This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ad problems in browsers [Solved]

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The add/remove program part gave error messages for the first two you listed, saying something like "there were problems removing this program, it may have already been moved, would you like to remove it from the list?" I clicked yes, although I'm not sure I should have. Trying to remove the torntv.com program caused my computer to freeze and I had to reboot. The following is the OTL log. I will run OTL one more time (post it's reboot) and post it in my next post. All processes killed ========== FILES ========== Folder move failed. C:\Program Files (x86)\TornTV.com scheduled to be moved on reboot. C:\Program Files (x86)\Yontoo folder moved successfully. C:\ProgramData\Tarma Installer\{68F250EA-9638-4DCF-96C4-D68CC340EC48}\Cache folder moved successfully. C:\ProgramData\Tarma Installer\{68F250EA-9638-4DCF-96C4-D68CC340EC48} folder moved successfully. C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Cache folder moved successfully. C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} folder moved successfully. File\Folder C:\Users\All Users\Tarma Installer\{68F250EA-9638-4DCF-96C4-D68CC340EC48} not found. File\Folder C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} not found. C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0 folder moved successfully. C:\Users\JimAngehr\Downloads\Firefox_Setup.exe moved successfully. C:\Users\JimAngehr\Downloads\GoogleChromeExtensionUpdate_m5.exe moved successfully. C:\Users\JimAngehr\Downloads\GoogleChromeExtensionUpdate_m6.exe moved successfully. C:\Users\JimAngehr\Downloads\JazzPlanet)Miles_Davis-The_Complete_Live_at_the_Plugged_Nickel_19658CD_UF_SPG (1).exe moved successfully. C:\Users\JimAngehr\Downloads\JazzPlanet)Miles_Davis-The_Complete_Live_at_the_Plugged_Nickel_19658CD_UF_SPG.exe moved successfully. C:\Users\JimAngehr\Downloads\Miles_Davis_-_Complete_at_the_Plugged_Nickel_(8CD)_(1995).exe moved successfully. File move failed. C:\Windows\WinSxS\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.2.9200.20521_none_2ea2287def6db600\sdbinst.exe scheduled to be moved on reboot. ========== COMMANDS ========== [EMPTYTEMP] User: All Users
Sorry - walked away and forgot.

OTL logfile created on: 7/16/2013 8:47:44 AM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\JimAngehr\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.47 Gb Total Physical Memory | 2.29 Gb Available Physical Memory | 65.96% Memory free
6.97 Gb Paging File | 5.65 Gb Available in Paging File | 81.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 672.51 Gb Total Space | 501.24 Gb Free Space | 74.53% Space Free | Partition Type: NTFS
Drive D: | 25.36 Gb Total Space | 3.02 Gb Free Space | 11.91% Space Free | Partition Type: NTFS
Drive E: | 620.24 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: JIMCOMPUTER | User Name: JimAngehr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/07/09 09:14:09 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
PRC - [2013/07/07 09:00:43 | 004,640,768 | —- | M] (Spotify Ltd) – C:\Users\JimAngehr\AppData\Roaming\Spotify\spotify.exe
PRC - [2013/07/07 09:00:35 | 001,104,384 | —- | M] (Spotify Ltd) – C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2013/05/24 20:47:30 | 027,776,968 | —- | M] (Dropbox, Inc.) – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013/05/09 04:58:30 | 004,858,968 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/05/09 04:58:30 | 000,046,808 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/07/27 21:21:26 | 000,136,488 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2012/07/09 16:40:02 | 000,580,512 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
PRC - [2012/07/09 16:40:02 | 000,035,232 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
PRC - [2012/06/07 23:34:06 | 000,111,120 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
PRC - [2012/03/28 21:34:30 | 000,091,432 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2011/08/26 17:37:18 | 001,342,008 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
PRC - [2006/11/02 21:40:12 | 000,174,656 | —- | M] () – C:\Windows\SysWOW64\PSIService.exe


========== Modules (No Company Name) ==========

MOD - [2013/07/07 09:00:36 | 024,985,600 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\libcef.dll
MOD - [2013/03/13 16:48:52 | 024,978,944 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2012/11/13 19:32:50 | 003,558,400 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2012/06/08 14:34:06 | 000,016,400 | —- | M] () – C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
MOD - [2012/06/07 23:34:06 | 000,627,216 | —- | M] () – C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
MOD - [2012/02/20 21:29:04 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 21:28:42 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll


========== Services (SafeList) ==========

SRV:64bit: - [2013/05/09 04:58:30 | 000,046,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2013/05/04 02:58:02 | 000,470,528 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\netprofmsvc.dll – (netprofm)
SRV:64bit: - [2013/05/04 02:57:05 | 000,179,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\bisrv.dll – (BrokerInfrastructure)
SRV:64bit: - [2013/04/09 00:48:42 | 000,169,472 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\AudioEndpointBuilder.dll – (AudioEndpointBuilder)
SRV:64bit: - [2013/03/01 22:45:07 | 000,171,008 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\TimeBrokerServer.dll – (TimeBroker)
SRV:64bit: - [2013/03/01 22:45:05 | 000,180,224 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\SystemEventsBrokerServer.dll – (SystemEventsBroker)
SRV:64bit: - [2013/01/28 21:57:14 | 000,014,920 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend)
SRV:64bit: - [2013/01/09 19:23:16 | 001,964,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wlidsvc.dll – (wlidsvc)
SRV:64bit: - [2013/01/09 19:22:35 | 000,438,272 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\lsm.dll – (LSM)
SRV:64bit: - [2012/11/06 00:36:55 | 002,675,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll – (PrintNotify)
SRV:64bit: - [2012/09/20 05:10:47 | 002,367,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\WSService.dll – (WSService)
SRV:64bit: - [2012/09/20 02:31:18 | 000,116,736 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\fhsvc.dll – (fhsvc)
SRV:64bit: - [2012/08/23 10:45:42 | 000,029,600 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Windows\SysNative\hpservice.exe – (hpsrv)
SRV:64bit: - [2012/08/09 02:45:58 | 000,239,616 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2012/08/08 13:36:06 | 000,361,984 | —- | M] (Advanced Micro Devices, Inc.) [Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe – (AMD FUEL Service)
SRV:64bit: - [2012/07/25 23:07:47 | 000,065,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wiarpc.dll – (WiaRpc)
SRV:64bit: - [2012/07/25 23:07:42 | 000,263,680 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wcmsvc.dll – (Wcmsvc)
SRV:64bit: - [2012/07/25 23:07:40 | 000,283,648 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\vaultsvc.dll – (VaultSvc)
SRV:64bit: - [2012/07/25 23:07:25 | 000,012,800 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\svsvc.dll – (svsvc)
SRV:64bit: - [2012/07/25 23:06:34 | 000,743,936 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\netlogon.dll – (Netlogon)
SRV:64bit: - [2012/07/25 23:06:33 | 000,161,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\NcaSvc.dll – (NcaSvc)
SRV:64bit: - [2012/07/25 23:06:33 | 000,073,728 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\NcdAutoSetup.dll – (NcdAutoSetup)
SRV:64bit: - [2012/07/25 23:05:55 | 000,059,904 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\keyiso.dll – (KeyIso)
SRV:64bit: - [2012/07/25 23:05:34 | 000,037,376 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\efssvc.dll – (EFS)
SRV:64bit: - [2012/07/25 23:05:28 | 000,207,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\DeviceSetupManager.dll – (DsmSvc)
SRV:64bit: - [2012/07/25 23:05:24 | 000,342,016 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\das.dll – (DeviceAssociationService)
SRV:64bit: - [2012/07/25 23:05:08 | 000,122,368 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\AUInstallAgent.dll – (AllUserInstallAgent)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicvss)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmictimesync)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicshutdown)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicrdv)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmickvpexchange)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicheartbeat)
SRV:64bit: - [2012/07/21 12:30:36 | 000,321,536 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Program Files\IDT\WDM\stacsv64.exe – (STacSV)
SRV:64bit: - [2010/04/14 20:56:24 | 001,052,328 | —- | M] ( ) [Auto | Running] – C:\Windows\SysNative\lxebcoms.exe – (lxeb_device)
SRV - [2013/07/04 14:25:59 | 000,117,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2013/06/23 09:02:05 | 000,256,904 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/11/06 00:36:55 | 002,675,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll – (PrintNotify)
SRV - [2012/08/10 20:53:44 | 000,085,504 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe – (HP Support Assistant Service)
SRV - [2012/07/25 23:20:04 | 000,018,432 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\StorSvc.dll – (StorSvc)
SRV - [2012/07/25 23:18:41 | 000,408,064 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\inetsrv\iisw3adm.dll – (WAS)
SRV - [2012/07/25 23:17:52 | 000,060,416 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\inetsrv\apphostsvc.dll – (AppHostSvc)
SRV - [2012/07/13 21:02:16 | 002,451,456 | —- | M] (Realsil Microelectronics Inc.) [Auto | Running] – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe – (IconMan_R)
SRV - [2012/07/09 16:40:02 | 000,035,232 | —- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe – (HPWMISVC)
SRV - [2010/10/12 13:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2006/11/02 21:40:12 | 000,174,656 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PSIService.exe – (ProtexisLicensing)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/07/07 18:56:36 | 001,030,952 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2013/07/07 18:56:36 | 000,378,944 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2013/07/07 18:56:36 | 000,189,936 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswVmm.sys – (aswVmm)
DRV:64bit: - [2013/05/09 04:59:07 | 000,072,016 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\aswRdr2.sys – (aswRdr)
DRV:64bit: - [2013/05/09 04:59:07 | 000,065,336 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswRvrt.sys – (aswRvrt)
DRV:64bit: - [2013/05/09 04:59:07 | 000,064,288 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2013/05/09 04:59:06 | 000,080,816 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\Drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2013/05/09 04:59:06 | 000,033,400 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2013/05/04 03:34:17 | 000,446,720 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\USBHUB3.SYS – (USBHUB3)
DRV:64bit: - [2013/05/04 03:34:17 | 000,213,248 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\UCX01000.SYS – (UCX01000)
DRV:64bit: - [2013/05/04 03:34:15 | 000,284,416 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\spaceport.sys – (spaceport)
DRV:64bit: - [2013/03/02 06:57:48 | 000,337,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\USBXHCI.SYS – (USBXHCI)
DRV:64bit: - [2013/03/02 06:57:46 | 000,077,544 | —- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\storahci.sys – (storahci)
DRV:64bit: - [2013/03/02 06:45:20 | 000,148,712 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\tpm.sys – (TPM)
DRV:64bit: - [2013/03/02 06:45:19 | 000,194,792 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2013/03/02 06:39:38 | 000,069,864 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\pdc.sys – (pdc)
DRV:64bit: - [2013/02/02 03:25:23 | 000,037,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\BthAvrcpTg.sys – (BthAvrcpTg)
DRV:64bit: - [2013/01/28 21:57:05 | 000,035,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WdBoot.sys – (WdBoot)
DRV:64bit: - [2013/01/28 19:08:22 | 000,230,904 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WdFilter.sys – (WdFilter)
DRV:64bit: - [2013/01/09 21:53:32 | 000,028,904 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\msgpiowin32.sys – (msgpiowin32)
DRV:64bit: - [2012/11/26 23:55:44 | 000,029,952 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\BthhfHid.sys – (bthhfhid)
DRV:64bit: - [2012/11/20 00:54:31 | 000,039,936 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\hidi2c.sys – (hidi2c)
DRV:64bit: - [2012/11/05 23:55:44 | 000,022,528 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\fxppm.sys – (FxPPM)
DRV:64bit: - [2012/10/12 04:08:01 | 000,027,880 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2012/10/11 03:25:48 | 000,056,552 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\sdstor.sys – (sdstor)
DRV:64bit: - [2012/10/11 03:13:49 | 000,058,088 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – C:\Windows\SysNative\Drivers\dam.sys – (dam)
DRV:64bit: - [2012/09/28 11:32:56 | 000,053,760 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2012/09/20 03:55:30 | 000,120,040 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\msgpioclx.sys – (GPIOClx0101)
DRV:64bit: - [2012/09/20 03:55:27 | 003,265,256 | —- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2012/09/20 03:55:24 | 000,533,224 | —- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2012/08/31 10:40:24 | 000,020,800 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\WirelessButtonDriver64.sys – (WirelessButtonDriver)
DRV:64bit: - [2012/08/24 05:38:28 | 000,448,312 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2012/08/24 05:38:28 | 000,043,832 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\Smb_driver_Intel.sys – (SmbDrvI)
DRV:64bit: - [2012/08/24 05:38:26 | 000,041,272 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\Smb_driver_AMDASF.sys – (SmbDrv)
DRV:64bit: - [2012/08/23 10:45:42 | 000,042,400 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\Accelerometer.sys – (Accelerometer)
DRV:64bit: - [2012/08/23 10:45:42 | 000,029,600 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\hpdskflt.sys – (hpdskflt)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2012/08/09 04:03:32 | 010,283,520 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2012/08/09 01:48:20 | 000,368,640 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2012/07/31 15:22:00 | 000,645,952 | —- | M] (Intel Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\iaStorA.sys – (iaStorA)
DRV:64bit: - [2012/07/31 04:04:12 | 000,690,832 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\Rt630x64.sys – (RTL8168)
DRV:64bit: - [2012/07/26 01:26:46 | 000,025,328 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/07/26 01:26:45 | 000,033,792 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\condrv.sys – (condrv)
DRV:64bit: - [2012/07/26 01:00:58 | 000,322,800 | —- | M] (VIA Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\VSTXRAID.SYS – (VSTXRAID)
DRV:64bit: - [2012/07/26 01:00:58 | 000,106,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\VerifierExt.sys – (VerifierExt)
DRV:64bit: - [2012/07/26 01:00:58 | 000,097,008 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\uaspstor.sys – (UASPStor)
DRV:64bit: - [2012/07/26 01:00:57 | 000,077,040 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\acpiex.sys – (acpiex)
DRV:64bit: - [2012/07/26 01:00:55 | 000,064,240 | —- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\mvumis.sys – (mvumis)
DRV:64bit: - [2012/07/26 01:00:55 | 000,030,960 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2012/07/26 01:00:52 | 000,092,400 | —- | M] (LSI Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2012/07/26 01:00:52 | 000,081,136 | —- | M] (LSI Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\lsi_sss.sys – (LSI_SSS)
DRV:64bit: - [2012/07/26 01:00:52 | 000,064,752 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2012/07/26 01:00:51 | 000,113,904 | —- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys – (EhStorTcgDrv)
DRV:64bit: - [2012/07/26 01:00:51 | 000,081,136 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\EhStorClass.sys – (EhStorClass)
DRV:64bit: - [2012/07/26 01:00:49 | 000,258,288 | —- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2012/07/26 01:00:49 | 000,106,736 | —- | M] (LSI) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\3ware.sys – (3ware)
DRV:64bit: - [2012/07/26 01:00:49 | 000,076,016 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2012/07/26 01:00:48 | 000,026,352 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2012/07/26 00:57:54 | 000,361,200 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\clfs.sys – (CLFS)
DRV:64bit: - [2012/07/26 00:54:34 | 000,096,496 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\wfplwfs.sys – (WFPLWFS)
DRV:64bit: - [2012/07/26 00:53:16 | 000,067,824 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\vpci.sys – (vpci)
DRV:64bit: - [2012/07/25 23:17:38 | 000,036,592 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\terminpt.sys – (terminpt)
DRV:64bit: - [2012/07/25 22:29:47 | 000,021,504 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\WSDPrint.sys – (WSDPrintDevice)
DRV:64bit: - [2012/07/25 22:29:14 | 000,010,752 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\mshidumdf.sys – (mshidumdf)
DRV:64bit: - [2012/07/25 22:29:08 | 000,048,640 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\BasicDisplay.sys – (BasicDisplay)
DRV:64bit: - [2012/07/25 22:29:03 | 000,024,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\HyperVideo.sys – (HyperVideo)
DRV:64bit: - [2012/07/25 22:28:52 | 000,029,696 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\BasicRender.sys – (BasicRender)
DRV:64bit: - [2012/07/25 22:27:58 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\vmgencounter.sys – (gencounter)
DRV:64bit: - [2012/07/25 22:27:41 | 000,018,432 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\kdnic.sys – (kdnic)
DRV:64bit: - [2012/07/25 22:27:37 | 000,010,752 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\acpitime.sys – (acpitime)
DRV:64bit: - [2012/07/25 22:27:33 | 000,023,552 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\npsvctrig.sys – (npsvctrig)
DRV:64bit: - [2012/07/25 22:27:29 | 000,019,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WpdUpFltr.sys – (WpdUpFltr)
DRV:64bit: - [2012/07/25 22:27:16 | 000,010,240 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\acpipagr.sys – (acpipagr)
DRV:64bit: - [2012/07/25 22:27:01 | 000,011,776 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\hyperkbd.sys – (hyperkbd)
DRV:64bit: - [2012/07/25 22:26:46 | 000,062,976 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\SerCx.sys – (SerCx)
DRV:64bit: - [2012/07/25 22:26:43 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\SpbCx.sys – (SpbCx)
DRV:64bit: - [2012/07/25 22:26:34 | 000,030,208 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2012/07/25 22:26:13 | 000,051,200 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\bthhfenum.sys – (BthHFEnum)
DRV:64bit: - [2012/07/25 22:25:57 | 000,033,280 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\dmvsc.sys – (dmvsc)
DRV:64bit: - [2012/07/25 22:25:56 | 000,057,344 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2012/07/25 22:25:13 | 000,045,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\wpcfltr.sys – (wpcfltr)
DRV:64bit: - [2012/07/25 22:25:01 | 000,126,464 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\NdisImPlatform.sys – (NdisImPlatform)
DRV:64bit: - [2012/07/25 22:23:53 | 000,068,608 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\mslldp.sys – (MsLldp)
DRV:64bit: - [2012/07/25 22:23:42 | 000,097,792 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\SysNative\Drivers\Ndu.sys – (Ndu)
DRV:64bit: - [2012/07/24 11:44:02 | 003,618,304 | —- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\athw8x.sys – (athr)
DRV:64bit: - [2012/07/24 05:35:12 | 000,079,528 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\amd_sata.sys – (amd_sata)
DRV:64bit: - [2012/07/24 05:35:12 | 000,026,280 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\amd_xata.sys – (amd_xata)
DRV:64bit: - [2012/07/21 12:30:36 | 000,540,160 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\stwrt64.sys – (STHDA)
DRV:64bit: - [2012/07/18 00:59:12 | 000,098,472 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\AtihdW86.sys – (AtiHDAudioService)
DRV:64bit: - [2012/07/03 18:09:08 | 000,269,968 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\RtsP2Stor.sys – (RSP2STOR)
DRV:64bit: - [2012/06/25 13:24:50 | 000,092,536 | —- | M] (CyberLink) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\CLVirtualDrive.sys – (CLVirtualDrive)
DRV:64bit: - [2012/06/23 09:23:38 | 000,199,008 | —- | M] (AppEx Networks Corporation) [Kernel | Auto | Running] – C:\Windows\SysNative\Drivers\appexDrv.sys – (APXACC)
DRV:64bit: - [2012/06/19 10:07:50 | 000,057,000 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\usbfilter.sys – (usbfilter)
DRV:64bit: - [2012/06/02 10:32:26 | 010,627,744 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\igdkmd64.sys – (igfx)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE - HKLM\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://search.aol.com/search/search?q={searchTerms}&s;_it=webpickaol-ff&s;_qt=sb&tb;_uuid=D1E32A0EB1E84CB199BF9D10246EAD1B&tb;_oid=25-04-2013&tb;_mrud=26-04-2013"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1489
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=utf-8&q;="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/07/07 18:56:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/07/04 14:24:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/07/04 14:24:40 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/07/04 14:24:39 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/07/04 14:24:40 | 000,000,000 | —D | M]

[2012/11/01 21:44:34 | 000,000,000 | —D | M] (No name found) – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Extensions
[2013/07/07 19:12:25 | 000,000,000 | —D | M] (No name found) – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\extensions
[2013/07/07 19:05:10 | 000,002,552 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\searchplugins\aol-search.xml
[2013/07/07 09:01:43 | 000,001,988 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\searchplugins\search.xml
[2013/07/04 14:24:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/07/04 14:26:02 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/07/07 18:56:00 | 000,000,000 | —D | M] (avast! Online Security) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Norton Identity Safe (Enabled) = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.2.0.18_0\npcoplgn.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2013/07/13 08:24:25 | 000,000,027 | —- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QuickFinder Scheduler] C:\Program Files (x86)\WordPerfect Office X3\Programs\QFSCHD130.EXE (Corel Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004..\Run: [Spotify] C:\Users\JimAngehr\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004..\Run: [Spotify Web Helper] C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - Startup: C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Open with WordPerfect - C:\Program Files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta ()
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C6BDB04-E01A-40C1-AD9D-37A8A0EE53D6}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/07/14 15:40:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2013/07/14 15:39:29 | 002,347,384 | —- | C] (ESET) – C:\Users\JimAngehr\Desktop\esetsmartinstaller_enu.exe
[2013/07/13 12:45:50 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/07/13 08:46:26 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/07/13 08:12:22 | 000,000,000 | —D | C] – C:\ComboFix
[2013/07/11 09:30:56 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Local\temp
[2013/07/11 08:17:47 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/07/11 08:17:47 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/07/11 08:17:47 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2013/07/11 08:17:47 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/07/11 08:17:28 | 000,000,000 | —D | C] – C:\Qoobox
[2013/07/11 08:17:03 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/07/11 08:14:12 | 005,088,739 | R— | C] (Swearware) – C:\Users\JimAngehr\Desktop\ComboFix.exe
[2013/07/10 18:00:46 | 000,595,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/10 18:00:45 | 000,496,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/10 18:00:37 | 001,838,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/07/10 18:00:36 | 002,842,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/10 18:00:36 | 002,620,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/10 18:00:01 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/10 17:59:55 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/10 17:59:54 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/10 17:59:53 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/10 17:59:53 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/10 17:53:56 | 000,000,000 | —D | C] – C:\_OTL
[2013/07/09 09:14:08 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
[2013/07/08 16:17:27 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/08 16:16:49 | 000,000,000 | —D | C] – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004
[2013/07/08 14:54:34 | 000,688,992 | R— | C] (Swearware) – C:\Users\JimAngehr\Desktop\dds(1).scr
[2013/07/07 18:56:32 | 000,378,944 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/07/07 18:56:32 | 000,072,016 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2013/07/07 18:56:32 | 000,064,288 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2013/07/07 18:56:32 | 000,033,400 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013/07/07 18:56:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013/07/07 18:56:18 | 001,030,952 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/07/07 18:56:18 | 000,080,816 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013/07/07 18:55:43 | 000,041,664 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2013/07/04 14:24:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/07/04 07:43:26 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tssdisai.dll
[2013/06/23 09:01:20 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Local\Adobe
[2013/06/16 09:11:00 | 001,257,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/06/16 09:10:58 | 001,300,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gdi32.dll
[2013/06/16 09:10:55 | 000,888,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\autochk.exe
[2013/06/16 09:10:55 | 000,793,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\autochk.exe
[2013/06/16 09:10:55 | 000,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\untfs.dll
[2013/06/16 09:10:55 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\untfs.dll

========== Files - Modified Within 30 Days ==========

[2013/07/16 08:35:09 | 000,000,924 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/16 08:35:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/16 08:22:25 | 001,587,416 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/16 08:22:25 | 000,417,202 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/16 08:22:25 | 000,006,364 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/16 08:19:46 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/16 08:17:45 | 000,349,016 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/07/16 08:17:27 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
[2013/07/16 08:17:21 | 2981,527,552 | -HS- | M] () – C:\hiberfil.sys
[2013/07/16 08:11:02 | 000,000,928 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/14 15:39:30 | 002,347,384 | —- | M] (ESET) – C:\Users\JimAngehr\Desktop\esetsmartinstaller_enu.exe
[2013/07/13 08:24:25 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/07/12 13:30:05 | 005,088,739 | R— | M] (Swearware) – C:\Users\JimAngehr\Desktop\ComboFix.exe
[2013/07/09 09:14:09 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
[2013/07/08 16:16:15 | 013,399,154 | —- | M] () – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004.zip
[2013/07/08 15:21:46 | 551,744,019 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/08 14:59:34 | 000,377,856 | —- | M] () – C:\Users\JimAngehr\Desktop\glnzpoxp.exe
[2013/07/08 14:54:35 | 000,688,992 | R— | M] (Swearware) – C:\Users\JimAngehr\Desktop\dds(1).scr
[2013/07/07 18:56:37 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys.sum
[2013/07/07 18:56:36 | 001,030,952 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/07/07 18:56:36 | 000,378,944 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/07/07 18:56:36 | 000,189,936 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/07/07 18:56:36 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswSP.sys.sum
[2013/07/07 18:56:36 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswSnx.sys.sum
[2013/07/07 18:56:33 | 000,001,922 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/07/07 18:56:18 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/07/07 08:26:35 | 000,000,372 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJimAngehr.job
[2013/06/27 18:04:51 | 000,693,112 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/27 18:04:51 | 000,078,200 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/06/21 22:39:11 | 000,001,092 | —- | M] () – C:\Users\JimAngehr\Desktop\Continue Vid-Saver Installation.lnk
[2013/06/18 07:45:40 | 000,000,002 | —- | M] () – C:\END

========== Files Created - No Company Name ==========

[2013/07/16 08:17:27 | 000,349,016 | —- | C] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/07/11 08:17:47 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/07/11 08:17:47 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/07/11 08:17:47 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/07/11 08:17:47 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/07/11 08:17:47 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/07/08 16:16:12 | 013,399,154 | —- | C] () – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004.zip
[2013/07/08 14:59:33 | 000,377,856 | —- | C] () – C:\Users\JimAngehr\Desktop\glnzpoxp.exe
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswVmm.sys.sum
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswSP.sys.sum
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswSnx.sys.sum
[2013/07/07 18:56:33 | 000,001,922 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/07/07 18:56:18 | 000,189,936 | —- | C] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/07/07 18:56:18 | 000,065,336 | —- | C] () – C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/06/21 22:39:11 | 000,001,092 | —- | C] () – C:\Users\JimAngehr\Desktop\Continue Vid-Saver Installation.lnk
[2013/06/18 07:45:39 | 000,000,002 | —- | C] () – C:\END
[2013/04/01 13:01:32 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2013/01/09 10:33:21 | 000,200,704 | —- | C] () – C:\Windows\SysWow64\Bwbits50.dll
[2013/01/09 10:33:21 | 000,181,760 | —- | C] () – C:\Windows\SysWow64\patchw32.dll
[2013/01/09 10:33:21 | 000,116,736 | —- | C] () – C:\Windows\SysWow64\patchw.dll
[2013/01/09 10:33:21 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\bwplay.exe
[2013/01/09 10:33:21 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\zlib.dll
[2013/01/09 10:33:21 | 000,020,992 | —- | C] () – C:\Windows\SysWow64\bwntsend.dll
[2013/01/09 10:33:21 | 000,016,896 | —- | C] () – C:\Windows\SysWow64\bwnthook.dll
[2012/11/07 13:02:13 | 000,001,056 | -HS- | C] () – C:\Windows\SysWow64\KGyGaAvL.sys
[2012/11/04 15:22:24 | 000,083,968 | —- | C] () – C:\Windows\SysWow64\OEMLicense.dll
[2012/08/16 23:46:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/08/09 02:10:22 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/08/09 02:10:22 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/08/03 18:40:09 | 000,916,510 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/07/26 04:13:10 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2012/07/26 04:13:09 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 03:21:26 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2012/07/25 21:17:42 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/25 16:37:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2012/07/25 16:28:31 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2012/07/25 16:22:54 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2012/07/25 16:22:54 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2012/07/25 16:22:54 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2012/06/02 10:31:19 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2012/05/10 19:35:16 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2011/09/13 10:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2012/08/17 00:03:34 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/03/06 02:31:28 | 019,758,592 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/03/06 01:03:37 | 017,561,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2012/07/25 23:05:38 | 001,004,544 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2012/07/25 23:18:27 | 000,784,896 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2012/07/25 23:07:41 | 000,455,680 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >
C:\Windows\WinSxS\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.2.9200.20521_none_2ea2287def6db600\sdbinst.exe probably unknown STEALTH.POLY.CRYPT.TSR.DRIVER virus C:\_OTL\MovedFiles\07102013_175356\C_ProgramData\BBRowsE2savve\5179416ce7628.dll a variant of Win32/Adware.MultiPlug.I application C:\_OTL\MovedFiles\07102013_175356\C_ProgramData\EybooikBBriowsue\5179419ef2e8c.dll a variant of Win32/Adware.MultiPlug.I application C:\_OTL\MovedFiles\07102013_175356\C_Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\anokniebcoameopaknmpbhaaoedjajik\1\5179416ce73ca7.54540579.js Win32/Adware.MultiPlug.H application C:\_OTL\MovedFiles\07102013_175356\C_Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niieikgjphnahhnnmdheblakpelnfgaj\1\5179419ef2c4a9.81363360.js Win32/Adware.MultiPlug.H application C:\_OTL\MovedFiles\07162013_081304\C_Program Files (x86)\TornTV.com\uninst.exe Win32/Adware.1ClickDownload.J application C:\_OTL\MovedFiles\07162013_081304\C_Program Files (x86)\Yontoo\YontooIEClient.dll a variant of Win32/Adware.Yontoo.A application C:\_OTL\MovedFiles\07162013_081304\C_Program Files (x86)\Yontoo\YontooLayers.crx JS/Adware.Yontoo.A application C:\_OTL\MovedFiles\07162013_081304\C_ProgramData\Tarma Installer\{68F250EA-9638-4DCF-96C4-D68CC340EC48}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\_OTL\MovedFiles\07162013_081304\C_ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\_OTL\MovedFiles\07162013_081304\C_Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\background.html JS/Adware.Yontoo.A application C:\_OTL\MovedFiles\07162013_081304\C_Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\yl.js JS/Adware.Yontoo.A application C:\_OTL\MovedFiles\07162013_081304\C_Users\JimAngehr\Downloads\Firefox_Setup.exe a variant of Win32/Adware.iBryte.G application C:\_OTL\MovedFiles\07162013_081304\C_Users\JimAngehr\Downloads\GoogleChromeExtensionUpdate_m5.exe multiple threats C:\_OTL\MovedFiles\07162013_081304\C_Users\JimAngehr\Downloads\GoogleChromeExtensionUpdate_m6.exe multiple threats C:\_OTL\MovedFiles\07162013_081304\C_Users\JimAngehr\Downloads\JazzPlanet)Miles_Davis-The_Complete_Live_at_the_Plugged_Nickel_19658CD_UF_SPG (1).exe multiple threats C:\_OTL\MovedFiles\07162013_081304\C_Users\JimAngehr\Downloads\JazzPlanet)Miles_Davis-The_Complete_Live_at_the_Plugged_Nickel_19658CD_UF_SPG.exe multiple threats C:\_OTL\MovedFiles\07162013_081304\C_Users\JimAngehr\Downloads\Miles_Davis_-_Complete_at_the_Plugged_Nickel_(8CD)_(1995).exe multiple threats
Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.

SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.
# AdwCleaner v2.305 - Logfile created 07/18/2013 at 09:05:34 # Updated 11/07/2013 by Xplode # Operating system : Windows 8 (64 bits) # User : JimAngehr - JIMCOMPUTER # Boot Mode : Normal # Running from : C:\Users\JimAngehr\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\END File Deleted : C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\searchplugins\search.xml File Deleted : C:\Users\JimAngehr\Desktop\TornTV.lnk File Deleted : C:\Users\Public\Desktop\eBay.lnk Folder Deleted : C:\Program Files (x86)\Common Files\Software Update Utility Folder Deleted : C:\ProgramData\InstallMate Folder Deleted : C:\ProgramData\SoftSafe Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com Folder Deleted : C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\jetpack ***** [Registry] ***** Key Deleted : HKCU\Software\1ClickDownload Key Deleted : HKCU\Software\AppDataLow\Software\DefaultTab Key Deleted : HKCU\Software\AppDataLow\SProtector Key Deleted : HKCU\Software\Default Tab Key Deleted : HKCU\Software\DefaultTab Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Deleted : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser.1 Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1 Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1 Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1 Key Deleted : HKLM\Software\Default Tab Key Deleted : HKLM\Software\DefaultTab Key Deleted : HKLM\Software\Iminent Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\Software\SProtector Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16537 [OK] Registry is clean. -\\ Mozilla Firefox v22.0 (en-US) File : C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\prefs.js C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\user.js … Deleted ! Deleted : user_pref("FirstSearch.aol_toolbar.search.hasDoneFirst", 57); Deleted : user_pref("browser.search.defaulturl", "hxxp://search.aol.com/search/search?q={searchTerms}&s_it=web[…] -\\ Google Chrome v28.0.1500.72 File : C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [6626 octets] - [18/07/2013 09:05:34] ########## EOF - C:\AdwCleaner[S1].tx
Results of screen317's Security Check version 0.99.70
x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
avast! Antivirus
Windows Defender
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 13
Java version out of Date!
Adobe Flash Player 11.7.700.224
Mozilla Firefox (22.0)
Google Chrome 28.0.1500.71
Google Chrome 28.0.1500.72
````````Process Check: objlist.exe by Laurent````````
AVAST Software Avast AvastUI.exe
AVAST Software Avast AvastSvc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
One thing that I am still noticing that I forgot to check is that Internet Explorer still doesn't seem to work properly. I don't know if it's a problem with the settings or something rather than a virus or what, but if I type an address in the address bar, it won't take me there - it will only stay at the bing start page. If I click on links on the bing start-up page, then I can get to other places, but it still won't let me type alternates in the address bar. I just now tried setting google.com as the start-up page rather than bing, then restarted IE, and am only getting a blank page. If this is not a virus and just some weird setting, that's fine with me - we never use Internet Explorer.
It says that the fix doesn't apply to my operating system (windows 8). Again, I'm happy to just leave it unless it's virus related.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI