AFter running the programs, the ads are still playing. I did run the programs with the Internet Explorer up to see the directions.
OTL Text:
OTL logfile created on: 7/18/2012 11:51:59 AM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\LizDon13\Desktop\Don
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 1.90 Gb Available Physical Memory | 50.78% Memory free
7.50 Gb Paging File | 5.59 Gb Available in Paging File | 74.56% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.66 Gb Total Space | 339.24 Gb Free Space | 75.11% Space Free | Partition Type: NTFS
Drive D: | 5.54 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 3.69 Gb Total Space | 0.03 Gb Free Space | 0.77% Space Free | Partition Type: FAT32
Computer Name: LIZDON13-PC | User Name: LizDon13 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\LizDon13\Desktop\Don\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Windows\Runservice.exe ()
PRC - C:\Program Files (x86)\Norton AntiVirus\Engine\19.7.1.5\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe ()
PRC - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe (Acer Incorporated)
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe ()
MOD - C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyHook.dll ()
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:
64bit: - (Updater Service) – C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe (Acer Group)
SRV:
64bit: - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV:
64bit: - (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (lxdn_device) – C:\Windows\SysNative\lxdncoms.exe ( )
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (LicCtrlService) – C:\Windows\Runservice.exe ()
SRV - (NAV) – C:\Program Files (x86)\Norton AntiVirus\Engine\19.7.1.5\ccSvcHst.exe (Symantec Corporation)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\eMachines Games\eMachines Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (GREGService) – C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:
64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:
64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\symnets.sys (Symantec Corporation)
DRV:
64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\SymEFA64.sys (Symantec Corporation)
DRV:
64bit: - (SymDS) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\SymDS64.sys (Symantec Corporation)
DRV:
64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\Ironx64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\srtsp64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\srtspx64.sys (Symantec Corporation)
DRV:
64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:
64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (ccSet_NAV) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\ccSetx64.sys (Symantec Corporation)
DRV:
64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.7.1.5\Definitions\VirusDefs\20120717.018\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.7.1.5\Definitions\VirusDefs\20120717.018\eng64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.7.1.5\Definitions\IPSDefs\20120717.003\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.7.1.5\Definitions\BASHDefs\20120711.002\BHDrvx64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://emachines.msn.com
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://emachines.msn.com
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:
64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://emachines.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://emachines.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://emachines.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/?PC=msnHomeST&OCID=msnHomepage
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…1I7ADFA_enUS478
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\LizDon13\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.7.1.5\IPSFFPlgn\ [2012/07/12 11:22:10 | 000,000,000 | —D | M]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Bing Bar (Enabled) = C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:
64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\19.7.1.5\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:
64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKCU..\Run: [EA Core] C:\Program Files (x86)\Electronic Arts\EADM\Core.exe (Electronic Arts)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874}
http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinner.com/games/launcher/….0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{068BA458-B45C-47FE-A520-7FA3691B0CDC}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/29 22:57:16 | 000,054,544 | R— | M] (Electronic Arts) - D:\Autorun.exe – [ UDF ]
O32 - AutoRun File - [2008/10/21 18:22:16 | 000,000,045 | R— | M] () - D:\Autorun.inf – [ UDF ]
O33 - MountPoints2\{8f2f7c0b-7b66-11e1-bb54-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{8f2f7c0b-7b66-11e1-bb54-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun.exe – [2009/04/29 22:57:16 | 000,054,544 | R— | M] (Electronic Arts)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/07/18 11:29:07 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\svchost.exe
[2012/07/18 00:41:59 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2012/07/18 00:41:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2012/07/17 23:07:47 | 000,000,000 | —D | C] – C:\Users\LizDon13\AppData\Roaming\Ad-Aware Antivirus
[2012/07/13 12:38:10 | 000,000,000 | —D | C] – C:\Users\LizDon13\AppData\Roaming\Malwarebytes
[2012/07/13 12:37:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/13 12:37:43 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/07/13 12:37:42 | 000,024,904 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/07/13 12:37:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/07/12 11:48:01 | 000,000,000 | —D | C] – C:\Users\LizDon13\Documents\Symantec
[2012/07/12 11:20:43 | 000,175,736 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/07/12 11:20:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2012/07/12 11:20:43 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2012/07/12 11:20:08 | 001,092,728 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\SymEFA64.sys
[2012/07/12 11:20:08 | 000,737,912 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\srtsp64.sys
[2012/07/12 11:20:08 | 000,451,192 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\SymDS64.sys
[2012/07/12 11:20:08 | 000,405,624 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\symnets.sys
[2012/07/12 11:20:08 | 000,190,072 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\Ironx64.sys
[2012/07/12 11:20:08 | 000,167,048 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\ccSetx64.sys
[2012/07/12 11:20:08 | 000,037,496 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NAVx64\1307010.005\srtspx64.sys
[2012/07/12 11:20:04 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NAVx64
[2012/07/12 11:20:04 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NAVx64\1307010.005
[2012/07/12 11:20:03 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton AntiVirus
[2012/07/12 11:20:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton AntiVirus
[2012/07/12 11:06:12 | 000,000,000 | —D | C] – C:\ProgramData\PCSettings
[2012/07/12 08:01:14 | 000,000,000 | —D | C] – C:\Users\LizDon13\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
[2012/07/11 21:11:24 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/07/11 21:11:24 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/07/11 21:11:23 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/07/11 21:11:23 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/07/11 21:11:23 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/07/11 21:11:23 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/07/11 21:11:22 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/07/11 21:11:22 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/07/11 21:11:21 | 002,311,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/07/11 21:11:21 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/07/11 21:11:21 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/07/11 21:11:21 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/07/11 21:11:21 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/07/11 11:02:44 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/07/04 21:09:21 | 000,000,000 | —D | C] – C:\Users\LizDon13\AppData\Local\{402BF6B9-B999-4D69-BCF0-D129B744E982}
[2012/07/04 21:05:47 | 000,000,000 | R–D | C] – C:\Users\LizDon13\Documents\Scanned Documents
[2012/07/04 21:05:47 | 000,000,000 | —D | C] – C:\Users\LizDon13\Documents\Fax
[2012/06/28 14:03:30 | 000,000,000 | —D | C] – C:\Windows\Sun
[2012/06/27 14:55:04 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2012/06/27 14:55:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2012/06/27 14:54:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Oracle
[2012/06/27 14:52:56 | 000,687,504 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2012/06/27 14:52:55 | 000,772,504 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2012/06/27 14:52:55 | 000,227,720 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2012/06/27 14:52:20 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2012/06/27 14:52:20 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2012/06/27 14:52:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2012/06/27 14:51:19 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2012/06/27 14:49:22 | 000,000,000 | -H-D | C] – C:\jexepackres
[2012/06/22 17:32:42 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/22 17:32:42 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/22 17:32:42 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/22 17:32:30 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/22 17:32:30 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/22 17:32:30 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/22 17:32:19 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/22 17:32:19 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
========== Files - Modified Within 30 Days ==========
[2012/07/18 11:35:58 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/18 11:35:58 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/18 11:30:02 | 000,000,412 | —- | M] () – C:\Windows\tasks\eMachines Registration - Reminder Recall task.job
[2012/07/18 11:28:26 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/18 11:28:10 | 000,001,713 | -HS- | M] () – C:\Windows\SysWow64\mmf.sys
[2012/07/18 11:28:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/18 11:28:01 | 3019,399,168 | -HS- | M] () – C:\hiberfil.sys
[2012/07/18 02:15:00 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/18 02:10:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/18 00:58:32 | 000,000,405 | —- | M] () – C:\Windows\wininit.ini
[2012/07/17 20:56:39 | 000,003,288 | —- | M] () – C:\bootsqm.dat
[2012/07/13 12:55:58 | 406,944,098 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/07/13 12:37:47 | 000,001,118 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/12 17:28:28 | 000,008,942 | —- | M] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\VT20120410.034
[2012/07/12 13:17:06 | 000,002,349 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/07/12 11:22:14 | 001,974,627 | —- | M] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\Cat.DB
[2012/07/12 11:20:43 | 000,175,736 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/07/12 11:20:43 | 000,007,488 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/07/12 11:20:43 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/07/12 11:20:36 | 000,002,469 | —- | M] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2012/07/12 11:19:41 | 000,001,265 | —- | M] () – C:\Users\LizDon13\Desktop\Norton Installation Files.lnk
[2012/07/12 05:47:55 | 000,274,320 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/11 19:10:42 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/07/11 19:10:42 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/07/03 13:46:44 | 000,024,904 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/06/27 14:52:06 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2012/06/27 14:52:06 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
========== Files Created - No Company Name ==========
[2012/07/17 20:56:39 | 000,003,288 | —- | C] () – C:\bootsqm.dat
[2012/07/13 12:48:52 | 406,944,098 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/07/13 12:37:46 | 000,001,118 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/12 17:28:42 | 000,008,942 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\VT20120410.034
[2012/07/12 11:20:46 | 001,974,627 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\Cat.DB
[2012/07/12 11:20:43 | 000,007,488 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/07/12 11:20:43 | 000,000,855 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/07/12 11:20:36 | 000,002,469 | —- | C] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2012/07/12 11:20:04 | 000,007,496 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\SymDS64.cat
[2012/07/12 11:20:04 | 000,007,468 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\ccsetx64.cat
[2012/07/12 11:20:04 | 000,007,462 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\srtspx64.cat
[2012/07/12 11:20:04 | 000,007,460 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\SymEFA64.cat
[2012/07/12 11:20:04 | 000,007,458 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\symnet64.cat
[2012/07/12 11:20:04 | 000,007,458 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\srtsp64.cat
[2012/07/12 11:20:04 | 000,007,450 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\iron.cat
[2012/07/12 11:20:04 | 000,004,782 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\SymVTcer.dat
[2012/07/12 11:20:04 | 000,003,434 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\SymEFA.inf
[2012/07/12 11:20:04 | 000,002,852 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\SymDS.inf
[2012/07/12 11:20:04 | 000,001,441 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\SymNet.inf
[2012/07/12 11:20:04 | 000,001,437 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\srtsp64.inf
[2012/07/12 11:20:04 | 000,001,419 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\srtspx64.inf
[2012/07/12 11:20:04 | 000,000,853 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\ccSetx64.inf
[2012/07/12 11:20:04 | 000,000,772 | R— | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\Iron.inf
[2012/07/12 11:20:04 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\NAVx64\1307010.005\isolate.ini
[2012/07/12 08:01:14 | 000,001,265 | —- | C] () – C:\Users\LizDon13\Desktop\Norton Installation Files.lnk
[2012/06/06 12:25:27 | 000,000,405 | —- | C] () – C:\Windows\wininit.ini
[2012/04/02 17:25:12 | 000,743,066 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/04/01 07:45:45 | 000,001,713 | -HS- | C] () – C:\Windows\SysWow64\mmf.sys
[2012/04/01 07:45:43 | 000,048,640 | —- | C] () – C:\Windows\mmfs.dll
[2012/04/01 07:45:43 | 000,002,560 | —- | C] () – C:\Windows\Runservice.exe
========== Custom Scans ==========
< >
< %SYSTEMDRIVE%\*.* >
[2010/08/30 07:51:36 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/07/17 20:56:39 | 000,003,288 | —- | M] () – C:\bootsqm.dat
[2012/07/18 11:28:01 | 3019,399,168 | -HS- | M] () – C:\hiberfil.sys
[2012/07/18 11:28:03 | 4025,868,288 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/09/23 03:32:56 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/04/03 12:25:03 | 000,000,221 | -HS- | M] () – C:\Users\LizDon13\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
CHECKUP LOG
Results of screen317's Security Check version 0.99.43
Windows 7 x64 (UAC is enabled)
Out of date service pack!!
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Norton AntiVirus
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.62.0.1300
JavaFX 2.1.1
Java™ 7 Update 5
Adobe Reader X (10.1.2)
Google Chrome 20.0.1132.47
Google Chrome 20.0.1132.57
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Norton AntiVirus Engine 19.7.1.5 ccSvcHst.exe
Symantec Norton Online Backup NOBuAgent.exe
Symantec Norton Online Backup NOBuClient.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 7%
````````````````````End of Log``````````````````````