,000,030 | —- | C] () – C:\WINDOWS\INTURS.DAT
[2012/09/14 17:42:01 | 000,004,578 | —- | C] () – C:\Documents and Settings\Lew\Application Data\wklnhst.dat
[2012/09/14 12:18:32 | 000,000,107 | —- | C] () – C:\WINDOWS\QHI.INI
[2012/09/14 12:07:48 | 000,000,646 | —- | C] () – C:\WINDOWS\INTU_ONL.INI
[2012/09/14 11:59:56 | 000,000,832 | —- | C] () – C:\WINDOWS\WININIT.INI
[2012/09/14 11:59:52 | 000,001,545 | —- | C] () – C:\WINDOWS\QfnOnl.ini
[2012/09/14 11:59:52 | 000,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2012/09/14 11:59:50 | 000,000,252 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2012/09/14 11:59:48 | 000,008,256 | —- | C] () – C:\WINDOWS\QFNOADB.DAT
[2012/09/14 11:59:48 | 000,000,326 | —- | C] () – C:\WINDOWS\QDQICK.INI
[2012/09/14 11:59:45 | 000,000,054 | —- | C] () – C:\WINDOWS\QFP.INI
[2012/09/14 11:59:45 | 000,000,054 | —- | C] () – C:\WINDOWS\MFF.INI
[2012/09/14 08:25:34 | 000,000,000 | —- | C] () – C:\WINDOWS\NT.INI
[2012/09/12 12:02:40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/09/11 18:15:28 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2012/09/11 18:10:59 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2012/09/11 11:32:51 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2012/09/11 11:31:39 | 000,165,912 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
========== ZeroAccess Check ==========
[2012/09/18 12:43:50 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2012/06/28 17:33:05 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 05:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/05/05 10:45:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\4Team
[2012/12/08 18:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2012/12/15 15:58:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2013/05/05 10:45:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\4Team
[2012/09/16 09:27:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\DTV
[2012/12/25 11:33:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\ElevatedDiagnostics
[2012/10/01 09:30:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\FCTB000100567
[2012/11/27 21:42:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\FixCleaner
[2013/03/17 09:36:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\Spotify
[2012/09/14 17:42:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\Template
[2012/09/12 15:09:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Lew\Application Data\WinBatch
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2006/02/28 08:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2012/11/13 15:07:52 | 003,906,584 | —- | M] (Safer-Networking Ltd.) MD5=E4A0900CF535888DDD85B10040CA3E34 – C:\Program Files\Spybot - Search & Destroy 2\explorer.exe
< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 05:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/14 05:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2006/02/28 08:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe
< MD5 for: SVCHOST.EXE >
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\erdnt\cache\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\Copy of Malwarbytes\Chameleon\svchost.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\Malwarbytes\Chameleon\svchost.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\USB20FD (E)\Copy of Malwarbytes\Chameleon\svchost.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\USB20FD (E)\Malwarbytes\Chameleon\svchost.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarbytes\Chameleon\svchost.exe
[2006/02/28 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
< MD5 for: USERINIT.EXE >
[2006/02/28 08:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\erdnt\cache\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2006/02/28 08:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\Copy of Malwarbytes\Chameleon\winlogon.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\Malwarbytes\Chameleon\winlogon.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\USB20FD (E)\Copy of Malwarbytes\Chameleon\winlogon.exe
[2012/09/07 18:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Documents and Settings\Lew\Desktop\All files from Flashdrive\USB20FD (E)\Malwarbytes\Chameleon\winlogon.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarbytes\Chameleon\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /rp /s >
< %systemdrive%\$Recycle.Bin|@;true;true;true >
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
========== Base Services ==========
SRV - [2008/04/14 05:42:14 | 000,044,544 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\alg.exe – (ALG)
SRV - [2008/04/14 05:42:12 | 000,006,656 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wuauserv.dll – (wuauserv)
SRV - [2008/04/14 05:42:04 | 000,409,088 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\qmgr.dll – (BITS)
SRV - [2012/07/06 09:58:51 | 000,078,336 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\WINDOWS\system32\browser.dll – (Browser)
SRV - [2008/04/14 05:41:52 | 000,062,464 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\cryptsvc.dll – (CryptSvc)
SRV - [2008/04/14 05:41:52 | 000,126,976 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dhcpcsvc.dll – (Dhcp)
SRV - [2009/04/20 13:17:26 | 000,045,568 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dnsrslvr.dll – (Dnscache)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (Eventlog)
SRV - [2008/04/14 05:41:54 | 000,033,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\eapsvc.dll – (EapHost)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\shsvcs.dll – (FastUserSwitchingCompatibility)
SRV - [2008/04/14 05:42:10 | 000,015,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\w3ssl.dll – (HTTPFilter)
SRV - [2008/04/14 06:41:56 | 000,021,504 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\hidserv.dll – (HidServ)
SRV - [2008/04/14 05:42:24 | 000,150,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\imapi.exe – (ImapiService)
SRV - [2008/04/14 05:42:26 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (PolicyAgent)
SRV - [2008/04/14 05:41:54 | 000,023,552 | —- | M] (Microsoft Corp.) [On_Demand | Stopped] – C:\WINDOWS\system32\dmserver.dll – (dmserver)
SRV - [2008/04/14 05:42:18 | 000,224,768 | —- | M] (Microsoft Corp., Veritas Software) [On_Demand | Stopped] – C:\WINDOWS\System32\dmadmin.exe – (dmadmin)
SRV - [2008/04/14 05:42:18 | 000,005,120 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\dllhost.exe – (SwPrv)
SRV - [2008/04/14 05:42:26 | 000,013,312 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\lsass.exe – (Netlogon)
SRV - [2008/04/14 05:42:02 | 000,198,144 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\netman.dll – (Netman)
SRV - [2008/06/20 12:02:47 | 000,245,248 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\mswsock.dll – (Nla)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (PlugPlay)
SRV - [2010/08/17 09:17:06 | 000,058,880 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\spoolsv.exe – (Spooler)
SRV - [2008/04/14 05:42:26 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (ProtectedStorage)
SRV - [2008/04/14 05:42:04 | 000,088,576 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\rasauto.dll – (RasAuto)
SRV - [2008/04/14 05:42:04 | 000,186,368 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\rasmans.dll – (RasMan)
SRV - [2009/02/09 08:10:48 | 000,401,408 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\rpcss.dll – (RpcSs)
SRV - [2008/04/14 05:42:04 | 000,435,200 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\ntmssvc.dll – (NtmsSvc)
SRV - [2008/04/14 05:42:06 | 000,018,944 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\seclogon.dll – (seclogon)
SRV - [2008/04/14 05:42:26 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (SamSs)
SRV - [2008/04/14 05:42:12 | 000,080,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wscsvc.dll – (wscsvc)
SRV - [2010/08/27 01:57:43 | 000,099,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srvsvc.dll – (lanmanserver)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (ShellHWDetection)
SRV - [2008/04/14 05:42:08 | 000,171,008 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srsvc.dll – (srservice)
SRV - [2008/04/14 05:42:06 | 000,192,512 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\schedsvc.dll – (Schedule)
SRV - [2008/04/14 05:41:58 | 000,013,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lmhsvc.dll – (LmHosts)
SRV - [2008/04/14 05:42:08 | 000,249,856 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\tapisrv.dll – (TapiSrv)
SRV - [2008/04/14 05:42:08 | 000,295,424 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\termsrv.dll – (TermService)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (Themes)
SRV - [2008/04/14 05:42:40 | 000,289,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\vssvc.exe – (VSS)
SRV - [2008/04/14 05:41:52 | 000,042,496 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\audiosrv.dll – (AudioSrv)
SRV - [2008/04/14 05:41:56 | 000,331,264 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\ipnathlp.dll – (SharedAccess)
SRV - [2008/04/14 05:42:10 | 000,333,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wiaservc.dll – (stisvc)
SRV - [2008/04/14 05:42:30 | 000,078,848 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\msiexec.exe – (MSIServer)
SRV - [2008/04/14 05:42:10 | 000,144,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wbem\wmisvc.dll – (winmgmt)
No service found with a name of Wmi
SRV - [2008/04/14 05:41:54 | 000,132,096 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\dot3svc.dll – (Dot3svc)
SRV - [2008/04/14 05:42:12 | 000,483,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wzcsvc.dll – (WZCSVC)
SRV - [2009/06/10 02:14:49 | 000,132,096 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wkssvc.dll – (lanmanworkstation)
========== Drive Information ==========
Physical Drives
—————
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: WDC WD5000AAKX-001CA0
Partitions: 1
Status: OK
Status Info: 0
Partitions
—————
DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 32256
Hidden sectors: 0
< >
[2012/09/11 18:11:47 | 000,000,065 | RH– | C] () – C:\WINDOWS\Tasks\desktop.ini
[2012/09/11 18:18:10 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT
[2012/09/12 14:50:29 | 000,000,830 | —- | C] () – C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012/09/12 14:58:31 | 000,000,282 | —- | C] () – C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
[2012/09/12 14:58:32 | 000,000,274 | —- | C] () – C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
[2012/09/18 15:21:42 | 000,000,464 | —- | C] () – C:\WINDOWS\Tasks\At1.job
[2012/09/18 15:21:42 | 000,000,464 | —- | C] () – C:\WINDOWS\Tasks\At2.job
[2012/09/18 15:21:42 | 000,000,464 | —- | C] () – C:\WINDOWS\Tasks\At3.job
[2012/09/18 15:21:42 | 000,000,464 | —- | C] () – C:\WINDOWS\Tasks\At4.job
[2012/11/21 17:17:41 | 000,000,332 | —- | C] () – C:\WINDOWS\Tasks\CandyUpdater.job.bak
[2012/11/24 15:32:47 | 000,000,446 | —- | C] () – C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
[2012/11/24 15:32:47 | 000,000,616 | —- | C] () – C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
[2012/11/24 15:32:47 | 000,000,620 | —- | C] () – C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
[2012/11/27 21:42:16 | 000,000,434 | —- | C] () – C:\WINDOWS\Tasks\FixCleaner Scan.job.bak
[2013/02/27 04:10:48 | 000,000,366 | -H– | C] () – C:\WINDOWS\Tasks\MpIdleTask.job
[2013/02/27 04:10:56 | 000,000,384 | -H– | C] () – C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
< >
========== Files - Unicode (All) ==========
[2013/02/21 16:34:50 | 000,000,353 | —- | M] ()(C:\Documents and Settings\Lew\Desktop\The ??st?n?ans (1984) - YouTube.url) – C:\Documents and Settings\Lew\Desktop\The Βọstọnịąns (1984) - YouTube.url
[2013/01/28 10:01:13 | 000,000,353 | —- | C] ()(C:\Documents and Settings\Lew\Desktop\The ??st?n?ans (1984) - YouTube.url) – C:\Documents and Settings\Lew\Desktop\The Βọstọnịąns (1984) - YouTube.url
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
< End of report >
Must have missed the MBR.zip file. Will look again for it….