Additional scan result of Farbar Recovery Scan Tool (x86) Version:07-11-2015
Ran by [removed] (2015-11-09 20:45:30)
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
Microsoft Windows XP Home Edition Service Pack 3 (X86) (2012-09-11 22:15:23)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2052111302-861567501-725345543-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
Guest (S-1-5-21-2052111302-861567501-725345543-501 - Limited - Enabled)
HelpAssistant (S-1-5-21-2052111302-861567501-725345543-1000 - Limited - Disabled)
Lew (S-1-5-21-2052111302-861567501-725345543-1004 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Lew
SUPPORT_388945a0 (S-1-5-21-2052111302-861567501-725345543-1002 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 19 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 19.0.0.226 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Apple Application Support (HKLM\…\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AT&T; Troubleshoot & Resolve (HKLM\…\ATT-AT&T; Troubleshoot & Resolve) (Version: 8.5.0.48 - AT&T;)
Avast Free Antivirus (HKLM\…\avast) (Version: 10.4.2233 - AVAST Software)
Bing Bar (HKLM\…\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bing Maps 3D (HKLM\…\{2D87E961-577B-492B-AD54-1368680FB9A7}) (Version: 4.0.903.16005 - Microsoft Corporation)
Bing Rewards Client Installer (Version: 16.0.345.0 - Microsoft Corporation) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 3.23 - Piriform)
Centricity DICOM Viewer (HKLM\…\Centricity DICOM Viewer) (Version: 3.1.4 - GE Healthcare IT)
Chinese Traditional Fonts Support For Adobe Reader X (HKLM\…\{AC76BA86-7AD7-2448-0000-A00000000003}) (Version: 10.0.0 - Adobe Systems Incorporated)
Citrix Online Launcher (HKLM\…\{E5F6D26D-E180-4547-A865-565EAB61000C}) (Version: 1.0.362 - Citrix)
Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
DIRECTV Player (HKLM\…\{43D1B973-3D12-42ba-9E6E-56A8FEFF5250}) (Version: 8.0 - DIRECTV)
D-Link DFE-530TX+ (HKLM\…\InstallShield_{2D6A5BD9-FE4B-49CD-8D96-2C4746302A82}) (Version: - D-Link)
D-Link DFE-530TX+ (Version: - D-Link) Hidden
D-Link PCI Fast Ethernet Adapter (HKLM\…\VN_VUIns_Rhine_D-Link) (Version: - )
Enhanced Multimedia Keyboard Solution (HKLM\…\KBD) (Version: - )
ESET Online Scanner v3 (HKLM\…\ESET Online Scanner) (Version: - )
Google Chrome (HKLM\…\Google Chrome) (Version: 46.0.2490.80 - Google Inc.)
Google Earth Plug-in (HKLM\…\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.15 - Google Inc.) Hidden
HitmanPro 3.7 (HKLM\…\HitmanPro37) (Version: 3.7.10.251 - SurfRight B.V.)
HP Deskjet 3050 J610 series Basic Device Software (HKLM\…\{0564C76B-8E1F-4157-8654-B0F9F308BEE9}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 3050 J610 series Help (HKLM\…\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}) (Version: 140.0.63.63 - Hewlett Packard)
HP Update (HKLM\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Internet Explorer (Enable DEP) (HKLM\…\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb) (Version: - )
iSEEK AnswerWorks English Runtime (HKLM\…\{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}) (Version: [removed] - Vantage Linguistics)
Java 8 Update 65 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
McAfee Virtual Technician (HKLM\…\McAfee Virtual Technician) (Version: 7.7.0.366 - McAfee, Inc.)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 41.0.2 (x86 en-US) (HKLM\…\Mozilla Firefox 41.0.2 (x86 en-US)) (Version: 41.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 41.0.2.5765 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 6.0 Parser (HKLM\…\{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}) (Version: 6.10.1129.0 - Microsoft Corporation)
Nikon Message Center 2 (HKLM\…\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon)
Nikon Movie Editor (HKLM\…\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.3.0 - Nikon)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: - )
Picture Control Utility (HKLM\…\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.4.2 - Nikon)
Quicken 2012 (HKLM\…\{0A1E0BDA-5E8F-436d-8BE5-7E97C5CB899D}) (Version: 21.1.7.18 - Intuit)
QuickTime 7 (HKLM\…\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Roxio Creator DE (HKLM\…\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}) (Version: 10.1 - )
SketchUp 8 (HKLM\…\{8EB62C87-AAA6-4850-A5BC-64155884B973}) (Version: 3.0.16846 - Trimble Navigation Limited)
Spell Checker For OE 2.1 (HKLM\…\Spell Checker For OE 2.1) (Version: - )
Spotify (HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\Spotify) (Version: 1.0.13.108.gcd94e7db - Spotify AB)
Spybot - Search & Destroy (HKLM\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.0.12 - Safer-Networking Ltd.)
TaxACT 2012 - 1040 Edition (HKLM\…\TaxACT 2012 - 1040 Edition) (Version: - 2nd Story Software, Inc.)
TaxACT 2012 Georgia (HKLM\…\TaxACT 2012 Georgia) (Version: - 2nd Story Software, Inc.)
TaxACT 2013 - 1040 Edition (HKLM\…\TaxACT 2013 - 1040 Edition) (Version: - TaxACT, Inc.)
TaxACT 2013 Georgia (HKLM\…\TaxACT 2013 Georgia) (Version: - TaxACT, Inc.)
TaxACT 2014 - 1040 Edition (HKLM\…\TaxACT 2014 - 1040 Edition) (Version: 1.00 - TaxACT, Inc.)
TaxACT 2014 Georgia (HKLM\…\TaxACT 2014 Georgia) (Version: 1.01 - TaxACT, Inc.)
Trend Micro RUBotted 2.0 Beta (HKLM\…\{54D4EAF5-4C80-4878-B4AC-5AE454A02E3C}_is1) (Version: 2.0.0.1034 - Trend Micro, Inc.)
ViewNX 2 (HKLM\…\{E64C137C-D0B7-467A-B47F-460AAB30F0A3}) (Version: 2.3.0 - Nikon)
VIMGenSetup (HKLM\…\{70615FBA-A23A-489B-AA6C-858186D8D0BA}) (Version: 1.0.0 - trick77)
WD SES Driver Setup (Version: 1.0.0 - Western Digital) Hidden
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\KB892130) (Version: - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows PowerShell(TM) 1.0 (HKLM\…\KB926139-v2) (Version: 2 - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
WOT for Internet Explorer (HKLM\…\{DCAEC601-735C-41AE-B84F-D792F09FB7D1}) (Version: 12.8.2.0 - WOT Services Oy)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2052111302-861567501-725345543-1004_Classes\CLSID\{0C03DEC4-B374-44DF-9B0D-38BD942080C4}\InprocServer32 -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\COPPXP_filter.ax ()
CustomCLSID: HKU\S-1-5-21-2052111302-861567501-725345543-1004_Classes\CLSID\{7a434a49-f21e-5011-8f99-aa7578492b9c}\InprocServer32 -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll (NDS)
==================== Restore Points =========================
12-08-2015 05:46:39 System Checkpoint
12-08-2015 07:44:28 Software Distribution Service 3.0
13-08-2015 07:53:04 System Checkpoint
14-08-2015 08:14:49 System Checkpoint
15-08-2015 09:13:54 System Checkpoint
16-08-2015 10:29:52 System Checkpoint
17-08-2015 10:37:35 System Checkpoint
18-08-2015 11:07:55 System Checkpoint
19-08-2015 12:07:29 System Checkpoint
20-08-2015 12:48:25 System Checkpoint
21-08-2015 13:36:56 System Checkpoint
22-08-2015 14:25:01 System Checkpoint
23-08-2015 15:25:01 System Checkpoint
24-08-2015 16:56:42 System Checkpoint
25-08-2015 17:40:20 System Checkpoint
26-08-2015 18:28:23 System Checkpoint
27-08-2015 19:19:51 System Checkpoint
28-08-2015 19:51:36 System Checkpoint
29-08-2015 20:26:46 System Checkpoint
30-08-2015 21:26:45 System Checkpoint
31-08-2015 14:06:47 Removed HP Deskjet 3050 J610 series Basic Device Software
31-08-2015 14:08:10 Removed HP Deskjet 3050 J610 series Basic Device Software
01-09-2015 09:47:19 avast! antivirus system restore point
01-09-2015 09:48:51 Installed Windows XP Wdf01009.
01-09-2015 10:01:32 Removed HP Update.
01-09-2015 10:01:41 Installed HP Update.
02-09-2015 11:48:34 Removed HP Deskjet 3050 J610 series Basic Device Software
02-09-2015 11:49:33 Removed HP Deskjet 3050 J610 series Help
02-09-2015 11:50:13 Removed HP Deskjet 3050 J610 series Product Improvement Study
03-09-2015 13:34:37 System Checkpoint
04-09-2015 14:33:42 System Checkpoint
05-09-2015 15:33:37 System Checkpoint
06-09-2015 15:58:05 System Checkpoint
07-09-2015 16:14:53 System Checkpoint
08-09-2015 17:14:57 System Checkpoint
09-09-2015 17:52:33 System Checkpoint
09-09-2015 18:41:24 Software Distribution Service 3.0
10-09-2015 19:23:36 System Checkpoint
11-09-2015 20:03:55 System Checkpoint
12-09-2015 21:00:05 System Checkpoint
13-09-2015 21:57:37 System Checkpoint
14-09-2015 22:29:13 System Checkpoint
15-09-2015 23:25:29 System Checkpoint
17-09-2015 00:05:39 System Checkpoint
17-09-2015 11:31:34 WinThruster Thu, Sep 17, 15 12:31
18-09-2015 11:34:01 System Checkpoint
19-09-2015 11:34:15 System Checkpoint
20-09-2015 11:39:14 System Checkpoint
21-09-2015 12:38:06 System Checkpoint
22-09-2015 14:10:44 System Checkpoint
23-09-2015 14:17:52 System Checkpoint
24-09-2015 07:37:33 avast! antivirus system restore point
24-09-2015 07:38:49 Installed Windows XP Wdf01009.
25-09-2015 08:37:27 System Checkpoint
26-09-2015 09:41:36 System Checkpoint
27-09-2015 10:21:22 System Checkpoint
28-09-2015 10:50:57 System Checkpoint
29-09-2015 12:31:14 System Checkpoint
30-09-2015 14:44:09 System Checkpoint
01-10-2015 14:59:58 System Checkpoint
02-10-2015 15:57:00 System Checkpoint
03-10-2015 14:00:56 Installed "ViewNX 2"
04-10-2015 16:58:08 System Checkpoint
05-10-2015 17:37:09 System Checkpoint
06-10-2015 17:43:39 System Checkpoint
07-10-2015 18:43:41 System Checkpoint
08-10-2015 18:50:07 System Checkpoint
09-10-2015 18:52:49 System Checkpoint
10-10-2015 19:28:25 System Checkpoint
11-10-2015 19:31:04 System Checkpoint
12-10-2015 19:47:29 System Checkpoint
13-10-2015 20:19:02 System Checkpoint
14-10-2015 19:43:52 Software Distribution Service 3.0
15-10-2015 19:53:43 System Checkpoint
16-10-2015 19:54:46 System Checkpoint
17-10-2015 20:08:07 System Checkpoint
18-10-2015 20:19:38 System Checkpoint
19-10-2015 21:11:14 System Checkpoint
20-10-2015 21:18:51 System Checkpoint
21-10-2015 21:58:30 System Checkpoint
22-10-2015 22:58:31 System Checkpoint
23-10-2015 23:16:33 System Checkpoint
24-10-2015 23:30:18 System Checkpoint
26-10-2015 00:28:27 System Checkpoint
27-10-2015 00:54:20 System Checkpoint
28-10-2015 01:54:22 System Checkpoint
29-10-2015 02:54:21 System Checkpoint
30-10-2015 03:26:28 System Checkpoint
31-10-2015 04:26:28 System Checkpoint
01-11-2015 04:30:22 System Checkpoint
02-11-2015 05:30:22 System Checkpoint
03-11-2015 06:12:27 System Checkpoint
04-11-2015 03:00:14 Software Distribution Service 3.0
05-11-2015 03:44:22 System Checkpoint
05-11-2015 18:22:49 Printer Driver GIRDAC Installed
06-11-2015 18:25:16 System Checkpoint
07-11-2015 19:25:16 System Checkpoint
08-11-2015 20:25:10 System Checkpoint
09-11-2015 12:47:39 Checkpoint by HitmanPro
09-11-2015 12:48:37 Checkpoint by HitmanPro
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2014-04-20 08:25 - 2014-03-05 18:24 - 00566098 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 m.fr.a2dfp.net
127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 abcstats.com
127.0.0.1 a.abv.bg
127.0.0.1 adserver.abv.bg
127.0.0.1 adv.abv.bg
127.0.0.1 bimg.abv.bg
127.0.0.1 ca.abv.bg
127.0.0.1 www2.a-counter.kiev.ua
127.0.0.1 track.acclaimnetwork.com
127.0.0.1 accuserveadsystem.com
127.0.0.1 www.accuserveadsystem.com
127.0.0.1 achmedia.com
127.0.0.1 csh.actiondesk.com
127.0.0.1 www.activemeter.com #[Tracking.Cookie]
127.0.0.1 ads.activepower.net
127.0.0.1 app.activetrail.com
127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
127.0.0.1 cms.ad2click.nl
127.0.0.1 ad2games.com
127.0.0.1 ads.ad2games.com
127.0.0.1 content.ad20.net
127.0.0.1 core.ad20.net
127.0.0.1 banner.ad.nu
127.0.0.1 cl21.v4.adaction.se
127.0.0.1 adadvisor.net
127.0.0.1 tag1.adaptiveads.com
127.0.0.1 www.adbanner.ro
There are 12420 more lines.
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job.bak => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\CandyUpdater.job.bak => C:\Documents and Settings\Lew\Local Settings\Application Data\ArcadeCandy\candyUpdater.exe
Task: C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job.bak => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
Task: C:\WINDOWS\Tasks\FixCleaner Scan.job.bak => C:\Program Files\FixCleaner\FixCleaner.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{90A41A15-AAF1-4707-8558-2318913D9F39}.job => C:\WINDOWS\system32\msfeedssync.exe
==================== Loaded Modules (Whitelisted) ==============
2015-03-19 09:43 - 2015-09-24 07:37 - 00103376 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-03-19 09:43 - 2015-09-24 07:37 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-11-09 09:17 - 2015-11-09 09:17 - 02990592 _____ () C:\Program Files\AVAST Software\Avast\defs\15110901\algo.dll
2015-11-09 16:51 - 2015-11-09 16:51 - 02990592 _____ () C:\Program Files\AVAST Software\Avast\defs\15110902\algo.dll
2012-11-24 14:32 - 2012-11-13 14:06 - 00108960 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2012-11-24 14:32 - 2012-11-13 14:06 - 00416160 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
2012-11-24 14:32 - 2012-11-13 14:06 - 00158624 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2012-11-24 14:32 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll
2012-11-24 14:32 - 2012-11-13 14:06 - 00528288 _____ () C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl
2014-01-07 06:40 - 2015-09-24 07:37 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com
There are 7849 more sites.
IE trusted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\whatthetech.com -> hxxps://www.whatthetech.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\123simsen.com -> www.123simsen.com
There are 7848 more sites.
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-2052111302-861567501-725345543-500\…\123simsen.com -> www.123simsen.com
There are 7849 more sites.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2052111302-861567501-725345543-1004\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-2052111302-861567501-725345543-500\Control Panel\Desktop\\Wallpaper -> (None)
DNS Servers: 192.168.1.254
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: RTHDCPL => RTHDCPL.EXE
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Lew\Application Data\Spotify\spotify.exe] => Enabled:Spotify
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot-S&D; 2 Tray Icon
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\dpvsetup.exe] => Enabled:Microsoft DirectPlay Voice Test
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe] => Enabled:WebKit
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Lew\Local Settings\temp\2eat48h\CloudBackupSetup] => Enabled:CloudBackupSetup (in)
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:Google Chrome
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\rundll32.exe] => Enabled:Run a DLL as an App
StandardProfile\AuthorizedApplications: [C:\Spotify.exe] => Enabled:Spotify
StandardProfile\AuthorizedApplications: [C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe] => :LocalSubNet:Enabled:HP Device Setup
StandardProfile\AuthorizedApplications: [C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe] => :LocalSubNet:Enabled:HP Network Communicator
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)
DomainProfile\GloballyOpenPorts: [139:TCP] => Enabled:@xpsp2res.dll,-22004
DomainProfile\GloballyOpenPorts: [445:TCP] => Enabled:@xpsp2res.dll,-22005
DomainProfile\GloballyOpenPorts: [137:UDP] => Enabled:@xpsp2res.dll,-22001
DomainProfile\GloballyOpenPorts: [138:UDP] => Enabled:@xpsp2res.dll,-22002
StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22007
StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22008
StandardProfile\GloballyOpenPorts: [139:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22004
StandardProfile\GloballyOpenPorts: [445:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22005
StandardProfile\GloballyOpenPorts: [137:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22001
StandardProfile\GloballyOpenPorts: [138:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22002
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: LSI PCI-SV92PP Soft Modem
Description: LSI PCI-SV92PP Soft Modem
Class Guid: {4D36E96D-E325-11CE-BFC1-08002BE10318}
Manufacturer: LSI
Service: Modem
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: NVIDIA nForce Networking Controller
Description: NVIDIA nForce Networking Controller
Class Guid: {4D36E972-E325-11CE-BFC1-08002BE10318}
Manufacturer: NVIDIA
Service: NVENETFD
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/09/2015 12:18:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application mbam.exe, version 1.0.1.711, faulting module msvcr100.dll, version 10.0.40219.325, fault address 0x0008d6fd.
Processing media-specific event for [mbam.exe!ws!]
Error: (11/09/2015 11:22:44 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 41.0.2.5765, faulting module mozglue.dll, version 41.0.2.5765, fault address 0x0000ec91.
Processing media-specific event for [plugin-container.exe!ws!]
Error: (11/06/2015 08:12:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 41.0.2.5765, faulting module mozglue.dll, version 41.0.2.5765, fault address 0x0000ec91.
Processing media-specific event for [plugin-container.exe!ws!]
Error: (11/02/2015 08:21:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 41.0.2.5765, faulting module mozglue.dll, version 41.0.2.5765, fault address 0x0000ec91.
Processing media-specific event for [plugin-container.exe!ws!]
Error: (10/31/2015 09:20:10 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module wot.dll, version 12.8.2.0, fault address 0x00017fe0.
Processing media-specific event for [iexplore.exe!ws!]
Error: (10/25/2015 10:22:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (10/25/2015 10:22:01 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (10/25/2015 10:22:00 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (10/25/2015 10:06:45 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (10/24/2015 09:08:35 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module wot.dll, version 12.8.2.0, fault address 0x00017fe0.
Processing media-specific event for [iexplore.exe!ws!]
System errors:
=============
Error: (11/09/2015 12:51:00 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The HitmanPro 3.7 Crusader (Boot) service terminated with service-specific error 0 (0x0).
Error: (11/09/2015 12:50:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D; 2 Security Center Service service failed to start due to the following error:
%%1053
Error: (11/09/2015 12:50:55 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D; 2 Security Center Service service to connect.
Error: (11/09/2015 12:50:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Trend Micro RUBotted Service service failed to start due to the following error:
%%1053
Error: (11/09/2015 12:50:55 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the Trend Micro RUBotted Service service to connect.
Error: (11/09/2015 12:33:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D; 2 Security Center Service service failed to start due to the following error:
%%1053
Error: (11/09/2015 12:33:56 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the Spybot-S&D; 2 Security Center Service service to connect.
Error: (11/09/2015 12:33:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Trend Micro RUBotted Service service failed to start due to the following error:
%%1053
Error: (11/09/2015 12:33:56 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the Trend Micro RUBotted Service service to connect.
Error: (11/09/2015 12:24:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D; 2 Security Center Service service failed to start due to the following error:
%%1053
==================== Memory info ===========================
Processor: AMD Athlon™ 64 Processor 3800+
Percentage of memory in use: 59%
Total physical RAM: 958.48 MB
Available physical RAM: 388.58 MB
Total Virtual: 2310.54 MB
Available Virtual: 1744.32 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:465.75 GB) (Free:424.41 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: (Desktop Favorite) (CDROM) (Total:0.2 GB) (Free:0 GB) CDFS
Drive i: (My Passport) (Fixed) (Total:465.73 GB) (Free:352.99 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: 8F59DC31)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 465.7 GB) (Disk ID: 0004A183)
Partition 1: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-11-2015
Ran by [removed] (administrator) on LEW-0CCC0E88CE3 (09-11-2015 20:44:25)
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
[removed]
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Hewlett-Packard Company) C:\HP\KBD\kbd.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Alcatel-Lucent) C:\Program Files\ATT\8.5.0.48\ma\bin\pcTrayApp.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Spotify Ltd) C:\Documents and Settings\Lew\Application Data\Spotify\SpotifyWebHelper.exe
(Microsoft® Corporation) C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Outlook Express\msimn.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [KBD] => C:\HP\KBD\KBD.EXE [61440 2005-02-02] (Hewlett-Packard Company)
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-06] (AVAST Software)
HKLM\…\Run: [ATT_McciTrayApp] => C:\Program Files\ATT\8.5.0.48\ma\bin\pcTrayApp.exe [2044416 2015-01-22] (Alcatel-Lucent)
HKLM\…\Run: [Nikon Message Center 2] => C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\…\Run: [TkBellExe] => C:\program files\real\realplayer\update\realsched.exe [295512 2013-09-07] (RealNetworks, Inc.)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKLM\…\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-2052111302-861567501-725345543-1004\…\Run: [Spotify Web Helper] => C:\Documents and Settings\Lew\Application Data\Spotify\SpotifyWebHelper.exe [2023480 2015-07-27] (Spotify Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-09-24] (AVAST Software)
Startup: C:\Documents and Settings\Lew\Start Menu\Programs\Startup\WKCALREM.LNK [2013-07-09]
ShortcutTarget: WKCALREM.LNK -> C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
BootExecute: autocheck autochk * bootdelete
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{2E5072BA-3DCD-43F1-A347-7B3E0450AF88}: [DhcpNameServer] 192.168.1.254
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
URLSearchHook: [S-1-5-21-2052111302-861567501-725345543-500] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2052111302-861567501-725345543-1004 -> {1FF59F01-1B18-4F35-8C03-65E1FEE35225} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei;=utf-8&ilc;=12&type;=531140&p;={searchTerms}
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-10-23] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-09-01] (AVAST Software)
BHO: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files\WOT\WOT.dll [2012-08-02] ()
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-23] (Oracle Corporation)
Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll [2012-08-02] ()
Toolbar: HKU\S-1-5-21-2052111302-861567501-725345543-1004 -> WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll [2012-08-02] ()
Toolbar: HKU\S-1-5-21-2052111302-861567501-725345543-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-06-08] (Microsoft Corporation)
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll [2012-08-02] ()
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Lew\Application Data\Mozilla\Firefox\Profiles\7an7alhq.default-1439150236187
FF DefaultSearchEngine: Yahoo!
FF DefaultSearchEngine.US: Yahoo!
FF SelectedSearchEngine: Yahoo!
FF Homepage: hxxps://search.yahoo.com/?type=531140&fr;=spigot-yhp-ff
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-17] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-23] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-23] (Oracle Corporation)
FF Plugin: @mcafee.com/MVT -> C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll [2015-08-18] (McAfee, Inc.)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files\Virtual Earth 3D\ [] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @Motive.com/NpMotive,version=1.1 -> C:\Program Files\ATT\8.5.0.48\ma\bin\npMotive.dll [2015-01-22] (Alcatel-Lucent)
FF Plugin: @Motive.com/npMotiveRequest,version=1.1 -> C:\Program Files\Common Files\Motive\npMotiveRequest.dll [2014-08-27] (Alcatel-Lucent)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll [2013-09-07] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll [2013-09-07] (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2052111302-861567501-725345543-1004: @citrixonline.com/appdetectorplugin -> C:\Documents and Settings\Lew\Local Settings\Application Data\Citrix\Plugins\104\npappdetector.dll [2015-11-02] (Citrix Online)
FF Plugin HKU\S-1-5-21-2052111302-861567501-725345543-1004: @nds.com/PCShowPlugin -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPCShowPlugin.dll [No File]
FF Plugin HKU\S-1-5-21-2052111302-861567501-725345543-1004: @nds.com/PlayerPlugin -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll [2012-10-15] (NDS)
FF Plugin HKU\S-1-5-21-2052111302-861567501-725345543-1004: NDS.com/PlayerPlugin -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll [2012-10-15] (NDS)
FF Extension: Motive Extension - C:\Program Files\Mozilla Firefox\browser\extensions\[removed] [2015-09-24] [not signed]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-09-19] [not signed]
FF HKLM\…\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-07] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-09-24] [not signed]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Profile: C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (RealDownloader) - C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-08-20]
CHR Extension: (Motive Extension) - C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kofilaoejfjbjfopdnckahcidedndnln [2015-11-09]
CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\Lew\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-09]
CHR HKLM\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-19]
CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\…\Chrome\Extension: [kofilaoejfjbjfopdnckahcidedndnln] - C:\Program Files\Common Files\Motive\extensions\MotiveRequest.crx [2015-09-24]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation)
S4 AT&T; Troubleshoot & Resolve; C:\Program Files\ATT\8.5.0.48\ma\bin\MAHostService.exe [321024 2015-01-22] (Alcatel-Lucent) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-24] (AVAST Software)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [106248 2015-11-09] (SurfRight B.V.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
S4 pcCMService; C:\Program Files\Common Files\Motive\pcCMService.exe [369152 2014-09-10] (Alcatel-Lucent) [File not signed]
S4 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S2 RUBotSrv; C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe [443416 2013-07-25] (Trend Micro Inc.)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
S3 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-09-24] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [76000 2015-09-24] (AVAST Software)
R1 AswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-09-24] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-09-24] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [794952 2015-11-06] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [435464 2015-11-06] (AVAST Software)
S3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [157888 2015-09-24] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-09-24] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208664 2015-09-24] (AVAST Software)
R3 FETNDISB; C:\WINDOWS\System32\DRIVERS\dlkfet5b.sys [43008 2007-07-13] (D-Link )
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [114904 2015-11-09] (Malwarebytes Corporation)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [34176 2006-03-03] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [13056 2006-03-03] (NVIDIA Corporation)
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-09 20:43 - 2015-11-09 20:44 - 00000000 ____D C:\FRST
2015-11-09 12:48 - 2015-11-09 12:48 - 00012956 _____ C:\WINDOWS\system32\.crusader
2015-11-09 12:43 - 2015-11-09 12:43 - 00001610 _____ C:\Documents and Settings\All Users\Desktop\HitmanPro.lnk
2015-11-09 12:43 - 2015-11-09 12:43 - 00000000 ____D C:\Program Files\HitmanPro
2015-11-09 12:43 - 2015-11-09 12:43 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\HitmanPro
2015-11-09 12:42 - 2015-11-09 12:49 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HitmanPro
2015-11-09 12:28 - 2015-11-09 12:39 - 00002352 _____ C:\WINDOWS\KB842773.log
2015-11-09 12:21 - 2015-11-09 12:22 - 00002669 _____ C:\AdwCleaner[S9].txt
2015-11-09 12:21 - 2015-11-09 12:21 - 00002551 _____ C:\AdwCleaner[R15].txt
2015-11-09 12:20 - 2015-11-09 12:20 - 00002490 _____ C:\AdwCleaner[R14].txt
2015-11-06 08:48 - 2015-11-06 08:48 - 00000680 _____ C:\Documents and Settings\Lew\My Documents\cc_20151106_084808.reg
2015-11-05 11:11 - 2015-11-05 11:11 - 00001082 _____ C:\Documents and Settings\Lew\My Documents\cc_20151105_111147.reg
2015-11-02 22:45 - 2015-11-02 22:45 - 00000000 ____D C:\Program Files\McAfee
2015-11-02 22:45 - 2015-11-02 22:45 - 00000000 ____D C:\Documents and Settings\Lew\Application Data\McAfee
2015-11-02 22:45 - 2015-11-02 22:45 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
2015-11-02 21:14 - 2015-11-02 21:14 - 00004526 _____ C:\Documents and Settings\Lew\My Documents\cc_20151102_211453.reg
2015-11-02 21:01 - 2015-11-02 21:01 - 00000000 ____D C:\Documents and Settings\Lew\Local Settings\Application Data\Citrix
2015-10-29 20:20 - 2015-10-29 20:20 - 00002487 _____ C:\AdwCleaner[S8].txt
2015-10-29 20:20 - 2015-10-29 20:20 - 00002369 _____ C:\AdwCleaner[R13].txt
2015-10-23 08:27 - 2015-10-23 08:27 - 00002816 _____ C:\AdwCleaner[S7].txt
2015-10-23 08:26 - 2015-10-23 08:26 - 00002690 _____ C:\AdwCleaner[R12].txt
2015-10-23 08:10 - 2015-10-23 08:10 - 00000000 ____D C:\Program Files\Common Files\Java
2015-10-18 09:21 - 2015-10-18 09:21 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Trend Micro
2015-10-16 08:49 - 2015-10-16 08:52 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-10-15 11:40 - 2015-10-15 11:45 - 11534454 _____ C:\Documents and Settings\Lew\My Documents\Boat Lift.bmp
2015-10-13 20:27 - 2015-10-17 02:27 - 03996360 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-09 20:45 - 2014-03-26 21:48 - 00000000 ____D C:\Documents and Settings\Lew\Local Settings\temp
2015-11-09 20:38 - 2013-09-13 07:15 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2015-11-09 20:31 - 2015-09-19 10:17 - 00000282 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
2015-11-09 20:31 - 2015-09-19 10:17 - 00000274 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
2015-11-09 20:31 - 2014-03-23 11:07 - 00000218 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-11-09 20:31 - 2013-07-10 09:57 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-09 20:31 - 2012-09-12 13:58 - 00000274 _____ C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-861567501-725345543-1004.job
2015-11-09 20:31 - 2012-09-11 19:49 - 00043531 _____ C:\WINDOWS\system32\nvapps.xml
2015-11-09 20:31 - 2006-02-28 07:00 - 00012598 _____ C:\WINDOWS\system32\wpa.dbl
2015-11-09 20:27 - 2012-09-12 13:50 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-11-09 19:57 - 2013-07-10 09:57 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-09 19:10 - 2012-09-11 17:18 - 00000178 ___SH C:\Documents and Settings\Lew\ntuser.ini
2015-11-09 16:27 - 2015-07-29 19:38 - 00032534 _____ C:\WINDOWS\SchedLgU.Txt
2015-11-09 13:09 - 2014-05-01 10:43 - 01410380 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-09 12:50 - 2012-09-11 17:18 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-09 12:50 - 2012-09-11 10:34 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-11-09 12:50 - 2012-09-11 10:34 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-11-09 12:49 - 2012-11-24 14:32 - 00524288 _____ C:\WINDOWS\system32\config\SpybotSD.evt
2015-11-09 11:31 - 2014-06-25 13:18 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-09 10:55 - 2014-01-08 08:41 - 00000418 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{90A41A15-AAF1-4707-8558-2318913D9F39}.job
2015-11-09 10:41 - 2012-11-24 14:32 - 00000446 _____ C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
2015-11-09 10:41 - 2012-09-11 17:18 - 00000000 ____D C:\Documents and Settings\Lew
2015-11-08 15:00 - 2014-03-23 11:07 - 00000212 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2015-11-07 13:49 - 2012-09-12 13:58 - 00000282 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-861567501-725345543-1004.job
2015-11-06 15:06 - 2012-09-14 16:42 - 00015114 _____ C:\Documents and Settings\Lew\Application Data\wklnhst.dat
2015-11-06 14:47 - 2013-07-10 09:57 - 00794952 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2015-11-06 14:47 - 2013-07-10 09:57 - 00435464 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2015-11-05 18:22 - 2012-09-11 17:18 - 00000000 __SHD C:\Documents and Settings\LocalService
2015-11-05 18:22 - 2012-09-11 17:16 - 00000000 __SHD C:\Documents and Settings\NetworkService
2015-11-05 11:15 - 2014-11-19 13:34 - 00000675 _____ C:\Documents and Settings\Lew\Desktop\Grocery List.txt
2015-11-04 00:30 - 2012-11-24 14:32 - 00000616 _____ C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2015-11-03 09:31 - 2012-09-11 17:13 - 00023392 _____ C:\WINDOWS\system32\nscompat.tlb
2015-11-03 09:31 - 2012-09-11 17:13 - 00016832 _____ C:\WINDOWS\system32\amcompat.tlb
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\WindowsShell.Manifest
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\system32\wuaucpl.cpl.manifest
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\system32\sapi.cpl.manifest
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\system32\nwc.cpl.manifest
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\system32\ncpa.cpl.manifest
2015-11-03 09:31 - 2012-09-11 17:12 - 00000749 ___RH C:\WINDOWS\system32\cdplayer.exe.manifest
2015-11-02 22:45 - 2012-09-12 13:15 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\McAfee
2015-11-02 20:37 - 2015-06-13 14:30 - 00000000 ____D C:\AdwCleaner
2015-11-02 19:40 - 2012-09-12 11:19 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2603381$
2015-11-02 08:26 - 2012-09-11 10:32 - 00603070 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-02 07:44 - 2012-09-24 10:40 - 00000235 _____ C:\Documents and Settings\Lew\Desktop\The Brunswick News - Home Page.url
2015-10-31 08:50 - 2014-08-27 06:53 - 00000000 ____D C:\Documents and Settings\Lew\Desktop\1938 Ford Woody Mecum Auctions_files
2015-10-30 08:22 - 2014-02-15 09:54 - 00000352 _____ C:\Documents and Settings\Lew\Desktop\7-Day Forecast for Hampton Point.url
2015-10-28 10:30 - 2013-12-08 12:20 - 00000272 _____ C:\Documents and Settings\Lew\Desktop\Lost Atlanta The Way We Were.url
2015-10-27 17:31 - 2012-11-16 16:07 - 00000241 _____ C:\Documents and Settings\Lew\Desktop\craigslist Brunswick, GA.url
2015-10-26 13:57 - 2012-09-11 10:30 - 00000360 ___SH C:\boot.ini
2015-10-25 09:07 - 2013-09-04 16:08 - 00000000 ____D C:\Documents and Settings\Lew\My Documents\Capital One Statements
2015-10-25 09:02 - 2013-07-25 10:02 - 00000000 ____D C:\Documents and Settings\Lew\My Documents\GA Power Bills
2015-10-25 08:57 - 2013-07-04 08:52 - 00000000 ____D C:\Documents and Settings\Lew\My Documents\JWSC Statements
2015-10-23 08:39 - 2013-01-25 12:27 - 00001621 _____ C:\Documents and Settings\Lew\Desktop\Central Modern High-Spec En-suite in London.url
2015-10-23 08:36 - 2012-12-06 09:35 - 00000773 _____ C:\Documents and Settings\Lew\Desktop\Travel News You Can Use.url
2015-10-23 08:20 - 2015-03-03 19:18 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Java
2015-10-23 08:20 - 2014-08-08 14:41 - 00000000 ____D C:\Program Files\Java
2015-10-23 08:09 - 2015-09-04 17:07 - 00000000 ____D C:\Documents and Settings\Lew\.oracle_jre_usage
2015-10-23 08:09 - 2015-03-03 19:18 - 00146432 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2015-10-23 08:09 - 2015-03-03 19:18 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2015-10-19 08:39 - 2013-12-27 17:04 - 00000253 _____ C:\Documents and Settings\Lew\Desktop\Bible Study Tools Online - Verses, Commentaries, Concordances, Verses, Parallel Versions.url
2015-10-18 14:08 - 2014-02-21 13:45 - 00000752 _____ C:\Documents and Settings\Lew\Desktop\Invisible Mask - Clear Bra Paint Protection,.url
2015-10-18 14:04 - 2015-03-17 18:13 - 00000724 _____ C:\Documents and Settings\Lew\Desktop\Mozilla Firefox.lnk
2015-10-18 10:34 - 2014-08-25 18:43 - 00000000 ____D C:\Documents and Settings\Lew\Local Settings\Application Data\Adobe
2015-10-18 10:34 - 2012-09-12 13:50 - 00780488 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-10-18 10:34 - 2012-09-12 13:50 - 00142536 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-10-18 09:32 - 2012-09-12 13:08 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB970430$
2015-10-18 08:55 - 2015-08-28 08:29 - 00000000 ____D C:\Program Files\ATT
2015-10-17 11:16 - 2015-03-17 18:13 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-10-17 09:18 - 2015-01-06 17:21 - 00000000 ____D C:\Documents and Settings\Lew\Desktop\Carol
2015-10-14 19:53 - 2013-08-08 02:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-10-14 19:44 - 2012-09-12 11:21 - 141105520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories =======
2015-10-03 14:06 - 2015-10-03 14:06 - 0000268 ___RH () C:\Documents and Settings\Lew\Application Data\Hybrid Basic
2015-10-03 14:19 - 2015-10-03 14:19 - 0000268 ___RH () C:\Documents and Settings\Lew\Application Data\Hybrid Chords
2015-10-03 14:06 - 2015-10-03 14:06 - 0000268 ___RH () C:\Documents and Settings\Lew\Application Data\Hybrid Morph
2014-03-25 10:11 - 2014-03-25 10:11 - 0000041 _____ () C:\Documents and Settings\Lew\Application Data\WB.CFG
2012-09-14 16:42 - 2015-11-06 15:06 - 0015114 _____ () C:\Documents and Settings\Lew\Application Data\wklnhst.dat
2012-09-20 15:50 - 2015-01-06 21:17 - 0133120 _____ () C:\Documents and Settings\Lew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================