phil.j
Topic Starter
Running winxp sp3 Home edition.
Running more than 1 application at a time pc comes to a halt. Here are my logs:
OLT:
OTL logfile created on: 11/14/2010 12:09:06 AM - Run 3
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\melissa\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
446.00 Mb Total Physical Memory | 49.00 Mb Available Physical Memory | 11.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 55.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 51.18 Gb Free Space | 68.70% Space Free | Partition Type: NTFS
Drive D: | 170.63 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: C521 | User Name: melissa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\melissa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
PRC - C:\Program Files\ATT-SST\McciTrayApp.exe (Alcatel-Lucent)
PRC - C:\Program Files\Common Files\Motive\McciServiceHost.exe (Alcatel-Lucent)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\melissa\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Motive\McciContextHook_DSR.dll (Alcatel-Lucent)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Trend Micro RUBotted Service) – C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe (Trend Micro Inc.)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (McciServiceHost) – C:\Program Files\Common Files\Motive\McciServiceHost.exe (Alcatel-Lucent)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (ATTRcAppSvc) – C:\Program Files\AT&T;\Communication Manager\RcAppSvc.exe (SmithMicro Inc.)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (ISPwdSvc) – C:\Program Files\Norton AntiVirus\isPwdSvc.exe (Symantec Corporation)
SRV - (LiveUpdate Notice Ex) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (pgsql-8.2) – C:\Nautilus\rdbms\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (SymAppCore) – C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (HP Port Resolver) – C:\WINDOWS\system32\hpbpro.exe (Hewlett-Packard Company)
SRV - (HP Status Server) – C:\WINDOWS\system32\hpboid.exe (Hewlett-Packard Company)
========== Driver Services (SafeList) ==========
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (sscemdm) – C:\WINDOWS\system32\drivers\sscemdm.sys (MCCI Corporation)
DRV - (sscebus) SAMSUNG USB Composite Device V2 driver (WDM) – C:\WINDOWS\system32\drivers\sscebus.sys (MCCI Corporation)
DRV - (sscemdfl) – C:\WINDOWS\system32\drivers\sscemdfl.sys (MCCI Corporation)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (usbsermpt) – C:\WINDOWS\system32\drivers\usbsermpt.sys (Microsoft Corporation)
DRV - (tcpipBM) – C:\WINDOWS\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (PCTINDIS5) – C:\WINDOWS\system32\PCTINDIS5.sys (Smith Micro Inc.)
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (swmsflt) – C:\WINDOWS\System32\drivers\swmsflt.sys ()
DRV - (SWUMX80) Sierra Wireless USB MUX Driver (UMTS80) – C:\WINDOWS\system32\drivers\swumx80.sys (Sierra Wireless Inc.)
DRV - (SWNC8U80) Sierra Wireless MUX NDIS Driver (UMTS80) – C:\WINDOWS\system32\drivers\swnc8u80.sys (Sierra Wireless Inc.)
DRV - (pavboot) – C:\WINDOWS\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080516.019\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080516.019\NAVENG.SYS (Symantec Corporation)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (SYMIDSCO) – C:\Program Files\Common Files\Symantec Shared\SymcData\ids-diskless\20080623.001\SymIDSCo.sys (Symantec Corporation)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (Winacusb) – C:\WINDOWS\system32\drivers\winacusb.sys (U.S. Robotics)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://news.yahoo.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 82 A0 3E A9 8E 5E CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/07 22:03:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/09 17:37:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/03/31 14:28:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2008/12/24 12:44:09 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Mozilla\Extensions
[2010/11/13 00:36:40 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Mozilla\Firefox\Profiles\uaetpfrv.default\extensions
[2010/05/08 06:47:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\melissa\Application Data\Mozilla\Firefox\Profiles\uaetpfrv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/13 00:36:40 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/27 15:32:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/23 13:33:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/09 22:26:28 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AT&T; Communication Manager] C:\Program Files\AT&T;\Communication Manager\ATTCM.exe (ATT)
O4 - HKLM..\Run: [ATT-SST_McciTrayApp] C:\Program Files\ATT-SST\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe (HP)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [Trend Micro RUBotted V2.0 Beta] C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [FreeRAM XP] C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (YourWare Solutions ™)
O4 - HKCU..\Run: [UpdateFlow.ATT-SST] C:\Program Files\ATT-SST\McciBrowser.exe (Alcatel-Lucent)
O4 - HKLM..\RunOnce: [TSC] C:\Documents and Settings\melissa\Local Settings\Temp\HouseCall\TSC.exe (Trend Micro Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O15 - HKCU\..Trusted Domains: //@signup.mar@/ ([]money in My Computer)
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: att.com ([ufix] https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab (Windows Live Safety Center Base Module)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} http://cid-c76209a9d8ecd425.spaces.live.co…ad/MsnPUpld.cab (Windows Live Photo Upload Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\melissa\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\melissa\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/05/01 09:05:33 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/08/24 11:52:37 | 000,000,026 | RH– | M] () - D:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{feed18c1-f7c9-11db-a3d6-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{feed18c1-f7c9-11db-a3d6-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{feed18c1-f7c9-11db-a3d6-806d6172696f}\Shell\AutoRun\command - "" = D:\tcauto.exe – [2009/11/04 18:59:01 | 007,636,800 | R— | M] (HR Block )
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: VIDC.NSVI - nsvideo.dll File not found
Drivers32: vidc.wmv3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/11/13 21:26:45 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\melissa\Desktop\OTL.exe
[2010/11/13 21:03:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Trend Micro
[2010/11/13 20:53:05 | 000,000,000 | —D | C] – C:\Program Files\WinPcap
[2010/11/13 20:52:39 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/11/13 20:46:44 | 000,000,000 | —D | C] – C:\Program Files\HijackThis
[2010/11/10 13:53:50 | 000,000,000 | —D | C] – C:\Documents and Settings\melissa\Application Data\Camfrog
[2010/11/10 13:52:30 | 000,000,000 | —D | C] – C:\Program Files\Camfrog
[2010/11/09 22:26:16 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/11/09 22:26:14 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/11/09 22:26:14 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/11/09 22:26:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2007/05/17 16:10:04 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/14 00:06:38 | 000,002,563 | —- | M] () – C:\Documents and Settings\melissa\Desktop\HiJackThis.lnk
[2010/11/13 23:19:06 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/13 21:28:00 | 000,359,929 | —- | M] () – C:\Documents and Settings\melissa\Desktop\dds.scr
[2010/11/13 21:27:58 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\melissa\Desktop\OTL.exe
[2010/11/13 20:57:32 | 000,000,036 | —- | M] () – C:\Documents and Settings\melissa\Local Settings\Application Data\housecall.guid.cache
[2010/11/13 20:53:09 | 000,000,073 | —- | M] () – C:\WINDOWS\System32\-1
[2010/11/13 20:28:12 | 000,000,426 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{78661A67-11FF-4A9B-86B9-1A61F1709684}.job
[2010/11/13 19:40:14 | 000,000,216 | —- | M] () – C:\WINDOWS\tasks\ms.job
[2010/11/13 17:19:11 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/13 16:56:01 | 000,000,562 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for melissa.job
[2010/11/13 01:51:30 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/12 17:30:22 | 000,001,836 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AT&T; Service & Support Tool.lnk
[2010/11/12 13:29:41 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/11/12 13:29:40 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/11/12 10:55:40 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/11/12 09:00:00 | 000,000,386 | —- | M] () – C:\WINDOWS\tasks\rpc.job
[2010/11/11 00:02:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/10 15:58:33 | 000,000,390 | —- | M] () – C:\WINDOWS\Trpmaker.INI
[2010/11/09 22:18:35 | 000,462,058 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/11/09 22:18:34 | 000,078,260 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/11/09 17:37:54 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2010/11/08 20:00:00 | 000,000,580 | —- | M] () – C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - SEI Aaron's Rents.job
[2010/11/07 07:19:58 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/10/19 10:41:44 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/10/15 02:34:59 | 000,157,952 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/15 02:16:58 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/13 21:27:15 | 000,359,929 | —- | C] () – C:\Documents and Settings\melissa\Desktop\dds.scr
[2010/11/13 20:57:32 | 000,000,036 | —- | C] () – C:\Documents and Settings\melissa\Local Settings\Application Data\housecall.guid.cache
[2010/11/13 20:53:08 | 000,000,073 | —- | C] () – C:\WINDOWS\System32\-1
[2010/11/13 20:46:45 | 000,002,563 | —- | C] () – C:\Documents and Settings\melissa\Desktop\HiJackThis.lnk
[2010/11/12 17:30:21 | 000,001,836 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AT&T; Service & Support Tool.lnk
[2010/11/12 13:29:41 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/11/12 13:29:40 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/08/01 15:55:34 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/08/01 15:55:34 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/08/01 15:53:59 | 000,002,528 | —- | C] () – C:\Documents and Settings\melissa\Application Data\$_hpcst$.hpc
[2010/04/06 14:06:07 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2010/02/15 17:35:26 | 000,000,253 | —- | C] () – C:\WINDOWS\fantasy2.ini
[2010/02/15 17:35:26 | 000,000,021 | —- | C] () – C:\WINDOWS\Pf_setup.ini
[2010/02/14 20:41:21 | 000,010,630 | —- | C] () – C:\WINDOWS\System32\WTCPAPI.DLL
[2010/02/14 20:41:20 | 000,496,336 | —- | C] () – C:\WINDOWS\System32\LEAD40.DLL
[2010/02/14 20:41:20 | 000,084,448 | —- | C] () – C:\WINDOWS\System32\PCDLIB.DLL
[2010/02/14 20:26:15 | 001,690,896 | —- | C] () – C:\WINDOWS\System32\Mso97v.dll
[2010/02/14 20:26:15 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\Docobj.dll
[2010/02/14 20:26:15 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\Hlinkprx.dll
[2009/10/20 13:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/10/09 18:03:28 | 000,000,440 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2009/10/09 17:58:20 | 000,000,415 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/07/29 17:12:51 | 000,026,760 | —- | C] () – C:\WINDOWS\System32\drivers\swmsflt.sys
[2009/01/06 22:57:54 | 000,223,232 | —- | C] () – C:\WINDOWS\System32\sqlite3.dll
[2008/12/15 18:44:35 | 000,000,130 | —- | C] () – C:\Documents and Settings\melissa\Local Settings\Application Data\fusioncache.dat
[2008/12/05 00:47:11 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2008/09/27 23:05:01 | 000,000,742 | —- | C] () – C:\WINDOWS\PODW.INI
[2008/09/27 23:05:00 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\SfwIFmt.dll
[2008/09/18 21:31:13 | 000,000,390 | —- | C] () – C:\WINDOWS\Trpmaker.INI
[2008/09/18 21:30:54 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\PlugFile.dll
[2008/09/18 21:30:53 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2008/09/18 21:30:51 | 000,038,688 | —- | C] () – C:\WINDOWS\System32\Leaddib.drv
[2008/09/18 21:30:51 | 000,011,136 | —- | C] () – C:\WINDOWS\System32\Fprun300.dll
[2008/07/08 16:45:53 | 000,012,288 | —- | C] () – C:\Documents and Settings\melissa\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/15 23:53:03 | 000,000,083 | —- | C] () – C:\WINDOWS\usrwiz.ini
[2008/04/14 13:58:40 | 002,854,912 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2008/04/07 00:36:24 | 000,000,142 | —- | C] () – C:\WINDOWS\wpd99.drv
[2008/04/07 00:35:58 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2008/03/18 18:30:11 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2008/03/18 18:28:54 | 000,001,020 | —- | C] () – C:\WINDOWS\disney.ini
[2008/02/04 17:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2008/01/12 16:01:37 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2007/11/29 20:18:08 | 000,000,283 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2007/11/29 20:18:07 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2007/11/29 20:17:01 | 000,013,646 | —- | C] () – C:\WINDOWS\hpdj6800.ini
[2007/11/29 20:16:54 | 000,002,742 | —- | C] () – C:\WINDOWS\hpf6800m.ini
[2007/11/26 20:04:18 | 000,000,033 | —- | C] () – C:\WINDOWS\wwwbatch.ini
[2007/11/12 15:18:10 | 000,000,047 | —- | C] () – C:\WINDOWS\promftax.ini
[2007/11/12 15:13:50 | 000,001,570 | —- | C] () – C:\WINDOWS\promilesxf.ini
[2007/10/25 16:26:10 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/06/20 16:11:21 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/05/12 15:12:44 | 000,000,143 | —- | C] () – C:\WINDOWS\VWORK32.INI
[2007/05/12 15:05:22 | 000,000,012 | —- | C] () – C:\WINDOWS\EZPhotoTools2.ini
[2007/05/12 15:04:42 | 000,000,012 | —- | C] () – C:\WINDOWS\EZPhotoBrowser2.ini
[2007/05/12 15:03:41 | 000,000,012 | —- | C] () – C:\WINDOWS\Showtime1.ini
[2007/05/01 09:56:53 | 000,000,331 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/05/01 09:43:17 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/05/01 09:43:17 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/05/01 09:43:17 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/05/01 09:43:16 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/05/01 09:43:15 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/05/01 09:43:15 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2007/05/01 09:43:13 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2007/05/01 04:55:57 | 000,004,346 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/06/22 13:37:46 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/01/08 09:30:22 | 000,011,170 | —- | C] () – C:\WINDOWS\System32\PA207USD.DLL
[2001/11/14 13:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
========== LOP Check ==========
[2007/06/26 14:58:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aliasworlds
[2009/01/06 23:03:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ascentive
[2009/07/29 19:29:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2008/12/15 13:33:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/02/04 08:21:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EA
[2008/12/05 00:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/02/02 16:18:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2007/05/13 07:21:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FloodLightGames
[2007/07/11 14:36:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Friends Games
[2008/01/12 13:58:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameBlend
[2007/06/10 09:23:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin
[2007/05/13 14:51:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2007/05/25 19:35:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/12/16 23:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/04/06 14:08:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2007/06/30 18:08:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2007/07/01 15:22:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Playtonium Games
[2010/08/01 15:56:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2007/07/15 10:10:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2007/05/29 15:40:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecretsOfOlympus
[2010/04/04 13:25:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2008/03/27 18:21:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/05 00:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2007/05/01 10:01:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/08/26 13:43:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2007/05/18 21:19:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Winferno
[2009/07/29 17:14:59 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\AT&T;
[2009/07/29 17:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Bytemobile
[2010/11/10 13:56:13 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Camfrog
[2009/07/29 17:15:15 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\DBUpdater
[2008/02/04 08:21:12 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\EA
[2008/02/02 16:18:31 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Flood Light Games
[2008/01/12 13:58:56 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\GameBlend
[2008/02/02 12:35:12 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\iWin
[2008/04/05 19:52:38 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\LargoSoftware
[2007/10/06 20:31:24 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Leadertech
[2009/03/28 16:36:40 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Nikon
[2008/12/09 10:43:56 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\OpenOffice.org
[2010/04/06 14:06:18 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\pdf995
[2008/02/02 08:17:34 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Pogo Games
[2009/11/29 08:38:41 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Qualcomm
[2010/08/01 15:52:06 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Samsung
[2008/05/14 14:55:17 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\SecondLife
[2009/07/29 17:00:55 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Sierra Wireless
[2010/04/06 14:08:54 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\TaxCut
[2009/11/29 12:45:18 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Thunderbird
[2008/12/15 18:40:39 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Windows Desktop Search
[2008/12/16 23:57:27 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Windows Search
[2010/11/13 01:51:30 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/11/13 19:40:14 | 000,000,216 | —- | M] () – C:\WINDOWS\Tasks\ms.job
[2010/11/12 09:00:00 | 000,000,386 | —- | M] () – C:\WINDOWS\Tasks\rpc.job
[2010/11/13 20:28:12 | 000,000,426 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{78661A67-11FF-4A9B-86B9-1A61F1709684}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2007/05/01 09:05:33 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/07/29 19:39:28 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2007/05/01 09:05:33 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/12/17 08:57:00 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2007/07/01 13:34:15 | 000,000,098 | —- | M] () – C:\DownloadLog.txt
[2003/12/08 12:15:56 | 000,028,672 | R— | M] ( ) – C:\hpqimgrc.resources.dll
[2007/07/10 10:42:12 | 000,000,438 | —- | M] () – C:\INSTALL.LOG
[2007/05/01 09:05:33 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2007/07/20 16:15:06 | 000,000,125 | —- | M] () – C:\ioSpecial.ini
[2007/05/18 21:18:05 | 000,000,243 | —- | M] () – C:\log.html
[2007/05/01 09:05:33 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/08/05 17:00:50 | 000,001,097 | —- | M] () – C:\net_save.dna
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/12/27 12:09:28 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/11/13 20:37:53 | 1017,118,720 | -HS- | M] () – C:\pagefile.sys
[2007/08/18 09:25:09 | 000,043,665 | —- | M] () – C:\playground.log
[2009/11/12 10:37:42 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/11/13 00:32:43 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/11/15 17:10:03 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/11/23 12:21:44 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/11/26 01:35:27 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009/11/26 20:08:58 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/11/27 14:51:33 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009/11/28 06:26:03 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2009/11/28 20:24:23 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/11/29 07:40:01 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/11/30 06:01:54 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/11/30 09:05:07 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/11/30 09:34:37 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/11/03 15:18:49 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/11/03 16:33:05 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/11/05 16:15:04 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2009/11/06 18:34:04 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2009/11/07 05:45:15 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009/11/08 00:27:43 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009/11/08 23:19:46 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/11/12 10:37:42 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/11/13 00:32:42 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/11/15 17:10:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/11/23 12:21:44 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/11/26 01:35:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/11/26 20:08:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/11/27 14:51:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/11/28 06:26:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/11/28 20:24:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/11/29 07:40:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/11/30 06:01:54 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/11/30 09:05:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/11/30 09:34:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/11/03 15:18:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/11/03 16:33:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/11/05 16:15:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/11/06 18:34:04 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/11/07 05:45:15 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/11/08 00:27:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/11/08 23:19:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2007/07/16 17:10:17 | 000,230,454 | —- | M] () – C:\StiImg.dat
[2007/06/01 09:32:59 | 000,064,188 | —- | M] () – C:\VETlog.dmp
[2007/06/01 09:32:59 | 000,020,259 | —- | M] () – C:\VETlog.txt
[2007/10/15 22:08:15 | 000,000,146 | —- | M] () – C:\YServer.txt
< %systemroot%\Fonts\*.com >
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2007/05/01 09:05:08 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/08/14 20:49:20 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/08/14 17:02:46 | 000,594,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2008/12/01 17:00:31 | 000,489,628 | —- | M] (MacSourcery) – C:\WINDOWS\Install.scr
[2009/07/10 12:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/02/14 16:19:21 | 000,001,666 | -H– | M] () – C:\Documents and Settings\melissa\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2007/05/17 16:10:00 | 000,774,144 | —- | M] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2007/05/01 04:54:10 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/05/01 04:54:10 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/05/01 04:54:10 | 000,892,928 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/27 12:17:20 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2009/07/30 07:53:42 | 000,006,656 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/07/10 10:27:08 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\melissa\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/07/10 10:27:07 | 000,000,079 | —- | M] () – C:\Documents and Settings\melissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2008/12/31 19:56:54 | 000,223,368 | —- | M] () – C:\Documents and Settings\melissa\Desktop\CrucialScan.exe
[2010/11/13 21:27:58 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\melissa\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-12 06:50:21
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DE73B0FE
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:20DB61D6
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DB365884
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CF5C4195
@Alternate Data Stream - 173 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D8A7F3FF
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:17639624
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1A5D64BE
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F686C4A
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F65733F1
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4E903DEB
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8A44841A
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4D24FC46
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:43301D1D
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A73A758
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BDCD8531
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CE6885F1
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C1CCF2C1
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7C412B92
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:580E04D8
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2A208B5C
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CE0A077E
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BBE01348
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:426796C0
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9884A8C7
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:78E0DF72
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:51574724
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96CC3FEF
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8B90426A
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:260575F1
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:55F44B88
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54997B77
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:375A40C3
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F00E008B
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E36F5B57
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B7ADB4DA
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59D05D9A
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5759F6F0
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D6BDE53F
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC95B5ED
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0ED4AC2F
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:98DFF516
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8643C5BE
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:453190EC
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B623B5B8
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:949483BD
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:270A3983
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2B99FE60
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B745EBA5
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A98DA12
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:053BAE56
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E60C72DB
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3CD562B4
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63CFD724
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:618BF152
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D09AEE3D
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2ABEB9EB
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:88D615D5
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:70E897B5
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:507C73B7
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F7862839
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6BD304B9
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60C47453
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8AB6C1D7
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5BC73C48
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E55CE2D1
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FF8F1AE3
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E4AC8DCB
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90BA5E08
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B3A35EC
< End of report >
HiJackThis:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:07:05 AM, on 11/14/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\ATT-SST\McciTrayApp.exe
C:\Program Files\Common Files\Motive\McciServiceHost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [AT&T; Communication Manager] "C:\Program Files\AT&T;\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [ATT-SST_McciTrayApp] "C:\Program Files\ATT-SST\McciTrayApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Trend Micro RUBotted V2.0 Beta] C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
O4 - HKLM\..\RunOnce: [TSC] "C:\DOCUME~1\melissa\LOCALS~1\Temp\HouseCall\tsc.exe" /HD
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [UpdateFlow.ATT-SST] C:\Program Files\ATT-SST\McciBrowser.exe -AppKey=ATT-SST -URL=file://C:\Program Files\ATT-SST\OfflineUpdate\redirector.htm
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-c76209a9d8ecd425.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AT&T; RcAppSvc (ATTRcAppSvc) - SmithMicro Inc. - C:\Program Files\AT&T;\Communication Manager\RcAppSvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McciServiceHost - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciServiceHost.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server 8.2 (pgsql-8.2) - PostgreSQL Global Development Group - C:\Nautilus\rdbms\bin\pg_ctl.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Trend Micro RUBotted Service - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe
–
End of file - 11275 bytes
DDS:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 0:07:40.96 on Sun 11/14/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.33 [GMT -5:00]
AV: Norton AntiVirus *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\ATT-SST\McciTrayApp.exe
C:\Program Files\Common Files\Motive\McciServiceHost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\melissa\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn1\YTSingleInstance.dll
TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [FreeRAM XP] "c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe" -win
uRun: [UpdateFlow.ATT-SST] c:\program files\att-sst\mccibrowser.exe -appkey=att-sst -url=file://c:\program files\att-sst\offlineupdate\redirector.htm
uRun: [AutoStartNPSAgent] c:\program files\samsung\samsung new pc studio\NPSAgent.exe
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [AT&T; Communication Manager] "c:\program files\at&t;\communication manager\ATTCM.exe" -a
mRun: [ccApp] c:\program files\common files\symantec shared\ccApp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Software Update] "c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe
mRun: [ATT-SST_McciTrayApp] "c:\program files\att-sst\McciTrayApp.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [NPSStartup]
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Trend Micro RUBotted V2.0 Beta] c:\program files\trend micro\rubotted\RUBottedGUI.exe
mRunOnce: [TSC] "c:\docume~1\melissa\locals~1\temp\housecall\tsc.exe" /HD
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
LSP: bmnet.dll
Trusted Zone: att.com\ufix
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} - hxxp://cid-c76209a9d8ecd425.spaces.live.com/PhotoUpload/MsnPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - c:\program files\qualcomm\eudora\EuShlExt.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\melissa\applic~1\mozilla\firefox\profiles\uaetpfrv.default\
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - plugin: c:\program files\view22\version 3.10.50\NPView22.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-7-22 28544]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-7-28 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-7-28 67656]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2007-1-10 108648]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2007-1-10 108648]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-8-1 238952]
R2 McciServiceHost;McciServiceHost;c:\program files\common files\motive\McciServiceHost.exe [2009-11-29 315392]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
R2 Trend Micro RUBotted Service;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\RUBotSrv.exe [2010-11-13 431440]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-8-1 36608]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20080516.019\NAVENG.SYS [2008-5-17 82256]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20080516.019\NAVEX15.SYS [2008-5-17 895408]
R3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-6-20 1251720]
R3 Winacusb;Winacusb;c:\windows\system32\drivers\winacusb.sys [2008-11-23 902860]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-24 136176]
S2 pgsql-8.2;PostgreSQL Database Server 8.2;c:\nautilus\rdbms\bin\pg_ctl.exe runservice -n "pgsql-8.2" -d "c:\nautilus\rdbms\data\" –> c:\nautilus\rdbms\bin\pg_ctl.exe runservice -N pgsql-8.2 [?]
S3 ATTRcAppSvc;AT&T; RcAppSvc;c:\program files\at&t;\communication manager\RcAppSvc.exe [2008-11-20 113152]
S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-4 14336]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-7-28 12872]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\drivers\sscebus.sys [2010-8-1 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\drivers\sscemdfl.sys [2010-8-1 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\drivers\sscemdm.sys [2010-8-1 123648]
S3 SWNC8U80;Sierra Wireless MUX NDIS Driver (UMTS80);c:\windows\system32\drivers\swnc8u80.sys [2008-8-20 168192]
S3 SWUMX80;Sierra Wireless USB MUX Driver (UMTS80);c:\windows\system32\drivers\swumx80.sys [2008-8-20 142976]
=============== Created Last 30 ================
2010-11-13 21:03 –d—– c:\docume~1\alluse~1\applic~1\Trend Micro
2010-11-13 20:53 73 a——- c:\windows\system32\-1
2010-11-13 20:53 –d—– c:\program files\WinPcap
2010-11-13 20:52 –d—– c:\program files\Trend Micro
2010-11-12 13:29 1,409 a——- c:\windows\QTFont.for
2010-11-12 13:29 54,156 a—h— c:\windows\QTFont.qfn
2010-11-10 13:53 –d—– c:\docume~1\melissa\applic~1\Camfrog
2010-11-10 13:52 –d—– c:\program files\Camfrog
2010-11-09 22:26 73,728 a——- c:\windows\system32\javacpl.cpl
==================== Find3M ====================
2010-10-19 10:41 222,080 ——– c:\windows\system32\MpSigStub.exe
2010-09-18 11:23 974,848 a——- c:\windows\system32\mfc42u.dll
2010-09-18 01:53 974,848 a——- c:\windows\system32\mfc42.dll
2010-09-18 01:53 953,856 a——- c:\windows\system32\mfc40u.dll
2010-09-18 01:53 954,368 ——– c:\windows\system32\mfc40.dll
2010-09-15 04:50 472,808 a——- c:\windows\system32\deployJava1.dll
2010-09-10 00:58 916,480 a——- c:\windows\system32\wininet.dll
2010-09-10 00:58 43,520 a——- c:\windows\system32\licmgr10.dll
2010-09-01 06:51 285,824 a——- c:\windows\system32\atmfd.dll
2010-08-31 08:42 1,852,800 a——- c:\windows\system32\win32k.sys
2010-08-27 03:02 119,808 ——– c:\windows\system32\t2embed.dll
2010-08-27 00:57 99,840 a——- c:\windows\system32\srvsvc.dll
2010-08-26 07:52 5,120 a——- c:\windows\system32\xpsp4res.dll
2010-08-23 11:12 617,472 a——- c:\windows\system32\comctl32.dll
2010-08-17 08:17 58,880 a——- c:\windows\system32\spoolsv.exe
2010-08-16 03:45 590,848 a——- c:\windows\system32\rpcrt4.dll
2009-03-28 16:33 20 a—h— c:\docume~1\alluse~1\applic~1\PKP_DLec.DAT
2008-12-17 09:00 92,064 a——- c:\documents and settings\melissa\mqdmmdm.sys
2008-12-17 09:00 79,328 a——- c:\documents and settings\melissa\mqdmserd.sys
2008-12-17 09:00 9,232 a——- c:\documents and settings\melissa\mqdmmdfl.sys
2008-12-17 09:00 5,936 a——- c:\documents and settings\melissa\mqdmwhnt.sys
2008-12-17 09:00 4,048 a——- c:\documents and settings\melissa\mqdmcr.sys
2008-12-17 09:00 66,656 a——- c:\documents and settings\melissa\mqdmbus.sys
2008-12-17 09:00 25,600 a——- c:\documents and settings\melissa\usbsermptxp.sys
2008-12-17 09:00 22,768 a——- c:\documents and settings\melissa\usbsermpt.sys
2008-12-17 09:00 6,208 a——- c:\documents and settings\melissa\mqdmcmnt.sys
2007-05-17 16:10 774,144 ac—— c:\program files\RngInterstitial.dll
============= FINISH: 0:08:13.90 ===============
DDS Attach:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 5/1/2007 10:07:24 AM
System Uptime: 11/11/2010 12:01:58 AM (72 hours ago)
Motherboard: Dell Inc | | 0HY175
Processor: AMD Athlon™ 64 Processor 3500+ | Socket M2 | 2204/1000mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 74 GiB total, 51.177 GiB free.
D: is CDROM (CDFS)
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP748: 8/16/2010 5:35:31 AM - System Checkpoint
RP749: 8/17/2010 1:09:40 AM - Software Distribution Service 3.0
RP750: 8/18/2010 1:35:31 AM - System Checkpoint
RP751: 8/19/2010 3:42:30 AM - System Checkpoint
RP752: 8/19/2010 9:51:49 AM - Software Distribution Service 3.0
RP753: 8/20/2010 10:35:32 AM - System Checkpoint
RP754: 8/21/2010 11:35:31 AM - System Checkpoint
RP755: 8/22/2010 12:05:15 PM - System Checkpoint
RP756: 8/23/2010 12:35:31 PM - System Checkpoint
RP757: 8/23/2010 1:31:13 PM - Software Distribution Service 3.0
RP758: 8/24/2010 2:07:29 AM - Software Distribution Service 3.0
RP759: 8/25/2010 3:46:29 AM - System Checkpoint
RP760: 8/26/2010 3:57:34 AM - System Checkpoint
RP761: 8/27/2010 2:06:35 AM - Software Distribution Service 3.0
RP762: 8/28/2010 2:35:45 AM - System Checkpoint
RP763: 8/29/2010 4:29:44 AM - System Checkpoint
RP764: 8/30/2010 4:35:30 AM - System Checkpoint
RP765: 8/31/2010 2:09:02 AM - Software Distribution Service 3.0
RP766: 9/1/2010 4:24:06 AM - System Checkpoint
RP767: 9/2/2010 4:35:31 AM - System Checkpoint
RP768: 9/3/2010 2:04:51 AM - Software Distribution Service 3.0
RP769: 9/4/2010 4:35:39 AM - System Checkpoint
RP770: 9/5/2010 5:24:52 AM - System Checkpoint
RP771: 9/6/2010 6:10:53 AM - System Checkpoint
RP772: 9/7/2010 2:06:09 AM - Software Distribution Service 3.0
RP773: 9/8/2010 3:00:41 AM - Software Distribution Service 3.0
RP774: 9/9/2010 3:46:56 AM - System Checkpoint
RP775: 9/10/2010 2:04:52 AM - Software Distribution Service 3.0
RP776: 9/11/2010 3:47:11 AM - System Checkpoint
RP777: 9/12/2010 4:42:23 AM - System Checkpoint
RP778: 9/13/2010 5:27:39 AM - System Checkpoint
RP779: 9/14/2010 2:09:59 AM - Software Distribution Service 3.0
RP780: 9/15/2010 2:17:38 AM - System Checkpoint
RP781: 9/15/2010 3:00:32 AM - Software Distribution Service 3.0
RP782: 9/16/2010 3:38:29 AM - System Checkpoint
RP783: 9/17/2010 1:56:54 AM - Software Distribution Service 3.0
RP784: 9/18/2010 3:30:35 AM - System Checkpoint
RP785: 9/19/2010 3:32:35 AM - System Checkpoint
RP786: 9/20/2010 3:39:07 AM - System Checkpoint
RP787: 9/21/2010 1:57:02 AM - Software Distribution Service 3.0
RP788: 9/22/2010 3:23:27 AM - System Checkpoint
RP789: 9/23/2010 3:35:09 AM - System Checkpoint
RP790: 9/23/2010 2:30:41 PM - Installed Java™ 6 Update 21
RP791: 9/24/2010 1:56:41 AM - Software Distribution Service 3.0
RP792: 9/25/2010 3:53:19 AM - System Checkpoint
RP793: 9/26/2010 4:49:39 AM - System Checkpoint
RP794: 9/27/2010 5:21:04 AM - System Checkpoint
RP795: 9/28/2010 1:56:56 AM - Software Distribution Service 3.0
RP796: 9/29/2010 3:00:44 AM - Software Distribution Service 3.0
RP797: 9/30/2010 3:40:52 AM - System Checkpoint
RP798: 10/1/2010 1:57:08 AM - Software Distribution Service 3.0
RP799: 10/1/2010 10:21:51 PM - Software Distribution Service 3.0
RP800: 10/2/2010 11:17:03 PM - System Checkpoint
RP801: 10/4/2010 12:17:03 AM - System Checkpoint
RP802: 10/5/2010 1:17:03 AM - System Checkpoint
RP803: 10/5/2010 1:56:37 AM - Software Distribution Service 3.0
RP804: 10/6/2010 3:29:16 AM - System Checkpoint
RP805: 10/7/2010 4:17:04 AM - System Checkpoint
RP806: 10/8/2010 1:56:35 AM - Software Distribution Service 3.0
RP807: 10/8/2010 3:00:55 AM - Software Distribution Service 3.0
RP808: 10/8/2010 3:30:10 AM - Windows Defender Checkpoint
RP809: 10/9/2010 4:17:32 AM - System Checkpoint
RP810: 10/10/2010 5:13:42 AM - System Checkpoint
RP811: 10/11/2010 6:26:14 AM - System Checkpoint
RP812: 10/12/2010 1:50:42 AM - Software Distribution Service 3.0
RP813: 10/13/2010 3:31:15 AM - System Checkpoint
RP814: 10/14/2010 4:13:45 AM - System Checkpoint
RP815: 10/15/2010 1:50:53 AM - Software Distribution Service 3.0
RP816: 10/15/2010 3:00:48 AM - Software Distribution Service 3.0
RP817: 10/16/2010 3:44:05 AM - System Checkpoint
RP818: 10/17/2010 4:40:05 AM - System Checkpoint
RP819: 10/18/2010 5:40:05 AM - System Checkpoint
RP820: 10/19/2010 2:03:49 AM - Software Distribution Service 3.0
RP821: 10/20/2010 3:51:18 AM - System Checkpoint
RP822: 10/21/2010 4:40:08 AM - System Checkpoint
RP823: 10/22/2010 2:03:30 AM - Software Distribution Service 3.0
RP824: 10/23/2010 3:40:15 AM - System Checkpoint
RP825: 10/24/2010 3:52:16 AM - System Checkpoint
RP826: 10/25/2010 4:40:03 AM - System Checkpoint
RP827: 10/26/2010 2:03:48 AM - Software Distribution Service 3.0
RP828: 10/27/2010 3:50:24 AM - System Checkpoint
RP829: 10/28/2010 4:40:02 AM - System Checkpoint
RP830: 10/29/2010 2:03:42 AM - Software Distribution Service 3.0
RP831: 10/30/2010 3:17:01 AM - System Checkpoint
RP832: 10/31/2010 4:27:38 AM - System Checkpoint
RP833: 11/1/2010 4:40:01 AM - System Checkpoint
RP834: 11/2/2010 2:03:49 AM - Software Distribution Service 3.0
RP835: 11/2/2010 3:26:42 AM - Software Distribution Service 3.0
RP836: 11/2/2010 11:36:50 PM - Software Distribution Service 3.0
RP837: 11/3/2010 2:03:19 AM - Software Distribution Service 3.0
RP838: 11/3/2010 8:24:34 PM - Software Distribution Service 3.0
RP839: 11/4/2010 2:04:34 AM - Software Distribution Service 3.0
RP840: 11/4/2010 6:11:42 PM - Software Distribution Service 3.0
RP841: 11/5/2010 2:04:37 AM - Software Distribution Service 3.0
RP842: 11/5/2010 5:53:16 PM - Software Distribution Service 3.0
RP843: 11/6/2010 2:03:27 AM - Software Distribution Service 3.0
RP844: 11/7/2010 12:48:17 AM - Software Distribution Service 3.0
RP845: 11/8/2010 1:12:55 AM - System Checkpoint
RP846: 11/9/2010 1:39:53 AM - System Checkpoint
RP847: 11/9/2010 2:03:41 AM - Software Distribution Service 3.0
RP848: 11/9/2010 10:23:06 PM - Installed Java™ 6 Update 22
RP849: 11/10/2010 3:00:43 AM - Software Distribution Service 3.0
RP850: 11/11/2010 3:42:48 AM - System Checkpoint
RP851: 11/12/2010 1:47:19 AM - Software Distribution Service 3.0
RP852: 11/13/2010 2:50:54 AM - System Checkpoint
RP853: 11/13/2010 8:46:41 PM - Installed HiJackThis
RP854: 11/14/2010 12:00:12 AM - OTL Restore Point
==== Installed Programs ======================
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.2.5
Adobe Shockwave Player 11.5
AppCore
ArcSoft Panorama Maker 3
AT&T; Communication Manager
AT&T; Self Support Tool
AT&T; Service & Support Tool
Athlon 64 Processor Driver
AV
Avanquest update
Broadcom 440x 10/100 Integrated Controller
Broadcom Management Programs
ccCommon
CleanUp!
Conexant D850 56K V.9x DFVc Modem
CreativeProjects
CreativeProjectsTemplates
Critical Update for Windows Media Player 11 (KB959772)
CueTour
DeductionPro 2008
DeductionPro 2009
Dell ResourceCD
Destinations
Director
Driver Installer
Drivers Daily Log - LITE
Google Chrome
Google Earth
Google Talk (remove only)
Google Update Helper
H&R; Block Connecticut 2009
H&R; Block Premium + Efile + State 2009
High Definition Audio Driver Package - KB835221
HiJackThis
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB971276-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Deskjet 6800
HP Photo & Imaging 4.1
HP Product Detection
HP Software Update
HP Update
HPSystemDiagnostics
InstantShare
Internet Worm Protection
J2SE Runtime Environment 5.0 Update 3
Jalbum 8.0
Java Auto Updater
Java™ 6 Update 18
Java™ 6 Update 22
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Java™ SE Runtime Environment 6 Update 1
LiveUpdate 3.2 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Malwarebytes' Anti-Malware
Marine Data Center
Marine Data Center Tutorials
Media Library Management Wizard
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft MapPoint 2002 North America
Microsoft Money 2005
Microsoft National Language Support Downlevel APIs
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Motorola Driver Installation 3.4.0
Motorola Phone Tools
Movie Maker Background Music Files
Movie Maker Sound Effects
Movie Maker Title Images
Mozilla Firefox (3.6.12)
Mozilla Thunderbird (2.0.0.24)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB954459)
Nautilus IV
Nikon Message Center
Norton AntiVirus
Norton AntiVirus (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton AntiVirus SYMLT MSI
Norton Protection Center
Norton Security Scan
NVIDIA Drivers
OpenOffice.org 3.2
Overland
Panda ActiveScan 2.0
PC ScanAndSweep
Pdf995 (installed by H&R; Block)
PdfEdit995 (installed by H&R; Block)
Personal License Update Wizard for Windows Media Player
PhotoFantasy 2.0
PhotoGallery
PhotoWorks v2.41
Picasa 3
PictureProject
PictureProject In Touch Downloader 1.0
Platform
Plus! MP3 Audio Converter LE
PostgreSQL 8.2
Power Point Viewer
PowerISO
PrintScreen
QFolder
QuickProjects
QuickTime
Rand McNally TripMaker Deluxe 2000 SE
Samsung New PC Studio
SAMSUNG USB Driver for Mobile Phones
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
SEE-Bottom
SEE-Patterns
SEE-Structure
SEE-Temp FREE Version
SEE-Temp Plus
SEE-Tides
Segoe UI
SigmaTel Audio
SkinsHP1
Sonic Audio module
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
SPBBC 32bit
SUPERAntiSpyware Free Edition
Symantec
Symantec Real Time Storage Protection Component
SymNet
TaxCut Connecticut 2008
TaxCut Premium + State + Efile 2008
TaxCut Premium 2006
TrailSYM
TrayApp
Trend Micro RUBotted 2.0 Beta
U.S. Robotics 56K Faxmodem USB
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB972636)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VIA Platform Device Manager
View22
WebFldrs XP
WebReg
WIDCOMM Bluetooth Software
Windows Defender
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Media Bonus Pack for Windows XP
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Playlist Import to Excel Wizard
Windows Media Player Skin Importer
Windows Media Player Tray Control
Windows Search 4.0
Windows XP Service Pack 3
WinPcap 4.1.1
XML Paper Specification Shared Components Pack 1.0
XPS Essentials Pack
XPS Essentials Pack 1.0
Yahoo! Browser Services
Yahoo! Messenger
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
11/13/2010 7:40:11 PM, error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
11/11/2010 12:03:16 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
11/10/2010 10:54:41 PM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists.
11/10/2010 10:49:11 PM, error: Service Control Manager [7034] - The FsUsbExService service terminated unexpectedly. It has done this 1 time(s).
11/10/2010 10:48:57 PM, error: Service Control Manager [7034] - The Pml Driver HPZ12 service terminated unexpectedly. It has done this 1 time(s).
11/10/2010 10:48:45 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
11/10/2010 10:41:22 PM, error: Service Control Manager [7034] - The McciServiceHost service terminated unexpectedly. It has done this 1 time(s).
11/10/2010 10:24:46 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.
11/10/2010 10:24:46 PM, error: Service Control Manager [7000] - The LiveUpdate service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/10/2010 10:24:23 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service LiveUpdate with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}
==== End Of File ===========================
Running more than 1 application at a time pc comes to a halt. Here are my logs:
OLT:
OTL logfile created on: 11/14/2010 12:09:06 AM - Run 3
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\melissa\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
446.00 Mb Total Physical Memory | 49.00 Mb Available Physical Memory | 11.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 55.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 51.18 Gb Free Space | 68.70% Space Free | Partition Type: NTFS
Drive D: | 170.63 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: C521 | User Name: melissa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\melissa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
PRC - C:\Program Files\ATT-SST\McciTrayApp.exe (Alcatel-Lucent)
PRC - C:\Program Files\Common Files\Motive\McciServiceHost.exe (Alcatel-Lucent)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\melissa\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Motive\McciContextHook_DSR.dll (Alcatel-Lucent)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Trend Micro RUBotted Service) – C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe (Trend Micro Inc.)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (McciServiceHost) – C:\Program Files\Common Files\Motive\McciServiceHost.exe (Alcatel-Lucent)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (ATTRcAppSvc) – C:\Program Files\AT&T;\Communication Manager\RcAppSvc.exe (SmithMicro Inc.)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (ISPwdSvc) – C:\Program Files\Norton AntiVirus\isPwdSvc.exe (Symantec Corporation)
SRV - (LiveUpdate Notice Ex) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (pgsql-8.2) – C:\Nautilus\rdbms\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (SymAppCore) – C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (HP Port Resolver) – C:\WINDOWS\system32\hpbpro.exe (Hewlett-Packard Company)
SRV - (HP Status Server) – C:\WINDOWS\system32\hpboid.exe (Hewlett-Packard Company)
========== Driver Services (SafeList) ==========
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (sscemdm) – C:\WINDOWS\system32\drivers\sscemdm.sys (MCCI Corporation)
DRV - (sscebus) SAMSUNG USB Composite Device V2 driver (WDM) – C:\WINDOWS\system32\drivers\sscebus.sys (MCCI Corporation)
DRV - (sscemdfl) – C:\WINDOWS\system32\drivers\sscemdfl.sys (MCCI Corporation)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (usbsermpt) – C:\WINDOWS\system32\drivers\usbsermpt.sys (Microsoft Corporation)
DRV - (tcpipBM) – C:\WINDOWS\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (PCTINDIS5) – C:\WINDOWS\system32\PCTINDIS5.sys (Smith Micro Inc.)
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (swmsflt) – C:\WINDOWS\System32\drivers\swmsflt.sys ()
DRV - (SWUMX80) Sierra Wireless USB MUX Driver (UMTS80) – C:\WINDOWS\system32\drivers\swumx80.sys (Sierra Wireless Inc.)
DRV - (SWNC8U80) Sierra Wireless MUX NDIS Driver (UMTS80) – C:\WINDOWS\system32\drivers\swnc8u80.sys (Sierra Wireless Inc.)
DRV - (pavboot) – C:\WINDOWS\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080516.019\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080516.019\NAVENG.SYS (Symantec Corporation)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (SYMIDSCO) – C:\Program Files\Common Files\Symantec Shared\SymcData\ids-diskless\20080623.001\SymIDSCo.sys (Symantec Corporation)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (Winacusb) – C:\WINDOWS\system32\drivers\winacusb.sys (U.S. Robotics)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://news.yahoo.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 82 A0 3E A9 8E 5E CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/07 22:03:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/09 17:37:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/03/31 14:28:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2008/12/24 12:44:09 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Mozilla\Extensions
[2010/11/13 00:36:40 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Mozilla\Firefox\Profiles\uaetpfrv.default\extensions
[2010/05/08 06:47:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\melissa\Application Data\Mozilla\Firefox\Profiles\uaetpfrv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/13 00:36:40 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/27 15:32:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/23 13:33:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/09 22:26:28 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AT&T; Communication Manager] C:\Program Files\AT&T;\Communication Manager\ATTCM.exe (ATT)
O4 - HKLM..\Run: [ATT-SST_McciTrayApp] C:\Program Files\ATT-SST\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe (HP)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [Trend Micro RUBotted V2.0 Beta] C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [FreeRAM XP] C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (YourWare Solutions ™)
O4 - HKCU..\Run: [UpdateFlow.ATT-SST] C:\Program Files\ATT-SST\McciBrowser.exe (Alcatel-Lucent)
O4 - HKLM..\RunOnce: [TSC] C:\Documents and Settings\melissa\Local Settings\Temp\HouseCall\TSC.exe (Trend Micro Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O15 - HKCU\..Trusted Domains: //@signup.mar@/ ([]money in My Computer)
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: att.com ([ufix] https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab (Windows Live Safety Center Base Module)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} http://cid-c76209a9d8ecd425.spaces.live.co…ad/MsnPUpld.cab (Windows Live Photo Upload Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\melissa\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\melissa\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/05/01 09:05:33 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/08/24 11:52:37 | 000,000,026 | RH– | M] () - D:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{feed18c1-f7c9-11db-a3d6-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{feed18c1-f7c9-11db-a3d6-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{feed18c1-f7c9-11db-a3d6-806d6172696f}\Shell\AutoRun\command - "" = D:\tcauto.exe – [2009/11/04 18:59:01 | 007,636,800 | R— | M] (HR Block )
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: VIDC.NSVI - nsvideo.dll File not found
Drivers32: vidc.wmv3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/11/13 21:26:45 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\melissa\Desktop\OTL.exe
[2010/11/13 21:03:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Trend Micro
[2010/11/13 20:53:05 | 000,000,000 | —D | C] – C:\Program Files\WinPcap
[2010/11/13 20:52:39 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/11/13 20:46:44 | 000,000,000 | —D | C] – C:\Program Files\HijackThis
[2010/11/10 13:53:50 | 000,000,000 | —D | C] – C:\Documents and Settings\melissa\Application Data\Camfrog
[2010/11/10 13:52:30 | 000,000,000 | —D | C] – C:\Program Files\Camfrog
[2010/11/09 22:26:16 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/11/09 22:26:14 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/11/09 22:26:14 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/11/09 22:26:13 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2007/05/17 16:10:04 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/14 00:06:38 | 000,002,563 | —- | M] () – C:\Documents and Settings\melissa\Desktop\HiJackThis.lnk
[2010/11/13 23:19:06 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/13 21:28:00 | 000,359,929 | —- | M] () – C:\Documents and Settings\melissa\Desktop\dds.scr
[2010/11/13 21:27:58 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\melissa\Desktop\OTL.exe
[2010/11/13 20:57:32 | 000,000,036 | —- | M] () – C:\Documents and Settings\melissa\Local Settings\Application Data\housecall.guid.cache
[2010/11/13 20:53:09 | 000,000,073 | —- | M] () – C:\WINDOWS\System32\-1
[2010/11/13 20:28:12 | 000,000,426 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{78661A67-11FF-4A9B-86B9-1A61F1709684}.job
[2010/11/13 19:40:14 | 000,000,216 | —- | M] () – C:\WINDOWS\tasks\ms.job
[2010/11/13 17:19:11 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/13 16:56:01 | 000,000,562 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for melissa.job
[2010/11/13 01:51:30 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/12 17:30:22 | 000,001,836 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AT&T; Service & Support Tool.lnk
[2010/11/12 13:29:41 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/11/12 13:29:40 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/11/12 10:55:40 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/11/12 09:00:00 | 000,000,386 | —- | M] () – C:\WINDOWS\tasks\rpc.job
[2010/11/11 00:02:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/10 15:58:33 | 000,000,390 | —- | M] () – C:\WINDOWS\Trpmaker.INI
[2010/11/09 22:18:35 | 000,462,058 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/11/09 22:18:34 | 000,078,260 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/11/09 17:37:54 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2010/11/08 20:00:00 | 000,000,580 | —- | M] () – C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - SEI Aaron's Rents.job
[2010/11/07 07:19:58 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/10/19 10:41:44 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/10/15 02:34:59 | 000,157,952 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/15 02:16:58 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/13 21:27:15 | 000,359,929 | —- | C] () – C:\Documents and Settings\melissa\Desktop\dds.scr
[2010/11/13 20:57:32 | 000,000,036 | —- | C] () – C:\Documents and Settings\melissa\Local Settings\Application Data\housecall.guid.cache
[2010/11/13 20:53:08 | 000,000,073 | —- | C] () – C:\WINDOWS\System32\-1
[2010/11/13 20:46:45 | 000,002,563 | —- | C] () – C:\Documents and Settings\melissa\Desktop\HiJackThis.lnk
[2010/11/12 17:30:21 | 000,001,836 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AT&T; Service & Support Tool.lnk
[2010/11/12 13:29:41 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/11/12 13:29:40 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/08/01 15:55:34 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/08/01 15:55:34 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/08/01 15:53:59 | 000,002,528 | —- | C] () – C:\Documents and Settings\melissa\Application Data\$_hpcst$.hpc
[2010/04/06 14:06:07 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2010/02/15 17:35:26 | 000,000,253 | —- | C] () – C:\WINDOWS\fantasy2.ini
[2010/02/15 17:35:26 | 000,000,021 | —- | C] () – C:\WINDOWS\Pf_setup.ini
[2010/02/14 20:41:21 | 000,010,630 | —- | C] () – C:\WINDOWS\System32\WTCPAPI.DLL
[2010/02/14 20:41:20 | 000,496,336 | —- | C] () – C:\WINDOWS\System32\LEAD40.DLL
[2010/02/14 20:41:20 | 000,084,448 | —- | C] () – C:\WINDOWS\System32\PCDLIB.DLL
[2010/02/14 20:26:15 | 001,690,896 | —- | C] () – C:\WINDOWS\System32\Mso97v.dll
[2010/02/14 20:26:15 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\Docobj.dll
[2010/02/14 20:26:15 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\Hlinkprx.dll
[2009/10/20 13:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/10/09 18:03:28 | 000,000,440 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2009/10/09 17:58:20 | 000,000,415 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/07/29 17:12:51 | 000,026,760 | —- | C] () – C:\WINDOWS\System32\drivers\swmsflt.sys
[2009/01/06 22:57:54 | 000,223,232 | —- | C] () – C:\WINDOWS\System32\sqlite3.dll
[2008/12/15 18:44:35 | 000,000,130 | —- | C] () – C:\Documents and Settings\melissa\Local Settings\Application Data\fusioncache.dat
[2008/12/05 00:47:11 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2008/09/27 23:05:01 | 000,000,742 | —- | C] () – C:\WINDOWS\PODW.INI
[2008/09/27 23:05:00 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\SfwIFmt.dll
[2008/09/18 21:31:13 | 000,000,390 | —- | C] () – C:\WINDOWS\Trpmaker.INI
[2008/09/18 21:30:54 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\PlugFile.dll
[2008/09/18 21:30:53 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2008/09/18 21:30:51 | 000,038,688 | —- | C] () – C:\WINDOWS\System32\Leaddib.drv
[2008/09/18 21:30:51 | 000,011,136 | —- | C] () – C:\WINDOWS\System32\Fprun300.dll
[2008/07/08 16:45:53 | 000,012,288 | —- | C] () – C:\Documents and Settings\melissa\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/15 23:53:03 | 000,000,083 | —- | C] () – C:\WINDOWS\usrwiz.ini
[2008/04/14 13:58:40 | 002,854,912 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2008/04/07 00:36:24 | 000,000,142 | —- | C] () – C:\WINDOWS\wpd99.drv
[2008/04/07 00:35:58 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2008/03/18 18:30:11 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2008/03/18 18:28:54 | 000,001,020 | —- | C] () – C:\WINDOWS\disney.ini
[2008/02/04 17:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2008/01/12 16:01:37 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2007/11/29 20:18:08 | 000,000,283 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2007/11/29 20:18:07 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2007/11/29 20:17:01 | 000,013,646 | —- | C] () – C:\WINDOWS\hpdj6800.ini
[2007/11/29 20:16:54 | 000,002,742 | —- | C] () – C:\WINDOWS\hpf6800m.ini
[2007/11/26 20:04:18 | 000,000,033 | —- | C] () – C:\WINDOWS\wwwbatch.ini
[2007/11/12 15:18:10 | 000,000,047 | —- | C] () – C:\WINDOWS\promftax.ini
[2007/11/12 15:13:50 | 000,001,570 | —- | C] () – C:\WINDOWS\promilesxf.ini
[2007/10/25 16:26:10 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/06/20 16:11:21 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/05/12 15:12:44 | 000,000,143 | —- | C] () – C:\WINDOWS\VWORK32.INI
[2007/05/12 15:05:22 | 000,000,012 | —- | C] () – C:\WINDOWS\EZPhotoTools2.ini
[2007/05/12 15:04:42 | 000,000,012 | —- | C] () – C:\WINDOWS\EZPhotoBrowser2.ini
[2007/05/12 15:03:41 | 000,000,012 | —- | C] () – C:\WINDOWS\Showtime1.ini
[2007/05/01 09:56:53 | 000,000,331 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/05/01 09:43:17 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/05/01 09:43:17 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/05/01 09:43:17 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/05/01 09:43:16 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/05/01 09:43:15 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/05/01 09:43:15 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2007/05/01 09:43:13 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2007/05/01 04:55:57 | 000,004,346 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/06/22 13:37:46 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/01/08 09:30:22 | 000,011,170 | —- | C] () – C:\WINDOWS\System32\PA207USD.DLL
[2001/11/14 13:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
========== LOP Check ==========
[2007/06/26 14:58:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aliasworlds
[2009/01/06 23:03:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ascentive
[2009/07/29 19:29:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2008/12/15 13:33:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/02/04 08:21:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EA
[2008/12/05 00:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/02/02 16:18:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2007/05/13 07:21:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FloodLightGames
[2007/07/11 14:36:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Friends Games
[2008/01/12 13:58:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameBlend
[2007/06/10 09:23:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin
[2007/05/13 14:51:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2007/05/25 19:35:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/12/16 23:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/04/06 14:08:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2007/06/30 18:08:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2007/07/01 15:22:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Playtonium Games
[2010/08/01 15:56:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2007/07/15 10:10:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2007/05/29 15:40:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecretsOfOlympus
[2010/04/04 13:25:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2008/03/27 18:21:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/05 00:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2007/05/01 10:01:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/08/26 13:43:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2007/05/18 21:19:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Winferno
[2009/07/29 17:14:59 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\AT&T;
[2009/07/29 17:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Bytemobile
[2010/11/10 13:56:13 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Camfrog
[2009/07/29 17:15:15 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\DBUpdater
[2008/02/04 08:21:12 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\EA
[2008/02/02 16:18:31 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Flood Light Games
[2008/01/12 13:58:56 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\GameBlend
[2008/02/02 12:35:12 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\iWin
[2008/04/05 19:52:38 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\LargoSoftware
[2007/10/06 20:31:24 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Leadertech
[2009/03/28 16:36:40 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Nikon
[2008/12/09 10:43:56 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\OpenOffice.org
[2010/04/06 14:06:18 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\pdf995
[2008/02/02 08:17:34 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Pogo Games
[2009/11/29 08:38:41 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Qualcomm
[2010/08/01 15:52:06 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Samsung
[2008/05/14 14:55:17 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\SecondLife
[2009/07/29 17:00:55 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Sierra Wireless
[2010/04/06 14:08:54 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\TaxCut
[2009/11/29 12:45:18 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Thunderbird
[2008/12/15 18:40:39 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Windows Desktop Search
[2008/12/16 23:57:27 | 000,000,000 | —D | M] – C:\Documents and Settings\melissa\Application Data\Windows Search
[2010/11/13 01:51:30 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/11/13 19:40:14 | 000,000,216 | —- | M] () – C:\WINDOWS\Tasks\ms.job
[2010/11/12 09:00:00 | 000,000,386 | —- | M] () – C:\WINDOWS\Tasks\rpc.job
[2010/11/13 20:28:12 | 000,000,426 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{78661A67-11FF-4A9B-86B9-1A61F1709684}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2007/05/01 09:05:33 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/07/29 19:39:28 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2007/05/01 09:05:33 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/12/17 08:57:00 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2007/07/01 13:34:15 | 000,000,098 | —- | M] () – C:\DownloadLog.txt
[2003/12/08 12:15:56 | 000,028,672 | R— | M] ( ) – C:\hpqimgrc.resources.dll
[2007/07/10 10:42:12 | 000,000,438 | —- | M] () – C:\INSTALL.LOG
[2007/05/01 09:05:33 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2007/07/20 16:15:06 | 000,000,125 | —- | M] () – C:\ioSpecial.ini
[2007/05/18 21:18:05 | 000,000,243 | —- | M] () – C:\log.html
[2007/05/01 09:05:33 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/08/05 17:00:50 | 000,001,097 | —- | M] () – C:\net_save.dna
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/12/27 12:09:28 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/11/13 20:37:53 | 1017,118,720 | -HS- | M] () – C:\pagefile.sys
[2007/08/18 09:25:09 | 000,043,665 | —- | M] () – C:\playground.log
[2009/11/12 10:37:42 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/11/13 00:32:43 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/11/15 17:10:03 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/11/23 12:21:44 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/11/26 01:35:27 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009/11/26 20:08:58 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/11/27 14:51:33 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009/11/28 06:26:03 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2009/11/28 20:24:23 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/11/29 07:40:01 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/11/30 06:01:54 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/11/30 09:05:07 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/11/30 09:34:37 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/11/03 15:18:49 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/11/03 16:33:05 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/11/05 16:15:04 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2009/11/06 18:34:04 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2009/11/07 05:45:15 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009/11/08 00:27:43 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009/11/08 23:19:46 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/11/12 10:37:42 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/11/13 00:32:42 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/11/15 17:10:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/11/23 12:21:44 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/11/26 01:35:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/11/26 20:08:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/11/27 14:51:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/11/28 06:26:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/11/28 20:24:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/11/29 07:40:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/11/30 06:01:54 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/11/30 09:05:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/11/30 09:34:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/11/03 15:18:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/11/03 16:33:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/11/05 16:15:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/11/06 18:34:04 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/11/07 05:45:15 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/11/08 00:27:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/11/08 23:19:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2007/07/16 17:10:17 | 000,230,454 | —- | M] () – C:\StiImg.dat
[2007/06/01 09:32:59 | 000,064,188 | —- | M] () – C:\VETlog.dmp
[2007/06/01 09:32:59 | 000,020,259 | —- | M] () – C:\VETlog.txt
[2007/10/15 22:08:15 | 000,000,146 | —- | M] () – C:\YServer.txt
< %systemroot%\Fonts\*.com >
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2007/05/01 09:05:08 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/08/14 20:49:20 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/08/14 17:02:46 | 000,594,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2008/12/01 17:00:31 | 000,489,628 | —- | M] (MacSourcery) – C:\WINDOWS\Install.scr
[2009/07/10 12:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/02/14 16:19:21 | 000,001,666 | -H– | M] () – C:\Documents and Settings\melissa\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2007/05/17 16:10:00 | 000,774,144 | —- | M] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2007/05/01 04:54:10 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/05/01 04:54:10 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/05/01 04:54:10 | 000,892,928 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/27 12:17:20 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2009/07/30 07:53:42 | 000,006,656 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/07/10 10:27:08 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\melissa\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/07/10 10:27:07 | 000,000,079 | —- | M] () – C:\Documents and Settings\melissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2008/12/31 19:56:54 | 000,223,368 | —- | M] () – C:\Documents and Settings\melissa\Desktop\CrucialScan.exe
[2010/11/13 21:27:58 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\melissa\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-12 06:50:21
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DE73B0FE
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:20DB61D6
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DB365884
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CF5C4195
@Alternate Data Stream - 173 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D8A7F3FF
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:17639624
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1A5D64BE
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F686C4A
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F65733F1
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4E903DEB
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8A44841A
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4D24FC46
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:43301D1D
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A73A758
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BDCD8531
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CE6885F1
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C1CCF2C1
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7C412B92
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:580E04D8
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2A208B5C
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CE0A077E
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BBE01348
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:426796C0
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9884A8C7
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:78E0DF72
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:51574724
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96CC3FEF
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8B90426A
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:260575F1
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:55F44B88
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54997B77
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:375A40C3
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F00E008B
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E36F5B57
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B7ADB4DA
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59D05D9A
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5759F6F0
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D6BDE53F
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC95B5ED
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0ED4AC2F
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:98DFF516
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8643C5BE
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:453190EC
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B623B5B8
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:949483BD
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:270A3983
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2B99FE60
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B745EBA5
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A98DA12
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:053BAE56
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E60C72DB
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3CD562B4
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63CFD724
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:618BF152
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D09AEE3D
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2ABEB9EB
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:88D615D5
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:70E897B5
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:507C73B7
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F7862839
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6BD304B9
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60C47453
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8AB6C1D7
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5BC73C48
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E55CE2D1
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FF8F1AE3
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E4AC8DCB
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90BA5E08
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B3A35EC
< End of report >
HiJackThis:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:07:05 AM, on 11/14/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\ATT-SST\McciTrayApp.exe
C:\Program Files\Common Files\Motive\McciServiceHost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [AT&T; Communication Manager] "C:\Program Files\AT&T;\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [ATT-SST_McciTrayApp] "C:\Program Files\ATT-SST\McciTrayApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Trend Micro RUBotted V2.0 Beta] C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
O4 - HKLM\..\RunOnce: [TSC] "C:\DOCUME~1\melissa\LOCALS~1\Temp\HouseCall\tsc.exe" /HD
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [UpdateFlow.ATT-SST] C:\Program Files\ATT-SST\McciBrowser.exe -AppKey=ATT-SST -URL=file://C:\Program Files\ATT-SST\OfflineUpdate\redirector.htm
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-c76209a9d8ecd425.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AT&T; RcAppSvc (ATTRcAppSvc) - SmithMicro Inc. - C:\Program Files\AT&T;\Communication Manager\RcAppSvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McciServiceHost - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciServiceHost.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server 8.2 (pgsql-8.2) - PostgreSQL Global Development Group - C:\Nautilus\rdbms\bin\pg_ctl.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Trend Micro RUBotted Service - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe
–
End of file - 11275 bytes
DDS:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 0:07:40.96 on Sun 11/14/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.33 [GMT -5:00]
AV: Norton AntiVirus *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\ATT-SST\McciTrayApp.exe
C:\Program Files\Common Files\Motive\McciServiceHost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\melissa\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn1\YTSingleInstance.dll
TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [FreeRAM XP] "c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe" -win
uRun: [UpdateFlow.ATT-SST] c:\program files\att-sst\mccibrowser.exe -appkey=att-sst -url=file://c:\program files\att-sst\offlineupdate\redirector.htm
uRun: [AutoStartNPSAgent] c:\program files\samsung\samsung new pc studio\NPSAgent.exe
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [AT&T; Communication Manager] "c:\program files\at&t;\communication manager\ATTCM.exe" -a
mRun: [ccApp] c:\program files\common files\symantec shared\ccApp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Software Update] "c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe
mRun: [ATT-SST_McciTrayApp] "c:\program files\att-sst\McciTrayApp.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [NPSStartup]
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Trend Micro RUBotted V2.0 Beta] c:\program files\trend micro\rubotted\RUBottedGUI.exe
mRunOnce: [TSC] "c:\docume~1\melissa\locals~1\temp\housecall\tsc.exe" /HD
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
LSP: bmnet.dll
Trusted Zone: att.com\ufix
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} - hxxp://cid-c76209a9d8ecd425.spaces.live.com/PhotoUpload/MsnPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - c:\program files\qualcomm\eudora\EuShlExt.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\melissa\applic~1\mozilla\firefox\profiles\uaetpfrv.default\
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - plugin: c:\program files\view22\version 3.10.50\NPView22.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-7-22 28544]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-7-28 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-7-28 67656]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2007-1-10 108648]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2007-1-10 108648]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-8-1 238952]
R2 McciServiceHost;McciServiceHost;c:\program files\common files\motive\McciServiceHost.exe [2009-11-29 315392]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
R2 Trend Micro RUBotted Service;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\RUBotSrv.exe [2010-11-13 431440]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-8-1 36608]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20080516.019\NAVENG.SYS [2008-5-17 82256]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20080516.019\NAVEX15.SYS [2008-5-17 895408]
R3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-6-20 1251720]
R3 Winacusb;Winacusb;c:\windows\system32\drivers\winacusb.sys [2008-11-23 902860]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-24 136176]
S2 pgsql-8.2;PostgreSQL Database Server 8.2;c:\nautilus\rdbms\bin\pg_ctl.exe runservice -n "pgsql-8.2" -d "c:\nautilus\rdbms\data\" –> c:\nautilus\rdbms\bin\pg_ctl.exe runservice -N pgsql-8.2 [?]
S3 ATTRcAppSvc;AT&T; RcAppSvc;c:\program files\at&t;\communication manager\RcAppSvc.exe [2008-11-20 113152]
S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-4 14336]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-7-28 12872]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\drivers\sscebus.sys [2010-8-1 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\drivers\sscemdfl.sys [2010-8-1 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\drivers\sscemdm.sys [2010-8-1 123648]
S3 SWNC8U80;Sierra Wireless MUX NDIS Driver (UMTS80);c:\windows\system32\drivers\swnc8u80.sys [2008-8-20 168192]
S3 SWUMX80;Sierra Wireless USB MUX Driver (UMTS80);c:\windows\system32\drivers\swumx80.sys [2008-8-20 142976]
=============== Created Last 30 ================
2010-11-13 21:03 –d—– c:\docume~1\alluse~1\applic~1\Trend Micro
2010-11-13 20:53 73 a——- c:\windows\system32\-1
2010-11-13 20:53 –d—– c:\program files\WinPcap
2010-11-13 20:52 –d—– c:\program files\Trend Micro
2010-11-12 13:29 1,409 a——- c:\windows\QTFont.for
2010-11-12 13:29 54,156 a—h— c:\windows\QTFont.qfn
2010-11-10 13:53 –d—– c:\docume~1\melissa\applic~1\Camfrog
2010-11-10 13:52 –d—– c:\program files\Camfrog
2010-11-09 22:26 73,728 a——- c:\windows\system32\javacpl.cpl
==================== Find3M ====================
2010-10-19 10:41 222,080 ——– c:\windows\system32\MpSigStub.exe
2010-09-18 11:23 974,848 a——- c:\windows\system32\mfc42u.dll
2010-09-18 01:53 974,848 a——- c:\windows\system32\mfc42.dll
2010-09-18 01:53 953,856 a——- c:\windows\system32\mfc40u.dll
2010-09-18 01:53 954,368 ——– c:\windows\system32\mfc40.dll
2010-09-15 04:50 472,808 a——- c:\windows\system32\deployJava1.dll
2010-09-10 00:58 916,480 a——- c:\windows\system32\wininet.dll
2010-09-10 00:58 43,520 a——- c:\windows\system32\licmgr10.dll
2010-09-01 06:51 285,824 a——- c:\windows\system32\atmfd.dll
2010-08-31 08:42 1,852,800 a——- c:\windows\system32\win32k.sys
2010-08-27 03:02 119,808 ——– c:\windows\system32\t2embed.dll
2010-08-27 00:57 99,840 a——- c:\windows\system32\srvsvc.dll
2010-08-26 07:52 5,120 a——- c:\windows\system32\xpsp4res.dll
2010-08-23 11:12 617,472 a——- c:\windows\system32\comctl32.dll
2010-08-17 08:17 58,880 a——- c:\windows\system32\spoolsv.exe
2010-08-16 03:45 590,848 a——- c:\windows\system32\rpcrt4.dll
2009-03-28 16:33 20 a—h— c:\docume~1\alluse~1\applic~1\PKP_DLec.DAT
2008-12-17 09:00 92,064 a——- c:\documents and settings\melissa\mqdmmdm.sys
2008-12-17 09:00 79,328 a——- c:\documents and settings\melissa\mqdmserd.sys
2008-12-17 09:00 9,232 a——- c:\documents and settings\melissa\mqdmmdfl.sys
2008-12-17 09:00 5,936 a——- c:\documents and settings\melissa\mqdmwhnt.sys
2008-12-17 09:00 4,048 a——- c:\documents and settings\melissa\mqdmcr.sys
2008-12-17 09:00 66,656 a——- c:\documents and settings\melissa\mqdmbus.sys
2008-12-17 09:00 25,600 a——- c:\documents and settings\melissa\usbsermptxp.sys
2008-12-17 09:00 22,768 a——- c:\documents and settings\melissa\usbsermpt.sys
2008-12-17 09:00 6,208 a——- c:\documents and settings\melissa\mqdmcmnt.sys
2007-05-17 16:10 774,144 ac—— c:\program files\RngInterstitial.dll
============= FINISH: 0:08:13.90 ===============
DDS Attach:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 5/1/2007 10:07:24 AM
System Uptime: 11/11/2010 12:01:58 AM (72 hours ago)
Motherboard: Dell Inc | | 0HY175
Processor: AMD Athlon™ 64 Processor 3500+ | Socket M2 | 2204/1000mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 74 GiB total, 51.177 GiB free.
D: is CDROM (CDFS)
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP748: 8/16/2010 5:35:31 AM - System Checkpoint
RP749: 8/17/2010 1:09:40 AM - Software Distribution Service 3.0
RP750: 8/18/2010 1:35:31 AM - System Checkpoint
RP751: 8/19/2010 3:42:30 AM - System Checkpoint
RP752: 8/19/2010 9:51:49 AM - Software Distribution Service 3.0
RP753: 8/20/2010 10:35:32 AM - System Checkpoint
RP754: 8/21/2010 11:35:31 AM - System Checkpoint
RP755: 8/22/2010 12:05:15 PM - System Checkpoint
RP756: 8/23/2010 12:35:31 PM - System Checkpoint
RP757: 8/23/2010 1:31:13 PM - Software Distribution Service 3.0
RP758: 8/24/2010 2:07:29 AM - Software Distribution Service 3.0
RP759: 8/25/2010 3:46:29 AM - System Checkpoint
RP760: 8/26/2010 3:57:34 AM - System Checkpoint
RP761: 8/27/2010 2:06:35 AM - Software Distribution Service 3.0
RP762: 8/28/2010 2:35:45 AM - System Checkpoint
RP763: 8/29/2010 4:29:44 AM - System Checkpoint
RP764: 8/30/2010 4:35:30 AM - System Checkpoint
RP765: 8/31/2010 2:09:02 AM - Software Distribution Service 3.0
RP766: 9/1/2010 4:24:06 AM - System Checkpoint
RP767: 9/2/2010 4:35:31 AM - System Checkpoint
RP768: 9/3/2010 2:04:51 AM - Software Distribution Service 3.0
RP769: 9/4/2010 4:35:39 AM - System Checkpoint
RP770: 9/5/2010 5:24:52 AM - System Checkpoint
RP771: 9/6/2010 6:10:53 AM - System Checkpoint
RP772: 9/7/2010 2:06:09 AM - Software Distribution Service 3.0
RP773: 9/8/2010 3:00:41 AM - Software Distribution Service 3.0
RP774: 9/9/2010 3:46:56 AM - System Checkpoint
RP775: 9/10/2010 2:04:52 AM - Software Distribution Service 3.0
RP776: 9/11/2010 3:47:11 AM - System Checkpoint
RP777: 9/12/2010 4:42:23 AM - System Checkpoint
RP778: 9/13/2010 5:27:39 AM - System Checkpoint
RP779: 9/14/2010 2:09:59 AM - Software Distribution Service 3.0
RP780: 9/15/2010 2:17:38 AM - System Checkpoint
RP781: 9/15/2010 3:00:32 AM - Software Distribution Service 3.0
RP782: 9/16/2010 3:38:29 AM - System Checkpoint
RP783: 9/17/2010 1:56:54 AM - Software Distribution Service 3.0
RP784: 9/18/2010 3:30:35 AM - System Checkpoint
RP785: 9/19/2010 3:32:35 AM - System Checkpoint
RP786: 9/20/2010 3:39:07 AM - System Checkpoint
RP787: 9/21/2010 1:57:02 AM - Software Distribution Service 3.0
RP788: 9/22/2010 3:23:27 AM - System Checkpoint
RP789: 9/23/2010 3:35:09 AM - System Checkpoint
RP790: 9/23/2010 2:30:41 PM - Installed Java™ 6 Update 21
RP791: 9/24/2010 1:56:41 AM - Software Distribution Service 3.0
RP792: 9/25/2010 3:53:19 AM - System Checkpoint
RP793: 9/26/2010 4:49:39 AM - System Checkpoint
RP794: 9/27/2010 5:21:04 AM - System Checkpoint
RP795: 9/28/2010 1:56:56 AM - Software Distribution Service 3.0
RP796: 9/29/2010 3:00:44 AM - Software Distribution Service 3.0
RP797: 9/30/2010 3:40:52 AM - System Checkpoint
RP798: 10/1/2010 1:57:08 AM - Software Distribution Service 3.0
RP799: 10/1/2010 10:21:51 PM - Software Distribution Service 3.0
RP800: 10/2/2010 11:17:03 PM - System Checkpoint
RP801: 10/4/2010 12:17:03 AM - System Checkpoint
RP802: 10/5/2010 1:17:03 AM - System Checkpoint
RP803: 10/5/2010 1:56:37 AM - Software Distribution Service 3.0
RP804: 10/6/2010 3:29:16 AM - System Checkpoint
RP805: 10/7/2010 4:17:04 AM - System Checkpoint
RP806: 10/8/2010 1:56:35 AM - Software Distribution Service 3.0
RP807: 10/8/2010 3:00:55 AM - Software Distribution Service 3.0
RP808: 10/8/2010 3:30:10 AM - Windows Defender Checkpoint
RP809: 10/9/2010 4:17:32 AM - System Checkpoint
RP810: 10/10/2010 5:13:42 AM - System Checkpoint
RP811: 10/11/2010 6:26:14 AM - System Checkpoint
RP812: 10/12/2010 1:50:42 AM - Software Distribution Service 3.0
RP813: 10/13/2010 3:31:15 AM - System Checkpoint
RP814: 10/14/2010 4:13:45 AM - System Checkpoint
RP815: 10/15/2010 1:50:53 AM - Software Distribution Service 3.0
RP816: 10/15/2010 3:00:48 AM - Software Distribution Service 3.0
RP817: 10/16/2010 3:44:05 AM - System Checkpoint
RP818: 10/17/2010 4:40:05 AM - System Checkpoint
RP819: 10/18/2010 5:40:05 AM - System Checkpoint
RP820: 10/19/2010 2:03:49 AM - Software Distribution Service 3.0
RP821: 10/20/2010 3:51:18 AM - System Checkpoint
RP822: 10/21/2010 4:40:08 AM - System Checkpoint
RP823: 10/22/2010 2:03:30 AM - Software Distribution Service 3.0
RP824: 10/23/2010 3:40:15 AM - System Checkpoint
RP825: 10/24/2010 3:52:16 AM - System Checkpoint
RP826: 10/25/2010 4:40:03 AM - System Checkpoint
RP827: 10/26/2010 2:03:48 AM - Software Distribution Service 3.0
RP828: 10/27/2010 3:50:24 AM - System Checkpoint
RP829: 10/28/2010 4:40:02 AM - System Checkpoint
RP830: 10/29/2010 2:03:42 AM - Software Distribution Service 3.0
RP831: 10/30/2010 3:17:01 AM - System Checkpoint
RP832: 10/31/2010 4:27:38 AM - System Checkpoint
RP833: 11/1/2010 4:40:01 AM - System Checkpoint
RP834: 11/2/2010 2:03:49 AM - Software Distribution Service 3.0
RP835: 11/2/2010 3:26:42 AM - Software Distribution Service 3.0
RP836: 11/2/2010 11:36:50 PM - Software Distribution Service 3.0
RP837: 11/3/2010 2:03:19 AM - Software Distribution Service 3.0
RP838: 11/3/2010 8:24:34 PM - Software Distribution Service 3.0
RP839: 11/4/2010 2:04:34 AM - Software Distribution Service 3.0
RP840: 11/4/2010 6:11:42 PM - Software Distribution Service 3.0
RP841: 11/5/2010 2:04:37 AM - Software Distribution Service 3.0
RP842: 11/5/2010 5:53:16 PM - Software Distribution Service 3.0
RP843: 11/6/2010 2:03:27 AM - Software Distribution Service 3.0
RP844: 11/7/2010 12:48:17 AM - Software Distribution Service 3.0
RP845: 11/8/2010 1:12:55 AM - System Checkpoint
RP846: 11/9/2010 1:39:53 AM - System Checkpoint
RP847: 11/9/2010 2:03:41 AM - Software Distribution Service 3.0
RP848: 11/9/2010 10:23:06 PM - Installed Java™ 6 Update 22
RP849: 11/10/2010 3:00:43 AM - Software Distribution Service 3.0
RP850: 11/11/2010 3:42:48 AM - System Checkpoint
RP851: 11/12/2010 1:47:19 AM - Software Distribution Service 3.0
RP852: 11/13/2010 2:50:54 AM - System Checkpoint
RP853: 11/13/2010 8:46:41 PM - Installed HiJackThis
RP854: 11/14/2010 12:00:12 AM - OTL Restore Point
==== Installed Programs ======================
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.2.5
Adobe Shockwave Player 11.5
AppCore
ArcSoft Panorama Maker 3
AT&T; Communication Manager
AT&T; Self Support Tool
AT&T; Service & Support Tool
Athlon 64 Processor Driver
AV
Avanquest update
Broadcom 440x 10/100 Integrated Controller
Broadcom Management Programs
ccCommon
CleanUp!
Conexant D850 56K V.9x DFVc Modem
CreativeProjects
CreativeProjectsTemplates
Critical Update for Windows Media Player 11 (KB959772)
CueTour
DeductionPro 2008
DeductionPro 2009
Dell ResourceCD
Destinations
Director
Driver Installer
Drivers Daily Log - LITE
Google Chrome
Google Earth
Google Talk (remove only)
Google Update Helper
H&R; Block Connecticut 2009
H&R; Block Premium + Efile + State 2009
High Definition Audio Driver Package - KB835221
HiJackThis
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB971276-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Deskjet 6800
HP Photo & Imaging 4.1
HP Product Detection
HP Software Update
HP Update
HPSystemDiagnostics
InstantShare
Internet Worm Protection
J2SE Runtime Environment 5.0 Update 3
Jalbum 8.0
Java Auto Updater
Java™ 6 Update 18
Java™ 6 Update 22
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Java™ SE Runtime Environment 6 Update 1
LiveUpdate 3.2 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Malwarebytes' Anti-Malware
Marine Data Center
Marine Data Center Tutorials
Media Library Management Wizard
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft MapPoint 2002 North America
Microsoft Money 2005
Microsoft National Language Support Downlevel APIs
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Motorola Driver Installation 3.4.0
Motorola Phone Tools
Movie Maker Background Music Files
Movie Maker Sound Effects
Movie Maker Title Images
Mozilla Firefox (3.6.12)
Mozilla Thunderbird (2.0.0.24)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB954459)
Nautilus IV
Nikon Message Center
Norton AntiVirus
Norton AntiVirus (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton AntiVirus SYMLT MSI
Norton Protection Center
Norton Security Scan
NVIDIA Drivers
OpenOffice.org 3.2
Overland
Panda ActiveScan 2.0
PC ScanAndSweep
Pdf995 (installed by H&R; Block)
PdfEdit995 (installed by H&R; Block)
Personal License Update Wizard for Windows Media Player
PhotoFantasy 2.0
PhotoGallery
PhotoWorks v2.41
Picasa 3
PictureProject
PictureProject In Touch Downloader 1.0
Platform
Plus! MP3 Audio Converter LE
PostgreSQL 8.2
Power Point Viewer
PowerISO
PrintScreen
QFolder
QuickProjects
QuickTime
Rand McNally TripMaker Deluxe 2000 SE
Samsung New PC Studio
SAMSUNG USB Driver for Mobile Phones
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
SEE-Bottom
SEE-Patterns
SEE-Structure
SEE-Temp FREE Version
SEE-Temp Plus
SEE-Tides
Segoe UI
SigmaTel Audio
SkinsHP1
Sonic Audio module
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
SPBBC 32bit
SUPERAntiSpyware Free Edition
Symantec
Symantec Real Time Storage Protection Component
SymNet
TaxCut Connecticut 2008
TaxCut Premium + State + Efile 2008
TaxCut Premium 2006
TrailSYM
TrayApp
Trend Micro RUBotted 2.0 Beta
U.S. Robotics 56K Faxmodem USB
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB972636)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VIA Platform Device Manager
View22
WebFldrs XP
WebReg
WIDCOMM Bluetooth Software
Windows Defender
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Media Bonus Pack for Windows XP
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Playlist Import to Excel Wizard
Windows Media Player Skin Importer
Windows Media Player Tray Control
Windows Search 4.0
Windows XP Service Pack 3
WinPcap 4.1.1
XML Paper Specification Shared Components Pack 1.0
XPS Essentials Pack
XPS Essentials Pack 1.0
Yahoo! Browser Services
Yahoo! Messenger
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
11/13/2010 7:40:11 PM, error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
11/11/2010 12:03:16 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
11/10/2010 10:54:41 PM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists.
11/10/2010 10:49:11 PM, error: Service Control Manager [7034] - The FsUsbExService service terminated unexpectedly. It has done this 1 time(s).
11/10/2010 10:48:57 PM, error: Service Control Manager [7034] - The Pml Driver HPZ12 service terminated unexpectedly. It has done this 1 time(s).
11/10/2010 10:48:45 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
11/10/2010 10:41:22 PM, error: Service Control Manager [7034] - The McciServiceHost service terminated unexpectedly. It has done this 1 time(s).
11/10/2010 10:24:46 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.
11/10/2010 10:24:46 PM, error: Service Control Manager [7000] - The LiveUpdate service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/10/2010 10:24:23 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service LiveUpdate with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}
==== End Of File ===========================