Second Half of ComboFix and HJT Log
C:\temp\HP_WebRelease\Setup\Old_1_thank_you.bmp
C:\temp\HP_WebRelease\Setup\opthelp1025.rtf
C:\temp\HP_WebRelease\Setup\opthelp1028.rtf
C:\temp\HP_WebRelease\Setup\opthelp1029.rtf
C:\temp\HP_WebRelease\Setup\opthelp1030.rtf
C:\temp\HP_WebRelease\Setup\opthelp1031.rtf
C:\temp\HP_WebRelease\Setup\opthelp1032.rtf
C:\temp\HP_WebRelease\Setup\opthelp1033.rtf
C:\temp\HP_WebRelease\Setup\opthelp1034.rtf
C:\temp\HP_WebRelease\Setup\opthelp1035.rtf
C:\temp\HP_WebRelease\Setup\opthelp1036.rtf
C:\temp\HP_WebRelease\Setup\opthelp1037.rtf
C:\temp\HP_WebRelease\Setup\opthelp1038.rtf
C:\temp\HP_WebRelease\Setup\opthelp1040.rtf
C:\temp\HP_WebRelease\Setup\opthelp1041.rtf
C:\temp\HP_WebRelease\Setup\opthelp1042.rtf
C:\temp\HP_WebRelease\Setup\opthelp1043.rtf
C:\temp\HP_WebRelease\Setup\opthelp1044.rtf
C:\temp\HP_WebRelease\Setup\opthelp1045.rtf
C:\temp\HP_WebRelease\Setup\opthelp1046.rtf
C:\temp\HP_WebRelease\Setup\opthelp1049.rtf
C:\temp\HP_WebRelease\Setup\opthelp1053.rtf
C:\temp\HP_WebRelease\Setup\opthelp1054.rtf
C:\temp\HP_WebRelease\Setup\opthelp1055.rtf
C:\temp\HP_WebRelease\Setup\opthelp2052.rtf
C:\temp\HP_WebRelease\Setup\panostandalone\panostandalone.cab
C:\temp\HP_WebRelease\Setup\panostandalone\panostandalone.msi
C:\temp\HP_WebRelease\Setup\photogallery\PhotoGallery.cab
C:\temp\HP_WebRelease\Setup\photogallery\PhotoGallery.msi
C:\temp\HP_WebRelease\Setup\plk\ie6setup.exe
C:\temp\HP_WebRelease\Setup\product\1000.msi
C:\temp\HP_WebRelease\Setup\product\1033.mst
C:\temp\HP_WebRelease\Setup\product\1034.mst
C:\temp\HP_WebRelease\Setup\product\1036.mst
C:\temp\HP_WebRelease\Setup\product\1046.mst
C:\temp\HP_WebRelease\Setup\product\1100.msi
C:\temp\HP_WebRelease\Setup\product\1200.msi
C:\temp\HP_WebRelease\Setup\product\1300.msi
C:\temp\HP_WebRelease\Setup\product\1310.msi
C:\temp\HP_WebRelease\Setup\product\1400.msi
C:\temp\HP_WebRelease\Setup\product\1500.msi
C:\temp\HP_WebRelease\Setup\product\1600.msi
C:\temp\HP_WebRelease\Setup\product\2100.msi
C:\temp\HP_WebRelease\Setup\product\2150.msi
C:\temp\HP_WebRelease\Setup\product\2170.msi
C:\temp\HP_WebRelease\Setup\product\2200.msi
C:\temp\HP_WebRelease\Setup\product\2300.msi
C:\temp\HP_WebRelease\Setup\product\2350.msi
C:\temp\HP_WebRelease\Setup\product\2400.msi
C:\temp\HP_WebRelease\Setup\product\2500.cab
C:\temp\HP_WebRelease\Setup\product\2500.msi
C:\temp\HP_WebRelease\Setup\product\2600.cab
C:\temp\HP_WebRelease\Setup\product\2600.msi
C:\temp\HP_WebRelease\Setup\product\2700.cab
C:\temp\HP_WebRelease\Setup\product\2700.msi
C:\temp\HP_WebRelease\Setup\product\4100.msi
C:\temp\HP_WebRelease\Setup\product\4105.msi
C:\temp\HP_WebRelease\Setup\product\4200.msi
C:\temp\HP_WebRelease\Setup\product\5500.msi
C:\temp\HP_WebRelease\Setup\product\6100.msi
C:\temp\HP_WebRelease\Setup\product\6200.msi
C:\temp\HP_WebRelease\Setup\product\7200.cab
C:\temp\HP_WebRelease\Setup\product\7200.msi
C:\temp\HP_WebRelease\Setup\product\7300.cab
C:\temp\HP_WebRelease\Setup\product\7300.msi
C:\temp\HP_WebRelease\Setup\product\7400.cab
C:\temp\HP_WebRelease\Setup\product\7400.msi
C:\temp\HP_WebRelease\Setup\ProductContext\productcontext.cab
C:\temp\HP_WebRelease\Setup\ProductContext\productcontext.msi
C:\temp\HP_WebRelease\Setup\ptb\ie6setup.exe
C:\temp\HP_WebRelease\Setup\QFolder\QFolder.msi
C:\temp\HP_WebRelease\Setup\Readme\readme.msi
C:\temp\HP_WebRelease\Setup\RedBox\Data1.cab
C:\temp\HP_WebRelease\Setup\RedBox\Redbox.msi
C:\temp\HP_WebRelease\Setup\releases\Enterprise\setup\hponac.dat
C:\temp\HP_WebRelease\Setup\RulesEngine.dll
C:\temp\HP_WebRelease\Setup\rus\ie6setup.exe
C:\temp\HP_WebRelease\Setup\Scan\Data1.cab
C:\temp\HP_WebRelease\Setup\Scan\Scan.msi
C:\temp\HP_WebRelease\Setup\ScannerCopy\Data1.cab
C:\temp\HP_WebRelease\Setup\ScannerCopy\ScannerCopy.msi
C:\temp\HP_WebRelease\Setup\Sherlock\1028.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1029.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1030.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1031.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1032.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1033.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1034.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1035.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1036.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1038.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1040.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1041.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1042.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1043.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1044.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1045.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1046.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1049.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1053.mst
C:\temp\HP_WebRelease\Setup\Sherlock\1055.mst
C:\temp\HP_WebRelease\Setup\Sherlock\2052.mst
C:\temp\HP_WebRelease\Setup\Sherlock\HPSystemDiagnostics.msi
C:\temp\HP_WebRelease\Setup\SkinsHP1\SkinsHP1.cab
C:\temp\HP_WebRelease\Setup\SkinsHP1\SkinsHP1.msi
C:\temp\HP_WebRelease\Setup\sve\ie6setup.exe
C:\temp\HP_WebRelease\Setup\Tour\1000tour.cab
C:\temp\HP_WebRelease\Setup\Tour\1000tour.msi
C:\temp\HP_WebRelease\Setup\Tour\1300tour.msi
C:\temp\HP_WebRelease\Setup\Tour\1310tour.cab
C:\temp\HP_WebRelease\Setup\Tour\1310tour.msi
C:\temp\HP_WebRelease\Setup\Tour\2100tour.cab
C:\temp\HP_WebRelease\Setup\Tour\2100tour.msi
C:\temp\HP_WebRelease\Setup\Tour\2150tour.cab
C:\temp\HP_WebRelease\Setup\Tour\2150tour.msi
C:\temp\HP_WebRelease\Setup\Tour\2170tour.cab
C:\temp\HP_WebRelease\Setup\Tour\2170tour.msi
C:\temp\HP_WebRelease\Setup\Tour\2200tour.cab
C:\temp\HP_WebRelease\Setup\Tour\2200tour.msi
C:\temp\HP_WebRelease\Setup\Tour\23_24_2500tour.cab
C:\temp\HP_WebRelease\Setup\Tour\23_24_2500tour.msi
C:\temp\HP_WebRelease\Setup\Tour\4100tour.cab
C:\temp\HP_WebRelease\Setup\Tour\4100tour.msi
C:\temp\HP_WebRelease\Setup\Tour\4200tour.cab
C:\temp\HP_WebRelease\Setup\Tour\4200tour.msi
C:\temp\HP_WebRelease\Setup\Tour\5500tour.cab
C:\temp\HP_WebRelease\Setup\Tour\5500tour.msi
C:\temp\HP_WebRelease\Setup\Tour\6100tour.cab
C:\temp\HP_WebRelease\Setup\Tour\6100tour.msi
C:\temp\HP_WebRelease\Setup\trayapp\TrayApp.cab
C:\temp\HP_WebRelease\Setup\trayapp\TrayApp.msi
C:\temp\HP_WebRelease\Setup\trk\ie6setup.exe
C:\temp\HP_WebRelease\Setup\UnloadIntent\Data1.cab
C:\temp\HP_WebRelease\Setup\UnloadIntent\Unload.msi
C:\temp\HP_WebRelease\Setup\usbready.exe
C:\temp\HP_WebRelease\Setup\webreg\WebReg.cab
C:\temp\HP_WebRelease\Setup\webreg\WebReg.msi
C:\temp\HP_WebRelease\Setup\wis\Win2K_XP\instmsi.exe
C:\temp\HP_WebRelease\Setup\wis\Win9x\instmsi.exe
C:\temp\HP_WebRelease\svc\drivers\com_lang\hpfmom12.hl_
C:\temp\HP_WebRelease\svc\drivers\com_lang\hpofax08.dll
C:\temp\HP_WebRelease\svc\drivers\com_lang\hpqish09.dat
C:\temp\HP_WebRelease\svc\drivers\com_lang\hpzl3212.dl_
C:\temp\HP_WebRelease\svc\drivers\com_lang\hpzr3212.dl_
C:\temp\HP_WebRelease\svc\drivers\com_lang\hpzrm312.dl_
C:\temp\HP_WebRelease\svc\drivers\win9x_me\hpoupdrm.inf
C:\temp\HP_WebRelease\svc\drivers\win9x_me\hpzrm112.dl_
C:\temp\HP_WebRelease\svc\drivers\win9x_me\usbmon.dll
C:\temp\HP_WebRelease\svc\drivers\win9x_me\usbprint.sys
C:\temp\HP_WebRelease\sve\drivers\com_lang\hpqish09.dat
C:\temp\HP_WebRelease\tls704d.dll
C:\temp\HP_WebRelease\trk\drivers\com_lang\hpqish09.dat
C:\temp\HP_WebRelease\tur\drivers\com_lang\hpfmom12.hl_
C:\temp\HP_WebRelease\tur\drivers\com_lang\hpofax08.dll
C:\temp\HP_WebRelease\tur\drivers\com_lang\hpqish09.dat
C:\temp\HP_WebRelease\tur\drivers\com_lang\hpzl3212.dl_
C:\temp\HP_WebRelease\tur\drivers\com_lang\hpzr3212.dl_
C:\temp\HP_WebRelease\tur\drivers\com_lang\hpzrm312.dl_
C:\temp\HP_WebRelease\tur\drivers\win9x_me\hpoupdrm.inf
C:\temp\HP_WebRelease\tur\drivers\win9x_me\hpzrm112.dl_
C:\temp\HP_WebRelease\tur\drivers\win9x_me\usbmon.dll
C:\temp\HP_WebRelease\tur\drivers\win9x_me\usbprint.sys
C:\temp\HP_WebRelease\usbhub.sys
C:\temp\HP_WebRelease\usbmon.dll
C:\temp\HP_WebRelease\usbprint.sys
C:\temp\HP_WebRelease\util\AIO\hpopdi05.exe
C:\temp\HP_WebRelease\util\AIO\hpopin05.exe
C:\temp\HP_WebRelease\util\CCC\1606fix.reg
C:\temp\HP_WebRelease\util\CCC\240075.exe
C:\temp\HP_WebRelease\util\CCC\270615USAM.EXE
C:\temp\HP_WebRelease\util\CCC\afs2k_install.bat
C:\temp\HP_WebRelease\util\CCC\afs2k_remove.bat
C:\temp\HP_WebRelease\util\CCC\afsinst.exe
C:\temp\HP_WebRelease\util\CCC\chs\Q283787_W2K_SP3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\cht\Q283787_W2K_SP3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\csy\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\dan\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\deu\Q283787_W2K_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\ell\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\enu\Q283787_W2K_SP3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\enu\WindowsXP-KB822603-x86-ENU.exe
C:\temp\HP_WebRelease\util\CCC\esm\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\esn\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\esn\WindowsXP-KB822603-x86-ESN.exe
C:\temp\HP_WebRelease\util\CCC\fin\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\fra\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\fra\WindowsXP-KB822603-x86-FRA.exe
C:\temp\HP_WebRelease\util\CCC\hposcrlr.bat
C:\temp\HP_WebRelease\util\CCC\hun\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\ita\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\jpn\Q283787_W2K_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\kor\Q283787_W2K_SP3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\MediaSizeSettings.exe
C:\temp\HP_WebRelease\util\CCC\nld\Q283787_W2K_SP3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\nob\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\plk\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\ptb\Q283787_W2K_SP3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\ptb\WindowsXP-KB822603-x86-PTB.exe
C:\temp\HP_WebRelease\util\CCC\Q256858_W2K_SP1_x86.EXE
C:\temp\HP_WebRelease\util\CCC\rus\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\sve\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\trk\Q283787_w2k_sp3_x86.EXE
C:\temp\HP_WebRelease\util\CCC\Uninstall.bat
C:\temp\HP_WebRelease\util\CCC\Uninstall_L1.bat
C:\temp\HP_WebRelease\util\CCC\Uninstall_L2.bat
C:\temp\HP_WebRelease\util\CCC\Uninstall_L3.bat
C:\temp\HP_WebRelease\util\CCC\Uninstall_L4.bat
C:\temp\HP_WebRelease\util\cfgmgr32.dll
C:\temp\HP_WebRelease\util\common\hpfpdi12.exe
C:\temp\HP_WebRelease\util\common\hpqisc09.exe
C:\temp\HP_WebRelease\util\common\hpzghl12.exe
C:\temp\HP_WebRelease\util\common\hpzpin12.exe
C:\temp\HP_WebRelease\util\setupapi.dll
C:\temp\HP_WebRelease\util\Support_Tools\MSI_Install_Cleanup\Win2000\msicuu.exe
C:\temp\HP_WebRelease\util\Support_Tools\MSI_Install_Cleanup\Win9x\msicu.exe
C:\temp\NU\Manual\NU2002.PDF
C:\temp\NU\NU\_INST32I.EX_
C:\temp\NU\NU\_ISDel.exe
C:\temp\NU\NU\_ISNU.DLL
C:\temp\NU\NU\_Setup.dll
C:\temp\NU\NU\_sys1.cab
C:\temp\NU\NU\_sys1.hdr
C:\temp\NU\NU\_user1.cab
C:\temp\NU\NU\_user1.hdr
C:\temp\NU\NU\ACTEXT.DLL
C:\temp\NU\NU\ALARM.DLL
C:\temp\NU\NU\ATL.DLL
C:\temp\NU\NU\BACKLOG.EXE
C:\temp\NU\NU\BLUEROCK.BMP
C:\temp\NU\NU\BOOKMARK.OCX
C:\temp\NU\NU\CENTHELP.CNT
C:\temp\NU\NU\CHKASSC.DLL
C:\temp\NU\NU\CLOUDS.BMP
C:\temp\NU\NU\COFRGTST.DLL
C:\temp\NU\NU\COFSTST.DLL
C:\temp\NU\NU\CONDDTST.DLL
C:\temp\NU\NU\COREGTST.DLL
C:\temp\NU\NU\CORSCTST.DLL
C:\temp\NU\NU\CPUUTIL.DLL
C:\temp\NU\NU\CSH.DLL
C:\temp\NU\NU\DAO\DAO2535.TLB
C:\temp\NU\NU\DAO\DAO350.DLL
C:\temp\NU\NU\DAO\MSJET35.DLL
C:\temp\NU\NU\DAO\MSJINT35.DLL
C:\temp\NU\NU\DAO\MSJTER35.DLL
C:\temp\NU\NU\DAO\MSRD2X35.DLL
C:\temp\NU\NU\DAO\VBAJET32.DLL
C:\temp\NU\NU\DAO\VBAR332.DLL
C:\temp\NU\NU\DATA.TAG
C:\temp\NU\NU\data1.cab
C:\temp\NU\NU\data1.hdr
C:\temp\NU\NU\DDENGSC.DLL
C:\temp\NU\NU\DISKEDIT.EXE
C:\temp\NU\NU\DISKEDIT.HLP
C:\temp\NU\NU\DISKEDIT.ICO
C:\temp\NU\NU\DISKEDIT.PID
C:\temp\NU\NU\DSCANATL.DLL
C:\temp\NU\NU\EVENTLG.DLL
C:\temp\NU\NU\EXCLUDE.REG
C:\temp\NU\NU\EXPSRV.DLL
C:\temp\NU\NU\HELPNT\NU.CNT
C:\temp\NU\NU\HELPNT\NU.HLP
C:\temp\NU\NU\HTRKPAGE.DLL
C:\temp\NU\NU\ICMP.DLL
C:\temp\NU\NU\IMAGE32.EXE
C:\temp\NU\NU\IMAGE32.HLP
C:\temp\NU\NU\INSDiag.dll
C:\temp\NU\NU\lang.dat
C:\temp\NU\NU\layout.bin
C:\temp\NU\NU\LNKCOM.DLL
C:\temp\NU\NU\LOGBOOK.CNT
C:\temp\NU\NU\LOGBOOK.EXE
C:\temp\NU\NU\LOGBOOK.HLP
C:\temp\NU\NU\LOGGER.EXE
C:\temp\NU\NU\LOGGERPS.DLL
C:\temp\NU\NU\LUCB.DLL
C:\temp\NU\NU\MAGELLAN.CSS
C:\temp\NU\NU\MARBLE_B.BMP
C:\temp\NU\NU\marker9x.txt
C:\temp\NU\NU\markerNT.txt
C:\temp\NU\NU\MDSCAN.DLL
C:\temp\NU\NU\METAL_A.BMP
C:\temp\NU\NU\METAL_P.BMP
C:\temp\NU\NU\MFC42.DLL
C:\temp\NU\NU\MOONROCK.BMP
C:\temp\NU\NU\MSSHLIB\_INST32I.EX_
C:\temp\NU\NU\MSSHLIB\_Setup.dll
C:\temp\NU\NU\MSSHLIB\_sys1.cab
C:\temp\NU\NU\MSSHLIB\_sys1.hdr
C:\temp\NU\NU\MSSHLIB\_user1.cab
C:\temp\NU\NU\MSSHLIB\_user1.hdr
C:\temp\NU\NU\MSSHLIB\DATA.TAG
C:\temp\NU\NU\MSSHLIB\data1.cab
C:\temp\NU\NU\MSSHLIB\data1.hdr
C:\temp\NU\NU\MSSHLIB\lang.dat
C:\temp\NU\NU\MSSHLIB\layout.bin
C:\temp\NU\NU\MSSHLIB\os.dat
C:\temp\NU\NU\MSSHLIB\Setup.exe
C:\temp\NU\NU\MSSHLIB\SETUP.INI
C:\temp\NU\NU\MSSHLIB\setup.ins
C:\temp\NU\NU\MSSHLIB\setup.iss
C:\temp\NU\NU\MSSHLIB\setup.lid
C:\temp\NU\NU\MSVCIRT.DLL
C:\temp\NU\NU\MSVCP60.DLL
C:\temp\NU\NU\MSVCRT.DLL
C:\temp\NU\NU\MSVCRT40.DLL
C:\temp\NU\NU\MYSTERY.BMP
C:\temp\NU\NU\N32DLIST.DLL
C:\temp\NU\NU\N32DLSTU.DLL
C:\temp\NU\NU\NCOMCAT.DLL
C:\temp\NU\NU\NCOMPARE.EXE
C:\temp\NU\NU\NCOMPARE.HLP
C:\temp\NU\NU\NDD.EXE
C:\temp\NU\NU\NDD.HLP
C:\temp\NU\NU\NDD32.DAT
C:\temp\NU\NU\NDD32.EXE
C:\temp\NU\NU\NDD32.HLP
C:\temp\NU\NU\NDD32.NT
C:\temp\NU\NU\NDDENG.DLL
C:\temp\NU\NU\NDDENGNT.DLL
C:\temp\NU\NU\NDRVEX.DLL
C:\temp\NU\NU\NINTROBJ.DLL
C:\temp\NU\NU\NORTON.EXE
C:\temp\NU\NU\NPComSvr.DLL
C:\temp\NU\NU\NPDRIVER.SYS
C:\temp\NU\NU\NPROTECT.EXE
C:\temp\NU\NU\NPROTECT.VXD
C:\temp\NU\NU\NREGEDIT.EXE
C:\temp\NU\NU\NREGEDIT.HLP
C:\temp\NU\NU\NREGXPRT.EXE
C:\temp\NU\NU\NSMPLOGR.DLL
C:\temp\NU\NU\NTABSHT.DLL
C:\temp\NU\NU\NU.CNT
C:\temp\NU\NU\NU.HLP
C:\temp\NU\NU\NUABOUT.DLL
C:\temp\NU\NU\NUCD.EXE
C:\temp\NU\NU\NUCOM\REGWDOC.EXE
C:\temp\NU\NU\NUFONT.DLL
C:\temp\NU\NU\NUGLOSS.HLP
C:\temp\NU\NU\NUINTRO.DLL
C:\temp\NU\NU\NULIVE.DLL
C:\temp\NU\NU\NUMISC.DLL
C:\temp\NU\NU\NUPLUGIN.DLL
C:\temp\NU\NU\NURESC.DLL
C:\temp\NU\NU\nusess.txt
C:\temp\NU\NU\NUSPLASH.DLL
C:\temp\NU\NU\NUSPLOBJ.DLL
C:\temp\NU\NU\NUTHK16.DLL
C:\temp\NU\NU\NUTHK32.DLL
C:\temp\NU\NU\NWCALLS.DLL
C:\temp\NU\NU\NWDENG.DLL
C:\temp\NU\NU\OAK.BMP
C:\temp\NU\NU\OLEAUT32.DLL
C:\temp\NU\NU\OLEPRO32.DLL
C:\temp\NU\NU\OPTWIZ.DAT
C:\temp\NU\NU\OPTWIZ.EXE
C:\temp\NU\NU\OPTWIZ.HLP
C:\temp\NU\NU\OPTWIZ.NT
C:\temp\NU\NU\os.dat
C:\temp\NU\NU\PAPER_G.BMP
C:\temp\NU\NU\partial.reg
C:\temp\NU\NU\PGNORTON.DLL
C:\temp\NU\NU\README.TXT
C:\temp\NU\NU\REGEXT.DLL
C:\temp\NU\NU\REGOPT.DLL
C:\temp\NU\NU\REGSVR32.EXE
C:\temp\NU\NU\REGTRK.EXE
C:\temp\NU\NU\REGTRK.HLP
C:\temp\NU\NU\RESCUE\_INST32I.EX_
C:\temp\NU\NU\RESCUE\_rscinst.dll
C:\temp\NU\NU\RESCUE\_Setup.dll
C:\temp\NU\NU\RESCUE\_sys1.cab
C:\temp\NU\NU\RESCUE\_sys1.hdr
C:\temp\NU\NU\RESCUE\_user1.cab
C:\temp\NU\NU\RESCUE\_user1.hdr
C:\temp\NU\NU\RESCUE\centhelp.cnt
C:\temp\NU\NU\RESCUE\CHOICE.COM
C:\temp\NU\NU\RESCUE\CloneDlg.exe
C:\temp\NU\NU\RESCUE\config.sys
C:\temp\NU\NU\RESCUE\CPUID.EXE
C:\temp\NU\NU\RESCUE\DATA.TAG
C:\temp\NU\NU\RESCUE\data1.cab
C:\temp\NU\NU\RESCUE\data1.hdr
C:\temp\NU\NU\RESCUE\Defloc.dat
C:\temp\NU\NU\RESCUE\lang.dat
C:\temp\NU\NU\RESCUE\layout.bin
C:\temp\NU\NU\RESCUE\NAVDEF32.DLL
C:\temp\NU\NU\RESCUE\NAVSDK.VXD
C:\temp\NU\NU\RESCUE\NAVSDR32.DLL
C:\temp\NU\NU\RESCUE\NUGloss.HLP
C:\temp\NU\NU\RESCUE\os.dat
C:\temp\NU\NU\RESCUE\RCOMCAT.dll
C:\temp\NU\NU\RESCUE\readme.txt
C:\temp\NU\NU\RESCUE\RescDL.dll
C:\temp\NU\NU\RESCUE\Rescue.dll
C:\temp\NU\NU\RESCUE\RESCUE.EXE
C:\temp\NU\NU\RESCUE\Rescue32.cnt
C:\temp\NU\NU\RESCUE\Rescue32.exe
C:\temp\NU\NU\RESCUE\RESCUE32.HLP
C:\temp\NU\NU\RESCUE\RESCUED.HLP
C:\temp\NU\NU\RESCUE\RESCUEDV.EXE
C:\temp\NU\NU\RESCUE\RESCUEN.EXE
C:\temp\NU\NU\RESCUE\REXCLUDE.REG
C:\temp\NU\NU\RESCUE\RNavOem.dll
C:\temp\NU\NU\RESCUE\RSCFMT.DLL
C:\temp\NU\NU\RESCUE\RShell.EXE
C:\temp\NU\NU\RESCUE\RShelln.exe
C:\temp\NU\NU\RESCUE\RShellv.EXE
C:\temp\NU\NU\RESCUE\S32FATL.DLL
C:\temp\NU\NU\RESCUE\S32GUIL.DLL
C:\temp\NU\NU\RESCUE\S32KRNLL.DLL
C:\temp\NU\NU\RESCUE\S32SYSL.DLL
C:\temp\NU\NU\RESCUE\S32UTILL.DLL
C:\temp\NU\NU\RESCUE\ScsiDll.Dll
C:\temp\NU\NU\RESCUE\Setup.exe
C:\temp\NU\NU\RESCUE\SETUP.INI
C:\temp\NU\NU\RESCUE\setup.ins
C:\temp\NU\NU\RESCUE\setup.iss
C:\temp\NU\NU\RESCUE\setup.lid
C:\temp\NU\NU\RESCUE\SYMKRNLL.DLL
C:\temp\NU\NU\RESCUE\SYMKRNLL.VXD
C:\temp\NU\NU\RESCUE\TKKE16L.DLL
C:\temp\NU\NU\RESCUE\TKKE32L.DLL
C:\temp\NU\NU\RESCUE\TROUBLE.TXT
C:\temp\NU\NU\RESCUE\VIEW.COM
C:\temp\NU\NU\RNAPH.DLL
C:\temp\NU\NU\RSCAN.DLL
C:\temp\NU\NU\RSUNDO.DLL
C:\temp\NU\NU\S32DMAPL.DLL
C:\temp\NU\NU\S32FATL.DLL
C:\temp\NU\NU\S32GUIL.DLL
C:\temp\NU\NU\S32KRNLL.DLL
C:\temp\NU\NU\S32MAILL.DLL
C:\temp\NU\NU\S32MTHKL.DLL
C:\temp\NU\NU\S32NPTL.DLL
C:\temp\NU\NU\S32RASU.DLL
C:\temp\NU\NU\S32STAT.DLL
C:\temp\NU\NU\S32SYSL.DLL
C:\temp\NU\NU\S32UTILL.DLL
C:\temp\NU\NU\SALTHK16.DLL
C:\temp\NU\NU\SALTHK32.DLL
C:\temp\NU\NU\SD32.EXE
C:\temp\NU\NU\SD32.HLP
C:\temp\NU\NU\SD32ENG.DLL
C:\temp\NU\NU\SD32VXD.VXD
C:\temp\NU\NU\SDNT\_INST32I.EX_
C:\temp\NU\NU\SDNT\_ISDEL.EXE
C:\temp\NU\NU\SDNT\_SETUP.DLL
C:\temp\NU\NU\SDNT\_sys1.cab
C:\temp\NU\NU\SDNT\_user1.cab
C:\temp\NU\NU\SDNT\DATA.TAG
C:\temp\NU\NU\SDNT\data1.cab
C:\temp\NU\NU\SDNT\lang.dat
C:\temp\NU\NU\SDNT\layout.bin
C:\temp\NU\NU\SDNT\os.dat
C:\temp\NU\NU\SDNT\SETUP.EXE
C:\temp\NU\NU\SDNT\SETUP.INI
C:\temp\NU\NU\SDNT\setup.ins
C:\temp\NU\NU\SDNT\setup.iss
C:\temp\NU\NU\SDNT\setup.lid
C:\temp\NU\NU\SEARCH.AVI
C:\temp\NU\NU\SECACL.DLL
C:\temp\NU\NU\SENSOR32.DLL
C:\temp\NU\NU\SEP_2.GIF
C:\temp\NU\NU\Setup.exe
C:\temp\NU\NU\SETUP.INI
C:\temp\NU\NU\setup.ins
C:\temp\NU\NU\setup.lid
C:\temp\NU\NU\SETVER.PID
C:\temp\NU\NU\SI32.EXE
C:\temp\NU\NU\SI32.HLP
C:\temp\NU\NU\SIDESYM2.GIF
C:\temp\NU\NU\SIREGIST.EXE
C:\temp\NU\NU\sku.reg
C:\temp\NU\NU\SLATE.BMP
C:\temp\NU\NU\SMARTDRV\SMARTDRV.TXT
C:\temp\NU\NU\SMARTDRV\SMARTUPD.EXE
C:\temp\NU\NU\SPACER.GIF
C:\temp\NU\NU\SPDSTART.EXE
C:\temp\NU\NU\SPDSTART.VXD
C:\temp\NU\NU\STONE_G.BMP
C:\temp\NU\NU\STYLE.CSS
C:\temp\NU\NU\SUNSET.BMP
C:\temp\NU\NU\SUPPORT.CNT
C:\temp\NU\NU\SUPPORT.HLP
C:\temp\NU\NU\SYMCOM.DLL
C:\temp\NU\NU\SYMGUNDO.DLL
C:\temp\NU\NU\SYMKRNLL.DLL
C:\temp\NU\NU\SYMKRNLL.VXD
C:\temp\NU\NU\SYMMIGR8.DLL
C:\temp\NU\NU\SYMMONIT.VXD
C:\temp\NU\NU\SYMPRREC.DLL
C:\temp\NU\NU\SYMUNDO.EXE
C:\temp\NU\NU\SYMUNDPS.DLL
C:\temp\NU\NU\SYSCHECK.EXE
C:\temp\NU\NU\SYSCHECK.HLP
C:\temp\NU\NU\SYSDOC32.EXE
C:\temp\NU\NU\SYSDOC32.HLP
C:\temp\NU\NU\SYSINFO.VXD
C:\temp\NU\NU\SYSNT\ATL.DLL
C:\temp\NU\NU\TKKE16L.DLL
C:\temp\NU\NU\TKKE32L.DLL
C:\temp\NU\NU\TRKENG.DLL
C:\temp\NU\NU\UE32.DAT
C:\temp\NU\NU\UE32.EXE
C:\temp\NU\NU\UE32.HLP
C:\temp\NU\NU\UE32.NT
C:\temp\NU\NU\UEBMP32.DLL
C:\temp\NU\NU\UNERASE.EXE
C:\temp\NU\NU\UNERASE.HLP
C:\temp\NU\NU\UNFORMAT.EXE
C:\temp\NU\NU\UNFORMAT.HLP
C:\temp\NU\NU\URLCACHE.DLL
C:\temp\NU\NU\USHELLEX.DLL
C:\temp\NU\NU\VSENSOR.VXD
C:\temp\NU\NU\WALNUT.BMP
C:\temp\NU\NU\WATERFAL.BMP
C:\temp\NU\NU\WDSCAN.EXE
C:\temp\NU\NU\WFSHELEX.DLL
C:\temp\NU\NU\WINDOC.DAT
C:\temp\NU\NU\WINDOC.EXE
C:\temp\NU\NU\WINDOC.HLP
C:\temp\NU\NU\WINDOC.NT
C:\temp\NU\NU\WINSOX16.DLL
C:\temp\NU\NU\WINSOX32.DLL
C:\temp\NU\NU\WIPEDLL.DLL
C:\temp\NU\NU\WIPEINFO.DAT
C:\temp\NU\NU\WIPEINFO.EXE
C:\temp\NU\NU\WIPEINFO.HLP
C:\temp\NU\NU\WIPEINFO.NT
C:\temp\NU\NU\WIPINFNT.EXE
C:\temp\NU\NU\WIPINFNT.HLP
C:\temp\NU\NU\WIPINFNT.NT
C:\temp\NU\NUSetup.exe
C:\temp\NU\README.TXT
C:\temp\NU\Support\ComCtl32\50comupd.exe
C:\temp\NU\Support\EDisk\Disk1.img
C:\temp\NU\Support\EDisk\Disk2.img
C:\temp\NU\Support\EDisk\NED.exe
C:\temp\NU\Support\EDisk\readme.txt
C:\temp\NU\Support\Integrat\NMAIN.EXE
C:\temp\NU\Support\Integrat\SYMEXCPT.DLL
C:\temp\NU\Support\LiveReg\lrsetup.exe
C:\temp\NU\Support\LUpdate\lusetup.exe
C:\temp\NU\Support\sevinst\sevinst.exe
C:\temp\NU\Support\Wintdist\wintdist.exe
C:\WINDOWS\system32\bdir
C:\WINDOWS\system32\bdir\ZAXR429I26.exe
C:\WINDOWS\system32\dbl
C:\WINDOWS\system32\mpull
C:\WINDOWS\system32\mpull\MAG32015x.exe
C:\WINDOWS\system32\tec
C:\WINDOWS\system32\tec\tvgrem041.exe
C:\WINDOWS\system32\towl
C:\WINDOWS\system32\towl\SAT4510net.exe
C:\WINDOWS\system32\wTR02
C:\WINDOWS\system32\wTR02\wTR022328.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MTLMNT55
-------\Service_mtlmnt55
((((((((((((((((((((((((( Files Created from 2008-08-01 to 2008-09-01 )))))))))))))))))))))))))))))))
.
2008-08-30 16:49 . 2008-08-31 01:36 1,476 --a------ C:\WINDOWS\wininit.ini
2008-08-30 11:59 . 2008-08-30 11:59 <DIR> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-08-30 11:14 . 2008-08-30 11:24 134,358,357 --a------ C:\PC-GAMES - Risk 2 (Tested).zip
2008-08-30 11:02 . 2008-08-30 11:02 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-08-30 10:50 . 2008-08-30 23:28 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-30 10:42 . 2008-08-30 10:42 <DIR> d-------- C:\WINDOWS\Sun
2008-08-30 10:42 . 2008-08-30 12:13 <DIR> d-------- C:\Documents and Settings\Stan\Application Data\LimeWire
2008-08-30 10:41 . 2008-08-30 10:41 <DIR> d-------- C:\Program Files\Java
2008-08-30 10:41 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-30 10:40 . 2008-08-30 10:40 <DIR> d-------- C:\Program Files\Common Files\Java
2008-08-21 20:06 . 2008-08-21 20:35 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-08-17 18:44 . 2008-08-17 18:44 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-08-13 22:08 . 2008-05-01 10:30 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-08 18:51 . 1999-04-23 22:22 528,384 --a------ C:\WINDOWS\KODAKIMG.EXE
2008-08-08 18:51 . 1999-04-23 22:22 114,688 --a------ C:\WINDOWS\KODAKPRV.EXE
2008-08-08 16:49 . 2008-08-08 16:49 <DIR> d-------- C:\Program Files\TWAIN Working Group
2008-08-08 16:49 . 1998-02-06 22:37 299,520 --a------ C:\WINDOWS\uninst.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-30 16:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-30 16:08 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-11 18:26 --------- d-----w C:\Documents and Settings\Stan\Application Data\WeatherBug
2006-03-23 00:31 28,856 ----a-w C:\Documents and Settings\Stan\Application Data\GDIPFONTCACHEV1.DAT
2005-12-30 06:34 2 --shatr C:\WINDOWS\winstart.bat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-01-13 18:05 69632]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 18:14 8491008]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 18:14 81920]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 13:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"nwiz"="nwiz.exe" [2007-10-04 18:14 1626112 C:\WINDOWS\system32\nwiz.exe]
C:\Documents and Settings\Stan\Start Menu\Programs\Startup\
Toolbar.lnk.disabled [2006-01-11 01:11:10 734]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Service Manager.lnk.disabled [2006-01-17 09:04:27 577]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifcaxuu]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Steam"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RegRun WinBait"=C:\WINDOWS\winbait.exe
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"kgsystray"=g:\Program Files\Kuma Games\kgsystray\Kumawar_tray.exe
"KW2SysTray"=G:\Program Files\Kuma Games\KW2SysTray\Kumawar_tray.exe
"pccguide.exe"="E:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=nwiz.exe /install
"QuickTime Task"="E:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"G:\\Program Files\\Firefly Studios\\Stronghold 2\\Stronghold2.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc8fefc3-fa4a-11dc-a98e-000476cea4ef}]
\Shell\AutoRun\command - L:\LaunchU3.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-01 09:08:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\snmp.exe
C:\Program Files\Speed Disk\NOPDB.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
C:\WINDOWS\system32\devldr32.exe
.
**************************************************************************
.
Completion time: 2008-09-01 9:11:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-01 13:11:17
ComboFix2.txt 2008-09-01 12:27:16
Pre-Run: 4,220,796,928 bytes free
Post-Run: 4,164,157,440 bytes free
1507 --- E O F --- 2008-08-14 21:21:05
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:11:59 AM, on 9/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Stan\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ptdprolog.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - Startup: Toolbar.lnk.disabled
O4 - Global Startup: Service Manager.lnk.disabled
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} -
http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) -
https://remote.superiorink.com/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1135197102328
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {E1AD733A-8259-49EF-980F-C5AB69F12D06} (RunKuma Control) -
http://www.kumagames.com/runkuma.cab
O20 - Winlogon Notify: iifcaxuu - C:\WINDOWS\
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - E:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed Disk\nopdb.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - E:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - E:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - E:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
--
End of file - 6341 bytes