benbar36
Topic Starter
Not always, but often enough to be annoying, a couple of rundll32.exe processes run the CPU to 100%. Per instructions in the forum I have run the OTL scan. Please help.
OTL logfile created on: 11/2/2011 12:26:53 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Carrie\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 73.86% Memory free
5.99 Gb Paging File | 4.66 Gb Available in Paging File | 77.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 227.00 Gb Total Space | 143.35 Gb Free Space | 63.15% Space Free | Partition Type: NTFS
Computer Name: CARRIE-PC | User Name: Carrie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Carrie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11c_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASC.exe (IObit)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe (IObit)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe (Trend Micro Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\Scan.dll ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\sqlite3.dll ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\NtfsData.dll ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\DiskMap.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (LPDSVC) – C:\Windows\SysNative\lpdsvc.dll (Microsoft Corporation)
SRV:64bit: - (CISVC) – C:\Windows\SysNative\CISVC.EXE (Microsoft Corporation)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdvancedSystemCareService) – C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (bcm44amd64) – C:\Windows\SysNative\drivers\b44amd64.sys (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (OEM02Dev) – C:\Windows\SysNative\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\drivers\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\drivers\rimspx64.sys (REDC)
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\drivers\rimmpx64.sys (REDC)
DRV:64bit: - (OEM02Vfx) – C:\Windows\SysNative\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6B 25 ED 60 A5 D7 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {9427041a-a8dc-4d06-9a68-93873486e957} - No CLSID value found
IE - HKCU\..\URLSearchHook: {da566842-d620-41bf-8a10-149cfa14035d} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/10/25 14:40:59 | 000,000,000 | —D | M]
[2011/07/31 20:53:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Carrie\AppData\Roaming\Mozilla\Extensions
========== Chrome ==========
CHR - Extension: No name found = C:\Users\Carrie\AppData\Local\Google\Chrome\User Data\Default\Extensions\neghaibmbjedngldjldidfoobmkkfkle\2_0\
O1 HOSTS File: ([2011/10/05 22:28:57 | 000,437,925 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15060 more lines…
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Play Pickle Text) - {02F0243C-2E71-4a1a-A790-6C30888119D0} - Reg Error: Value error. File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/US/Core/Pla…_IKEA_Win32.cab (20-20 3D Viewer for IKEA)
O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} https://ehelp.nelnet.net/netagent/objects/custappx3.CAB (eAssist NetAgent Customer ActiveX Control version 3)
O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} https://lowes.2020.net/planner/Core/Player/…yerAX_Win32.cab (20-20 3D Viewer)
O16 - DPF: {8A5BE387-D09A-4DFA-A56B-DCB89BD11468} https://lowes.2020.net/planner/Core/Player/…X_WEB_Win32.cab (20-20 3D Viewer for WEB)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4A990216-4EF3-419D-A2F7-DEE72BAF67C2}: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/02 00:24:05 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Carrie\Desktop\OTL.exe
[2011/11/01 22:53:07 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/11/01 22:53:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/11/01 20:53:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/11/01 20:53:11 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Roaming\IObit
[2011/11/01 20:53:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2011/11/01 20:50:03 | 030,515,552 | —- | C] (IObit ) – C:\Users\Carrie\Desktop\asc-setup.exe
[2011/10/31 21:24:35 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{CF1DB14D-AB59-4A3E-B088-20B8B6C8EC8F}
[2011/10/31 21:24:02 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{6298ADD4-8D03-4DC0-83F6-9629D77F6AD0}
[2011/10/30 16:27:26 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/10/27 15:57:59 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{5DE4C264-1112-4635-8B98-CC0B98D20345}
[2011/10/27 15:57:38 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{DEED43CE-3B58-4708-B827-9A63CD9AD655}
[2011/10/24 14:45:08 | 000,000,000 | —D | C] – C:\Users\Carrie\Desktop\Skunk
[2011/10/24 14:25:25 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{60DE18B1-2FB1-449A-AFBD-042028FAE9D0}
[2011/10/24 14:25:11 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{3C086A37-E415-4280-BA59-B548DD4CACE3}
[2011/10/21 16:58:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\GamingWonderlandEI
[2011/10/19 16:36:59 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{C548EBE3-2D4D-4E41-B4C1-82C3E85BB57C}
[2011/10/19 16:36:47 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{589FA694-6D53-4CBC-A370-24BE7D7729C7}
[2011/10/18 09:14:27 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{BEABAF05-E5D9-4B53-B1B2-877557AA1B48}
[2011/10/18 09:14:16 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{05D27152-30A5-40D6-8567-84361FF57A9B}
[2011/10/16 13:22:04 | 000,000,000 | -HSD | C] – C:\Windows\SysNative\%APPDATA%
[2011/10/16 13:22:04 | 000,000,000 | -H-D | C] – C:\Windows\AxInstSV
[2011/10/12 16:54:20 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/12 16:54:20 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/12 16:54:19 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/12 16:54:19 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/12 16:54:18 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/12 16:54:17 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/10/12 16:54:17 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/10/12 16:54:17 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/12 16:54:16 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/10/12 15:37:09 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/12 15:37:09 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/12 15:37:09 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/12 15:37:09 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/12 15:36:54 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/12 15:36:53 | 000,861,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/12 13:54:01 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{BAF86BAA-E667-4D4C-9706-13C03320E7C0}
[2011/10/12 13:53:50 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{1AB6826F-BA5D-4DF0-B7FF-925099CC4C62}
[2011/10/11 17:58:41 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{0964AF25-D224-419A-A0AB-F080DFC5B4FF}
[2011/10/11 17:58:29 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{D4450F11-ECA2-402B-A1A3-792CF4668925}
[2011/10/10 00:50:02 | 000,000,000 | —D | C] – C:\Users\Carrie\Desktop\Prayer
[2011/10/09 23:21:14 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{9FB426C5-7549-472F-A3F2-CBF1F356DD14}
[2011/10/09 23:20:54 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{A4A405C8-E857-48B6-84DD-30C7C295BDC5}
[2011/10/06 11:39:47 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\AVG
[2011/10/05 23:00:04 | 000,000,000 | —D | C] – C:\Users\Carrie\Desktop\Colten Videos
[2011/10/05 21:51:52 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/10/05 21:51:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2011/10/03 18:59:48 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Roaming\AVG
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/02 00:25:05 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Carrie\Desktop\OTL.exe
[2011/11/02 00:20:38 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/01 22:53:07 | 000,002,981 | —- | M] () – C:\Users\Carrie\Desktop\HiJackThis.lnk
[2011/11/01 20:53:40 | 000,001,239 | —- | M] () – C:\Users\Public\Desktop\Quick Care.lnk
[2011/11/01 20:53:38 | 000,001,217 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/11/01 20:50:46 | 030,515,552 | —- | M] (IObit ) – C:\Users\Carrie\Desktop\asc-setup.exe
[2011/11/01 20:05:11 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/01 20:05:11 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/01 20:01:49 | 108,432,321 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/11/01 19:58:17 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/01 19:57:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/01 19:57:13 | 2414,379,008 | -HS- | M] () – C:\hiberfil.sys
[2011/10/30 18:59:07 | 000,435,715 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/10/30 16:27:35 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/26 09:47:53 | 000,743,290 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/26 09:47:53 | 000,635,206 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/10/26 09:47:53 | 000,111,914 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/10/12 21:41:49 | 000,310,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/06 11:39:47 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/10/06 11:39:47 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/10/05 22:28:57 | 000,437,925 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/10/05 22:27:45 | 000,437,925 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20111005-222857.backup
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/01 22:53:07 | 000,002,981 | —- | C] () – C:\Users\Carrie\Desktop\HiJackThis.lnk
[2011/11/01 20:53:40 | 000,001,239 | —- | C] () – C:\Users\Public\Desktop\Quick Care.lnk
[2011/11/01 20:53:38 | 000,001,217 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/10/06 11:39:47 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/10/06 11:39:47 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/05/14 22:22:33 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/05/08 16:50:21 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\.minecraft
[2011/10/03 19:44:50 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\AVG
[2011/09/27 21:41:19 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\AVG2012
[2011/05/12 22:36:46 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\com.Shutterfly.ExpressUploader
[2011/11/01 20:53:11 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\IObit
[2011/05/15 10:26:16 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\iWin
[2011/06/19 05:07:19 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\Oberon Media
[2011/09/19 13:20:57 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\WinAVI
[2011/04/11 14:43:52 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\Windows Live Writer
[2011/10/07 13:18:24 | 000,032,622 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/10/29 22:01:08 | 000,000,211 | -H– | M] () – C:\Boot.BAK
[2011/02/28 22:30:46 | 000,000,355 | RHS- | M] () – C:\Boot.ini.saved
[2010/11/20 08:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/02/28 22:30:48 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/06/10 19:35:20 | 000,007,747 | RH– | M] () – C:\dell.sdr
[2011/11/01 19:57:13 | 2414,379,008 | -HS- | M] () – C:\hiberfil.sys
[2008/07/01 13:08:04 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2009/09/24 20:38:38 | 000,000,744 | -H– | M] () – C:\IPH.PH
[2009/07/28 22:44:19 | 000,000,085 | —- | M] () – C:\log-other.txt
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/06/10 19:58:43 | 000,022,729 | —- | M] () – C:\newfile.enc
[2008/06/10 19:58:43 | 000,022,729 | —- | M] () – C:\newkey
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/16 23:42:49 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/11/01 19:57:13 | 3219,173,376 | -HS- | M] () – C:\pagefile.sys
[2008/06/22 14:44:16 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2008/07/04 12:24:13 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2008/07/05 19:55:27 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2008/07/06 10:51:37 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2008/07/08 00:42:36 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2008/07/11 01:07:12 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2008/07/12 01:23:55 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2008/07/13 09:58:25 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2008/07/18 00:18:25 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2008/07/19 01:17:59 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2008/09/27 13:45:14 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2008/09/27 13:45:26 | 000,000,208 | -H– | M] () – C:\sqmdata11.sqm
[2008/09/27 14:40:35 | 000,000,172 | -H– | M] () – C:\sqmdata12.sqm
[2008/10/04 13:45:56 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2008/10/04 19:08:08 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/01/15 21:14:45 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/02/01 15:19:26 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/02/01 15:19:27 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/03/21 18:27:06 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/03/23 21:55:28 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2008/06/22 14:44:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2008/07/04 12:24:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2008/07/05 19:55:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2008/07/06 10:51:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2008/07/08 00:42:36 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2008/07/11 01:07:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2008/07/12 01:23:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2008/07/13 09:58:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2008/07/18 00:18:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2008/07/19 01:17:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2008/09/27 13:45:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2008/09/27 13:45:26 | 000,000,172 | -H– | M] () – C:\sqmnoopt11.sqm
[2008/09/27 14:40:35 | 000,000,172 | -H– | M] () – C:\sqmnoopt12.sqm
[2008/10/04 13:45:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2008/10/04 19:08:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/01/15 21:14:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/02/01 15:19:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/02/01 15:19:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/03/21 18:27:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/03/23 21:55:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/13 15:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/03 19:24:21 | 000,000,221 | -HS- | M] () – C:\Users\Carrie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/11/01 20:50:46 | 030,515,552 | —- | M] (IObit ) – C:\Users\Carrie\Desktop\asc-setup.exe
[2011/11/02 00:25:05 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Carrie\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:54CB420C
< End of report >
OTL Extras logfile created on: 11/2/2011 12:26:53 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Carrie\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 73.86% Memory free
5.99 Gb Paging File | 4.66 Gb Available in Paging File | 77.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 227.00 Gb Total Space | 143.35 Gb Free Space | 63.15% Space Free | Partition Type: NTFS
Computer Name: CARRIE-PC | User Name: Carrie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B7465E2-1A7E-4D21-8670-94D9C11449B8}" = AVG 2012
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{88381CA0-AB27-45B5-8BB8-E68987822AF8}" = AVG 2012
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"AVG" = AVG 2012
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 24
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Media Driver Ver.3.53.02
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"WinLiveSuite" = Windows Live Essentials
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/13/2011 6:45:21 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 100c Start
Time: 01cc89f9a7d98963 Termination Time: 375 Application Path: C:\Program Files (x86)\Internet
Explorer\iexplore.exe Report Id:
Error - 10/17/2011 5:18:48 PM | Computer Name = Carrie-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.
Error - 10/17/2011 10:21:58 PM | Computer Name = Carrie-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x20296425 Faulting process id:
0xdac Faulting application start time: 0x01cc8d06bea175b6 Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: f3f12c70-f92f-11e0-bdf1-001d09cee6b9
Error - 10/22/2011 12:56:24 PM | Computer Name = Carrie-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: Flash11c.ocx, version: 11.0.1.152, time
stamp: 0x4e7d1782 Exception code: 0xc0000005 Fault offset: 0x0019ac6c Faulting process
id: 0xe28 Faulting application start time: 0x01cc90d3d4dc0571 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\SysWOW64\Macromed\Flash\Flash11c.ocx Report Id: c622e815-fcce-11e0-8ff3-001d09cee6b9
Error - 10/23/2011 12:51:09 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: c40 Start
Time: 01cc91a3a98434f1 Termination Time: 8526 Application Path: C:\Program Files
(x86)\Internet Explorer\iexplore.exe Report Id:
Error - 10/23/2011 6:09:12 PM | Computer Name = Carrie-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.
Error - 10/24/2011 3:20:27 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 140 Start
Time: 01cc9281d1b39eee Termination Time: 5101 Application Path: C:\Program Files
(x86)\Internet Explorer\iexplore.exe Report Id:
Error - 10/25/2011 6:44:33 PM | Computer Name = Carrie-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.
Error - 10/29/2011 2:19:46 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: c74 Start
Time: 01cc96612657099b Termination Time: 10 Application Path: C:\Program Files (x86)\Internet
Explorer\iexplore.exe Report Id:
Error - 10/31/2011 8:15:42 PM | Computer Name = Carrie-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7ba58 Exception code: 0xc0000374 Fault offset: 0x000ce653 Faulting
process id: 0x274 Faulting application start time: 0x01cc982b58c9bfec Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: a1f2ee1a-041e-11e1-af55-001d09cee6b9
[ Media Center Events ]
Error - 5/7/2011 10:56:37 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:56:36 PM - Failed to retrieve Directory (Error: Unable to connect
to the remote server)
Error - 5/7/2011 10:57:45 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:57:24 PM - Failed to retrieve NetTV (Error: Unable to connect to
the remote server)
Error - 5/7/2011 10:58:35 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:58:06 PM - Failed to retrieve MCEClientUX (Error: Unable to connect
to the remote server)
Error - 5/7/2011 10:59:17 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:58:56 PM - Failed to retrieve SportsSchedule (Error: Unable to
connect to the remote server)
Error - 5/7/2011 10:59:59 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:59:38 PM - Failed to retrieve SportsV2 (Error: Unable to connect
to the remote server)
Error - 5/7/2011 11:00:31 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 11:00:20 PM - Failed to retrieve Broadband (Error: Unable to connect
to the remote server)
Error - 5/8/2011 12:01:20 AM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 12:01:20 AM - Error connecting to the internet. 12:01:20 AM - Unable
to contact server..
Error - 5/8/2011 12:02:08 AM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 12:02:07 AM - Error connecting to the internet. 12:02:07 AM - Unable
to contact server..
[ System Events ]
Error - 8/15/2011 1:26:26 PM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.
Error - 8/15/2011 1:32:45 PM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).
Error - 8/15/2011 5:56:12 PM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.
Error - 8/15/2011 6:33:23 PM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).
Error - 8/16/2011 4:15:39 AM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.
Error - 8/16/2011 4:22:32 AM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).
Error - 8/16/2011 7:00:46 AM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).
Error - 8/16/2011 10:30:44 AM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.
Error - 8/16/2011 11:49:17 AM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).
Error - 8/16/2011 3:28:43 PM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.
< End of report >
OTL logfile created on: 11/2/2011 12:26:53 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Carrie\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 73.86% Memory free
5.99 Gb Paging File | 4.66 Gb Available in Paging File | 77.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 227.00 Gb Total Space | 143.35 Gb Free Space | 63.15% Space Free | Partition Type: NTFS
Computer Name: CARRIE-PC | User Name: Carrie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Carrie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11c_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASC.exe (IObit)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe (IObit)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe (Trend Micro Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\Scan.dll ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\sqlite3.dll ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\NtfsData.dll ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\DiskMap.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (LPDSVC) – C:\Windows\SysNative\lpdsvc.dll (Microsoft Corporation)
SRV:64bit: - (CISVC) – C:\Windows\SysNative\CISVC.EXE (Microsoft Corporation)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdvancedSystemCareService) – C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (bcm44amd64) – C:\Windows\SysNative\drivers\b44amd64.sys (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (OEM02Dev) – C:\Windows\SysNative\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\drivers\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\drivers\rimspx64.sys (REDC)
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\drivers\rimmpx64.sys (REDC)
DRV:64bit: - (OEM02Vfx) – C:\Windows\SysNative\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6B 25 ED 60 A5 D7 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {9427041a-a8dc-4d06-9a68-93873486e957} - No CLSID value found
IE - HKCU\..\URLSearchHook: {da566842-d620-41bf-8a10-149cfa14035d} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/10/25 14:40:59 | 000,000,000 | —D | M]
[2011/07/31 20:53:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Carrie\AppData\Roaming\Mozilla\Extensions
========== Chrome ==========
CHR - Extension: No name found = C:\Users\Carrie\AppData\Local\Google\Chrome\User Data\Default\Extensions\neghaibmbjedngldjldidfoobmkkfkle\2_0\
O1 HOSTS File: ([2011/10/05 22:28:57 | 000,437,925 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15060 more lines…
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Play Pickle Text) - {02F0243C-2E71-4a1a-A790-6C30888119D0} - Reg Error: Value error. File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/US/Core/Pla…_IKEA_Win32.cab (20-20 3D Viewer for IKEA)
O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} https://ehelp.nelnet.net/netagent/objects/custappx3.CAB (eAssist NetAgent Customer ActiveX Control version 3)
O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} https://lowes.2020.net/planner/Core/Player/…yerAX_Win32.cab (20-20 3D Viewer)
O16 - DPF: {8A5BE387-D09A-4DFA-A56B-DCB89BD11468} https://lowes.2020.net/planner/Core/Player/…X_WEB_Win32.cab (20-20 3D Viewer for WEB)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4A990216-4EF3-419D-A2F7-DEE72BAF67C2}: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/02 00:24:05 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Carrie\Desktop\OTL.exe
[2011/11/01 22:53:07 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/11/01 22:53:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/11/01 20:53:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/11/01 20:53:11 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Roaming\IObit
[2011/11/01 20:53:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2011/11/01 20:50:03 | 030,515,552 | —- | C] (IObit ) – C:\Users\Carrie\Desktop\asc-setup.exe
[2011/10/31 21:24:35 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{CF1DB14D-AB59-4A3E-B088-20B8B6C8EC8F}
[2011/10/31 21:24:02 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{6298ADD4-8D03-4DC0-83F6-9629D77F6AD0}
[2011/10/30 16:27:26 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/10/27 15:57:59 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{5DE4C264-1112-4635-8B98-CC0B98D20345}
[2011/10/27 15:57:38 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{DEED43CE-3B58-4708-B827-9A63CD9AD655}
[2011/10/24 14:45:08 | 000,000,000 | —D | C] – C:\Users\Carrie\Desktop\Skunk
[2011/10/24 14:25:25 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{60DE18B1-2FB1-449A-AFBD-042028FAE9D0}
[2011/10/24 14:25:11 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{3C086A37-E415-4280-BA59-B548DD4CACE3}
[2011/10/21 16:58:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\GamingWonderlandEI
[2011/10/19 16:36:59 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{C548EBE3-2D4D-4E41-B4C1-82C3E85BB57C}
[2011/10/19 16:36:47 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{589FA694-6D53-4CBC-A370-24BE7D7729C7}
[2011/10/18 09:14:27 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{BEABAF05-E5D9-4B53-B1B2-877557AA1B48}
[2011/10/18 09:14:16 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{05D27152-30A5-40D6-8567-84361FF57A9B}
[2011/10/16 13:22:04 | 000,000,000 | -HSD | C] – C:\Windows\SysNative\%APPDATA%
[2011/10/16 13:22:04 | 000,000,000 | -H-D | C] – C:\Windows\AxInstSV
[2011/10/12 16:54:20 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/12 16:54:20 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/12 16:54:19 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/12 16:54:19 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/12 16:54:18 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/12 16:54:17 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/10/12 16:54:17 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/10/12 16:54:17 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/12 16:54:16 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/10/12 15:37:09 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/12 15:37:09 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/12 15:37:09 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/12 15:37:09 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/12 15:36:54 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/12 15:36:53 | 000,861,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/12 13:54:01 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{BAF86BAA-E667-4D4C-9706-13C03320E7C0}
[2011/10/12 13:53:50 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{1AB6826F-BA5D-4DF0-B7FF-925099CC4C62}
[2011/10/11 17:58:41 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{0964AF25-D224-419A-A0AB-F080DFC5B4FF}
[2011/10/11 17:58:29 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{D4450F11-ECA2-402B-A1A3-792CF4668925}
[2011/10/10 00:50:02 | 000,000,000 | —D | C] – C:\Users\Carrie\Desktop\Prayer
[2011/10/09 23:21:14 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{9FB426C5-7549-472F-A3F2-CBF1F356DD14}
[2011/10/09 23:20:54 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{A4A405C8-E857-48B6-84DD-30C7C295BDC5}
[2011/10/06 11:39:47 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\AVG
[2011/10/05 23:00:04 | 000,000,000 | —D | C] – C:\Users\Carrie\Desktop\Colten Videos
[2011/10/05 21:51:52 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/10/05 21:51:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2011/10/03 18:59:48 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Roaming\AVG
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/02 00:25:05 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Carrie\Desktop\OTL.exe
[2011/11/02 00:20:38 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/01 22:53:07 | 000,002,981 | —- | M] () – C:\Users\Carrie\Desktop\HiJackThis.lnk
[2011/11/01 20:53:40 | 000,001,239 | —- | M] () – C:\Users\Public\Desktop\Quick Care.lnk
[2011/11/01 20:53:38 | 000,001,217 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/11/01 20:50:46 | 030,515,552 | —- | M] (IObit ) – C:\Users\Carrie\Desktop\asc-setup.exe
[2011/11/01 20:05:11 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/01 20:05:11 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/01 20:01:49 | 108,432,321 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/11/01 19:58:17 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/01 19:57:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/01 19:57:13 | 2414,379,008 | -HS- | M] () – C:\hiberfil.sys
[2011/10/30 18:59:07 | 000,435,715 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/10/30 16:27:35 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/26 09:47:53 | 000,743,290 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/26 09:47:53 | 000,635,206 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/10/26 09:47:53 | 000,111,914 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/10/12 21:41:49 | 000,310,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/06 11:39:47 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/10/06 11:39:47 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/10/05 22:28:57 | 000,437,925 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/10/05 22:27:45 | 000,437,925 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20111005-222857.backup
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/01 22:53:07 | 000,002,981 | —- | C] () – C:\Users\Carrie\Desktop\HiJackThis.lnk
[2011/11/01 20:53:40 | 000,001,239 | —- | C] () – C:\Users\Public\Desktop\Quick Care.lnk
[2011/11/01 20:53:38 | 000,001,217 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/10/06 11:39:47 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/10/06 11:39:47 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/05/14 22:22:33 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/05/08 16:50:21 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\.minecraft
[2011/10/03 19:44:50 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\AVG
[2011/09/27 21:41:19 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\AVG2012
[2011/05/12 22:36:46 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\com.Shutterfly.ExpressUploader
[2011/11/01 20:53:11 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\IObit
[2011/05/15 10:26:16 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\iWin
[2011/06/19 05:07:19 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\Oberon Media
[2011/09/19 13:20:57 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\WinAVI
[2011/04/11 14:43:52 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\Windows Live Writer
[2011/10/07 13:18:24 | 000,032,622 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/10/29 22:01:08 | 000,000,211 | -H– | M] () – C:\Boot.BAK
[2011/02/28 22:30:46 | 000,000,355 | RHS- | M] () – C:\Boot.ini.saved
[2010/11/20 08:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/02/28 22:30:48 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/06/10 19:35:20 | 000,007,747 | RH– | M] () – C:\dell.sdr
[2011/11/01 19:57:13 | 2414,379,008 | -HS- | M] () – C:\hiberfil.sys
[2008/07/01 13:08:04 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2009/09/24 20:38:38 | 000,000,744 | -H– | M] () – C:\IPH.PH
[2009/07/28 22:44:19 | 000,000,085 | —- | M] () – C:\log-other.txt
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/06/10 19:58:43 | 000,022,729 | —- | M] () – C:\newfile.enc
[2008/06/10 19:58:43 | 000,022,729 | —- | M] () – C:\newkey
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/16 23:42:49 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/11/01 19:57:13 | 3219,173,376 | -HS- | M] () – C:\pagefile.sys
[2008/06/22 14:44:16 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2008/07/04 12:24:13 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2008/07/05 19:55:27 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2008/07/06 10:51:37 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2008/07/08 00:42:36 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2008/07/11 01:07:12 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2008/07/12 01:23:55 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2008/07/13 09:58:25 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2008/07/18 00:18:25 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2008/07/19 01:17:59 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2008/09/27 13:45:14 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2008/09/27 13:45:26 | 000,000,208 | -H– | M] () – C:\sqmdata11.sqm
[2008/09/27 14:40:35 | 000,000,172 | -H– | M] () – C:\sqmdata12.sqm
[2008/10/04 13:45:56 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2008/10/04 19:08:08 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/01/15 21:14:45 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/02/01 15:19:26 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/02/01 15:19:27 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/03/21 18:27:06 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/03/23 21:55:28 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2008/06/22 14:44:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2008/07/04 12:24:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2008/07/05 19:55:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2008/07/06 10:51:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2008/07/08 00:42:36 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2008/07/11 01:07:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2008/07/12 01:23:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2008/07/13 09:58:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2008/07/18 00:18:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2008/07/19 01:17:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2008/09/27 13:45:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2008/09/27 13:45:26 | 000,000,172 | -H– | M] () – C:\sqmnoopt11.sqm
[2008/09/27 14:40:35 | 000,000,172 | -H– | M] () – C:\sqmnoopt12.sqm
[2008/10/04 13:45:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2008/10/04 19:08:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/01/15 21:14:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/02/01 15:19:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/02/01 15:19:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/03/21 18:27:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/03/23 21:55:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/13 15:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/03 19:24:21 | 000,000,221 | -HS- | M] () – C:\Users\Carrie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/11/01 20:50:46 | 030,515,552 | —- | M] (IObit ) – C:\Users\Carrie\Desktop\asc-setup.exe
[2011/11/02 00:25:05 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Carrie\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:54CB420C
< End of report >
OTL Extras logfile created on: 11/2/2011 12:26:53 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Carrie\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 73.86% Memory free
5.99 Gb Paging File | 4.66 Gb Available in Paging File | 77.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 227.00 Gb Total Space | 143.35 Gb Free Space | 63.15% Space Free | Partition Type: NTFS
Computer Name: CARRIE-PC | User Name: Carrie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B7465E2-1A7E-4D21-8670-94D9C11449B8}" = AVG 2012
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{88381CA0-AB27-45B5-8BB8-E68987822AF8}" = AVG 2012
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"AVG" = AVG 2012
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 24
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Media Driver Ver.3.53.02
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"WinLiveSuite" = Windows Live Essentials
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/13/2011 6:45:21 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 100c Start
Time: 01cc89f9a7d98963 Termination Time: 375 Application Path: C:\Program Files (x86)\Internet
Explorer\iexplore.exe Report Id:
Error - 10/17/2011 5:18:48 PM | Computer Name = Carrie-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.
Error - 10/17/2011 10:21:58 PM | Computer Name = Carrie-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x20296425 Faulting process id:
0xdac Faulting application start time: 0x01cc8d06bea175b6 Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: f3f12c70-f92f-11e0-bdf1-001d09cee6b9
Error - 10/22/2011 12:56:24 PM | Computer Name = Carrie-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: Flash11c.ocx, version: 11.0.1.152, time
stamp: 0x4e7d1782 Exception code: 0xc0000005 Fault offset: 0x0019ac6c Faulting process
id: 0xe28 Faulting application start time: 0x01cc90d3d4dc0571 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\SysWOW64\Macromed\Flash\Flash11c.ocx Report Id: c622e815-fcce-11e0-8ff3-001d09cee6b9
Error - 10/23/2011 12:51:09 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: c40 Start
Time: 01cc91a3a98434f1 Termination Time: 8526 Application Path: C:\Program Files
(x86)\Internet Explorer\iexplore.exe Report Id:
Error - 10/23/2011 6:09:12 PM | Computer Name = Carrie-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.
Error - 10/24/2011 3:20:27 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 140 Start
Time: 01cc9281d1b39eee Termination Time: 5101 Application Path: C:\Program Files
(x86)\Internet Explorer\iexplore.exe Report Id:
Error - 10/25/2011 6:44:33 PM | Computer Name = Carrie-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.
Error - 10/29/2011 2:19:46 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: c74 Start
Time: 01cc96612657099b Termination Time: 10 Application Path: C:\Program Files (x86)\Internet
Explorer\iexplore.exe Report Id:
Error - 10/31/2011 8:15:42 PM | Computer Name = Carrie-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7ba58 Exception code: 0xc0000374 Fault offset: 0x000ce653 Faulting
process id: 0x274 Faulting application start time: 0x01cc982b58c9bfec Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: a1f2ee1a-041e-11e1-af55-001d09cee6b9
[ Media Center Events ]
Error - 5/7/2011 10:56:37 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:56:36 PM - Failed to retrieve Directory (Error: Unable to connect
to the remote server)
Error - 5/7/2011 10:57:45 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:57:24 PM - Failed to retrieve NetTV (Error: Unable to connect to
the remote server)
Error - 5/7/2011 10:58:35 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:58:06 PM - Failed to retrieve MCEClientUX (Error: Unable to connect
to the remote server)
Error - 5/7/2011 10:59:17 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:58:56 PM - Failed to retrieve SportsSchedule (Error: Unable to
connect to the remote server)
Error - 5/7/2011 10:59:59 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:59:38 PM - Failed to retrieve SportsV2 (Error: Unable to connect
to the remote server)
Error - 5/7/2011 11:00:31 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 11:00:20 PM - Failed to retrieve Broadband (Error: Unable to connect
to the remote server)
Error - 5/8/2011 12:01:20 AM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 12:01:20 AM - Error connecting to the internet. 12:01:20 AM - Unable
to contact server..
Error - 5/8/2011 12:02:08 AM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 12:02:07 AM - Error connecting to the internet. 12:02:07 AM - Unable
to contact server..
[ System Events ]
Error - 8/15/2011 1:26:26 PM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.
Error - 8/15/2011 1:32:45 PM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).
Error - 8/15/2011 5:56:12 PM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.
Error - 8/15/2011 6:33:23 PM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).
Error - 8/16/2011 4:15:39 AM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.
Error - 8/16/2011 4:22:32 AM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).
Error - 8/16/2011 7:00:46 AM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).
Error - 8/16/2011 10:30:44 AM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.
Error - 8/16/2011 11:49:17 AM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).
Error - 8/16/2011 3:28:43 PM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.
< End of report >