O4:
64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:
64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre7\bin\jp2iexp.dll ()
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clinic-pc ([]* in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 10.10.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6B9FE9ED-DC66-4CB2-A3EB-DB642C74B7CB}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E6EFAFB4-F975-4525-9ACC-3EDD1A3748D1}: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\intu-help-qb4 - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\qbwc - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files (x86)\Intuit\QuickBooks 2011\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{4ffc5fe5-5dbc-11e1-8059-001bb18e1658}\Shell - "" = AutoRun
O33 - MountPoints2\{4ffc5fe5-5dbc-11e1-8059-001bb18e1658}\Shell\AutoRun\command - "" = E:\SISetup.exe
O33 - MountPoints2\{703706bb-0d84-11e1-a6bb-206a8a292e75}\Shell - "" = AutoRun
O33 - MountPoints2\{703706bb-0d84-11e1-a6bb-206a8a292e75}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/02/26 09:30:30 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Acer\Documents\OTL.exe
[2013/02/21 16:10:49 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\Symantec
[2013/02/12 09:07:25 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\{BD8FCE93-9BCC-41B0-93A0-FD6EDF3365C9}
[2013/02/11 09:30:40 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\{56DE1E4A-916A-4171-A1D6-32DF40C03489}
[2013/02/07 12:28:13 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\{7D5ED516-AE71-485E-8D2A-C053B6CD2F42}
[2013/02/05 14:39:13 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\{FEC636FC-5997-462F-B7C2-895E7E25661B}
[2013/01/31 18:34:56 | 000,000,000 | ---D | C] -- C:\Users\Acer\AppData\Local\{AA0C04FC-8A3F-4738-958D-076919FFC823}
[6 C:\Users\Acer\Documents\*.tmp files -> C:\Users\Acer\Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/02/26 09:30:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Acer\Documents\OTL.exe
[2013/02/26 08:47:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/25 16:47:00 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/25 11:11:34 | 000,469,671 | ---- | M] () -- C:\Users\Acer\Documents\em sat score.mht
[2013/02/25 11:08:42 | 000,024,656 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/25 11:08:42 | 000,024,656 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/25 11:01:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/02/25 11:00:58 | 2960,470,016 | -HS- | M] () -- C:\hiberfil.sys
[2013/02/25 08:43:15 | 000,336,162 | ---- | M] () -- C:\Users\Acer\Documents\structural evaluation 181 montcalm.pdf
[2013/02/24 17:42:16 | 000,423,264 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/02/22 15:36:21 | 000,002,256 | ---- | M] () -- C:\{7577B6EC-BBA5-43F5-937D-69F95C8B6F71}
[2013/02/22 12:30:09 | 000,726,444 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/02/22 12:30:09 | 000,624,412 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/02/22 12:30:09 | 000,106,756 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/01/31 10:21:26 | 000,054,047 | ---- | M] () -- C:\Users\Acer\Desktop\qpu5nfsvll_193832698.2[1].jpg
[2013/01/31 10:21:26 | 000,005,614 | ---- | M] () -- C:\Users\Acer\Desktop\qpu5nfsvll_193832368.2[1].jpg
[6 C:\Users\Acer\Documents\*.tmp files -> C:\Users\Acer\Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/02/25 11:11:31 | 000,469,671 | ---- | C] () -- C:\Users\Acer\Documents\em sat score.mht
[2013/02/25 08:43:15 | 000,336,162 | ---- | C] () -- C:\Users\Acer\Documents\structural evaluation 181 montcalm.pdf
[2013/02/22 15:36:04 | 000,002,256 | ---- | C] () -- C:\{7577B6EC-BBA5-43F5-937D-69F95C8B6F71}
[2013/02/01 10:32:19 | 000,054,047 | ---- | C] () -- C:\Users\Acer\Desktop\qpu5nfsvll_193832698.2[1].jpg
[2013/02/01 10:32:12 | 000,005,614 | ---- | C] () -- C:\Users\Acer\Desktop\qpu5nfsvll_193832368.2[1].jpg
[2012/11/15 13:28:42 | 000,102,248 | ---- | C] () -- C:\Users\Acer\GoToAssistDownloadHelper.exe
[2012/01/10 14:37:54 | 000,060,304 | ---- | C] () -- C:\Users\Acer\g2mdlhlpx.exe
[2011/11/15 12:08:36 | 000,207,571 | ---- | C] () -- C:\Windows\hpwins28.dat
[2011/11/14 16:54:47 | 000,000,095 | ---- | C] () -- C:\Windows\QBChanUtil_Trigger.ini
[2011/11/08 12:41:43 | 000,000,267 | ---- | C] () -- C:\Windows\LaunApp.ini
[2011/11/08 12:38:44 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2011/11/08 12:38:44 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2011/11/08 12:38:44 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2011/11/08 12:38:44 | 000,104,796 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2011/11/08 12:38:43 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2011/11/08 12:38:04 | 000,001,412 | ---- | C] () -- C:\Windows\WPatchProgress.ini
[2011/04/08 13:32:40 | 000,000,321 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2011/04/08 13:32:40 | 000,000,271 | ---- | C] () -- C:\Windows\WisPriority.ini
[2011/04/08 13:32:40 | 000,000,168 | ---- | C] () -- C:\Windows\WisLangCode.ini
========== ZeroAccess Check ==========
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 00:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2011/11/08 11:44:55 | 000,000,000 | ---D | M] -- C:\Users\Acer\AppData\Roaming\Barnes & Noble
[2012/06/28 09:47:35 | 000,000,000 | ---D | M] -- C:\Users\Acer\AppData\Roaming\Tific
[2012/01/25 14:48:58 | 000,000,000 | ---D | M] -- C:\Users\Acer\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
< End of report >