I tried the security check scan and when I click it to start, I got a popup similar to the one I had before but this its says "Autolt v3: Objlist.exe- Bad Image". Though fortunately when I click x twice, it goes away unlike the problem I previously had.
here is the finished security check log that popped up after the scan finished.
Results of screen317's Security Check version 0.99.78
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Spy Sweeper for MSN
Spy Sweeper Core
Malwarebytes Anti-Malware version 1.75.0.1300
Java 6 Update 30
Java version out of Date!
Adobe Flash Player 11.6.602.171
Adobe Reader 10.1.7 Adobe Reader out of Date!
Mozilla Firefox 9.0 Firefox out of Date!
Google Chrome 31.0.1650.57
Google Chrome 31.0.1650.63
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 6%
````````````````````End of Log``````````````````````
Here is the frst.txt log:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-01-2014 03
Ran by Nashih (administrator) on HOME-7992934537 on 11-01-2014 17:44:32
Running from C:\Documents and Settings\Nashih\My Documents\Downloads
Microsoft Windows XP Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
ATTENTION: If processes are not listed WMI should be repaired.
==================== Processes (Whitelisted) ===================
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [16125440 2007-02-26] (Realtek Semiconductor Corp.)
HKLM\...\Run: [SkyTel] - C:\Windows\SkyTel.EXE [2879488 2006-05-16] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Samsung PanelMgr] - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe [536576 2008-08-13] ()
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [NeroFilterCheck] - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-03-09] (Nero AG)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [421160 2011-04-27] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [ICF] - C:\Program Files\Internet Content Filter\mfp.exe [1280016 2010-03-09] (McAfee, Inc.)
HKLM\...\Run: [SpySweeper] - C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe [6156336 2011-04-05] (Webroot Software, Inc.)
HKLM\...\Run: [DWQueuedReporting] - C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [434080 2011-07-27] (Microsoft Corporation)
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] fastprox.dll ATTENTION! ====> ZeroAccess?
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [153136 2007-03-12] (Nero AG)
HKCU\...\Run: [Driver Whiz] - C:\Program Files\Driver Whiz\Driver Whiz\DriverWhiz.exe [3534704 2013-01-25] (PC Drivers Headquarters)
HKCU\...409d6c4515e9\InprocServer32: [Default-shell32] shell32.dll ATTENTION! ====> ZeroAccess/Alureon?
HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe [ 2007-03-12] (Nero AG)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...er=6&ar=msnhome
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
URLSearchHook: HKCU - (No Name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - No File
BHO: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Nashih\Application Data\Mozilla\Firefox\Profiles\unz3zo6e.default
FF user.js: detected! => C:\Documents and Settings\Nashih\Application Data\Mozilla\Firefox\Profiles\unz3zo6e.default\user.js
FF SelectedSearchEngine: Google
FF Homepage: hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&sourceid=navclient&gfns=1&q=
FF NetworkProxy: "http", "68.71.76.242"
FF NetworkProxy: "http_port", 8082
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1165635.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll ()
FF Plugin: @movenetworks.com/Quantum Media Player - C:\Documents and Settings\Nashih\Application Data\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @veetle.com/vbp;version=0.9.17 - C:\Program Files\Veetle\VLCBroadcast\npvbp.dll No File
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Documents and Settings\Nashih\Application Data\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np_gp.dll (NOS Microsystems Ltd.)
FF SearchPlugin: C:\Documents and Settings\Nashih\Application Data\Mozilla\Firefox\Profiles\unz3zo6e.default\searchplugins\web-search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\answers.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Nashih\Application Data\Mozilla\Firefox\Profiles\unz3zo6e.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-04-28]
FF Extension: iMacros for Firefox - C:\Documents and Settings\Nashih\Application Data\Mozilla\Firefox\Profiles\unz3zo6e.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2013-12-23]
FF Extension: Adobe DLM (powered by getPlus®) - C:\Documents and Settings\Nashih\Application Data\Mozilla\Firefox\Profiles\unz3zo6e.default\Extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2009-11-04]
FF Extension: Clear Form History - C:\Documents and Settings\Nashih\Application Data\Mozilla\Firefox\Profiles\unz3zo6e.default\Extensions\{1e0fd655-5aea-4b4c-a583-f76ef1e3af9c}.xpi [2013-11-20]
FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2010-01-13]
FF HKLM\...\Firefox\Extensions: [fbphotozoom@installdaddy.com] - C:\Program Files\fbphotozoom\fbphotozoom15.xpi
FF Extension: FBPhotoZoom - C:\Program Files\fbphotozoom\fbphotozoom15.xpi [2012-03-24]
FF HKCU\...\Firefox\Extensions: [moveplayer@movenetworks.com] - C:\Documents and Settings\Nashih\Application Data\Move Networks
FF Extension: No Name - C:\Documents and Settings\Nashih\Application Data\Move Networks [2009-11-07]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.300.12) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java Platform SE 6 U30) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (getPlusPlus for Adobe 16248) - C:\Program Files\Mozilla Firefox\plugins\np_gp.dll (NOS Microsystems Ltd.)
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Move Streaming Media Player) - C:\Documents and Settings\Nashih\Application Data\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave for Director) - C:\WINDOWS\system32\Adobe\Director\np32dsw_1165635.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (FBPHOTOZOOM) - C:\Documents and Settings\Nashih\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mpieaakhacmfleokhjcjnpcnmnmpfkid\3.0_0 [2014-01-07]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Nashih\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 [2014-01-07]
CHR HKLM\...\Chrome\Extension: [mpieaakhacmfleokhjcjnpcnmnmpfkid] - C:\Program Files\fbphotozoom\fbphotozoom15.crx [2012-03-24]
========================== Services (Whitelisted) =================
S4 Alerter; C:\Windows\system32\alrsvc.dll [17408 2008-04-13] ()
S3 Dot3svc; C:\Windows\System32\dot3svc.dll [132096 2008-04-13] ()
R2 fpUpdateSvc; C:\Program Files\Internet Content Filter\UpdateService.exe [235024 2010-03-09] (McAfee, Inc.)
S3 getPlusHelper; C:\Program Files\NOS\bin\getPlus_Helper.dll [51168 2009-09-23] (NOS Microsystems Ltd.)
R2 IHA_MessageCenter; C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe [350792 2013-09-13] (Verizon)
R2 JavaQuickStarterService; C:\Program Files\Java\jre6\bin\jqs.exe [153376 2011-11-10] (Sun Microsystems, Inc.)
S2 LCOM Service; C:\Documents and Settings\Nashih\My Documents\Downloads\YouTubeViewer\YTVC.exe [93696 2011-10-17] (Microsoft)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 WebrootSpySweeperService; C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe [4048256 2011-03-22] (Webroot Software, Inc. (www.webroot.com))
S3 WMPNetworkSvc; C:\Program Files\Windows Media Player\WMPNetwk.exe [913408 2006-10-18] ()
R2 WRConsumerService; C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe [1201656 2011-07-03] (Webroot Software, Inc. )
S3 Roxio UPnP Renderer 11; "C:\Program Files\Roxio Creator 2009 Special Edition\Digital Home 11\RoxioUPnPRenderer11.exe" [x]
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [x]
==================== Drivers (Whitelisted) ====================
R1 AmdK8; C:\Windows\System32\DRIVERS\AmdK8.sys [36864 2006-07-01] (Advanced Micro Devices)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [32896 2004-08-03] ()
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-11] ()
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [50704 2009-10-21] (CACE Technologies, Inc.)
R0 nvata; C:\Windows\System32\DRIVERS\nvata.sys [105472 2006-10-17] (NVIDIA Corporation)
R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [57856 2006-09-27] (NVIDIA Corporation)
R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [19968 2006-09-27] (NVIDIA Corporation)
S0 sr; C:\Windows\System32\DRIVERS\sr.sys [73472 2008-04-13] ()
R0 ssfs0bbc; C:\Windows\System32\DRIVERS\ssfs0bbc.sys [29832 2011-03-22] (Webroot Software, Inc. (www.webroot.com))
R0 sshrmd; C:\Windows\System32\DRIVERS\sshrmd.sys [23176 2011-03-22] (Webroot Software, Inc. (www.webroot.com))
R0 ssidrv; C:\Windows\System32\DRIVERS\ssidrv.sys [176776 2011-03-22] (Webroot Software, Inc. (www.webroot.com))
S3 WISTechVIDCAP; C:\Windows\System32\drivers\Xstream.sys [118400 2004-09-03] (Plextor Corp.)
S1 WS2IFSL; C:\Windows\System32\drivers\ws2ifsl.sys [12032 2004-08-03] ()
S3 WudfRd; C:\Windows\System32\DRIVERS\wudfrd.sys [82944 2006-09-28] ()
S3 XLoader; C:\Windows\System32\Drivers\XLoader.sys [13184 2004-09-03] (Plextor Corp.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 cpuz132; \??\C:\DOCUME~1\Nashih\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys [x]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S2 SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-10 14:21 - 2014-01-11 17:43 - 00000000 ____D C:\FRST
2014-01-08 16:14 - 2014-01-08 16:14 - 00000499 _____ C:\Documents and Settings\Nashih\Desktop\MBR.zip
2014-01-08 16:13 - 2014-01-08 16:13 - 00002007 _____ C:\Documents and Settings\Nashih\Desktop\aswMBR.txt
2014-01-08 16:13 - 2014-01-08 16:13 - 00000512 _____ C:\Documents and Settings\Nashih\Desktop\MBR.dat
2014-01-05 15:25 - 2014-01-05 15:25 - 00000000 ____D C:\Documents and Settings\Nashih\My Documents\New Folder (2)
2014-01-03 22:26 - 2014-01-03 22:26 - 00039823 _____ C:\Documents and Settings\Nashih\My Documents\Book11.xlsx
2013-12-31 11:04 - 2013-12-31 11:05 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-12-23 14:07 - 2013-12-23 14:08 - 00012685 _____ C:\WINDOWS\KB2898785-IE8.log
2013-12-23 14:07 - 2013-12-23 14:07 - 00005000 _____ C:\WINDOWS\KB2904266.log
2013-12-23 14:07 - 2013-12-23 14:07 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2904266$
2013-12-23 14:07 - 2013-12-23 14:07 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2898715$
2013-12-23 14:04 - 2013-12-23 14:04 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2893294$
2013-12-23 14:03 - 2013-12-23 14:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2893984$
2013-12-23 14:03 - 2013-12-23 14:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2892075$
2013-12-18 13:45 - 2013-12-23 14:07 - 00011252 _____ C:\WINDOWS\KB2898715.log
2013-12-18 13:45 - 2013-12-23 14:04 - 00010089 _____ C:\WINDOWS\KB2893294.log
2013-12-18 13:45 - 2013-12-23 14:03 - 00010788 _____ C:\WINDOWS\KB2893984.log
2013-12-18 13:45 - 2013-12-23 14:03 - 00009292 _____ C:\WINDOWS\KB2892075.log
==================== One Month Modified Files and Folders =======
2014-01-11 17:43 - 2014-01-10 14:21 - 00000000 ____D C:\FRST
2014-01-11 17:32 - 2012-06-05 00:21 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-01-11 17:23 - 2012-08-11 12:24 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-11 13:23 - 2012-08-11 12:24 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-11 12:59 - 2009-10-06 21:01 - 01646011 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-11 12:54 - 2009-10-06 21:05 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-11 12:54 - 2009-10-06 16:55 - 00000159 ____C C:\WINDOWS\wiadebug.log
2014-01-11 12:54 - 2009-10-06 16:55 - 00000049 ____C C:\WINDOWS\wiaservc.log
2014-01-10 11:32 - 2009-10-14 15:24 - 00002473 _____ C:\Documents and Settings\Nashih\Desktop\Microsoft Office Excel 2007.lnk
2014-01-10 10:38 - 2004-08-03 20:07 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2014-01-09 16:34 - 2009-10-06 21:06 - 00000178 __SHC C:\Documents and Settings\Nashih\ntuser.ini
2014-01-09 16:34 - 2009-10-06 21:06 - 00000000 ____D C:\Documents and Settings\Nashih
2014-01-09 16:34 - 2009-10-06 21:05 - 00032540 _____ C:\WINDOWS\SchedLgU.Txt
2014-01-08 16:14 - 2014-01-08 16:14 - 00000499 _____ C:\Documents and Settings\Nashih\Desktop\MBR.zip
2014-01-08 16:13 - 2014-01-08 16:13 - 00002007 _____ C:\Documents and Settings\Nashih\Desktop\aswMBR.txt
2014-01-08 16:13 - 2014-01-08 16:13 - 00000512 _____ C:\Documents and Settings\Nashih\Desktop\MBR.dat
2014-01-05 15:25 - 2014-01-05 15:25 - 00000000 ____D C:\Documents and Settings\Nashih\My Documents\New Folder (2)
2014-01-03 22:26 - 2014-01-03 22:26 - 00039823 _____ C:\Documents and Settings\Nashih\My Documents\Book11.xlsx
2014-01-01 11:33 - 2012-05-06 12:45 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-12-31 11:05 - 2013-12-31 11:04 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-12-23 14:30 - 2011-09-14 15:53 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-12-23 14:14 - 2009-10-06 16:52 - 00291680 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-23 14:08 - 2013-12-23 14:07 - 00012685 _____ C:\WINDOWS\KB2898785-IE8.log
2013-12-23 14:08 - 2009-10-06 16:54 - 00704065 ____C C:\WINDOWS\ocgen.log
2013-12-23 14:07 - 2013-12-23 14:07 - 00005000 _____ C:\WINDOWS\KB2904266.log
2013-12-23 14:07 - 2013-12-23 14:07 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2904266$
2013-12-23 14:07 - 2013-12-23 14:07 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2898715$
2013-12-23 14:07 - 2013-12-18 13:45 - 00011252 _____ C:\WINDOWS\KB2898715.log
2013-12-23 14:07 - 2013-08-26 02:04 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-12-23 14:07 - 2009-10-07 20:15 - 00055518 ____C C:\WINDOWS\system32\TZLog.log
2013-12-23 14:07 - 2009-10-07 19:15 - 00038737 ____C C:\WINDOWS\updspapi.log
2013-12-23 14:04 - 2013-12-23 14:04 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2893294$
2013-12-23 14:04 - 2013-12-18 13:45 - 00010089 _____ C:\WINDOWS\KB2893294.log
2013-12-23 14:04 - 2009-10-07 19:31 - 88123800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-12-23 14:03 - 2013-12-23 14:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2893984$
2013-12-23 14:03 - 2013-12-23 14:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2892075$
2013-12-23 14:03 - 2013-12-18 13:45 - 00010788 _____ C:\WINDOWS\KB2893984.log
2013-12-23 14:03 - 2013-12-18 13:45 - 00009292 _____ C:\WINDOWS\KB2892075.log
2013-12-18 13:29 - 2012-10-27 19:14 - 00001813 _____ C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2013-12-18 13:14 - 2012-08-06 19:46 - 00000000 ____D C:\Documents and Settings\Nashih\Desktop\Samir
ZeroAccess:
C:\RECYCLER\S-1-5-21-1214440339-1614895754-725345543-1003\$142e8fc1cdeb2027af6c9d8d24fdebc2
Some content of TEMP:
====================
C:\Documents and Settings\Nashih\Local Settings\temp\InstallNorton.exe
C:\Documents and Settings\Nashih\Local Settings\temp\install_flashplayer11x32_mssd_aaa_aih.exe
C:\Documents and Settings\Nashih\Local Settings\temp\install_flashplayer11x32_mssd_aaa_aih_1.exe
C:\Documents and Settings\Nashih\Local Settings\temp\mcinsint.exe
C:\Documents and Settings\Nashih\Local Settings\temp\SymcPCCUInstaller.exe
C:\Documents and Settings\Nashih\Local Settings\temp\VASInstallerWizard.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================