OTL.Text
OTL logfile created on: 4/10/2010 2:44:25 AM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
958.00 Mb Total Physical Memory | 443.00 Mb Available Physical Memory | 46.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.38 Gb Total Space | 143.49 Gb Free Space | 63.95% Space Free | Partition Type: NTFS
Drive D: | 8.49 Gb Total Space | 0.42 Gb Free Space | 4.98% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SHAMAN
Current User Name: HP_Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/04/10 02:43:55 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\OTL.exe
PRC - [2010/02/21 05:03:12 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2009/12/09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009/08/07 17:15:06 | 000,311,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
PRC - [2009/08/07 17:15:06 | 000,242,048 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2008/05/26 23:19:14 | 000,123,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/11/12 00:11:12 | 000,237,568 | ---- | M] (Digital Interactive Systems Corporation, Inc.) -- C:\Program Files\DISC\DiscGui.exe
PRC - [2005/11/12 00:11:04 | 001,064,960 | ---- | M] (Digital Interactive Systems Corporation) -- C:\Program Files\DISC\DISCover.exe
PRC - [2005/11/12 00:10:00 | 000,061,440 | ---- | M] (Digital Interactive Systems Corporation, Inc.) -- C:\Program Files\DISC\DISCUpdateMgr.exe
PRC - [2005/11/12 00:10:00 | 000,049,152 | ---- | M] (Digital Interactive Systems Corporation, Inc.) -- C:\Program Files\DISC\DiscStreamHub.exe
PRC - [2005/08/03 03:19:16 | 000,077,312 | ---- | M] (Microsoft) -- C:\WINDOWS\arpwrmsg.exe
PRC - [2005/08/03 03:19:16 | 000,058,880 | ---- | M] (Microsoft) -- C:\WINDOWS\arservice.exe
PRC - [2005/05/03 22:07:32 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
========== Modules (SafeList) ========== MOD - [2010/04/10 02:43:55 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\OTL.exe
========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- -- (McSysmon)
SRV - File not found [Unknown | Stopped] -- -- (McShield)
SRV - [2009/12/09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2009/08/07 17:15:06 | 000,242,048 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2005/08/03 03:19:16 | 000,058,880 | ---- | M] (Microsoft) [Auto | Running] -- C:\WINDOWS\arservice.exe -- (ARSVC)
========== Driver Services (SafeList) ========== DRV - [2009/12/02 15:23:40 | 000,149,040 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2009/11/11 11:14:44 | 000,214,664 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2009/11/11 11:14:44 | 000,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2009/11/11 11:14:44 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - [2009/11/11 11:14:44 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2009/11/11 11:14:12 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2008/07/09 10:51:43 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2008/07/09 10:51:43 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2008/04/13 14:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 12:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2006/01/24 21:15:00 | 003,535,520 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006/01/23 18:41:52 | 004,145,152 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/12/12 17:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PS2.sys -- (Ps2)
DRV - [2005/10/20 19:01:56 | 001,095,009 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2005/07/29 19:11:04 | 000,012,928 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005/07/29 19:11:02 | 000,034,048 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005/06/17 09:33:40 | 000,872,064 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2005/03/09 16:53:00 | 000,036,352 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2004/08/03 17:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktopIE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktopIE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktopIE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktopIE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktopIE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktopIE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktopIE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktopIE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.yahoo.com/ [binary data]
IE - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://att.my.yahoo.com/IE - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/03/30 15:53:49 | 000,000,000 | ---D | M]
[2006/08/22 12:41:50 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2006/08/22 12:41:54 | 000,000,680 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.png
[2006/08/22 12:41:53 | 000,001,150 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\answers.png
[2006/08/22 12:41:53 | 000,000,356 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.png
[2006/08/22 12:41:53 | 000,000,210 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay.gif
[2006/08/22 12:41:54 | 000,001,076 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.gif
[2006/08/22 12:41:53 | 000,000,088 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo.gif
O1 HOSTS File: ([2009/10/23 12:20:21 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - Reg Error: Value error. File not found
O2 - BHO: (MSN Toolbar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AT&&T Toolbar) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\Program Files\ATTToolbar\ATTToolbar.dll (AT&T)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\..\Toolbar\WebBrowser: (AT&&T Toolbar) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\Program Files\ATTToolbar\ATTToolbar.dll (AT&T)
O4 - HKLM..\Run: [AlwaysReady Power Message APP] C:\WINDOWS\arpwrmsg.exe (Microsoft)
O4 - HKLM..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
O4 - HKLM..\Run: [DiscUpdateManager] C:\Program Files\DISC\DISCUpdateMgr.exe (Digital Interactive Systems Corporation, Inc.)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\Pin.lnk = C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\Jamison\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
O7 - HKU\S-1-5-21-2857700694-1443985124-1909224973-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: link = [binary data]
O9 - Extra Button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm File not found
O9 - Extra 'Tools' menuitem : Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533}
https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B}
https://wimpro2.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1237159575078 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O21 - SSODL: fobomomop - {4ac59a72-1316-41be-a95d-94c060a5d880} - CLSID or File not found.
O21 - SSODL: hukepados - {e4da5a15-7068-4ef5-938d-e3e1348aedca} - CLSID or File not found.
O21 - SSODL: pibupajid - {a3d12b6f-a959-4e60-bc0f-4b9eca005110} - CLSID or File not found.
O21 - SSODL: sidezehik - {00e98634-4093-4607-94a7-9fdcedb99f65} - CLSID or File not found.
O21 - SSODL: yapivobin - {d8c1eb09-2cd0-409b-a637-0346af10e278} - CLSID or File not found.
O22 - SharedTaskScheduler: {00e98634-4093-4607-94a7-9fdcedb99f65} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {a3d12b6f-a959-4e60-bc0f-4b9eca005110} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {d8c1eb09-2cd0-409b-a637-0346af10e278} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {e4da5a15-7068-4ef5-938d-e3e1348aedca} - kupuhivus - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator.SHAMAN\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator.SHAMAN\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/05 21:46:49 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2006/03/09 19:01:32 | 000,000,100 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/27 15:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2004/04/30 07:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ]
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/04/10 02:43:21 | 000,561,664 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\OTL.exe
[2010/04/09 20:37:25 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/04/09 20:28:08 | 000,756,776 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\OneCareCleanUp.exe
[2010/04/08 09:00:23 | 000,000,000 | ---D | C] -- C:\WINSSLog
[2010/04/07 15:46:17 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live Safety Center
[2010/04/05 19:07:00 | 011,862,896 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\mssefullinstall-x86fre-en-us-xp.exe
[2010/04/05 17:47:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2010/04/04 18:01:30 | 000,000,000 | ---D | C] -- C:\Program Files\Registry Easy
[2010/04/03 16:57:14 | 005,294,087 | ---- | C] (McAfee Inc.) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\fakealertstinger.exe
[2010/04/03 14:09:13 | 004,792,552 | ---- | C] (Hewlett-Packard Development Company, L.P. ) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\sp40926.exe
[2010/03/30 15:53:24 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Toolbar
[2010/03/30 15:53:14 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/03/30 15:53:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/03/30 15:52:34 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Toolbar Installer
[2010/03/30 15:52:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/03/30 15:51:53 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/03/30 15:51:52 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/03/30 15:51:52 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/03/18 19:32:21 | 000,079,816 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys
[2010/03/18 19:32:21 | 000,040,552 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfesmfk.sys
[2010/03/18 19:32:21 | 000,035,272 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfebopk.sys
[2010/03/18 19:29:48 | 000,034,248 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdk.sys
[2010/03/18 19:25:24 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/03/18 19:25:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/03/18 19:13:47 | 000,214,664 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfehidk.sys
[2009/12/21 23:29:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\SACore
[2009/03/26 22:32:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/02/01 17:18:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2008/11/17 22:56:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\AOL
[2008/02/11 12:30:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008/02/01 03:17:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2005/09/24 11:49:16 | 000,012,288 | ---- | C] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\Fonts\RandFont.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\*.tmp files -> C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/04/10 02:45:00 | 000,000,428 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{2525D098-410A-478D-96E8-348ADA3C3107}.job
[2010/04/10 02:43:55 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\OTL.exe
[2010/04/10 02:24:00 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2010/04/10 00:05:00 | 000,000,330 | ---- | M] () -- C:\WINDOWS\tasks\Service Manager.job
[2010/04/09 22:36:11 | 000,000,444 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{11F92D12-0906-4BBA-840D-8B6AACB5482B}.job
[2010/04/09 20:42:38 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/09 20:37:26 | 000,000,831 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/04/09 20:37:14 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/04/09 20:37:01 | 011,862,896 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\mssefullinstall-x86fre-en-us-xp.exe
[2010/04/09 20:34:42 | 000,000,246 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.dat
[2010/04/09 20:32:12 | 000,043,531 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/04/09 20:31:27 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/04/09 20:31:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/04/09 20:31:15 | 1005,113,344 | -HS- | M] () -- C:\hiberfil.sys
[2010/04/09 20:30:41 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\ntuser.dat
[2010/04/09 20:30:41 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\ntuser.ini
[2010/04/09 20:28:25 | 000,756,776 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\OneCareCleanUp.exe
[2010/04/09 20:07:04 | 004,471,272 | -H-- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Local Settings\Application Data\IconCache.db
[2010/04/09 19:09:10 | 000,185,856 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\McaffeE_HANGUP_DURING_SCAN.doc
[2010/04/09 19:08:21 | 000,185,856 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Mcaf.doc
[2010/04/08 20:30:32 | 000,000,017 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\fakealertstinger.opt
[2010/04/08 07:50:22 | 000,317,952 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Virus Malware Protection Center-4-8-2012.doc
[2010/04/07 22:24:47 | 000,076,800 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Microsoft Trojan Removal - 4-7-2010.doc
[2010/04/07 21:06:10 | 000,002,187 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/04/05 19:22:07 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Microsoft Security Essentials Download.doc
[2010/04/05 17:44:37 | 000,136,704 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Uninstall Window Live OneCare safety scanner.doc
[2010/04/05 17:24:23 | 000,354,304 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\SHAMAN OneCare Safety Scanner Results.doc
[2010/04/04 18:18:14 | 000,000,042 | ---- | M] () -- C:\WINDOWS\System32\RegistryEasy.lie
[2010/04/04 18:17:13 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Registry Easy SS No.doc
[2010/04/04 18:01:32 | 000,000,758 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\Registry Easy.lnk
[2010/04/04 13:33:21 | 000,189,440 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Stinger Hangup.doc
[2010/04/03 16:57:26 | 005,294,087 | ---- | M] (McAfee Inc.) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\fakealertstinger.exe
[2010/04/03 14:59:12 | 000,014,508 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\HP_Chat_Session_3_Apr_2010_14_58.html
[2010/04/03 14:09:32 | 004,792,552 | ---- | M] (Hewlett-Packard Development Company, L.P. ) -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\sp40926.exe
[2010/04/03 14:03:10 | 000,565,248 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Error Message-jutizowliDOTdll.doc
[2010/04/02 19:06:18 | 000,567,808 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\RUNDLL-Error.doc
[2010/04/02 17:54:11 | 000,567,808 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\RUNDLL-e.doc
[2010/04/01 22:15:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/30 22:27:40 | 000,522,292 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/30 22:27:40 | 000,439,300 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/03/30 22:27:40 | 000,076,200 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/03/30 22:27:04 | 000,201,728 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\WD 1TB My Passport Essential SE Portable Hard Drive USB 2.doc
[2010/03/30 15:53:06 | 000,000,688 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/03/30 15:01:29 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/03/20 16:42:42 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/03/12 18:21:58 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\*.tmp files -> C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/04/09 20:42:38 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/09 20:37:25 | 000,000,831 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/04/09 20:23:23 | 1005,113,344 | -HS- | C] () -- C:\hiberfil.sys
[2010/04/09 19:09:10 | 000,185,856 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\McaffeE_HANGUP_DURING_SCAN.doc
[2010/04/09 19:08:21 | 000,185,856 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Mcaf.doc
[2010/04/08 07:50:22 | 000,317,952 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Virus Malware Protection Center-4-8-2012.doc
[2010/04/07 22:24:46 | 000,076,800 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Microsoft Trojan Removal - 4-7-2010.doc
[2010/04/05 19:22:07 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Microsoft Security Essentials Download.doc
[2010/04/05 19:04:36 | 000,000,017 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\fakealertstinger.opt
[2010/04/05 17:44:36 | 000,136,704 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Uninstall Window Live OneCare safety scanner.doc
[2010/04/05 16:39:16 | 000,354,304 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\SHAMAN OneCare Safety Scanner Results.doc
[2010/04/04 18:18:14 | 000,000,042 | ---- | C] () -- C:\WINDOWS\System32\RegistryEasy.lie
[2010/04/04 18:17:13 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Registry Easy SS No.doc
[2010/04/04 18:01:32 | 000,000,758 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Desktop\Registry Easy.lnk
[2010/04/04 13:33:20 | 000,189,440 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\Stinger Hangup.doc
[2010/04/03 14:59:11 | 000,014,508 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\HP_Chat_Session_3_Apr_2010_14_58.html
[2010/04/02 17:54:45 | 000,567,808 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\RUNDLL-Error.doc
[2010/04/02 17:54:10 | 000,567,808 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\RUNDLL-e.doc
[2010/03/30 22:27:03 | 000,201,728 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\My Documents\WD 1TB My Passport Essential SE Portable Hard Drive USB 2.doc
[2010/01/19 18:38:01 | 000,001,447 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\hirstarts notes.txt
[2009/12/30 14:55:55 | 000,000,400 | ---- | C] () -- C:\WINDOWS\g_pjspur491.ini
[2009/12/25 21:38:10 | 000,038,537 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Application Data\Comma Separated Values (Windows).ADR
[2009/12/17 23:53:27 | 002,714,456 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/09/18 22:24:27 | 000,000,178 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Application Data\wklnhst.dat
[2009/09/06 01:05:07 | 000,065,536 | ---- | C] () -- C:\WINDOWS\ICE_JNIRegistry.dll
[2009/08/21 13:27:56 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/23 13:31:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\str.sys
[2009/04/26 17:06:33 | 005,767,168 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\ntuser.dat
[2009/03/21 13:53:29 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\PUTTY.RND
[2009/03/17 11:59:18 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\BongoSDK.10.v40.dll
[2009/03/15 21:44:21 | 000,230,607 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2009/03/15 21:26:19 | 000,058,819 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
[2009/03/15 21:26:11 | 000,002,244 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Application Data\HPSU_48BitScanUpdate.log
[2009/03/15 11:55:29 | 000,000,075 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\LuResult.txt
[2009/03/14 22:10:16 | 000,372,736 | ---- | C] () -- C:\WINDOWS\System32\hpzidi01.dll
[2009/03/14 22:10:15 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2009/03/14 20:20:04 | 000,000,146 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\Local Settings\Application Data\fusioncache.dat
[2009/03/14 20:20:00 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\ntuser.dat.LOG
[2009/03/14 20:20:00 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\HP_Administrator.SHAMAN\ntuser.ini
[2008/11/22 15:37:13 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2008/09/29 06:03:48 | 016,777,270 | ---- | C] () -- C:\Program Files\uv horned helm.bmp
[2008/09/29 06:02:01 | 016,777,270 | ---- | C] () -- C:\Program Files\UV celt helm.bmp
[2008/09/24 22:34:01 | 000,002,670 | ---- | C] () -- C:\WINDOWS\ACROREAD.INI
[2008/03/31 19:47:57 | 000,008,934 | ---- | C] () -- C:\WINDOWS\hpdj3840.ini
[2008/02/28 19:28:23 | 000,001,571 | ---- | C] () -- C:\WINDOWS\Faxcpp1.ini
[2008/02/28 19:28:23 | 000,000,422 | ---- | C] () -- C:\WINDOWS\Faxcpp.ini
[2007/12/19 22:33:00 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/04/17 22:06:02 | 000,000,107 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2007/01/12 03:22:41 | 000,000,091 | ---- | C] () -- C:\WINDOWS\NDH2007.INI
[2007/01/12 03:21:54 | 000,000,032 | ---- | C] () -- C:\WINDOWS\INSTAL~4.INI
[2007/01/10 08:44:26 | 001,457,024 | R--- | C] () -- C:\WINDOWS\System32\SSCProt.dll
[2006/11/22 13:34:17 | 000,000,000 | ---- | C] () -- C:\Program Files\Common Files\err.log
[2006/10/25 18:10:52 | 000,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/08/08 16:19:31 | 000,002,238 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006/07/06 20:59:56 | 000,001,774 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/06/25 15:14:00 | 000,000,227 | ---- | C] () -- C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/06/25 15:13:51 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/06/15 22:02:13 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2006/06/15 21:51:22 | 000,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006/05/27 12:42:31 | 000,000,233 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2006/05/27 09:52:00 | 000,262,144 | ---- | C] () -- C:\Documents and Settings\All Users\NTUSER.DAT
[2006/05/27 09:52:00 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2006/03/09 19:32:45 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/03/09 19:09:37 | 000,028,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys
[2006/03/09 19:04:32 | 000,014,314 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2006/03/09 19:04:24 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2006/03/09 19:02:05 | 000,000,031 | ---- | C] () -- C:\WINDOWS\Quicken.ini
[2006/03/09 18:59:25 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/03/09 18:48:59 | 000,000,108 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2006/03/09 18:47:32 | 000,000,698 | ---- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/03/09 18:32:59 | 000,003,904 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/03/09 18:31:58 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006/03/09 18:28:30 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/03/09 18:28:29 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/03/09 18:28:29 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006/03/09 18:28:29 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/03/09 18:28:29 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006/03/09 18:28:29 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006/03/09 18:28:29 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006/03/09 18:27:04 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/03/09 18:08:19 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2005/12/09 17:03:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/08/06 01:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/08/03 03:19:16 | 000,050,176 | ---- | C] () -- C:\WINDOWS\armcex.dll
[2004/08/10 00:00:00 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2004/08/10 00:00:00 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/10 00:00:00 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2004/08/10 00:00:00 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/10 00:00:00 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
[2004/07/26 10:51:38 | 000,000,560 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/07 02:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
< End of report >