This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

multiple "rundll32.exe" running CPU to 100%

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Not always, but often enough to be annoying, a couple of rundll32.exe processes run the CPU to 100%. Per instructions in the forum I have run the OTL scan. Please help.

OTL logfile created on: 11/2/2011 12:26:53 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Carrie\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 73.86% Memory free
5.99 Gb Paging File | 4.66 Gb Available in Paging File | 77.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 227.00 Gb Total Space | 143.35 Gb Free Space | 63.15% Space Free | Partition Type: NTFS

Computer Name: CARRIE-PC | User Name: Carrie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Carrie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11c_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASC.exe (IObit)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe (IObit)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe (Trend Micro Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\Scan.dll ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\sqlite3.dll ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\NtfsData.dll ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 4\DiskMap.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (LPDSVC) – C:\Windows\SysNative\lpdsvc.dll (Microsoft Corporation)
SRV:64bit: - (CISVC) – C:\Windows\SysNative\CISVC.EXE (Microsoft Corporation)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdvancedSystemCareService) – C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (bcm44amd64) – C:\Windows\SysNative\drivers\b44amd64.sys (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (OEM02Dev) – C:\Windows\SysNative\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\drivers\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\drivers\rimspx64.sys (REDC)
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\drivers\rimmpx64.sys (REDC)
DRV:64bit: - (OEM02Vfx) – C:\Windows\SysNative\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6B 25 ED 60 A5 D7 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {9427041a-a8dc-4d06-9a68-93873486e957} - No CLSID value found
IE - HKCU\..\URLSearchHook: {da566842-d620-41bf-8a10-149cfa14035d} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/10/25 14:40:59 | 000,000,000 | —D | M]

[2011/07/31 20:53:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Carrie\AppData\Roaming\Mozilla\Extensions

========== Chrome ==========

CHR - Extension: No name found = C:\Users\Carrie\AppData\Local\Google\Chrome\User Data\Default\Extensions\neghaibmbjedngldjldidfoobmkkfkle\2_0\

O1 HOSTS File: ([2011/10/05 22:28:57 | 000,437,925 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15060 more lines…
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Play Pickle Text) - {02F0243C-2E71-4a1a-A790-6C30888119D0} - Reg Error: Value error. File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/US/Core/Pla…_IKEA_Win32.cab (20-20 3D Viewer for IKEA)
O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} https://ehelp.nelnet.net/netagent/objects/custappx3.CAB (eAssist NetAgent Customer ActiveX Control version 3)
O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} https://lowes.2020.net/planner/Core/Player/…yerAX_Win32.cab (20-20 3D Viewer)
O16 - DPF: {8A5BE387-D09A-4DFA-A56B-DCB89BD11468} https://lowes.2020.net/planner/Core/Player/…X_WEB_Win32.cab (20-20 3D Viewer for WEB)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4A990216-4EF3-419D-A2F7-DEE72BAF67C2}: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/02 00:24:05 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Carrie\Desktop\OTL.exe
[2011/11/01 22:53:07 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/11/01 22:53:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/11/01 20:53:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/11/01 20:53:11 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Roaming\IObit
[2011/11/01 20:53:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2011/11/01 20:50:03 | 030,515,552 | —- | C] (IObit ) – C:\Users\Carrie\Desktop\asc-setup.exe
[2011/10/31 21:24:35 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{CF1DB14D-AB59-4A3E-B088-20B8B6C8EC8F}
[2011/10/31 21:24:02 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{6298ADD4-8D03-4DC0-83F6-9629D77F6AD0}
[2011/10/30 16:27:26 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/10/27 15:57:59 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{5DE4C264-1112-4635-8B98-CC0B98D20345}
[2011/10/27 15:57:38 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{DEED43CE-3B58-4708-B827-9A63CD9AD655}
[2011/10/24 14:45:08 | 000,000,000 | —D | C] – C:\Users\Carrie\Desktop\Skunk
[2011/10/24 14:25:25 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{60DE18B1-2FB1-449A-AFBD-042028FAE9D0}
[2011/10/24 14:25:11 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{3C086A37-E415-4280-BA59-B548DD4CACE3}
[2011/10/21 16:58:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\GamingWonderlandEI
[2011/10/19 16:36:59 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{C548EBE3-2D4D-4E41-B4C1-82C3E85BB57C}
[2011/10/19 16:36:47 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{589FA694-6D53-4CBC-A370-24BE7D7729C7}
[2011/10/18 09:14:27 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{BEABAF05-E5D9-4B53-B1B2-877557AA1B48}
[2011/10/18 09:14:16 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{05D27152-30A5-40D6-8567-84361FF57A9B}
[2011/10/16 13:22:04 | 000,000,000 | -HSD | C] – C:\Windows\SysNative\%APPDATA%
[2011/10/16 13:22:04 | 000,000,000 | -H-D | C] – C:\Windows\AxInstSV
[2011/10/12 16:54:20 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/12 16:54:20 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/12 16:54:19 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/12 16:54:19 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/12 16:54:18 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/12 16:54:17 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/10/12 16:54:17 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/10/12 16:54:17 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/12 16:54:16 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/10/12 15:37:09 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/12 15:37:09 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/12 15:37:09 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/12 15:37:09 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/12 15:36:54 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/12 15:36:53 | 000,861,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/12 13:54:01 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{BAF86BAA-E667-4D4C-9706-13C03320E7C0}
[2011/10/12 13:53:50 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{1AB6826F-BA5D-4DF0-B7FF-925099CC4C62}
[2011/10/11 17:58:41 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{0964AF25-D224-419A-A0AB-F080DFC5B4FF}
[2011/10/11 17:58:29 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{D4450F11-ECA2-402B-A1A3-792CF4668925}
[2011/10/10 00:50:02 | 000,000,000 | —D | C] – C:\Users\Carrie\Desktop\Prayer
[2011/10/09 23:21:14 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{9FB426C5-7549-472F-A3F2-CBF1F356DD14}
[2011/10/09 23:20:54 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Local\{A4A405C8-E857-48B6-84DD-30C7C295BDC5}
[2011/10/06 11:39:47 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\AVG
[2011/10/05 23:00:04 | 000,000,000 | —D | C] – C:\Users\Carrie\Desktop\Colten Videos
[2011/10/05 21:51:52 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/10/05 21:51:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2011/10/03 18:59:48 | 000,000,000 | —D | C] – C:\Users\Carrie\AppData\Roaming\AVG
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/02 00:25:05 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Carrie\Desktop\OTL.exe
[2011/11/02 00:20:38 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/01 22:53:07 | 000,002,981 | —- | M] () – C:\Users\Carrie\Desktop\HiJackThis.lnk
[2011/11/01 20:53:40 | 000,001,239 | —- | M] () – C:\Users\Public\Desktop\Quick Care.lnk
[2011/11/01 20:53:38 | 000,001,217 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/11/01 20:50:46 | 030,515,552 | —- | M] (IObit ) – C:\Users\Carrie\Desktop\asc-setup.exe
[2011/11/01 20:05:11 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/01 20:05:11 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/01 20:01:49 | 108,432,321 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/11/01 19:58:17 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/01 19:57:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/01 19:57:13 | 2414,379,008 | -HS- | M] () – C:\hiberfil.sys
[2011/10/30 18:59:07 | 000,435,715 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/10/30 16:27:35 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/26 09:47:53 | 000,743,290 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/26 09:47:53 | 000,635,206 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/10/26 09:47:53 | 000,111,914 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/10/12 21:41:49 | 000,310,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/06 11:39:47 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/10/06 11:39:47 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/10/05 22:28:57 | 000,437,925 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/10/05 22:27:45 | 000,437,925 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20111005-222857.backup
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/01 22:53:07 | 000,002,981 | —- | C] () – C:\Users\Carrie\Desktop\HiJackThis.lnk
[2011/11/01 20:53:40 | 000,001,239 | —- | C] () – C:\Users\Public\Desktop\Quick Care.lnk
[2011/11/01 20:53:38 | 000,001,217 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/10/06 11:39:47 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/10/06 11:39:47 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/05/14 22:22:33 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/05/08 16:50:21 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\.minecraft
[2011/10/03 19:44:50 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\AVG
[2011/09/27 21:41:19 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\AVG2012
[2011/05/12 22:36:46 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\com.Shutterfly.ExpressUploader
[2011/11/01 20:53:11 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\IObit
[2011/05/15 10:26:16 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\iWin
[2011/06/19 05:07:19 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\Oberon Media
[2011/09/19 13:20:57 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\WinAVI
[2011/04/11 14:43:52 | 000,000,000 | —D | M] – C:\Users\Carrie\AppData\Roaming\Windows Live Writer
[2011/10/07 13:18:24 | 000,032,622 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/10/29 22:01:08 | 000,000,211 | -H– | M] () – C:\Boot.BAK
[2011/02/28 22:30:46 | 000,000,355 | RHS- | M] () – C:\Boot.ini.saved
[2010/11/20 08:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/02/28 22:30:48 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/06/10 19:35:20 | 000,007,747 | RH– | M] () – C:\dell.sdr
[2011/11/01 19:57:13 | 2414,379,008 | -HS- | M] () – C:\hiberfil.sys
[2008/07/01 13:08:04 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2009/09/24 20:38:38 | 000,000,744 | -H– | M] () – C:\IPH.PH
[2009/07/28 22:44:19 | 000,000,085 | —- | M] () – C:\log-other.txt
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/06/10 19:58:43 | 000,022,729 | —- | M] () – C:\newfile.enc
[2008/06/10 19:58:43 | 000,022,729 | —- | M] () – C:\newkey
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/16 23:42:49 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/11/01 19:57:13 | 3219,173,376 | -HS- | M] () – C:\pagefile.sys
[2008/06/22 14:44:16 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2008/07/04 12:24:13 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2008/07/05 19:55:27 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2008/07/06 10:51:37 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2008/07/08 00:42:36 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2008/07/11 01:07:12 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2008/07/12 01:23:55 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2008/07/13 09:58:25 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2008/07/18 00:18:25 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2008/07/19 01:17:59 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2008/09/27 13:45:14 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2008/09/27 13:45:26 | 000,000,208 | -H– | M] () – C:\sqmdata11.sqm
[2008/09/27 14:40:35 | 000,000,172 | -H– | M] () – C:\sqmdata12.sqm
[2008/10/04 13:45:56 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2008/10/04 19:08:08 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/01/15 21:14:45 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/02/01 15:19:26 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/02/01 15:19:27 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/03/21 18:27:06 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/03/23 21:55:28 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2008/06/22 14:44:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2008/07/04 12:24:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2008/07/05 19:55:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2008/07/06 10:51:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2008/07/08 00:42:36 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2008/07/11 01:07:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2008/07/12 01:23:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2008/07/13 09:58:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2008/07/18 00:18:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2008/07/19 01:17:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2008/09/27 13:45:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2008/09/27 13:45:26 | 000,000,172 | -H– | M] () – C:\sqmnoopt11.sqm
[2008/09/27 14:40:35 | 000,000,172 | -H– | M] () – C:\sqmnoopt12.sqm
[2008/10/04 13:45:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2008/10/04 19:08:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/01/15 21:14:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/02/01 15:19:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/02/01 15:19:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/03/21 18:27:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/03/23 21:55:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/05/13 15:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/03 19:24:21 | 000,000,221 | -HS- | M] () – C:\Users\Carrie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/11/01 20:50:46 | 030,515,552 | —- | M] (IObit ) – C:\Users\Carrie\Desktop\asc-setup.exe
[2011/11/02 00:25:05 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Carrie\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:54CB420C

< End of report >

OTL Extras logfile created on: 11/2/2011 12:26:53 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Carrie\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 73.86% Memory free
5.99 Gb Paging File | 4.66 Gb Available in Paging File | 77.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 227.00 Gb Total Space | 143.35 Gb Free Space | 63.15% Space Free | Partition Type: NTFS

Computer Name: CARRIE-PC | User Name: Carrie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B7465E2-1A7E-4D21-8670-94D9C11449B8}" = AVG 2012
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{88381CA0-AB27-45B5-8BB8-E68987822AF8}" = AVG 2012
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"AVG" = AVG 2012
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 24
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Media Driver Ver.3.53.02
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"WinLiveSuite" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/13/2011 6:45:21 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 100c Start
Time: 01cc89f9a7d98963 Termination Time: 375 Application Path: C:\Program Files (x86)\Internet
Explorer\iexplore.exe Report Id:

Error - 10/17/2011 5:18:48 PM | Computer Name = Carrie-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 10/17/2011 10:21:58 PM | Computer Name = Carrie-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x20296425 Faulting process id:
0xdac Faulting application start time: 0x01cc8d06bea175b6 Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: f3f12c70-f92f-11e0-bdf1-001d09cee6b9

Error - 10/22/2011 12:56:24 PM | Computer Name = Carrie-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: Flash11c.ocx, version: 11.0.1.152, time
stamp: 0x4e7d1782 Exception code: 0xc0000005 Fault offset: 0x0019ac6c Faulting process
id: 0xe28 Faulting application start time: 0x01cc90d3d4dc0571 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\SysWOW64\Macromed\Flash\Flash11c.ocx Report Id: c622e815-fcce-11e0-8ff3-001d09cee6b9

Error - 10/23/2011 12:51:09 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: c40 Start
Time: 01cc91a3a98434f1 Termination Time: 8526 Application Path: C:\Program Files
(x86)\Internet Explorer\iexplore.exe Report Id:

Error - 10/23/2011 6:09:12 PM | Computer Name = Carrie-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 10/24/2011 3:20:27 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 140 Start
Time: 01cc9281d1b39eee Termination Time: 5101 Application Path: C:\Program Files
(x86)\Internet Explorer\iexplore.exe Report Id:

Error - 10/25/2011 6:44:33 PM | Computer Name = Carrie-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 10/29/2011 2:19:46 PM | Computer Name = Carrie-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: c74 Start
Time: 01cc96612657099b Termination Time: 10 Application Path: C:\Program Files (x86)\Internet
Explorer\iexplore.exe Report Id:

Error - 10/31/2011 8:15:42 PM | Computer Name = Carrie-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7601.17514,
time stamp: 0x4ce7ba58 Exception code: 0xc0000374 Fault offset: 0x000ce653 Faulting
process id: 0x274 Faulting application start time: 0x01cc982b58c9bfec Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: a1f2ee1a-041e-11e1-af55-001d09cee6b9

[ Media Center Events ]
Error - 5/7/2011 10:56:37 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:56:36 PM - Failed to retrieve Directory (Error: Unable to connect
to the remote server)

Error - 5/7/2011 10:57:45 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:57:24 PM - Failed to retrieve NetTV (Error: Unable to connect to
the remote server)

Error - 5/7/2011 10:58:35 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:58:06 PM - Failed to retrieve MCEClientUX (Error: Unable to connect
to the remote server)

Error - 5/7/2011 10:59:17 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:58:56 PM - Failed to retrieve SportsSchedule (Error: Unable to
connect to the remote server)

Error - 5/7/2011 10:59:59 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 10:59:38 PM - Failed to retrieve SportsV2 (Error: Unable to connect
to the remote server)

Error - 5/7/2011 11:00:31 PM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 11:00:20 PM - Failed to retrieve Broadband (Error: Unable to connect
to the remote server)

Error - 5/8/2011 12:01:20 AM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 12:01:20 AM - Error connecting to the internet. 12:01:20 AM - Unable
to contact server..

Error - 5/8/2011 12:02:08 AM | Computer Name = Carrie-PC | Source = MCUpdate | ID = 0
Description = 12:02:07 AM - Error connecting to the internet. 12:02:07 AM - Unable
to contact server..

[ System Events ]
Error - 8/15/2011 1:26:26 PM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.

Error - 8/15/2011 1:32:45 PM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).

Error - 8/15/2011 5:56:12 PM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.

Error - 8/15/2011 6:33:23 PM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).

Error - 8/16/2011 4:15:39 AM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.

Error - 8/16/2011 4:22:32 AM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).

Error - 8/16/2011 7:00:46 AM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).

Error - 8/16/2011 10:30:44 AM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.

Error - 8/16/2011 11:49:17 AM | Computer Name = Carrie-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows
XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows
Server 2008 R2 for x64-based Systems (KB2539636).

Error - 8/16/2011 3:28:43 PM | Computer Name = Carrie-PC | Source = volsnap | ID = 393241
Description = The shadow copies of volume C: were deleted because the shadow copy
storage could not grow in time. Consider reducing the IO load on the system or
choose a shadow copy storage volume that is not being shadow copied.


< End of report >
Hi,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————


NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
I ran combofix and here is the log :-) ComboFix 11-11-10.03 - Carrie 11/10/2011 21:31:25.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3070.1883 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2011-10-11 to 2011-11-11 ))))))))))))))))))))))))))))))) . . 2011-11-11 03:40 . 2011-11-11 03:40 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-11-09 03:17 . 2011-10-01 05:45 886784 —-a-w- c:\program files\Common Files\System\wab32.dll 2011-11-09 03:17 . 2011-10-01 04:37 708608 —-a-w- c:\program files (x86)\Common Files\System\wab32.dll 2011-11-09 03:17 . 2011-09-29 16:29 1923952 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-11-09 03:17 . 2011-09-29 04:03 3144704 —-a-w- c:\windows\system32\win32k.sys 2011-11-02 02:53 . 2011-11-02 02:53 388096 —-a-r- c:\users\Carrie\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-11-02 02:53 . 2011-11-02 02:53 ——– d—–w- c:\program files (x86)\Trend Micro 2011-11-02 00:53 . 2011-11-02 00:53 ——– d—–w- c:\users\Carrie\AppData\Roaming\IObit 2011-11-02 00:53 . 2011-11-02 00:53 ——– d—–w- c:\program files (x86)\IObit 2011-10-30 20:27 . 2011-10-30 20:27 ——– d—–w- c:\windows\system32\Macromed 2011-10-21 20:58 . 2011-10-21 20:58 ——– d—–w- c:\program files (x86)\GamingWonderlandEI 2011-10-16 17:22 . 2011-10-16 17:22 ——– d–h–w- c:\windows\AxInstSV 2011-10-16 17:22 . 2011-10-16 17:22 ——– d-sh–w- c:\windows\system32\%APPDATA% 2011-10-12 19:37 . 2011-08-17 05:26 613888 —-a-w- c:\windows\system32\psisdecd.dll 2011-10-12 19:37 . 2011-08-17 05:25 108032 —-a-w- c:\windows\system32\psisrndr.ax 2011-10-12 19:37 . 2011-08-17 04:24 465408 —-a-w- c:\windows\SysWow64\psisdecd.dll 2011-10-12 19:37 . 2011-08-17 04:19 75776 —-a-w- c:\windows\SysWow64\psisrndr.ax 2011-10-12 19:36 . 2011-08-27 05:37 331776 —-a-w- c:\windows\system32\oleacc.dll 2011-10-12 19:36 . 2011-08-27 04:26 233472 —-a-w- c:\windows\SysWow64\oleacc.dll 2011-10-12 19:36 . 2011-08-27 05:37 861696 —-a-w- c:\windows\system32\oleaut32.dll 2011-10-12 19:36 . 2011-08-27 04:26 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-10-30 20:27 . 2011-05-17 08:23 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-10-07 10:23 . 2011-10-07 10:23 283728 —-a-w- c:\windows\system32\drivers\avgldx64.sys 2011-09-13 10:30 . 2011-09-13 10:30 37456 —-a-w- c:\windows\system32\drivers\avgrkx64.sys 2011-08-14 04:31 . 2010-06-24 15:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Advanced SystemCare 4"="c:\program files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-08-09 417112] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-03 136176] R3 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-03 136176] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-08-09 328536] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x] S3 bcm44amd64;Broadcom 440x 10/100 Integrated Controller XP Driver;c:\windows\system32\DRIVERS\b44amd64.sys [x] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x] . . Contents of the 'Scheduled Tasks' folder . 2011-11-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-03 23:46] . 2011-11-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-03 23:46] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.igoogle.com/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.10.1 DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} - hxxp://kitchenplanner.ikea.com/US/Core/Player/2020PlayerAX_IKEA_Win32.cab DPF: {8A5BE387-D09A-4DFA-A56B-DCB89BD11468} - hxxps://lowes.2020.net/planner/Core/Player/2020PlayerAX_WEB_Win32.cab . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{da566842-d620-41bf-8a10-149cfa14035d} - (no file) URLSearchHooks-{9427041a-a8dc-4d06-9a68-93873486e957} - (no file) AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-11-10 22:47:38 ComboFix-quarantined-files.txt 2011-11-11 03:47 . Pre-Run: 153,383,579,648 bytes free Post-Run: 153,348,034,560 bytes free . - - End Of File - - 29CA0FA1D43795DFB11DBB93FF39BFFE
Hi,

Please do the following:

  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-12 19:34:30 —————————– 19:34:30.913 OS Version: Windows x64 6.1.7601 Service Pack 1 19:34:30.913 Number of processors: 2 586 0xF0D 19:34:30.913 ComputerName: CARRIE-PC UserName: Carrie 19:34:31.911 Initialize success 19:35:55.974 AVAST engine defs: 11111201 19:36:07.799 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 19:36:07.815 Disk 0 Vendor: WDC_WD2500BEVS-75UST0 01.01A01 Size: 238475MB BusType: 3 19:36:09.858 Disk 0 MBR read successfully 19:36:09.874 Disk 0 MBR scan 19:36:09.874 Disk 0 Windows 7 default MBR code 19:36:09.889 Service scanning 19:36:16.301 Modules scanning 19:36:16.301 Disk 0 trace - called modules: 19:36:16.332 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS intelide.sys 19:36:16.332 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80033d9060] 19:36:16.348 3 CLASSPNP.SYS[fffff8800180143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa8002f5e680] 19:36:18.017 AVAST engine scan C:\Windows 19:36:27.252 AVAST engine scan C:\Windows\system32 19:38:45.936 AVAST engine scan C:\Windows\system32\drivers 19:39:00.257 AVAST engine scan C:\Users\Carrie 19:50:19.638 AVAST engine scan C:\ProgramData 19:51:56.156 Scan finished successfully 19:53:24.171 Disk 0 MBR has been saved successfully to "C:\Users\Carrie\Desktop\MBR.dat" 19:53:24.187 The log file has been saved successfully to "C:\Users\Carrie\Desktop\aswMBR.txt"

Attachments:

Hi,

Please do the following:

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)



NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI