WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionCertain programs won't open.. help EmptyCertain programs won't open.. help

more_horiz
Ok so for a bit Ie wouldn't open.. But I fixed that by doing some stuff in regedit But still there is something wrong.. Here is the otl log..

descriptionCertain programs won't open.. help EmptyRe: Certain programs won't open.. help

more_horiz
OTL Extras logfile created on: 2/5/2011 3:55:24 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Chelsie\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.65 Gb Total Space | 164.38 Gb Free Space | 75.18% Space Free | Partition Type: NTFS
Drive D: | 13.94 Gb Total Space | 2.31 Gb Free Space | 16.54% Space Free | Partition Type: NTFS
Drive E: | 99.18 Mb Total Space | 92.52 Mb Free Space | 93.28% Space Free | Partition Type: FAT32
Drive F: | 2.75 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: CHELSIE-PC | User Name: Chelsie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{10F539B1-31AF-43BF-9F0C-0EB66E918922}" = HP Quick Launch
"{26A24AE4-039D-4CA4-87B4-2F86416017FF}" = Java(TM) 6 Update 17 (64-bit)
"{33EB1061-ABF1-4470-A540-32E97A610536}" = Apple Mobile Device Support
"{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5F02C14D-A630-4771-8409-0BA89FCCA8D6}" = iTunes
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{223E2363-6643-49CB-A062-59A9858EE8EE}" = HP Software Framework
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{43BA31BA-04BD-2EA3-0A60-A9C54E06D3F2}" = muvee Reveal
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{47D7C9B8-BD44-4D2E-9040-E946477B2F9A}" = Microsoft Live Search Toolbar
"{495A8A3C-8FD0-4C46-9979-95C26181A1AB}" = HP Support Assistant
"{49A143E9-4A6A-43E7-86B1-388194C79248}" = HP Smart Web Printing
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{54CC7901-804D-4155-B353-21F0CC9112AB}" = HP Wireless Assistant
"{54DF7BDA-1058-4D53-B3D4-2344C69B7D0C}" = Ragnarok Online
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76703039-C98C-4e62-A12C-4D7066BE9985}" = The Sims™ 2 University Life Collection
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}" = Spin & Win
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{901F0D4C-009D-1112-8DE4-03599E7B0C5C}" = REALTEK Wireless LAN Software
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A4317FB-5775-4FB3-BDC9-995595106F1F}" = HP User Guides 0178
"{A1DD0268-4069-4D39-B6D2-E00DB50CA9C4}" = League of Legends
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X
"{C22E50B4-B9D0-4a07-B1F3-12362514FEA7}" = The Sims™ 2 Double Deluxe
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}" = Adobe Shockwave Player
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E63E34A7-E552-412B-9E40-FD6FC5227ABA}_is1" = Uniblue RegistryBooster
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"BFGC" = Big Fish Games: Game Manager
"BFG-Reincarnations - Uncover the Past Collector's Edition" = Reincarnations: Uncover the Past Collector's Edition
"EADM" = EA Download Manager
"GamesBar" = GamesBar 2.0.1.73
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Smart Web Printing" = HP Smart Web Printing
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"My HP Game Console" = HP Game Console
"NIS" = Norton Internet Security
"Plants vs. Zombies" = Plants vs. Zombies
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WT082122" = Blackhawk Striker 2
"WT082124" = Blasterball 3
"WT082133" = Dora's Carnival Adventure
"WT082141" = FATE
"WT082168" = Penguins!
"WT082170" = Plants vs. Zombies
"WT082171" = Poker Superstars III
"WT082172" = Polar Bowler
"WT082173" = Polar Golfer
"WT082188" = Virtual Families
"WT082189" = Wheel of Fortune 2
"WT082192" = Bejeweled 2 Deluxe
"WT082200" = Chuzzle Deluxe
"WT082241" = Virtual Villagers - The Secret City
"WT082396" = Diner Dash 2 Restaurant Rescue
"WT082438" = Build-a-lot 2
"WT082442" = Faerie Solitaire
"WT082443" = Jewel Quest 3
"WT082456" = Mystery P.I. - The New York Fortune
"WT082463" = Zuma's Revenge
"WT082468" = Jewel Quest Solitaire 2
"WT083477" = Cake Mania
"WT083484" = Escape Rosecliff Island
"WT083491" = TextTwist 2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/12/2011 10:51:00 PM | Computer Name = Chelsie-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 1/12/2011 10:51:00 PM | Computer Name = Chelsie-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 13026

Error - 1/12/2011 10:51:00 PM | Computer Name = Chelsie-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 13026

Error - 1/12/2011 10:51:29 PM | Computer Name = Chelsie-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 1/12/2011 10:51:29 PM | Computer Name = Chelsie-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 12948

Error - 1/12/2011 10:51:29 PM | Computer Name = Chelsie-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 12948

Error - 1/12/2011 10:51:58 PM | Computer Name = Chelsie-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 1/12/2011 10:51:58 PM | Computer Name = Chelsie-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 12777

Error - 1/12/2011 10:51:58 PM | Computer Name = Chelsie-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 12777

Error - 1/12/2011 10:52:22 PM | Computer Name = Chelsie-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

[ System Events ]
Error - 1/23/2011 9:14:42 PM | Computer Name = Chelsie-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 47.

Error - 1/23/2011 9:14:42 PM | Computer Name = Chelsie-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 47.

Error - 1/23/2011 9:14:42 PM | Computer Name = Chelsie-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 47.

Error - 1/23/2011 9:14:42 PM | Computer Name = Chelsie-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 47.

Error - 1/23/2011 9:14:42 PM | Computer Name = Chelsie-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 47.

Error - 1/23/2011 9:14:44 PM | Computer Name = Chelsie-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 47.

Error - 1/23/2011 9:14:44 PM | Computer Name = Chelsie-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 47.

Error - 1/23/2011 9:14:47 PM | Computer Name = Chelsie-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 47.

Error - 1/23/2011 9:14:47 PM | Computer Name = Chelsie-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 47.

Error - 1/24/2011 12:44:22 AM | Computer Name = Chelsie-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{A39FCA36-3081-4831-AF98-508089FB8FD4}
because another computer on the network has the same name. The server could not

descriptionCertain programs won't open.. help EmptyRe: Certain programs won't open.. help

more_horiz
OTL logfile created on: 2/5/2011 3:55:24 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Chelsie\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.65 Gb Total Space | 164.38 Gb Free Space | 75.18% Space Free | Partition Type: NTFS
Drive D: | 13.94 Gb Total Space | 2.31 Gb Free Space | 16.54% Space Free | Partition Type: NTFS
Drive E: | 99.18 Mb Total Space | 92.52 Mb Free Space | 93.28% Space Free | Partition Type: FAT32
Drive F: | 2.75 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: CHELSIE-PC | User Name: Chelsie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/05 15:54:51 | 000,188,928 | ---- | M] () -- C:\Users\Chelsie\AppData\Local\Temp\csrss.exe
PRC - [2011/02/05 15:52:28 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Chelsie\Downloads\OTL.com
PRC - [2011/02/05 15:29:15 | 000,184,320 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\Microsoft\conhost.exe
PRC - [2011/01/29 02:50:08 | 000,181,248 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\dwm.exe
PRC - [2011/01/20 11:10:52 | 000,211,456 | ---- | M] (IO) -- C:\Users\Chelsie\AppData\Roaming\FILE_54330.exe
PRC - [2011/01/19 18:41:28 | 000,491,739 | ---- | M] (IO) -- C:\Users\Chelsie\AppData\Roaming\Sys32Disp.exe.exe
PRC - [2011/01/14 08:25:51 | 000,072,704 | ---- | M] (win32) -- C:\Users\Chelsie\AppData\Local\Temp\mepxuax.exe
PRC - [2010/10/17 02:58:02 | 000,546,192 | ---- | M] (Oberon Media ) -- C:\Program Files (x86)\GamesBar\SearchEngineProtection.exe
PRC - [2010/09/15 12:18:42 | 000,025,976 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files (x86)\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2010/08/13 11:58:56 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/02/25 17:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\ccsvchst.exe


========== Modules (SafeList) ==========

MOD - [2011/02/05 15:52:28 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Chelsie\Downloads\OTL.com
MOD - [2010/08/20 22:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/01/18 15:04:08 | 000,020,480 | ---- | M] () [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe -- (HPWMISVC)
SRV:64bit: - [2009/11/17 19:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2010/08/13 11:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/07/28 14:36:52 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010/06/08 10:24:22 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/25 17:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe -- (NIS)
SRV - [2009/06/10 14:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/08/09 19:19:07 | 000,173,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2010/07/07 18:18:58 | 000,051,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB)
DRV:64bit: - [2010/05/05 21:01:59 | 000,451,120 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1108000.005\symtdiv.sys -- (SYMTDIv)
DRV:64bit: - [2010/04/28 22:03:51 | 000,150,064 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1108000.005\ironx64.sys -- (SymIRON)
DRV:64bit: - [2010/04/21 20:02:20 | 000,221,232 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1108000.005\symefa64.sys -- (SymEFA)
DRV:64bit: - [2010/04/21 19:29:51 | 000,505,392 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NISx64\1108000.005\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2010/04/21 19:29:51 | 000,032,304 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1108000.005\srtspx64.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2010/04/19 19:47:42 | 000,050,688 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010/03/05 12:57:00 | 010,300,800 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010/02/25 17:22:52 | 000,615,040 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1108000.005\cchpx64.sys -- (ccHP)
DRV:64bit: - [2010/02/05 17:49:04 | 000,316,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/01/19 18:55:34 | 001,088,544 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192se.sys -- (rtl8192se)
DRV:64bit: - [2009/11/27 18:45:00 | 000,295,424 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/10/13 11:16:40 | 000,409,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/08/29 17:17:18 | 000,433,200 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1108000.005\symds64.sys -- (SymDS)
DRV:64bit: - [2009/07/13 18:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/13 18:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 16:31:10 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009/06/10 14:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009/06/10 14:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009/06/10 14:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009/06/10 13:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 13:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009/06/10 13:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel(R)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/05/09 01:14:20 | 000,015,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nuidfltr.sys -- (NuidFltr)
DRV - [2010/10/06 14:04:27 | 001,804,336 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20101007.002\EX64.SYS -- (NAVEX15)
DRV - [2010/10/06 14:04:27 | 000,117,808 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20101007.002\ENG64.SYS -- (NAVENG)
DRV - [2010/09/15 11:02:19 | 000,476,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20101005.005\IDSviA64.sys -- (IDSVia64)
DRV - [2010/08/31 15:57:03 | 000,954,928 | ---- | M] (Symantec Corporation) [Kernel | System | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100901.003\BHDrvx64.sys -- (BHDrvx64)
DRV - [2010/08/12 16:04:54 | 000,475,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2010/08/12 16:04:54 | 000,132,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2009/09/22 18:39:00 | 000,225,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\RtsUStor.sys -- (RSUSBSTOR)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQNOT/1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.pogo.iplay.com/?o=shp
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:62808

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.51
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: {CB281163-0353-4C28-8D63-2FD9E55FF913}:1.9.1
FF - prefs.js..extensions.enabledItems: gamesbar@oberon-media.com:1.1.0.66
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 62808
FF - prefs.js..network.proxy.type: 1

FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/24 12:41:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\ [2010/08/23 10:37:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\ [2010/08/23 09:00:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/10/11 20:06:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/12/15 19:09:56 | 000,000,000 | ---D | M]

[2010/10/11 20:07:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chelsie\AppData\Roaming\Mozilla\Extensions
[2011/02/05 15:23:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chelsie\AppData\Roaming\Mozilla\Firefox\Profiles\p88tblqf.default\extensions
[2011/01/27 21:13:46 | 000,000,000 | ---D | M] (Oberon GamesBar) -- C:\Users\Chelsie\AppData\Roaming\Mozilla\Firefox\Profiles\p88tblqf.default\extensions\gamesbar@oberon-media.com
[2010/10/11 20:06:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/03/24 12:41:23 | 000,000,000 | ---D | M] (HP Smart Web Printing) -- C:\PROGRAM FILES (X86)\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON3
[2010/08/23 09:00:45 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\COFFPLGN
[2010/08/23 10:37:58 | 000,000,000 | ---D | M] (Norton IPS) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPLGN
[2011/01/14 08:27:32 | 000,000,000 | ---D | M] (XULRunner) -- C:\USERS\CHELSIE\APPDATA\LOCAL\{CB281163-0353-4C28-8D63-2FD9E55FF913}
[2011/01/27 21:13:46 | 000,001,600 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\WebSearchober5902656.xml

O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll (Google Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (GamesBarBHO Class) - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files (x86)\GamesBar\2.0.1.73\oberontb.dll (Oberon Media Ltd.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (GamesBar) - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files (x86)\GamesBar\2.0.1.73\oberontb.dll (Oberon Media Ltd.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\coieplg.dll (Symantec Corporation)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtkOSD] C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [] File not found
O4 - HKCU..\Run: [506E7F4D_ 0] C:\Users\Chelsie\AppData\Roaming\FILE_54330.exe (IO)
O4 - HKCU..\Run: [506E7F4D_0] C:\Users\Chelsie\AppData\Local\Temp\mepxuax.exe (win32)
O4 - HKCU..\Run: [aqycfnyf] C:\Users\Chelsie\AppData\Local\Temp\qaipckspl\kbobetkusbs.exe ()
O4 - HKCU..\Run: [AVG Antivirus 2011] C:\Program Files (x86)\AVG Antivirus 2011\avg.exe ()
O4 - HKCU..\Run: [conhost] C:\Users\Chelsie\AppData\Roaming\Microsoft\conhost.exe ()
O4 - HKCU..\Run: [Cyofugo] C:\Users\Chelsie\AppData\Local\ihiqitejigucin.dll (VoLT, 2010)
O4 - HKCU..\Run: [Ewijoziyi] C:\Users\Chelsie\AppData\Local\KBDURM.dll ()
O4 - HKCU..\Run: [Exent_SDM] C:\Users\Chelsie\AppData\Local\Temp\SDM143\Free Ride Games.exe (Exent Technologies Ltd.)
O4 - HKCU..\Run: [RegistryBooster] C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O4 - HKCU..\Run: [SearchEngineProtection] C:\Program Files (x86)\GamesBar\SearchEngineProtection.exe (Oberon Media )
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [swoncearxm.exe] C:\Users\Chelsie\AppData\Local\Temp\swoncearxm.exe (It Systems)
O4 - HKCU..\Run: [System Display] C:\Users\Chelsie\AppData\Roaming\Sys32Disp.exe.exe (IO)
F3:64bit: - HKCU WinNT: Load - (C:\Users\Chelsie\AppData\Local\Temp\csrss.exe) - C:\Users\Chelsie\AppData\Local\Temp\csrss.exe ()
F3 - HKCU WinNT: Load - (C:\Users\Chelsie\AppData\Local\Temp\csrss.exe) - C:\Users\Chelsie\AppData\Local\Temp\csrss.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - Reg Error: Value error. File not found
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.109.67.166 213.109.73.41
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Users\Chelsie\AppData\Roaming\dwm.exe) - C:\Users\Chelsie\AppData\Roaming\dwm.exe ()
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O27:64bit: - HKLM IFEO\chrome.exe: Debugger - File not found
O27:64bit: - HKLM IFEO\opera.exe: Debugger - File not found
O27:64bit: - HKLM IFEO\safari.exe: Debugger - File not found
O27 - HKLM IFEO\chrome.exe: Debugger - iesafemode.exe -sb ()
O27 - HKLM IFEO\opera.exe: Debugger - iesafemode.exe -sb ()
O27 - HKLM IFEO\safari.exe: Debugger - iesafemode.exe -sb ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/07/27 17:29:03 | 000,000,000 | R--D | M] - F:\AutoRun -- [ UDF ]
O32 - AutoRun File - [2009/07/27 17:34:55 | 000,703,552 | R--- | M] (Electronic Arts Inc.) - F:\AutoRun.exe -- [ UDF ]
O32 - AutoRun File - [2009/07/27 17:34:55 | 000,715,840 | R--- | M] (Electronic Arts Inc.) - F:\AutoRunGUI.dll -- [ UDF ]
O32 - AutoRun File - [2009/07/27 17:34:49 | 000,000,179 | R--- | M] () - F:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{ba849ded-a45c-11df-bda0-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{ba849ded-a45c-11df-bda0-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2009/07/27 17:34:55 | 000,703,552 | R--- | M] (Electronic Arts Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*


MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: HP Quick Launch - hkey= - key= - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Company)
MsConfig:64bit - StartUpReg: HP Software Update - hkey= - key= - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard)
MsConfig:64bit - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: Norton Online Backup - hkey= - key= - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
MsConfig:64bit - StartUpReg: NortonOnlineBackupReminder - hkey= - key= - C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)

SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/01/29 02:38:14 | 000,262,656 | ---- | C] (Microsoft Corporation) -- C:\Users\Chelsie\AppData\Local\aaldq.exe
[2011/01/28 01:50:07 | 000,264,192 | ---- | C] (Microsoft Corporation) -- C:\Users\Chelsie\AppData\Local\wmxuin.exe
[2011/01/27 21:55:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Antivirus 2011
[2011/01/27 21:14:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Arcade Lab
[2011/01/27 21:13:57 | 000,000,000 | ---D | C] -- C:\Users\Chelsie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pogo Games
[2011/01/27 21:13:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pogo Games
[2011/01/27 21:13:50 | 000,000,000 | ---D | C] -- C:\Users\Chelsie\AppData\Roaming\Oberon Media
[2011/01/27 21:13:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GamesBar
[2011/01/27 21:13:50 | 000,000,000 | ---D | C] -- C:\ProgramData\GamesBar
[2011/01/27 21:13:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GamesBar
[2011/01/27 21:13:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Oberon Media
[2011/01/27 21:13:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Oberon Media
[2011/01/27 21:13:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Oberon Media
[2011/01/27 21:13:18 | 000,000,000 | ---D | C] -- C:\Users\Chelsie\AppData\Local\Oberon Media
[2011/01/26 11:48:13 | 000,241,664 | ---- | C] (Microsoft Corporation) -- C:\Users\Chelsie\AppData\Local\xsppaex.exe
[2011/01/23 13:21:31 | 000,000,000 | ---D | C] -- C:\Users\Chelsie\AppData\Roaming\LolClient
[2011/01/22 14:08:41 | 000,332,800 | ---- | C] (Microsoft Corporation) -- C:\Users\Chelsie\AppData\Local\mmsxerflmu.exe
[2011/01/22 13:34:31 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_39.dll
[2011/01/22 13:34:31 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_39.dll
[2011/01/22 13:34:31 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_2.dll
[2011/01/22 13:34:31 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_39.dll
[2011/01/22 13:34:31 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_1.dll
[2011/01/22 13:30:25 | 000,000,000 | ---D | C] -- C:\Riot Games
[2011/01/22 13:30:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2011/01/22 13:16:16 | 000,000,000 | ---D | C] -- C:\Users\Chelsie\Desktop\NA.01_10_2011
[2011/01/22 13:15:48 | 000,000,000 | ---D | C] -- C:\Users\Chelsie\AppData\Local\PMB Files
[2011/01/22 13:15:47 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2011/01/22 13:15:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
[2011/01/22 13:06:42 | 000,268,800 | ---- | C] (T7sOiZ) -- C:\Users\Chelsie\AppData\Roaming\FILE_91852.exe
[2011/01/20 17:51:22 | 000,211,456 | ---- | C] (IO) -- C:\Users\Chelsie\AppData\Roaming\FILE_83028.exe
[2011/01/20 13:04:16 | 000,211,456 | ---- | C] (IO) -- C:\Users\Chelsie\AppData\Roaming\FILE_24601.exe
[2011/01/20 11:10:52 | 000,211,456 | ---- | C] (IO) -- C:\Users\Chelsie\AppData\Roaming\FILE_54330.exe
[2011/01/19 20:56:55 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2011/01/19 18:40:38 | 000,491,739 | ---- | C] (IO) -- C:\Users\Chelsie\AppData\Roaming\Sys32Disp.exe.exe
[2011/01/14 08:27:32 | 000,000,000 | ---D | C] -- C:\Users\Chelsie\AppData\Local\{CB281163-0353-4C28-8D63-2FD9E55FF913}
[2011/01/14 08:25:32 | 000,000,000 | ---D | C] -- C:\Users\Chelsie\AppData\Roaming\0EF438B8294817A96A3526A2A045FB13
[2011/01/13 21:18:40 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2011/01/13 21:18:40 | 001,837,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2011/01/13 21:18:40 | 001,540,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2011/01/13 21:18:40 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10warp.dll
[2011/01/13 21:18:40 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2011/01/13 21:18:40 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d2d1.dll
[2011/01/13 21:18:39 | 004,068,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2011/01/13 21:18:39 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2011/01/13 21:18:39 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DWrite.dll
[2011/01/13 21:18:39 | 000,662,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2011/01/13 21:18:38 | 001,863,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2011/01/13 21:18:38 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2011/01/13 21:18:38 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2011/01/13 21:18:38 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2011/01/13 21:18:38 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2011/01/13 21:18:38 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll
[2011/01/13 21:18:38 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/01/13 21:18:38 | 000,258,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/01/13 21:18:38 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll
[2011/01/13 21:18:38 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll
[2011/01/13 21:18:38 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1core.dll
[2011/01/13 21:18:38 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2011/01/13 21:18:38 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll
[2011/01/13 21:18:38 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll
[2011/01/13 21:18:37 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll
[2011/01/13 21:18:37 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1.dll
[2011/01/13 21:18:37 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2011/01/13 21:18:33 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbc32.dll
[2011/01/13 21:18:33 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbc32.dll
[2011/01/12 18:09:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Sandlot Games
[2011/01/11 22:30:26 | 000,000,000 | ---D | C] -- C:\ProgramData\HipSoft
[2009/07/13 16:24:58 | 000,221,184 | ---- | C] (VoLT, 2010) -- C:\Users\Chelsie\AppData\Local\ihiqitejigucin.dll

descriptionCertain programs won't open.. help EmptyRe: Certain programs won't open.. help

more_horiz
========== Files - Modified Within 30 Days ==========

[2011/02/05 15:54:32 | 000,017,740 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\45DA.FF8
[2011/02/05 15:52:49 | 000,000,120 | ---- | M] () -- C:\Users\Chelsie\AppData\Local\Clezoqo.dat
[2011/02/05 15:52:49 | 000,000,000 | ---- | M] () -- C:\Users\Chelsie\AppData\Local\Ogoboyobubobo.bin
[2011/02/05 15:07:56 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/05 15:07:56 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/05 15:01:00 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/05 15:00:20 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/05 14:52:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/02/02 17:23:33 | 000,000,605 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\FILE_10965.exe
[2011/02/02 17:23:13 | 000,000,858 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\net.bat
[2011/02/02 17:23:13 | 000,000,515 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\net.vbs
[2011/02/02 17:22:57 | 000,000,348 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2011/02/02 17:22:48 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForChelsie.job
[2011/02/02 17:22:36 | 1556,291,584 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/29 02:50:08 | 000,181,248 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\dwm.exe
[2011/01/29 02:38:14 | 000,262,656 | ---- | M] (Microsoft Corporation) -- C:\Users\Chelsie\AppData\Local\aaldq.exe
[2011/01/28 01:50:07 | 000,264,192 | ---- | M] (Microsoft Corporation) -- C:\Users\Chelsie\AppData\Local\wmxuin.exe
[2011/01/27 21:56:11 | 001,313,280 | ---- | M] () -- C:\Windows\SysWow64\iesafemode.exe
[2011/01/27 21:56:11 | 000,001,052 | ---- | M] () -- C:\Users\Chelsie\Desktop\AVG Antivirus 2011.lnk
[2011/01/27 21:13:57 | 000,002,078 | ---- | M] () -- C:\Users\Chelsie\Desktop\Spin & Win.lnk
[2011/01/27 21:13:57 | 000,001,160 | ---- | M] () -- C:\Users\Chelsie\Desktop\Pogo Games.lnk
[2011/01/26 11:48:13 | 000,241,664 | ---- | M] (Microsoft Corporation) -- C:\Users\Chelsie\AppData\Local\xsppaex.exe
[2011/01/25 09:24:50 | 000,726,316 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/01/25 09:24:50 | 000,624,178 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/01/25 09:24:50 | 000,106,522 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/01/22 14:08:41 | 000,332,800 | ---- | M] (Microsoft Corporation) -- C:\Users\Chelsie\AppData\Local\mmsxerflmu.exe
[2011/01/22 13:06:44 | 000,268,800 | ---- | M] (T7sOiZ) -- C:\Users\Chelsie\AppData\Roaming\FILE_91852.exe
[2011/01/22 11:07:48 | 000,293,376 | ---- | M] () -- C:\Users\Chelsie\AppData\Local\dwrjmqfe.exe
[2011/01/20 17:51:22 | 000,211,456 | ---- | M] (IO) -- C:\Users\Chelsie\AppData\Roaming\FILE_83028.exe
[2011/01/20 13:04:17 | 000,211,456 | ---- | M] (IO) -- C:\Users\Chelsie\AppData\Roaming\FILE_24601.exe
[2011/01/20 11:10:52 | 000,211,456 | ---- | M] (IO) -- C:\Users\Chelsie\AppData\Roaming\FILE_54330.exe
[2011/01/19 20:56:54 | 000,337,920 | ---- | M] () -- C:\Users\Chelsie\AppData\Local\qufgjafiy.exe
[2011/01/19 18:41:46 | 000,000,019 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\lovely.ini
[2011/01/19 18:41:28 | 000,491,739 | ---- | M] (IO) -- C:\Users\Chelsie\AppData\Roaming\Sys32Disp.exe.exe
[2011/01/14 08:27:09 | 000,000,000 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\chrtmp

========== Files Created - No Company Name ==========

[2011/02/02 17:23:33 | 000,000,605 | ---- | C] () -- C:\Users\Chelsie\AppData\Roaming\FILE_10965.exe
[2011/01/27 21:56:11 | 001,313,280 | ---- | C] () -- C:\Windows\SysWow64\iesafemode.exe
[2011/01/27 21:56:11 | 000,001,052 | ---- | C] () -- C:\Users\Chelsie\Desktop\AVG Antivirus 2011.lnk
[2011/01/27 21:13:57 | 000,002,078 | ---- | C] () -- C:\Users\Chelsie\Desktop\Spin & Win.lnk
[2011/01/27 21:13:57 | 000,001,160 | ---- | C] () -- C:\Users\Chelsie\Desktop\Pogo Games.lnk
[2011/01/23 13:18:27 | 000,181,248 | ---- | C] () -- C:\Users\Chelsie\AppData\Roaming\dwm.exe
[2011/01/22 11:07:48 | 000,293,376 | ---- | C] () -- C:\Users\Chelsie\AppData\Local\dwrjmqfe.exe
[2011/01/20 00:13:26 | 000,000,860 | ---- | C] () -- C:\Users\Chelsie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Shield.lnk
[2011/01/19 20:56:54 | 000,337,920 | ---- | C] () -- C:\Users\Chelsie\AppData\Local\qufgjafiy.exe
[2011/01/19 18:41:46 | 000,000,858 | ---- | C] () -- C:\Users\Chelsie\AppData\Roaming\net.bat
[2011/01/19 18:41:46 | 000,000,515 | ---- | C] () -- C:\Users\Chelsie\AppData\Roaming\net.vbs
[2011/01/19 18:41:46 | 000,000,019 | ---- | C] () -- C:\Users\Chelsie\AppData\Roaming\lovely.ini
[2011/01/19 17:02:24 | 000,017,740 | ---- | C] () -- C:\Users\Chelsie\AppData\Roaming\45DA.FF8
[2011/01/14 08:27:33 | 000,000,120 | ---- | C] () -- C:\Users\Chelsie\AppData\Local\Clezoqo.dat
[2011/01/14 08:27:33 | 000,000,000 | ---- | C] () -- C:\Users\Chelsie\AppData\Local\Ogoboyobubobo.bin
[2011/01/14 08:27:09 | 000,000,000 | ---- | C] () -- C:\Users\Chelsie\AppData\Roaming\chrtmp
[2010/09/23 08:14:54 | 000,000,094 | ---- | C] () -- C:\Users\Chelsie\AppData\Roaming\wklnhst.dat
[2010/08/09 19:17:51 | 000,000,560 | ---- | C] () -- C:\ProgramData\HPWALog.txt
[2010/04/27 01:35:33 | 000,000,105 | ---- | C] () -- C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2010/04/27 01:35:29 | 000,000,032 | ---- | C] () -- C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2010/04/27 01:35:19 | 000,000,032 | ---- | C] () -- C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2010/04/27 01:35:03 | 000,000,032 | ---- | C] () -- C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2010/04/27 01:34:29 | 000,000,032 | ---- | C] () -- C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2010/04/27 01:19:14 | 000,000,282 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog2.ini
[2010/04/27 01:19:14 | 000,000,223 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog.ini
[2010/03/24 12:30:15 | 000,000,109 | ---- | C] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2010/03/24 12:25:41 | 000,000,110 | ---- | C] () -- C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2010/03/24 12:24:33 | 000,000,105 | ---- | C] () -- C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2010/03/24 12:24:01 | 000,000,107 | ---- | C] () -- C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2010/03/05 12:57:10 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010/03/05 12:57:08 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2009/09/29 15:25:16 | 000,013,312 | ---- | C] () -- C:\Windows\LPRES.DLL
[2009/07/13 16:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:24:58 | 000,094,208 | ---- | C] () -- C:\Users\Chelsie\AppData\Local\KBDURM.dll
[2009/07/13 14:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

========== Custom Scans ==========


< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | -H-- | M] () -- C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 12:15:46 | 000,306,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2011/02/05 15:57:53 | 000,183,808 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\Microsoft\conhost.exe
[2011/01/20 17:50:34 | 000,000,159 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\Microsoft\gb_52884.bat

< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/09 21:28:40 | 000,000,221 | -HS- | M] () -- C:\Users\Chelsie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2009/06/10 14:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\addins\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2010/09/14 15:59:43 | 000,105,432 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe
[2010/09/14 15:59:44 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
[2010/09/14 15:59:52 | 000,014,808 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
[2010/09/14 15:59:56 | 000,243,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\updater.exe

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/08/12 21:44:51 | 000,000,402 | -HS- | M] () -- C:\Users\Chelsie\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2011/02/02 18:26:05 | 000,000,560 | ---- | M] () -- C:\ProgramData\HPWALog.txt
[2010/04/27 01:35:29 | 000,000,032 | ---- | M] () -- C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2010/03/24 12:30:54 | 000,000,109 | ---- | M] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2010/04/27 01:35:03 | 000,000,032 | ---- | M] () -- C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2010/03/24 12:25:35 | 000,000,105 | ---- | M] () -- C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2010/04/27 01:34:29 | 000,000,032 | ---- | M] () -- C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2010/04/27 01:35:19 | 000,000,032 | ---- | M] () -- C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2010/03/24 12:24:28 | 000,000,107 | ---- | M] () -- C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2010/03/24 12:30:10 | 000,000,110 | ---- | M] () -- C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2010/04/27 01:35:35 | 000,000,105 | ---- | M] () -- C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\*.exe /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.sys >

< %systemroot%\system32\drivers\*.dll >

< %systemroot%\system32\drivers\*.ini >

< %systemroot%\system32\drivers\*.exe >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

< %SYSTEMDRIVE%\*.* >
[2009/07/13 18:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2011/02/02 17:22:36 | 1556,291,584 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/02 17:22:41 | 2075,058,176 | -HS- | M] () -- C:\pagefile.sys

< %PROGRAMFILES%\*. >
[2010/11/23 14:55:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
[2010/10/06 13:48:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
[2011/01/27 21:55:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AVG Antivirus 2011
[2010/10/06 13:48:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\bfgclient
[2010/10/06 13:48:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour
[2010/04/27 01:23:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Cisco
[2011/01/27 21:13:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
[2010/04/27 01:37:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CyberLink
[2010/10/13 09:55:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\EA GAMES
[2010/10/13 10:25:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Electronic Arts
[2011/01/27 21:13:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\GamesBar
[2010/11/23 14:53:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google
[2010/12/20 07:47:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Gravity
[2010/04/27 01:27:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hewlett-Packard
[2010/03/24 13:38:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HP
[2010/04/27 01:47:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HP Games
[2011/01/22 13:30:24 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2010/04/27 01:21:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Intel
[2010/12/16 11:06:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
[2010/10/06 13:48:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes
[2010/03/24 13:12:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java
[2010/03/24 10:53:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft
[2010/03/24 11:30:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
[2010/03/24 11:31:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office Suite Activation Assistant
[2010/12/25 00:44:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
[2010/03/24 10:54:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2010/12/16 11:04:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Works
[2010/09/28 09:59:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
[2010/10/11 20:06:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
[2009/07/13 22:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
[2010/04/27 01:29:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSN
[2010/04/27 01:39:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\muvee Technologies
[2010/04/27 01:41:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Norton Internet Security
[2010/04/27 01:41:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NortonInstaller
[2011/01/27 21:13:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Oberon Media
[2010/09/27 14:59:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OGPlanet
[2010/08/09 19:08:51 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Online Services
[2011/01/22 13:15:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Pando Networks
[2010/08/12 21:59:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PopCap Games
[2010/09/23 10:11:42 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime
[2010/04/27 01:23:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
[2009/07/13 22:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
[2010/09/27 20:07:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reincarnations - Uncover the Past Collector's Edition
[2010/04/27 01:38:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Symantec
[2010/04/27 01:21:56 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
[2010/09/27 19:22:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Uniblue
[2009/07/13 21:57:06 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Uninstall Information
[2009/07/13 22:37:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
[2010/03/24 10:54:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live
[2010/03/24 10:53:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live SkyDrive
[2010/12/16 11:06:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
[2010/10/20 09:34:01 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
[2009/07/13 22:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
[2009/07/13 22:37:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
[2009/07/13 22:32:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
[2010/08/09 19:08:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar

< %appdata%\*.* >
[2011/02/05 15:54:32 | 000,017,740 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\45DA.FF8
[2011/01/14 08:27:09 | 000,000,000 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\chrtmp
[2011/01/29 02:50:08 | 000,181,248 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\dwm.exe
[2011/02/02 17:23:33 | 000,000,605 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\FILE_10965.exe
[2011/01/20 13:04:17 | 000,211,456 | ---- | M] (IO) -- C:\Users\Chelsie\AppData\Roaming\FILE_24601.exe
[2011/01/20 11:10:52 | 000,211,456 | ---- | M] (IO) -- C:\Users\Chelsie\AppData\Roaming\FILE_54330.exe
[2011/01/20 17:51:22 | 000,211,456 | ---- | M] (IO) -- C:\Users\Chelsie\AppData\Roaming\FILE_83028.exe
[2011/01/22 13:06:44 | 000,268,800 | ---- | M] (T7sOiZ) -- C:\Users\Chelsie\AppData\Roaming\FILE_91852.exe
[2011/01/19 18:41:46 | 000,000,019 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\lovely.ini
[2011/02/02 17:23:13 | 000,000,858 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\net.bat
[2011/02/02 17:23:13 | 000,000,515 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\net.vbs
[2011/01/19 18:41:28 | 000,491,739 | ---- | M] (IO) -- C:\Users\Chelsie\AppData\Roaming\Sys32Disp.exe.exe
[2010/09/23 08:55:40 | 000,000,094 | ---- | M] () -- C:\Users\Chelsie\AppData\Roaming\wklnhst.dat


< MD5 for: AGP440.SYS >
[2009/07/13 18:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/13 18:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/13 18:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 18:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009/07/13 18:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/13 18:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 18:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 18:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 18:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009/07/13 18:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: DISK.SYS >
[2009/07/13 18:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\SysNative\drivers\disk.sys
[2009/07/13 18:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\SysNative\DriverStore\FileRepository\disk.inf_amd64_neutral_10ce25bbc5a9cc43\disk.sys
[2009/07/13 18:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) MD5=9819EEE8B5EA3784EC4AF3B137A5244C -- C:\Windows\winsxs\amd64_disk.inf_31bf3856ad364e35_6.1.7600.16385_none_55bb738b8ddd8a01\disk.sys

< MD5 for: EVENTLOG.DLL >
[2007/05/17 21:34:04 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll

< MD5 for: IASTOR.SYS >
[2009/10/13 11:09:36 | 000,331,288 | ---- | M] (Intel Corporation) MD5=0BAA4115DFFFD6A6D809A89D65E1281A -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2009/10/13 11:16:40 | 000,409,624 | ---- | M] (Intel Corporation) MD5=BE7D72FCF442C26975942007E0831241 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2009/10/13 11:16:40 | 000,409,624 | ---- | M] (Intel Corporation) MD5=BE7D72FCF442C26975942007E0831241 -- C:\Windows\SysNative\drivers\iaStor.sys
[2009/10/13 11:16:40 | 000,409,624 | ---- | M] (Intel Corporation) MD5=BE7D72FCF442C26975942007E0831241 -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_6fca727099cdabf1\iaStor.sys

< MD5 for: IASTORV.SYS >
[2009/07/13 18:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2009/07/13 18:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 18:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 18:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009/07/13 18:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/13 18:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 18:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 18:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\drivers\nvstor.sys
[2009/07/13 18:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 18:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 18:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009/07/13 18:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 18:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009/07/13 18:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< MD5 for: USBSTOR.SYS >
[2009/07/13 17:06:34 | 000,089,600 | ---- | M] (Microsoft Corporation) MD5=080D3820DA6C046BE82FC8B45A893E83 -- C:\Windows\SysNative\drivers\USBSTOR.SYS
[2009/07/13 17:06:34 | 000,089,600 | ---- | M] (Microsoft Corporation) MD5=080D3820DA6C046BE82FC8B45A893E83 -- C:\Windows\SysNative\DriverStore\FileRepository\usbstor.inf_amd64_neutral_c301b770e0bfb179\USBSTOR.SYS
[2009/07/13 17:06:34 | 000,089,600 | ---- | M] (Microsoft Corporation) MD5=080D3820DA6C046BE82FC8B45A893E83 -- C:\Windows\winsxs\amd64_usbstor.inf_31bf3856ad364e35_6.1.7600.16385_none_a47b405db18421ea\USBSTOR.SYS

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:93EB7685
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:6BFA43EB
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:DC0B1070
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:5C82AA2E

< End of report >

descriptionCertain programs won't open.. help EmptyRe: Certain programs won't open.. help

more_horiz
Hello.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Certain programs won't open.. help DXwU4
Certain programs won't open.. help VvYDg

descriptionCertain programs won't open.. help EmptyRe: Certain programs won't open.. help

more_horiz
Wouldnt dl from the Here button so had to get it by googling it and junk.. gonna post log soon

descriptionCertain programs won't open.. help EmptyRe: Certain programs won't open.. help

more_horiz
Okay, standing by.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Certain programs won't open.. help DXwU4
Certain programs won't open.. help VvYDg

descriptionCertain programs won't open.. help EmptyRe: Certain programs won't open.. help

more_horiz
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5824

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

2/20/2011 4:33:40 PM
mbam-log-2011-02-20 (16-33-40).txt

Scan type: Quick scan
Objects scanned: 161427
Time elapsed: 3 minute(s), 9 second(s)

Memory Processes Infected: 4
Memory Modules Infected: 2
Registry Keys Infected: 4
Registry Values Infected: 9
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 229

Memory Processes Infected:
c:\Users\Chelsie\AppData\Local\Temp\mepxuax.exe (Trojan.LVBP) -> 3256 -> Unloaded process successfully.
c:\Users\Chelsie\AppData\Roaming\sys32disp.exe.exe (Trojan.Agent) -> 3172 -> Unloaded process successfully.
c:\Users\Chelsie\AppData\Roaming\microsoft\conhost.exe (Trojan.Agent) -> 4924 -> Unloaded process successfully.
c:\Users\Chelsie\AppData\Local\Temp\csrss.exe (Trojan.Agent) -> 2956 -> Unloaded process successfully.

Memory Modules Infected:
c:\Users\Chelsie\AppData\Local\KBDURM.dll (Trojan.Hiloti) -> Delete on reboot.
c:\Users\Chelsie\AppData\Local\ihiqitejigucin.dll (Trojan.Agent.U) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe (Rogue.Antivirus8) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\yr87fk3d2dnszapq2 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\opera.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safari.exe (Security.Hijack) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\506E7F4D_0 (Trojan.LVBP) -> Value: 506E7F4D_0 -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Ewijoziyi (Trojan.Hiloti) -> Value: Ewijoziyi -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\swoncearxm.exe (Trojan.FakeAlert) -> Value: swoncearxm.exe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\aqycfnyf (Trojan.Downloader) -> Value: aqycfnyf -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\System Display (Trojan.Agent) -> Value: System Display -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\conhost (Trojan.Agent) -> Value: conhost -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Value: Load -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Cyofugo (Trojan.Agent.U) -> Value: Cyofugo -> Delete on reboot.
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Value: Shell -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Bad: (C:\Users\Chelsie\AppData\Local\Temp\csrss.exe) Good: () -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\Chelsie\AppData\Local\Temp\mepxuax.exe (Trojan.LVBP) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\KBDURM.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\swoncearxm.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\qaipckspl\kbobetkusbs.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Roaming\file_91852.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\0.04285226583969004.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\19792079 (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\1F43.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\247A.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\252C.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\29B4.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\2D00.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\2D84.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\3065.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\31BD.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\31C0.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\337B.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\34D7.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\3660.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\3775.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\3A62.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\3B0D.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\3BAD.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\3CCA.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\3EDB.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\3F3C.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\40DE.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\40EF.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\41FE.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\4A17.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\4AC0.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\4B8C.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\5A69.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\66A3.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\6990.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\6AFE.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\7023.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\71EB.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\72E6.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\7D96.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\8583.exe (Trojan.Kryptik) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\8AE5.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\910E.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\B8D8.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\BB54.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\D22D.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\D25D.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\D615.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dkikqtl.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne1087.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne145a.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne150d.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne1796.tmp.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne1cf7.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne2010.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne2363.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne27d2.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne2b84.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne2c93.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne2e89.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne3299.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne32ce.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne336b.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne3493.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne37cb.tmp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne3839.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne3c9.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne3ce3.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne3cee.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne3d2a.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne3eb2.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne40be.tmp.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne420c.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne425f.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne449a.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne45aa.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne470b.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne49ca.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne4a2.tmp.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne4b01.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne4cd4.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne4d05.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne51da.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne5205.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne5261.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne547.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne55ad.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne57e4.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne5dfd.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne6172.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne64ed.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne65c.tmp.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne6fd6.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne7187.tmp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne7704.tmp.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne7a0.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne7cde.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne7f8c.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne815b.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne8312.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne86ca.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne8ae9.tmp.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne8f0e.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne918b.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne93ab.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne94d2.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne95cb.tmp.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne987.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne98b7.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne9bb2.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dne9ceb.tmp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnea00b.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnea03a.tmp.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnea0db.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnea356.tmp.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnea604.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnea8ab.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnea8bf.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnea8fe.tmp.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnead31.tmp.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneaf4f.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneaffe.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneb0dc.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneb28c.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneb88f.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnebc44.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnebcaa.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnebd5f.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnebe78.tmp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnebeae.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnebf0b.tmp.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnec071.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnec125.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnec17b.tmp.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnec22c.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnec346.tmp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnec41.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnec4c9.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnec52.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnec5e9.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnec9a7.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnecaa.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnecc25.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dned21f.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dned224.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dned26e.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dned767.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneda95.tmp.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnedb44.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnede12.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnedf94.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnee1d1.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnee4b7.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnee6b3.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnee757.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnee8fb.tmp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneeab8.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneecc7.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneef.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneef65.tmp.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneefb0.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnef022.tmp.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnef0e8.tmp.exe (Trojan.Logger) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnef94.tmp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnef9ef.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnefaae.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dnefe09.tmp.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneff6d.tmp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneffc3.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\dneffe6.tmp.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\e.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\E96D.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\erscaxmwno.exe (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\F814.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\GTYN0M5J.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\lkwenoju.exe (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup1641124992.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup1644999544.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup194102672.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup20627620.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup220178676.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup2537032656.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup2712449752.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup2842997884.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup3093849072.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup3492994992.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup3708910728.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup4278776000.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup646809892.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\setup889617540.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\tvcastb.exe (Trojan.Dialer) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\yrusxbfc.exe (Adware.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\_ex-08.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Temp\_ex-68.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\aaldq.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\dwrjmqfe.exe (Rogue.SecurityShield) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\KBDURM.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\mmsxerflmu.exe (Rogue.SecurityShield) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\qufgjafiy.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\wmxuin.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\xsppaex.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\application data\aaldq.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\application data\dwrjmqfe.exe (Rogue.SecurityShield) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\application data\KBDURM.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\application data\mmsxerflmu.exe (Rogue.SecurityShield) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\application data\qufgjafiy.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\application data\wmxuin.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\application data\xsppaex.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\0XO71RHE\lpppatch70700reg[1].exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\0XO71RHE\sjnlgn[2].htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\C9VZJ202\hyfaitavt[1].htm (Trojan.LVBP) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\C9VZJ202\hyfaitavt[2].htm (Trojan.LVBP) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\C9VZJ202\mmaucwe[1].htm (Adware.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\C9VZJ202\qhlkrzhf[1].htm (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\K0KBCTNB\cptrlg[3].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\K0KBCTNB\iztbjhowu[1].htm (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\K0KBCTNB\qhlkrzhf[1].htm (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\K0KBCTNB\winnotepad[1].exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\PG1WM57C\cptrlg[2].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\PG1WM57C\kbwdyfeyta[1].htm (Trojan.Dialer) -> Quarantined and deleted successfully.
c:\Users\Chelsie\local settings\temporary internet files\Content.IE5\PG1WM57C\mmaucwe[1].htm (Adware.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Roaming\sys32disp.exe.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Roaming\microsoft\Windows\start menu\Programs\security shield.lnk (Rogue.SecurityShield) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Roaming\microsoft\conhost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\833219953.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\Temp\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\System32\iesafemode.exe (Rogue.Antivirus8) -> Quarantined and deleted successfully.
c:\Windows\SysWOW64\iesafemode.exe (Rogue.Antivirus8) -> Quarantined and deleted successfully.
c:\Users\Chelsie\AppData\Local\ihiqitejigucin.dll (Trojan.Agent.U) -> Quarantined and deleted successfully.

descriptionCertain programs won't open.. help EmptyRe: Certain programs won't open.. help

more_horiz
Your computer has multiple infections, including a backdoor. A backdoor gives intruders complete control of your computer, logs your keystrokes, steal personal information, etc.

You are strongly advised to do the following:

  • Disconnect the computer from the Internet and from any networked computers until it is cleaned.
  • Back up all your important data except programs. The programs can be reinstalled back from the original disc or from the Net.
  • Call all your banks, financial institutions, credit card companies and inform them that you may be a victim of identity theft and put a watch on your accounts. If you don't mind the hassle, change all your account numbers.
  • From a clean computer, change all your passwords (ISP login password, your email address(es) passwords, financial accounts, PayPal, eBay, Amazon, online groups and forums and any other online activities you carry out which require a username and password).
Do NOT change your passwords from this computer as the attacker will be able to get all the new passwords and transaction records.

Due to its backdoor functionality, your computer is very likely to have been compromised and there is no way that it can be trusted again. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be to do a reformat and reinstallation of the operating system (OS). However, if you do not have the resources to reinstall your OS and would like me to attempt to clean your machine, I will be happy to do so.

To help you understand more, please take some time to read the following articles:

What are Remote Access Trojans and why are they dangerous
How do I respond to a possible identity theft and how do I prevent it
When should I do a reformat and reinstallation of my OS
Where to backup your files
How to backup your files in Windows XP
Restoring your backups

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Certain programs won't open.. help DXwU4
Certain programs won't open.. help VvYDg

descriptionCertain programs won't open.. help EmptyRe: Certain programs won't open.. help

more_horiz
Ok so it didnt come with any os disc or anything so how could I check if there is a recovery partition on it?

descriptionCertain programs won't open.. help EmptyRe: Certain programs won't open.. help

more_horiz
Under My Computer, does it have another partition for recovery?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Certain programs won't open.. help DXwU4
Certain programs won't open.. help VvYDg

descriptionCertain programs won't open.. help EmptyRe: Certain programs won't open.. help

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum