Here are a few logs, I ran the malwarebytes and it showed nothing. Had a bios issue so I flashed an update a couple days ago. Thought i might as well do this too!
Addition
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 17-07-2016
Ran by [removed] (2016-07-16 11:28:10)
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
Microsoft Windows XP Professional Service Pack 3 (X86) (2011-10-28 21:46:59)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-602162358-1303643608-725345543-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
ASPNET (S-1-5-21-602162358-1303643608-725345543-1003 - Limited - Enabled)
Guest (S-1-5-21-602162358-1303643608-725345543-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-602162358-1303643608-725345543-1000 - Limited - Disabled)
Sarah (S-1-5-21-602162358-1303643608-725345543-1005 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Sarah
SUPPORT_388945a0 (S-1-5-21-602162358-1303643608-725345543-1002 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe AIR (HKLM\…\Adobe AIR) (Version: 3.0.0.4080 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM\…\Adobe Flash Player Plugin) (Version: 11.1.102.55 - Adobe Systems Incorporated)
Adobe Reader X (10.1.11) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM\…\Adobe Shockwave Player) (Version: 11.6.1.629 - Adobe Systems, Inc.)
Apple Application Support (32-bit) (HKLM\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{A75CA58D-DB9C-4D14-9428-E0C7B0F623DC}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
B57Inst (Version: 3.40 - Broadcom) Hidden
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom 440x 10/100 Integrated Controller (HKLM\…\InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}) (Version: 3.29 - Broadcom)
Broadcom 440x 10/100 Integrated Controller (Version: 3.29 - Broadcom) Hidden
Broadcom Driver Installer (HKLM\…\InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}) (Version: 3.40 - Broadcom)
Broadcom Management Programs (HKLM\…\InstallShield_{89EE857B-8970-4F9F-AB58-A1C873AC72B3}) (Version: 4.01.0000 - Broadcom)
Broadcom Management Programs (Version: 4.01.0000 - Broadcom) Hidden
Dell ResourceCD (HKLM\…\{D78653C3-A8FF-415F-92E6-D774E634FF2D}) (Version: - )
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.2.6793.01 - Dell)
Dell System Detect (HKU\S-1-5-21-602162358-1303643608-725345543-1005\…\58d94f3ce2c27db0) (Version: 7.6.0.17 - Dell)
Google Chrome (HKLM\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Update Helper (Version: 1.3.30.3 - Google Inc.) Hidden
HWiNFO32 Version 3.88 (HKLM\…\HWiNFO32_is1) (Version: 3.88 - Martin Malík - REALiX)
Intel(R) Extreme Graphics Driver (HKLM\…\{8A708DD8-A5E6-11D4-A706-000629E95E20}) (Version: - )
iTunes (HKLM\…\{868B9974-4F23-494D-B6BC-4FAB92B2755D}) (Version: 12.1.3.6 - Apple Inc.)
Java(TM) 6 Update 29 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83216029FF}) (Version: 6.0.290 - Oracle)
Junk Mail filter update (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MEGAsync (HKLM\…\MEGAsync) (Version: - Mega Limited)
Memory Key Boot Utility (HKLM\…\{D3943D0B-C281-4BF7-9FFB-2A4497986BF9}) (Version: 1.0.8.2 - Smart Modular (MA))
Microsoft .NET Framework 1.1 (HKLM\…\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\…\M2833941) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\…\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Base Smart Card Cryptographic Service Provider Package (HKLM\…\KB909520) (Version: - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\…\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 2.1.1116.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\…\Wudf01000) (Version: - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 9.0.1 (x86 en-US) (HKLM\…\Mozilla Firefox 9.0.1 (x86 en-US)) (Version: 9.0.1 - Mozilla)
MyHeritage Family Tree Builder (HKLM\…\Family Tree Builder) (Version: 6.0.0.5634 - MyHeritage.com)
QuickTime (HKLM\…\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)
Segoe UI (Version: 14.0.4327.805 - Microsoft Corp) Hidden
SiSoftware Sandra Lite 2011.SP5 (HKLM\…\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2296}_is1) (Version: 17.80.2011.10 - SiSoftware)
SoundMAX (HKLM\…\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 5.12.01.5246 - Analog Devices)
Spotify (HKU\S-1-5-21-602162358-1303643608-725345543-1005\…\Spotify) (Version: 0.6.4 - )
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
USB 2.0 Wireless LAN Card Utility (HKLM\…\{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}) (Version: 8.1.50 - Dell Inc.)
WebFldrs XP (Version: 9.50.6513 - Microsoft Corporation) Hidden
Windows Genuine Advantage Notifications (KB905474) (HKLM\…\WgaNotify) (Version: 1.9.0040.0 - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\KB892130) (Version: - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Live Essentials (HKLM\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Management Framework Core (HKLM\…\KB968930) (Version: - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\…\Windows Media Format Runtime) (Version: - )
Windows Media Player 11 (HKLM\…\Windows Media Player) (Version: - )
Windows Search 4.0 (HKLM\…\KB940157) (Version: 04.00.6001.503 - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\MP Scheduled Scan.job => c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2014-05-01 10:15 - 2014-05-01 10:15 - 00463360 _____ () C:\Documents and Settings\All Users\Application Data\MEGAsync\ShellExtX32.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-04-04 23:14 - 2014-02-10 13:44 - 04592128 _____ () C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
2016-04-04 23:14 - 2014-02-10 13:44 - 00112128 _____ () C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UploadMgr => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-602162358-1303643608-725345543-1005\…\dell.com -> dell.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2003-07-16 12:23 - 2003-07-16 12:23 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-602162358-1303643608-725345543-1005\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Sarah\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: 192.168.1.1
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Family Tree Builder Update => C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: MSMSGS => "C:\Program Files\Messenger\msmsgs.exe" /background
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Spotify => "C:\Documents and Settings\Sarah\Application Data\Spotify\Spotify.exe" /uri spotify:autostart
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
DomainProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe] => Enabled:Windows Live Sync
DomainProfile\AuthorizedApplications: [C:\Program Files\Dropbox\Client\Dropbox.exe] => Enabled:Dropbox
StandardProfile\AuthorizedApplications: [C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\RpcAgentSrv.exe] => Enabled:SiSoftware Deployment Agent Service
StandardProfile\AuthorizedApplications: [C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\WNt500x86\RpcSandraSrv.exe] => Enabled:SiSoftware Sandra Agent Service
StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Sarah\Application Data\Spotify\spotify.exe] => Enabled:Spotify
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Sarah\Application Data\Dropbox\bin\Dropbox.exe] => Enabled:Dropbox
StandardProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe] => Enabled:Windows Live Sync
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:Google Chrome
StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes
StandardProfile\GloballyOpenPorts: [5985:TCP] => Disabled:Windows Remote Management
StandardProfile\GloballyOpenPorts: [80:TCP] => Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)
==================== Restore Points =========================
17-04-2016 10:09:25 Software Distribution Service 3.0
17-04-2016 19:37:44 Software Distribution Service 3.0
18-04-2016 08:58:08 Software Distribution Service 3.0
18-04-2016 12:30:52 Software Distribution Service 3.0
19-04-2016 08:54:54 Software Distribution Service 3.0
20-04-2016 08:42:04 Software Distribution Service 3.0
20-04-2016 19:04:55 Software Distribution Service 3.0
21-04-2016 06:56:26 Software Distribution Service 3.0
21-04-2016 14:20:05 Software Distribution Service 3.0
21-04-2016 14:21:09 Software Distribution Service 3.0
21-04-2016 14:21:40 Software Distribution Service 3.0
22-04-2016 09:55:59 Software Distribution Service 3.0
23-04-2016 15:26:38 Software Distribution Service 3.0
24-04-2016 02:06:06 Software Distribution Service 3.0
25-04-2016 11:20:46 Software Distribution Service 3.0
26-04-2016 16:25:50 Software Distribution Service 3.0
27-04-2016 17:13:39 Software Distribution Service 3.0
28-04-2016 18:20:21 Software Distribution Service 3.0
29-04-2016 20:53:28 Software Distribution Service 3.0
01-05-2016 10:15:12 Software Distribution Service 3.0
02-05-2016 10:52:28 System Checkpoint
02-05-2016 20:03:15 Software Distribution Service 3.0
03-05-2016 20:48:53 System Checkpoint
04-05-2016 08:55:11 Software Distribution Service 3.0
05-05-2016 10:01:17 System Checkpoint
05-05-2016 19:52:26 Software Distribution Service 3.0
06-05-2016 21:01:54 Software Distribution Service 3.0
08-05-2016 08:32:06 Software Distribution Service 3.0
09-05-2016 10:30:13 Software Distribution Service 3.0
10-05-2016 11:45:00 System Checkpoint
11-05-2016 06:44:06 Software Distribution Service 3.0
11-05-2016 13:04:08 Software Distribution Service 3.0
12-05-2016 07:48:30 Software Distribution Service 3.0
13-05-2016 08:25:39 Software Distribution Service 3.0
14-05-2016 08:50:46 Software Distribution Service 3.0
15-05-2016 08:56:58 Software Distribution Service 3.0
15-05-2016 21:06:18 Software Distribution Service 3.0
16-05-2016 21:14:47 System Checkpoint
17-05-2016 05:55:37 Software Distribution Service 3.0
18-05-2016 09:12:29 Software Distribution Service 3.0
19-05-2016 09:36:14 System Checkpoint
19-05-2016 10:13:00 Software Distribution Service 3.0
20-05-2016 10:07:26 Software Distribution Service 3.0
21-05-2016 11:24:33 System Checkpoint
22-05-2016 01:41:16 Software Distribution Service 3.0
23-05-2016 09:31:40 Software Distribution Service 3.0
24-05-2016 09:40:48 System Checkpoint
25-05-2016 11:35:17 Software Distribution Service 3.0
26-05-2016 12:22:48 System Checkpoint
27-05-2016 08:57:46 Software Distribution Service 3.0
28-05-2016 09:41:40 Software Distribution Service 3.0
29-05-2016 10:41:13 Software Distribution Service 3.0
30-05-2016 11:09:43 System Checkpoint
31-05-2016 09:35:50 Software Distribution Service 3.0
01-06-2016 10:13:45 Software Distribution Service 3.0
02-06-2016 13:03:11 System Checkpoint
03-06-2016 06:33:48 Software Distribution Service 3.0
04-06-2016 10:36:22 Software Distribution Service 3.0
05-06-2016 20:35:29 Software Distribution Service 3.0
06-06-2016 21:50:48 Software Distribution Service 3.0
08-06-2016 15:42:34 Software Distribution Service 3.0
10-06-2016 08:26:50 Software Distribution Service 3.0
11-06-2016 10:10:15 Software Distribution Service 3.0
12-06-2016 10:57:41 Software Distribution Service 3.0
13-06-2016 15:04:05 System Checkpoint
15-06-2016 09:40:25 Software Distribution Service 3.0
15-06-2016 15:43:16 Software Distribution Service 3.0
15-06-2016 16:21:37 Software Distribution Service 3.0
16-06-2016 18:05:06 Software Distribution Service 3.0
18-06-2016 01:43:54 Software Distribution Service 3.0
19-06-2016 09:48:04 Software Distribution Service 3.0
20-06-2016 12:36:48 System Checkpoint
22-06-2016 09:06:12 Software Distribution Service 3.0
23-06-2016 09:31:08 Software Distribution Service 3.0
24-06-2016 19:21:10 Software Distribution Service 3.0
25-06-2016 22:23:14 System Checkpoint
26-06-2016 02:24:26 Software Distribution Service 3.0
27-06-2016 02:41:14 System Checkpoint
27-06-2016 18:26:59 Software Distribution Service 3.0
28-06-2016 18:54:33 Software Distribution Service 3.0
29-06-2016 18:57:28 Software Distribution Service 3.0
30-06-2016 18:50:29 Software Distribution Service 3.0
01-07-2016 18:56:39 Software Distribution Service 3.0
02-07-2016 18:57:19 Software Distribution Service 3.0
03-07-2016 02:29:04 Software Distribution Service 3.0
03-07-2016 18:50:06 Software Distribution Service 3.0
04-07-2016 18:57:30 Software Distribution Service 3.0
05-07-2016 18:57:11 Software Distribution Service 3.0
06-07-2016 18:56:47 Software Distribution Service 3.0
08-07-2016 07:28:46 Software Distribution Service 3.0
12-07-2016 21:24:38 Software Distribution Service 3.0
13-07-2016 09:47:34 Software Distribution Service 3.0
14-07-2016 01:20:20 Software Distribution Service 3.0
14-07-2016 09:51:20 Software Distribution Service 3.0
15-07-2016 10:15:18 Software Distribution Service 3.0
15-07-2016 22:17:07 Installed USB 2.0 Wireless LAN Card Utility
16-07-2016 11:17:55 JRT Pre-Junkware Removal
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/16/2016 11:07:27 AM) (Source: MPSampleSubmission) (EventID: 5000) (User: )
Description: EventType avsubmit, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P2 1.1.12902.0, P3 1.225.1565.0, P4 1.225.1565.0, P5 0000000000000000_0000000000000000000000000000000000000000, P6 NIL, P7 NIL, P8 NIL, P9 avsubmit0, P10 avsubmit1.
Error: (05/31/2016 09:39:03 AM) (Source: MPSampleSubmission) (EventID: 5000) (User: )
Description: EventType mptelemetry, P1 0x80070670, P2 patchapplication, P3 am bdd, P4 1.1.12745.0, P5 mpsigstub.exe, P6 3.0.8402.0, P7 microsoft security essentials, P8 NIL, P9 mptelemetry0, P10 mptelemetry1.
Error: (05/22/2016 07:24:00 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application wlmail.exe, version 14.0.8117.416, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
System errors:
=============
Error: (07/15/2016 10:47:41 PM) (Source: 0) (EventID: 7) (User: )
Description: \Device\Harddisk0\D
Error: (06/06/2016 09:39:22 PM) (Source: System Error) (EventID: 1003) (User: )
Description: Error code 10000050, parameter1 e3e4b26e, parameter2 00000000, parameter3 bf85fc9e, parameter4 00000001.
Error: (06/06/2016 09:38:56 PM) (Source: System Error) (EventID: 1003) (User: )
Description: Error code 000000ca, parameter1 00000001, parameter2 85c20030, parameter3 85d20030, parameter4 00000000.
Error: (05/31/2016 09:42:31 AM) (Source: Windows Update Agent) (EventID: 20) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Microsoft Security Essentials - KB2310138 (Definition 1.223.285.0).
Error: (05/31/2016 09:39:19 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.223.281.0
Update Source: %NT AUTHORITY59
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\SYSTEM
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (04/21/2016 02:21:52 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.217.1197.0
Update Source: %NT AUTHORITY51
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (04/21/2016 02:21:52 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.217.1197.0
Update Source: %NT AUTHORITY51
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (04/21/2016 02:21:52 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.217.1197.0
Update Source: %NT AUTHORITY51
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (04/21/2016 02:21:52 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.217.1197.0
Update Source: %NT AUTHORITY51
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (04/21/2016 02:21:47 PM) (Source: Windows Update Agent) (EventID: 20) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x800700c1: Definition Update for Microsoft Security Essentials - KB2310138 (Definition 1.217.1832.0).
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz
Percentage of memory in use: 53%
Total physical RAM: 766 MB
Available physical RAM: 353.3 MB
Total Virtual: 2260.76 MB
Available Virtual: 1705.25 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:73.5 GB) (Free:50.55 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive f: (SARAHS TD) (Removable) (Total:14.89 GB) (Free:11.19 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: 0002476D)
Partition 1: (Active) - (Size=73.5 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 14.9 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================
FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-07-2016
Ran by [removed] (administrator) on SARAH-ET-AL (16-07-2016 11:26:38)
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
[removed]
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1404928 2004-10-14] (Analog Devices, Inc.)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [997920 2011-06-15] (Microsoft Corporation)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-13] (Adobe Systems Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157456 2015-09-12] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2011-10-24] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxsrvc.dll [2005-06-21] (Intel Corporation)
Winlogon\Notify\PRISMAPI.DLL: C:\WINDOWS\system32\PRISMAPI.DLL [2005-12-22] (Conexant Systems, Inc.)
HKU\S-1-5-21-602162358-1303643608-725345543-1005\…\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-18\…\Run: [DWQueuedReporting] => c:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [437160 2007-02-26] (Microsoft Corporation)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Documents and Settings\All Users\Application Data\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Documents and Settings\All Users\Application Data\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Documents and Settings\All Users\Application Data\MEGAsync\ShellExtX32.dll [2014-05-01] ()
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk [2011-11-27]
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless USB 2.0 WLAN Card Utility.lnk [2016-07-15]
ShortcutTarget: Wireless USB 2.0 WLAN Card Utility.lnk -> C:\Program Files\Dell Wireless\PRISMCFG.exe (Dell Inc.)
Startup: C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\MEGAsync.lnk [2016-04-04]
ShortcutTarget: MEGAsync.lnk -> C:\Documents and Settings\All Users\Application Data\MEGAsync\MEGAsync.exe (Mega Limited)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9A53DC7E-5D45-4B2B-A6E5-4E5D96E83B0F}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-602162358-1303643608-725345543-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver;=6&ar;=msnhome
HKU\S-1-5-21-602162358-1303643608-725345543-1005\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-11-28] (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class -> {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -> C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-11-28] (Sun Microsystems, Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Sarah\Application Data\Mozilla\Firefox\Profiles\3729nmn9.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll [2011-12-05] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw.dll [2011-10-05] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2011-11-28] (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-08-03] (Adobe Systems Inc.)
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-11-28] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2011-11-28] [not signed]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.knoxlib.org/"
CHR Profile: C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-04-04]
CHR Extension: (Google Docs) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-04]
CHR Extension: (Google Drive) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-04]
CHR Extension: (YouTube) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-04]
CHR Extension: (Adblock Plus) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-06-29]
CHR Extension: (Google Sheets) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-04-04]
CHR Extension: (Google Docs Offline) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-04]
CHR Extension: (Disconnect) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo [2016-04-04]
CHR Extension: (Ghostery) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2016-04-04]
CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-04]
CHR Extension: (Gmail) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-04]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 JavaQuickStarterService; C:\Program Files\Java\jre6\bin\jqs.exe [153376 2011-11-28] (Sun Microsystems, Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [11736 2011-04-27] (Microsoft Corporation)
S2 PRISMSVC; C:\WINDOWS\system32\PRISMSVC.EXE [61526 2005-12-22] (Conexant Systems, Inc.) [File not signed]
S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\RpcAgentSrv.exe [93848 2008-09-18] (SiSoftware) [File not signed]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [20747 2005-10-12] (Meetinghouse Data Communications) [File not signed]
R2 fssfltr; C:\WINDOWS\System32\DRIVERS\fssfltr_tdi.sys [54760 2010-04-28] (Microsoft Corporation)
R2 HWiNFO32; C:\Program Files\HWiNFO32\HWiNFO32.SYS [21624 2011-09-22] (REALiX™)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [24448 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [170200 2016-07-16] (Malwarebytes)
R1 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [165648 2011-04-18] (Microsoft Corporation)
R1 MpKsl8a894191; c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{65EB9943-61D3-46FB-B3A9-46981B168618}\MpKsl8a894191.sys [39168 2016-07-15] (Microsoft Corporation)
R1 OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [13632 2001-08-22] (Dell Computer Corporation) [File not signed]
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\WNt500x86\Sandra.sys [23112 2009-08-07] (SiSoftware)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-16 11:26 - 2016-07-16 11:26 - 00000000 ____D C:\FRST
2016-07-16 11:21 - 2016-07-16 11:21 - 00003408 _____ C:\Documents and Settings\Sarah\Desktop\JRT.txt
2016-07-16 10:23 - 2016-07-16 11:21 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-07-16 10:18 - 2016-07-16 10:18 - 00000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2016-07-16 10:18 - 2016-07-16 10:18 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2016-07-16 10:17 - 2016-07-16 10:18 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-07-16 10:17 - 2016-07-16 10:17 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2016-07-16 10:17 - 2016-03-10 14:09 - 00123264 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-07-16 10:17 - 2016-03-10 14:08 - 00024448 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-07-16 10:14 - 2016-07-16 10:15 - 00003602 _____ C:\Documents and Settings\Sarah\Desktop\Rkill.txt
2016-07-16 09:36 - 2016-07-16 09:37 - 00000000 ____D C:\AdwCleaner
2016-07-15 22:41 - 2016-07-15 22:41 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Dell
2016-07-15 22:40 - 2016-07-15 22:42 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\PCDr
2016-07-15 22:40 - 2016-07-15 22:40 - 00000000 ____D C:\Program Files\Dell Support Center
2016-07-15 22:38 - 2016-07-15 22:38 - 00000000 ____D C:\Program Files\Dell
2016-07-15 22:32 - 2016-07-15 22:43 - 00000000 ____D C:\Documents and Settings\Sarah\Application Data\PCDr
2016-07-15 22:31 - 2016-07-15 22:51 - 00000000 ____D C:\temp
2016-07-15 22:18 - 2016-07-15 22:18 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Prism
2016-07-15 22:17 - 2016-07-15 22:17 - 00000000 ____D C:\Program Files\Dell Wireless
2016-07-15 22:17 - 2016-07-15 22:17 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Dell Wireless
2016-07-15 22:17 - 2005-12-22 20:21 - 00061526 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\PRISMSVC.exe
2016-07-15 22:17 - 2005-12-22 20:15 - 00381014 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\PRISMSVR.exe
2016-07-15 22:17 - 2005-12-22 20:08 - 00450646 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\PRISMAPI.dll
2016-07-15 22:17 - 2005-11-15 12:59 - 00049152 _____ C:\WINDOWS\system32\StopSrvr.exe
2016-07-15 22:17 - 2005-10-12 00:05 - 01396827 _____ (Meetinghouse Data Communications) C:\WINDOWS\system32\PRISME5.dll
2016-07-15 22:17 - 2005-10-12 00:04 - 00020747 _____ (Meetinghouse Data Communications) C:\WINDOWS\system32\Drivers\AegisP.sys
2016-07-15 22:11 - 2016-07-15 22:18 - 00000000 ____D C:\WINDOWS\LastGood
2016-07-15 21:58 - 2016-07-15 21:58 - 00000000 ____D C:\Documents and Settings\Sarah\Start Menu\Programs\Dell
2016-07-15 21:57 - 2016-07-15 22:29 - 00000000 ____D C:\Documents and Settings\Sarah\Local Settings\Application Data\Deployment
2016-07-15 21:47 - 2016-07-15 21:47 - 00031832 _____ (Phoenix Technologies) C:\WINDOWS\system32\Drivers\DrvAgent32.sys
2016-06-28 14:31 - 2016-06-28 14:31 - 00000000 _____ C:\Documents and Settings\Sarah\Desktop\lapbook.txt
2016-06-19 12:01 - 2016-06-19 12:01 - 00000909 _____ C:\Documents and Settings\Sarah\Desktop\Shortcut to IMG_8579.lnk
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-16 11:27 - 2011-10-28 23:05 - 00000000 ____D C:\Documents and Settings\Sarah\Local Settings\Temp
2016-07-16 11:25 - 2016-04-04 19:13 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-07-15 22:44 - 2011-10-28 13:29 - 00000000 ___HD C:\WINDOWS\inf
2016-07-15 22:28 - 2003-07-16 12:46 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2016-07-15 22:17 - 2011-10-28 18:05 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-07-15 22:17 - 2011-10-28 17:47 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Temp
2016-07-15 22:11 - 2011-11-27 22:46 - 00000424 ____H C:\WINDOWS\Tasks\MP Scheduled Scan.job
2016-07-15 22:06 - 2016-04-04 22:56 - 00000222 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2016-07-15 22:06 - 2016-04-04 19:13 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-07-15 22:06 - 2011-10-28 23:05 - 00000178 ___SH C:\Documents and Settings\Sarah\ntuser.ini
2016-07-15 22:06 - 2011-10-28 17:47 - 00032528 _____ C:\WINDOWS\SchedLgU.Txt
2016-07-15 22:06 - 2011-10-28 17:41 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-07-13 10:05 - 2016-04-04 20:52 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-07-13 09:50 - 2011-10-30 06:18 - 141983760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-07-08 15:43 - 2016-04-04 22:56 - 00000216 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2016-07-06 20:39 - 2011-11-27 22:45 - 00400552 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-07-05 08:07 - 2016-04-04 22:39 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2016-07-02 12:02 - 2011-10-28 23:05 - 00000000 ___RD C:\Documents and Settings\Sarah\My Documents\My Pictures
==================== Files in the root of some directories =======
2011-11-27 13:06 - 2011-12-27 08:11 - 0057856 _____ () C:\Documents and Settings\Sarah\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some files in TEMP:
====================
C:\Documents and Settings\Sarah\Local Settings\Temp\FP_PL_PFS_INSTALLER_32bit.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
JRT
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.7 (07.03.2016)
Operating System: Microsoft Windows XP x86
Ran by [removed] (Administrator) on Sat 07/16/2016 at 11:17:48.40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 18
Successfully deleted: C:\Documents and Settings\Sarah\Local Settings\Application Data\esupport.com (Folder)
Successfully deleted: C:\Program Files\mozilla firefox\defaults\pref\itms.js (File)
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\4T678LAB (Temporary Internet Files Folder)
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8XAZ01QF (Temporary Internet Files Folder)
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CDQRG56J (Temporary Internet Files Folder)
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CF8UHA5J (Temporary Internet Files Folder)
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IGZ3U892 (Temporary Internet Files Folder)
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SP2R45I7 (Temporary Internet Files Folder)
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UUEA115B (Temporary Internet Files Folder)
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\V5YCZJYV (Temporary Internet Files Folder)
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\4T678LAB (Temporary Internet Files Folder)
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8XAZ01QF (Temporary Internet Files Folder)
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\CDQRG56J (Temporary Internet Files Folder)
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\CF8UHA5J (Temporary Internet Files Folder)
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\IGZ3U892 (Temporary Internet Files Folder)
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\SP2R45I7 (Temporary Internet Files Folder)
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UUEA115B (Temporary Internet Files Folder)
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\V5YCZJYV (Temporary Internet Files Folder)
Registry: 1
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 07/16/2016 at 11:21:10.45
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ADWCleaner S1
# AdwCleaner v5.201 - Logfile created 16/07/2016 at 09:37:02
# Updated 30/06/2016 by ToolsLib
# Database : 2016-07-14.1 [Server]
# Operating system : Microsoft Windows XP Service Pack 3 (X86)
# Username : Sarah - SARAH-ET-AL
# Running from : F:\Cleaners for windows computers\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
Service Found : DrvAgent32
***** [ Folders ] *****
***** [ Files ] *****
File Found : C:\WINDOWS\system32\drivers\DrvAgent32.sys
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
Key Found : HKLM\SOFTWARE\Classes\ieplugin.JQSIEStartDetectorImpl
Key Found : HKLM\SOFTWARE\Classes\ieplugin.JQSIEStartDetectorImpl.1
Key Found : HKCU\Software\eSupport.com
Key Found : HKU\S-1-5-21-602162358-1303643608-725345543-1005\Software\eSupport.com
***** [ Web browsers ] *****
*************************
C:\AdwCleaner\AdwCleaner[S1].txt - [998 bytes] - [16/07/2016 09:37:02]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1070 bytes] ##########
RKILL
Rkill 2.8.4 by Lawrence Abrams (Grinler)
Copyright 2008-2016 BleepingComputer.com
More Information about Rkill can be found at this link:
Program started at: 07/16/2016 10:14:38 AM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\WINDOWS\system32\PRISMSVR.exe (PID: 1392) [WD-HEUR]
* C:\WINDOWS\system32\PRISMSVC.EXE (PID: 3712) [WD-HEUR]
* C:\Documents and Settings\Sarah\Local Settings\Apps\2.0\QXC45Y14.A9V\ZDX4WQ79.L7L\dell..tion_6d0a76327dca4869_0007.0006_be49b0d0ac5b5b8d\DellSystemDetect.exe (PID: 3996) [UP-HEUR]
3 proccesses terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Reparse Point/Junctions Found (Most likely legitimate)!
* C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a => C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492 [Dir]
* C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35 => C:\WINDOWS\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 [Dir]
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 07/16/2016 10:15:57 AM
Execution time: 0 hours(s), 1 minute(s), and 18 seconds(s)