This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Anit Virus Keeps Turning Itself Off...

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi There I'm running XP Home Edition I got some great help from this site a few months ago to sort out a TDSS problem. But my PC has thrown a streesy once again so I thought I'd come back and ask the experts for some help. First of all, I'm not sure if this spyware, malware, a virus problem or none of the fore-mentioned, so Im sorry if this is in the wrong place but I wasn't sure where to post it. Ok, everything on the pc was fine until I started it yesterday morning. First thing I noticed was that it took about 10 mins to load up. When it did eventually load I noticed the background pic on the desktop had changed seemingly by itself overnight. I then decided to run a scan using McAfee but seen that it had been turned off. I immediately turned it back on but before I could run the scan it turned itself back off. I tried turning it on 5-6 times but each time again it turned itself off after about 5 secs. I opened Malwarebites to try and run it but it only scanned for about 3 mins and then frooze. Again I tied this about 2-3 times and each time it frooze. I tied to update McAfee but it was having none of it, telling me that my internet was not not connected (it was connected as I managed to update Malwarebites before trying it). Everything on the pc is going soooo slow it's unbelievable. I',m now using a really old laptop to write this. This morning when I turned the pc on, it decided it was going to do a CHDSK thing. I let this run through and the pc loaded up but again it took about 10 mins and again, I can't get McAfee to stay on and Malware just simply won't load as it keeps telling me a file is corrupt. Camn anyone help me out with this or give me some advice? Thanks
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)











  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hi Mowman, thanks for getting back to me. Here are the reports.

TDSS Killer

2011/07/18 17:55:23.0828 1780 TDSS rootkit removing tool 2.5.11.0 Jul 11 2011 16:56:56
2011/07/18 17:55:25.0687 1780 ================================================================================
2011/07/18 17:55:25.0687 1780 SystemInfo:
2011/07/18 17:55:25.0687 1780
2011/07/18 17:55:25.0687 1780 OS Version: 5.1.2600 ServicePack: 3.0
2011/07/18 17:55:25.0687 1780 Product type: Workstation
2011/07/18 17:55:25.0687 1780 ComputerName: SN037427820165
2011/07/18 17:55:25.0703 1780 UserName: Stevie
2011/07/18 17:55:25.0703 1780 Windows directory: C:\WINDOWS
2011/07/18 17:55:25.0703 1780 System windows directory: C:\WINDOWS
2011/07/18 17:55:25.0703 1780 Processor architecture: Intel x86
2011/07/18 17:55:25.0703 1780 Number of processors: 1
2011/07/18 17:55:25.0703 1780 Page size: 0x1000
2011/07/18 17:55:25.0703 1780 Boot type: Normal boot
2011/07/18 17:55:25.0703 1780 ================================================================================
2011/07/18 17:55:28.0828 1780 Initialize success
2011/07/18 17:55:35.0453 3968 ================================================================================
2011/07/18 17:55:35.0453 3968 Scan started
2011/07/18 17:55:35.0453 3968 Mode: Manual;
2011/07/18 17:55:35.0453 3968 ================================================================================
2011/07/18 17:55:37.0250 3968 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
2011/07/18 17:55:37.0765 3968 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/07/18 17:55:38.0078 3968 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/07/18 17:55:38.0437 3968 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
2011/07/18 17:55:38.0765 3968 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/07/18 17:55:39.0093 3968 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
2011/07/18 17:55:39.0375 3968 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2011/07/18 17:55:39.0750 3968 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
2011/07/18 17:55:40.0062 3968 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
2011/07/18 17:55:40.0328 3968 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
2011/07/18 17:55:40.0671 3968 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
2011/07/18 17:55:41.0046 3968 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
2011/07/18 17:55:41.0437 3968 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
2011/07/18 17:55:41.0765 3968 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
2011/07/18 17:55:42.0109 3968 AmdK7 (8fce268cdbdd83b23419d1f35f42c7b1) C:\WINDOWS\system32\DRIVERS\amdk7.sys
2011/07/18 17:55:42.0343 3968 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
2011/07/18 17:55:42.0953 3968 Asapi (875f9079cabee679d34b49e466b61701) C:\WINDOWS\system32\drivers\Asapi.sys
2011/07/18 17:55:43.0265 3968 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
2011/07/18 17:55:43.0578 3968 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
2011/07/18 17:55:43.0953 3968 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
2011/07/18 17:55:44.0375 3968 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/07/18 17:55:44.0750 3968 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/07/18 17:55:45.0390 3968 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/07/18 17:55:45.0812 3968 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/07/18 17:55:46.0203 3968 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/07/18 17:55:46.0921 3968 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
2011/07/18 17:55:47.0203 3968 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/07/18 17:55:47.0500 3968 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/07/18 17:55:47.0875 3968 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
2011/07/18 17:55:48.0265 3968 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/07/18 17:55:48.0562 3968 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/07/18 17:55:48.0937 3968 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/07/18 17:55:49.0296 3968 cfwids (7fd604cd7a7a0ff8975af61bdf64c577) C:\WINDOWS\system32\drivers\cfwids.sys
2011/07/18 17:55:49.0906 3968 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
2011/07/18 17:55:54.0468 3968 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
2011/07/18 17:55:54.0859 3968 dgderdrv (d0d4f3ca1d3a4400e1f40f36a800cd12) C:\WINDOWS\system32\drivers\dgderdrv.sys
2011/07/18 17:55:55.0281 3968 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/07/18 17:55:55.0671 3968 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/07/18 17:55:56.0140 3968 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/07/18 17:55:56.0343 3968 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/07/18 17:55:56.0640 3968 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/07/18 17:55:57.0078 3968 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
2011/07/18 17:55:57.0437 3968 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/07/18 17:55:57.0890 3968 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/07/18 17:55:58.0281 3968 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/07/18 17:55:58.0609 3968 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/07/18 17:55:58.0984 3968 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/07/18 17:55:59.0281 3968 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/07/18 17:55:59.0687 3968 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
2011/07/18 17:56:00.0078 3968 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\WINDOWS\system32\FsUsbExDisk.SYS
2011/07/18 17:56:00.0421 3968 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/07/18 17:56:00.0734 3968 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/07/18 17:56:01.0031 3968 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
2011/07/18 17:56:01.0281 3968 GEARAspiWDM (f2f431d1573ee632975c524418655b84) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
2011/07/18 17:56:01.0562 3968 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/07/18 17:56:02.0046 3968 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/07/18 17:56:02.0359 3968 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
2011/07/18 17:56:02.0781 3968 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2011/07/18 17:56:03.0078 3968 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2011/07/18 17:56:03.0375 3968 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2011/07/18 17:56:05.0562 3968 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
2011/07/18 17:56:05.0859 3968 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
2011/07/18 17:56:06.0140 3968 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/07/18 17:56:06.0437 3968 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/07/18 17:56:06.0765 3968 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
2011/07/18 17:56:07.0093 3968 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/07/18 17:56:07.0390 3968 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/07/18 17:56:07.0656 3968 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/07/18 17:56:07.0937 3968 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/07/18 17:56:08.0234 3968 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/07/18 17:56:08.0562 3968 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/07/18 17:56:08.0875 3968 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/07/18 17:56:09.0156 3968 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/07/18 17:56:09.0484 3968 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/07/18 17:56:09.0765 3968 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/07/18 17:56:10.0031 3968 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/07/18 17:56:11.0640 3968 mfeapfk (113445fc6a858ef453cded5b0a0df665) C:\WINDOWS\system32\drivers\mfeapfk.sys
2011/07/18 17:56:11.0875 3968 mfeavfk (dbf6e1b388d5c070d438c61adb990c30) C:\WINDOWS\system32\drivers\mfeavfk.sys
2011/07/18 17:56:12.0109 3968 mfebopk (a528b15e330edb83ea649be318d841d5) C:\WINDOWS\system32\drivers\mfebopk.sys
2011/07/18 17:56:12.0406 3968 mfefirek (c7da1b8003c89acedaa13768f7a1c622) C:\WINDOWS\system32\drivers\mfefirek.sys
2011/07/18 17:56:12.0687 3968 mfehidk (5e9679bb2fc4fa38ec8ca906c47acd46) C:\WINDOWS\system32\drivers\mfehidk.sys
2011/07/18 17:56:13.0046 3968 mfendisk (b1728195877b18ce63cf0cd00b2871eb) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
2011/07/18 17:56:13.0156 3968 mfendiskmp (b1728195877b18ce63cf0cd00b2871eb) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
2011/07/18 17:56:13.0437 3968 mferkdet (ce1711f7c3f72f6762abd241dcfd5ee1) C:\WINDOWS\system32\drivers\mferkdet.sys
2011/07/18 17:56:13.0796 3968 mfetdi2k (25e12c68b49a64ffc873603dfd578236) C:\WINDOWS\system32\drivers\mfetdi2k.sys
2011/07/18 17:56:14.0125 3968 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/07/18 17:56:14.0453 3968 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/07/18 17:56:14.0796 3968 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/07/18 17:56:15.0109 3968 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/07/18 17:56:15.0421 3968 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/07/18 17:56:15.0750 3968 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
2011/07/18 17:56:16.0015 3968 MpKslddea143f (5f53edfead46fa7adb78eee9ecce8fdf) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{76948591-040F-4ACF-AF2B-27DA0ABF384C}\MpKslddea143f.sys
2011/07/18 17:56:16.0312 3968 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
2011/07/18 17:56:17.0781 3968 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/07/18 17:56:20.0171 3968 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/07/18 17:56:20.0609 3968 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/07/18 17:56:22.0781 3968 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/07/18 17:56:23.0046 3968 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/07/18 17:56:23.0296 3968 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/07/18 17:56:23.0609 3968 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/07/18 17:56:23.0906 3968 ms_mpu401 (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys
2011/07/18 17:56:24.0125 3968 Mtlmnt5 (c53775780148884ac87c455489a0c070) C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys
2011/07/18 17:56:24.0421 3968 Mtlstrm (54886a652bf5685192141df304e923fd) C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys
2011/07/18 17:56:24.0765 3968 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
2011/07/18 17:56:25.0015 3968 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/07/18 17:56:25.0640 3968 NCHSSVAD (4e822077f3ef30e34147767bbae8acd4) C:\WINDOWS\system32\drivers\nchssvad.sys
2011/07/18 17:56:26.0109 3968 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/07/18 17:56:26.0484 3968 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/07/18 17:56:26.0921 3968 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/07/18 17:56:27.0343 3968 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/07/18 17:56:27.0890 3968 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/07/18 17:56:28.0421 3968 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/07/18 17:56:28.0843 3968 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/07/18 17:56:29.0281 3968 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/07/18 17:56:30.0000 3968 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/07/18 17:56:30.0640 3968 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/07/18 17:56:31.0203 3968 NtMtlFax (576b34ceae5b7e5d9fd2775e93b3db53) C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys
2011/07/18 17:56:31.0562 3968 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/07/18 17:56:32.0187 3968 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/07/18 17:56:32.0734 3968 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/07/18 17:56:33.0171 3968 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/07/18 17:56:33.0656 3968 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/07/18 17:56:34.0062 3968 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/07/18 17:56:34.0500 3968 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/07/18 17:56:34.0937 3968 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/07/18 17:56:35.0671 3968 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/07/18 17:56:36.0296 3968 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/07/18 17:56:42.0093 3968 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/07/18 17:56:44.0750 3968 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
2011/07/18 17:56:45.0046 3968 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/07/18 17:56:45.0484 3968 PSSDK42 (c8eb36910d3bd582891977e80925e21e) C:\WINDOWS\system32\Drivers\pssdk42.sys
2011/07/18 17:56:46.0000 3968 PSSDKLBF (0bec7b42f4093400509821c63f13f1d5) C:\WINDOWS\system32\Drivers\pssdklbf.sys
2011/07/18 17:56:46.0421 3968 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/07/18 17:56:46.0718 3968 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
2011/07/18 17:56:47.0250 3968 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
2011/07/18 17:56:47.0562 3968 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
2011/07/18 17:56:47.0984 3968 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
2011/07/18 17:56:48.0484 3968 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
2011/07/18 17:56:49.0000 3968 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
2011/07/18 17:56:49.0281 3968 RapportCerberus_26762 (7bf4f7e3ff7067b80b7d3d1e031bcb0e) C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\26762\RapportCerberus_26762.sys
2011/07/18 17:56:49.0500 3968 RapportEI (d299e4973da2dc9ded9066232e99e3d2) C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys
2011/07/18 17:56:49.0968 3968 RapportKELL (b4fedb7c55968ebe2bb9b8d7612eb2d5) C:\WINDOWS\system32\Drivers\RapportKELL.sys
2011/07/18 17:56:50.0406 3968 RapportPG (352cae4a3c3b6f6ccdaa246a0a6a61c6) C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys
2011/07/18 17:56:50.0921 3968 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/07/18 17:56:51.0281 3968 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/07/18 17:56:52.0406 3968 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/07/18 17:56:54.0953 3968 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/07/18 17:56:55.0359 3968 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/07/18 17:56:55.0656 3968 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/07/18 17:56:56.0078 3968 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/07/18 17:56:56.0515 3968 RecAgent (e9aaa0092d74a9d371659c4c38882e12) C:\WINDOWS\system32\DRIVERS\RecAgent.sys
2011/07/18 17:56:56.0984 3968 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/07/18 17:56:57.0515 3968 rtl8139 (d0ac0b0355a3ffb85eb77b083cd0627c) C:\WINDOWS\system32\DRIVERS\R8139n51.SYS
2011/07/18 17:56:57.0812 3968 s716bus (d7a84ef8f953a2d704580e4e73e00011) C:\WINDOWS\system32\DRIVERS\s716bus.sys
2011/07/18 17:56:58.0218 3968 s716mdfl (c5b509cdeeb733efafadc2d93bc77712) C:\WINDOWS\system32\DRIVERS\s716mdfl.sys
2011/07/18 17:56:58.0593 3968 s716mdm (dc3dec64860878540b374dc7d15d921f) C:\WINDOWS\system32\DRIVERS\s716mdm.sys
2011/07/18 17:56:58.0984 3968 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2011/07/18 17:56:59.0140 3968 SASENUM (7ce61c25c159f50f9eaf6d77fc83fa35) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
2011/07/18 17:56:59.0343 3968 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
2011/07/18 17:56:59.0859 3968 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/07/18 17:57:00.0421 3968 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/07/18 17:57:00.0750 3968 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/07/18 17:57:01.0203 3968 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/07/18 17:57:03.0890 3968 sisagp (61ca562def09a782d26b3e7edec5369a) C:\WINDOWS\system32\DRIVERS\SISAGPX.sys
2011/07/18 17:57:04.0265 3968 SiSkp (94a0e9f4a7b42899b793f5de6c362662) C:\WINDOWS\system32\DRIVERS\srvkp.sys
2011/07/18 17:57:04.0890 3968 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/07/18 17:57:07.0234 3968 SlNtHal (f9b8e30e82ee95cf3e1d3e495599b99c) C:\WINDOWS\system32\DRIVERS\Slnthal.sys
2011/07/18 17:57:07.0531 3968 SlWdmSup (db56bb2c55723815cf549d7fc50cfceb) C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys
2011/07/18 17:57:07.0859 3968 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
2011/07/18 17:57:08.0593 3968 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/07/18 17:57:09.0046 3968 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/07/18 17:57:09.0484 3968 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/07/18 17:57:09.0828 3968 sscebus (b2063ce662af3ab20045121a5b716df6) C:\WINDOWS\system32\DRIVERS\sscebus.sys
2011/07/18 17:57:12.0218 3968 sscemdm (cbf03ffc08f8db547bab2f79aa663d16) C:\WINDOWS\system32\DRIVERS\sscemdm.sys
2011/07/18 17:57:12.0625 3968 ssm_bus (9ece19a1a4f4896597c3bb840fbfa721) C:\WINDOWS\system32\DRIVERS\ssm_bus.sys
2011/07/18 17:57:13.0093 3968 ssm_mdfl (8e93a17a5253999a0e7c332f475699dc) C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys
2011/07/18 17:57:13.0500 3968 ssm_mdm (c0ba1357c63deacf3b3ccf4b989fef06) C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys
2011/07/18 17:57:13.0921 3968 ss_bbus (3f0164fbc0bd1adbd02df9759181451a) C:\WINDOWS\system32\DRIVERS\ss_bbus.sys
2011/07/18 17:57:14.0250 3968 ss_bmdfl (b89d62206034e5fe573c80a24dd55675) C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys
2011/07/18 17:57:14.0562 3968 ss_bmdm (1ed0fcea586fe2a416ee15196e5631dd) C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys
2011/07/18 17:57:14.0906 3968 ss_bserd (994d2e5378cc337ec7dd73c1e04fcaa4) C:\WINDOWS\system32\DRIVERS\ss_bserd.sys
2011/07/18 17:57:15.0312 3968 STAC97 (8e84dc1619b02e57e6f0514718c6343d) C:\WINDOWS\system32\drivers\STAC97.sys
2011/07/18 17:57:15.0656 3968 STAC97NA (0fbaff0e2f6977b19dd8f2ee11931f8b) C:\WINDOWS\system32\drivers\stac97na.sys
2011/07/18 17:57:16.0046 3968 STAC97NH (9709f9292e951f7ee8f73469b998b7ba) C:\WINDOWS\system32\drivers\stac97nh.sys
2011/07/18 17:57:16.0531 3968 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys
2011/07/18 17:57:16.0937 3968 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
2011/07/18 17:57:17.0359 3968 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/07/18 17:57:17.0843 3968 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/07/18 17:57:18.0234 3968 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/07/18 17:57:18.0671 3968 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
2011/07/18 17:57:19.0078 3968 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
2011/07/18 17:57:19.0421 3968 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
2011/07/18 17:57:19.0781 3968 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
2011/07/18 17:57:20.0125 3968 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/07/18 17:57:20.0562 3968 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/07/18 17:57:21.0031 3968 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/07/18 17:57:21.0343 3968 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/07/18 17:57:21.0750 3968 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/07/18 17:57:22.0312 3968 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
2011/07/18 17:57:22.0750 3968 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/07/18 17:57:23.0281 3968 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
2011/07/18 17:57:23.0609 3968 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/07/18 17:57:24.0281 3968 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/07/18 17:57:25.0078 3968 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/07/18 17:57:26.0125 3968 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/07/18 17:57:26.0453 3968 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/07/18 17:57:27.0156 3968 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
2011/07/18 17:57:27.0578 3968 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/07/18 17:57:27.0921 3968 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/07/18 17:57:28.0343 3968 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/07/18 17:57:28.0703 3968 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/07/18 17:57:29.0171 3968 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
2011/07/18 17:57:29.0578 3968 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2011/07/18 17:57:29.0906 3968 viamraid (1b7b0954af54e716f697c511d68c150e) C:\WINDOWS\system32\DRIVERS\viamraid.sys
2011/07/18 17:57:30.0250 3968 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/07/18 17:57:30.0765 3968 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/07/18 17:57:31.0625 3968 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/07/18 17:57:32.0343 3968 WpdUsb (c60dc16d4e406810fad54b98dc92d5ec) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2011/07/18 17:57:32.0625 3968 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/07/18 17:57:33.0000 3968 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/07/18 17:57:33.0328 3968 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/07/18 17:57:33.0625 3968 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/07/18 17:57:34.0031 3968 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
2011/07/18 17:57:34.0406 3968 Boot (0x1200) (8d1eea3132144bdb1f464a7bb1028ed1) \Device\Harddisk0\DR0\Partition0
2011/07/18 17:57:34.0468 3968 ================================================================================
2011/07/18 17:57:34.0468 3968 Scan finished
2011/07/18 17:57:34.0468 3968 ================================================================================
2011/07/18 17:57:34.0609 3460 Detected object count: 0
2011/07/18 17:57:34.0609 3460 Actual detected object count: 0




OTL:

OTL logfile created on: 18/07/2011 18:04:56 - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Stevie\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

959.48 Mb Total Physical Memory | 462.63 Mb Available Physical Memory | 48.22% Memory free
2.26 Gb Paging File | 1.70 Gb Available in Paging File | 75.11% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.28 Gb Total Space | 9.48 Gb Free Space | 27.65% Space Free | Partition Type: NTFS

Computer Name: SN037427820165 | User Name: Stevie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Stevie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Stevie\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\McAfee\SiteAdvisor\sahook.dll ()
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (PEVSystemStart) – File not found
SRV - (NetTcpPortSharing) – File not found
SRV - (idsvc) – File not found
SRV - (HidServ) – File not found
SRV - (FontCache3.0.0.0) – File not found
SRV - (AppMgmt) – File not found
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (MatSvc) – C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (dgdersvc) – C:\WINDOWS\system32\dgdersvc.exe (Devguru Co., Ltd.)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)


========== Driver Services (SafeList) ==========

DRV - (MpKslddea143f) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{76948591-040F-4ACF-AF2B-27DA0ABF384C}\MpKslddea143f.sys (Microsoft Corporation)
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportEI) – C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\WINDOWS\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (RapportCerberus_26762) – C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\26762\RapportCerberus_26762.sys (Trusteer Ltd.)
DRV - (MRxSmb) – C:\WINDOWS\System32\DRIVERS\mrxsmb.sys ()
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (PSSDKLBF) – C:\WINDOWS\system32\drivers\pssdklbf.sys (microOLAP Technologies LTD)
DRV - (PSSDK42) – C:\WINDOWS\system32\drivers\pssdk42.sys (microOLAP Technologies LTD)
DRV - (SiSkp) – C:\WINDOWS\system32\drivers\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (dgderdrv) – C:\WINDOWS\system32\drivers\dgderdrv.sys (Devguru Co., Ltd)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (ssm_mdm) – C:\WINDOWS\system32\drivers\ssm_mdm.sys (MCCI Corporation)
DRV - (ssm_bus) SAMSUNG Mobile USB Device II 1.0 driver (WDM) – C:\WINDOWS\system32\drivers\ssm_bus.sys (MCCI Corporation)
DRV - (ssm_mdfl) – C:\WINDOWS\system32\drivers\ssm_mdfl.sys (MCCI Corporation)
DRV - (HTTP) – C:\WINDOWS\System32\Drivers\HTTP.sys ()
DRV - (sscemdm) – C:\WINDOWS\system32\drivers\sscemdm.sys (MCCI Corporation)
DRV - (sscebus) SAMSUNG USB Composite Device V2 driver (WDM) – C:\WINDOWS\system32\drivers\sscebus.sys (MCCI Corporation)
DRV - (sscemdfl) – C:\WINDOWS\System32\DRIVERS\sscemdfl.sys ()
DRV - (ss_bmdm) – C:\WINDOWS\system32\drivers\ss_bmdm.sys (MCCI Corporation)
DRV - (ss_bserd) – C:\WINDOWS\system32\drivers\ss_bserd.sys (MCCI Corporation)
DRV - (ss_bbus) SAMSUNG USB Mobile Device (WDM) – C:\WINDOWS\system32\drivers\ss_bbus.sys (MCCI)
DRV - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) – C:\WINDOWS\system32\drivers\ss_bmdfl.sys (MCCI Corporation)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (NCHSSVAD) – C:\WINDOWS\system32\drivers\nchssvad.sys (NCH Swift Sound)
DRV - (s716mdm) – C:\WINDOWS\system32\drivers\s716mdm.sys (MCCI Corporation)
DRV - (s716mdfl) – C:\WINDOWS\system32\drivers\s716mdfl.sys (MCCI Corporation)
DRV - (s716bus) Sony Ericsson Device 716 driver (WDM) – C:\WINDOWS\system32\drivers\s716bus.sys (MCCI Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (PRISM_A02) – C:\WINDOWS\System32\DRIVERS\PRISMA02.sys ()
DRV - (SlWdmSup) – C:\WINDOWS\system32\drivers\slwdmsup.sys (Smart Link)
DRV - (SlNtHal) – C:\WINDOWS\system32\drivers\slnthal.sys (Smart Link)
DRV - (NtMtlFax) – C:\WINDOWS\system32\drivers\ntmtlfax.sys (Smart Link)
DRV - (RecAgent) – C:\WINDOWS\system32\DRIVERS\RecAgent.sys (Smart Link)
DRV - (Mtlstrm) – C:\WINDOWS\system32\drivers\mtlstrm.sys (Smart Link)
DRV - (Mtlmnt5) – C:\WINDOWS\system32\drivers\mtlmnt5.sys (Smart Link)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (SiS315) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys ()
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (Slntamr) – C:\WINDOWS\System32\DRIVERS\slntamr.sys ()
DRV - (STAC97NH) – C:\WINDOWS\system32\drivers\stac97nh.sys (SigmaTel Inc.)
DRV - (STAC97NA) – C:\WINDOWS\system32\drivers\stac97na.sys (SigmaTel Inc.)
DRV - (Raspti) – C:\WINDOWS\System32\DRIVERS\raspti.sys ()
DRV - (Asapi) – C:\WINDOWS\System32\drivers\asapi.sys (VOB Computersysteme GmbH)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation)
DRV - (perc2hib) – C:\WINDOWS\System32\DRIVERS\perc2hib.sys ()
DRV - (perc2) – C:\WINDOWS\System32\DRIVERS\perc2.sys ()
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (Cpqarray) – C:\WINDOWS\System32\DRIVERS\cpqarray.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = EC FA E1 E2 16 B6 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.7.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.102: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.103: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/06/30 19:13:23 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/06/30 19:13:23 | 000,000,000 | —D | M]

[2011/06/22 22:41:11 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Stevie\Application Data\Mozilla\Extensions
[2008/05/04 12:57:37 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Stevie\Application Data\Mozilla\Extensions\[removed]
[2011/04/15 18:45:34 | 000,000,000 | —D | M] (Map status indicator) – C:\PROGRAM FILES\TOMTOM HOME 2\XUL\EXTENSIONS\[removed]
[2011/04/14 14:01:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\mozilla firefox\components\Scriptff.dll

O1 HOSTS File: ([2011/06/24 00:18:01 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110622211955.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download All By FlashGet3 - C:\Documents and Settings\Stevie\Application Data\FlashGetBHO\GetAllUrl.htm ()
O8 - Extra context menu item: Download By FlashGet3 - C:\Documents and Settings\Stevie\Application Data\FlashGetBHO\GetUrl.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Stevie\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll (Google Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: bitsoup.org ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: motive.com ([pbttbc.bt] https in Trusted sites)
O16 - DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} http://assets.photobox.com/assets/aurigma/…?20110428084740 (PhotoboxPhotowaysUploader5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1214166787500 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.orderingmemory.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Stevie\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Stevie\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/07/18 17:54:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Stevie\Desktop\tdsskiller
[2011/07/18 17:53:56 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Stevie\Desktop\OTL.exe
[2011/07/18 17:35:46 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/07/18 17:32:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/07/17 20:17:16 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/07/17 19:40:57 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/07/17 19:38:54 | 008,068,864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Stevie\Desktop\mseinstall.exe
[2011/07/17 19:17:57 | 000,450,352 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Stevie\Desktop\FixitCenter_Run.exe
[2011/07/17 17:17:27 | 000,005,632 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\InstFunc.dll
[2011/07/17 17:02:56 | 001,039,128 | —- | C] (PC Drivers HeadQuarters ) – C:\Documents and Settings\Stevie\Desktop\DriverInstaller_DT.exe
[2011/07/17 16:36:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Stevie\Local Settings\Application Data\PCHealth
[2011/07/16 23:03:09 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/07/16 23:03:09 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/07/16 23:03:09 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/07/16 23:03:09 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/07/16 23:02:10 | 000,000,000 | –SD | C] – C:\ComboFix
[2011/07/16 23:02:01 | 000,000,000 | —D | C] – C:\Qoobox
[2011/07/16 22:42:20 | 004,154,328 | R— | C] (Swearware) – C:\Documents and Settings\Stevie\Desktop\ComboFix.exe
[2011/07/07 22:16:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Supreme
[2011/07/07 22:16:38 | 000,000,000 | —D | C] – C:\Program Files\Supreme Auction
[2011/06/30 19:14:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2011/06/30 19:14:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Coupons
[2011/06/30 19:14:21 | 000,000,000 | —D | C] – C:\WINDOWS\Cache
[2011/06/30 19:14:19 | 000,000,000 | —D | C] – C:\Program Files\Coupons
[2011/06/30 19:14:10 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2011/06/30 19:14:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP Photo Creations
[2011/06/30 19:13:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Stevie\Application Data\HpUpdate
[2011/06/30 19:12:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2011/06/30 19:10:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\HP
[2011/06/30 19:08:06 | 000,589,824 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpost_d02d.dll
[2011/06/30 19:08:05 | 000,713,728 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\hposwia_d02d.dll
[2011/06/30 19:08:05 | 000,372,736 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\hppldcoi.dll
[2011/06/30 19:08:05 | 000,315,392 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hposc_d02a.dll
[2011/06/30 19:08:05 | 000,309,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\difxapi.dll
[2011/06/26 13:12:24 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/06/26 13:12:23 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/06/26 13:12:23 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/06/26 13:12:23 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/06/25 12:01:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/25 12:01:56 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/06/25 12:01:50 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/06/25 12:01:50 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/06/25 11:58:29 | 009,435,312 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Stevie\Desktop\mbam-setup-1.51.0.1200.exe
[2011/06/25 00:54:47 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/24 17:16:32 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/06/24 16:59:35 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/06/24 16:57:05 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Stevie\Desktop\ATF-Cleaner.exe
[2011/06/23 23:34:56 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/06/23 21:59:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Security Scan Plus
[2011/06/22 22:12:10 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Stevie\Desktop\HiJackThis.exe
[2011/06/22 21:05:26 | 000,000,000 | —D | C] – C:\Program Files\NOS
[2011/06/22 21:05:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2011/06/22 21:04:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS(7)
[2011/06/22 21:03:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS(6)
[2011/06/22 21:02:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS(5)
[2011/06/22 21:02:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS(4)
[2011/06/22 21:02:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS(3)
[2011/06/22 21:02:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/06/22 20:19:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS(2)
[2011/06/22 18:01:26 | 000,053,816 | —- | C] (Trusteer Ltd.) – C:\WINDOWS\System32\drivers\RapportKELL.sys
[2011/06/22 00:16:23 | 000,000,000 | –SD | C] – C:\Documents and Settings\Stevie\My Documents\My Data Sources
[2011/06/19 18:29:36 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\McAfee
[2008/06/07 12:21:56 | 001,570,816 | —- | C] (Toshiba Samsung Storage Technology Coporation) – C:\Documents and Settings\Stevie\Application Data\tsdnwin.dll
[2004/07/15 10:51:07 | 000,014,976 | —- | C] ( ) – C:\WINDOWS\System32\drivers\winddx.sys
[5 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/18 18:05:33 | 000,000,390 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2011/07/18 18:04:00 | 000,000,580 | -H– | M] () – C:\WINDOWS\tasks\DataUpload.job
[2011/07/18 17:54:04 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Stevie\Desktop\OTL.exe
[2011/07/18 17:52:58 | 001,383,430 | —- | M] () – C:\Documents and Settings\Stevie\Desktop\tdsskiller.zip
[2011/07/18 17:35:37 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/07/18 17:23:29 | 000,000,616 | -H– | M] () – C:\WINDOWS\tasks\ConfigExec.job
[2011/07/18 17:20:55 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/17 19:40:46 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/17 19:38:54 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Stevie\Desktop\mseinstall.exe
[2011/07/17 19:17:57 | 000,450,352 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Stevie\Desktop\FixitCenter_Run.exe
[2011/07/17 17:02:57 | 001,039,128 | —- | M] (PC Drivers HeadQuarters ) – C:\Documents and Settings\Stevie\Desktop\DriverInstaller_DT.exe
[2011/07/17 14:48:04 | 000,102,258 | —- | M] () – C:\WINDOWS\System32\VGAunistlog.ini
[2011/07/17 12:48:05 | 000,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/07/16 22:42:31 | 004,154,328 | R— | M] (Swearware) – C:\Documents and Settings\Stevie\Desktop\ComboFix.exe
[2011/07/16 22:12:11 | 000,000,787 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/13 07:18:13 | 000,318,744 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/13 00:51:17 | 049,089,992 | —- | M] () – C:\WINDOWS\System32\MRT.exe
[2011/07/13 00:50:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/07/11 17:19:26 | 000,000,532 | —- | M] () – C:\Documents and Settings\Stevie\My Documents\spider.sav
[2011/07/07 22:16:40 | 000,001,683 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Supreme Auction.lnk
[2011/07/07 22:16:40 | 000,001,433 | —- | M] () – C:\Documents and Settings\All Users\Desktop\eBay US.lnk
[2011/07/06 19:52:42 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/07/02 09:55:49 | 000,001,122 | —- | M] () – C:\Documents and Settings\Stevie\Desktop\Shortcut to EXCEL.lnk
[2011/07/02 09:48:30 | 000,000,795 | —- | M] () – C:\Documents and Settings\Stevie\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/07/02 09:48:05 | 000,466,550 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/02 09:48:05 | 000,081,590 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/06/30 19:39:10 | 000,045,093 | —- | M] () – C:\Documents and Settings\Stevie\Desktop\HP Installation Error - XP.hta
[2011/06/30 19:14:11 | 000,000,775 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HP Photo Creations.lnk
[2011/06/30 19:13:39 | 000,205,957 | —- | M] () – C:\WINDOWS\hpoins46.dat
[2011/06/30 19:13:03 | 000,000,889 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Shop for HP Supplies.lnk
[2011/06/30 19:12:01 | 000,001,021 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HP Solution Center.lnk
[2011/06/30 19:10:50 | 000,001,811 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2011/06/30 00:11:17 | 161,275,864 | —- | M] () – C:\Documents and Settings\Stevie\Desktop\DJ_AIO_06_F4500_USW_Full_Win_enu_140_175.exe
[2011/06/26 13:11:57 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/06/26 13:11:57 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/06/26 13:11:56 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/06/26 13:11:56 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/06/26 13:11:55 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/06/26 07:45:56 | 000,256,000 | —- | M] () – C:\WINDOWS\PEV.exe
[2011/06/25 11:58:29 | 009,435,312 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Stevie\Desktop\mbam-setup-1.51.0.1200.exe
[2011/06/25 00:54:47 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/24 16:57:06 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Stevie\Desktop\ATF-Cleaner.exe
[2011/06/24 00:18:01 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/06/23 23:35:06 | 000,000,327 | RHS- | M] () – C:\BOOT.INI
[2011/06/23 21:59:29 | 000,001,619 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2011/06/23 21:59:29 | 000,001,611 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/06/23 19:04:41 | 000,139,264 | —- | M] () – C:\Documents and Settings\Stevie\Desktop\RKUnhookerLE.EXE
[2011/06/22 22:12:16 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Stevie\Desktop\HiJackThis.exe
[2011/06/22 18:01:26 | 000,053,816 | —- | M] (Trusteer Ltd.) – C:\WINDOWS\System32\drivers\RapportKELL.sys
[5 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/18 17:52:53 | 001,383,430 | —- | C] () – C:\Documents and Settings\Stevie\Desktop\tdsskiller.zip
[2011/07/18 17:29:48 | 000,000,390 | -H– | C] () – C:\WINDOWS\tasks\MpIdleTask.job
[2011/07/17 19:50:49 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/07/17 19:43:52 | 000,001,683 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/07/17 12:48:05 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/07/16 23:03:09 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/07/16 23:03:09 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/07/16 23:03:09 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/07/16 23:03:09 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/07/16 23:03:09 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/07/11 17:19:26 | 000,000,532 | —- | C] () – C:\Documents and Settings\Stevie\My Documents\spider.sav
[2011/07/07 22:16:40 | 000,001,683 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Supreme Auction.lnk
[2011/07/07 22:16:40 | 000,001,433 | —- | C] () – C:\Documents and Settings\All Users\Desktop\eBay US.lnk
[2011/07/02 09:55:49 | 000,001,122 | —- | C] () – C:\Documents and Settings\Stevie\Desktop\Shortcut to EXCEL.lnk
[2011/06/30 19:39:10 | 000,045,093 | —- | C] () – C:\Documents and Settings\Stevie\Desktop\HP Installation Error - XP.hta
[2011/06/30 19:14:11 | 000,000,775 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Photo Creations.lnk
[2011/06/30 19:13:03 | 000,000,889 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Shop for HP Supplies.lnk
[2011/06/30 19:12:01 | 000,001,021 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Solution Center.lnk
[2011/06/30 19:10:50 | 000,001,811 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2011/06/30 19:03:14 | 000,205,957 | —- | C] () – C:\WINDOWS\hpoins46.dat
[2011/06/30 19:03:14 | 000,000,532 | —- | C] () – C:\WINDOWS\hpomdl46.dat
[2011/06/30 00:10:50 | 161,275,864 | —- | C] () – C:\Documents and Settings\Stevie\Desktop\DJ_AIO_06_F4500_USW_Full_Win_enu_140_175.exe
[2011/06/25 12:01:57 | 000,000,787 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/23 19:04:31 | 000,139,264 | —- | C] () – C:\Documents and Settings\Stevie\Desktop\RKUnhookerLE.EXE
[2011/05/27 18:20:32 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/05/27 00:16:57 | 001,136,664 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/09/29 17:21:35 | 000,040,960 | —- | C] () – C:\WINDOWS\Sublock.dll
[2010/09/29 17:21:34 | 000,258,048 | —- | C] () – C:\WINDOWS\esn.dll
[2010/09/29 17:21:34 | 000,221,291 | —- | C] () – C:\WINDOWS\Imei_dll.dll
[2010/08/15 15:33:38 | 000,014,848 | —- | C] () – C:\WINDOWS\System32\drivers\sscemdfl.sys
[2010/08/15 15:33:38 | 000,012,416 | —- | C] () – C:\WINDOWS\System32\drivers\sscecmnt.sys
[2010/07/17 11:57:55 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/07/17 11:57:55 | 000,036,640 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/07/17 11:57:23 | 000,002,528 | -H– | C] () – C:\Documents and Settings\Stevie\Application Data\$_hpcst$.hpc
[2010/07/09 21:52:23 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2010/05/08 14:28:22 | 000,000,606 | —- | C] () – C:\WINDOWS\hpomdl46.dat.temp
[2010/04/16 18:35:51 | 000,000,034 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/04/15 18:33:40 | 000,023,113 | —- | C] () – C:\WINDOWS\hpqins15.dat
[2009/11/14 17:31:52 | 000,069,504 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/09 03:08:10 | 000,974,848 | —- | C] () – C:\WINDOWS\System32\cis-2.4.dll
[2009/11/09 03:08:10 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2009/11/09 03:08:10 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2009/11/09 03:08:10 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\issacapi_se-2.3.dll
[2009/10/20 20:02:11 | 000,000,025 | —- | C] () – C:\WINDOWS\libem.INI
[2009/10/20 19:59:53 | 000,000,248 | —- | C] () – C:\WINDOWS\System32\secustat.dat
[2009/10/06 08:16:00 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/08/28 22:21:02 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2009/08/16 15:57:30 | 005,419,576 | —- | C] () – C:\Program Files\SopCast-3.2.4.zip
[2009/08/06 13:02:40 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\libcurl.dll
[2009/08/06 13:02:22 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\libexpatw.dll
[2009/06/26 21:52:38 | 000,000,048 | —- | C] () – C:\WINDOWS\cgminivw.ini
[2009/06/26 21:52:06 | 000,000,036 | —- | C] () – C:\WINDOWS\Tiny_Run.ini
[2009/03/23 15:08:29 | 000,000,145 | —- | C] () – C:\WINDOWS\System32\EBPPORT.DAT
[2009/02/18 19:03:46 | 000,000,020 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2009/01/23 23:28:06 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2009/01/23 23:20:59 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2008/11/13 19:20:56 | 000,000,039 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/08/15 21:28:24 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2008/07/13 02:54:06 | 000,000,599 | —- | C] () – C:\WINDOWS\videoimp.ini
[2008/06/22 20:23:55 | 000,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2008/05/13 17:46:23 | 000,000,087 | —- | C] () – C:\WINDOWS\ka.ini
[2008/04/24 14:27:10 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2008/04/18 15:30:03 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2008/04/14 23:58:10 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/02/23 16:49:28 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/02/17 23:59:45 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\msir3jp.dll
[2007/10/29 19:23:52 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/10/23 23:14:40 | 000,032,768 | —- | C] () – C:\Documents and Settings\Stevie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/09 17:52:54 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\instlsp.exe
[2007/10/05 23:40:06 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2007/10/05 22:14:34 | 049,089,992 | —- | C] () – C:\WINDOWS\System32\MRT.exe
[2007/10/05 22:14:04 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2005/09/21 17:38:10 | 000,000,677 | —- | C] () – C:\Program Files\lxce.vbs
[2005/02/01 13:27:00 | 000,348,640 | —- | C] () – C:\WINDOWS\System32\drivers\PRISMA02.sys
[2004/08/11 01:45:04 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\wdfmgr.exe
[2004/08/04 07:00:13 | 000,265,728 | —- | C] () – C:\WINDOWS\System32\drivers\http.sys
[2004/07/15 11:25:00 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/07/15 11:09:17 | 000,006,451 | —- | C] () – C:\WINDOWS\HDReg.ini
[2004/07/15 11:07:16 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/07/15 10:58:43 | 000,227,328 | —- | C] () – C:\WINDOWS\System32\wmerror.dll
[2004/07/15 10:58:05 | 000,005,007 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/07/15 10:55:44 | 000,115,383 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2004/07/15 10:55:37 | 000,102,258 | —- | C] () – C:\WINDOWS\System32\VGAunistlog.ini
[2004/07/15 10:55:28 | 000,210,176 | —- | C] () – C:\WINDOWS\System32\drivers\sisgrp.sys
[2004/07/15 10:55:28 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\sis760.bin
[2004/07/15 10:55:28 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\sis741.bin
[2004/07/15 10:55:28 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\sis660.bin
[2004/07/15 10:53:13 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/07/15 10:51:07 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\SLLights.dll
[2004/07/15 10:51:07 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\slmh.exe
[2004/07/15 10:51:07 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\minirec.exe
[2004/07/15 10:51:07 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\amr_cpl.dll
[2004/07/15 10:51:07 | 000,061,440 | —- | C] () – C:\WINDOWS\SmCfg.exe
[2004/07/02 15:33:00 | 000,454,742 | —- | C] () – C:\WINDOWS\System32\PRISMNDI.dll
[2004/03/31 22:01:24 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/09/20 09:22:44 | 000,179,584 | —- | C] () – C:\WINDOWS\System32\drivers\dac2w2k.sys
[2002/09/20 09:21:03 | 000,005,504 | —- | C] () – C:\WINDOWS\System32\drivers\perc2hib.sys
[2002/09/20 09:21:02 | 000,027,296 | —- | C] () – C:\WINDOWS\System32\drivers\perc2.sys
[2002/09/20 09:20:40 | 000,014,976 | —- | C] () – C:\WINDOWS\System32\drivers\cpqarray.sys
[2002/09/19 21:20:55 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2002/09/19 20:52:36 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2002/09/19 20:46:13 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2002/09/19 20:37:45 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2002/09/19 20:36:49 | 000,318,744 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2002/09/19 20:26:38 | 000,034,432 | —- | C] () – C:\WINDOWS\System32\drivers\rawwan.sys
[2002/09/19 20:26:38 | 000,016,512 | —- | C] () – C:\WINDOWS\System32\drivers\raspti.sys
[2002/09/19 20:26:36 | 000,466,550 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2002/09/19 20:26:36 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2002/09/19 20:26:36 | 000,081,590 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2002/09/19 20:26:36 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2002/09/19 20:26:31 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/09/19 20:26:30 | 000,108,464 | —- | C] () – C:\WINDOWS\System32\netapi.dll
[2002/09/19 20:26:28 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\msvidc32.dll
[2002/09/19 20:26:25 | 000,456,320 | —- | C] () – C:\WINDOWS\System32\drivers\mrxsmb.sys
[2002/09/19 20:26:24 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2002/09/19 20:26:24 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2002/09/19 20:26:15 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2002/09/19 20:26:07 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/09/05 15:00:38 | 000,004,481 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/09/05 15:00:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2001/08/17 13:24:46 | 000,012,032 | —- | C] () – C:\WINDOWS\System32\drivers\riodrv.sys
[2001/08/17 13:24:46 | 000,012,032 | —- | C] () – C:\WINDOWS\System32\drivers\rio8drv.sys
[2001/08/17 13:24:38 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\drivers\cpqdap01.sys
[2001/08/07 04:16:34 | 000,045,056 | —- | C] () – C:\WINDOWS\OTS_UI.EXE
[1999/01/22 19:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1980/01/01 00:00:00 | 000,516,616 | —- | C] () – C:\WINDOWS\System32\drivers\slntamr.sys
[1980/01/01 00:00:00 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\coinst.dll
[1980/01/01 00:00:00 | 000,024,576 | —- | C] () – C:\WINDOWS\slrundll.exe

========== LOP Check ==========

[2009/10/01 20:35:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2011/04/03 10:50:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2010/07/28 23:52:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/03/15 22:47:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Caphyon
[2008/08/17 20:14:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2011/03/15 22:48:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ConeXware
[2009/02/21 00:47:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2010/05/09 13:01:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoBit Games
[2008/04/14 23:49:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2009/02/14 21:46:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2010/08/20 22:36:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/07/22 13:28:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/02/12 00:25:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2009/02/18 19:03:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2009/11/11 11:02:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PPLiveVA
[2007/10/07 14:39:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Prism
[2010/08/28 23:06:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2009/02/16 12:32:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2009/11/11 11:01:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Storm
[2011/04/03 10:56:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SugarGames
[2011/04/03 11:27:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/03/29 21:36:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2010/11/05 10:08:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trusteer
[2007/10/06 04:19:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/10/29 07:16:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VirtualizedApplications
[2009/07/17 18:12:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivitar
[2009/07/17 18:12:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivitar Experience Image Manager
[2009/06/14 21:31:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/05/09 13:01:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zylom
[2009/03/26 21:37:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/04 12:41:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/01 20:18:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/08 12:03:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/02/13 17:37:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\Alawar
[2010/12/16 04:15:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\Azureus
[2009/11/11 11:00:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\BITS
[2011/03/21 19:40:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\DVDVideoSoftIEHelpers
[2011/05/25 21:45:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\ElevatedDiagnostics
[2009/10/20 20:00:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\FlashGet
[2009/10/20 20:00:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\FlashGetBHO
[2009/11/09 22:11:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\FlashgetSetup
[2009/02/16 12:29:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\GameHouse
[2010/07/09 21:52:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\GamesCafe
[2010/09/03 16:32:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\LG Electronics
[2008/11/14 01:13:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\LimeWire
[2009/10/21 17:04:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\MxBoost
[2010/12/23 19:34:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\NCH Swift Sound
[2010/07/22 13:28:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\PC Suite
[2009/10/20 20:02:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\PPLiveVA
[2009/11/11 11:03:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\PPStream
[2010/08/15 15:28:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\Samsung
[2010/11/06 18:34:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\SoftGrid Client
[2010/07/28 17:42:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\Sony
[2010/07/28 17:29:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\Sony Setup
[2008/08/20 20:18:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\Teleca
[2007/10/12 19:45:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\Template
[2007/12/25 22:44:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\TomTom
[2010/10/10 12:06:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\TP
[2010/11/05 10:09:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\Trusteer
[2008/02/08 18:42:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\Uniblue
[2009/09/25 20:31:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\Xbins
[2009/04/16 09:03:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Stevie\Application Data\Zylom
[2011/07/18 17:23:29 | 000,000,616 | -H– | M] () – C:\WINDOWS\Tasks\ConfigExec.job
[2011/07/18 18:04:00 | 000,000,580 | -H– | M] () – C:\WINDOWS\Tasks\DataUpload.job
[2011/07/18 17:35:37 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/07/18 18:05:33 | 000,000,390 | -H– | M] () – C:\WINDOWS\Tasks\MpIdleTask.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/08/15 15:28:07 | 000,002,006 | —- | M] () – C:\aqua_bitmap.cpp
[2010/07/10 16:27:28 | 000,000,281 | —- | M] () – C:\Boot.bak
[2011/06/23 23:35:06 | 000,000,327 | RHS- | M] () – C:\BOOT.INI
[2002/08/29 13:00:00 | 000,245,920 | RHS- | M] () – C:\cmldr
[2009/02/03 16:32:57 | 000,000,074 | —- | M] () – C:\CMLoader.log
[2004/07/15 10:49:16 | 000,006,238 | —- | M] () – C:\DWNLOG.TXT
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2000/03/09 09:06:00 | 000,028,680 | —- | M] () – C:\FLIPART.EXE
[2002/10/16 09:52:00 | 000,000,890 | —- | M] () – C:\GETBOOTD.BAT
[2002/08/29 15:03:06 | 000,006,384 | —- | M] () – C:\GETDRIVE.EXE
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2009/02/18 17:57:25 | 000,230,424 | —- | M] () – C:\img2-001.raw
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2004/07/15 11:05:47 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2004/07/15 11:08:56 | 000,000,870 | -H– | M] () – C:\IPH.PH
[2009/09/28 06:56:15 | 000,006,575 | —- | M] () – C:\lxce.log
[2007/10/12 17:34:46 | 000,000,275 | —- | M] () – C:\lxcefire.000
[2009/02/04 18:33:08 | 000,000,275 | —- | M] () – C:\lxcefire.001
[2009/02/04 19:01:37 | 000,000,275 | —- | M] () – C:\lxcefire.002
[2009/02/04 19:06:07 | 000,000,275 | —- | M] () – C:\lxcefire.csv
[2007/10/12 17:35:28 | 000,000,867 | —- | M] () – C:\lxceinst.000
[2009/02/04 18:41:11 | 000,001,123 | —- | M] () – C:\lxceinst.001
[2009/02/04 19:03:25 | 000,001,124 | —- | M] () – C:\lxceinst.002
[2009/02/04 19:07:10 | 000,001,124 | —- | M] () – C:\lxceinst.csv
[2010/03/15 17:25:24 | 000,159,448 | —- | M] () – C:\lxcescan.log
[2009/02/03 16:54:43 | 000,298,856 | —- | M] () – C:\lxceUNST.000
[2009/02/03 16:55:08 | 000,298,856 | —- | M] () – C:\lxceUNST.001
[2009/02/03 16:56:45 | 000,600,108 | —- | M] () – C:\lxceUNST.002
[2010/03/15 17:27:03 | 000,617,062 | —- | M] () – C:\lxceUNST.csv
[2010/06/30 19:42:16 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2004/07/15 11:05:47 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/10/05 23:48:30 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/15 01:02:21 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/18 17:20:45 | 1509,138,432 | -HS- | M] () – C:\pagefile.sys
[2009/06/06 00:13:56 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/06/06 00:21:54 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/06/06 10:24:27 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/06/06 16:42:05 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/06/07 02:37:09 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/06/07 03:04:24 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/06/25 17:23:26 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/06/25 17:34:16 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/06/26 00:11:13 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/06/26 01:03:06 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/06/26 01:09:30 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/06/26 11:28:02 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/06/26 13:07:04 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/06/26 15:26:26 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/06/26 16:33:19 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/06/07 17:23:47 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/06/07 23:55:28 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/06/08 09:07:22 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/06/08 14:01:34 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/06/05 22:41:38 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/06/06 00:13:56 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/06/06 00:21:54 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/06/06 10:24:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/06/06 16:42:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/06/07 02:37:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/06/07 03:04:24 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/06/25 17:23:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/06/25 17:34:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/06/26 00:11:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/06/26 01:03:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/06/26 01:09:30 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/06/26 11:28:02 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/06/26 13:07:04 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/06/26 15:26:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/06/26 16:33:18 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/06/07 17:23:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/06/07 23:55:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/06/08 09:07:22 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/06/08 14:01:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/06/05 22:41:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2011/07/18 17:58:29 | 000,058,462 | —- | M] () – C:\TDSSKiller.2.5.11.0_18.07.2011_17.55.23_log.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2002/09/19 20:48:26 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/04/16 13:42:24 | 000,315,904 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp70w.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >
[2003/04/22 17:50:46 | 000,095,540 | —- | M] () – C:\WINDOWS\DESK01.JPG
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2003/12/01 10:36:56 | 000,471,040 | —- | M] (ScreenTime Media) – C:\WINDOWS\PackardBell2003.scr
[2010/04/17 01:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2005/09/21 17:38:10 | 000,000,677 | —- | M] () – C:\Program Files\lxce.vbs
[2009/08/16 15:57:45 | 005,419,576 | —- | M] () – C:\Program Files\SopCast-3.2.4.zip

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2002/09/19 20:36:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2002/09/19 20:36:08 | 000,602,112 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2002/09/19 20:36:06 | 000,380,928 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/15 01:33:08 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/10/06 00:45:36 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Stevie\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/06/24 16:57:06 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Stevie\Desktop\ATF-Cleaner.exe
[2011/07/16 22:42:31 | 004,154,328 | R— | M] (Swearware) – C:\Documents and Settings\Stevie\Desktop\ComboFix.exe
[2011/06/30 00:11:17 | 161,275,864 | —- | M] () – C:\Documents and Settings\Stevie\Desktop\DJ_AIO_06_F4500_USW_Full_Win_enu_140_175.exe
[2011/07/17 17:02:57 | 001,039,128 | —- | M] (PC Drivers HeadQuarters ) – C:\Documents and Settings\Stevie\Desktop\DriverInstaller_DT.exe
[2011/07/17 19:17:57 | 000,450,352 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Stevie\Desktop\FixitCenter_Run.exe
[2011/06/22 22:12:16 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Stevie\Desktop\HiJackThis.exe
[2011/06/25 11:58:29 | 009,435,312 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Stevie\Desktop\mbam-setup-1.51.0.1200.exe
[2011/07/17 19:38:54 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Stevie\Desktop\mseinstall.exe
[2011/07/18 17:54:04 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Stevie\Desktop\OTL.exe
[2011/06/23 19:04:41 | 000,139,264 | —- | M] () – C:\Documents and Settings\Stevie\Desktop\RKUnhookerLE.EXE

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2010/10/20 23:23:26 | 000,000,698 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb
[2010/11/16 00:00:08 | 000,000,786 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >
[2009/05/19 21:47:06 | 000,654,920 | —- | M] () – C:\Documents and Settings\Stevie\My Documents\mtinst.exe

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2007/10/06 00:45:36 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Stevie\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/07/02 00:29:32 | 000,000,067 | -HS- | M] () – C:\Documents and Settings\Stevie\Cookies\desktop.ini
[2011/07/18 18:02:18 | 000,425,984 | -HS- | M] () – C:\Documents and Settings\Stevie\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-07-17 22:23:56

========== Alternate Data Streams ==========

@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:014BC3B4
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E1F04E8D
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C46995DA
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2CFBE2D1
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F085C8A1

< End of report >


OTL Extras:

OTL Extras logfile created on: 18/07/2011 18:04:56 - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Stevie\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

959.48 Mb Total Physical Memory | 462.63 Mb Available Physical Memory | 48.22% Memory free
2.26 Gb Paging File | 1.70 Gb Available in Paging File | 75.11% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.28 Gb Total Space | 9.48 Gb Free Space | 27.65% Space Free | Partition Type: NTFS

Computer Name: SN037427820165 | User Name: Stevie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OtsMedia.Surf] – Reg Error: Value error.
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"427:TCP" = 427:TCP:LocalSubNet:Enabled:SLP_Port(427)_TCP
"427:UDP" = 427:UDP:LocalSubNet:Enabled:SLP_Port(427)_UDP

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3659:UDP" = 3659:UDP:*:Enabled:PS3
"6000:UDP" = 6000:UDP:*:Enabled:ps3
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"135:TCP" = 135:TCP:*:Enabled:TCP Port 135
"5000:TCP" = 5000:TCP:*:Enabled:TCP Port 5000
"5001:TCP" = 5001:TCP:*:Enabled:TCP Port 5001
"5002:TCP" = 5002:TCP:*:Enabled:TCP Port 5002
"5003:TCP" = 5003:TCP:*:Enabled:TCP Port 5003
"5004:TCP" = 5004:TCP:*:Enabled:TCP Port 5004
"5005:TCP" = 5005:TCP:*:Enabled:TCP Port 5005
"5006:TCP" = 5006:TCP:*:Enabled:TCP Port 5006
"5007:TCP" = 5007:TCP:*:Enabled:TCP Port 5007
"5008:TCP" = 5008:TCP:*:Enabled:TCP Port 5008
"5009:TCP" = 5009:TCP:*:Enabled:TCP Port 5009
"5010:TCP" = 5010:TCP:*:Enabled:TCP Port 5010
"5011:TCP" = 5011:TCP:*:Enabled:TCP Port 5011
"5012:TCP" = 5012:TCP:*:Enabled:TCP Port 5012
"5013:TCP" = 5013:TCP:*:Enabled:TCP Port 5013
"5014:TCP" = 5014:TCP:*:Enabled:TCP Port 5014
"5015:TCP" = 5015:TCP:*:Enabled:TCP Port 5015
"5016:TCP" = 5016:TCP:*:Enabled:TCP Port 5016
"5017:TCP" = 5017:TCP:*:Enabled:TCP Port 5017
"5018:TCP" = 5018:TCP:*:Enabled:TCP Port 5018
"5019:TCP" = 5019:TCP:*:Enabled:TCP Port 5019
"5020:TCP" = 5020:TCP:*:Enabled:TCP Port 5020
"427:TCP" = 427:TCP:LocalSubNet:Enabled:SLP_Port(427)_TCP
"427:UDP" = 427:UDP:LocalSubNet:Enabled:SLP_Port(427)_UDP

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
"D:\setup\hpznui01.exe" = D:\setup\hpznui01.exe:*:Enabled:hpznui01.exe
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe
"E:\setup\hpznui01.exe" = E:\setup\hpznui01.exe:*:Enabled:hpznui01.exe
"C:\Documents and Settings\Stevie\Local Settings\temp\7zS609D\setup\hpznui01.exe" = C:\Documents and Settings\Stevie\Local Settings\temp\7zS609D\setup\hpznui01.exe:*:Enabled:hpznui01.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver – (www.sopcast.com)
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application – (www.sopcast.com)
"$INSTDIR\FlvDetector.exe" = C:\Program Files\FlashGet Network\FlashGet 3\FlvDetector.exe:*:Enabled:FGFlvDetector
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe
"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)
"C:\Documents and Settings\Stevie\Local Settings\temp\7zS609D\setup\hpznui01.exe" = C:\Documents and Settings\Stevie\Local Settings\temp\7zS609D\setup\hpznui01.exe:*:Enabled:hpznui01.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{097CDB1E-07C9-40F1-9972-F0F9F3A287E4}" = Network
"{09B44E78-A988-4BC0-962F-63ECD3333708}" = Packard Bell Companion
"{0AFFEA39-60AF-4C4F-BB47-4A1F7CB12129}" = HP Deskjet F4500 All-in-One Driver Software 14.0 Rel. 6
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation®Store
"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
"{14C35072-D7D0-4B29-B5BF-C94E426D77E9}" = Sky Broadband
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A6A6531-08FC-47AD-BAC4-C41497E71033}" = Nero 7 Essentials
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2376AAB2-F4D9-48D7-A42B-4E80B8967A8B}" = F4500
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 26
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{34610DE0-3C13-42CA-8E32-01FFA38AB6E8}" = PC Connectivity Solution
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74DC0593-6BC6-4001-AD5F-D810AFB68D86}" = HP Update
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{85498904-0748-45AA-9482-6DB8EA971B91}" = DJ_AIO_06_F4500_SW_MIN
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}" = Copy
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.5
"{AC76BA86-7AD7-5670-0000-900000000003}" = Korean Fonts Support For Adobe Reader 9
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B395BC1D-CC06-425E-9049-4CD985EFF004}" = LightScribe 1.8.15.1
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation®Network Downloader
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb" = Microsoft Automated Troubleshooting Services Shim
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
"{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}" = Kies
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"DivX Setup.divx.com" = DivX Setup
"ESET Online Scanner" = ESET Online Scanner v3
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.35.324
"HP Imaging Device Functions" = HP Imaging Device Functions 14.0
"HP Photo Creations" = HP Photo Creations
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"HPExtendedCapabilities" = HP Customer Participation Program 14.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}" = Kies
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"MSC" = McAfee Internet Security
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyFreeCodec" = MyFreeCodec
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Rapport_msi" = Rapport
"RealPlayer 12.0" = RealPlayer
"Shop for HP Supplies" = Shop for HP Supplies
"SiS VGA Driver" = SiS 651C
"SopCast" = SopCast 3.3.2
"Supreme Auction_is1" = Supreme Auction
"TomTom HOME" = TomTom HOME 2.8.1.2218
"Uninstall_is1" = Uninstall 1.0.0.1
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"Vivitar Experience Image Manager" = Vivitar Experience Image Manager
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"MyFreeCodec" = MyFreeCodec

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 17/07/2011 07:18:39 | Computer Name = SN037427820165 | Source = MsiInstaller | ID = 10005
Description =

Error - 17/07/2011 07:20:33 | Computer Name = SN037427820165 | Source = MsiInstaller | ID = 1023
Description =

Error - 17/07/2011 07:20:34 | Computer Name = SN037427820165 | Source = HotFixInstaller | ID = 5000
Description = EventType visualstudio8setup, P1 microsoft .net framework 3.0-kb982168,
P2 1033, P3 1603, P4 msi, P5 f, P6 9.0.40215.0, P7 install, P8 x86, P9 xp, P10
2330.

Error - 17/07/2011 07:30:25 | Computer Name = SN037427820165 | Source = MsiInstaller | ID = 11317
Description =

Error - 17/07/2011 07:30:46 | Computer Name = SN037427820165 | Source = MsiInstaller | ID = 10005
Description =

Error - 17/07/2011 07:34:58 | Computer Name = SN037427820165 | Source = MsiInstaller | ID = 1023
Description =

Error - 17/07/2011 07:34:59 | Computer Name = SN037427820165 | Source = HotFixInstaller | ID = 5000
Description = EventType visualstudio8setup, P1 microsoft .net framework 3.5-kb963707,
P2 1033, P3 1603, P4 msi, P5 f, P6 9.0.31211.0, P7 install, P8 x86, P9 xp, P10
2330.

Error - 17/07/2011 14:45:24 | Computer Name = SN037427820165 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 3.0.8402.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 17/07/2011 17:20:44 | Computer Name = SN037427820165 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0, P2 moaccapability, P3 3.0.8402.0, P4
0, P5 0, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 18/07/2011 13:01:43 | Computer Name = SN037427820165 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.26.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 18/07/2011 13:54:54 | Computer Name = SN037427820165 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 18/07/2011 13:54:56 | Computer Name = SN037427820165 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 18/07/2011 13:54:59 | Computer Name = SN037427820165 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 18/07/2011 13:55:01 | Computer Name = SN037427820165 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 18/07/2011 13:55:04 | Computer Name = SN037427820165 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 18/07/2011 13:55:05 | Computer Name = SN037427820165 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 18/07/2011 13:55:09 | Computer Name = SN037427820165 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 18/07/2011 13:55:10 | Computer Name = SN037427820165 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 18/07/2011 13:55:13 | Computer Name = SN037427820165 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 18/07/2011 13:55:15 | Computer Name = SN037427820165 | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.


< End of report >
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hi Mowman, here is the log report from Combofix.

ComboFix 11-07-19.02 - Stevie 19/07/2011 17:44:47.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.533 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix2.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Fonts\FTLTLT.TTF
c:\windows\Fonts\LBRITED.TTF
c:\windows\Fonts\MATURASC.TTF
c:\windows\Downloaded Program Files\cpcScan.dll . . . . Failed to delete
c:\windows\Fonts\ARBLI___.TTF . . . . Failed to delete
c:\windows\Fonts\BRLNSDB.TTF . . . . Failed to delete
c:\windows\Fonts\BRLNSR.TTF . . . . Failed to delete
c:\windows\Fonts\segoeuiz.ttf . . . . Failed to delete
.
.
((((((((((((((((((((((((( Files Created from 2011-06-19 to 2011-07-19 )))))))))))))))))))))))))))))))
.
.
2011-07-19 16:35 . 2011-06-20 07:57 7074640 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-19 16:34 . 2011-06-20 07:57 7074640 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{816F0728-4B16-4CAC-879E-FAB69DC69B7A}\mpengine.dll
2011-07-18 16:38 . 2004-08-04 05:41 404990 —-a-w- c:\windows\system32\drivers\SET39.tmp
2011-07-17 19:17 . 2010-10-19 20:51 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-07-17 18:40 . 2011-07-17 18:46 ——– d—–w- c:\program files\Microsoft Security Client
2011-07-17 16:17 . 2004-04-16 14:52 5632 —-a-w- c:\windows\InstFunc.dll
2011-07-07 21:16 . 2011-07-07 21:16 ——– d—–w- c:\program files\Supreme Auction
2011-06-30 18:14 . 2011-06-30 18:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2011-06-30 18:14 . 2011-06-30 18:14 ——– d—–w- c:\windows\Cache
2011-06-30 18:14 . 2011-06-30 18:14 ——– d—–w- c:\program files\Coupons
2011-06-30 18:14 . 2011-06-30 18:14 ——– d—–w- c:\program files\HP Photo Creations
2011-06-30 18:14 . 2011-06-30 18:14 ——– d—–w- c:\documents and settings\All Users\Application Data\HP Photo Creations
2011-06-30 18:12 . 2011-06-30 18:12 ——– d—–w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2011-06-30 18:10 . 2011-06-30 18:10 ——– d—–w- c:\program files\Common Files\HP
2011-06-30 18:08 . 2009-04-01 06:21 589824 —-a-w- c:\windows\system32\hpost_d02d.dll
2011-06-30 18:08 . 2009-04-01 06:21 713728 —-a-w- c:\windows\system32\hposwia_d02d.dll
2011-06-30 18:08 . 2009-04-01 06:21 315392 —-a-w- c:\windows\system32\hposc_d02a.dll
2011-06-30 18:08 . 2008-10-29 00:27 372736 —-a-w- c:\windows\system32\hppldcoi.dll
2011-06-30 18:08 . 2008-10-29 00:27 309760 —-a-w- c:\windows\system32\difxapi.dll
2011-06-26 12:12 . 2011-06-26 12:11 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-06-25 11:01 . 2011-07-06 18:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-25 11:01 . 2011-07-16 21:12 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-25 11:01 . 2011-07-06 18:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-24 23:54 . 2011-06-24 23:54 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-24 16:16 . 2011-06-24 16:16 ——– d—–w- c:\program files\ESET
2011-06-22 20:19 . 2011-04-14 13:01 24376 —-a-w- c:\program files\Mozilla Firefox\components\Scriptff.dll
2011-06-22 20:06 . 2011-06-22 20:06 ——– d—–w- c:\windows\system32\wbem\Repository
2011-06-22 20:05 . 2011-06-24 23:58 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2011-06-22 20:05 . 2011-06-22 20:05 ——– d—–w- c:\program files\NOS
2011-06-22 20:02 . 2011-06-22 20:02 ——– d—–w- c:\program files\Common Files\Adobe AIR
2011-06-22 17:01 . 2011-06-22 17:01 53816 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-26 12:11 . 2010-05-04 06:19 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-06-02 14:02 . 2002-09-19 19:26 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-05-02 15:31 . 2003-03-03 14:57 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2002-09-19 19:26 151552 —-a-w- c:\windows\system32\schannel.dll
2011-04-26 11:07 . 2002-09-19 19:26 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-04-26 11:07 . 2002-09-19 19:26 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-04-25 16:11 . 2006-06-23 10:33 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2002-09-19 19:26 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2002-09-19 19:26 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2002-09-19 19:26 105472 —-a-w- c:\windows\system32\drivers\mup.sys
2005-09-21 16:38 . 2005-09-21 16:38 677 -c–a-w- c:\program files\lxce.vbs
2011-04-14 13:01 . 2011-06-22 20:19 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-22 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-04-05 1195408]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2009-05-19 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-05 15:18 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"$INSTDIR\\FlvDetector.exe"= c:\\Program Files\\FlashGet Network\\FlashGet 3\\FlvDetector.exe
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Documents and Settings\\Stevie\\Local Settings\\temp\\7zS609D\\setup\\hpznui01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3659:UDP"= 3659:UDP:PS3
"6000:UDP"= 6000:UDP:ps3
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
.
R2 gupdate1ca8478a9da0ea4;Google Update Service (gupdate1ca8478a9da0ea4);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-24 133104]
R3 cpuz134;cpuz134;c:\program files\CPUID\PC Wizard 2010\pcwiz_x32.sys [x]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2010-07-26 18136]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-12-22 36640]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-24 133104]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtport.sys [x]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbus.sys [x]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmodem.sys [x]
R3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [2010-11-16 267568]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\DRIVERS\mfendisk.sys [2011-04-14 88736]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-04-14 84488]
R3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe [2008-04-14 14336]
R3 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [2011-03-16 38976]
R3 PSSDKLBF;PSSDKLBF;c:\windows\system32\Drivers\pssdklbf.sys [2011-03-16 53312]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-20 12872]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 123648]
R3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\DRIVERS\ss_bserd.sys [2009-09-19 100224]
R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2009-10-09 98560]
R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [x]
R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2009-10-09 123648]
R3 STAC97NA;SigmaTel 3D Environmental Audio;c:\windows\system32\drivers\stac97na.sys [2002-09-20 296179]
R3 STAC97NH;STAC97NH;c:\windows\system32\drivers\stac97nh.sys [2002-09-20 231983]
R4 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [2010-07-26 95568]
R4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-12-22 217088]
S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [2011-06-22 53816]
S1 Asapi;Asapi; [x]
S1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2011-04-14 84200]
S1 RapportCerberus_26762;RapportCerberus_26762;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\26762\RapportCerberus_26762.sys [2011-06-16 57144]
S1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [2011-06-22 66360]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2011-06-22 158904]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-20 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2010-09-15 67656]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-01-23 203280]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-04-14 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-04-14 141792]
S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-06-22 870200]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2011-03-09 92592]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-04-14 56064]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-04-14 314088]
S3 mfendiskmp;mfendiskmp;c:\windows\system32\DRIVERS\mfendisk.sys [2011-04-14 88736]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-07-18 16:53 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-19 c:\windows\Tasks\ConfigExec.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2010-11-16 00:09]
.
2011-07-18 c:\windows\Tasks\DataUpload.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2010-11-16 00:09]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-24 09:08]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-24 09:08]
.
2011-07-19 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 14:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.co.uk/
IE: Download All By FlashGet3 - c:\documents and settings\Stevie\Application Data\FlashGetBHO\GetAllUrl.htm
IE: Download By FlashGet3 - c:\documents and settings\Stevie\Application Data\FlashGetBHO\GetUrl.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Stevie\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
Trusted Zone: bitsoup.org\www
Trusted Zone: motive.com\pbttbc.bt
TCP: DhcpNameServer = 192.168.0.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20110428084740
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Microsoft .NET Framework 3.5 SP1 - c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-19 19:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbid01.dat 90159 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\Autorun.inf 365780 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\DJ_AIO_06_F4500_Webreg.ini 352 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\amd64
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\amd64\winxp
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\amd64\winxp\difxapi.dll 508928 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\amd64\winxp\hppldcoi.dll 551424 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\amd64\winxp\hppldcoi.x64.dll 481280 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\amd64\winxp\hpzid412.sys 187392 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\amd64\winxp\hpzipr12.sys 48640 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\amd64\winxp\hpzisc12.sys 29696 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\amd64\winxp\hpzius12.sys 50688 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\win2000
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\win2000\difxapi.dll 309760 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\win2000\hppldcoi.dll 372736 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\win2000\hpzc3212.dll 286720 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\win2000\hpzid412.sys 49920 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\win2000\hpzipr12.sys 16496 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\win2000\hpzisc12.sys 9712 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\win2000\hpzius12.sys 21568 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\win2000\hpzs2k12.sys 50424 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\winxp
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\winxp\hppaufd0.sys 16800 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\wrapper
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\wrapper\cioum32.msi 311296 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\dot4\wrapper\cioum64.msi 461824 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\scanner
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\scanner\x32
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\scanner\x32\hposc_d02a.dll 315392 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\scanner\x32\hpost_d02d.dll 589824 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\scanner\x32\hposwia_d02d.dll 713728 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\scanner\x32\hpotsti1.dll 229376 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\scanner\x64
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\scanner\x64\hposc_d02a.dll 516096 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\scanner\x64\hpost_d02d.dll 749056 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\drivers\scanner\x64\hposwia_d02d.dll 881664 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\help
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\help\enu
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\help\enu\HP_Setup_Help.chm 75828 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpF4500.cab 2419636 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpf4500.cat 141723 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpF4500.inf 19418 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpF4500a.cab 9245691 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpF4500s.cab 9494563 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpof4500_sc.cat 127425 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpoF4500_sc.inf 82470 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpof4500_u.cat 123158 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpoF4500_u.inf 3738 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpof4500_vp.cat 124856 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpoF4500_vp.inf
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpomdl46.dat 532 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpoprl01.dat 580 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpoprl10.dat 744 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpoprl12.dat 4021 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hppldcoi.config 1783 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbid05.dat 94829 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbid06.dat 99905 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbid15.dat 92078 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbid16.dat 88761 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbid20.dat 19898 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbid21.dat 17655 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbpl01.dat 4961 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbpl05.dat 4537 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbpl06.dat 4907 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbpl15.dat 5051 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpqbpl16.dat 4526 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzc3212.dll 282624 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzid413.cat 123579 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzid413.inf 185650 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzids01.dll 452408 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzids40.dll 642360 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzipa13.cat 125702 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzipa13.inf 143638 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzipr13.cat
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzipr13.inf 78086 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzius13.cat 126127 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzius13.inf 219790 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzprl01.dat 1424 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzprl02.dat 4037 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzprl03.dat 639 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzprl05.dat 3669 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzsetup.exe 1257088 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzstub.exe 1220224 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\hpzuci12.dll 18560 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\BallonsInFloweredTree2.jpg 72154 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\CarOnEuroBridge2.jpg 26342 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\Checked.jpg 909 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\ColoredHousesHarbor2.jpg 46752 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\ColoredPencils2.jpg 56655 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\CountryRoad2.jpg 48995 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\FailedInstall.jpg 969 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\HpLogo.jpg 2712 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\LP_Ext_finish.jpg 148786 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\LP_Ext_progress.jpg 80196 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\LP_Ext_swmenu.jpg 107998 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\disconnect_usb.JPG 8258 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\install_success.JPG 2715 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\adhoc.JPG 3056 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\already_on_network.jpg 8944 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\already_on_network_wireless_button.jpg 21795 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\connect_ethernet_big.jpg 35268 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\device_found.JPG 1942 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\device_notfound.JPG 2097 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\device_warning.JPG 14438 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\direct_connection.JPG 4084 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\disconnect_cable.JPG 7479 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\front_panel_wizard.JPG 21024 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\front_panel_wizard_wireless_button.jpg 21085 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\infrastructure.JPG 3302 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\insert_flash_drive_to_device.JPG 8034 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\insert_flash_drive_to_pc.JPG 4521 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\install_dialog_network.JPG 8829 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\install_dialog_network_2x.JPG 12178 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\install_failure.JPG 3080 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\network_Connection.JPG 4247 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\network_install_failure.JPG 11548 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\network_install_success.JPG 11042 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\network_install_warning.JPG 9548 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\reinsert_flash_drive_to_pc.JPG 7423 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\security_key.JPG 1124 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\security_lock.JPG 1512 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\SES.JPG 6383 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\step1.jpg 1178 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\step2.jpg 1295 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\still_not_found.jpg 8967 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\temporary_cable_connection.JPG 4236 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\usb_cable.jpg 19166 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\wired_network.JPG 4408 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\wired_net_connect_to_device.JPG 7130 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_nuiimages\wireless_network.JPG 3892 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\Connect_usb.JPG 19817 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\usb_bmp1.JPG 9866 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\usb_bmp2.JPG 6813 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\usb_bmp2a.JPG 6921 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\usb_bmp2b.JPG 6909 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\usb_bmp2c.JPG 6892 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\usb_bmp2d.JPG 6967 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\usb_bmp3.JPG 7860 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\usb_bmp4.JPG 8219 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\usb_to_wireless.jpg 20021 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\wired_network.jpg 4408 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\printer_usbimages\wireless_network.jpg 3892 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\Progress.jpg 315 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\SetupGuideImage.JPG 14024 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\SuccessInstall.jpg 974 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\images\UnChecked.jpg 867 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\OpenSource
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\OpenSource\boost_license.txt 1388 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\OpenSource\chmLib_license.txt 760 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\OpenSource\cLucene_license.txt 787 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\OpenSource\license.txt 1479 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\OpenSource\opensource_helpviewer.zip 7288471 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\OpenSource\snowball_license.txt 1558 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\OpenSource\swfObject_license.txt 1349 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\Partners
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\Partners\license1.txt 335 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\Partners\license3.txt 2883 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\Partners\license4.txt 19034 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\Partners\license5.txt 7989 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\licensing\Partners\license6.txt 816 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\bufferchm
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\bufferchm\BufferChm.cab 4809783 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\bufferchm\BufferChm.msi 501248 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\bufferchm\BufferChm1033.cab 727074 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\copy
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\copy\Copy.cab 8943907 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\copy\Copy.msi 611840 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\copy\Copy1033.cab
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\coupons
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\coupons\CouponPrinter.exe 1047656 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\destinations
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\destinations\Destinations.cab 22900710 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\destinations\Destinations.msi 522752 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\destinations\Destinations1033.cab 90464 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\devicediscovery
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\devicediscovery\DeviceDiscovery.cab 4671385 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\devicediscovery\DeviceDiscovery.msi 583680 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\difxapi.dll 319984 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\doccd.exe 408192 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\DOT4_Plugin.exe 292480 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\dtss
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\dtss\HPSSupply.cab 1055170 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\dtss\HPSSupply.msi 482816 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\dtss\HPSSupply1033.cab 14095 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\f4500
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\f4500\F4500.cab 54662276 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\f4500\F4500.msi 1432064 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\f4500\F45001033.cab 151241 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\f4500_ncl_help
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\f4500_ncl_help\F4500_NCL_Help.cab 2810049 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\f4500_ncl_help\F4500_NCL_Help.msi 745984 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\flashplayer10
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\flashplayer10\install_flash_player_10_active_x.msi 2995712 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\gpbaseservice2
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\gpbaseservice2\GPBaseService2.cab 49291625 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\gpbaseservice2\GPBaseService2.msi 760320 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\gpbaseservice2\GPBaseService21033.cab 3446826 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\HPCommunication.dll 213120 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\HPeDiag.dll 323712 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\HPeSupport.dll 124016 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\hpoScr46.dat 8512 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\hpphotogadget
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\hpphotogadget\HPPhotoGadget.cab
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\hpphotogadget\HPPhotoGadget.msi 618496 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\hpqbhp01.exe 647296 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\hpqbud01.dat 86413 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\hpqbud05.dat 60064 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\hpqbud15.dat 4653 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\hpqbud16.dat 5881 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\hpqhsc01.dat 59727 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\HPScripting.dll 86144 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\setup\hpupdate
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\Setup.exe 1137792 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\Blue Locomotive toy.JPG 375129 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\CCC_Uninstaller.exe 771712 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\collect.bat 24 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\enu
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\enu\WindowsXP-KB822603-x86-enu.exe 349472 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\FixErr1714.exe 196736 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\hposcrlr.bat 88 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\hpqrrx08.exe 125056 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\PrintUtil.exe 746112 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\Uninstall.bat 1360 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\Uninstall.dat 1467 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\Uninstall_L1.bat 879 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\Uninstall_L2.bat 1027 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\Uninstall_L3.bat 1004 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\Uninstall_L4.bat 1360 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\x64
c:\docume~1\Stevie\LOCALS~1\Temp\7zS36E6\util\ccc\x64\printutil.exe 884864 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS4CE3
c:\docume~1\Stevie\LOCALS~1\Temp\7zS4CE3\CIOUM32.msi 351232 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS4CE3\CIOUM64.msi 502784 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS4CE3\Dot4Scrubber.exe 301928 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS4CE3\ExecuteProcess.exe 109928 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS4CE3\HPeDiag.dll 354872 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS4CE3\Rules.xml 8567 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MaglevExpressTemp
c:\docume~1\Stevie\LOCALS~1\Temp\MAR10.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR11.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR12.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR13.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR14.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR15.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR16.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR17.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR18.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR19.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR1A.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR1B.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR1C.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR1D.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR1E.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR1F.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR20.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR21.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR22.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR23.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR24.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR24D.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR24E.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR25.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR26.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR27.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR28.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR29.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR2A.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR2B.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR2C.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR2D.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR2E.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR41.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTD1.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTD2.xml 2232826 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTD3.dtd 1022 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTE1.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTE2.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTE3.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTEE.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTEF.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTF0.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IOConnection.txt 631 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\isdialogbanner.jpg 5054 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\isdialogbitmap.jpg 75387 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\JAUReg.log 343 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\java_install.log 87027 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\java_install_reg.log 11207 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\java_install_sp.log 3643 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\jinstall.cfg 1284 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzscr003.log 23763 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzscr004.log 22919 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzscr005.log 30726 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzscr006.log 21280 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzscr007.log 2946 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzscr008.log 4018 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzscr01.EXE 1317504 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCSHIM000.log 1464 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCSHIM001.log 776 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCSHIM002.log 776 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCSK00000.log 785 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCSK00001.log 785 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCSK00002.log 785 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCSNMP000.log 784 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCSNMP001.log 784 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCSNMP002.log 784 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCUSW0000.log 2710 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCUSW0001.log 768 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{79bcfdaa-cd26-4ed1-9001-5de81ae0ba64}_PC_{63FF21C9-A810-464F-B60A-3111747B1A6D}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{9716d554-3fbd-4dfd-8ae0-424efd722d74}_PC_{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{a6b13343-d0a0-401a-a893-4989be404a82}_PC_{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{a8edadcd-bc6f-48d7-a9f0-cced80208050}_PC_{6BBA26E9-AB03-4FE7-831A-3535584CA002}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{e35bce58-dd40-4854-984d-379a4d1796ef}_PC_{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbid01.dat 90159 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\Autorun.inf 365780 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\DJ_AIO_06_F4500_Webreg.ini 352 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\amd64
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\amd64\winxp
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\amd64\winxp\difxapi.dll 508928 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\amd64\winxp\hppldcoi.dll 551424 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\amd64\winxp\hppldcoi.x64.dll 481280 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\amd64\winxp\hpzid412.sys 187392 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\amd64\winxp\hpzipr12.sys 48640 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\amd64\winxp\hpzisc12.sys 29696 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\amd64\winxp\hpzius12.sys 50688 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\win2000
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\win2000\difxapi.dll 309760 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\win2000\hppldcoi.dll 372736 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\win2000\hpzc3212.dll 286720 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\win2000\hpzid412.sys 49920 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\win2000\hpzipr12.sys 16496 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\win2000\hpzisc12.sys 9712 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\win2000\hpzius12.sys 21568 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\win2000\hpzs2k12.sys 50424 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\winxp
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\winxp\hppaufd0.sys 16800 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\wrapper
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\wrapper\cioum32.msi 311296 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\dot4\wrapper\cioum64.msi 461824 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\scanner
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\scanner\x32
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\scanner\x32\hposc_d02a.dll 315392 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\scanner\x32\hpost_d02d.dll 589824 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\scanner\x32\hposwia_d02d.dll 713728 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\scanner\x32\hpotsti1.dll 229376 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\scanner\x64
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\scanner\x64\hposc_d02a.dll 516096 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\scanner\x64\hpost_d02d.dll 749056 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\drivers\scanner\x64\hposwia_d02d.dll 881664 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\help
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\help\enu
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\help\enu\HP_Setup_Help.chm 75828 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpF4500.cab 2419636 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpf4500.cat 141723 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpF4500.inf 19418 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpF4500a.cab 9245691 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpF4500s.cab 9494563 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpof4500_sc.cat 127425 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpoF4500_sc.inf 82470 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpof4500_u.cat 123158 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpoF4500_u.inf 3738 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpof4500_vp.cat 124856 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpoF4500_vp.inf 8870 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpomdl46.dat 532 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpoprl01.dat 580 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpoprl10.dat 744 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpoprl12.dat 4021 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hppldcoi.config 1783 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbid05.dat 94829 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbid06.dat 99905 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbid15.dat 92078 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbid16.dat 88761 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbid20.dat
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbid21.dat 17655 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbpl01.dat 4961 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbpl05.dat 4537 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbpl06.dat 4907 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbpl15.dat 5051 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpqbpl16.dat 4526 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzc3212.dll 282624 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzid413.cat 123579 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzid413.inf 185650 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzids01.dll 452408 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzids40.dll 642360 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzipa13.cat 125702 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzipa13.inf 143638 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzipr13.cat 123579 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzipr13.inf 78086 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzius13.cat 126127 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzius13.inf 219790 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzprl01.dat 1424 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzprl02.dat 4037 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzprl03.dat 639 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzprl05.dat 3669 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzsetup.exe 1257088 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzstub.exe 1220224 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\hpzuci12.dll 18560 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\BallonsInFloweredTree2.jpg 72154 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\CarOnEuroBridge2.jpg 26342 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\Checked.jpg 909 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\ColoredHousesHarbor2.jpg 46752 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\ColoredPencils2.jpg 56655 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\CountryRoad2.jpg 48995 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\FailedInstall.jpg 969 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\HpLogo.jpg 2712 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\LP_Ext_finish.jpg 148786 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\LP_Ext_progress.jpg 80196 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\LP_Ext_swmenu.jpg 107998 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\disconnect_usb.JPG 8258 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\install_success.JPG 2715 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\adhoc.JPG 3056 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\already_on_network.jpg 8944 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\already_on_network_wireless_button.jpg 21795 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\connect_ethernet_big.jpg 35268 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\device_found.JPG 1942 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\device_notfound.JPG 2097 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\device_warning.JPG 14438 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\direct_connection.JPG 4084 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\disconnect_cable.JPG 7479 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\front_panel_wizard.JPG 21024 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\front_panel_wizard_wireless_button.jpg 21085 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\infrastructure.JPG 3302 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\insert_flash_drive_to_device.JPG 8034 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\insert_flash_drive_to_pc.JPG 4521 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\install_dialog_network.JPG 8829 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\install_dialog_network_2x.JPG 12178 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\install_failure.JPG 3080 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\network_Connection.JPG 4247 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\network_install_failure.JPG 11548 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\network_install_success.JPG 11042 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\network_install_warning.JPG 9548 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\reinsert_flash_drive_to_pc.JPG 7423 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\security_key.JPG 1124 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\security_lock.JPG 1512 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\SES.JPG 6383 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\step1.jpg 1178 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\step2.jpg 1295 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\still_not_found.jpg 8967 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\temporary_cable_connection.JPG 4236 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\usb_cable.jpg 19166 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\wired_network.JPG 4408 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\wired_net_connect_to_device.JPG 7130 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_nuiimages\wireless_network.JPG 3892 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\Connect_usb.JPG 19817 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\usb_bmp1.JPG 9866 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\usb_bmp2.JPG 6813 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\usb_bmp2a.JPG 6921 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\usb_bmp2b.JPG 6909 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\usb_bmp2c.JPG 6892 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\usb_bmp2d.JPG 6967 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\usb_bmp3.JPG 7860 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\usb_bmp4.JPG 8219 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\usb_to_wireless.jpg 20021 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\wired_network.jpg 4408 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\printer_usbimages\wireless_network.jpg 3892 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\Progress.jpg 315 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\SetupGuideImage.JPG 14024 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\SuccessInstall.jpg 974 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\images\UnChecked.jpg 867 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\OpenSource
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\OpenSource\boost_license.txt 1388 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\OpenSource\chmLib_license.txt 760 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\OpenSource\cLucene_license.txt 787 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\OpenSource\license.txt 1479 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\OpenSource\opensource_helpviewer.zip 7288471 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\OpenSource\snowball_license.txt 1558 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\OpenSource\swfObject_license.txt 1349 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\Partners
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\Partners\license1.txt 335 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\Partners\license3.txt 2883 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\Partners\license4.txt 19034 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\Partners\license5.txt 7989 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\licensing\Partners\license6.txt 816 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup\bufferchm
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup\bufferchm\BufferChm.cab 4809783 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup\bufferchm\BufferChm.msi 501248 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup\bufferchm\BufferChm1033.cab 727074 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup\copy
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup\copy\Copy.cab 8943907 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup\copy\Copy.msi 611840 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup\copy\Copy1033.cab 160531 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup\coupons
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup\coupons\CouponPrinter.exe 1047656 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\setup\destinations
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\Setup.exe 1137792 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\Blue Locomotive toy.JPG 375129 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\CCC_Uninstaller.exe 771712 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\collect.bat 24 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\enu
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\enu\WindowsXP-KB822603-x86-enu.exe 349472 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\FixErr1714.exe 196736 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\hposcrlr.bat 88 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\hpqrrx08.exe 125056 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\PrintUtil.exe 746112 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\Uninstall.bat
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\Uninstall.dat 1467 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\Uninstall_L1.bat 879 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\Uninstall_L2.bat 1027 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\Uninstall_L3.bat 1004 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\Uninstall_L4.bat 1360 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\x64
c:\docume~1\Stevie\LOCALS~1\Temp\7zS609D\util\ccc\x64\printutil.exe 884864 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\hpznop005.log 1872 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl010.log 2332 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzscr002.log 54382 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCUSW0002.log 768 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzstu000.log 2893 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{2f99dab3-0db8-4e64-8fb7-9f4a7a7406aa}_PC_{55A7B938-3D1E-4819-A87B-F83E736EF52E}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{772e49a1-d539-464f-b084-7994ebe11151}_PC_{75247E38-5C9B-45D6-ADF8-E11CB56B4990}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hp_files.log 294218 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT194.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT41.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTD0.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\jusched.log 1436 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR42.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\print.reg 191466 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\VGXA2.tmp 306 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{348082c7-a032-4e1d-9b2a-41514c010335}_PC_{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{3e1bd9d1-80f1-4965-824d-05587bd19fd5}_PC_{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{4a0c2ff7-f844-4a11-8546-613c19ad5a0c}_PC_{43CDF946-F5D9-4292-B006-BA0D92013021}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{52a20bf3-71ee-4ca0-abc5-2f2e0b71f013}_PC_{FAF26102-09D7-4C58-AB01-0D59A2E517CA}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{65b97cfb-5cfb-4764-badc-0b3a756e761c}_PC_{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}_uninstall.log
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{68fce472-ccc6-4113-a478-3d29fc934ea0}_PC_{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HpUpdate
c:\docume~1\Stevie\LOCALS~1\Temp\HpUpdate\25490
c:\docume~1\Stevie\LOCALS~1\Temp\HpUpdate\25490\CIOUMUpdate_3545_000_009_hpu.exe 1184088 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\HpUpdate\9762
c:\docume~1\Stevie\LOCALS~1\Temp\HpUpdate\9762\ModelUpdate.exe 122368 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\HpUpdate\9763
c:\docume~1\Stevie\LOCALS~1\Temp\HpUpdate\9763\ModelUpdate.exe 131072 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\HpUpdate\9764
c:\docume~1\Stevie\LOCALS~1\Temp\HpUpdate\9764\ModelUpdate.exe 131072 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\HpUpdate\Upload
c:\docume~1\Stevie\LOCALS~1\Temp\hpznop002.log 2138 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpznop003.log 1621 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpznop004.log 1878 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzswp000.log 1658 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzswp001.log 1670 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzwis000.log 1609 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzwrp000.log 2034 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzwrp001.log 2054 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzwrp002.log 2226 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzwrp003.log 2126 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzwrp004.log 2126 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzwrp005.log 1713 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzwrp006.log 1703 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzwrp007.log 1775 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzwrp008.log 1784 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzwup000.log 6973 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{105d9372-3ced-4e84-b864-3afb2245164a}_PC_{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{2470f2e0-13b4-4318-ba74-5253ffc55dc0}_PC_{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{253bb068-9844-4088-93ec-cfd276a2f044}_PC_{497072FE-0A75-4E5C-A5B7-EB1FA67F66F1}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{29288fbb-da46-4ac2-84b9-7a8367fe60df}_PC_{C43326F5-F135-4551-8270-7F7ABA0462E1}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpz_UC_{2d1f2124-29e6-460a-b140-e9df3bc594ce}_PC_{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}_uninstall.log 190 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpznui000.log 64543 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpznui001.log 714 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzpnp000.log 1497 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzpnp001.log 2045 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzpnp002.log 2045 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzpnp003.log 2045 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzpnp004.log 2235 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzpnp01.exe 938112 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl000.log 2386 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl001.log 2419 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl002.log 3938 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl003.log 2431 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl004.log 2435 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl005.log 2391 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl006.log 2443 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl007.log 2380 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl008.log 2332 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl009.log 2392 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl000.log 1971 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl001.log 2069 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl002.log 2332 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl003.log 1958 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl004.log 1978 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl005.log 1706 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl006.log 1911 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl007.log 2107 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl008.log 18468 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl009.log 1696 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl010.log 1710 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl011.log 5704 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl012.log 1712 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl013.log 3582 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl014.log 1746 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzshl015.log 1848 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzprl011.log 2332 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzpsc000.log 2077 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzrcv000.log 2294 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzrcv001.log 1986 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzrcv002.log 2447 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzrcv003.log 1986 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzrcv004.log 33237 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzrei000.log 4159 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCBPD0000.log 787 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCBPD0001.log 787 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCBPD0002.log 787 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCNOP0000.log 856 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCNOP0001.log 856 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCNOP0002.log 856 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzscr000.log 4890 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzscr001.log 4209 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCUSW0003.log 1228 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCUSW0004.log 768 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\HPZSCUSW0005.log 1277 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset000.log 52248 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset001.log 1928 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset002.log 1928 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset003.log 1928 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset004.log 1928 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset005.log 1928 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset006.log 1896 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset007.log 1928 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset008.log 1916 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset009.log 1928 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset010.log 1896 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset011.log 1928 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset012.log 1896 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset_E.S.C-29638133.log 668 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hpzset_error29638133.log 346 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\WERa1bc.dir00
c:\docume~1\Stevie\LOCALS~1\Temp\WERa1bc.dir00\iexplore.exe.hdmp 10615225 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\WERa1bc.dir00\iexplore.exe.mdmp 72911 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\wmplog00.sqm 1692 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\Word8.0
c:\docume~1\Stevie\LOCALS~1\Temp\Word8.0\MSForms.exd 166724 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\WPDNSE
c:\docume~1\Stevie\LOCALS~1\Temp\_add_ds.log 562 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\_ir_sf_temp_0
c:\docume~1\Stevie\LOCALS~1\Temp\_ir_sf_temp_0\npCouponPrinter.dll 91552 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\_ir_sf_temp_0\npCouponPrinter.xpt 207 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\_ir_sf_temp_0\npMozCouponPrinter.dll 91552 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\_remove_ds.log 174 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\~DF2A2A.tmp 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\~DF388.tmp 16384 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\~DF3A39.tmp 16384 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\~DF5933.tmp 147456 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\~DF8375.tmp 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\~DF85D6.tmp 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\~DF87A4.tmp 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\~DFA2DA.tmp 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\~DFAF73.tmp 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\~DFF0C1.tmp 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\~DFF15E.tmp 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\processes.log 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\RedboxLog.txt 374470 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\services.log 47635 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\Setup0000.log 2603 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\Setup0001.log 3074 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\SilverStreakLog
c:\docume~1\Stevie\LOCALS~1\Temp\SSUPDATE.EXE 355056 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\sw_hp.reg 61922 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\sw_unins.reg 628060 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\updatedatfix.log 329 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\VBE
c:\docume~1\Stevie\LOCALS~1\Temp\vga5E
c:\docume~1\Stevie\LOCALS~1\Temp\vga5E\VGAchecklog.txt 380 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\vga5E\VGAsetup1.ini 127850 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\vga5E\VGAsetup2.ini 127998 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\vga6C
c:\docume~1\Stevie\LOCALS~1\Temp\vga6C.tmp 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\vga6D
c:\docume~1\Stevie\LOCALS~1\Temp\vga6D\VGAchecklog.txt 927 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\vga6D\VGAsetup1.ini 127850 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\vga6D\VGAsetup2.ini 127998 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\VGXA1.tmp 958 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\AdobeARM.log 4650 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\Av-test.txt 72 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\catchme.dll 53248 bytes executable
c:\docume~1\Stevie\LOCALS~1\Temp\CDM
c:\docume~1\Stevie\LOCALS~1\Temp\dd_clwireg.txt 33097 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\dw.log 290 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\Google Toolbar
c:\docume~1\Stevie\LOCALS~1\Temp\Google Toolbar\1f6cb165-ff5b-4a20-8e23-137fd1976152.dmp 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\Google Toolbar\gtb1C5.tmp 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR6.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR7.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR9.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR97.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MAR98.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MARA.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MARB.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MARC.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MARD.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MARE.tmp 1285 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MARF.tmp 1313 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MessengerCache
c:\docume~1\Stevie\LOCALS~1\Temp\Microsoft .NET Framework 3.0-KB982168_20110717_111133531-Msi0.txt 2479266 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\Microsoft .NET Framework 3.0-KB982168_20110717_111133531.html 94172 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\Microsoft .NET Framework 3.5-KB963707_20110717_112048687-Msi0.txt 697162 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\Microsoft .NET Framework 3.5-KB963707_20110717_112048687.html 77552 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\mmc1DE1D0DB.xml 0 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\MsiExe000.log 58 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\msohtml
c:\docume~1\Stevie\LOCALS~1\Temp\msohtml1
c:\docume~1\Stevie\LOCALS~1\Temp\msohtml1\01
c:\docume~1\Stevie\LOCALS~1\Temp\OIS
c:\docume~1\Stevie\LOCALS~1\Temp\OIS\cacheFiles
c:\docume~1\Stevie\LOCALS~1\Temp\OIS\temp
c:\docume~1\Stevie\LOCALS~1\Temp\outlook logging
c:\docume~1\Stevie\LOCALS~1\Temp\outlook logging\firstrun.log 375 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\hsperfdata_Stevie
c:\docume~1\Stevie\LOCALS~1\Temp\ImageDebug
c:\docume~1\Stevie\LOCALS~1\Temp\IMT17D.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT17E.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT17F.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT185.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT186.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT187.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT188.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT189.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT18A.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT18B.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT18C.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT18D.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT18E.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT18F.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT190.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT191.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT192.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT193.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT42.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT43.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT44.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT45.xml 2232826 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT46.dtd 1022 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT47.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT48.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT49.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT4A.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT4B.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT4C.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTB6.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTB7.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTB8.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTC3.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTC4.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTC5.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMTCF.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT195.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT196.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT197.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT198.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT199.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT19A.xml 2232826 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT19B.dtd 1022 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT19C.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT19D.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT19E.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT19F.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT1A0.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT1A1.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT1A2.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT1A3.xml 426 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT1A4.xml 707340 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT3F.xml 1994 bytes
c:\docume~1\Stevie\LOCALS~1\Temp\IMT40.xml 426 bytes
c:\windows\TEMP\Cookies
c:\windows\TEMP\Cookies\index.dat 16384 bytes
c:\windows\TEMP\D22110CB-869C-4157-A837-153B9D79A365-Sigs
c:\windows\TEMP\dd_clwireg.txt 100359 bytes
c:\windows\TEMP\dw.log 320 bytes
c:\windows\TEMP\Google Toolbar
c:\windows\TEMP\GoogleToolbarInstaller1.log 270 bytes
c:\windows\TEMP\History
c:\windows\TEMP\History\History.IE5
c:\windows\TEMP\History\History.IE5\desktop.ini 145 bytes
c:\windows\TEMP\History\History.IE5\index.dat 16384 bytes
c:\windows\TEMP\sqlite_gIceaudAbVZ7qn1 1024 bytes
c:\windows\TEMP\sqlite_GkaWPZpuncCT9va 1024 bytes
c:\windows\TEMP\sqlite_h7GbeTkPWVZMGRI 1024 bytes
c:\windows\TEMP\sqlite_hbsyFiLgEfruBZB 1024 bytes
c:\windows\TEMP\sqlite_HdhefQ6JRpED7Ad 1024 bytes
c:\windows\TEMP\sqlite_Hfa2OxcsX0PUNe8 1024 bytes
c:\windows\TEMP\sqlite_hlOBnGhhg3uBabI 0 bytes
c:\windows\TEMP\sqlite_HNlrzLjsmpils71 0 bytes
c:\windows\TEMP\sqlite_iBLD7dpS1HUoZ9P 1024 bytes
c:\windows\TEMP\sqlite_IgpDnOp5r96trh2 1024 bytes
c:\windows\TEMP\sqlite_iHuZcZzeQOCH1dt 1024 bytes
c:\windows\TEMP\sqlite_ikpvwcr47xlCnxs 1024 bytes
c:\windows\TEMP\sqlite_INekYEinV2kz8zj 1024 bytes
c:\windows\TEMP\sqlite_JccmMdJY4iicIho 1024 bytes
c:\windows\TEMP\sqlite_jfqLMRMffONeJgJ 1024 bytes
c:\windows\TEMP\sqlite_JMis4oP3pmkJfyK 1024 bytes
c:\windows\TEMP\sqlite_jy6bnIETjQbQq2R 1024 bytes
c:\windows\TEMP\sqlite_K7vECs4T7MlptOX 1024 bytes
c:\windows\TEMP\sqlite_KR0JSpcB1NNQqbz 1024 bytes
c:\windows\TEMP\sqlite_KRY1hlu8izM4oGT 1024 bytes
c:\windows\TEMP\sqlite_KwA4vjBFJcnXpch 1024 bytes
c:\windows\TEMP\sqlite_ld5C13RjMsO7VOD 0 bytes
c:\windows\TEMP\sqlite_LDlDPrCai1hGAy8 1024 bytes
c:\windows\TEMP\sqlite_lyIJcUy9Qcp2L5M 1024 bytes
c:\windows\TEMP\sqlite_M4OFe5SsI1GbLye 1024 bytes
c:\windows\TEMP\sqlite_mg9QcbETucz0SiF 1024 bytes
c:\windows\TEMP\sqlite_MGr4zTuIFA6u2vC 1024 bytes
c:\windows\TEMP\sqlite_Mt8i8CMlghULnz3 1024 bytes
c:\windows\TEMP\sqlite_XMmTQfVrjlszqsw 1024 bytes
c:\windows\TEMP\sqlite_Y0rBGLwDIIeXvN8 0 bytes
c:\windows\TEMP\sqlite_y9Z8tIYvfv9L4Ie 1024 bytes
c:\windows\TEMP\sqlite_yc3di8W1v31kM2b 1024 bytes
c:\windows\TEMP\sqlite_yi3RkzBin4sycyE 1024 bytes
c:\windows\TEMP\sqlite_YMyF43L89QfMaXX 1024 bytes
c:\windows\TEMP\sqlite_yP8yoZjf00PLzCh 1024 bytes
c:\windows\TEMP\sqlite_zb6mN4L1xsPsg6G 1024 bytes
c:\windows\TEMP\sqlite_zjMER0tcS8triMo 1024 bytes
c:\windows\TEMP\sqlite_zL40zgKZl5jFlwv 1024 bytes
c:\windows\TEMP\sqlite_zQvwYMdxnLsoEyZ 1024 bytes
c:\windows\TEMP\sqlite_zuyw1EaD3jGmiw4 1024 bytes
c:\windows\TEMP\Temporary Internet Files
c:\windows\TEMP\Temporary Internet Files\Content.IE5
c:\windows\TEMP\Temporary Internet Files\Content.IE5\5EK8M6T0
c:\windows\TEMP\Temporary Internet Files\Content.IE5\5EK8M6T0\desktop.ini 67 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\desktop.ini 67 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\EBQ21A9O
c:\windows\TEMP\Temporary Internet Files\Content.IE5\EBQ21A9O\desktop.ini 67 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\index.dat 32768 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\QYTDBWR5
c:\windows\TEMP\Temporary Internet Files\Content.IE5\QYTDBWR5\desktop.ini 67 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W084U76L
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W084U76L\desktop.ini 67 bytes
c:\windows\TEMP\~sraxdir.tmp
c:\windows\TEMP\sqlite_UWeaLbCSH9m4F3N 1024 bytes
c:\windows\TEMP\sqlite_vE4x0TTAt7VfuZM 1024 bytes
c:\windows\TEMP\sqlite_Vf2ifaOYGXhzbe7 0 bytes
c:\windows\TEMP\sqlite_vmhKGeP3vD6C06t 1024 bytes
c:\windows\TEMP\sqlite_WcKziQvzLS0xu45 1024 bytes
c:\windows\TEMP\sqlite_WeNbUtkxipgGlxC 1024 bytes
c:\windows\TEMP\sqlite_wfC27ZXX51Cl8yR 1024 bytes
c:\windows\TEMP\sqlite_wmiNV5thcxlwc5d 0 bytes
c:\windows\TEMP\sqlite_ws1Kq5t4KC0qyMx 1024 bytes
c:\windows\TEMP\sqlite_wVFiInqux8cGKqf 1024 bytes
c:\windows\TEMP\sqlite_wWdfP2IBQcTubIa 1024 bytes
c:\windows\TEMP\sqlite_wWJqTDZXoIatjiO 1024 bytes
C:\Wcatchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
c:\windows\TEMP\sqlite_X4sJlXznQrZJ1Yo 0 bytes
c:\windows\TEMP\sqlite_x4syzPBw9EBdfav 1024 bytes
c:\windows\TEMP\sqlite_X8AthhX9toeXTnb 1024 bytes
c:\windows\TEMP\hpqddsvc.log 17537 bytes
c:\windows\TEMP\HPSLPSVC0000.log 3618 bytes
c:\windows\TEMP\HPSLPSVC0001.log 3616 bytes
c:\windows\TEMP\HPSLPSVC0002.log 3618 bytes
c:\windows\TEMP\HPSLPSVC0003.log 3617 bytes
c:\windows\TEMP\HPSLPSVC0004.log 2902 bytes
c:\windows\TEMP\HPSLPSVC0032.log 2903 bytes
c:\windows\TEMP\MpCmdRun.log 175402 bytes
c:\windows\TEMP\MpSigStub.log 8826 bytes
c:\windows\TEMP\MPTelemetrySubmit
c:\windows\TEMP\sqlite_mVxrESmvcVszSKl 1024 bytes
c:\windows\TEMP\sqlite_mwf8uTmo4wzOWuN 1024 bytes
c:\windows\TEMP\sqlite_myFRnOlikSDD2IF 1024 bytes
c:\windows\TEMP\sqlite_nkeVTKXI5E5b8nv 1024 bytes
c:\windows\TEMP\sqlite_nLxTJy9eKv92l5g 1024 bytes
c:\windows\TEMP\sqlite_NRaEMgqmkPqDGc2 1024 bytes
c:\windows\TEMP\sqlite_Nxb18yGnNl8V4ls 1024 bytes
c:\windows\TEMP\sqlite_o38mLher1VPq1yj 1024 bytes
c:\windows\TEMP\sqlite_oCBMYN9mW1TOQll 0 bytes
c:\windows\TEMP\sqlite_ohHNtbCoE8eOZ8e 1024 bytes
c:\windows\TEMP\sqlite_OT1Z1GoKfZfFjDN 1024 bytes
c:\windows\TEMP\sqlite_OXGO8wq5xhu0YsR 1024 bytes
c:\windows\TEMP\sqlite_p407Kb4qCIrECvH 1024 bytes
c:\windows\TEMP\sqlite_pB1yKoAQQg0Szhl 1024 bytes
c:\windows\TEMP\sqlite_PHNvp0Bt4XzeJ5i 1024 bytes
c:\windows\TEMP\sqlite_PjWkmOje0kGaQfA 1024 bytes
c:\windows\TEMP\sqlite_PVb2fX5BA4YXSmb 1024 bytes
c:\windows\TEMP\sqlite_Q0T4pAF4OXCDRn0 1024 bytes
c:\windows\TEMP\sqlite_q6Lju6KJl15Pyfl 0 bytes
c:\windows\TEMP\sqlite_qM5gZyxh6836yhk 1024 bytes
c:\windows\TEMP\sqlite_qwPaa8lBaWXQGjw 1024 bytes
c:\windows\TEMP\sqlite_qzOJHWbyTTCxlbp 1024 bytes
c:\windows\TEMP\sqlite_qzvPxl5QKDmfy8k 1024 bytes
c:\windows\TEMP\sqlite_RbVTGTHRyvjVL4w 1024 bytes
c:\windows\TEMP\sqlite_RUMRoFiidpHPbaG 1024 bytes
c:\windows\TEMP\sqlite_SEKGUHqBj9zXNyh 1024 bytes
c:\windows\TEMP\sqlite_SIUT6LdtrD1T1rv 1024 bytes
c:\windows\TEMP\sqlite_SMec3Vd5sctdcNd 1024 bytes
c:\windows\TEMP\sqlite_SuMtCteMFwZeu5B 1024 bytes
c:\windows\TEMP\sqlite_toMAIpUsJS3gh3Z 1024 bytes
c:\windows\TEMP\sqlite_1RL4nQ7jvRb2qJw 1024 bytes
c:\windows\TEMP\sqlite_9oRuG9nF88A4Phr 1024 bytes
c:\windows\TEMP\sqlite_a7L5Pbff7F1DM4V 1024 bytes
c:\windows\TEMP\sqlite_ag20aAxa5KhbINn 1024 bytes
c:\windows\TEMP\sqlite_AmNCHWhRjlqdCgD 1024 bytes
c:\windows\TEMP\sqlite_apPhppdPRQAdJYg 1024 bytes
c:\windows\TEMP\sqlite_AVNyBsSBo9u0WgT 1024 bytes
c:\windows\TEMP\sqlite_aXwcnY8Qwv6E2px
c:\windows\TEMP\sqlite_bQxyoxWdrp4IpMy 1024 bytes
c:\windows\TEMP\sqlite_CIt4yGHIPOIE2GM 1024 bytes
c:\windows\TEMP\sqlite_crXf1hHmXlXbBz5 1024 bytes
c:\windows\TEMP\sqlite_d10xB2JSArDBJea 1024 bytes
c:\windows\TEMP\sqlite_DCGH1N0gkHwIeqF 1024 bytes
c:\windows\TEMP\sqlite_dFESHhGGdptx8fe 1024 bytes
c:\windows\TEMP\sqlite_e86Tca1BxPZcOOu 1024 bytes
c:\windows\TEMP\sqlite_ejN1UBuqKOWNZzN 1024 bytes
c:\windows\TEMP\sqlite_f8hhbLUVKRFd4nG 1024 bytes
c:\windows\TEMP\sqlite_faON5cbWmIdSlwM 1024 bytes
c:\windows\TEMP\sqlite_fGotEOhxe61dasq 1024 bytes
c:\windows\TEMP\sqlite_FjtPZ5T8vSbkaiT 1024 bytes
c:\windows\TEMP\Perflib_Perfdata_29c.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_f4.dat 16384 bytes
c:\windows\TEMP\SiteAdvisor
c:\windows\TEMP\Perflib_Perfdata_1f8.dat 16384 bytes
c:\windows\TEMP\sqlite_gAKjcnGgNej3hpc 1024 bytes
c:\windows\TEMP\sqlite_MtI0Ge2ncefGZJM 1024 bytes
c:\windows\TEMP\sqlite_txwYWMT3gnxFEbF 1024 bytes
c:\windows\TEMP\sqlite_xGH5er6eONvE815 1024 bytes
.
scan completed successfully
hidden files: 926
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,24,77,29,7c,89,b8,d0,47,b0,6f,23,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,24,77,29,7c,89,b8,d0,47,b0,6f,23,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(804)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(3032)
c:\windows\system32\WININET.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\McAfee\SystemCore\mfefire.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
.
**************************************************************************
.
Completion time: 2011-07-19 20:13:04 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-19 19:12
.
Pre-Run: 9,866,752,000 bytes free
Post-Run: 9,873,084,416 bytes free
.
- - End Of File - - 28E02843B5DBA4EBF19F1ABF5DEA8C26
Please do the following in this order 1.Open ATF cleaner you have installed and Select all to remove all temp files in main and firefox. 2.Run Combofix again 3.Try to update and run Malwarebytes.
Hi Mowman I run the ATF Cleaner earlier tonight. I done what you said to, selecting to delete all files in main and firefox. When I selected firefox, it asked me if I wanted to delete the firefox passwords, I clicked yes but it then came back saying 'No Files Were Deleted'. The files in Main seem to delete fine. I then moved onto running Combofix again. While it was scanning, a Microsoft message came up saying that a problem was encountered with PEV.EXE and it had to close. I clicked not to send error report and progressed with the scan. Combo fix started to go through all the processes. It got to the point where it was telling me that it was deleting files. It deleted about 4 and then seemed to freeze. I left it sitting there for over 4 hours but nothing else changed and it never moved on any further. The little light that flickers when the HDD is being used wasn't doing anything, so I presummed it had froze and shut down and restarted. When it loaded back up again, it done it's usual CHKDSK thing and is still doing this. I'll let this complete overnight if necessary and get back to you tomorrow. This is the longest it's ever took and it's doing things I've never seen it do before. My plan is just to run the process you've told to in the last post again and see how far I get. Obviously, if you think I should do something else, just give me a shout and let me know. One other thing I noticed when the pc was loading. I don't know if it has always been like this or even if it makes a difference. But on the BIOS screen it's saying 'Master Disk SMART capability is Disabled. Shouldn't this really be Enabled?? Anyway, I appreciate your time on this and I'll get back to you tomorrow with the reports from your previous post, unless you advise me to do something different in the meantime. Steve
There may be a problem with your hard drive so let Chkdsk run until it finishes.

Delete the copy of Combofix you have and download a fresh one from the links below.


Link 1
Link 2
Hi Mowman

Here is the log file from the latest Combofix:

ComboFix 11-07-20.05 - Stevie 21/07/2011 0:23.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.566 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Downloaded Program Files\cpcScan.dll
c:\windows\Fonts\ARBLI___.TTF
c:\windows\Fonts\BRLNSDB.TTF
c:\windows\Fonts\BRLNSR.TTF
c:\windows\Fonts\segoeuiz.ttf
.
.
((((((((((((((((((((((((( Files Created from 2011-06-20 to 2011-07-20 )))))))))))))))))))))))))))))))
.
.
2011-07-20 23:17 . 2011-07-20 23:17 746 —-a-w- c:\windows\system32\drivers\riodrv.sys
2011-07-20 23:17 . 2011-07-20 23:17 70 —-a-w- c:\windows\system32\drivers\rawwan.sys
2011-07-20 22:48 . 2011-07-20 22:48 ——– d—–w- C:\found.000
2011-07-20 18:33 . 2011-06-20 07:57 7074640 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D941CE8A-A976-4D1E-9542-096F5599CDA2}\mpengine.dll
2011-07-19 16:35 . 2011-06-20 07:57 7074640 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-18 16:38 . 2004-08-04 05:41 404990 —-a-w- c:\windows\system32\drivers\SET39.tmp
2011-07-17 19:17 . 2010-10-19 20:51 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-07-17 18:40 . 2011-07-17 18:46 ——– d—–w- c:\program files\Microsoft Security Client
2011-07-17 16:17 . 2004-04-16 14:52 5632 —-a-w- c:\windows\InstFunc.dll
2011-07-07 21:16 . 2011-07-07 21:16 ——– d—–w- c:\program files\Supreme Auction
2011-06-30 18:14 . 2011-06-30 18:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2011-06-30 18:14 . 2011-06-30 18:14 ——– d—–w- c:\windows\Cache
2011-06-30 18:14 . 2011-06-30 18:14 ——– d—–w- c:\program files\Coupons
2011-06-30 18:14 . 2011-06-30 18:14 ——– d—–w- c:\program files\HP Photo Creations
2011-06-30 18:14 . 2011-06-30 18:14 ——– d—–w- c:\documents and settings\All Users\Application Data\HP Photo Creations
2011-06-30 18:12 . 2011-06-30 18:12 ——– d—–w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2011-06-30 18:10 . 2011-06-30 18:10 ——– d—–w- c:\program files\Common Files\HP
2011-06-30 18:08 . 2009-04-01 06:21 589824 —-a-w- c:\windows\system32\hpost_d02d.dll
2011-06-30 18:08 . 2009-04-01 06:21 713728 —-a-w- c:\windows\system32\hposwia_d02d.dll
2011-06-30 18:08 . 2009-04-01 06:21 315392 —-a-w- c:\windows\system32\hposc_d02a.dll
2011-06-30 18:08 . 2008-10-29 00:27 372736 —-a-w- c:\windows\system32\hppldcoi.dll
2011-06-30 18:08 . 2008-10-29 00:27 309760 —-a-w- c:\windows\system32\difxapi.dll
2011-06-26 12:12 . 2011-06-26 12:11 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-06-25 11:01 . 2011-07-06 18:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-25 11:01 . 2011-07-16 21:12 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-25 11:01 . 2011-07-06 18:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-24 23:54 . 2011-06-24 23:54 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-24 16:16 . 2011-06-24 16:16 ——– d—–w- c:\program files\ESET
2011-06-22 20:19 . 2011-04-14 13:01 24376 —-a-w- c:\program files\Mozilla Firefox\components\Scriptff.dll
2011-06-22 20:06 . 2011-06-22 20:06 ——– d—–w- c:\windows\system32\wbem\Repository
2011-06-22 20:05 . 2011-06-24 23:58 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2011-06-22 20:05 . 2011-06-22 20:05 ——– d—–w- c:\program files\NOS
2011-06-22 20:02 . 2011-06-22 20:02 ——– d—–w- c:\program files\Common Files\Adobe AIR
2011-06-22 17:01 . 2011-06-22 17:01 53816 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-26 12:11 . 2010-05-04 06:19 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-06-02 14:02 . 2002-09-19 19:26 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-05-02 15:31 . 2003-03-03 14:57 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2002-09-19 19:26 151552 —-a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2002-09-19 19:26 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07 . 2002-09-19 19:26 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-04-26 11:07 . 2002-09-19 19:26 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-04-25 16:11 . 2006-06-23 10:33 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2002-09-19 19:26 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2002-09-19 19:26 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2005-09-21 16:38 . 2005-09-21 16:38 677 -c–a-w- c:\program files\lxce.vbs
2011-04-14 13:01 . 2011-06-22 20:19 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-22 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-04-05 1195408]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2009-05-19 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-05 15:18 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"$INSTDIR\\FlvDetector.exe"= c:\\Program Files\\FlashGet Network\\FlashGet 3\\FlvDetector.exe
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3659:UDP"= 3659:UDP:PS3
"6000:UDP"= 6000:UDP:ps3
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
.
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [22/06/2011 18:01 53816]
R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [15/07/2004 11:11 11264]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [29/04/2011 00:27 84200]
R1 RapportCerberus_26762;RapportCerberus_26762;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\26762\RapportCerberus_26762.sys [16/06/2011 23:02 57144]
R1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [22/06/2011 18:01 66360]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [22/06/2011 18:01 158904]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [10/10/2006 12:53 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [27/02/2007 11:39 67656]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [08/05/2010 11:33 203280]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [29/04/2011 00:27 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [29/04/2011 00:27 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [29/04/2011 00:28 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [29/04/2011 00:27 141792]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [22/06/2011 18:01 870200]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [09/03/2011 13:30 92592]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [29/04/2011 00:27 56064]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [29/04/2011 00:27 314088]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [29/04/2011 00:27 88736]
S2 gupdate1ca8478a9da0ea4;Google Update Service (gupdate1ca8478a9da0ea4);c:\program files\Google\Update\GoogleUpdate.exe [24/12/2009 10:08 133104]
S3 cpuz134;cpuz134;\??\c:\program files\CPUID\PC Wizard 2010\pcwiz_x32.sys –> c:\program files\CPUID\PC Wizard 2010\pcwiz_x32.sys [?]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [22/12/2009 03:31 18136]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [17/07/2010 11:57 36640]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [24/12/2009 10:08 133104]
S3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtport.sys –> c:\windows\system32\DRIVERS\lgbtport.sys [?]
S3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbus.sys –> c:\windows\system32\DRIVERS\lgbtbus.sys [?]
S3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmodem.sys –> c:\windows\system32\DRIVERS\lgvmodem.sys [?]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [16/11/2010 01:10 267568]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15/01/2010 13:49 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [29/04/2011 00:27 88736]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [29/04/2011 00:27 84488]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [19/09/2002 20:26 14336]
S3 PSSDK42;PSSDK42;c:\windows\system32\drivers\pssdk42.sys [20/02/2011 18:31 38976]
S3 PSSDKLBF;PSSDKLBF;c:\windows\system32\drivers\pssdklbf.sys [20/02/2011 18:31 53312]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [16/02/2006 16:51 12872]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [15/08/2010 15:33 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [15/08/2010 15:33 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [15/08/2010 15:33 123648]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\drivers\ss_bserd.sys [15/08/2010 15:33 100224]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\drivers\sscebus.sys [15/08/2010 15:33 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\drivers\sscemdfl.sys [15/08/2010 15:33 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\drivers\sscemdm.sys [15/08/2010 15:33 123648]
S3 STAC97NA;SigmaTel 3D Environmental Audio;c:\windows\system32\drivers\stac97na.sys [01/01/1980 296179]
S3 STAC97NH;STAC97NH;c:\windows\system32\drivers\stac97nh.sys [01/01/1980 231983]
S4 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [22/12/2009 03:31 95568]
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [17/07/2010 11:57 217088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-07-18 16:53 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-20 c:\windows\Tasks\ConfigExec.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2010-11-16 00:09]
.
2011-07-19 c:\windows\Tasks\DataUpload.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2010-11-16 00:09]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-24 09:08]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-24 09:08]
.
2011-07-20 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 14:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.co.uk/
IE: Download All By FlashGet3 - c:\documents and settings\Stevie\Application Data\FlashGetBHO\GetAllUrl.htm
IE: Download By FlashGet3 - c:\documents and settings\Stevie\Application Data\FlashGetBHO\GetUrl.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Stevie\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
Trusted Zone: bitsoup.org\www
Trusted Zone: motive.com\pbttbc.bt
TCP: DhcpNameServer = 192.168.0.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20110428084740
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Supreme Auction_is1 - c:\program files\Supreme Auction\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-21 00:39
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,24,77,29,7c,89,b8,d0,47,b0,6f,23,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,24,77,29,7c,89,b8,d0,47,b0,6f,23,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(812)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(3932)
c:\windows\system32\WININET.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-07-21 00:49:21 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-20 23:49
ComboFix2.txt 2011-07-19 19:13
.
Pre-Run: 10,600,382,464 bytes free
Post-Run: 11,900,534,784 bytes free
.
- - End Of File - - BC94413DE60A99E194B97AC812E68802


And here the latest log file from Malwarebytes

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7216

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

21/07/2011 18:47:35
mbam-log-2011-07-21 (18-47-35).txt

Scan type: Quick scan
Objects scanned: 163336
Time elapsed: 25 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Thanks
Steve
The Combofix log is looking much better now and MBAM has run as well which is good.Are you still having problems?

Will run ESET next



Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Hi The pc itself seems to be running a bit quicker but it still wants to do a chkdsk each time I start. I've tried to turn on McAfee just a few minutes ago and it's still turning itself off. Do you think I should do a reinstall of it to see if that makes a difference? The graphics aspect of the pc seem to have really slowed down too. An example of this is my screen saver which shows some photos on a slide. As it comes across the screen to show the next slide, it takes ages…as if it's in slow motion. It's the same when I go onto websites. Any pics on websites seem to take a bit to show. It's almost like I'm back on the old dial up connection and your waiting for the pics to download bit by bit. Do you think it's maybe a graphics card issue or is it just maybe time to get rid of this 7 year old pc and invest in something a little more upt o date lol. Here is the log file from the Eset scanner: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=5552c01c1ddc184b9be8ac07ac421492 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-07-21 10:41:13 # local_time=2011-07-21 11:41:13 (+0000, GMT Daylight Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=5121 16777190 100 75 5926528 24803840 0 0 # compatibility_mode=5891 16776869 42 87 97070 8154778 0 0 # compatibility_mode=8192 67108863 100 0 2351716 2351716 0 0 # scanned=81961 # found=0 # cleaned=0 # scan_time=4173

Do you think it's maybe a graphics card issue or is it just maybe time to get rid of this 7 year old pc and invest in something a little more upto date lol.

I don't really know anything about graphics cards,we will try a couple of things and if not sorted it would be best to ask in the hardware forum,maybe it is time for a new machine.

I think it might be best to run chkdsk with the r switch just in case you have some disc errors that could be compounding the problem
Here's how:
1 Go to Start
2 Click on Run
3 Type in the white box
chkdsk /r
4 Click on OK
Note (the space between the k and the / is essential)
you will get a warning in a black box, this is Ok just
type in
Y
press the enter key
Note (this will allow the utility to run, when you restart your machine)
7 Close down your computer (a full shutdown, not a sleep/hibernate/standby) wait 30 seconds with a blank black screen and then restart your machine.
Note Chkdsk will analyse your hard drive, detect any bad sectors and fix them automatically without intervention by you. Chkdsk will take an hour or sometimes considerably longer to complete so allow plenty of time for this procedure especially as you may need to run it several times until it has completed all 5 passes on two consecutive runs without finding or fixing any problems.






Next


1 Go to Start
2 Click on Run
3 Type in the white box

sfc /scannow




You have two antivirus installed on this computer,can you please uninstall one of them.


After doing the above,please open OTL,under Extra registry check use safe list and click run scan,post both logs
Hi Mowman I run the chckdsk and it was fine. The blue screen came up and it said that the HDD was clean and didn't need to do anything. I moved onto the next thing you said. Typed in sfc /scannow. It started to scan and after about 1 munite told me 'Files that are required for windows to run properly must be copied to the dll cache. Insert windows xp home edition cd rom now. So, I've got a problem. The pc came with XP pre loaded and thus I don't have a cd-rom for it. I'm going to do a search on packard bell to see if I can download it or something as I've still got the XP key they gave me with the pc. If you come back on before I've reposted, let me know if you have any ideas how to get around this. Cheers Steve

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI