2013-09-20

I think I may be affected by longfintuna. An IE8 window opened spontaneously with longfintuna.net as the URL. I closed it while the window was still loading. I've run AVG and Microsoft Security Essentials, neither of which found anything. Could you help please?

My system is set to show all files. I've downloaded FRST.exe, have run it, and have pasted FRST.txt: pasting addition.txt results in the maximum length of the post being exceeded.

Many thanks

Julie

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-09-2013

Ran by julie (administrator) on JULIE-VOSTRO on 19-09-2013 16:43:07

Running from C:\Documents and Settings\julie\My Documents

Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)

Internet Explorer Version 8

Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2013\avgrsx.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe

(Trusteer Ltd.) C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe

(Intel Corporation ) C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

(A4Tech Co.,Ltd.) C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe

(A4Tech Co.,Ltd.) C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe

(Intel Corporation) C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Hewlett-Packard) C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe

(Symantec Corporation) D:\Norton SystemWorks 2003\Norton Ghost\GhostStartTrayApp.exe

(Seagate LLC) D:\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe

(SoftPerfect Research) D:\Networx monitor\NetWorx\networx.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe

(Alcatel-Lucent) C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe

(IDT, Inc.) C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe

(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe

(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgui.exe

(Apple Inc.) D:\iTunes\iTunesHelper.exe

(Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe

(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\Presen tationFontCache.exe

(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe

(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe

(OLYMPUS IMAGING CORP.) D:\Olympus Master\MMonitor.exe

(OLYMPUS IMAGING CORP.) D:\Olympus Viewer 2\OV2Monitor.exe

(Nokia) D:\Nokia PC Suite\Nokia PC Suite 7\PCSuite.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe

(SlimWare Utilities, Inc.) C:\Program Files\DriverUpdate\DriverUpdate.exe

(Google Inc.) C:\Documents and Settings\julie\Local Settings\Application Data\Google\Update\1.3.21.153\GoogleCrashHandler.e xe

(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgemcx.exe

(Seagate Technology LLC) D:\Seagate\SeagateManager\Sync\FreeAgentService.ex e

(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

(Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

(Dropbox, Inc.) C:\Documents and Settings\julie\Application Data\Dropbox\bin\Dropbox.exe

(Symantec Corporation) D:\Norton SystemWorks 2003\Norton Ghost\GhostStartService.exe

(Microsoft Corporation) C:\WINDOWS\regedit.exe

(Nero AG) D:\Nero\Nero8\Nero BackItUp\NBService.exe

(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

(Broadcom Corporation.) C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE

(Symantec Corporation) D:\Norton SystemWorks 2003\Norton Utilities\NPROTECT.EXE

(Alcatel-Lucent) C:\Program Files\Common Files\Motive\pcCMService.exe

(Prolific Technology Inc.) C:\WINDOWS\system32\IoctlSvc.exe

(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

(Symantec Corporation) D:\NORTON~1\SPEEDD~1\nopdb.exe

(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

(Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

(Trusteer Ltd.) C:\Program Files\Trusteer\Rapport\bin\RapportService.exe

(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe

(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe

(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe

(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe

(Eyeo GmbH) C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe

(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe

(Microsoft Corporation) C:\WINDOWS\system32\ntvdm.exe

(Farbar) C:\Documents and Settings\julie\Desktop\FSS.exe

(Microsoft Corporation) C:\Program Files\Outlook Express\msimn.exe

(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [iKeyWorks] - C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe [61440 2004-08-31] (A4Tech Co.,Ltd.)

HKLM\...\Run: [WheelMouse] - C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe [147456 2004-09-01] (A4Tech Co.,Ltd.)

HKLM\...\Run: [IntelZeroConfig] - C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [995328 2007-10-08] (Intel Corporation)

HKLM\...\Run: [IntelWireless] - C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [1101824 2007-10-08] (Intel Corporation)

HKLM\...\Run: [NBKeyScan] - D:\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2221352 2008-06-08] (Nero AG)

HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)

HKLM\...\Run: [EEventManager] - C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [102400 2006-10-12] (SEIKO EPSON CORPORATION)

HKLM\...\Run: [GhostStartTrayApp] - D:\Norton SystemWorks 2003\Norton Ghost\GhostStartTrayApp.exe [94208 2002-08-14] (Symantec Corporation)

HKLM\...\Run: [MaxMenuMgr] - D:\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [185640 2009-09-26] (Seagate LLC)

HKLM\...\Run: [] - [x]

HKLM\...\Run: [NetWorx] - D:\Networx monitor\NetWorx\networx.exe [3338448 2013-09-17] (SoftPerfect Research)

HKLM\...\Run: [NeroFilterCheck] - C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [570664 2008-06-19] (Nero AG)

HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft IntelliPoint\ipoint.exe [1797488 2011-01-07] (Microsoft Corporation)

HKLM\...\Run: [OV2_Monitor] - D:\Olympus Viewer 2\FirstStart.exe [54648 2010-11-19] (OLYMPUS IMAGING CORP.)

HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2011-07-05] (Apple Inc.)

HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)

HKLM\...\Run: [Nikon Message Center 2] - C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)

HKLM\...\Run: [btbb_McciTrayApp] - C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe [2011824 2012-11-23] (Alcatel-Lucent)

HKLM\...\Run: [SigmatelSysTrayApp] - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [405504 2000-01-01] (IDT, Inc.)

HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] ()

HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-08-15] (AVG Technologies CZ, s.r.o.)

HKLM\...\Run: [iTunesHelper] - D:\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)

HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995184 2013-07-18] (Microsoft Corporation)

Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)

Winlogon\Notify\WgaLogon: C:\Windows\system32\WgaLogon.dll (Microsoft Corporation)

HKCU\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)

HKCU\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1840424 2008-06-24] (Nero AG)

HKCU\...\Run: [OM2_Monitor] - D:\Olympus Master\MMonitor.exe [95632 2009-11-25] (OLYMPUS IMAGING CORP.)

HKCU\...\Run: [OV2_Monitor] - D:\Olympus Viewer 2\OV2Monitor.exe [230776 2010-11-19] (OLYMPUS IMAGING CORP.)

HKCU\...\Run: [Google Update] - C:\Documents and Settings\julie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [116648 2012-04-03] (Google Inc.)

HKCU\...\Run: [PC Suite Tray] - D:\Nokia PC Suite\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)

HKCU\...\Run: [DriverUpdate] - C:\Program Files\DriverUpdate\DriverUpdate.exe [28551040 2012-08-10] (SlimWare Utilities, Inc.)

HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe [39408 2012-12-20] (Google Inc.)

HKCU\...\Policies\Explorer: [NoDriveAutoRun] 0xFFEFFF03

HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Nero\Lib\NMFirstStart.exe [ 2008-06-24] (Nero AG)

Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk

ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk

ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)

Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk

ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)

Startup: C:\Documents and Settings\julie\Start Menu\Programs\Startup\Dropbox.lnk

ShortcutTarget: Dropbox.lnk -> C:\Documents and Settings\julie\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

BootExecute: autocheck autochk * C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.uk/webhp?rls=ig

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir...ie&ar=iesearch

SearchScopes: HKLM - DefaultScope value is missing.

SearchScopes: HKLM - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms}

SearchScopes: HKCU - DefaultScope {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://search.avg.com/route/?d=4dc432b8&v=6.103.18.1&i=23&tp=chrome&q={searchT erms}&lng={language}&iy=&ychte=us

SearchScopes: HKCU - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://search.avg.com/route/?d=4dc432b8&v=6.103.18.1&i=23&tp=chrome&q={searchT erms}&lng={language}&iy=&ychte=us

BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\s wg.dll (Google Inc.)

BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll (Adblock Plus)

Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File

Toolbar: HKLM - &NetWorx Desk Band - {FEEA54B4-D80F-41C7-87B9-DC08E6D3255F} - D:\NETWOR~1\NetWorx\deskband.dll (SoftPerfect Research)

Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File

Toolbar: HKCU - No Name - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File

Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/sof...iveXPlugin.cab

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File

Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

Chrome:

=======

CHR HomePage: hxxp://www.google.co.uk/

CHR RestoreOnStartup: "hxxp://www.google.co.uk/"

CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ }{google:originalQueryForSuggestion}{google:assist edQueryStats}{google:searchFieldtrialParameter}{go ogle:searchClient}{google:sourceId}{google:instant ExtendedEnabledParameter}{google:omniboxStartMargi nParameter}ie={inputEncoding}

CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldt rialParameter}client={google:suggestClient}&q={sea rchTerms}&{google:cursorPosition}{google:zeroPrefi xUrl}sugkey={google:suggestAPIKeyParameter}

CHR Plugin: (Remoting Viewer) - internal-remoting-viewer

CHR Plugin: (Native Client) - C:\Documents and Settings\julie\Local Settings\Application Data\Google\Chrome\Application\29.0.1547.66\ppGoog leNaClPluginChrome.dll ()

CHR Plugin: (Chrome PDF Viewer) - C:\Documents and Settings\julie\Local Settings\Application Data\Google\Chrome\Application\29.0.1547.66\pdf.dl l ()

CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\julie\Local Settings\Application Data\Google\Chrome\Application\29.0.1547.66\gcswf3 2.dll No File

CHR Plugin: (AVG Internet Security) - C:\Documents and Settings\julie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfme joahla\12.0.0.1901_0\plugins/avgnpss.dll No File

CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)

CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)

CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)

CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)

CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))

CHR Plugin: (Google Update) - C:\Documents and Settings\julie\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File

CHR Plugin: (BrowserPlus (from Yahoo!) v2.9.8) - C:\Documents and Settings\julie\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserpl us_2.9.8.dll (Yahoo! Inc.)

CHR Plugin: (Motive Plugin) - C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)

CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)

CHR Plugin: (Windows Presentation Foundation) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

CHR Plugin: (iTunes Application Detector) - D:\iTunes\Mozilla Plugins\npitunes.dll ()

CHR Extension: (Adblock Plus) - C:\DOCUME~1\julie\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddi lifddb\1.5.5_0

CHR Extension: (Motive Extension) - C:\DOCUME~1\julie\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\edmgmpmklgfbohogafcfobonnk ogchec\1.0_0

CHR Extension: (Chrome In-App Payments service) - C:\DOCUME~1\julie\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccm gmieda\0.0.4.10_0

CHR HKLM\...\Chrome\Extension: [edmgmpmklgfbohogafcfobonnkogchec] - C:\Program Files\Common Files\Motive\extensions\MotiveRequest.crx

CHR StartMenuInternet: Google Chrome - C:\Documents and Settings\julie\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

========================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)

R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.)

R2 FreeAgentGoNext Service; D:\Seagate\SeagateManager\Sync\FreeAgentService.ex e [189736 2009-09-26] (Seagate Technology LLC)

R2 GhostStartService; D:\Norton SystemWorks 2003\Norton Ghost\GhostStartService.exe [200704 2002-08-14] (Symantec Corporation)

S3 HP Port Resolver; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO. EXE [81920 2005-05-20] (Hewlett-Packard Company)

S3 HP Status Server; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID. EXE [73728 2004-10-16] (Hewlett-Packard Company)

R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2013-07-18] (Microsoft Corporation)

R2 Nero BackItUp Scheduler 3; D:\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-06-08] (Nero AG)

R2 NProtectService; D:\Norton SystemWorks 2003\Norton Utilities\NPROTECT.EXE [135168 2002-08-14] (Symantec Corporation)

R2 S24EventMonitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [1183744 2007-10-08] (Intel Corporation )

R2 Speed Disk service; D:\NORTON~1\SPEEDD~1\nopdb.exe [172065 2002-08-14] (Symantec Corporation)

R2 WLANKEEPER; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [356352 2007-10-08] (Intel Corporation)

==================== Drivers (Whitelisted) ====================

R2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [21361 2009-09-22] (Cisco Systems, Inc.)

R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.)

S3 Amps2prt; C:\Windows\System32\DRIVERS\Amps2prt.sys [9984 2004-08-25] (A4Tech Co.,Ltd.)

R2 Aspi32; C:\Windows\System32\Drivers\Aspi32.sys [17005 2002-08-14] (Adaptec)

R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.)

R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.)

R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-09-10] (AVG Technologies CZ, s.r.o.)

R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.)

R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.)

R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.)

R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-09-05] (AVG Technologies CZ, s.r.o.)

R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.)

R3 btaudio; C:\Windows\System32\drivers\btaudio.sys [533152 2000-01-01] (Broadcom Corporation.)

R3 BTDriver; C:\Windows\System32\DRIVERS\btport.sys [37160 2000-01-01] (Broadcom Corporation.)

R3 BTKRNL; C:\Windows\System32\DRIVERS\btkrnl.sys [991264 2000-01-01] (Broadcom Corporation.)

R3 BTWDNDIS; C:\Windows\System32\DRIVERS\btwdndis.sys [156816 2000-01-01] (Broadcom Corporation.)

R3 btwhid; C:\Windows\System32\DRIVERS\btwhid.sys [56992 2000-01-01] (Broadcom Corporation.)

R3 btwmodem; C:\Windows\System32\DRIVERS\btwmodem.sys [37032 2000-01-01] (Broadcom Corporation.)

R3 BTWUSB; C:\Windows\System32\Drivers\btwusb.sys [45984 2000-01-01] (Broadcom Corporation.)

R1 GhPciScan; D:\Norton SystemWorks 2003\Norton Ghost\ghpciscan.sys [5632 2002-08-14] (Symantec Corporation)

S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2009-08-26] (HP)

S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2000-01-01] (HP)

S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2009-08-26] (HP)

R3 HSFHWAZL; C:\Windows\System32\DRIVERS\HSFHWAZL.sys [210688 2000-01-01] (Conexant Systems, Inc.)

R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.sys [985728 2000-01-01] (Conexant Systems, Inc.)

S3 IKFileSec; C:\Windows\system32\drivers\ikfilesec.sys [40840 2008-08-25] (PCTools Research Pty Ltd.)

S3 IKSysFlt; C:\Windows\System32\drivers\iksysflt.sys [66952 2008-08-25] (PCTools Research Pty Ltd.)

S3 IKSysSec; C:\Windows\System32\drivers\iksyssec.sys [81288 2008-08-25] (PCTools Research Pty Ltd.)

R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)

R1 MpKsla85f763f; C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{191C72D0-3856-4D8B-BEC5-1B6A512F28DA}\MpKsla85f763f.sys [40392 2013-09-19] (Microsoft Corporation)

S3 MREMP50; C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [21248 2013-01-22] (Printing Communications Assoc., Inc. (PCAUSA))

R3 MRESP50; C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [20096 2013-01-22] (Printing Communications Assoc., Inc. (PCAUSA))

R3 NETw4x32; C:\Windows\System32\DRIVERS\NETw4x32.sys [2236032 2007-09-26] (Intel Corporation)

R1 networx; C:\Windows\System32\drivers\networx.sys [54400 2013-09-13] (NetFilterSDK.com)

R3 NPDriver; C:\WINDOWS\system32\Drivers\NPDRIVER.SYS [34578 2002-08-14] (Symantec Corporation)

R1 PQNTDrv; C:\Windows\System32\Drivers\PQNTDrv.sys [4228 2002-09-16] (PowerQuest Corporation)

R1 PSSDK42; C:\WINDOWS\system32\Drivers\pssdk42.sys [38976 2010-06-30] (microOLAP Technologies LTD)

R1 RapportCerberus_56758; C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\b aseline\RapportCerberus32_56758.sys [330960 2013-09-07] ()

R1 RapportEI; C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys [148688 2013-09-10] (Trusteer Ltd.)

R1 RapportPG; C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys [222416 2013-09-10] (Trusteer Ltd.)

R2 s24trans; C:\Windows\System32\DRIVERS\s24trans.sys [12288 2007-08-27] (Intel Corporation)

R3 STHDA; C:\Windows\System32\drivers\sthda.sys [1229949 2000-01-01] (IDT, Inc.)

S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13024 2013-09-19] ()

R3 SymEvent; C:\Program Files\Symantec\SYMEVENT.SYS [73224 2002-08-29] (Symantec Corporation)

R3 ubohci; C:\Windows\System32\DRIVERS\ubohci.sys [77056 2005-07-27] (Unibrain S.A.)

R2 ubsbm; C:\Windows\System32\DRIVERS\ubsbm.sys [14080 2005-07-27] (Unibrain S.A.)

R2 ubumapi; C:\Windows\System32\DRIVERS\ubumapi.sys [36352 2005-07-27] (Unibrain S.A.)

S3 cpuz132; \??\C:\DOCUME~1\julie\LOCALS~1\Temp\cpuz132\cpuz13 2_x32.sys [x]

S4 IntelIde; No ImagePath

S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]

S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]

U5 QDFSDRV; C:\Windows\System32\Drivers\QDFSDRV.sys [13792 2002-08-13] (Symantec Corporation)

U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)

S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [x]

U1 WS2IFSL;

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-09-19 16:42 - 2013-09-19 16:42 - 01083535 _____ (Farbar) C:\Documents and Settings\julie\My Documents\FRST.exe

2013-09-19 16:42 - 2013-09-19 16:42 - 00000000 ____D C:\FRST

2013-09-19 16:29 - 2013-09-19 16:35 - 00000384 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job

2013-09-19 16:29 - 2013-09-19 16:29 - 00000366 ____H C:\WINDOWS\Tasks\MpIdleTask.job

2013-09-19 16:21 - 2013-05-02 16:28 - 00238872 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe

2013-09-19 16:19 - 2013-09-19 16:19 - 00001945 _____ C:\WINDOWS\epplauncher.mif

2013-09-19 16:19 - 2013-09-19 16:19 - 00001698 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk

2013-09-19 16:18 - 2013-09-19 16:19 - 00000000 ____D C:\Program Files\Microsoft Security Client

2013-09-19 16:14 - 2013-09-19 16:14 - 11233112 _____ (Microsoft Corporation) C:\Documents and Settings\julie\My Documents\mseinstall.exe

2013-09-19 16:10 - 2013-09-19 16:19 - 00000000 ____D C:\WINDOWS\LastGood

2013-09-19 15:59 - 2013-09-19 16:02 - 00000000 ____D C:\AdwCleaner

2013-09-19 11:55 - 2013-09-19 11:55 - 00001643 _____ C:\Documents and Settings\julie\Desktop\FSS.txt

2013-09-19 11:30 - 2013-09-19 11:31 - 00001272 _____ C:\Documents and Settings\julie\My Documents\FSS.txt

2013-09-19 11:28 - 2013-09-19 11:28 - 00358923 _____ (Farbar) C:\Documents and Settings\julie\Desktop\FSS.exe

2013-09-19 11:27 - 2013-09-19 11:27 - 01039554 _____ C:\Documents and Settings\julie\My Documents\AdwCleaner.exe

2013-09-19 10:00 - 2013-09-19 10:00 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adblock Plus for IE

2013-09-18 11:55 - 2013-09-19 12:08 - 00000000 ____D C:\Documents and Settings\julie\Local Settings\Application Data\Adblock Plus for IE

2013-09-18 11:52 - 2013-09-18 18:07 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Package Cache

2013-09-18 11:52 - 2013-09-18 11:52 - 00000000 ____D C:\Program Files\Adblock Plus for IE

2013-09-18 11:52 - 2013-09-18 11:52 - 00000000 ____D C:\Documents and Settings\julie\Application Data\Adblock Plus for IE

2013-09-17 09:26 - 2013-09-17 09:26 - 00000000 __SHD C:\Documents and Settings\NetworkService\PrivacIE

2013-09-17 09:26 - 2013-09-17 09:26 - 00000000 ____D C:\Documents and Settings\NetworkService\Application Data\Macromedia

2013-09-17 09:26 - 2013-09-17 09:26 - 00000000 ____D C:\Documents and Settings\NetworkService\Application Data\Adobe

2013-09-15 18:26 - 2013-09-15 18:26 - 00000000 ____D C:\WINDOWS\system32\Trusteer

2013-09-15 18:26 - 2013-09-15 18:26 - 00000000 ____D C:\Documents and Settings\julie\Desktop\Trusteer

2013-09-14 10:28 - 2013-09-19 10:00 - 00000092 _____ C:\Documents and Settings\NetworkService\Application Data\WB.CFG

2013-09-14 10:28 - 2013-09-19 10:00 - 00000005 _____ C:\Documents and Settings\NetworkService\Application Data\WBPU-TTL.DAT

2013-09-13 13:39 - 2013-09-19 16:10 - 00009722 _____ C:\WINDOWS\setupapi.log

2013-09-13 13:29 - 2013-09-13 13:29 - 00014347 _____ C:\WINDOWS\KB2870699-IE8.log

2013-09-13 13:29 - 2013-09-13 13:29 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876315$

2013-09-13 13:28 - 2013-09-13 13:29 - 00026822 _____ C:\WINDOWS\iis6.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00024731 _____ C:\WINDOWS\FaxSetup.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00011824 _____ C:\WINDOWS\ocgen.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00011284 _____ C:\WINDOWS\tsoc.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00008215 _____ C:\WINDOWS\comsetup.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00007568 _____ C:\WINDOWS\msmqinst.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00006793 _____ C:\WINDOWS\KB2876315.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00004974 _____ C:\WINDOWS\ntdtcsetup.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00004560 _____ C:\WINDOWS\updspapi.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00004332 _____ C:\WINDOWS\netfxocm.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00001700 _____ C:\WINDOWS\MedCtrOC.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00001374 _____ C:\WINDOWS\imsins.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00001374 _____ C:\WINDOWS\imsins.BAK

2013-09-13 13:28 - 2013-09-13 13:29 - 00001368 _____ C:\WINDOWS\ocmsn.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00001244 _____ C:\WINDOWS\tabletoc.log

2013-09-13 13:28 - 2013-09-13 13:29 - 00001236 _____ C:\WINDOWS\msgsocm.log

2013-09-13 13:28 - 2013-09-13 13:28 - 00006359 _____ C:\WINDOWS\KB2876217.log

2013-09-13 13:28 - 2013-09-13 13:28 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876217$

2013-09-13 13:28 - 2013-09-13 13:28 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2864063$

2013-09-13 13:28 - 2013-09-13 13:28 - 00000000 _____ C:\WINDOWS\setuperr.log

2013-09-13 13:28 - 2013-09-13 13:28 - 00000000 _____ C:\WINDOWS\setupact.log

2013-09-13 13:26 - 2013-09-13 13:28 - 00006257 _____ C:\WINDOWS\KB2864063.log

2013-09-13 09:56 - 2013-09-13 09:56 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\AVG

2013-09-12 10:26 - 2013-09-15 18:28 - 00000120 _____ C:\Documents and Settings\julie\Application Data\WB.CFG

2013-09-12 10:26 - 2013-09-15 18:28 - 00000005 _____ C:\Documents and Settings\julie\Application Data\WBPU-TTL.DAT

2013-09-10 23:18 - 2013-09-10 23:18 - 00097008 _____ (Trusteer Ltd.) C:\WINDOWS\system32\Drivers\RapportKELL.sys

2013-09-10 20:31 - 2013-09-10 20:31 - 00000914 _____ C:\Documents and Settings\julie\Desktop\Continue Zip Opener Installation.lnk

2013-09-10 20:28 - 2013-09-19 16:28 - 00000408 _____ C:\WINDOWS\Tasks\At2.job

2013-09-10 20:26 - 2013-09-19 16:26 - 00000408 _____ C:\WINDOWS\Tasks\At1.job

2013-09-10 20:26 - 2013-09-10 20:26 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Open It!

2013-09-07 14:18 - 2013-09-18 18:11 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Trusteer Endpoint Protection

2013-09-07 00:17 - 2013-09-19 16:06 - 02211120 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

2013-09-07 00:09 - 2013-09-13 13:25 - 00000000 ____D C:\WINDOWS\system32\MRT

2013-09-07 00:09 - 2013-09-07 00:09 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$

2013-09-07 00:02 - 2013-09-07 00:02 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$

2013-09-07 00:02 - 2013-09-07 00:02 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$

2013-09-07 00:01 - 2013-09-07 00:01 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$

2013-09-07 00:01 - 2013-09-07 00:01 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$

2013-09-06 22:12 - 2013-09-13 09:58 - 00000000 ____D C:\Documents and Settings\julie\My Documents\TOTD

2013-09-02 18:52 - 2013-09-17 18:44 - 00000630 _____ C:\Documents and Settings\julie\Desktop\2013-11 Tosca (2).xls.lnk

2013-08-25 10:28 - 2013-09-19 16:10 - 00000448 _____ C:\WINDOWS\Tasks\DriverUpdate Scan.job

==================== One Month Modified Files and Folders =======

2013-09-19 16:42 - 2013-09-19 16:42 - 01083535 _____ (Farbar) C:\Documents and Settings\julie\My Documents\FRST.exe

2013-09-19 16:42 - 2013-09-19 16:42 - 00000000 ____D C:\FRST

2013-09-19 16:35 - 2013-09-19 16:29 - 00000384 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job

2013-09-19 16:29 - 2013-09-19 16:29 - 00000366 ____H C:\WINDOWS\Tasks\MpIdleTask.job

2013-09-19 16:28 - 2013-09-10 20:28 - 00000408 _____ C:\WINDOWS\Tasks\At2.job

2013-09-19 16:26 - 2013-09-10 20:26 - 00000408 _____ C:\WINDOWS\Tasks\At1.job

2013-09-19 16:26 - 2009-09-22 15:19 - 01609698 _____ C:\WINDOWS\WindowsUpdate.log

2013-09-19 16:20 - 2004-08-04 11:00 - 00000617 _____ C:\WINDOWS\win.ini

2013-09-19 16:19 - 2013-09-19 16:19 - 00001945 _____ C:\WINDOWS\epplauncher.mif

2013-09-19 16:19 - 2013-09-19 16:19 - 00001698 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk

2013-09-19 16:19 - 2013-09-19 16:18 - 00000000 ____D C:\Program Files\Microsoft Security Client

2013-09-19 16:19 - 2013-09-19 16:10 - 00000000 ____D C:\WINDOWS\LastGood

2013-09-19 16:15 - 2012-11-22 16:49 - 00000884 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

2013-09-19 16:14 - 2013-09-19 16:14 - 11233112 _____ (Microsoft Corporation) C:\Documents and Settings\julie\My Documents\mseinstall.exe

2013-09-19 16:11 - 2011-10-27 10:48 - 00000000 ____D C:\Documents and Settings\julie\Application Data\Dropbox

2013-09-19 16:10 - 2013-09-13 13:39 - 00009722 _____ C:\WINDOWS\setupapi.log

2013-09-19 16:10 - 2013-08-25 10:28 - 00000448 _____ C:\WINDOWS\Tasks\DriverUpdate Scan.job

2013-09-19 16:10 - 2011-10-27 10:55 - 00000000 ___RD C:\Documents and Settings\julie\My Documents\Dropbox

2013-09-19 16:09 - 2012-08-18 11:26 - 00013024 _____ C:\WINDOWS\system32\Drivers\SWDUMon.sys

2013-09-19 16:09 - 2009-09-24 13:06 - 00000412 _____ C:\WINDOWS\Tasks\Symantec NetDetect.job

2013-09-19 16:09 - 2009-09-22 16:01 - 00000159 _____ C:\WINDOWS\wiadebug.log

2013-09-19 16:09 - 2009-09-22 16:01 - 00000050 _____ C:\WINDOWS\wiaservc.log

2013-09-19 16:09 - 2004-08-04 11:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl

2013-09-19 16:07 - 2012-11-22 16:49 - 00000880 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

2013-09-19 16:07 - 2009-09-22 15:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT

2013-09-19 16:06 - 2013-09-07 00:17 - 02211120 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

2013-09-19 16:06 - 2012-04-03 13:31 - 00000978 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1417001333-682003330-1003UA.job

2013-09-19 16:06 - 2009-09-22 15:24 - 00000178 ___SH C:\Documents and Settings\julie\ntuser.ini

2013-09-19 16:06 - 2009-09-22 15:24 - 00000000 ____D C:\Documents and Settings\julie

2013-09-19 16:06 - 2009-09-22 15:23 - 00032632 _____ C:\WINDOWS\SchedLgU.Txt

2013-09-19 16:02 - 2013-09-19 15:59 - 00000000 ____D C:\AdwCleaner

2013-09-19 15:52 - 2012-04-06 09:15 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job

2013-09-19 14:06 - 2012-04-03 13:31 - 00000926 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1417001333-682003330-1003Core.job

2013-09-19 12:08 - 2013-09-18 11:55 - 00000000 ____D C:\Documents and Settings\julie\Local Settings\Application Data\Adblock Plus for IE

2013-09-19 11:55 - 2013-09-19 11:55 - 00001643 _____ C:\Documents and Settings\julie\Desktop\FSS.txt

2013-09-19 11:31 - 2013-09-19 11:30 - 00001272 _____ C:\Documents and Settings\julie\My Documents\FSS.txt

2013-09-19 11:28 - 2013-09-19 11:28 - 00358923 _____ (Farbar) C:\Documents and Settings\julie\Desktop\FSS.exe

2013-09-19 11:27 - 2013-09-19 11:27 - 01039554 _____ C:\Documents and Settings\julie\My Documents\AdwCleaner.exe

2013-09-19 10:00 - 2013-09-19 10:00 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adblock Plus for IE

2013-09-19 10:00 - 2013-09-14 10:28 - 00000092 _____ C:\Documents and Settings\NetworkService\Application Data\WB.CFG

2013-09-19 10:00 - 2013-09-14 10:28 - 00000005 _____ C:\Documents and Settings\NetworkService\Application Data\WBPU-TTL.DAT

2013-09-19 09:43 - 2009-12-21 18:20 - 00000000 ____D C:\Documents and Settings\julie\Local Settings\Application Data\CutePDF Writer

2013-09-19 09:32 - 2010-10-19 12:30 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\MFAData

2013-09-18 18:11 - 2013-09-07 14:18 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Trusteer Endpoint Protection

2013-09-18 18:07 - 2013-09-18 11:52 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Package Cache

2013-09-18 13:29 - 2010-06-30 01:00 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\NetWorx

2013-09-18 11:52 - 2013-09-18 11:52 - 00000000 ____D C:\Program Files\Adblock Plus for IE

2013-09-18 11:52 - 2013-09-18 11:52 - 00000000 ____D C:\Documents and Settings\julie\Application Data\Adblock Plus for IE

2013-09-18 11:44 - 2012-08-18 11:58 - 00000000 ____D C:\Documents and Settings\julie\Application Data\Audacity

2013-09-17 20:00 - 2009-09-27 16:59 - 00000356 _____ C:\WINDOWS\PhotMask.ini

2013-09-17 18:44 - 2013-09-02 18:52 - 00000630 _____ C:\Documents and Settings\julie\Desktop\2013-11 Tosca (2).xls.lnk

2013-09-17 17:38 - 2013-04-09 09:22 - 00000000 ____D C:\Documents and Settings\julie\My Documents\To read

2013-09-17 09:26 - 2013-09-17 09:26 - 00000000 __SHD C:\Documents and Settings\NetworkService\PrivacIE

2013-09-17 09:26 - 2013-09-17 09:26 - 00000000 ____D C:\Documents and Settings\NetworkService\Application Data\Macromedia

2013-09-17 09:26 - 2013-09-17 09:26 - 00000000 ____D C:\Documents and Settings\NetworkService\Application Data\Adobe

2013-09-17 09:26 - 2009-09-22 15:23 - 00000000 __SHD C:\Documents and Settings\NetworkService

2013-09-16 18:01 - 2012-12-13 15:50 - 00104034 _____ C:\WINDOWS\HPFins09.dat

2013-09-16 18:01 - 2009-09-23 17:27 - 00006267 ____C C:\Documents and Settings\All Users\Application Data\hpzinstall.log

2013-09-15 18:28 - 2013-09-12 10:26 - 00000120 _____ C:\Documents and Settings\julie\Application Data\WB.CFG

2013-09-15 18:28 - 2013-09-12 10:26 - 00000005 _____ C:\Documents and Settings\julie\Application Data\WBPU-TTL.DAT

2013-09-15 18:26 - 2013-09-15 18:26 - 00000000 ____D C:\WINDOWS\system32\Trusteer

2013-09-15 18:26 - 2013-09-15 18:26 - 00000000 ____D C:\Documents and Settings\julie\Desktop\Trusteer

2013-09-15 18:26 - 2012-04-03 13:31 - 00000000 ____D C:\Documents and Settings\julie\Local Settings\Application Data\Google

2013-09-14 23:19 - 2011-11-13 19:54 - 00000020 ____H C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT

2013-09-14 20:09 - 2013-06-17 22:59 - 00000000 ____D C:\Documents and Settings\julie\Desktop\Print

2013-09-13 13:38 - 2009-09-22 15:56 - 00288496 _____ C:\WINDOWS\system32\FNTCACHE.DAT

2013-09-13 13:37 - 2009-09-23 09:39 - 00000164 _____ C:\WINDOWS\POSTIT.INI

2013-09-13 13:29 - 2013-09-13 13:29 - 00014347 _____ C:\WINDOWS\KB2870699-IE8.log

2013-09-13 13:29 - 2013-09-13 13:29 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876315$

2013-09-13 13:29 - 2013-09-13 13:28 - 00026822 _____ C:\WINDOWS\iis6.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00024731 _____ C:\WINDOWS\FaxSetup.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00011824 _____ C:\WINDOWS\ocgen.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00011284 _____ C:\WINDOWS\tsoc.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00008215 _____ C:\WINDOWS\comsetup.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00007568 _____ C:\WINDOWS\msmqinst.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00006793 _____ C:\WINDOWS\KB2876315.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00004974 _____ C:\WINDOWS\ntdtcsetup.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00004560 _____ C:\WINDOWS\updspapi.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00004332 _____ C:\WINDOWS\netfxocm.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00001700 _____ C:\WINDOWS\MedCtrOC.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00001374 _____ C:\WINDOWS\imsins.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00001374 _____ C:\WINDOWS\imsins.BAK

2013-09-13 13:29 - 2013-09-13 13:28 - 00001368 _____ C:\WINDOWS\ocmsn.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00001244 _____ C:\WINDOWS\tabletoc.log

2013-09-13 13:29 - 2013-09-13 13:28 - 00001236 _____ C:\WINDOWS\msgsocm.log

2013-09-13 13:29 - 2009-11-05 11:31 - 00000000 ____D C:\WINDOWS\ie8updates

2013-09-13 13:28 - 2013-09-13 13:28 - 00006359 _____ C:\WINDOWS\KB2876217.log

2013-09-13 13:28 - 2013-09-13 13:28 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876217$

2013-09-13 13:28 - 2013-09-13 13:28 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2864063$

2013-09-13 13:28 - 2013-09-13 13:28 - 00000000 _____ C:\WINDOWS\setuperr.log

2013-09-13 13:28 - 2013-09-13 13:28 - 00000000 _____ C:\WINDOWS\setupact.log

2013-09-13 13:28 - 2013-09-13 13:26 - 00006257 _____ C:\WINDOWS\KB2864063.log

2013-09-13 13:25 - 2013-09-07 00:09 - 00000000 ____D C:\WINDOWS\system32\MRT

2013-09-13 13:21 - 2009-09-27 15:17 - 76725432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

2013-09-13 12:52 - 2012-04-06 09:15 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe

2013-09-13 12:52 - 2011-11-25 09:42 - 00071048 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl

2013-09-13 09:58 - 2013-09-06 22:12 - 00000000 ____D C:\Documents and Settings\julie\My Documents\TOTD

2013-09-13 09:56 - 2013-09-13 09:56 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\AVG

2013-09-13 09:56 - 2013-04-02 15:36 - 00000702 _____ C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk

2013-09-13 09:41 - 2011-03-15 22:55 - 00054400 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\networx.sys

2013-09-10 23:18 - 2013-09-10 23:18 - 00097008 _____ (Trusteer Ltd.) C:\WINDOWS\system32\Drivers\RapportKELL.sys

2013-09-10 20:31 - 2013-09-10 20:31 - 00000914 _____ C:\Documents and Settings\julie\Desktop\Continue Zip Opener Installation.lnk

2013-09-10 20:26 - 2013-09-10 20:26 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Open It!

2013-09-10 01:34 - 2011-12-23 13:32 - 00022328 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsshimx.sys

2013-09-09 23:04 - 2009-09-23 16:07 - 00000131 _____ C:\Documents and Settings\julie\Application Data\default.pls

2013-09-09 23:04 - 2009-09-23 16:06 - 00000069 _____ C:\WINDOWS\NeroDigital.ini

2013-09-07 15:21 - 2011-11-13 19:54 - 00000020 ____H C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT

2013-09-07 14:27 - 2009-09-22 19:37 - 00000000 ____D C:\WINDOWS\Microsoft.NET

2013-09-07 00:09 - 2013-09-07 00:09 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$

2013-09-07 00:05 - 2009-09-22 15:58 - 00570868 _____ C:\WINDOWS\system32\PerfStringBackup.INI

2013-09-07 00:02 - 2013-09-07 00:02 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$

2013-09-07 00:02 - 2013-09-07 00:02 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$

2013-09-07 00:01 - 2013-09-07 00:01 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$

2013-09-07 00:01 - 2013-09-07 00:01 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$

2013-09-07 00:01 - 2009-09-26 12:51 - 00048810 ____C C:\WINDOWS\system32\TZLog.log

2013-09-06 19:49 - 2009-09-24 12:53 - 00000262 _____ C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job

2013-09-06 19:47 - 2010-07-01 10:45 - 00000000 ____D C:\Documents and Settings\julie\Desktop\Frequently used files

2013-09-06 11:11 - 2012-04-03 13:32 - 00002284 _____ C:\Documents and Settings\julie\Desktop\Google Chrome.lnk

2013-09-05 01:43 - 2010-09-07 03:48 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgrkx86.sys

2013-09-02 16:41 - 2009-09-22 15:17 - 00000000 ____D C:\Program Files\Outlook Express

2013-08-27 11:40 - 2009-09-24 16:16 - 00001351 _____ C:\WINDOWS\pstudio.ini

Files to move or delete:

====================

C:\Windows\Tasks\At1.job

C:\Windows\Tasks\At2.job

Some content of TEMP:

====================

C:\Documents and Settings\julie\Local Settings\Temp\ICReinstall_NetworxSetup.exe

C:\Documents and Settings\julie\Local Settings\Temp\Quarantine.exe

C:\Documents and Settings\julie\Local Settings\Temp\uninst1.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== End Of Log ============================

Show more