Hello,
I recently had another thread but I got caught up in some things recently and have not been able to get on my computer, therefore my thread was closed. I apologize for this, and I am available now and will be keeping my eyes open for a reply. My last helper was Marie Curie, but it doesn't really matter who helps me. I did not follow the instructions i was given on my last thread as i did not know if i would have the same helper. Here is a copy of my last thread:
Hello,
Last Friday my computer was infected with a file encryption virus asking for a ransom to restore my files. I have done extensive research and cant find much on what to do so this is my last resort for some personalized help. The virus provided me with some information about what it is but I will not post that unless requested. I recently tried a system restore and all attempts have failed no matter how far back I go. Any help will be much appreciated, thank you.
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-05-25 15:56:02
—————————–
15:56:02.859 OS Version: Windows 5.1.2600 Service Pack 3
15:56:02.859 Number of processors: 2 586 0xF0D
15:56:02.859 ComputerName: GRANTMARISLEE UserName: Gamer
15:56:03.718 Initialize success
15:56:03.718 VM: initialized successfully
15:56:03.718 VM: Intel CPU BiosDisabled
15:57:13.296 AVAST engine defs: 16052501
15:57:28.765 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
15:57:28.765 Disk 0 Vendor: ST500LM021-1KJ152 0002LIM1 Size: 476940MB BusType: 3
15:57:28.968 Disk 0 MBR read successfully
15:57:28.968 Disk 0 MBR scan
15:57:28.984 Disk 0 Windows XP default MBR code
15:57:28.984 Disk 0 Partition 1 00 DE Dell Utility Dell 8.1 47 MB offset 63
15:57:29.000 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 473815 MB offset 96390
15:57:29.015 Disk 0 default boot code
15:57:29.031 Disk 0 Partition - 00 0F Extended LBA 3074 MB offset 970470585
15:57:29.062 Disk 0 Partition 3 00 DD MSDOS5.0 3074 MB offset 970470648
15:57:29.078 Disk 0 scanning sectors +976768065
15:57:29.109 Disk 0 scanning C:\WINDOWS\system32\drivers
15:57:44.390 Service scanning
15:57:59.468 Modules scanning
15:57:59.500 Disk 0 trace - called modules:
15:57:59.515 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
15:57:59.531 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a797ab8]
15:57:59.531 3 CLASSPNP.SYS[b8108fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x8a892b00]
15:58:00.343 AVAST engine scan C:\WINDOWS
15:58:03.718 AVAST engine scan C:\WINDOWS\system32
16:00:59.078 AVAST engine scan C:\WINDOWS\system32\drivers
16:01:24.953 AVAST engine scan C:\Documents and Settings\Gamer
16:03:02.109 AVAST engine scan C:\Documents and Settings\All Users
16:05:24.953 Disk 0 statistics 1684394/0/0 @ 2.49 MB/s
16:05:24.953 Scan finished successfully
16:06:20.421 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Gamer\Desktop\MBR.dat"
16:06:20.421 The log file has been saved successfully to "C:\Documents and Settings\Gamer\Desktop\aswMBR.txt"
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:25-05-2016
Ran by [removed] (administrator) on GRANTMARISLEE (25-05-2016 16:09:44)
Running from C:\Documents and Settings\[removed]\Desktop
[removed]
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo…very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
() C:\WINDOWS\system32\WLTRYSVC.EXE
(Dell Inc.) C:\WINDOWS\system32\BCMWLTRY.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\cisvc.exe
(PC Tools) C:\Program Files\PC Tools Firewall Plus\FWService.exe
(Microsoft Corporation) C:\WINDOWS\system32\snmp.exe
(Microsoft Corporation) C:\WINDOWS\system32\cidaemon.exe
(CyberLink Corp.) C:\Program Files\Dell\MediaDirect\PCMService.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Dell Inc.) C:\WINDOWS\system32\WLTRAY.EXE
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(PC Tools) C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
(SigmaTel, Inc.) C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
(Knowles Acoustics) C:\WINDOWS\system32\KADxMain.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Avanquest Software ) C:\Program Files\Digital Line Detect\DLG.exe
(Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [PCMService] => C:\Program Files\Dell\MediaDirect\PCMService.exe [189736 2007-11-01] (CyberLink Corp.)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1024000 2007-10-26] (Synaptics, Inc.)
HKLM\…\Run: [Broadcom Wireless Manager UI] => C:\WINDOWS\system32\WLTRAY.exe [2289664 2008-11-26] (Dell Inc.)
HKLM\…\Run: [Dell QuickSet] => C:\Program Files\Dell\QuickSet\Quickset.exe [1228800 2007-07-20] (Dell Inc.)
HKLM\…\Run: [EPSON Stylus CX5800F Series] => C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIALA.EXE [98304 2005-05-10] (SEIKO EPSON CORPORATION)
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7400576 2016-05-20] (AVAST Software)
HKLM\…\Run: [00PCTFW] => C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe [2672600 2011-04-07] (PC Tools)
HKLM\…\Run: [SigmatelSysTrayApp] => C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [405504 2007-05-10] (SigmaTel, Inc.)
HKLM\…\Run: [KADxMain] => C:\WINDOWS\system32\KADxMain.exe [282624 2006-11-02] (Knowles Acoustics)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM\…\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NVHotkey] => rundll32.exe nvHotkey.dll,Start
HKLM\…\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1753192 2010-11-04] ()
HKU\S-1-5-21-1482476501-1644491937-725345543-1006\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssstars.scr [14336 2008-04-14] (Microsoft Corporation)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-05-20] (AVAST Software)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk [2015-08-29]
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk [2015-08-29]
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
Startup: C:\Documents and Settings\Grant Lee\Start Menu\Programs\Startup\AEFD8E935DCAB.lnk [1899-12-30]
ShortcutTarget: AEFD8E935DCAB.lnk -> C:\Documents and Settings\All Users\Application Data\AEFD8E935DCA.bmp ()
Startup: C:\Documents and Settings\Grant Lee\Start Menu\Programs\Startup\AEFD8E935DCAH.lnk [1899-12-30]
ShortcutTarget: AEFD8E935DCAH.lnk -> C:\Documents and Settings\All Users\Application Data\AEFD8E935DCA.html ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{5703616A-3B9A-447F-9EEE-55F0F241014A}: [DhcpNameServer] [removed] [removed]
Internet Explorer:
==================
BHO: Spybot-S&D; IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26] (Safer Networking Limited)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-05-20] (AVAST Software)
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} hxxp://www.pcpitstop.com/nirvana/controls/pcmatic.cab
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Gamer\Application Data\Mozilla\Firefox\Profiles\dpo71ux4.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-12] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-05-20]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-08-29] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-05-20]
Chrome:
=======
CHR Profile: C:\Documents and Settings\Gamer\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Documents and Settings\Gamer\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-30]
CHR Extension: (Google Docs) - C:\Documents and Settings\Gamer\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-30]
CHR Extension: (Google Drive) - C:\Documents and Settings\Gamer\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-23]
CHR Extension: (YouTube) - C:\Documents and Settings\Gamer\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-23]
CHR Extension: (Google Search) - C:\Documents and Settings\Gamer\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-23]
CHR Extension: (Google Sheets) - C:\Documents and Settings\Gamer\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-30]
CHR Extension: (Google Docs Offline) - C:\Documents and Settings\Gamer\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-20]
CHR Extension: (Avast Online Security) - C:\Documents and Settings\Gamer\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-23]
CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\Gamer\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-30]
CHR Extension: (Gmail) - C:\Documents and Settings\Gamer\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-30]
CHR HKLM\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-05-20]
CHR HKLM\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-05-20]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-05-20] (AVAST Software)
S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 PCToolsFirewallPlus; C:\Program Files\PC Tools Firewall Plus\FWService.exe [286000 2011-01-24] (PC Tools)
R2 wltrysvc; C:\WINDOWS\System32\bcmwltry.exe [2039808 2008-11-26] (Dell Inc.) [File not signed]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 APPDRV; C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS [16128 2005-08-12] (Dell Inc) [File not signed]
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [32792 2016-05-20] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [35096 2016-05-20] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [91168 2016-05-20] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [64272 2016-05-20] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [58776 2016-05-20] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [815792 2016-05-20] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [449640 2016-05-20] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [187208 2016-05-20] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [67216 2016-05-20] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [221368 2016-05-20] (AVAST Software)
R3 BCM43XX; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [1391104 2008-11-26] (Broadcom Corporation)
S0 cercsr6; C:\WINDOWS\system32\Drivers\cercsr6.sys [39904 2004-12-13] (Adaptec, Inc.) [File not signed]
R3 DXEC02; C:\WINDOWS\System32\drivers\dxec02.sys [103168 2006-11-02] (Knowles Acoustics) [File not signed]
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2005-10-22] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2005-10-22] (HP)
R3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [211200 2007-08-02] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [989952 2007-08-02] (Conexant Systems, Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [24448 2016-03-10] (Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [170200 2016-05-20] (Malwarebytes)
R2 PCTAppEvent; C:\WINDOWS\system32\drivers\PCTAppEvent.sys [160576 2011-03-02] (PC Tools)
R3 PCTFW-PacketFilter; C:\WINDOWS\system32\drivers\pctNdis-PacketFilter.sys [89472 2011-01-12] (PC Tools)
R1 pctgntdi; C:\WINDOWS\system32\drivers\pctgntdi.sys [251560 2011-01-17] (PC Tools)
S3 pctNdis; C:\WINDOWS\System32\DRIVERS\pctNdis.sys [57536 2010-07-08] (PC Tools)
R3 pctNdisMP; C:\WINDOWS\System32\DRIVERS\pctNdis.sys [57536 2010-07-08] (PC Tools)
R3 pctplfw; C:\WINDOWS\system32\drivers\pctplfw.sys [125248 2011-01-17] (PC Tools)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1222840 2007-05-10] (SigmaTel, Inc.)
S4 IntelIde; no ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [X]
U1 WS2IFSL; no ImagePath
U3 aswMBR; \??\C:\DOCUME~1\Gamer\LOCALS~1\Temp\aswMBR.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-05-25 16:09 - 2016-05-25 16:10 - 00014030 _____ C:\Documents and Settings\Gamer\Desktop\FRST.txt
2016-05-25 16:08 - 2016-05-25 16:09 - 00000000 ____D C:\FRST
2016-05-25 16:06 - 2016-05-25 16:06 - 00002323 _____ C:\Documents and Settings\Gamer\Desktop\aswMBR.txt
2016-05-25 16:06 - 2016-05-25 16:06 - 00000512 _____ C:\Documents and Settings\Gamer\Desktop\MBR.dat
2016-05-25 15:41 - 2016-05-25 15:42 - 01733632 _____ (Farbar) C:\Documents and Settings\Gamer\Desktop\FRST.exe
2016-05-25 15:35 - 2016-05-25 15:37 - 05198336 _____ (AVAST Software) C:\Documents and Settings\Gamer\Desktop\aswMBR.exe
2016-05-20 23:57 - 2016-05-20 23:59 - 00119358 _____ C:\WINDOWS\ntbtlog.txt
2016-05-20 23:13 - 2016-05-20 23:59 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-05-20 23:11 - 2016-05-20 23:11 - 00000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2016-05-20 23:11 - 2016-05-20 23:11 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-05-20 23:11 - 2016-05-20 23:11 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2016-05-20 23:11 - 2016-05-20 23:11 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2016-05-20 23:11 - 2016-03-10 14:09 - 00123264 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-05-20 23:11 - 2016-03-10 14:08 - 00024448 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-05-20 21:41 - 2016-05-20 21:41 - 00148400 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-05-20 21:36 - 2016-05-20 21:36 - 00000398 _____ C:\Documents and Settings\Guest\My Documents\cc_20160520_213635.reg
2016-05-20 21:01 - 2016-05-20 23:50 - 00000664 _____ C:\Documents and Settings\Grant Lee\Local Settings\Application Data\d3d9caps.dat
2016-05-20 17:25 - 2016-05-25 15:15 - 00000470 _____ C:\WINDOWS\Tasks\SafeZone scheduled Autoupdate 1463779520.job
2016-05-20 17:25 - 2016-05-20 17:25 - 00000756 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-05-20 17:25 - 2016-05-20 17:25 - 00000756 _____ C:\Documents and Settings\All Users\Desktop\Avast SafeZone Browser.lnk
2016-05-20 17:14 - 2016-05-20 17:13 - 00334280 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2016-05-20 17:13 - 2016-05-20 17:13 - 00052184 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2016-05-19 08:47 - 2016-05-20 19:37 - 00001324 _____ C:\Documents and Settings\Guest\Local Settings\Application Data\d3d9caps.tmp
2016-05-14 19:18 - 2016-05-14 19:18 - 00000822 _____ C:\Documents and Settings\Grant Lee\Desktop\Auslogics DiskDefrag.lnk
2016-05-14 19:10 - 2016-05-14 19:10 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2016-05-12 17:50 - 2016-05-12 17:50 - 05995712 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2016-05-08 22:01 - 2016-05-08 22:01 - 00000000 ____D C:\Documents and Settings\Guest\Application Data\java
2016-05-08 21:59 - 2016-05-08 22:00 - 00000000 ____D C:\Documents and Settings\Guest\Application Data\.minecraft
2016-05-06 22:55 - 2016-05-06 22:55 - 00000000 ____D C:\Documents and Settings\Guest\Application Data\Unity
2016-05-06 22:20 - 2016-05-06 22:20 - 00000000 ____D C:\Documents and Settings\Guest\Local Settings\Application Data\Unity
2016-05-04 14:51 - 2016-05-04 14:51 - 00011158 ____R C:\Documents and Settings\Guest\My Documents\Lemke.docx.crypt
2016-05-04 14:51 - 2016-05-04 14:51 - 00011024 ____R C:\Documents and Settings\Guest\My Documents\Miller.docx.crypt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-05-25 16:10 - 2015-08-28 22:53 - 00000000 ____D C:\Documents and Settings\Gamer\Local Settings\Temp
2016-05-25 15:50 - 2015-08-30 03:10 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-05-25 15:36 - 2015-08-28 05:02 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-25 15:28 - 2015-05-23 21:07 - 00588700 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-05-25 15:27 - 2015-08-30 07:04 - 00088773 _____ C:\WINDOWS\system32\nvModes.001
2016-05-25 15:27 - 2015-08-28 06:24 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TEMP
2016-05-25 15:15 - 2015-08-28 05:24 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2016-05-25 15:14 - 2015-08-28 06:23 - 00000000 ____D C:\Program Files\PC Tools Firewall Plus
2016-05-25 15:14 - 2015-08-28 05:46 - 00000230 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2016-05-25 15:14 - 2015-08-28 05:02 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-25 15:14 - 2015-05-24 01:31 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-05-25 15:13 - 2015-12-09 06:00 - 00032490 _____ C:\WINDOWS\SchedLgU.Txt
2016-05-25 15:08 - 2015-08-28 22:53 - 00000000 ____D C:\Documents and Settings\Gamer
2016-05-25 15:04 - 2015-05-24 01:40 - 00000178 ___SH C:\Documents and Settings\Grant Lee\ntuser.ini
2016-05-25 15:04 - 2015-05-24 01:39 - 00000000 ____D C:\Documents and Settings\Grant Lee
2016-05-25 15:02 - 2015-05-24 01:39 - 00000000 ____D C:\Documents and Settings\Grant Lee\Local Settings\Temp
2016-05-25 14:59 - 2016-04-17 01:44 - 00000000 ____D C:\Documents and Settings\Guest\Local Settings\Application Data\Spotify
2016-05-25 14:59 - 2016-04-06 20:05 - 00000000 ___HD C:\Documents and Settings\All Users\Application Data\{9C669205-8A7C-4F7F-80A9-9126264911EA}
2016-05-25 14:46 - 2016-03-01 23:15 - 00000000 ____D C:\Documents and Settings\Guest
2016-05-25 14:42 - 2016-04-17 01:43 - 00000000 ____D C:\Documents and Settings\Guest\Application Data\Spotify
2016-05-24 21:58 - 2016-03-01 23:15 - 00000000 ____D C:\Documents and Settings\Guest\Local Settings\Temp
2016-05-24 16:15 - 2016-03-23 15:30 - 00000502 _____ C:\WINDOWS\Tasks\SystemToolsDailyTest.job
2016-05-23 13:54 - 2004-08-04 06:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2016-05-21 00:37 - 2015-08-28 22:53 - 00000178 ___SH C:\Documents and Settings\Gamer\ntuser.ini
2016-05-20 23:43 - 2015-05-24 01:21 - 00000000 ____D C:\WINDOWS\srchasst
2016-05-20 23:42 - 2015-08-30 03:49 - 00524288 _____ C:\WINDOWS\system32\config\WindowsPowerShell.evt
2016-05-20 22:18 - 2015-12-08 20:55 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2016-05-20 21:36 - 2016-03-01 23:15 - 00000000 ___RD C:\Documents and Settings\Guest\My Documents
2016-05-20 21:27 - 2015-08-29 20:21 - 00000000 ____D C:\Documents and Settings\Gamer\My Documents\CCleaner
2016-05-20 21:01 - 2015-08-28 07:02 - 00000000 ____D C:\Documents and Settings\Grant Lee\My Documents\CCleaner
2016-05-20 17:19 - 2015-09-24 17:02 - 00089232 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2016-05-20 17:17 - 2015-05-23 20:58 - 00000000 ___HD C:\WINDOWS\inf
2016-05-20 17:14 - 2015-08-28 05:24 - 00449640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2016-05-20 17:14 - 2015-08-28 05:24 - 00221368 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2016-05-20 17:14 - 2015-08-28 05:24 - 00187208 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys
2016-05-20 17:14 - 2015-08-28 05:24 - 00091168 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2016-05-20 17:14 - 2015-08-28 05:24 - 00067216 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2016-05-20 17:14 - 2015-08-28 05:24 - 00064272 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2016-05-20 17:14 - 2015-08-28 05:24 - 00058776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2016-05-20 17:14 - 2015-08-28 05:24 - 00032792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2016-05-20 17:13 - 2016-03-22 20:44 - 00035096 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2016-05-20 17:13 - 2015-08-28 05:24 - 00815792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2016-05-20 16:25 - 2016-03-01 23:15 - 00000000 ___RD C:\Documents and Settings\Guest\My Documents\My Pictures
2016-05-20 16:25 - 2016-02-26 16:03 - 00000000 ____D C:\Games
2016-05-20 16:19 - 2015-09-23 17:28 - 00000000 ____D C:\Documents and Settings\Grant Lee\Application Data\PCDr
2016-05-20 16:15 - 2015-05-24 02:55 - 00000000 ____D C:\Documents and Settings\Grant Lee\My Documents\Linksys Router Settings
2016-05-20 16:15 - 2015-05-24 01:39 - 00000000 ___RD C:\Documents and Settings\Grant Lee\My Documents
2016-05-20 16:07 - 2015-05-24 01:24 - 00000000 ____D C:\DELL
2016-05-20 16:05 - 2015-08-29 23:07 - 00000000 ____D C:\b40c7efc715d63c2bd016bc8a6
2016-05-20 15:05 - 2016-03-23 15:30 - 00000478 _____ C:\WINDOWS\Tasks\PCDDataUploadTask.job
2016-05-20 11:03 - 2015-09-13 19:04 - 00000000 ____D C:\WINDOWS\Minidump
2016-05-17 20:00 - 2016-03-23 15:31 - 00000564 _____ C:\WINDOWS\Tasks\PCDoctorBackgroundMonitorTask.job
2016-05-14 19:13 - 2016-02-25 14:12 - 00000000 ____D C:\Documents and Settings\Grant Lee\Application Data\uTorrent
2016-05-14 19:10 - 2015-08-28 06:56 - 00000682 _____ C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
2016-05-12 17:53 - 2015-08-30 03:10 - 00797376 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-05-12 17:53 - 2015-08-30 03:10 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-05-12 13:44 - 2015-08-28 04:19 - 136686448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories =======
2015-08-28 22:53 - 2015-08-28 22:53 - 0000664 ____C () C:\Documents and Settings\Gamer\Local Settings\Application Data\d3d9caps.tmp
1899-12-30 00:00 - 1899-12-30 00:00 - 2048054 ____T () C:\Documents and Settings\All Users\Application Data\AEFD8E935DCA.bmp
1601-03-12 09:17 - 1601-03-12 09:17 - 0014193 _____ () C:\Documents and Settings\All Users\Application Data\AEFD8E935DCA.html
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version:25-05-2016
Ran by [removed] (2016-05-25 16:10:59)
Running from C:\Documents and Settings\[removed]\Desktop
Microsoft Windows XP Home Edition Service Pack 3 (X86) (2015-05-24 05:26:06)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1482476501-1644491937-725345543-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
ASPNET (S-1-5-21-1482476501-1644491937-725345543-1007 - Limited - Disabled)
Gamer (S-1-5-21-1482476501-1644491937-725345543-1006 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Gamer
Grant Lee (S-1-5-21-1482476501-1644491937-725345543-1004 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Grant Lee
Guest (S-1-5-21-1482476501-1644491937-725345543-501 - Limited - Enabled) => %SystemDrive%\Documents and Settings\Guest
HelpAssistant (S-1-5-21-1482476501-1644491937-725345543-1000 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-1482476501-1644491937-725345543-1002 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: PC Tools Firewall Plus (Disabled) {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 21 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 21.0.0.242 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Auslogics DiskDefrag (HKLM\…\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 6.2.1.0 - Auslogics Labs Pty Ltd)
Avast Free Antivirus (HKLM\…\Avast) (Version: 11.2.2262 - AVAST Software)
Broadcom 440x 10/100 Integrated Controller (HKLM\…\{612B9183-67A9-4B44-9877-2F059E35B86A}) (Version: 10.04.02 - Broadcom Corporation)
CCleaner (HKLM\…\CCleaner) (Version: 5.17 - Piriform)
Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6021.5000 - Microsoft Corporation)
Conexant HDA D330 MDC V.92 Modem (HKLM\…\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F) (Version: - )
Dell Resource CD (HKLM\…\{42929F0F-CE14-47AF-9FC7-FF297A603021}) (Version: 1.00.0000 - Dell Inc.)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.2.6745.47 - Dell)
Dell Touchpad (HKLM\…\SynTPDeinstKey) (Version: 10.1.2.0 - Synaptics)
Dell Wireless WLAN Card Utility (HKLM\…\Broadcom 802.11 Application) (Version: 5.10.38.30 - Dell Inc.)
Digital Line Detect (HKLM\…\{E646DCF0-5A68-11D5-B229-002078017FBF}) (Version: 1.21 - BVRP Software, Inc)
EPSON Printer Software (HKLM\…\EPSON Printer and Utilities) (Version: - )
EPSON Scan (HKLM\…\EPSON Scanner) (Version: - )
Fallout: New Vegas (HKLM\…\Steam App 22380) (Version: - Obsidian Entertainment)
Google Chrome (HKLM\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Update Helper (Version: 1.3.30.3 - Google Inc.) Hidden
HD Tune 2.55 (HKLM\…\HD Tune_is1) (Version: - EFD Software)
IntelliSonic Speech Enhancement (HKLM\…\{D1B5E9C8-4CCF-44E3-87D6-7C00D7DA5370}) (Version: 2.1.37 - Knowles Acoustics)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
McGill English Dictionary of Rhyme & Verse Perfect 2.0 (HKLM\…\McGill English Dictionary of Rhyme with VersePer~286A7AE6_is1) (Version: - Bryant McGill / McGill International)
MediaDirect (HKLM\…\{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}) (Version: 3.5 - Dell)
Microsoft .NET Framework 1.1 (HKLM\…\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\…\M2833941) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\…\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\…\Wudf01000) (Version: - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Minecraft (HKLM\…\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Mozilla Firefox 40.0.3 (x86 en-US) (HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\Mozilla Firefox 40.0.3 (x86 en-US)) (Version: 40.0.3 - Mozilla)
Mozilla Firefox 45.0.1 (x86 en-US) (HKLM\…\Mozilla Firefox 45.0.1 (x86 en-US)) (Version: 45.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 45.0.1.5918 - Mozilla)
mProSafe (Version: 9.00.0000 - Intel) Hidden
NVIDIA Graphics Driver 266.58 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 266.58 - NVIDIA Corporation)
NVIDIA nView 135.50 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 135.50 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.10.0514 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.10.0514 - NVIDIA Corporation)
Origin (HKLM\…\Origin) (Version: 9.7.2.53208 - Electronic Arts, Inc.)
OutlookAddinSetup (HKLM\…\{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}) (Version: 1.0.0 - CyberLink)
PC Tools Firewall Plus 7.0 (HKLM\…\PC Tools Firewall Plus) (Version: 7.0 - PC Tools)
QuickSet (HKLM\…\{C5074CC4-0E26-4716-A307-960272A90040}) (Version: 8.3.11 - Dell Computer Corporation)
SafeZone Stable 1.48.2066.101 (Version: 1.48.2066.101 - Avast Software) Hidden
SeaTools for Windows 1.4.0.2 (HKLM\…\SeaTools for Windows) (Version: 1.4.0.2 - Seagate Technology)
SigmaTel Audio (HKLM\…\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}) (Version: 5.10.5210.0 - SigmaTel)
Skype™ 7.9 (HKLM\…\{1845470B-EB14-4ABC-835B-E36C693DC07D}) (Version: 7.9.103 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM\…\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Steam (HKLM\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04) (HKLM\…\4569969E1360D2854474C661EF9B4D54F143EB16) (Version: 11/14/2006 6.00.01.04 - Ricoh Company)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\KB892130) (Version: - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Management Framework Core (HKLM\…\KB968930) (Version: - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\…\Windows Media Format Runtime) (Version: - )
Windows Media Player 11 (HKLM\…\Windows Media Player) (Version: - )
Windows Search 4.0 (HKLM\…\KB940157) (Version: 04.00.6001.503 - Microsoft Corporation)
Windows Support Tools (HKLM\…\{89B078C4-50B0-453E-BF53-3A7E6A0D85FA}) (Version: 5.1.2600.2180 - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
WinRAR 5.30 beta 3 (32-bit) (HKLM\…\WinRAR archiver) (Version: 5.30.3 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1482476501-1644491937-725345543-1006_Classes\CLSID\{713DC8AF-3342-4F9E-81E4-3A12D3E902A4}\InprocServer32 -> C:\Documents and Settings\All Users\Application Data\{9C669205-8A7C-4F7F-80A9-9126264911EA}\mpr.dll (the data entry has 10 more characters).
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\PCDDataUploadTask.job => C:\Program Files\Dell\SupportAssist\uaclauncher.exe
Task: C:\WINDOWS\Tasks\PCDoctorBackgroundMonitorTask.job => C:\Program Files\Dell\SupportAssist\uaclauncher.exeq-backgroundmon scripts\backgroundmon.xml
Task: C:\WINDOWS\Tasks\SafeZone scheduled Autoupdate 1463779520.job => C:\Program Files\AVAST Software\SZBrowser\launcher.exe
Task: C:\WINDOWS\Tasks\SystemToolsDailyTest.job => C:\Program Files\Dell\SupportAssist\uaclauncher.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2015-05-24 02:11 - 2008-11-26 11:39 - 00024576 _____ () C:\WINDOWS\System32\WLTRYSVC.EXE
2015-05-24 02:11 - 2008-11-26 11:39 - 00753664 _____ () C:\WINDOWS\System32\bcm1xsup.dll
2015-08-28 05:23 - 2016-05-20 17:13 - 00123344 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-08-28 05:23 - 2016-05-20 17:13 - 00135816 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-05-25 11:04 - 2016-05-25 11:04 - 02977888 _____ () C:\Program Files\AVAST Software\Avast\defs\16052501\algo.dll
2016-04-14 16:01 - 2016-05-20 17:13 - 00479680 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2015-12-08 16:15 - 2016-05-20 17:13 - 00309912 _____ () C:\Program Files\AVAST Software\Avast\browser_pass.dll
2015-05-24 03:12 - 2007-07-20 16:56 - 00098304 _____ () C:\Program Files\Dell\QuickSet\dadkeyb.dll
2004-08-04 06:00 - 2013-01-02 02:49 - 01292288 _____ () C:\WINDOWS\system32\quartz.dll
2015-05-24 02:11 - 2008-11-26 11:39 - 00143360 _____ () C:\WINDOWS\system32\preflib.dll
2015-05-24 03:12 - 2005-10-13 13:53 - 00090223 _____ () C:\Program Files\Dell\QuickSet\preflibcl.dll
2015-08-28 05:23 - 2015-12-08 16:15 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-05-12 17:50 - 2016-05-12 17:53 - 19427520 _____ () C:\WINDOWS\system32\Macromed\Flash\NPSWF32_21_0_0_242.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:C31F31E6 [244]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com
There are 7871 more sites.
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1482476501-1644491937-725345543-1006\…\123simsen.com -> www.123simsen.com
There are 7871 more sites.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2004-08-04 06:00 - 2016-02-23 15:56 - 00450867 ____R C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com
There are 15469 more lines.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1482476501-1644491937-725345543-1006\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Gamer\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: [removed] - [removed]
Windows Firewall is disabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Spotify => "C:\Documents and Settings\Grant Lee\Application Data\Spotify\Spotify.exe" -autostart -minimized
MSCONFIG\startupreg: Spotify Web Helper => "C:\Documents and Settings\Grant Lee\Application Data\Spotify\SpotifyWebHelper.exe"
MSCONFIG\startupreg: Steam => "C:\Program Files\Steam\steam.exe" -silent
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
StandardProfile\AuthorizedApplications: [C:\Program Files\Dell\MediaDirect\PCMService.exe] => Enabled:CyberLink PowerCinema Resident Program
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE] => Enabled:Microsoft Office OneNote
StandardProfile\AuthorizedApplications: [C:\Program Files\Internet Explorer\IEXPLORE.EXE] => Enabled:Internet Explorer
StandardProfile\AuthorizedApplications: [C:\WINDOWS\twain_32\escndv\escndv.exe] => Enabled:EPSON Scan
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:Google Chrome
StandardProfile\AuthorizedApplications: [C:\Program Files\Steam\Steam.exe] => Enabled:Steam
StandardProfile\AuthorizedApplications: [C:\Program Files\Skype\Phone\Skype.exe] => Enabled:Skype
StandardProfile\AuthorizedApplications: [C:\Program Files\Steam\bin\steamwebhelper.exe] => Enabled:Steam Web Helper
StandardProfile\AuthorizedApplications: [C:\Program Files\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe] => Enabled:Fallout: New Vegas
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Grant Lee\Application Data\uTorrent\uTorrent.exe] => Enabled:µTorrent (Grant Lee)
StandardProfile\AuthorizedApplications: [C:\Games\SimCity5\SimCity 2013 Offline\SimCity\SimCity.exe] => Enabled:SimCity
StandardProfile\AuthorizedApplications: [C:\Games\SimCity 2013 Offline\SimCity\SimCity.exe] => Enabled:SimCity
StandardProfile\AuthorizedApplications: [C:\Games\SimCity 2013 Offline\SimCity\SimCity\SimCity.exe] => Enabled:SimCity
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)
StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22007
StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22008
StandardProfile\GloballyOpenPorts: [139:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22004
StandardProfile\GloballyOpenPorts: [445:TCP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22005
StandardProfile\GloballyOpenPorts: [137:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22001
StandardProfile\GloballyOpenPorts: [138:UDP] => :LocalSubNet:Disabled:@xpsp2res.dll,-22002
StandardProfile\GloballyOpenPorts: [5985:TCP] => Disabled:Windows Remote Management
StandardProfile\GloballyOpenPorts: [80:TCP] => Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)
==================== Restore Points =========================
02-05-2016 01:51:37 System Checkpoint
03-05-2016 02:41:30 System Checkpoint
06-05-2016 21:23:11 System Checkpoint
07-05-2016 22:46:05 System Checkpoint
10-05-2016 14:23:41 System Checkpoint
11-05-2016 17:12:46 Software Distribution Service 3.0
12-05-2016 21:31:29 System Checkpoint
14-05-2016 16:49:25 System Checkpoint
15-05-2016 19:44:19 System Checkpoint
17-05-2016 09:26:55 System Checkpoint
18-05-2016 12:51:08 System Checkpoint
19-05-2016 12:57:00 System Checkpoint
20-05-2016 13:48:39 System Checkpoint
20-05-2016 17:17:47 Installed Windows XP Wdf01009.
24-05-2016 11:52:33 System Checkpoint
25-05-2016 12:45:48 System Checkpoint
25-05-2016 15:00:45 Restore Operation
25-05-2016 15:10:14 Restore Operation
25-05-2016 15:14:46 Restore Operation
==================== Faulty Device Manager Devices =============
Name: Broadcom 440x 10/100 Integrated Controller
Description: Broadcom 440x 10/100 Integrated Controller
Class Guid: {4D36E972-E325-11CE-BFC1-08002BE10318}
Manufacturer: Broadcom
Service: bcm4sbxp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (05/25/2016 04:10:04 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download….uthrootseq.txt>with error: The specified server cannot perform the requested operation.
Error: (05/25/2016 04:10:04 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download….uthrootseq.txt>with error: The specified server cannot perform the requested operation.
Error: (05/25/2016 04:10:04 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download….uthrootseq.txt>with error: The specified server cannot perform the requested operation.
Error: (05/25/2016 04:10:04 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download….uthrootseq.txt>with error: The specified server cannot perform the requested operation.
Error: (05/25/2016 04:10:04 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download….uthrootseq.txt>with error: The specified server cannot perform the requested operation.
Error: (05/25/2016 04:10:04 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download….uthrootseq.txt>with error: The specified server cannot perform the requested operation.
Error: (05/25/2016 04:10:04 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download….uthrootseq.txt>with error: The specified server cannot perform the requested operation.
Error: (05/25/2016 04:10:04 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download….uthrootseq.txt>with error: The specified server cannot perform the requested operation.
Error: (05/25/2016 04:10:04 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download….uthrootseq.txt>with error: The specified server cannot perform the requested operation.
Error: (05/25/2016 04:10:04 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download….uthrootseq.txt>with error: The specified server cannot perform the requested operation.
System errors:
=============
Error: (05/25/2016 04:14:00 PM) (Source: DCOM) (EventID: 10010) (User: GRANTMARISLEE)
Description: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.
Error: (05/25/2016 04:13:30 PM) (Source: DCOM) (EventID: 10010) (User: GRANTMARISLEE)
Description: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.
Error: (05/25/2016 04:12:59 PM) (Source: DCOM) (EventID: 10010) (User: GRANTMARISLEE)
Description: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.
Error: (05/25/2016 04:12:29 PM) (Source: DCOM) (EventID: 10010) (User: GRANTMARISLEE)
Description: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.
Error: (05/25/2016 04:11:58 PM) (Source: DCOM) (EventID: 10010) (User: GRANTMARISLEE)
Description: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.
Error: (05/25/2016 04:11:28 PM) (Source: DCOM) (EventID: 10010) (User: GRANTMARISLEE)
Description: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.
Error: (05/25/2016 04:10:57 PM) (Source: DCOM) (EventID: 10010) (User: GRANTMARISLEE)
Description: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.
Error: (05/25/2016 04:10:26 PM) (Source: DCOM) (EventID: 10010) (User: GRANTMARISLEE)
Description: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.
Error: (05/25/2016 04:09:56 PM) (Source: DCOM) (EventID: 10010) (User: GRANTMARISLEE)
Description: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.
Error: (05/25/2016 04:09:25 PM) (Source: DCOM) (EventID: 10010) (User: GRANTMARISLEE)
Description: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.
==================== Memory info ===========================
Processor: Intel® Core™2 Duo CPU T7250 @ 2.00GHz
Percentage of memory in use: 25%
Total physical RAM: 3581.97 MB
Available physical RAM: 2657.6 MB
Total Virtual: 5464.26 MB
Available Virtual: 4593.58 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:462.71 GB) (Free:409.92 GB) NTFS ==>[drive with boot components (Windows XP)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: 00000080)
Partition 1: (Not Active) - (Size=47 MB) - (Type=DE)
Partition 2: (Active) - (Size=462.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=3 GB) - (Type=OF Extended)
==================== End of Addition.txt ============================