This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Last computer done, might as well check this one too.

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here are a few logs, I ran the malwarebytes and it showed nothing. Had a bios issue so I flashed an update a couple days ago. Thought i might as well do this too!

 

 

Addition

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 17-07-2016

Ran by [removed] (2016-07-16 11:28:10)
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
Microsoft Windows XP Professional Service Pack 3 (X86) (2011-10-28 21:46:59)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-602162358-1303643608-725345543-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
ASPNET (S-1-5-21-602162358-1303643608-725345543-1003 - Limited - Enabled)
Guest (S-1-5-21-602162358-1303643608-725345543-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-602162358-1303643608-725345543-1000 - Limited - Disabled)
Sarah (S-1-5-21-602162358-1303643608-725345543-1005 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Sarah
SUPPORT_388945a0 (S-1-5-21-602162358-1303643608-725345543-1002 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe AIR (HKLM\…\Adobe AIR) (Version: 3.0.0.4080 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM\…\Adobe Flash Player Plugin) (Version: 11.1.102.55 - Adobe Systems Incorporated)
Adobe Reader X (10.1.11) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM\…\Adobe Shockwave Player) (Version: 11.6.1.629 - Adobe Systems, Inc.)
Apple Application Support (32-bit) (HKLM\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{A75CA58D-DB9C-4D14-9428-E0C7B0F623DC}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
B57Inst (Version: 3.40 - Broadcom) Hidden
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom 440x 10/100 Integrated Controller (HKLM\…\InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}) (Version: 3.29 - Broadcom)
Broadcom 440x 10/100 Integrated Controller (Version: 3.29 - Broadcom) Hidden
Broadcom Driver Installer (HKLM\…\InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}) (Version: 3.40 - Broadcom)
Broadcom Management Programs (HKLM\…\InstallShield_{89EE857B-8970-4F9F-AB58-A1C873AC72B3}) (Version: 4.01.0000 - Broadcom)
Broadcom Management Programs (Version: 4.01.0000 - Broadcom) Hidden
Dell ResourceCD (HKLM\…\{D78653C3-A8FF-415F-92E6-D774E634FF2D}) (Version:  - )
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.2.6793.01 - Dell)
Dell System Detect (HKU\S-1-5-21-602162358-1303643608-725345543-1005\…\58d94f3ce2c27db0) (Version: 7.6.0.17 - Dell)
Google Chrome (HKLM\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Update Helper (Version: 1.3.30.3 - Google Inc.) Hidden
HWiNFO32 Version 3.88 (HKLM\…\HWiNFO32_is1) (Version: 3.88 - Martin Malík - REALiX)
Intel(R) Extreme Graphics Driver (HKLM\…\{8A708DD8-A5E6-11D4-A706-000629E95E20}) (Version:  - )
iTunes (HKLM\…\{868B9974-4F23-494D-B6BC-4FAB92B2755D}) (Version: 12.1.3.6 - Apple Inc.)
Java(TM) 6 Update 29 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83216029FF}) (Version: 6.0.290 - Oracle)
Junk Mail filter update (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MEGAsync (HKLM\…\MEGAsync) (Version:  - Mega Limited)
Memory Key Boot Utility (HKLM\…\{D3943D0B-C281-4BF7-9FFB-2A4497986BF9}) (Version: 1.0.8.2 - Smart Modular (MA))
Microsoft .NET Framework 1.1 (HKLM\…\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\…\M2833941) (Version:  - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\…\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Base Smart Card Cryptographic Service Provider Package (HKLM\…\KB909520) (Version:  - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\…\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 2.1.1116.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\…\Wudf01000) (Version:  - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 9.0.1 (x86 en-US) (HKLM\…\Mozilla Firefox 9.0.1 (x86 en-US)) (Version: 9.0.1 - Mozilla)
MyHeritage Family Tree Builder (HKLM\…\Family Tree Builder) (Version: 6.0.0.5634 - MyHeritage.com)
QuickTime (HKLM\…\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)
Segoe UI (Version: 14.0.4327.805 - Microsoft Corp) Hidden
SiSoftware Sandra Lite 2011.SP5 (HKLM\…\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2296}_is1) (Version: 17.80.2011.10 - SiSoftware)
SoundMAX (HKLM\…\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 5.12.01.5246 - Analog Devices)
Spotify (HKU\S-1-5-21-602162358-1303643608-725345543-1005\…\Spotify) (Version: 0.6.4 - )
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
USB 2.0 Wireless LAN Card Utility (HKLM\…\{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}) (Version: 8.1.50 - Dell Inc.)
WebFldrs XP (Version: 9.50.6513 - Microsoft Corporation) Hidden
Windows Genuine Advantage Notifications (KB905474) (HKLM\…\WgaNotify) (Version: 1.9.0040.0 - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\KB892130) (Version:  - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Live Essentials (HKLM\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Management Framework Core (HKLM\…\KB968930) (Version:  - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\…\Windows Media Format Runtime) (Version:  - )
Windows Media Player 11 (HKLM\…\Windows Media Player) (Version:  - )
Windows Search 4.0 (HKLM\…\KB940157) (Version: 04.00.6001.503 - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\MP Scheduled Scan.job => c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-05-01 10:15 - 2014-05-01 10:15 - 00463360 _____ () C:\Documents and Settings\All Users\Application Data\MEGAsync\ShellExtX32.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-04-04 23:14 - 2014-02-10 13:44 - 04592128 _____ () C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
2016-04-04 23:14 - 2014-02-10 13:44 - 00112128 _____ () C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UploadMgr => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-602162358-1303643608-725345543-1005\…\dell.com -> dell.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2003-07-16 12:23 - 2003-07-16 12:23 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-602162358-1303643608-725345543-1005\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Sarah\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: 192.168.1.1
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Family Tree Builder Update => C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: MSMSGS => "C:\Program Files\Messenger\msmsgs.exe" /background
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Spotify => "C:\Documents and Settings\Sarah\Application Data\Spotify\Spotify.exe" /uri spotify:autostart
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
DomainProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe] => Enabled:Windows Live Sync
DomainProfile\AuthorizedApplications: [C:\Program Files\Dropbox\Client\Dropbox.exe] => Enabled:Dropbox
StandardProfile\AuthorizedApplications: [C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\RpcAgentSrv.exe] => Enabled:SiSoftware Deployment Agent Service
StandardProfile\AuthorizedApplications: [C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\WNt500x86\RpcSandraSrv.exe] => Enabled:SiSoftware Sandra Agent Service
StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Sarah\Application Data\Spotify\spotify.exe] => Enabled:Spotify
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Sarah\Application Data\Dropbox\bin\Dropbox.exe] => Enabled:Dropbox
StandardProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe] => Enabled:Windows Live Sync
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:Google Chrome
StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes
StandardProfile\GloballyOpenPorts: [5985:TCP] => Disabled:Windows Remote Management 
StandardProfile\GloballyOpenPorts: [80:TCP] => Disabled:Windows Remote Management - Compatibility Mode (HTTP-In) 
 
==================== Restore Points =========================
 
17-04-2016 10:09:25 Software Distribution Service 3.0
17-04-2016 19:37:44 Software Distribution Service 3.0
18-04-2016 08:58:08 Software Distribution Service 3.0
18-04-2016 12:30:52 Software Distribution Service 3.0
19-04-2016 08:54:54 Software Distribution Service 3.0
20-04-2016 08:42:04 Software Distribution Service 3.0
20-04-2016 19:04:55 Software Distribution Service 3.0
21-04-2016 06:56:26 Software Distribution Service 3.0
21-04-2016 14:20:05 Software Distribution Service 3.0
21-04-2016 14:21:09 Software Distribution Service 3.0
21-04-2016 14:21:40 Software Distribution Service 3.0
22-04-2016 09:55:59 Software Distribution Service 3.0
23-04-2016 15:26:38 Software Distribution Service 3.0
24-04-2016 02:06:06 Software Distribution Service 3.0
25-04-2016 11:20:46 Software Distribution Service 3.0
26-04-2016 16:25:50 Software Distribution Service 3.0
27-04-2016 17:13:39 Software Distribution Service 3.0
28-04-2016 18:20:21 Software Distribution Service 3.0
29-04-2016 20:53:28 Software Distribution Service 3.0
01-05-2016 10:15:12 Software Distribution Service 3.0
02-05-2016 10:52:28 System Checkpoint
02-05-2016 20:03:15 Software Distribution Service 3.0
03-05-2016 20:48:53 System Checkpoint
04-05-2016 08:55:11 Software Distribution Service 3.0
05-05-2016 10:01:17 System Checkpoint
05-05-2016 19:52:26 Software Distribution Service 3.0
06-05-2016 21:01:54 Software Distribution Service 3.0
08-05-2016 08:32:06 Software Distribution Service 3.0
09-05-2016 10:30:13 Software Distribution Service 3.0
10-05-2016 11:45:00 System Checkpoint
11-05-2016 06:44:06 Software Distribution Service 3.0
11-05-2016 13:04:08 Software Distribution Service 3.0
12-05-2016 07:48:30 Software Distribution Service 3.0
13-05-2016 08:25:39 Software Distribution Service 3.0
14-05-2016 08:50:46 Software Distribution Service 3.0
15-05-2016 08:56:58 Software Distribution Service 3.0
15-05-2016 21:06:18 Software Distribution Service 3.0
16-05-2016 21:14:47 System Checkpoint
17-05-2016 05:55:37 Software Distribution Service 3.0
18-05-2016 09:12:29 Software Distribution Service 3.0
19-05-2016 09:36:14 System Checkpoint
19-05-2016 10:13:00 Software Distribution Service 3.0
20-05-2016 10:07:26 Software Distribution Service 3.0
21-05-2016 11:24:33 System Checkpoint
22-05-2016 01:41:16 Software Distribution Service 3.0
23-05-2016 09:31:40 Software Distribution Service 3.0
24-05-2016 09:40:48 System Checkpoint
25-05-2016 11:35:17 Software Distribution Service 3.0
26-05-2016 12:22:48 System Checkpoint
27-05-2016 08:57:46 Software Distribution Service 3.0
28-05-2016 09:41:40 Software Distribution Service 3.0
29-05-2016 10:41:13 Software Distribution Service 3.0
30-05-2016 11:09:43 System Checkpoint
31-05-2016 09:35:50 Software Distribution Service 3.0
01-06-2016 10:13:45 Software Distribution Service 3.0
02-06-2016 13:03:11 System Checkpoint
03-06-2016 06:33:48 Software Distribution Service 3.0
04-06-2016 10:36:22 Software Distribution Service 3.0
05-06-2016 20:35:29 Software Distribution Service 3.0
06-06-2016 21:50:48 Software Distribution Service 3.0
08-06-2016 15:42:34 Software Distribution Service 3.0
10-06-2016 08:26:50 Software Distribution Service 3.0
11-06-2016 10:10:15 Software Distribution Service 3.0
12-06-2016 10:57:41 Software Distribution Service 3.0
13-06-2016 15:04:05 System Checkpoint
15-06-2016 09:40:25 Software Distribution Service 3.0
15-06-2016 15:43:16 Software Distribution Service 3.0
15-06-2016 16:21:37 Software Distribution Service 3.0
16-06-2016 18:05:06 Software Distribution Service 3.0
18-06-2016 01:43:54 Software Distribution Service 3.0
19-06-2016 09:48:04 Software Distribution Service 3.0
20-06-2016 12:36:48 System Checkpoint
22-06-2016 09:06:12 Software Distribution Service 3.0
23-06-2016 09:31:08 Software Distribution Service 3.0
24-06-2016 19:21:10 Software Distribution Service 3.0
25-06-2016 22:23:14 System Checkpoint
26-06-2016 02:24:26 Software Distribution Service 3.0
27-06-2016 02:41:14 System Checkpoint
27-06-2016 18:26:59 Software Distribution Service 3.0
28-06-2016 18:54:33 Software Distribution Service 3.0
29-06-2016 18:57:28 Software Distribution Service 3.0
30-06-2016 18:50:29 Software Distribution Service 3.0
01-07-2016 18:56:39 Software Distribution Service 3.0
02-07-2016 18:57:19 Software Distribution Service 3.0
03-07-2016 02:29:04 Software Distribution Service 3.0
03-07-2016 18:50:06 Software Distribution Service 3.0
04-07-2016 18:57:30 Software Distribution Service 3.0
05-07-2016 18:57:11 Software Distribution Service 3.0
06-07-2016 18:56:47 Software Distribution Service 3.0
08-07-2016 07:28:46 Software Distribution Service 3.0
12-07-2016 21:24:38 Software Distribution Service 3.0
13-07-2016 09:47:34 Software Distribution Service 3.0
14-07-2016 01:20:20 Software Distribution Service 3.0
14-07-2016 09:51:20 Software Distribution Service 3.0
15-07-2016 10:15:18 Software Distribution Service 3.0
15-07-2016 22:17:07 Installed USB 2.0 Wireless LAN Card Utility
16-07-2016 11:17:55 JRT Pre-Junkware Removal
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/16/2016 11:07:27 AM) (Source: MPSampleSubmission) (EventID: 5000) (User: )
Description: EventType avsubmit, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P2 1.1.12902.0, P3 1.225.1565.0, P4 1.225.1565.0, P5 0000000000000000_0000000000000000000000000000000000000000, P6 NIL, P7 NIL, P8 NIL, P9 avsubmit0, P10 avsubmit1.
 
Error: (05/31/2016 09:39:03 AM) (Source: MPSampleSubmission) (EventID: 5000) (User: )
Description: EventType mptelemetry, P1 0x80070670, P2 patchapplication, P3 am bdd, P4 1.1.12745.0, P5 mpsigstub.exe, P6 3.0.8402.0, P7 microsoft security essentials, P8 NIL, P9 mptelemetry0, P10 mptelemetry1.
 
Error: (05/22/2016 07:24:00 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application wlmail.exe, version 14.0.8117.416, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
 
System errors:
=============
Error: (07/15/2016 10:47:41 PM) (Source: 0) (EventID: 7) (User: )
Description: \Device\Harddisk0\D
 
Error: (06/06/2016 09:39:22 PM) (Source: System Error) (EventID: 1003) (User: )
Description: Error code 10000050, parameter1 e3e4b26e, parameter2 00000000, parameter3 bf85fc9e, parameter4 00000001.
 
Error: (06/06/2016 09:38:56 PM) (Source: System Error) (EventID: 1003) (User: )
Description: Error code 000000ca, parameter1 00000001, parameter2 85c20030, parameter3 85d20030, parameter4 00000000.
 
Error: (05/31/2016 09:42:31 AM) (Source: Windows Update Agent) (EventID: 20) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Microsoft Security Essentials - KB2310138 (Definition 1.223.285.0).
 
Error: (05/31/2016 09:39:19 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.223.281.0
 
Update Source: %NT AUTHORITY59
 
Update Stage: 3.0.8402.00
 
Source Path: 3.0.8402.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\SYSTEM
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (04/21/2016 02:21:52 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.217.1197.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 3.0.8402.00
 
Source Path: 3.0.8402.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (04/21/2016 02:21:52 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.217.1197.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 3.0.8402.00
 
Source Path: 3.0.8402.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (04/21/2016 02:21:52 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.217.1197.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 3.0.8402.00
 
Source Path: 3.0.8402.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (04/21/2016 02:21:52 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.217.1197.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 3.0.8402.00
 
Source Path: 3.0.8402.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (04/21/2016 02:21:47 PM) (Source: Windows Update Agent) (EventID: 20) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x800700c1: Definition Update for Microsoft Security Essentials - KB2310138 (Definition 1.217.1832.0).
 
 
==================== Memory info =========================== 
 
Processor:  Intel(R) Pentium(R) 4 CPU 2.80GHz
Percentage of memory in use: 53%
Total physical RAM: 766 MB
Available physical RAM: 353.3 MB
Total Virtual: 2260.76 MB
Available Virtual: 1705.25 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:73.5 GB) (Free:50.55 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive f: (SARAHS TD) (Removable) (Total:14.89 GB) (Free:11.19 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: 0002476D)
Partition 1: (Active) - (Size=73.5 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 14.9 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

 

FRST

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-07-2016

Ran by [removed] (administrator) on SARAH-ET-AL (16-07-2016 11:26:38)
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
[removed]
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1404928 2004-10-14] (Analog Devices, Inc.)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [997920 2011-06-15] (Microsoft Corporation)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-13] (Adobe Systems Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157456 2015-09-12] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2011-10-24] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxsrvc.dll [2005-06-21] (Intel Corporation)
Winlogon\Notify\PRISMAPI.DLL: C:\WINDOWS\system32\PRISMAPI.DLL [2005-12-22] (Conexant Systems, Inc.)
HKU\S-1-5-21-602162358-1303643608-725345543-1005\…\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-18\…\Run: [DWQueuedReporting] => c:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [437160 2007-02-26] (Microsoft Corporation)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Documents and Settings\All Users\Application Data\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Documents and Settings\All Users\Application Data\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Documents and Settings\All Users\Application Data\MEGAsync\ShellExtX32.dll [2014-05-01] ()
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk [2011-11-27]
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless USB 2.0 WLAN Card Utility.lnk [2016-07-15]
ShortcutTarget: Wireless USB 2.0 WLAN Card Utility.lnk -> C:\Program Files\Dell Wireless\PRISMCFG.exe (Dell Inc.)
Startup: C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\MEGAsync.lnk [2016-04-04]
ShortcutTarget: MEGAsync.lnk -> C:\Documents and Settings\All Users\Application Data\MEGAsync\MEGAsync.exe (Mega Limited)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9A53DC7E-5D45-4B2B-A6E5-4E5D96E83B0F}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\S-1-5-21-602162358-1303643608-725345543-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver;=6&ar;=msnhome
HKU\S-1-5-21-602162358-1303643608-725345543-1005\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-11-28] (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class -> {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -> C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-11-28] (Sun Microsystems, Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
 
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Sarah\Application Data\Mozilla\Firefox\Profiles\3729nmn9.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll [2011-12-05] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw.dll [2011-10-05] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2011-11-28] (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-08-03] (Adobe Systems Inc.)
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-11-28] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2011-11-28] [not signed]
 
Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.knoxlib.org/"
CHR Profile: C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-04-04]
CHR Extension: (Google Docs) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-04]
CHR Extension: (Google Drive) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-04]
CHR Extension: (YouTube) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-04]
CHR Extension: (Adblock Plus) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-06-29]
CHR Extension: (Google Sheets) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-04-04]
CHR Extension: (Google Docs Offline) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-04]
CHR Extension: (Disconnect) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo [2016-04-04]
CHR Extension: (Ghostery) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2016-04-04]
CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-04]
CHR Extension: (Gmail) - C:\Documents and Settings\Sarah\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-04]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 JavaQuickStarterService; C:\Program Files\Java\jre6\bin\jqs.exe [153376 2011-11-28] (Sun Microsystems, Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [11736 2011-04-27] (Microsoft Corporation)
S2 PRISMSVC; C:\WINDOWS\system32\PRISMSVC.EXE [61526 2005-12-22] (Conexant Systems, Inc.) [File not signed]
S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\RpcAgentSrv.exe [93848 2008-09-18] (SiSoftware) [File not signed]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [20747 2005-10-12] (Meetinghouse Data Communications) [File not signed]
R2 fssfltr; C:\WINDOWS\System32\DRIVERS\fssfltr_tdi.sys [54760 2010-04-28] (Microsoft Corporation)
R2 HWiNFO32; C:\Program Files\HWiNFO32\HWiNFO32.SYS [21624 2011-09-22] (REALiX™)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [24448 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [170200 2016-07-16] (Malwarebytes)
R1 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [165648 2011-04-18] (Microsoft Corporation)
R1 MpKsl8a894191; c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{65EB9943-61D3-46FB-B3A9-46981B168618}\MpKsl8a894191.sys [39168 2016-07-15] (Microsoft Corporation)
R1 OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [13632 2001-08-22] (Dell Computer Corporation) [File not signed]
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\WNt500x86\Sandra.sys [23112 2009-08-07] (SiSoftware)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-07-16 11:26 - 2016-07-16 11:26 - 00000000 ____D C:\FRST
2016-07-16 11:21 - 2016-07-16 11:21 - 00003408 _____ C:\Documents and Settings\Sarah\Desktop\JRT.txt
2016-07-16 10:23 - 2016-07-16 11:21 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-07-16 10:18 - 2016-07-16 10:18 - 00000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2016-07-16 10:18 - 2016-07-16 10:18 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2016-07-16 10:17 - 2016-07-16 10:18 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-07-16 10:17 - 2016-07-16 10:17 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2016-07-16 10:17 - 2016-03-10 14:09 - 00123264 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-07-16 10:17 - 2016-03-10 14:08 - 00024448 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-07-16 10:14 - 2016-07-16 10:15 - 00003602 _____ C:\Documents and Settings\Sarah\Desktop\Rkill.txt
2016-07-16 09:36 - 2016-07-16 09:37 - 00000000 ____D C:\AdwCleaner
2016-07-15 22:41 - 2016-07-15 22:41 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Dell
2016-07-15 22:40 - 2016-07-15 22:42 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\PCDr
2016-07-15 22:40 - 2016-07-15 22:40 - 00000000 ____D C:\Program Files\Dell Support Center
2016-07-15 22:38 - 2016-07-15 22:38 - 00000000 ____D C:\Program Files\Dell
2016-07-15 22:32 - 2016-07-15 22:43 - 00000000 ____D C:\Documents and Settings\Sarah\Application Data\PCDr
2016-07-15 22:31 - 2016-07-15 22:51 - 00000000 ____D C:\temp
2016-07-15 22:18 - 2016-07-15 22:18 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Prism
2016-07-15 22:17 - 2016-07-15 22:17 - 00000000 ____D C:\Program Files\Dell Wireless
2016-07-15 22:17 - 2016-07-15 22:17 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Dell Wireless
2016-07-15 22:17 - 2005-12-22 20:21 - 00061526 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\PRISMSVC.exe
2016-07-15 22:17 - 2005-12-22 20:15 - 00381014 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\PRISMSVR.exe
2016-07-15 22:17 - 2005-12-22 20:08 - 00450646 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\PRISMAPI.dll
2016-07-15 22:17 - 2005-11-15 12:59 - 00049152 _____ C:\WINDOWS\system32\StopSrvr.exe
2016-07-15 22:17 - 2005-10-12 00:05 - 01396827 _____ (Meetinghouse Data Communications) C:\WINDOWS\system32\PRISME5.dll
2016-07-15 22:17 - 2005-10-12 00:04 - 00020747 _____ (Meetinghouse Data Communications) C:\WINDOWS\system32\Drivers\AegisP.sys
2016-07-15 22:11 - 2016-07-15 22:18 - 00000000 ____D C:\WINDOWS\LastGood
2016-07-15 21:58 - 2016-07-15 21:58 - 00000000 ____D C:\Documents and Settings\Sarah\Start Menu\Programs\Dell
2016-07-15 21:57 - 2016-07-15 22:29 - 00000000 ____D C:\Documents and Settings\Sarah\Local Settings\Application Data\Deployment
2016-07-15 21:47 - 2016-07-15 21:47 - 00031832 _____ (Phoenix Technologies) C:\WINDOWS\system32\Drivers\DrvAgent32.sys
2016-06-28 14:31 - 2016-06-28 14:31 - 00000000 _____ C:\Documents and Settings\Sarah\Desktop\lapbook.txt
2016-06-19 12:01 - 2016-06-19 12:01 - 00000909 _____ C:\Documents and Settings\Sarah\Desktop\Shortcut to IMG_8579.lnk
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-07-16 11:27 - 2011-10-28 23:05 - 00000000 ____D C:\Documents and Settings\Sarah\Local Settings\Temp
2016-07-16 11:25 - 2016-04-04 19:13 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-07-15 22:44 - 2011-10-28 13:29 - 00000000 ___HD C:\WINDOWS\inf
2016-07-15 22:28 - 2003-07-16 12:46 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2016-07-15 22:17 - 2011-10-28 18:05 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-07-15 22:17 - 2011-10-28 17:47 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Temp
2016-07-15 22:11 - 2011-11-27 22:46 - 00000424 ____H C:\WINDOWS\Tasks\MP Scheduled Scan.job
2016-07-15 22:06 - 2016-04-04 22:56 - 00000222 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2016-07-15 22:06 - 2016-04-04 19:13 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-07-15 22:06 - 2011-10-28 23:05 - 00000178 ___SH C:\Documents and Settings\Sarah\ntuser.ini
2016-07-15 22:06 - 2011-10-28 17:47 - 00032528 _____ C:\WINDOWS\SchedLgU.Txt
2016-07-15 22:06 - 2011-10-28 17:41 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-07-13 10:05 - 2016-04-04 20:52 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-07-13 09:50 - 2011-10-30 06:18 - 141983760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-07-08 15:43 - 2016-04-04 22:56 - 00000216 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2016-07-06 20:39 - 2011-11-27 22:45 - 00400552 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-07-05 08:07 - 2016-04-04 22:39 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2016-07-02 12:02 - 2011-10-28 23:05 - 00000000 ___RD C:\Documents and Settings\Sarah\My Documents\My Pictures
 
==================== Files in the root of some directories =======
 
2011-11-27 13:06 - 2011-12-27 08:11 - 0057856 _____ () C:\Documents and Settings\Sarah\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
Some files in TEMP:
====================
C:\Documents and Settings\Sarah\Local Settings\Temp\FP_PL_PFS_INSTALLER_32bit.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
==================== End of FRST.txt ============================

 

JRT

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.7 (07.03.2016)
Operating System: Microsoft Windows XP x86 
Ran by [removed] (Administrator) on Sat 07/16/2016 at 11:17:48.40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 18 
 
Successfully deleted: C:\Documents and Settings\Sarah\Local Settings\Application Data\esupport.com (Folder) 
Successfully deleted: C:\Program Files\mozilla firefox\defaults\pref\itms.js (File) 
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\4T678LAB (Temporary Internet Files Folder) 
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8XAZ01QF (Temporary Internet Files Folder) 
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CDQRG56J (Temporary Internet Files Folder) 
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CF8UHA5J (Temporary Internet Files Folder) 
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IGZ3U892 (Temporary Internet Files Folder) 
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SP2R45I7 (Temporary Internet Files Folder) 
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UUEA115B (Temporary Internet Files Folder) 
Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\V5YCZJYV (Temporary Internet Files Folder) 
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\4T678LAB (Temporary Internet Files Folder) 
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8XAZ01QF (Temporary Internet Files Folder) 
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\CDQRG56J (Temporary Internet Files Folder) 
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\CF8UHA5J (Temporary Internet Files Folder) 
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\IGZ3U892 (Temporary Internet Files Folder) 
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\SP2R45I7 (Temporary Internet Files Folder) 
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UUEA115B (Temporary Internet Files Folder) 
Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\V5YCZJYV (Temporary Internet Files Folder) 
 
 
 
Registry: 1 
 
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value) 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 07/16/2016 at 11:21:10.45
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

 

 

ADWCleaner S1

# AdwCleaner v5.201 - Logfile created 16/07/2016 at 09:37:02
# Updated 30/06/2016 by ToolsLib
# Database : 2016-07-14.1 [Server]
# Operating system : Microsoft Windows XP Service Pack 3 (X86)
# Username : Sarah - SARAH-ET-AL
# Running from : F:\Cleaners for windows computers\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
Service Found : DrvAgent32
 
***** [ Folders ] *****
 
 
***** [ Files ] *****
 
File Found : C:\WINDOWS\system32\drivers\DrvAgent32.sys
 
***** [ DLL ] *****
 
 
***** [ WMI ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Classes\ieplugin.JQSIEStartDetectorImpl
Key Found : HKLM\SOFTWARE\Classes\ieplugin.JQSIEStartDetectorImpl.1
Key Found : HKCU\Software\eSupport.com
Key Found : HKU\S-1-5-21-602162358-1303643608-725345543-1005\Software\eSupport.com
 
***** [ Web browsers ] *****
 
 
*************************
 
C:\AdwCleaner\AdwCleaner[S1].txt - [998 bytes] - [16/07/2016 09:37:02]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1070 bytes] ##########

 

 
 
RKILL
Rkill 2.8.4 by Lawrence Abrams (Grinler)
Copyright 2008-2016 BleepingComputer.com
More Information about Rkill can be found at this link:
 
Program started at: 07/16/2016 10:14:38 AM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * C:\WINDOWS\system32\PRISMSVR.exe (PID: 1392) [WD-HEUR]
 * C:\WINDOWS\system32\PRISMSVC.EXE (PID: 3712) [WD-HEUR]
 * C:\Documents and Settings\Sarah\Local Settings\Apps\2.0\QXC45Y14.A9V\ZDX4WQ79.L7L\dell..tion_6d0a76327dca4869_0007.0006_be49b0d0ac5b5b8d\DellSystemDetect.exe (PID: 3996) [UP-HEUR]
 
3 proccesses terminated!
 
Checking Registry for malware related settings:
 
 * No issues found in the Registry.
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
 
Performing miscellaneous checks:
 
 * Reparse Point/Junctions Found (Most likely legitimate)!
 
     * C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a => C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492 [Dir]
     * C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35 => C:\WINDOWS\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 [Dir]
 
Checking Windows Service Integrity: 
 
 * No issues found.
 
Searching for Missing Digital Signatures: 
 
 * No issues found.
 
Checking HOSTS File: 
 
 * HOSTS file entries found: 
 
  127.0.0.1       localhost
 
Program finished at: 07/16/2016 10:15:57 AM
Execution time: 0 hours(s), 1 minute(s), and 18 seconds(s)

For some reason and for the life of me I gang recall why, but I decided to stop updating Java. There was some conflict with another more important application or something. 

 

Is there a way of keeping the old download or finding this download if the conflict still continues? Just hate to go higher and create a bigger mess. 

There might be an older java version out there somewhere but, the older versions are heavily exploited because of the tools vulnerabilities
…..

I'll have to leave that up to you

 

How much does this computer connect to the internet?,  because Microsoft has stopped support for XP machines.

Seems everything has stopped support for xp. Sad for me. Perhaps the hackers will forget about old versions! ? I didn't think so but I can hope, just can't swing a new one for the kiddies right now.

 

As for this image, I just got this. Chrome forcing an update window. closed browser, got this msg 

 

Ideas. Ill also look into it and post what I find if I find.

 

Thanks. 

 

EDIT*** What I seem to gather is that it is just notice that the bios update and any other update to drivers I did the other day are now causing issue. Not to mention that the HDD is so old it could also be failing. Oh Joy!

 

📎1.jpg

For the Google Chrome update, don't click on the pop up just for security measures

Follow these instructions
Update Google Chrome
https://support.google.com/chrome/answer/95414?co=GENIE.Platform%3DDesktop&hl=en

Now for the blue screen errors

CHKDSK:
  • Click on Start >> double click on My Computer
  • Right click on the icon designated for the hard-drive (commonly C:\ ) and select Properties
  • Now click on the Tools tab.
  • In the Error Checking option click on the tab Check Now
  • When the 'Check Disk (Drive letter / name etc) window pops up select the two available options: Automatically fix file system errors and Scan for and attempt for recovery of bad sectors
  • In the next pop up window that basically explains a reboot is needed for the chkdsk to run click on Yes tab.
Note: Do not reboot yet!.

Disc Cleanup:
click Start >> Run and type cleanmgr in the box and press OK.
  • Ensure the boxes for Temporary Files, Temporary Internet Files and Recycle Bin are checked.
  • You can choose to check other boxes if you wish but they are not required.
  • Click on OK then Yes.
  • Now Reboot(restart) your computer.
Note: Now when your PC restarts and after the POST/RC option(if installed) you will be informed CHKDSK has been scheduled do you wish to cancel etc. Just ignore and let it run/scan.
this scan may take some time.


The below links are from people with similar problems
http://answers.microsoft.com/en-us/windows/forum/windows_vista-hardware/blue-screencheck-with-your-hardware-vendor-for-any/26de1b06-0ef1-465e-8fec-bb61b30ee74b?auth=1
http://www.bleepingcomputer.com/forums/t/338150/unable-to-boot/

The chrome part doesn't work as there is nothing there for me to click. Seems when they removed any help/support for it they removed that button too.

 

 

 

I did the other parts as you said. There was two notices and I cannot recall what they were now. one was something about danger will robbinson danger but outside of that i don't recall. Chrome jumped up to tell me I needed a new browser. 

 

Did you want to see the logs or something? I didn't see any.

No, theres no other logs I need to see.

I found a notice from Google Chrome, end support for Windows XP
https://chrome.googleblog.com/2015/11/updates-to-chrome-platform-support.html


Let's remove tools and quarantine folders
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
**************************

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI