Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Malware removal help needed please.

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: Malware removal help needed please.

Unread postby askey127 » January 21st, 2012, 5:38 pm

LaJuene,
That's a good result.
Now we just have to find any malware files and/or registry entries
----------------------------------------------
Perform a Custom Fix with OTL
Run OTL (Right click and choose "Run as administrator" in Vista/Win7)
  • In the Custom Scans/Fixes box at the bottom, paste in the following lines from the Code box (Do not include the word "Code"):
    Code: Select all
    :OTL
    [2011/03/30 14:08:17 | 000,000,000 | ---D | M] -- C:\Users\Kim and Greg\AppData\Roaming\PCDr
    [2012/01/16 09:21:55 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
    O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
    FF - prefs.js..browser.search.useDBForOrder: true
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [emptyjava]
    [emptyflash] 
    [EMPTYTEMP]
    [CREATERESTOREPOINT]
    
  • Then click the Run Fix button at the top.
  • Let the program run unhindered and reboot the PC when it is done.
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
----------------------------------------------------------------------------------
Download and Run MalwareBytes' Anti-Malware It is free for non-business use.
Please go here to the Download Location, click on Download in the Free column..
When the next page comes up, click on the Download Now button.
  • After clicking on the download and choosing Save, the "Save to location" dialog will come up.
  • Click the browse folders button, then click on Desktop on the left as the location for the installer and click Save again. Close the dialog when the download is complete.
  • You should now have a desktop icon named mbam-setup.exe. (If the download was saved somewhere else, locate it and copy or move it to your desktop).
  • Right click it, choose Run as administrator and Continue
  • Let it install where it wants to, with the default settings, and click Finish.
  • If an update is found, it will download and install the latest version. A shield symbol will show on the desktop icon while it is updating, and will disappear when it's done.
  • If necessary, start Malwarebytes Anti-Malware again.
    (You can Decline any Offer for a Trial if you don't want the paid version)
  • Once the program has started up, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • If it found any malware items, check all items... and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location, and post the contents in your reply.
  • The log can also be found using the "Logs" tab in the program. You can click any "Scan" log listed to open its contents. The logs are listed and named by time/date stamp.

So we will be looking for the newest OTL.txt and the log from Malwarebytes' Anti-Malware.
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA
Advertisement
Register to Remove

Re: Malware removal help needed please.

Unread postby LaJuene » January 21st, 2012, 7:28 pm

Here's the OTL Quick Scan Log:

OTL logfile created on: 1/21/2012 6:21:54 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Kim and Greg\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.75 Gb Total Physical Memory | 4.49 Gb Available Physical Memory | 78.03% Memory free
11.50 Gb Paging File | 9.95 Gb Available in Paging File | 86.53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.91 Gb Total Space | 401.47 Gb Free Space | 88.84% Space Free | Partition Type: NTFS

Computer Name: COLLIERPC | User Name: Kim and Greg | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/19 17:54:29 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Kim and Greg\Desktop\OTL.exe
PRC - [2011/09/06 12:29:20 | 004,259,648 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
PRC - [2011/08/18 10:05:54 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2011/08/18 10:05:46 | 001,692,480 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2011/08/01 12:56:48 | 000,460,096 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
PRC - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2010/06/27 02:47:26 | 000,105,632 | ---- | M] (Corel) -- C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe
PRC - [2010/06/26 23:03:40 | 000,526,992 | ---- | M] (Corel, Inc.) -- C:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
PRC - [2010/03/11 13:06:06 | 000,193,824 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2009/06/09 09:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe


========== Modules (No Company Name) ==========

MOD - [2011/10/13 12:30:13 | 002,295,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\6d859463c9e6a7423ddb335211a79dda\System.Core.ni.dll
MOD - [2011/10/12 17:06:58 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5672e6b9d976feca51deb06d8dd1df0e\PresentationFramework.Aero.ni.dll
MOD - [2011/10/12 17:06:35 | 014,322,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\09e39322b47f9b4e8dd2199ff03acb2e\PresentationFramework.ni.dll
MOD - [2011/10/12 17:06:23 | 012,431,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll
MOD - [2011/10/12 17:06:17 | 001,586,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll
MOD - [2011/10/12 17:06:15 | 012,216,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\d2dc021a8311197516e4fa325b292f21\PresentationCore.ni.dll
MOD - [2011/10/12 17:06:07 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\3136e12cfb8809d39813e76c766c782c\WindowsBase.ni.dll
MOD - [2011/10/12 17:06:02 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll
MOD - [2011/10/12 17:05:59 | 007,949,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll
MOD - [2011/10/12 17:05:59 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll
MOD - [2011/10/12 17:05:52 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll
MOD - [2011/08/18 10:05:54 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/14 13:01:38 | 000,245,352 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)
SRV:64bit: - [2011/04/14 13:01:38 | 000,200,056 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV:64bit: - [2011/04/14 13:01:38 | 000,149,032 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
SRV:64bit: - [2010/10/07 19:34:28 | 000,509,416 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/03/10 09:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy)
SRV:64bit: - [2010/03/10 09:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV:64bit: - [2010/03/10 09:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV:64bit: - [2010/03/10 09:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV:64bit: - [2010/03/10 09:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV:64bit: - [2010/03/10 09:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV:64bit: - [2009/07/15 01:14:38 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/06/09 09:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2011/08/18 10:05:46 | 001,692,480 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService)
SRV - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/03/09 23:52:23 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2010/10/22 12:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2010/08/25 21:28:54 | 002,823,000 | ---- | M] (Dell, Inc.) [Auto | Running] -- C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe -- (NOBU)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/11 13:06:06 | 000,193,824 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/05 19:07:28 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe -- (GameConsoleService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/04/14 13:01:38 | 000,530,304 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2011/04/14 13:01:38 | 000,441,840 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
DRV:64bit: - [2011/04/14 13:01:38 | 000,283,744 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
DRV:64bit: - [2011/04/14 13:01:38 | 000,190,520 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2011/04/14 13:01:38 | 000,121,376 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
DRV:64bit: - [2011/04/14 13:01:38 | 000,094,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
DRV:64bit: - [2011/04/14 13:01:38 | 000,075,160 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfenlfk.sys -- (mfenlfk)
DRV:64bit: - [2011/04/14 13:01:38 | 000,063,056 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
DRV:64bit: - [2011/03/11 01:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 01:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/03/19 04:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/10/01 01:34:30 | 000,121,872 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009/08/06 07:43:58 | 000,320,040 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:64bit: - [2009/07/15 03:23:30 | 006,096,896 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/05 13:00:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2009/03/29 21:01:34 | 000,056,448 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PTHDRBUS.sys -- (PTHDRBUS)
DRV:64bit: - [2006/11/01 13:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Search the Web"
FF - prefs.js..browser.search.useDBForOrder: ""
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Kim and Greg\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Kim and Greg\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/04/02 08:45:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/11/11 17:11:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/15 11:42:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/04/02 08:45:49 | 000,000,000 | ---D | M]

[2011/03/28 19:04:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kim and Greg\AppData\Roaming\Mozilla\Extensions
[2011/09/25 18:26:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kim and Greg\AppData\Roaming\Mozilla\Firefox\Profiles\j96vl9cu.default\extensions
[2011/05/16 18:13:39 | 000,001,742 | ---- | M] () -- C:\Users\Kim and Greg\AppData\Roaming\Mozilla\Firefox\Profiles\j96vl9cu.default\searchplugins\search-the-web.xml
[2012/01/19 21:18:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/01/19 21:18:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2011/11/24 16:17:59 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/04/14 13:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
[2012/01/15 10:58:55 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/01/15 10:58:55 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Kim and Greg\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Kim and Greg\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Chrome NaCl (Enabled) = C:\Users\Kim and Greg\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\Kim and Greg\AppData\Local\Google\Chrome\Application\15.0.874.121\gears.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Kim and Greg\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.31.137.7_0\McChPlg.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Kim and Greg\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\Kim and Greg\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: SiteAdvisor = C:\Users\Kim and Greg\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\
CHR - Extension: Poppit = C:\Users\Kim and Greg\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: AT_YannArthus-BertrandV2 = C:\Users\Kim and Greg\AppData\Local\Google\Chrome\User Data\Default\Extensions\plaekpceeonanmjojailaojkconcgofc\3_0\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110510083805.dll (McAfee, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20110510083805.dll (McAfee, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Corel File Shell Monitor] C:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe File not found
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Standby] C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe (Corel)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Corel Photo Downloader] C:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe (Corel, Inc.)
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - Startup: C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DA0ECF33-EC52-4F76-8D34-8F3C718F9179}: DhcpNameServer = 192.168.0.1 192.168.1.254
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/21 18:21:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/01/21 17:52:56 | 000,000,000 | ---D | C] -- C:\Users\Kim and Greg\Desktop\temp stuff
[2012/01/19 21:33:13 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/01/19 21:27:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2012/01/19 21:18:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/01/19 20:50:14 | 000,000,000 | ---D | C] -- C:\Users\Kim and Greg\AppData\Roaming\Roxio Log Files
[2012/01/19 17:54:24 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Kim and Greg\Desktop\OTL.exe
[2012/01/15 11:29:17 | 000,000,000 | ---D | C] -- C:\Windows\Minidump

========== Files - Modified Within 30 Days ==========

[2012/01/21 18:21:43 | 000,001,790 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Center.lnk
[2012/01/21 18:19:33 | 000,000,506 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012/01/21 18:19:30 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/21 18:19:27 | 334,737,407 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/21 17:42:00 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1688888446-1463142418-4294190705-1000UA.job
[2012/01/21 17:42:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1688888446-1463142418-4294190705-1000Core.job
[2012/01/21 09:54:22 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/21 09:54:22 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/21 09:51:31 | 000,726,316 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/21 09:51:31 | 000,624,034 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/01/21 09:51:31 | 000,106,410 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/01/19 21:27:37 | 000,002,021 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/01/19 20:59:14 | 000,376,312 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/01/19 17:54:29 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Kim and Greg\Desktop\OTL.exe
[2012/01/17 19:08:32 | 520,768,043 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/01/16 21:13:54 | 000,003,350 | -HS- | M] () -- C:\ProgramData\KGyGaAvL.sys
[2012/01/16 14:08:53 | 000,006,144 | ---- | M] () -- C:\Users\Kim and Greg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/15 17:46:08 | 000,002,441 | ---- | M] () -- C:\Users\Kim and Greg\Desktop\Google Chrome.lnk
[2012/01/15 12:10:24 | 000,001,181 | ---- | M] () -- C:\Users\Kim and Greg\Desktop\System Checkup.lnk

========== Files Created - No Company Name ==========

[2012/01/19 21:27:37 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/19 21:27:37 | 000,002,021 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/01/15 12:10:23 | 000,001,181 | ---- | C] () -- C:\Users\Kim and Greg\Desktop\System Checkup.lnk
[2012/01/15 12:01:56 | 520,768,043 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/04/02 08:41:05 | 000,221,279 | ---- | C] () -- C:\Windows\hpoins19.dat
[2011/04/02 08:41:05 | 000,013,898 | ---- | C] () -- C:\Windows\hpomdl19.dat
[2011/04/01 15:32:47 | 000,000,008 | RHS- | C] () -- C:\ProgramData\6959BDB2A3.sys
[2011/04/01 15:17:43 | 000,006,144 | ---- | C] () -- C:\Users\Kim and Greg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/01 15:17:29 | 000,003,350 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2011/03/30 13:00:54 | 000,042,108 | ---- | C] () -- C:\Windows\SysWow64\fun_avutil.dll
[2011/03/30 13:00:53 | 003,566,434 | ---- | C] () -- C:\Windows\SysWow64\fun_avcodec.dll
[2011/03/30 13:00:53 | 000,827,392 | ---- | C] () -- C:\Windows\SysWow64\Mpeg4System.dll
[2011/03/30 13:00:53 | 000,167,936 | ---- | C] () -- C:\Windows\SysWow64\Mpeg4Tools.dll
[2011/03/30 13:00:53 | 000,122,880 | ---- | C] () -- C:\Windows\SysWow64\Mpeg4DSF.dll
[2011/03/30 13:00:52 | 000,241,664 | ---- | C] () -- C:\Windows\SysWow64\AMR.dll
[2011/03/30 13:00:52 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\EvrcDecDll.dll
[2011/03/30 13:00:52 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\AMRDSF.dll
[2011/03/10 01:45:11 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/03/29 20:36:45 | 000,581,872 | ---- | C] () -- C:\Windows\SysWow64\WODCERTIFICATE.DLL
[2009/03/29 20:34:41 | 000,631,472 | ---- | C] () -- C:\Windows\SysWow64\brgrt.DLL

========== LOP Check ==========

[2011/06/09 14:44:51 | 000,000,000 | ---D | M] -- C:\Users\Kim and Greg\AppData\Roaming\Diploma
[2011/03/30 13:37:28 | 000,000,000 | ---D | M] -- C:\Users\Kim and Greg\AppData\Roaming\Pantech
[2011/09/11 18:49:14 | 000,000,000 | ---D | M] -- C:\Users\Kim and Greg\AppData\Roaming\PeaceCraft2
[2011/09/11 16:27:09 | 000,000,000 | ---D | M] -- C:\Users\Kim and Greg\AppData\Roaming\PeaceCraft3
[2011/07/24 14:32:35 | 000,000,000 | ---D | M] -- C:\Users\Kim and Greg\AppData\Roaming\PlayFirst
[2011/04/01 15:33:33 | 000,000,000 | ---D | M] -- C:\Users\Kim and Greg\AppData\Roaming\Ulead Systems
[2011/03/16 19:48:53 | 000,000,000 | ---D | M] -- C:\Users\Kim and Greg\AppData\Roaming\WildTangent
[2011/08/29 18:12:34 | 000,000,000 | ---D | M] -- C:\Users\Kim and Greg\AppData\Roaming\Windows Live Writer
[2011/09/21 13:12:57 | 000,032,606 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/01/21 18:19:33 | 000,000,506 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



< End of report >
LaJuene
Regular Member
 
Posts: 24
Joined: July 11th, 2008, 11:41 am

Re: Malware removal help needed please.

Unread postby LaJuene » January 21st, 2012, 7:55 pm

I have tried to post the log from Malwarebytes' Anti-Malware, but it is telling me that it is about 9 times larger than what is allowed so I cannot post it. I could try to copy and paste it a little at a time. Also, that program didn't give me an option to choose a quick scan, it just started running automatically. Now I have a big fat log that is too large to post. :) I need instructions.
LaJuene
Regular Member
 
Posts: 24
Joined: July 11th, 2008, 11:41 am

Re: Malware removal help needed please.

Unread postby askey127 » January 22nd, 2012, 8:12 am

Right below the box where you paste and type your reply, there is a separate area where you can browse to the correct Malwarebytes file and choose the "Add the Fil"e button to attach it to your reply. Then hit the submit button.

You do need to type something into the reply box as well even if it's only "Here it is"
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Malware removal help needed please.

Unread postby LaJuene » January 22nd, 2012, 10:08 am

It told me the file is too big, maximum allowed size is 256 kb. The file is 840 kb. Tried it twice. I typed something in the box like you said too.
LaJuene
Regular Member
 
Posts: 24
Joined: July 11th, 2008, 11:41 am

Re: Malware removal help needed please.

Unread postby askey127 » January 22nd, 2012, 1:01 pm

LaJuene,
Please try to copy and paste the last 100 lines or so of the file into a reply.
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Malware removal help needed please.

Unread postby LaJuene » January 22nd, 2012, 1:35 pm

Here is the last part of the log.

The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D0C9D2423BC2B240855C836B14DFB95 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\sr-Latn-CS\system.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\sv\Microsoft.VisualBasic.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4BF9CF6CEB027E24786FC77D5C70186B that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\sv\Microsoft.VisualBasic.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\sv\mscorlib.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B2AECDEE7117BC049B68C39038439439 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\sv\mscorlib.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\sv\mscorrc.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5AEFA2EDA59E84842BDC1CFBD85BD2AE that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\sv\mscorrc.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\sv\system.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6FF6ECB5C136C494CA62D27F209E87C5 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\sv\system.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Core.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0F0922A4B862CDB4B93272CD4F76E324 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Core.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\system.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\865460B2570116D4DB8E7781C28B5D1E that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\system.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Net.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\709608AB0A455C54F85E60EE37A37057 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Net.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Runtime.Serialization.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A1925B23D0EA4764DBC9645331131B3F that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Runtime.Serialization.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.ServiceModel.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5243EDA5308DFC14B93EA668ED8811F0 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.ServiceModel.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.ServiceModel.Web.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2C47A6F6ADA243F42B78CBAA67F09031 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.ServiceModel.Web.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Windows.Browser.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F31FB23AC6312F54292828B769C9F59D that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Windows.Browser.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Windows.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\04F96EBADC4ACE5459C4EF8FC2D7AD38 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Windows.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Xml.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA64042A7718DD74EA2A1685ABE9CC0F that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\System.Xml.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\th\Microsoft.VisualBasic.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DEAF746797E5594EAC5BED4D4E21583 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\th\Microsoft.VisualBasic.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\th\mscorlib.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\694CFD2398493684D9FDC3A4A6744371 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\th\mscorlib.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\th\mscorrc.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D9EF44D8B67EA4647B0FE1EC994A39B0 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\th\mscorrc.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\th\system.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\11CFC3304800860439472D2FEE6E16D1 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\th\system.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\tr\Microsoft.VisualBasic.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\979C55F1FD2AEA740A0638EF321CF811 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\tr\Microsoft.VisualBasic.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\tr\mscorlib.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7C63447C0C788B84CAF618D872CBAD8E that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\tr\mscorlib.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\tr\mscorrc.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC068540A070EDF4399980A157A69427 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\tr\mscorrc.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\tr\system.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B8849B760F1A93C4FB65DAD2D67A997E that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\tr\system.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\uk\Microsoft.VisualBasic.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E4D5B4B6A5D288438F3A4076C765485 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\uk\Microsoft.VisualBasic.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\uk\mscorlib.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B0756E042A791A489A4CA54611771CA that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\uk\mscorlib.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\uk\mscorrc.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F4662716771FF49489962539971390B8 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\uk\mscorrc.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\uk\system.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\03AF0BE9A1B53114AB81543103F7FAA4 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\uk\system.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\vi\Microsoft.VisualBasic.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27F1718DE49E0AA42AF296C03772CC07 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\vi\Microsoft.VisualBasic.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\vi\mscorlib.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE270CBEFB30AD24CBFAF222887935E9 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\vi\mscorlib.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\vi\mscorrc.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE3C1DF3E29D010419E7D0D35E08867D that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\vi\mscorrc.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\vi\system.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7324B59585A71344DBFE7965E093F69F that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\vi\system.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hans\Microsoft.VisualBasic.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45DB756EC1B9E26469C654E1DBD983E7 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hans\Microsoft.VisualBasic.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hans\mscorlib.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\534D892668E0B934588EF6FDE059959F that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hans\mscorlib.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hans\mscorrc.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CF87DE8854293742AE9DDCC26FE4FE1 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hans\mscorrc.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hans\system.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2305281243A93114992DCF4C58E57B74 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hans\system.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hant\Microsoft.VisualBasic.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC3D4F9B46CA6E24FB1D462D94C220C8 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hant\Microsoft.VisualBasic.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hant\mscorlib.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2CC8041D0925776478DE56FCD393CBD2 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hant\mscorlib.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hant\mscorrc.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47FC224F4B7326F449DB6F64FB6F7997 that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hant\mscorrc.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hant\system.resources.dll</Entry> <Details>The registry contains an entry for the font D7314F9862C648A4DB8BE2A5B47BE100 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A9AB32A51D2F6BE46889BF52018AB1FD that points to the missing file c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\zh-Hant\system.resources.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files (x86)\Mozilla Firefox\plugins</Entry> <Details>The registry contains an entry for the font Plugins under HKEY_LOCAL_MACHINE\software\Mozilla\Mozilla Firefox 8.0.1\extensions that points to the missing file C:\Program Files (x86)\Mozilla Firefox\plugins.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files (x86)\Pantech\Pantech PC Suite\P7000\{42620353-DE5E-415D-9011-81D661BB5E2C}\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\35302624E5EDD5140911186D16BBE5C2\InstallProperties that points to the missing file C:\Program Files (x86)\Pantech\Pantech PC Suite\P7000\{42620353-DE5E-415D-9011-81D661BB5E2C}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files (x86)\Pantech\Pantech PC Suite\P7000\{42620353-DE5E-415D-9011-81D661BB5E2C}\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{42620353-DE5E-415D-9011-81D661BB5E2C} that points to the missing file C:\Program Files (x86)\Pantech\Pantech PC Suite\P7000\{42620353-DE5E-415D-9011-81D661BB5E2C}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files (x86)\Pantech\Pantech PC Suite\P7000\{42620353-DE5E-415D-9011-81D661BB5E2C}\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\35302624E5EDD5140911186D16BBE5C2\SourceList\Net that points to the missing file C:\Program Files (x86)\Pantech\Pantech PC Suite\P7000\{42620353-DE5E-415D-9011-81D661BB5E2C}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files (x86)\Pantech\Pantech PC Suite\P7000\{42620353-DE5E-415D-9011-81D661BB5E2C}\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\35302624E5EDD5140911186D16BBE5C2\SourceList\Net that points to the missing file C:\Program Files (x86)\Pantech\Pantech PC Suite\P7000\{42620353-DE5E-415D-9011-81D661BB5E2C}\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files (x86)\Roxio\OEM\VideoCore 12\SbdData.dll</Entry> <Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4928C2BA-66EF-DC3F-E65E-9920FBB24820}\InprocServer32 that points to the missing file C:\Program Files (x86)\Roxio\OEM\VideoCore 12\SbdData.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files (x86)\Roxio\OEM\VideoUI 12\VUIAudioVideoMMPlugIn.dll</Entry> <Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AE4C0CB4-FA9B-CF0C-B8E7-E12DF1C54B77}\InProcServer32 that points to the missing file C:\Program Files (x86)\Roxio\OEM\VideoUI 12\VUIAudioVideoMMPlugIn.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files (x86)\Roxio\OEM\VideoUI 12\VUIAudioVideoMMPlugIn.dll</Entry> <Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\CLSID\{945980E9-F206-8898-532A-BBB3895C8648}\InProcServer32 that points to the missing file C:\Program Files (x86)\Roxio\OEM\VideoUI 12\VUIAudioVideoMMPlugIn.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files (x86)\Roxio\OEM\VideoUI 12\VUIDVDProjectMMPlugin.dll</Entry> <Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4049177A-292F-BE95-8B71-13076A8CAAD4}\InProcServer32 that points to the missing file C:\Program Files (x86)\Roxio\OEM\VideoUI 12\VUIDVDProjectMMPlugin.dll.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files (x86)\Windows Live\Writer\Plugins\</Entry> <Details>The registry contains an entry for the font 076CFAAAB965F2A4284B2449E5D03EFE under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CA30106D382A7D4D843A88E313A2323 that points to the missing file C:\Program Files (x86)\Windows Live\Writer\Plugins\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\OEM Links</Entry> <Details>The registry contains an entry for the font OEM Links under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders that points to the missing file C:\ProgramData\OEM Links.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\OEM Links</Entry> <Details>The registry contains an entry for the font OEM Links under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders that points to the missing file C:\ProgramData\OEM Links.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\ProgramData\WildTangent\oem-eula.exe</Entry> <Details>The registry contains an entry for the font 47825BBE2F63448428D86397E7AA60A1 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F9E4A652B6DD5B5468D8857F8955BD10 that points to the missing file C:\ProgramData\WildTangent\oem-eula.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\IXP000.TMP\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{7EC66A95-AC2D-4127-940B-0445A526AB2F} that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\IXP000.TMP\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\59A66CE7D2CA721449B040545A62BAF2\SourceList\Net that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\IXP000.TMP\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\59A66CE7D2CA721449B040545A62BAF2\SourceList\Net that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\IXP000.TMP\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\59A66CE7D2CA721449B040545A62BAF2\InstallProperties that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\mia1</Entry> <Details>The registry contains an entry for the font 2 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2493A37C8C487954F9B9EE22D7BC7A85\SourceList\Net that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\mia1.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\mia1</Entry> <Details>The registry contains an entry for the font 2 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2493A37C8C487954F9B9EE22D7BC7A85\SourceList\Net that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\mia1.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\mia1\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2493A37C8C487954F9B9EE22D7BC7A85\InstallProperties that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\mia1\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\mia1\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{C73A3942-84C8-4597-9F9B-EE227DCBA758} that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\mia1\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2493A37C8C487954F9B9EE22D7BC7A85\SourceList\Net that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\</Entry> <Details>The registry contains an entry for the font 2493A37C8C487954F9B9EE22D7BC7A85 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF2703DCD4F150B4EAAF1475A017F69E that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\</Entry> <Details>The registry contains an entry for the font 2493A37C8C487954F9B9EE22D7BC7A85 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CD0D34AC104ECFC45B9C3DC2B18DC43C that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2493A37C8C487954F9B9EE22D7BC7A85\SourceList\Net that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\</Entry> <Details>The registry contains an entry for the font 2493A37C8C487954F9B9EE22D7BC7A85 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1FE6EA05E1548214BBA632DD60546D3F that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\</Entry> <Details>The registry contains an entry for the font 2493A37C8C487954F9B9EE22D7BC7A85 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F65BCE05F3E6444AB33A7C52E71278E that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\</Entry> <Details>The registry contains an entry for the font 2493A37C8C487954F9B9EE22D7BC7A85 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5003DEB2CBAF1A343B28DB6F06EB7155 that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\miaE33D.tmp\data\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Users\ADMINI~1\AppData\Local\Temp\WildTangentOEM\bejeweled2deluxe-oem.exe</Entry> <Details>The registry contains an entry for the font 47825BBE2F63448428D86397E7AA60A1 under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1BA2F2A0BD1697C478F39016B991B71D that points to the missing file C:\Users\ADMINI~1\AppData\Local\Temp\WildTangentOEM\bejeweled2deluxe-oem.exe.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Windows\Installer\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}\ApplicationIcon.ico</Entry> <Details>The registry contains an entry for the font ProductIcon under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\076CFAAAB965F2A4284B2449E5D03EFE that points to the missing file C:\Windows\Installer\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}\ApplicationIcon.ico.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Windows\Installer\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}\ApplicationIcon.ico</Entry> <Details>The registry contains an entry for the font ProductIcon under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\076CFAAAB965F2A4284B2449E5D03EFE that points to the missing file C:\Windows\Installer\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}\ApplicationIcon.ico.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Windows\TEMP\IXP000.TMP\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\c1c4f01781cc94c4c8fb1542c0981a2a\InstallProperties that points to the missing file C:\Windows\TEMP\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Windows\TEMP\IXP000.TMP\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\c1c4f01781cc94c4c8fb1542c0981a2a\SourceList\Net that points to the missing file C:\Windows\TEMP\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Windows\TEMP\IXP000.TMP\</Entry> <Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2} that points to the missing file C:\Windows\TEMP\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Windows\TEMP\IXP000.TMP\</Entry> <Details>The registry contains an entry for the font 1 under HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\c1c4f01781cc94c4c8fb1542c0981a2a\SourceList\Net that points to the missing file C:\Windows\TEMP\IXP000.TMP\.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : file://C:\Windows\web\iejit.htm</Entry> <Details>The registry contains an entry for the font JITSetupPage under HKEY_LOCAL_MACHINE\software\Microsoft\Active Setup that points to the missing file file://C:\Windows\web\iejit.htm.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : file://C:\Windows\web\iejit.htm</Entry> <Details>The registry contains an entry for the font JITSetupPage under HKEY_LOCAL_MACHINE\software\Microsoft\Active Setup that points to the missing file file://C:\Windows\web\iejit.htm.</Details></EntryDetails> </Scanning> -<Scanning Section="Current User"><Description>Current User settings for installed programs may differ from System settings, be invalid, or orphaned.</Description><ErrorsInThisSection>45 Errors</ErrorsInThisSection> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\iolo\System Mechanic\Disk Medic\Automatic\Disk Drives key HKEY_CURRENT_USER\Software\iolo\System Mechanic\Disk Medic\Automatic\Disk Drives for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\iolo\System Mechanic\Disk Medic\Advanced\Disk Drives key HKEY_CURRENT_USER\Software\iolo\System Mechanic\Disk Medic\Advanced\Disk Drives for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\iolo\System Mechanic\PC Cleanup Tool\Deep Cleanup key HKEY_CURRENT_USER\Software\iolo\System Mechanic\PC Cleanup Tool\Deep Cleanup for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\iolo\System Mechanic\Registry Optimizer\Automatic Options key HKEY_CURRENT_USER\Software\iolo\System Mechanic\Registry Optimizer\Automatic Options for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\iolo\System Mechanic\PC Cleanup Tool\Quick Cleanup key HKEY_CURRENT_USER\Software\iolo\System Mechanic\PC Cleanup Tool\Quick Cleanup for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\ATI\ACE\Dismissables key HKEY_CURRENT_USER\Software\ATI\ACE\Dismissables for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cocgStates key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cocgStates for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\10.0\Acrobat.com key HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\10.0\Acrobat.com for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\9.0\Acrobat.com key HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\9.0\Acrobat.com for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\10.0\Acrobat.com.v2 key HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\10.0\Acrobat.com.v2 for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Pantech\Pantech PCSuite\at&t\1.0\PC Sync\Settings key HKEY_CURRENT_USER\Software\Pantech\Pantech PCSuite\at&t\1.0\PC Sync\Settings for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Pantech\Pantech PCSuite\at&t\1.0\FileManager\Settings key HKEY_CURRENT_USER\Software\Pantech\Pantech PCSuite\at&t\1.0\FileManager\Settings for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\PC-Doctor\PC-Doctor for Windows key HKEY_CURRENT_USER\Software\PC-Doctor\PC-Doctor for Windows for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\System\CurrentControlSet\Policies key HKEY_CURRENT_USER\System\CurrentControlSet\Policies for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Samsung\Samsung PC Studio 3\Image Editor\Settings key HKEY_CURRENT_USER\Software\Samsung\Samsung PC Studio 3\Image Editor\Settings for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\DestComp\Settings key HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\DestComp\Settings for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\iolo\System Mechanic\Registry Optimizer\Manual Options key HKEY_CURRENT_USER\Software\iolo\System Mechanic\Registry Optimizer\Manual Options for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\iolo\System Mechanic\Registry Optimizer\Exclusions key HKEY_CURRENT_USER\Software\iolo\System Mechanic\Registry Optimizer\Exclusions for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\iolo\System Mechanic\Startup Optimizer\Advanced\Exclusions key HKEY_CURRENT_USER\Software\iolo\System Mechanic\Startup Optimizer\Advanced\Exclusions for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\JavaSoft\Prefs key HKEY_CURRENT_USER\Software\JavaSoft\Prefs for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\iolo\System Mechanic\Startup Optimizer\Automatic\Exclusions key HKEY_CURRENT_USER\Software\iolo\System Mechanic\Startup Optimizer\Automatic\Exclusions for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cBottomView key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\RememberedViews\cNoCategoryFiles\c1\cViewDef\cBottomView for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\PrintComplete\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\PrintComplete\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Open\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Open\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\RestoreDown\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\RestoreDown\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemQuestion\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemQuestion\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\RestoreUp\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\RestoreUp\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Maximize\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Maximize\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Close\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Close\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\MenuCommand\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\MenuCommand\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Minimize\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Minimize\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\MenuPopup\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\MenuPopup\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\AppGPFault\.Default key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\AppGPFault\.Default for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVGeneral\cDockables key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVGeneral\cDockables for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVConversionToPDF\cSettings key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVConversionToPDF\cSettings for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVGeneral\cFavoritesCommandsDesktop key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVGeneral\cFavoritesCommandsDesktop for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVGeneral\cToolbars\cBasicCommenting key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVGeneral\cToolbars\cBasicCommenting for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVGeneral\cToolbars\cAdvCommenting key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVGeneral\cToolbars\cAdvCommenting for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Control Panel\don't load key HKEY_CURRENT_USER\Control Panel\don't load for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Control Panel\Desktop\LanguageConfiguration key HKEY_CURRENT_USER\Control Panel\Desktop\LanguageConfiguration for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Control Panel\Personalization\Desktop Slideshow key HKEY_CURRENT_USER\Control Panel\Personalization\Desktop Slideshow for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVConversionFromPDF\cSettings key HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\10.0\AVConversionFromPDF\cSettings for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Empty Key</Entry> <Details>The HKEY_CURRENT_USER\Network key HKEY_CURRENT_USER\Network for this object contains no data. This subkey can be deleted for this object.</Details></EntryDetails> -<EntryDetails><Entry>Missing File : C:\Program Files (x86)\Pure Networks\Network Magic\notify.wav</Entry> <Details>The registry contains an entry for the font under HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Network Magic\NetworkMagic_Notify\.current that points to the missing file C:\Program Files (x86)\Pure Networks\Network Magic\notify.wav.</Details></EntryDetails> </Scanning> -<Scanning Section="Memory Dumps"><Description>Comprises of contents of your computer's memory when an application crashes and is useful only for debugging purposes by a technician. This can be deleted.</Description><ErrorsInThisSection>2 Errors</ErrorsInThisSection> -<EntryDetails><Entry>011712-12558-01.dmp</Entry> <Details>Memory dump file C:\Windows\minidump\011712-12558-01.dmp of 268 KB size found in dump folder.</Details></EntryDetails> -<EntryDetails><Entry>MEMORY.DMP</Entry> <Details>Memory dump file C:\Windows\MEMORY.DMP of 508562 KB size found in dump folder.</Details></EntryDetails> </Scanning> -<Scanning Section="Recent Documents"><Description>Displays links of recently used documents on your computer that can be deleted periodically to protect your privacy and avoid misuse of your personal data.</Description><ErrorsInThisSection>91 Errors</ErrorsInThisSection> -<EntryDetails><Entry>01192012_213313.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\01192012_213313.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>01212012_181536.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\01212012_181536.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>100SSCAM.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\100SSCAM.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>108-syllabus.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\108-syllabus.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>2011-05-30.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\2011-05-30.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>A New York Ghost Story.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\A New York Ghost Story.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>autorun.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\autorun.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Back view.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Back view.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>beats.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\beats.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>bug and moog 2011.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\bug and moog 2011.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>CD Drive.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CD Drive.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>checkhd.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\checkhd.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Cover Letter.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Cover Letter.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>creativeworld.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\creativeworld.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>DDS.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\DDS.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>dell diag.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\dell diag.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>desktop.ini</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\desktop.ini found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Documents.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Documents.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Downloads.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Downloads.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Driveway view.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Driveway view.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>europe_map1.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\europe_map1.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Extras.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Extras.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Front view2.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Front view2.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Greg's Stuff.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Greg's Stuff.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>HIS 101-Part Three.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\HIS 101-Part Three.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>HIS 101-Part Two.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\HIS 101-Part Two.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>HIS 108 - Assignments.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\HIS 108 - Assignments.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>HIS 108.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\HIS 108.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>house photos (2).lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\house photos (2).lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>House photos.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\House photos.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>index.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\index.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Kim's Stuff.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Kim's Stuff.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Kimberly Collier, Agency Test, RE120.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Kimberly Collier, Agency Test, RE120.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>KRS & KAR.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\KRS & KAR.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>London questionnaire.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\London questionnaire.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>magicbox.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\magicbox.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Master Bath.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Master Bath.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Master Bedroom.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Master Bedroom.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Master Bedroom2.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Master Bedroom2.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Master Bedroom3.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Master Bedroom3.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Master Bedroom4.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Master Bedroom4.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Master Bedroom5.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Master Bedroom5.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>MBRCheck_01.21.12_11.07.36.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\MBRCheck_01.21.12_11.07.36.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Merry_Christmas__by_chopeh.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Merry_Christmas__by_chopeh.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Muscle Strain Treatment.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Muscle Strain Treatment.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>music-beats.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\music-beats.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>My Pictures.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\My Pictures.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>OS (C).lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\OS (C).lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>OTL.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\OTL.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Pictures.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Pictures.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>RE100 and RE120.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\RE100 and RE120.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Resume' 2011.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Resume' 2011.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>scan0001.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\scan0001.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Stairway.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Stairway.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Strayer_Brief_Sources.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Strayer_Brief_Sources.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>TaxReturn2011.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\TaxReturn2011.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>TDSSKiller.2.7.6.0_19.01.2012_22.04.21_log.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\TDSSKiller.2.7.6.0_19.01.2012_22.04.21_log.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>TRAVELDRIVE (I).lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\TRAVELDRIVE (I).lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>tumblr_lpn2nqz8Pr1qm0fxjo1_500.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\tumblr_lpn2nqz8Pr1qm0fxjo1_500.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>uninstallLog.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\uninstallLog.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Untitled.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Untitled.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>Ways of the World_Brief_Sources.lnk</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\Ways of the World_Brief_Sources.lnk found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>12dc1ea8e34b5a6.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\12dc1ea8e34b5a6.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>1b4dd67f29cb1962.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>1f4664c3850d490b.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\1f4664c3850d490b.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>39d55a51c3c7c42a.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\39d55a51c3c7c42a.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>5d696d521de238c3.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\5d696d521de238c3.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>74d7f43c1561fc1e.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\74d7f43c1561fc1e.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>7e4dca80246863e3.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\7e4dca80246863e3.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>9821aa5a1b3e530e.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\9821aa5a1b3e530e.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>9b9cdc69c1c24e2b.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\9b9cdc69c1c24e2b.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>a7bd71699cd38d1c.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\a7bd71699cd38d1c.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>ee462c3b81abb6f6.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\AutomaticDestinations\ee462c3b81abb6f6.automaticDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>122c907c4dc5911f.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\122c907c4dc5911f.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>1461132e553e2e6c.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\1461132e553e2e6c.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>18fa158a64c9508a.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\18fa158a64c9508a.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>1b4dd67f29cb1962.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\1b4dd67f29cb1962.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>1eb796d87c32eff9.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\1eb796d87c32eff9.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>28c8b86deab549a1.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\28c8b86deab549a1.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>5afe4de1b92fc382.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>5d696d521de238c3.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\5d696d521de238c3.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>5df4765359170e26.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\5df4765359170e26.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>634bd393510dd415.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\634bd393510dd415.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>6b8904e2b6864f0f.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\6b8904e2b6864f0f.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>6c810151099d596c.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\6c810151099d596c.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>74d7f43c1561fc1e.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\74d7f43c1561fc1e.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>7e4dca80246863e3.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\7e4dca80246863e3.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>9645f58513b1a821.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\9645f58513b1a821.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>9821aa5a1b3e530e.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\9821aa5a1b3e530e.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>9f29afe9a425456d.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\9f29afe9a425456d.customDestinations-ms found in recent documents.</Details></EntryDetails> -<EntryDetails><Entry>b29c2867f702c3ab.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\appdata\roaming\microsoft\windows\recent\CustomDestinations\b29c2867f702c3ab.customDestinations-ms found in recent documents.</Details></EntryDetails> </Scanning> -<Scanning Section="Recycle Bin"><Description>Collects all the files and folders that you have deleted on your computer. These can be deleted.</Description><ErrorsInThisSection>37 Errors</ErrorsInThisSection> -<EntryDetails><Entry>$I3GQV65</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$I3GQV65 found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$I769L9R.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$I769L9R.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$I81BGEE.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$I81BGEE.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$I862JMJ.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$I862JMJ.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$I87GLBM.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$I87GLBM.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$I8K15JM.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$I8K15JM.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$I8Q0P4H.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$I8Q0P4H.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$I8T10SZ.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$I8T10SZ.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$IAHP8I8.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$IAHP8I8.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$IBDZ596.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$IBDZ596.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$IC871C5.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$IC871C5.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$ICCAZGI.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$ICCAZGI.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$ID9J9DI.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$ID9J9DI.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$IEHGDBD.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$IEHGDBD.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$IEQH1DQ.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$IEQH1DQ.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$IOSR9XH.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$IOSR9XH.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$IPEAZGR.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$IPEAZGR.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$IQXNASS.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$IQXNASS.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$IUHHCPR.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$IUHHCPR.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$R769L9R.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$R769L9R.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$R81BGEE.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$R81BGEE.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$R862JMJ.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$R862JMJ.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$R87GLBM.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$R87GLBM.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$R8K15JM.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$R8K15JM.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$R8Q0P4H.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$R8Q0P4H.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$R8T10SZ.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$R8T10SZ.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$RAHP8I8.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$RAHP8I8.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$RBDZ596.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$RBDZ596.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$RC871C5.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$RC871C5.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$RCCAZGI.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$RCCAZGI.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$RD9J9DI.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$RD9J9DI.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$REHGDBD.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$REHGDBD.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$REQH1DQ.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$REQH1DQ.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$ROSR9XH.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$ROSR9XH.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$RPEAZGR.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$RPEAZGR.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$RQXNASS.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$RQXNASS.JPG found in recycle bin.</Details></EntryDetails> -<EntryDetails><Entry>$RUHHCPR.JPG</Entry> <Details>File C:\$Recycle.Bin\S-1-5-21-1688888446-1463142418-4294190705-1000\$RUHHCPR.JPG found in recycle bin.</Details></EntryDetails> </Scanning> -<Scanning Section="Shortcuts"><Description>Some shortcuts on your system refer to missing targets.</Description><ErrorsInThisSection>8 Errors</ErrorsInThisSection> -<EntryDetails><Entry>creativeworld</Entry> <Details>The shortcut c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\creativeworld.lnk points to the missing target c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\creativeworld.lnk and can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>HIS 101-Part Three</Entry> <Details>The shortcut c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\HIS 101-Part Three.lnk points to the missing target c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\HIS 101-Part Three.lnk and can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>HIS 101-Part Two</Entry> <Details>The shortcut c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\HIS 101-Part Two.lnk points to the missing target c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\HIS 101-Part Two.lnk and can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>HIS 108</Entry> <Details>The shortcut c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\HIS 108.lnk points to the missing target c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\HIS 108.lnk and can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>index</Entry> <Details>The shortcut c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\index.lnk points to the missing target c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\index.lnk and can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>magicbox</Entry> <Details>The shortcut c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\magicbox.lnk points to the missing target c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\magicbox.lnk and can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>music-beats</Entry> <Details>The shortcut c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\music-beats.lnk points to the missing target c:\users\kim and greg\appdata\roaming\microsoft\windows\recent\music-beats.lnk and can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>System Checkup</Entry> <Details>The shortcut c:\users\kim and greg\desktop\System Checkup.lnk points to the missing target c:\users\kim and greg\desktop\System Checkup.lnk and can be deleted.</Details></EntryDetails> </Scanning> -<Scanning Section="Taskbar Jumplist"><Description>Displays links of recently used applications and documents on the task bar. These can be deleted to protect your privacy and avoid misuse of personal data.</Description><ErrorsInThisSection>29 Errors</ErrorsInThisSection> -<EntryDetails><Entry>12dc1ea8e34b5a6.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\12dc1ea8e34b5a6.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>1b4dd67f29cb1962.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>1f4664c3850d490b.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1f4664c3850d490b.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>39d55a51c3c7c42a.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\39d55a51c3c7c42a.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>5d696d521de238c3.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\5d696d521de238c3.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>74d7f43c1561fc1e.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\74d7f43c1561fc1e.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>7e4dca80246863e3.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\7e4dca80246863e3.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>9821aa5a1b3e530e.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\9821aa5a1b3e530e.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>9b9cdc69c1c24e2b.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\9b9cdc69c1c24e2b.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>a7bd71699cd38d1c.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\a7bd71699cd38d1c.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>ee462c3b81abb6f6.automaticDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\ee462c3b81abb6f6.automaticDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>122c907c4dc5911f.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\122c907c4dc5911f.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>1461132e553e2e6c.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1461132e553e2e6c.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>18fa158a64c9508a.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\18fa158a64c9508a.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>1b4dd67f29cb1962.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1b4dd67f29cb1962.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>1eb796d87c32eff9.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1eb796d87c32eff9.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>28c8b86deab549a1.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\28c8b86deab549a1.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>5afe4de1b92fc382.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>5d696d521de238c3.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>5df4765359170e26.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5df4765359170e26.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>634bd393510dd415.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\634bd393510dd415.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>6b8904e2b6864f0f.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6b8904e2b6864f0f.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>6c810151099d596c.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6c810151099d596c.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>74d7f43c1561fc1e.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\74d7f43c1561fc1e.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>7e4dca80246863e3.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7e4dca80246863e3.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>9645f58513b1a821.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9645f58513b1a821.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>9821aa5a1b3e530e.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9821aa5a1b3e530e.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>9f29afe9a425456d.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9f29afe9a425456d.customDestinations-ms found in task bar jump list</Details></EntryDetails> -<EntryDetails><Entry>b29c2867f702c3ab.customDestinations-ms</Entry> <Details>File C:\Users\Kim and Greg\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\b29c2867f702c3ab.customDestinations-ms found in task bar jump list</Details></EntryDetails> </Scanning> -<Scanning Section="Temporary Files"><Description>These are files created and left behind by applications and programs when they are launched. These can be deleted.</Description><ErrorsInThisSection>16 Errors</ErrorsInThisSection> -<EntryDetails><Entry>859A95E3.TMP</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\859a95e3.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>ArmUI.ini</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\armui.ini found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>hpqddusr.log</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\hpqddusr.log found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>MAR56B6.tmp</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\mar56b6.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>MAR5725.tmp</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\mar5725.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>RedboxLog.txt</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\redboxlog.txt found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>ci.log</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\apnlogs\ci.log found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>iw.log</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\apnlogs\iw.log found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>APNLogs</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\apnlogs found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>partnercobranding.dat</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\asksearch\partnercobranding.dat found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>AskSearch</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\asksearch found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>soref.dll</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\is-4uug1.tmp\soref.dll found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>is-4UUG1.tmp</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\is-4uug1.tmp found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>Low</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\low found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>WPDNSE</Entry> <Details>File c:\users\kim and greg\appdata\local\temp\wpdnse found in temporary files can be deleted.</Details></EntryDetails> -<EntryDetails><Entry>hpqddsvc.log</Entry> <Details>File c:\windows\temp\hpqddsvc.log found in temporary files can be deleted.</Details></EntryDetails> </Scanning> </AROScanLog>
LaJuene
Regular Member
 
Posts: 24
Joined: July 11th, 2008, 11:41 am

Re: Malware removal help needed please.

Unread postby askey127 » January 22nd, 2012, 2:05 pm

LaJuene,
I must say I have never seen anything like that before.
Looks like part of a log in html instead of plain text.

Would you please start Malwarebytes again, and run a Quick Scan?
Then look in the Malwarebytes under the logs tab for the latest log. They are listed by time/date stamp.
You should have one in there from the time/date when you ran the Quick Scan.
Double click that latest log - it should pop up in Notepad, and see if you can copy and paste the results here.
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Malware removal help needed please.

Unread postby LaJuene » January 22nd, 2012, 3:01 pm

Yeah, I'm not sure the program you are telling me to use is the one that I have because it does not have a quick scan feature, I cannot view my logs, and it does not produce a notepad log. The program I have downloaded from the link you provided is called ARO 2011 by support.com. And since I ran it, my computer has crashed to the blue screen two more times. One time I didn't think I was going to get it started back again. This is the program that was in the free column of the link you provided. If you want remote access to my desktop, you can see what I am seeing, but I don't think this is the program that you are thinking I have.
LaJuene
Regular Member
 
Posts: 24
Joined: July 11th, 2008, 11:41 am

Re: Malware removal help needed please.

Unread postby askey127 » January 22nd, 2012, 3:31 pm

LaJuene,
Let's go from the beginning. You are running the wrong program.
ARO2011 is a Registry Optimizer that you should NEVER use.
It can permanently damage your machine.
Did you notice that the icon was not correct?

Please follow these directions carefully if you can, in this sequence.
------------------------------------------------
Remove Programs Using Control Panel
From Start, Control Panel, click on Programs and Features
Click each Entry, as follows, one by one, if it exists, choose Uninstall, and give permission to Continue:

ARO 2011

Take extra care in answering questions posed by any Uninstaller.
------------------------------------------------
Download and Run Rkill
Please download and run the tool named Rkill, which may help in allowing other programs to run.
There are different versions with different names. If one of them won't run ,then download and try to run one of the other ones.
After the download, Vista and Win7 users will need to right click the icon and choose Run as Administrator. XP Users can just double-click.
You only need to get ONE of these to run, not all of them. You may get warnings from your antivirus about any of these tools. Either ignore the warnings or shutdown your antivirus.
Please download Rkill from one of the following links (note the different names) and save to your Desktop:
iExplore.exe
Rkill.exe
eXplorer.exe
RKill.com
RKill.scr
Rkill.pif
uSeRiNiT.exe
  • Double-click on the iExplore, Rkill, eXplorer, or uSeRiNiT desktop icon to run the tool.(If using Vista or Windows 7 right-click on it and choose Run As Administrator).
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully. You only have to get any one of them to run successfully once.
  • If you get a Warning Message when you try to run it, run it again while the Warning Message is still displayed.
  • If it doesn't run on the first try, please try to run it another two or three times.
  • If it still does not run, delete the desktop entry. Then download and use the one provided in the next link.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided after trying each a few times, please let me know.
----------------------------------------------------------------------------------
Download and Run MalwareBytes' Anti-Malware It is free for non-business use.
Please go here to the Download Location, click on Download in the Free column..
When the next page comes up, click on the Download Now button.
  • After clicking on the download and choosing Save, the "Save to location" dialog will come up.
  • Click the browse folders button, then click on Desktop on the left as the location for the installer and click Save again. Close the dialog when the download is complete.
  • You should now have a desktop icon named mbam-setup.exe. (If the download was saved somewhere else, locate it and copy or move it to your desktop).
  • Right click it, choose Run as administrator and Continue
  • Let it install where it wants to, with the default settings, and click Finish.
  • If an update is found, it will download and install the latest version. A shield symbol will show on the desktop icon while it is updating, and will disappear when it's done.
  • If necessary, start Malwarebytes Anti-Malware again.
    (You can Decline any Offer for a Trial if you don't want the paid version)
  • Once the program has started up, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • If it found any malware items, check all items except items in the C:\System Volume Information folder... and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location, and post the contents in your reply.
  • The log can also be found using the "Logs" tab in the program. You can click any "Scan" log listed to open its contents. The logs are listed and named by time/date stamp.

askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Malware removal help needed please.

Unread postby LaJuene » January 22nd, 2012, 4:11 pm

Hey, I followed your instructions before, but I don't think either of us thought that when I followed the link you provided, I would end up with something I didn't need. I noticed that the program name was not the same as what you were telling me it should be but by then it had already ran. What do I know? Enough to be dangerous is about it. Which is why I need your help and can't do this myself. Atleast we are back on track now.

I am assuming you want the MalwareBytes log so I have attached it because it was too large to post. Let me know if you want the rkill log and I will post it too.
You do not have the required permissions to view the files attached to this post.
LaJuene
Regular Member
 
Posts: 24
Joined: July 11th, 2008, 11:41 am

Re: Malware removal help needed please.

Unread postby askey127 » January 23rd, 2012, 9:04 am

LaJuene,
Open your McAfee Security Center, have it run a full scan and remove anything it finds.
I think your machine should be free of malware at this point.
Stay away from any Registry enhancer/booster/optimizer/helper programs. They are dangerous for your machine.

If you get any further Blue Screens, it is most likely a hardware problem (something wrong with graphics card, motherboard, hard drive, etc.) which would need to be addressed by a repair shop.
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Malware removal help needed please.

Unread postby LaJuene » January 23rd, 2012, 8:27 pm

Will do, thanks for your help. I really appreciate it. Have a great week!

Kim Collier (LaJuene)
LaJuene
Regular Member
 
Posts: 24
Joined: July 11th, 2008, 11:41 am

Re: Malware removal help needed please.

Unread postby askey127 » January 23rd, 2012, 9:36 pm

this topic is now closed.

We are pleased we could help you resolve your computer's malware issues.

If you would like to make a comment or leave a compliment regarding the help you have received, please see Feedback for Our Helpers - Say "Thanks" Here.
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA
Advertisement
Register to Remove

Previous

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 107 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware