This time everything worked okay, so it obviously was to do with Malwarebytes. I used to have the paid-for Pro version. I have an email saying that I paid for that in 2012, but nothing to say that I renewed it in 2013.... I was under the impression that I had done so, but maybe I didn't. So, perhape the problem was somehow caused by that!
Anyway.... here are the logs you requested: -
1)OTL fixes log
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
Service BrowserDefendert stopped successfully!
Service BrowserDefendert deleted successfully!
File C:\Documents and Settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1E3691A2-B51D-4DA8-B072-435E8B77E70F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E3691A2-B51D-4DA8-B072-435E8B77E70F}\ not found.
Prefs.js: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0 removed from extensions.enabledAddons
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected] deleted successfully.
File C:\Program Files\Babylon\Babylon-Pro\Utils\[email protected] not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\KSS not found.
File C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{57c40fd6-1c5d-11e3-984c-00137216c65c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57c40fd6-1c5d-11e3-984c-00137216c65c}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{57c40fd6-1c5d-11e3-984c-00137216c65c}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57c40fd6-1c5d-11e3-984c-00137216c65c}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{57c40fd6-1c5d-11e3-984c-00137216c65c}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57c40fd6-1c5d-11e3-984c-00137216c65c}\ not found.
File L:\Startme.exe not found.
C:\Documents and Settings\User\Application Data\9481 moved successfully.
C:\Documents and Settings\User\Local Settings\Application Data\2631 moved successfully.
C:\Documents and Settings\All Users\Application Data\1548 moved successfully.
C:\Documents and Settings\All Users\Application Data\1477 moved successfully.
C:\Documents and Settings\All Users\Application Data\0359 moved successfully.
C:\Documents and Settings\User\Desktop\Συνάντησα την Ειρήνη στο σούπερμάρκετ.docx moved successfully.
File C:\Documents and Settings\User\Desktop\Συνάντησα την Ειρήνη στο σούπερμάρκετ.docx not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\User\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\User\Desktop\cmd.txt deleted successfully.
C:\Documents and Settings\All Users\Application Data\BrowserDefender folder moved successfully.
File\Folder C:\Program Files\Babylon not found.
File\Folder C:\Program Files\Kaspersky Lab not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Google Chrome cache emptied: 7513027 bytes
User: NetworkService
->Temp folder emptied: 112908 bytes
->Temporary Internet Files folder emptied: 33237 bytes
User: User
->Temp folder emptied: 38971881 bytes
->Temporary Internet Files folder emptied: 28678605 bytes
->FireFox cache emptied: 222915020 bytes
->Google Chrome cache emptied: 6444597 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 977 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 368832 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 95450035 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 181238783 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34318 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 555.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 03062014_142549
Files\Folders moved on Reboot...
File\Folder C:\WINDOWS\temp\_avast_\Webshlock.txt not found!
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
2)AdwCleaner log
# AdwCleaner v3.020 - Report created 06/03/2014 at 14:50:17
# Updated 27/02/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : User - USER-0868A33E33
# Running from : C:\Documents and Settings\User\Desktop\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\zc8wxp68.default-1392919065375\invalidprefs.js
Folder Found : C:\Documents and Settings\LocalService\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\f558bdae769b946
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A0B10EBE-4E51-4CAE-949B-E6B9E7D68CEA}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F511AFDB-726E-4458-90E7-1ECB97406544}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Found : HKLM\SOFTWARE\f558bdae769b946
Key Found : HKLM\Software\mysearchdial
Key Found : HKLM\Software\Tarma Installer
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\webcakeupdater
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs] - hxxp://start.mysearchdial.com/?f=2&a=dnldmsd&cd=2XzuyEtN2Y1L1QzutDtDtCtAyBtBtCyC0CyCyD0C0C0E0EyBtN0D0Tzu0CyDzytDtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=1346160172&ir=
-\\ Mozilla Firefox v27.0.1 (en-GB)
[ File : C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\zc8wxp68.default-1392919065375\prefs.js ]
-\\ Google Chrome v33.0.1750.146
[ File : C:\Documents and Settings\LocalService\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]
[ File : C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]
Found : icon_url
Found : search_url
Found : keyword
*************************
AdwCleaner[R3].txt - [2559 octets] - [06/03/2014 14:50:17]
########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [2619 octets] ##########
3) FRST.txt log
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-03-2014
Ran by User (administrator) on USER-0868A33E33 on 06-03-2014 14:55:04
Running from C:\Documents and Settings\User\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(Trusteer Ltd.) C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.22.5\GoogleCrashHandler.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Trusteer Ltd.) C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
(Microsoft Corporation) C:\WINDOWS\eHome\ehRecvr.exe
(Microsoft Corporation) C:\WINDOWS\eHome\ehSched.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
() C:\WINDOWS\system32\PSIService.exe
(Microsoft Corporation) C:\WINDOWS\ehome\mcrdsvc.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe
(Creative Technology Ltd) C:\WINDOWS\system32\CTHELPER.EXE
(Microsoft Corporation) C:\WINDOWS\eHome\ehmsas.exe
(Creative Technology Ltd) C:\WINDOWS\system32\CTXFIHLP.EXE
(Creative Technology Ltd) C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
(SigmaTel, Inc.) C:\WINDOWS\stsystra.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Dell) C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe
() C:\Program Files\Dell Photo AIO Printer 944\memcard.exe
() C:\Program Files\Nova Development\Greeting Card Factory Deluxe 8.0\ReminderApp.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
() C:\WINDOWS\system32\dlcdcoms.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe
(Dell) C:\Documents and Settings\User\Local Settings\Apps\2.0\EP0VAQM6.NL6\RY7M30ZQ.GD2\dell..tion_0f612f649c4a10af_0005.0005_9914611622934cec\DellSystemDetect.exe
(Spotify Ltd) C:\Documents and Settings\User\Application Data\Spotify\Data\SpotifyWebHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Sony) C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
() C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ehTray] - C:\WINDOWS\ehome\ehtray.exe [64512 2005-08-05] (Microsoft Corporation)
HKLM\...\Run: [CTHelper] - C:\WINDOWS\system32\CTHELPER.EXE [19456 2006-12-12] (Creative Technology Ltd)
HKLM\...\Run: [CTxfiHlp] - C:\WINDOWS\system32\CTXFIHLP.EXE [20480 2006-12-12] (Creative Technology Ltd)
HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [8491008 2007-09-17] (NVIDIA Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.)
HKLM\...\Run: [SigmatelSysTrayApp] - C:\WINDOWS\stsystra.exe [339968 2005-03-22] (SigmaTel, Inc.)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [DLCDCATS] - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll [69632 2005-06-07] ()
HKLM\...\Run: [dlcdmon.exe] - C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe [430080 2005-07-22] (Dell)
HKLM\...\Run: [MemoryCardManager] - C:\Program Files\Dell Photo AIO Printer 944\memcard.exe [282624 2005-06-27] ()
HKLM\...\Run: [ReminderApp] - C:\Program Files\Nova Development\Greeting Card Factory Deluxe 8.0\ReminderApp.exe [144672 2009-10-20] ()
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-13] (AVAST Software)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-06] (Apple Inc.)
HKU\S-1-5-21-220523388-1979792683-1801674531-1003\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-220523388-1979792683-1801674531-1003\...\Run: [DellSystemDetect] - C:\Documents and Settings\User\Local Settings\Apps\2.0\EP0VAQM6.NL6\RY7M30ZQ.GD2\dell..tion_0f612f649c4a10af_0005.0005_9914611622934cec\DellSystemDetect.exe [253952 2014-02-22] (Dell)
HKU\S-1-5-21-220523388-1979792683-1801674531-1003\...\Run: [Spotify Web Helper] - C:\Documents and Settings\User\Application Data\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-02-11] (Spotify Ltd)
HKU\S-1-5-21-220523388-1979792683-1801674531-1003\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-06-03] (Google Inc.)
HKU\S-1-5-21-220523388-1979792683-1801674531-1003\...\Run: [Sony PC Companion] - C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [449760 2013-10-31] (Sony)
Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.my.yahoo.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {1E3691A2-B51D-4DA8-B072-435E8B77E70F} URL =
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate...b?1370086580859
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1370086717752
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 194.168.4.100 194.168.8.100
FireFox:
========
FF ProfilePath: C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\zc8wxp68.default-1392919065375
FF Homepage: hxxp://uk.my.yahoo.com/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: sony.com/MediaGoDetector - C:\Program Files\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazon-en-GB.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\chambers-en-GB.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-en-GB.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-en-GB.xml
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-06-03]
Chrome:
=======
CHR HomePage: hxxp://uk.my.yahoo.com/
CHR DefaultSearchKeyword: delta-search.com
CHR DefaultSearchProvider: Delta Search
CHR DefaultSearchURL: http://www1.delta-se...121240&tsp=4975
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\33.0.1750.117\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\WINDOWS\system32\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Google Docs) - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-03]
CHR Extension: (Google Wallet) - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-06]
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-13] (AVAST Software)
R3 dlcd_device; C:\WINDOWS\system32\dlcdcoms.exe [491520 2005-06-21] ()
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-12-18] (Oracle Corporation)
R2 McrdSvc; C:\WINDOWS\ehome\mcrdsvc.exe [99328 2005-08-05] (Microsoft Corporation)
R2 ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [177704 2007-06-05] ()
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
==================== Drivers (Whitelisted) ====================
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [26136 2013-12-10] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-02-13] (AVAST Software)
R1 AswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [54832 2014-02-13] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2013-12-10] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [775952 2014-02-13] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [410784 2014-02-13] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57672 2014-02-13] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [180248 2014-01-04] ()
S3 ctdvda2k; C:\WINDOWS\System32\drivers\ctdvda2k.sys [340704 2005-07-13] (Creative Technology Ltd)
R1 RapportCerberus_59849; C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_59849.sys [340432 2013-10-28] ()
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1047816 2005-11-16] (SigmaTel, Inc.)
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
NETSVC: MHN -> C:\Windows\System32\mhn.dll (Microsoft Corporation)
==================== One Month Created Files and Folders ========
2014-03-06 14:55 - 2014-03-06 14:55 - 00015482 _____ () C:\Documents and Settings\User\Desktop\FRST.txt
2014-03-06 14:54 - 2014-03-06 14:55 - 00000000 ____D () C:\FRST
2014-03-06 14:53 - 2014-03-06 14:53 - 00002699 _____ () C:\Documents and Settings\User\Desktop\AdwCleaner[R3].txt
2014-03-06 14:49 - 2014-03-06 14:51 - 00000000 ____D () C:\AdwCleaner
2014-03-06 14:39 - 2014-03-06 14:39 - 00009318 _____ () C:\Documents and Settings\User\Desktop\03062014_142549.log
2014-03-06 14:06 - 2014-03-06 14:05 - 00090112 _____ () C:\WINDOWS\Minidump\Mini030614-01.dmp
2014-03-06 13:35 - 2014-03-06 13:36 - 01145344 _____ (Farbar) C:\Documents and Settings\User\Desktop\FRST.exe
2014-03-06 13:34 - 2014-03-06 13:34 - 00080456 _____ (Malwarebytes Corporation) C:\Documents and Settings\User\Desktop\mbam-clean-1.60.2.0003.exe
2014-03-03 20:42 - 2014-03-03 20:42 - 01244192 _____ () C:\Documents and Settings\User\Desktop\AdwCleaner.exe
2014-03-02 15:28 - 2014-03-02 15:41 - 00000618 _____ () C:\Documents and Settings\User\Desktop\checkhd.txt
2014-03-02 15:12 - 2014-03-06 14:06 - 00000000 ____D () C:\WINDOWS\Minidump
2014-03-02 15:12 - 2014-03-02 15:11 - 00090112 _____ () C:\WINDOWS\Minidump\Mini030214-01.dmp
2014-02-28 17:44 - 2014-02-28 17:44 - 00000000 ____D () C:\_OTL
2014-02-27 12:08 - 2014-02-27 12:08 - 00128509 _____ () C:\Documents and Settings\User\Desktop\HtmlReport.zip
2014-02-25 14:02 - 2014-02-25 14:04 - 00000262 _____ () C:\Documents and Settings\User\Desktop\GeeksToGo.url
2014-02-25 04:05 - 2014-03-06 13:03 - 00045003 _____ () C:\WINDOWS\setupapi.log
2014-02-25 01:17 - 2014-02-25 10:01 - 00043532 _____ () C:\Documents and Settings\User\Desktop\Extras.Txt
2014-02-25 01:15 - 2014-03-02 16:19 - 00132852 _____ () C:\Documents and Settings\User\Desktop\OTL.Txt
2014-02-24 23:35 - 2014-02-24 23:35 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\User\Desktop\OTL.exe
2014-02-24 23:17 - 2014-02-24 23:17 - 00012127 _____ () C:\Documents and Settings\User\Desktop\RKreport[0]_S_02242014_231718.txt
2014-02-24 22:56 - 2014-02-24 22:56 - 03818496 _____ () C:\Documents and Settings\User\Desktop\RogueKiller.exe
2014-02-24 20:14 - 2014-02-24 20:22 - 132325736 _____ () C:\Documents and Settings\User\Desktop\setup_11.0.1.1245.x01_2014_02_24_23_41.exe
2014-02-24 19:37 - 2014-02-24 19:37 - 00014144 _____ () C:\Documents and Settings\User\Desktop\HitmanPro_20140224_1936.log
2014-02-24 18:55 - 2014-02-24 18:55 - 00001998 _____ () C:\Documents and Settings\User\Desktop\aswMBR.txt
2014-02-24 18:55 - 2014-02-24 18:55 - 00000512 _____ () C:\Documents and Settings\User\Desktop\MBR.dat
2014-02-24 18:16 - 2014-02-24 18:16 - 00000000 ____D () C:\Documents and Settings\User\Desktop\Dell Diagnostic Scan Results
2014-02-24 16:02 - 2014-02-24 21:37 - 00000000 ____D () C:\Documents and Settings\User\Desktop\KasperskyScanResults_files
2014-02-20 18:33 - 2014-02-20 18:45 - 00000000 ____D () C:\Documents and Settings\User\Desktop\RK_Quarantine
2014-02-20 18:29 - 2014-02-20 18:29 - 04102163 _____ () C:\Documents and Settings\User\Desktop\tdsskiller.zip
2014-02-20 18:29 - 2014-02-20 18:29 - 00000000 ____D () C:\Documents and Settings\User\Desktop\tdsskiller
2014-02-20 17:58 - 2014-02-20 17:58 - 00000000 ____D () C:\Documents and Settings\User\Desktop\Old Firefox Data
2014-02-20 10:46 - 2014-02-20 10:47 - 00000000 ____D () C:\Documents and Settings\User\Desktop\mbar
2014-02-19 22:36 - 2014-02-19 22:37 - 00035528 _____ () C:\Documents and Settings\User\Desktop\cc_20140219_223641.reg
2014-02-19 22:15 - 2014-02-19 22:32 - 00000000 ____D () C:\Program Files\stinger
2014-02-18 17:38 - 2014-02-18 17:38 - 00000000 ____D () C:\Documents and Settings\User\My Documents\Labels
2014-02-17 22:25 - 2014-02-17 22:26 - 00000079 _____ () C:\WINDOWS\wininit.ini
2014-02-17 20:00 - 2014-02-24 19:10 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\HitmanPro
2014-02-17 18:24 - 2014-02-17 18:11 - 00450613 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140217-182408.backup
2014-02-17 18:11 - 2004-08-10 12:00 - 00000734 _____ () C:\WINDOWS\system32\Drivers\etc\hosts.20140217-181129.backup
2014-02-17 17:44 - 2014-02-17 22:54 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
2014-02-17 17:44 - 2014-02-17 22:26 - 00065536 _____ () C:\WINDOWS\system32\config\SpybotSD.evt
2014-02-17 17:44 - 2014-02-17 22:26 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2014-02-17 15:46 - 2014-02-17 15:46 - 00000000 ____D () C:\Program Files\Common Files\Windows Live
2014-02-15 13:01 - 2014-02-15 13:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-14 09:12 - 2014-03-06 13:01 - 00000458 _____ () C:\WINDOWS\Tasks\SystemToolsDailyTest.job
2014-02-14 09:12 - 2014-02-25 04:02 - 00000520 _____ () C:\WINDOWS\Tasks\PCDoctorBackgroundMonitorTask.job
2014-02-14 09:11 - 2014-02-14 09:11 - 00000000 ____D () C:\Program Files\Dell Support Center
2014-02-13 01:08 - 2014-02-13 01:08 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-02-13 00:53 - 2014-02-13 00:53 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2904878$
2014-02-11 13:57 - 2014-02-11 13:57 - 00001542 _____ () C:\Documents and Settings\All Users\Desktop\iTunes.lnk
2014-02-11 13:57 - 2014-02-11 13:57 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
2014-02-11 13:56 - 2014-02-11 13:57 - 00000000 ____D () C:\Program Files\iTunes
2014-02-11 13:56 - 2014-02-11 13:57 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-02-11 13:56 - 2014-02-11 13:56 - 00000000 ____D () C:\Program Files\iPod
2014-02-10 11:35 - 2014-02-10 11:35 - 00107256 _____ (Trusteer Ltd.) C:\WINDOWS\system32\Drivers\RapportKELL.sys
2014-02-08 13:01 - 2014-03-06 14:42 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-02-06 20:40 - 2014-02-15 18:19 - 00000000 ____D () C:\Program Files\Mozilla Firefox.bak
==================== One Month Modified Files and Folders =======
2014-03-06 14:55 - 2014-03-06 14:55 - 00015482 _____ () C:\Documents and Settings\User\Desktop\FRST.txt
2014-03-06 14:55 - 2014-03-06 14:54 - 00000000 ____D () C:\FRST
2014-03-06 14:53 - 2014-03-06 14:53 - 00002699 _____ () C:\Documents and Settings\User\Desktop\AdwCleaner[R3].txt
2014-03-06 14:51 - 2014-03-06 14:49 - 00000000 ____D () C:\AdwCleaner
2014-03-06 14:49 - 2013-06-01 10:46 - 01787659 _____ () C:\WINDOWS\WindowsUpdate.log
2014-03-06 14:42 - 2014-02-08 13:01 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-03-06 14:39 - 2014-03-06 14:39 - 00009318 _____ () C:\Documents and Settings\User\Desktop\03062014_142549.log
2014-03-06 14:39 - 2013-06-04 15:33 - 00000000 ____D () C:\Program Files\Dl_cats
2014-03-06 14:39 - 2013-06-01 10:44 - 00000000 ____D () C:\WINDOWS\Registration
2014-03-06 14:36 - 2013-06-04 15:05 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-03-06 14:36 - 2013-06-03 20:37 - 00000364 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-03-06 14:35 - 2013-06-04 15:05 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-03-06 14:35 - 2013-06-03 20:37 - 00000878 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-06 14:35 - 2013-06-01 10:57 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-03-06 14:32 - 2013-06-07 13:18 - 00001080 _____ () C:\WINDOWS\system32\settingsbkup.sfm
2014-03-06 14:32 - 2013-06-07 13:18 - 00001080 _____ () C:\WINDOWS\system32\settings.sfm
2014-03-06 14:32 - 2013-06-01 10:57 - 00032554 _____ () C:\WINDOWS\SchedLgU.Txt
2014-03-06 14:13 - 2013-06-03 20:37 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-06 14:06 - 2014-03-02 15:12 - 00000000 ____D () C:\WINDOWS\Minidump
2014-03-06 14:05 - 2014-03-06 14:06 - 00090112 _____ () C:\WINDOWS\Minidump\Mini030614-01.dmp
2014-03-06 13:53 - 2013-06-05 23:37 - 00046252 _____ () C:\dlcd.log
2014-03-06 13:40 - 2013-06-05 23:34 - 01614242 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-220523388-1979792683-1801674531-1003-0.dat
2014-03-06 13:40 - 2013-06-05 23:34 - 00311730 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2014-03-06 13:36 - 2014-03-06 13:35 - 01145344 _____ (Farbar) C:\Documents and Settings\User\Desktop\FRST.exe
2014-03-06 13:34 - 2014-03-06 13:34 - 00080456 _____ (Malwarebytes Corporation) C:\Documents and Settings\User\Desktop\mbam-clean-1.60.2.0003.exe
2014-03-06 13:03 - 2014-02-25 04:05 - 00045003 _____ () C:\WINDOWS\setupapi.log
2014-03-06 13:01 - 2014-02-14 09:12 - 00000458 _____ () C:\WINDOWS\Tasks\SystemToolsDailyTest.job
2014-03-05 20:45 - 2004-08-10 12:00 - 00012598 _____ () C:\WINDOWS\system32\wpa.dbl
2014-03-04 12:37 - 2014-01-16 17:16 - 00064106 _____ () C:\Documents and Settings\User\My Documents\Page.mht
2014-03-04 12:23 - 2013-06-03 20:39 - 00001813 _____ () C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2014-03-03 20:42 - 2014-03-03 20:42 - 01244192 _____ () C:\Documents and Settings\User\Desktop\AdwCleaner.exe
2014-03-03 13:26 - 2013-06-13 16:08 - 00042414 _____ () C:\dlcdscan.log
2014-03-02 16:19 - 2014-02-25 01:15 - 00132852 _____ () C:\Documents and Settings\User\Desktop\OTL.Txt
2014-03-02 15:41 - 2014-03-02 15:28 - 00000618 _____ () C:\Documents and Settings\User\Desktop\checkhd.txt
2014-03-02 15:22 - 2013-06-08 09:54 - 00000000 ____D () C:\Documents and Settings\User\My Documents\B) Vince
2014-03-02 15:11 - 2014-03-02 15:12 - 00090112 _____ () C:\WINDOWS\Minidump\Mini030214-01.dmp
2014-02-28 17:44 - 2014-02-28 17:44 - 00000000 ____D () C:\_OTL
2014-02-27 12:08 - 2014-02-27 12:08 - 00128509 _____ () C:\Documents and Settings\User\Desktop\HtmlReport.zip
2014-02-26 22:58 - 2013-06-09 19:52 - 00002473 _____ () C:\Documents and Settings\User\Desktop\Excel.lnk
2014-02-25 22:54 - 2013-11-07 12:27 - 00000000 ____D () C:\Documents and Settings\User\Desktop\Translators
2014-02-25 14:04 - 2014-02-25 14:02 - 00000262 _____ () C:\Documents and Settings\User\Desktop\GeeksToGo.url
2014-02-25 10:50 - 2013-06-01 10:59 - 00000178 ___SH () C:\Documents and Settings\User\ntuser.ini
2014-02-25 10:13 - 2013-06-03 18:07 - 00000284 _____ () C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2014-02-25 10:01 - 2014-02-25 01:17 - 00043532 _____ () C:\Documents and Settings\User\Desktop\Extras.Txt
2014-02-25 04:02 - 2014-02-14 09:12 - 00000520 _____ () C:\WINDOWS\Tasks\PCDoctorBackgroundMonitorTask.job
2014-02-24 23:35 - 2014-02-24 23:35 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\User\Desktop\OTL.exe
2014-02-24 23:17 - 2014-02-24 23:17 - 00012127 _____ () C:\Documents and Settings\User\Desktop\RKreport[0]_S_02242014_231718.txt
2014-02-24 22:56 - 2014-02-24 22:56 - 03818496 _____ () C:\Documents and Settings\User\Desktop\RogueKiller.exe
2014-02-24 21:37 - 2014-02-24 16:02 - 00000000 ____D () C:\Documents and Settings\User\Desktop\KasperskyScanResults_files
2014-02-24 21:18 - 2013-06-03 10:27 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Application Data\Adobe
2014-02-24 21:17 - 2013-12-13 12:44 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-02-24 21:17 - 2013-12-13 12:44 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-02-24 20:22 - 2014-02-24 20:14 - 132325736 _____ () C:\Documents and Settings\User\Desktop\setup_11.0.1.1245.x01_2014_02_24_23_41.exe
2014-02-24 19:37 - 2014-02-24 19:37 - 00014144 _____ () C:\Documents and Settings\User\Desktop\HitmanPro_20140224_1936.log
2014-02-24 19:10 - 2014-02-17 20:00 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\HitmanPro
2014-02-24 18:55 - 2014-02-24 18:55 - 00001998 _____ () C:\Documents and Settings\User\Desktop\aswMBR.txt
2014-02-24 18:55 - 2014-02-24 18:55 - 00000512 _____ () C:\Documents and Settings\User\Desktop\MBR.dat
2014-02-24 18:16 - 2014-02-24 18:16 - 00000000 ____D () C:\Documents and Settings\User\Desktop\Dell Diagnostic Scan Results
2014-02-24 12:22 - 2013-06-04 15:36 - 00000000 ____D () C:\Documents and Settings\User\Application Data\Jasc Software Inc
2014-02-24 12:22 - 2013-06-04 15:35 - 00000000 ____D () C:\Program Files\Jasc Software Inc
2014-02-24 12:18 - 2013-06-04 15:36 - 00000000 ____D () C:\Documents and Settings\User\Start Menu\Programs\Dell Picture Studio 3
2014-02-22 14:44 - 2013-06-05 16:28 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Application Data\Deployment
2014-02-22 09:13 - 2013-09-20 15:37 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Trusteer Endpoint Protection
2014-02-21 22:22 - 2013-06-08 09:58 - 00000000 ____D () C:\Documents and Settings\User\My Documents\C) Matt
2014-02-20 21:53 - 2013-06-03 20:26 - 00000000 ____D () C:\Documents and Settings\User\Desktop\COMPUTER HEALTH
2014-02-20 18:45 - 2014-02-20 18:33 - 00000000 ____D () C:\Documents and Settings\User\Desktop\RK_Quarantine
2014-02-20 18:29 - 2014-02-20 18:29 - 04102163 _____ () C:\Documents and Settings\User\Desktop\tdsskiller.zip
2014-02-20 18:29 - 2014-02-20 18:29 - 00000000 ____D () C:\Documents and Settings\User\Desktop\tdsskiller
2014-02-20 17:58 - 2014-02-20 17:58 - 00000000 ____D () C:\Documents and Settings\User\Desktop\Old Firefox Data
2014-02-20 17:45 - 2013-12-23 00:57 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Internet Helper Anti-phishing
2014-02-20 17:09 - 2013-09-11 16:39 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2014-02-20 15:38 - 2013-06-03 10:50 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\PCDr
2014-02-20 15:37 - 2013-06-05 22:15 - 00000000 ____D () C:\Program Files\My Dell
2014-02-20 10:47 - 2014-02-20 10:46 - 00000000 ____D () C:\Documents and Settings\User\Desktop\mbar
2014-02-20 10:23 - 2013-06-01 09:46 - 00000000 ____D () C:\WINDOWS\Cursors
2014-02-19 22:37 - 2014-02-19 22:36 - 00035528 _____ () C:\Documents and Settings\User\Desktop\cc_20140219_223641.reg
2014-02-19 22:32 - 2014-02-19 22:15 - 00000000 ____D () C:\Program Files\stinger
2014-02-18 17:38 - 2014-02-18 17:38 - 00000000 ____D () C:\Documents and Settings\User\My Documents\Labels
2014-02-18 15:11 - 2013-06-03 20:24 - 00000000 ____D () C:\Documents and Settings\User\Desktop\Chris' Websites
2014-02-18 14:52 - 2013-06-04 16:05 - 00122880 _____ () C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-17 22:54 - 2014-02-17 17:44 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
2014-02-17 22:26 - 2014-02-17 22:25 - 00000079 _____ () C:\WINDOWS\wininit.ini
2014-02-17 22:26 - 2014-02-17 17:44 - 00065536 _____ () C:\WINDOWS\system32\config\SpybotSD.evt
2014-02-17 22:26 - 2014-02-17 17:44 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2014-02-17 18:11 - 2014-02-17 18:24 - 00450613 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140217-182408.backup
2014-02-17 16:19 - 2013-06-01 12:10 - 00000000 ____D () C:\Program Files\Windows Desktop Search
2014-02-17 15:46 - 2014-02-17 15:46 - 00000000 ____D () C:\Program Files\Common Files\Windows Live
2014-02-17 15:45 - 2013-06-01 10:02 - 00629766 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-16 13:36 - 2013-06-03 17:56 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-15 18:19 - 2014-02-06 20:40 - 00000000 ____D () C:\Program Files\Mozilla Firefox.bak
2014-02-15 13:01 - 2014-02-15 13:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-14 09:11 - 2014-02-14 09:11 - 00000000 ____D () C:\Program Files\Dell Support Center
2014-02-14 09:11 - 2013-06-05 22:16 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Dell
2014-02-14 08:24 - 2013-06-08 09:51 - 00000000 ____D () C:\Documents and Settings\User\My Documents\A) Chris
2014-02-14 07:54 - 2013-08-09 11:36 - 00002573 _____ () C:\Documents and Settings\All Users\Desktop\Greeting Card Factory Deluxe.lnk
2014-02-13 14:36 - 2013-06-01 10:43 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-02-13 13:10 - 2014-01-04 21:55 - 00001791 _____ () C:\Documents and Settings\All Users\Desktop\avast! SafeZone.lnk
2014-02-13 13:10 - 2014-01-04 21:55 - 00001731 _____ () C:\Documents and Settings\All Users\Desktop\avast! Pro Antivirus.lnk
2014-02-13 13:10 - 2013-06-03 20:37 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys
2014-02-13 13:09 - 2013-06-03 20:37 - 00775952 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2014-02-13 13:09 - 2013-06-03 20:37 - 00410784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-02-13 13:09 - 2013-06-03 20:37 - 00270240 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-02-13 13:09 - 2013-06-03 20:37 - 00057672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2014-02-13 13:09 - 2013-06-03 20:37 - 00054832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2014-02-13 13:09 - 2013-06-03 20:36 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-02-13 01:08 - 2014-02-13 01:08 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2916036$
2014-02-13 00:58 - 2013-08-14 09:26 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-02-13 00:54 - 2013-06-01 12:34 - 85946576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-02-13 00:53 - 2014-02-13 00:53 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2904878$
2014-02-13 00:53 - 2013-06-01 12:38 - 00000000 ____D () C:\WINDOWS\ie8updates
2014-02-12 22:56 - 2013-07-16 12:07 - 00000396 _____ () C:\Documents and Settings\User\Desktop\Santander Online Banking.url
2014-02-11 14:22 - 2013-06-12 21:07 - 00000000 ____D () C:\Documents and Settings\User\Application Data\Spotify
2014-02-11 13:57 - 2014-02-11 13:57 - 00001542 _____ () C:\Documents and Settings\All Users\Desktop\iTunes.lnk
2014-02-11 13:57 - 2014-02-11 13:57 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
2014-02-11 13:57 - 2014-02-11 13:56 - 00000000 ____D () C:\Program Files\iTunes
2014-02-11 13:57 - 2014-02-11 13:56 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-02-11 13:56 - 2014-02-11 13:56 - 00000000 ____D () C:\Program Files\iPod
2014-02-11 13:56 - 2013-06-03 18:06 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-02-11 13:35 - 2013-06-03 18:06 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Apple
2014-02-10 11:35 - 2014-02-10 11:35 - 00107256 _____ (Trusteer Ltd.) C:\WINDOWS\system32\Drivers\RapportKELL.sys
2014-02-08 14:00 - 2013-06-12 21:08 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Application Data\Spotify
2014-02-06 03:54 - 2009-03-08 03:32 - 00174592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ie4uinit.exe
2014-02-06 03:54 - 2004-08-10 12:00 - 00174592 ____N (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-02-05 23:26 - 2013-06-01 12:39 - 00522240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsdbgui.dll
2014-02-05 23:26 - 2013-06-01 12:38 - 11113472 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieframe.dll
2014-02-05 23:26 - 2013-06-01 12:38 - 02006016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iertutil.dll
2014-02-05 23:26 - 2013-06-01 12:38 - 00743424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedvtool.dll
2014-02-05 23:26 - 2013-06-01 12:38 - 00630272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeeds.dll
2014-02-05 23:26 - 2013-06-01 12:38 - 00247808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieproxy.dll
2014-02-05 23:26 - 2013-06-01 12:38 - 00055296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2014-02-05 23:26 - 2013-06-01 12:38 - 00012800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpshims.dll
2014-02-05 23:26 - 2009-03-08 13:09 - 00387584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedkcs32.dll
2014-02-05 23:26 - 2009-03-08 03:41 - 06021120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtml.dll
2014-02-05 23:26 - 2009-03-08 03:39 - 11113472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-02-05 23:26 - 2009-03-08 03:34 - 01469440 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetcpl.cpl
2014-02-05 23:26 - 2009-03-08 03:34 - 01216000 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\urlmon.dll
2014-02-05 23:26 - 2009-03-08 03:34 - 00920064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wininet.dll
2014-02-05 23:26 - 2009-03-08 03:34 - 00206848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\occache.dll
2014-02-05 23:26 - 2009-03-08 03:34 - 00105984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\url.dll
2014-02-05 23:26 - 2009-03-08 03:34 - 00043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\licmgr10.dll
2014-02-05 23:26 - 2009-03-08 03:33 - 00759296 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\vgx.dll
2014-02-05 23:26 - 2009-03-08 03:33 - 00025600 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsproxy.dll
2014-02-05 23:26 - 2009-03-08 03:33 - 00018944 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\corpol.dll
2014-02-05 23:26 - 2009-03-08 03:32 - 02006016 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-02-05 23:26 - 2009-03-08 03:32 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-02-05 23:26 - 2009-03-08 03:32 - 00611840 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mstime.dll
2014-02-05 23:26 - 2009-03-08 03:31 - 00184320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iepeers.dll
2014-02-05 23:26 - 2009-03-08 03:31 - 00067072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mshtmled.dll
2014-02-05 23:26 - 2009-03-08 03:31 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 06021120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 01469440 ____N (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-02-05 23:26 - 2004-08-10 12:00 - 01216000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 00611840 ____N (Microsoft Corporation) C:\WINDOWS\system32\mstime.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 00387584 ____N (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 00206848 ____N (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 00184320 ____N (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 00067072 ____N (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 00043520 ____N (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 00025600 ____N (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-02-05 23:26 - 2004-08-10 12:00 - 00018944 ____N (Microsoft Corporation) C:\WINDOWS\system32\corpol.dll
2014-02-05 22:24 - 2004-08-10 12:00 - 00385024 ____N (Microsoft Corporation) C:\WINDOWS\system32\html.iec
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe => MD5 is legit
C:\WINDOWS\system32\winlogon.exe => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
C:\WINDOWS\system32\User32.dll => MD5 is legit
C:\WINDOWS\system32\userinit.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================
The Addition.txt log is attached as requested.
I hope I haven't forgotten anything!
Chris.
Attached Files
Edited by Channeal, 06 March 2014 - 12:15 PM.