Windows XP My computer so messed up my post disappeared

Joined
Nov 24, 2006
Messages
15
Reaction score
0
Computer very messed up, still desperate for help.

Hello. I just described everything and when I went to preview, the site said I wasn't logged in, even though I was, and deleted my post. I need help, please, so here it is again. Computer has gotten very slow, used to be very fast, I have verizon fios (fiber optic internet). Suspect invasion, but am not able to find it with Zone Labs Internet Security, AVG antivirus, spybot, spyware doctor, or panda activescan. Ran a hijack this log, but don't know how to interpret. Upon starting, something called AiO software tries to install but is missing source code and wants me to insert CD, so I keep hitting cancel until the last message I receive is Error Code 1607, or 1706, I'm sorry, I'm tired and it's 5 am where I am. Windows explorer keeps having to close from all programs. Forefox will no longer open up no matter what I do and it is still definitely on my computer. Pages freeze constantly, and task manager won't always open. I use my security software always, and I have spent the last 4 days and nights trying to figure out what the problem is. Everything I need to access is stored with firefox, not IE, which I am forced to use right now. Here is my computer info:
HP Pavilion a1430n
AMD dual processors 3800
250 GB hard drive
4 GB possible RAM, 1 GB currently installed
GE force 6150 graphics
MS XP Media center 2005 OS

I'm frustrated, exhausted, and will be extremely grateful for help. I'm also praying that my post doesn't disappear again, because I'm too tired to write this again. Thank you very much for your time.
Cindy
 
Last edited:

V_R

¯\_(ツ)_/¯
Moderator
Joined
Jan 31, 2005
Messages
13,572
Reaction score
1,888
Welcome to PCR. :)

AIO (All in one) software is hp related. Have you uninstalled anything recently, if so what?

Have a read of this and see if it helps you any. :)

You can copy and paste you HijackThis log here for us to have a look at if you wish.

From what you have said it sounds like you have more than one problem on that pc.
 
Joined
Nov 24, 2006
Messages
15
Reaction score
0
Thank you V_R and TriplexDread for writing back. I have copied and pasted the hijack this log that just ran when I turned on the computer. I did delete a program that I thought I did not need, so much for me thinking. When I discovered that I might still need that program I tried system restore several times to earlier dates, but no luck. I am very grateful for your help.
Cindy

Logfile of HijackThis v1.99.1
Scan saved at 11:05:10 AM, on 11/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\arservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\DISC\DiscUpdateMgr.exe
C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Registry Mechanic\regmech.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Hijack This\HijackThis.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\WINDOWS\system32\msiexec.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MICROS~4\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\regmech.exe /H
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Hijack This\HijackThis.exe /startupscan
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files\iMacros\imacros.dll (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.1.1067.14/WinSSWebAgent.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1149394242859
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1149394233203
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
Joined
Nov 24, 2006
Messages
15
Reaction score
0
results of rootkit-thanks for the download recommendations

The rootkit scan said there are 383 instances, please see below. I am not going to delete anything without advice. Thank you for the thread on useful programs, and I was glad to see I all ready had most of the security recommendations, but I did add Rootkit and Backlight, and I plan on adding Spysweeper after reading the thread. Cindy

HKLM\SECURITY\Policy\Secrets\SAC* 3/9/2006 10:15 AM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 3/9/2006 10:15 AM 0 bytes Key name contains embedded nulls (*)
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates 11/24/2006 12:23 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup 11/24/2006 12:24 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpasbase.vdm 11/24/2006 12:17 PM 328.20 KB Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.vdm 11/24/2006 12:17 PM 8.70 KB Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 11/24/2006 12:17 PM 2.45 MB Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Default 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Default\mpasbase.vdm 11/24/2006 12:17 PM 328.20 KB Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Default\mpasdlta.vdm 11/24/2006 12:17 PM 8.70 KB Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Default\MpEngine.dll 11/24/2006 12:17 PM 2.45 MB Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Updates 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{1B43D593-5899-4A43-89FA-D74C0B14DFFC} 11/24/2006 12:23 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{1B43D593-5899-4A43-89FA-D74C0B14DFFC}\mpasbase.vdm 11/24/2006 12:23 PM 1.54 MB Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{1B43D593-5899-4A43-89FA-D74C0B14DFFC}\mpasdlta.vdm 11/24/2006 12:23 PM 700.32 KB Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{1B43D593-5899-4A43-89FA-D74C0B14DFFC}\mpengine.dll 11/24/2006 12:23 PM 2.44 MB Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\LocalCopy 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Quarantine 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Scans 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Scans\History 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Scans\History\Results 11/24/2006 12:20 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Scans\History\Results\Resource 11/24/2006 12:20 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Scans\History\Results\Resource\{FD5A7D97-9050-467D-AFED-4EE4A462E09F} 11/24/2006 12:20 PM 5.01 KB Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-11242006-121754.log 11/24/2006 12:24 PM 2.03 KB Hidden from Windows API.
C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defender.lnk 11/24/2006 12:17 PM 966 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Desktop\WindowsDefender.msi 11/24/2006 12:16 PM 4.95 MB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Desktop\WindowsDefender.msi:Zone.Identifier 11/24/2006 12:16 PM 26 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Favorites\Computer Problems\F-Secure Blacklight Rootkit Elimination Technology.url 11/24/2006 12:11 PM 180 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Favorites\Computer Problems\RootkitRevealer v1.71.url 11/24/2006 12:11 PM 322 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Favorites\Computer Problems\RootkitRevealer v1.71.url:favicon 11/24/2006 12:11 PM 3.55 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows Defender 11/24/2006 12:18 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker 11/24/2006 12:18 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{F62799D0-3F68-4494-BBEB-1E4CB1350F82} 11/24/2006 12:18 PM 69.94 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\120x240_IE7_banner_101606[1].swf 11/24/2006 12:15 PM 20.41 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\ADSAdClient31[2].htm 11/24/2006 12:23 PM 729 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\ADSAdClient31[3].htm 11/24/2006 12:13 PM 728 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\arrow[1].gif 11/24/2006 11:52 AM 834 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\arrow_px_up[1].gif 11/24/2006 12:13 PM 53 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\background_transparent[1].gif 11/24/2006 11:52 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\bodyBackground[1].gif 11/24/2006 11:50 AM 79 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\btn_addtocart[1].gif 11/24/2006 12:01 PM 1.01 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\common[1].css 11/24/2006 11:58 AM 36.96 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\company_logo[1].gif 11/24/2006 11:50 AM 3.46 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\couponx_01[1].gif 11/24/2006 11:58 AM 21.21 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\couponx_02[1].gif 11/24/2006 11:58 AM 8.85 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\cybertrust_new[1].gif 11/24/2006 11:59 AM 3.34 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\details[1].htm 11/24/2006 12:23 PM 41.17 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\EC.HP.A1632X[1].jpg 11/24/2006 12:01 PM 1.60 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\EC.MXT.F01E200[1].jpg 11/24/2006 12:01 PM 2.39 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\EC.MXT.R01E060[1].jpg 11/24/2006 12:01 PM 2.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\EC.PAN.VDRD250.FL.KIB[1].jpg 11/24/2006 12:01 PM 2.55 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\EC.SGE.ST3320833ETRK[1].jpg 11/24/2006 12:01 PM 2.22 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\EC.SNN.SWRPCDVR4[1].jpg 11/24/2006 12:01 PM 1.62 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\EC.SON.CRX230AEU[1].jpg 11/24/2006 12:01 PM 1.46 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\EC.SON.DRXS50U[1].jpg 11/24/2006 12:01 PM 1.97 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\EC.VLU.755142105365[1].jpg 11/24/2006 12:01 PM 5.62 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\eluminate[1].gif 11/24/2006 12:00 PM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\eluminate[2].gif 11/24/2006 12:00 PM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\eluminate[3].gif 11/24/2006 12:01 PM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\eluminate[4].gif 11/24/2006 12:01 PM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\favicon[1].ico 11/24/2006 12:01 PM 318 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\gaicon[1].gif 11/24/2006 12:13 PM 556 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\go_search[1].gif 11/24/2006 11:59 AM 442 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\header_account[1].gif 11/24/2006 11:59 AM 1.07 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\header_bottom_right[1].gif 11/24/2006 11:59 AM 150 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\icon_call[1].gif 11/24/2006 12:00 PM 239 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\icon_question_gy[1].gif 11/24/2006 12:01 PM 139 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\js[2] 11/24/2006 12:01 PM 109 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\js[3] 11/24/2006 12:15 PM 1.33 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\js[5] 11/24/2006 12:23 PM 1.33 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\ll_ico_list[1].gif 11/24/2006 12:01 PM 496 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\main_menu[1].js 11/24/2006 11:52 AM 24.57 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\mod2[1].gif 11/24/2006 11:59 AM 4.82 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\mod3[1].gif 11/24/2006 11:59 AM 3.71 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\mod9[1].gif 11/24/2006 11:59 AM 5.37 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\MSGR_WLLIG_movieMS_072006_120x240[1].swf 11/24/2006 12:14 PM 19.60 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\redbar[1].gif 11/24/2006 11:58 AM 157 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\RootkitRevealer[1].zip 11/24/2006 11:57 AM 225.97 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\searchButton[2].gif 11/24/2006 11:52 AM 417 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\sidebanner_footer_center[2].gif 11/24/2006 11:52 AM 56 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\sidebanner_footer_left_side[1].gif 11/24/2006 11:52 AM 83 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\sidebanner_header_logo[1].gif 11/24/2006 11:52 AM 788 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\sidebanner_info_center[1].gif 11/24/2006 11:52 AM 56 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\sidebanner_info_left_side[1].gif 11/24/2006 11:52 AM 83 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\sidebanner_shadow_bottom_right_corner[1].gif 11/24/2006 11:52 AM 47 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\sidebanner_shadow_bottom_side[1].gif 11/24/2006 11:52 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\sidebanner_shadow_right_side[1].gif 11/24/2006 11:52 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\thanks_free_shipping[1].gif 11/24/2006 11:59 AM 4.82 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\try_blacklight[1].htm 11/24/2006 11:51 AM 10.75 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\WinGenuine[1].css 11/24/2006 12:14 PM 3.46 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\JDWD75ZO\yellow_1_1[1].gif 11/24/2006 12:01 PM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\0000000001_000000000000000354303[1].swf 11/24/2006 11:54 AM 18.31 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\01[1].htm 11/24/2006 12:23 PM 363 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\02_default_rtClick[1].gif 11/24/2006 12:14 PM 15.25 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\55x55_download[1].gif 11/24/2006 11:54 AM 1.72 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\arrow[1].gif 11/24/2006 11:58 AM 64 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\arrow_refine[1].gif 11/24/2006 12:01 PM 266 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\background[1].gif 11/24/2006 11:58 AM 893 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\banner2[1].gif 11/24/2006 11:58 AM 14.46 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\blacklightleft_img_147x25[1].jpg 11/24/2006 11:50 AM 2.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\bottom_roundcorners[1].gif 11/24/2006 11:59 AM 407 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\cm[1].gif 11/24/2006 11:59 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\compare_2[1].gif 11/24/2006 12:01 PM 1.14 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\compare_3[1].gif 11/24/2006 12:01 PM 2.81 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\couponx_05[1].gif 11/24/2006 11:58 AM 1.28 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\cssstyle[1].htm 11/24/2006 11:52 AM 7.31 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\DocumentDotWrite[1].js 11/24/2006 12:13 PM 48 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\EC.AO.HD320UFAPE572[1].jpg 11/24/2006 12:01 PM 1.51 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\EC.BLK.F8T012[1].jpg 11/24/2006 12:01 PM 1.68 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\EC.IMM.IDVD16DLS[1].jpg 11/24/2006 12:01 PM 6.39 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\EC.LKS.WRTP54G[1].jpg 11/24/2006 12:01 PM 1.38 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\EC.MXT.U01H320[1].jpg 11/24/2006 12:01 PM 2.49 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\EC.SON.DRX830U[1].jpg 11/24/2006 12:01 PM 1.89 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\EC.TOS.A105S4284[1].jpg 11/24/2006 12:01 PM 3.02 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\eluminate[1].gif 11/24/2006 12:01 PM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\footer_3ways[1].gif 11/24/2006 11:58 AM 6.22 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\header_bottom_right_corner[1].gif 11/24/2006 11:59 AM 408 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\iaccept[1].jpg 11/24/2006 11:54 AM 1.37 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\icon_check_gy[1].gif 11/24/2006 12:01 PM 104 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\icon_RSS_logo[1].gif 11/24/2006 11:59 AM 401 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\icon_write[1].gif 11/24/2006 12:00 PM 364 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\index[1].htm 11/24/2006 11:52 AM 10.83 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\js[1] 11/24/2006 12:23 PM 1.33 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\js[2] 11/24/2006 11:54 AM 1.33 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\js[4] 11/24/2006 12:22 PM 1.33 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\leftnavBG[1].gif 11/24/2006 11:58 AM 52 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\LegitCheckControl[1].cab 11/24/2006 12:14 PM 767.53 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\logoint[1].gif 11/24/2006 11:52 AM 4.63 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\main[1].css 11/24/2006 12:13 PM 14.88 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\mod1[1].gif 11/24/2006 11:59 AM 4.10 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\mod6[1].gif 11/24/2006 11:59 AM 4.50 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\ms_masthead_ltr[1].gif 11/24/2006 12:13 PM 947 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\nav_privacy[1].gif 11/24/2006 11:52 AM 1.35 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\notifications_sidebar[1].gif 11/24/2006 12:15 PM 4.09 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\PC.NXX.NIFD1.CN[1].jpg 11/24/2006 12:01 PM 1.93 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\PC.WBT.667208662104.CN[1].jpg 11/24/2006 12:01 PM 1.92 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\RootkitRevealer[1].gif 11/24/2006 11:54 AM 42.20 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\sidebanner_footer_left_corner[1].gif 11/24/2006 11:52 AM 45 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\sidebanner_footer_right_side[1].gif 11/24/2006 11:52 AM 83 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\sidebanner_header_info_divider_left[1].gif 11/24/2006 11:52 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\sidebanner_info_footer_divider_center[1].gif 11/24/2006 11:52 AM 49 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\sidebanner_info_footer_divider_left[2].gif 11/24/2006 11:52 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\sidebanner_info_right_side[1].gif 11/24/2006 11:52 AM 83 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\sidebanner_shadow_bottom_left_corner[1].gif 11/24/2006 11:52 AM 47 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\sort_grad_light[1].gif 11/24/2006 12:01 PM 148 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\space[1].gif 11/24/2006 11:58 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\TechNetB_masthead_ltr[1].gif 11/24/2006 11:54 AM 3.49 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\tool_createaccount[1].gif 11/24/2006 11:59 AM 1.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ROIFESPU\TopMenu[1].do 11/24/2006 12:01 PM 17.83 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\0000000001_000000000000000196560[1].gif 11/24/2006 12:15 PM 4.76 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\0000053432_000000000000000348682[1].gif 11/24/2006 12:15 PM 11.69 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\3ways_to_shop_nolinkon[1].gif 11/24/2006 11:58 AM 3.59 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\arrow_down[1].gif 11/24/2006 12:01 PM 51 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\arrow_px_up[1].gif 11/24/2006 11:54 AM 53 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\banner1x[1].gif 11/24/2006 11:58 AM 11.87 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\blacklight[2].htm 11/24/2006 11:54 AM 10.80 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\blbetac[1].exe 11/24/2006 11:52 AM 96.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\btn_compare[1].gif 11/24/2006 12:01 PM 160 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\btn_go_sm_gy[1].gif 11/24/2006 12:01 PM 392 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\btn_login_yl[1].gif 11/24/2006 11:59 AM 767 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\compare_1[1].gif 11/24/2006 12:01 PM 509 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\couponx_03[1].gif 11/24/2006 11:58 AM 213 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\couponx_06[1].jpg 11/24/2006 11:58 AM 8.40 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\download1[1].gif 11/24/2006 11:52 AM 1.24 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\EC.AO.HD160UFAPE572[1].jpg 11/24/2006 12:01 PM 1.51 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\EC.CL.VF0060[1].jpg 11/24/2006 12:01 PM 1.63 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\EC.CL.ZENV2GBBGR[1].jpg 11/24/2006 12:01 PM 3.26 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\EC.HP.DVD840RE[1].jpg 11/24/2006 12:01 PM 2.31 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\EC.HP.DVD840RI[1].jpg 11/24/2006 12:01 PM 2.42 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\EC.SON.DRU820A[1].jpg 11/24/2006 12:01 PM 2.54 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\eluminate[1].gif 11/24/2006 12:01 PM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\eluminate[2].gif 11/24/2006 12:01 PM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\footer_bg[2].gif 11/24/2006 11:59 AM 3.07 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\fsecure[1].css 11/24/2006 11:52 AM 2.73 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\home_marquee_112406[1].jpg 11/24/2006 11:59 AM 59.69 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\icon_cart[1].gif 11/24/2006 11:58 AM 355 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\icon_x_gy[1].gif 11/24/2006 12:01 PM 134 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\js[1] 11/24/2006 11:54 AM 1.33 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\js[5] 11/24/2006 12:15 PM 1.33 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\left_subbuttonbg[1].gif 11/24/2006 11:52 AM 105 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\mod5[1].gif 11/24/2006 11:59 AM 4.43 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\mod7[1].gif 11/24/2006 11:59 AM 1.50 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\nav_arrow[1].gif 11/24/2006 11:58 AM 143 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\nav_contact2[1].gif 11/24/2006 11:52 AM 1.31 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\no_image[1].jpg 11/24/2006 12:01 PM 1.65 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\PC.HP.DJD1341.CN.PCG[1].jpg 11/24/2006 12:01 PM 2.12 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\ql[1].css 11/24/2006 11:54 AM 1.46 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\sidebanner_footer_bottom_side[1].gif 11/24/2006 11:52 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\sidebanner_footer_right_corner[1].gif 11/24/2006 11:52 AM 45 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\sidebanner_header_right_corner[1].gif 11/24/2006 11:52 AM 45 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\sidebanner_header_top_side[2].gif 11/24/2006 11:52 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\sidebanner_info_footer_divider_right[1].gif 11/24/2006 11:52 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\sneakpeek_midpage_banner[1].gif 11/24/2006 11:59 AM 3.40 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\space[1].gif 11/24/2006 11:59 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\spacer[1].gif 11/24/2006 11:58 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\T7J7Q7DZ\WindowsDefender[1].msi 11/24/2006 12:15 PM 4.95 MB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\012008_finance_sm[1].gif 11/24/2006 12:01 PM 1.35 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\01[2].htm 11/24/2006 12:13 PM 5.01 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\01_default_goldbar[1].gif 11/24/2006 12:14 PM 15.53 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\38DF6AB1-13D4-409C-966D-CBE61F040027[1].gif 11/24/2006 12:13 PM 3.59 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\arrow_down[1].gif 11/24/2006 12:13 PM 53 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\arrow_up[1].gif 11/24/2006 12:01 PM 52 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\arrowRight[1].gif 11/24/2006 11:54 AM 64 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\banner1a2[1].gif 11/24/2006 11:58 AM 8.08 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\banner_blacklight_600x161[1].jpg 11/24/2006 11:54 AM 24.12 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\besure[1].gif 11/24/2006 11:54 AM 1.06 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\blbeta[1].exe 11/24/2006 11:53 AM 96.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\btn_comp_sel_yl[1].gif 11/24/2006 12:01 PM 1.06 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\campaign[1].css 11/24/2006 11:50 AM 355 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\categorystyle[1].css 11/24/2006 11:58 AM 1.17 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\details[1].htm 11/24/2006 12:13 PM 41.61 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\dotted_line[1].gif 11/24/2006 11:52 AM 69 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\EC.ELA.014633162752[1].jpg 11/24/2006 12:01 PM 3.02 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\EC.GMN.0100037800[1].jpg 11/24/2006 12:01 PM 2.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\EC.LIN.SHD16P1S[1].jpg 11/24/2006 12:01 PM 1.92 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\EC.MDG.MDED1F[1].jpg 11/24/2006 12:01 PM 4.35 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\EC.SGE.ST3500841ETRK[1].jpg 11/24/2006 12:01 PM 2.23 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\EC.SLC.11004305[1].jpg 11/24/2006 12:01 PM 1.35 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\EC.SON.DRU830A[1].jpg 11/24/2006 12:01 PM 1.93 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\eluminate[1].gif 11/24/2006 11:59 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\eluminate[2].gif 11/24/2006 12:01 PM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\gaiconbig[1].gif 11/24/2006 12:13 PM 620 bytes Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\go_search[1].gif 11/24/2006 11:59 AM 442 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\header_bottom_left[1].gif 11/24/2006 11:59 AM 636 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\header_cart[1].gif 11/24/2006 11:59 AM 1.10 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\home_styles_110706[1].css 11/24/2006 11:59 AM 1.96 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\htmlBackground[1].gif 11/24/2006 11:54 AM 97 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\icon_account[1].gif 11/24/2006 11:58 AM 221 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\icon_email[1].gif 11/24/2006 12:00 PM 357 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\icon_help[1].gif 11/24/2006 11:58 AM 359 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\icon_peekcart[1].gif 11/24/2006 12:01 PM 63 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\icon_print[1].gif 11/24/2006 12:00 PM 339 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\js[1] 11/24/2006 11:54 AM 1.33 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\js[2] 11/24/2006 11:54 AM 1.33 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\js[3] 11/24/2006 12:15 PM 1.33 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\js[4] 11/24/2006 12:22 PM 1.33 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\js[5] 11/24/2006 12:22 PM 1.33 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\logo2[1].gif 11/24/2006 11:58 AM 3.47 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\main[1].css 11/24/2006 11:54 AM 17.61 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\masthead_friend_no_ship[1].gif 11/24/2006 11:58 AM 9.79 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\menutop[1].gif 11/24/2006 11:52 AM 2.81 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\mod4[1].gif 11/24/2006 11:59 AM 4.08 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\mod8[1].gif 11/24/2006 11:59 AM 3.17 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\PC.ADO.883919002422.CN[1].jpg 11/24/2006 12:01 PM 2.58 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\pgtop-left[1].gif 11/24/2006 12:14 PM 2.66 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\pgtop-right[1].gif 11/24/2006 12:14 PM 2.30 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\ql[1].css 11/24/2006 12:13 PM 1.46 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\sidebanner_header_center[2].gif 11/24/2006 11:52 AM 56 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\sidebanner_header_info_divider_center[1].gif 11/24/2006 11:52 AM 49 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\sidebanner_header_info_divider_right[1].gif 11/24/2006 11:52 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\sidebanner_header_left_corner[1].gif 11/24/2006 11:52 AM 45 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\sidebanner_header_left_side[2].gif 11/24/2006 11:52 AM 83 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\sidebanner_header_right_side[1].gif 11/24/2006 11:52 AM 83 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\sidebanner_shadow_right_bottom_side[1].gif 11/24/2006 11:52 AM 46 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\sidebanner_shadow_right_top_corner[1].gif 11/24/2006 11:52 AM 47 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\space[1].gif 11/24/2006 11:59 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\WAGH0561585B59FA325283376FF950[1].gif 11/24/2006 11:58 AM 43 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XBE13JXH\wtsdc[1].js 11/24/2006 11:50 AM 6.04 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\NetworkService\Local Settings\Temp\MpCmdRun.log 11/24/2006 12:38 PM 506 bytes Hidden from Windows API.
C:\Program Files\Windows Defender 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\Program Files\Windows Defender\LegitLib.dll 11/24/2006 12:17 PM 449.30 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MpAsDesc.dll 11/24/2006 12:17 PM 47.77 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MpClient.dll 11/24/2006 12:17 PM 312.77 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MpCmdRun.exe 11/24/2006 12:38 PM 286.27 KB Hidden from Windows API.
C:\Program Files\Windows Defender\mpevmsg.dll 11/24/2006 12:17 PM 25.27 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MpOAv.dll 11/24/2006 12:17 PM 83.27 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MpRtMon.dll 11/24/2006 12:17 PM 676.77 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MpRtPlug.dll 11/24/2006 12:17 PM 51.27 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MpShHook.dll 11/24/2006 12:17 PM 81.27 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MpSigDwn.dll 11/24/2006 12:17 PM 136.77 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MpSoftEx.dll 11/24/2006 12:17 PM 501.77 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MpSvc.dll 11/24/2006 12:17 PM 264.77 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MSASCui.exe 11/24/2006 12:18 PM 846.27 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MsMpCom.dll 11/24/2006 12:17 PM 210.27 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MsMpEng.exe 11/24/2006 12:17 PM 13.27 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MsMpLics.dll 11/24/2006 12:17 PM 10.77 KB Hidden from Windows API.
C:\Program Files\Windows Defender\MsMpRes.dll 11/24/2006 12:17 PM 611.77 KB Hidden from Windows API.
C:\Program Files\Windows Defender\wgadef.chm 11/24/2006 12:17 PM 67.25 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP206\A0052896.RDB 11/24/2006 12:04 PM 1.73 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP206\A0052897.RDB 11/24/2006 12:05 PM 1.73 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP206\A0052898.dll 6/19/2006 3:19 PM 557.80 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP206\change.log 11/24/2006 12:05 PM 66.81 KB Visible in Windows API, but not in MFT or directory index.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP206\change.log.2 11/24/2006 12:17 PM 71.93 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP206\drivetable.txt 11/24/2006 12:17 PM 310 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\A0052899.RDB 11/24/2006 12:17 PM 1.73 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\A0052900.ini 11/24/2006 12:17 PM 718 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\A0052901.msi 11/24/2006 12:16 PM 4.95 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\A0052902.RDB 11/24/2006 12:07 PM 1.73 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\change.log.1 11/24/2006 12:22 PM 15.65 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\drivetable.txt 11/24/2006 12:23 PM 308 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\RestorePointSize 11/24/2006 12:23 PM 8 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\rp.log 11/24/2006 12:17 PM 536 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_MACHINE_SAM 11/24/2006 12:17 PM 28.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_MACHINE_SECURITY 11/24/2006 12:17 PM 56.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_MACHINE_SOFTWARE 11/24/2006 12:17 PM 30.37 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_MACHINE_SYSTEM 11/24/2006 12:17 PM 5.03 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_USER_.DEFAULT 11/24/2006 12:17 PM 636.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18 6/2/2006 12:00 PM 256.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19 11/24/2006 12:17 PM 616.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20 11/24/2006 12:17 PM 616.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2372092983-3006565277-3157113345-1008 11/24/2006 12:17 PM 4.38 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2372092983-3006565277-3157113345-500 11/22/2006 5:19 PM 1.25 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-18 6/2/2006 12:00 PM 256.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19 11/24/2006 12:17 PM 8.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20 11/24/2006 12:17 PM 8.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2372092983-3006565277-3157113345-1008 11/24/2006 12:17 PM 112.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2372092983-3006565277-3157113345-500 11/22/2006 5:19 PM 256.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\ComDb.Dat 3/9/2006 5:10 PM 33.26 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\domain.txt 11/24/2006 12:17 PM 56 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\Repository 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\Repository\$WinMgmt.CFG 11/24/2006 10:25 AM 20 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\Repository\FS 11/24/2006 12:17 PM 0 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\Repository\FS\INDEX.BTR 11/24/2006 12:01 PM 1.22 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\Repository\FS\INDEX.MAP 11/24/2006 12:17 PM 656 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\Repository\FS\MAPPING.VER 11/24/2006 12:17 PM 4 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\Repository\FS\MAPPING1.MAP 11/24/2006 12:17 PM 3.86 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\Repository\FS\MAPPING2.MAP 11/24/2006 12:05 PM 3.86 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\Repository\FS\OBJECTS.DATA 11/24/2006 12:01 PM 6.33 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP207\snapshot\Repository\FS\OBJECTS.MAP 11/24/2006 12:17 PM 3.21 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208 11/24/2006 12:23 PM 0 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\A0052903.ini 11/24/2006 12:23 PM 718 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\A0052904.RDB 11/24/2006 12:23 PM 1.73 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\A0052905.RDB 11/24/2006 12:22 PM 1.73 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\A0052906.RDB 11/24/2006 12:25 PM 1.73 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\A0052907.RDB 11/24/2006 12:28 PM 1.73 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\A0052908.RDB 11/24/2006 12:32 PM 1.73 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\change.log 11/24/2006 12:39 PM 8.74 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\RestorePointSize 11/24/2006 12:23 PM 8 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\rp.log 11/24/2006 12:23 PM 536 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot 11/24/2006 12:23 PM 0 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_MACHINE_SAM 11/24/2006 12:23 PM 28.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_MACHINE_SECURITY 11/24/2006 12:23 PM 56.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_MACHINE_SOFTWARE 11/24/2006 12:23 PM 30.41 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_MACHINE_SYSTEM 11/24/2006 12:23 PM 5.03 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_USER_.DEFAULT 11/24/2006 12:23 PM 636.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18 11/24/2006 12:23 PM 256.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19 11/24/2006 12:23 PM 616.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20 11/24/2006 12:23 PM 616.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2372092983-3006565277-3157113345-1008 11/24/2006 12:23 PM 4.38 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2372092983-3006565277-3157113345-500 11/24/2006 12:23 PM 1.25 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-18 11/24/2006 12:23 PM 256.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19 11/24/2006 12:23 PM 8.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20 11/24/2006 12:23 PM 8.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2372092983-3006565277-3157113345-1008 11/24/2006 12:23 PM 112.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2372092983-3006565277-3157113345-500 11/24/2006 12:23 PM 256.00 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\ComDb.Dat 6/2/2006 10:43 AM 33.26 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\domain.txt 11/24/2006 12:23 PM 56 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\Repository 11/24/2006 12:23 PM 0 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\Repository\$WinMgmt.CFG 11/24/2006 10:25 AM 20 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\Repository\FS 11/24/2006 12:23 PM 0 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\Repository\FS\INDEX.BTR 11/24/2006 12:01 PM 1.22 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\Repository\FS\INDEX.MAP 11/24/2006 12:23 PM 656 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\Repository\FS\MAPPING.VER 11/24/2006 12:23 PM 4 bytes Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\Repository\FS\MAPPING1.MAP 11/24/2006 12:23 PM 3.86 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\Repository\FS\MAPPING2.MAP 11/24/2006 12:22 PM 3.86 KB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\Repository\FS\OBJECTS.DATA 11/24/2006 12:01 PM 6.33 MB Hidden from Windows API.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP208\snapshot\Repository\FS\OBJECTS.MAP 11/24/2006 12:23 PM 3.21 KB Hidden from Windows API.
C:\WINDOWS\inf\windowsdefender.adm 9/28/2006 11:53 AM 19.57 KB Hidden from Windows API.
C:\WINDOWS\Installer\674ce5.msi 11/24/2006 12:17 PM 1.10 MB Hidden from Windows API.
C:\WINDOWS\LastGood 11/24/2006 12:14 PM 0 bytes Hidden from Windows API.
C:\WINDOWS\LastGood\Downloaded Program Files 11/24/2006 12:14 PM 0 bytes Hidden from Windows API.
C:\WINDOWS\LastGood\Downloaded Program Files\LegitCheckControl.inf 5/15/2006 5:48 PM 367 bytes Hidden from Windows API.
C:\WINDOWS\LastGood\system32 11/24/2006 12:14 PM 0 bytes Hidden from Windows API.
C:\WINDOWS\LastGood\system32\LegitCheckControl.DLL 6/19/2006 3:19 PM 557.80 KB Hidden from Windows API.
C:\WINDOWS\Prefetch\MPAS-FE.EXE-03A19C8B.pf 11/24/2006 12:23 PM 52.70 KB Hidden from Windows API.
C:\WINDOWS\Prefetch\MPCMDRUN.EXE-1F9D1CA1.pf 11/24/2006 12:38 PM 43.50 KB Hidden from Windows API.
C:\WINDOWS\Prefetch\MPSIGSTUB.EXE-2907AFB3.pf 11/24/2006 12:23 PM 17.38 KB Hidden from Windows API.
C:\WINDOWS\Prefetch\MSASCUI.EXE-08BEC8D8.pf 11/24/2006 12:18 PM 47.10 KB Hidden from Windows API.
C:\WINDOWS\Prefetch\MSMPENG.EXE-273B5E0F.pf 11/24/2006 12:17 PM 65.44 KB Hidden from Windows API.
C:\WINDOWS\setupapi.log 11/24/2006 12:14 PM 1.45 KB Hidden from Windows API.
C:\WINDOWS\SoftwareDistribution\Download\b89203ef9da37df6b522231b78f0049e99895714 11/23/2006 10:53 PM 3.26 MB Hidden from Windows API.
C:\WINDOWS\SoftwareDistribution\Download\Install 11/24/2006 12:23 PM 0 bytes Hidden from Windows API.
C:\WINDOWS\SoftwareDistribution\Download\Install\mpas-fe.exe 11/23/2006 10:53 PM 3.26 MB Hidden from Windows API.
C:\WINDOWS\system32\CatRoot2\tmp.edb 11/24/2006 12:1
 
Last edited:

Me__2001

Internet Junkie
Joined
Apr 5, 2004
Messages
4,354
Reaction score
1
your HJT log looks clean, theres a few things that are probably unessecary at startup but they can stay for now

i must say that is one long old rootkit scan log, what application did you use for this scan ?
 

Ian

Administrator
Joined
Feb 23, 2002
Messages
19,873
Reaction score
1,499
Which program was it you deleted Cindy, can you remember the name of it?
 
Joined
Nov 24, 2006
Messages
15
Reaction score
0
Hi. The program I deleted was the hp all-in-one deskjet printer program, must be the reason for the AiO message, duh. I have a new canon printer and did not think I needed the hp deskjet program. I won't be making that mistake again, thinking, overrated. As far as the rootkit, I used the 2 that were recommended by V_R on the essential pc items thread. Blacklight (or is it Backlight?) found nothing, Rootkit Reveal went to town, so all you see is from rootkit reveal. Any clue why I can not access firefox at all? I do get a message that JS_DHashTableOperate . . . js3250.dll can not be found, portal gone or something like that. I have tried re-downloading firefox, but it doesn't make any difference. Now I have firefox 1.5 and 2.0 in the add/remove programs, but neither one works. Thank you so much for any and all help. Cindy
 

Adywebb

Growing old....
Moderator
Joined
Jan 1, 2005
Messages
5,459
Reaction score
21
Thers nothing wrong in either your HJT log, or the Rootkit Reveal log - so you can eliminate posible virus/malware problems.

Error codes 1607 or 1706 are Windows Installer errors, I would suggest you have some quite severe corruption within the Windows OS and often the only way to resolve them is to try a repair/re-install of Windows.

You could first try a System Restore back to a previous date when you were working OK.

Being a HP machine, am I right in assuming you were not given a copy of the OS? - in which case there should be a way to restore the machine back to its factory settings using HP's recovery software.

If you do have a copy of the OS, boot from it and try a repair install, and failing that you may have to go for a full re-install.

For all of the above options, please make sure you make backups to CD/DVD/Flash etc of all your important files etc before proceeding ;)
 
Joined
Nov 24, 2006
Messages
15
Reaction score
0
Thank you, I'm very relieved to know I don't have a virus or malware currently. Two days ago, AVG popped up with an infection, a generic trojan, I will see if I have the names of the files and trojan in my scan logs, however, I'm not sure I still have them since I did about 5 system restores trying to get firefox back. Also, between Zone Alarm and AVG there were 3 episodes of virus/malware that were quarantined and I deleted all three files. I did make a copy of windows XP for recovery when first starting the computer. That is the first thing I did. I hope I can find the scan logs with the file names in them so that maybe I can just restore those files? Is it possible to do that? Again, thank you so much for all your time and help, I was very concerned about a virus when I got the message that my memory was all most used up and virtual memory had to be increased. I will look for the virus files, try another system restore, and see what happens.
Gratefully, Cindy
 

Adywebb

Growing old....
Moderator
Joined
Jan 1, 2005
Messages
5,459
Reaction score
21
If you do find the scan logs, before restoring the files please tell us what they are - if they are malware/virus then you don't want to put them back on!
 
Joined
Nov 24, 2006
Messages
15
Reaction score
0
The computer is also very slow, and I am an eBay addict. I'm going to have a difficult time winning at the last minute, oh and all my research sites are on firefox, plus all bookmarks for school. ( Which is the most important thing.)

There are logs kept in HP help pages, errors, etc. I can copy and paste thiose if they would help. I'm getting desperate to access the info I have in firefox because school starts again Monday, and finals are beginning the 13th of December. I hope I did not send this twice, I was on the phone with my mom and I looked at the screen and what I had typed was gone. I'm still crunching away happily as well. Let me know if the system logs will help, and thank you.
 
Last edited:
Joined
Nov 24, 2006
Messages
15
Reaction score
0
Okay, there is really something very wrong, because I am unable to log in to any websites where I normally online shop. I keep getting error messages, and the last time this type of thing happened my computer was very infected. Please, I need help before it goes down for good. I will attach the logs I found, and I will call HP as well, and I need to walk the mooses, but I'll leave the pc up.
 

Adywebb

Growing old....
Moderator
Joined
Jan 1, 2005
Messages
5,459
Reaction score
21
Cindy, I can only suggest what I put in my earlier post #9 - go back to the factory state or re-install I'm afraid (after back-up of impotant data/files)

Sorry I can't be more help, perhaps someone else here can suggest an alternative?
 
Joined
Nov 24, 2006
Messages
15
Reaction score
0
Think I have it partially fixed

To all who helped - Thank you! I think I have it partially fixed and maybe this will help someone else. I should have thought of it much sooner, I would have saved a week, and gotten something done. I searched for repair firefox on google, and found my answer. It's the new firefox browser release 2.0, and many are receiving the same error messages. I didn't do anything stupid like I figured I had, it's the browser! I did uncheck automatic browser updates in firefox, and now if I can figure out how to remove 2.0 and keep 1.8, since I put them both in the same file, everything will be great. In the meantime I am able to start firefox in safe mode, or open it from the programs bar in the start menu. I can not tell you how relieved I am, and the first thing I did was back up my hard drive to DVD. Thank you all so much, not just for the help, but the friendly spirit in which it was given. I am still crunching away, and sending everyone I know the website so that they may crunch as well.
Very gratefully,
Cindy
 

Adywebb

Growing old....
Moderator
Joined
Jan 1, 2005
Messages
5,459
Reaction score
21
Never thought about it being a browser problem to be honest - I don't use the latest FF at the moment.

Well I'm glad your nearly sorted and able to back-up all your data - and thanks for your crunching contributions :cool:
 
Joined
Nov 24, 2006
Messages
15
Reaction score
0
Hello again,
I believe I have my computer cleaned up, spyware doctor found trojan.dumaru and quarantined that, so the reason I'm writing is to find out how to switch to the other type of feed I guess it is . Captain Boinc had offered to help me switch my machine from the WCG regular program to the BOINC program, since my pc is an amd 3800 x 2 (dual processors), it's ready for 64, but I'm not sure if I need to do anything for it to operate at 64 rather than 32. Anyway, I'm ready to switch whenever it's convenient for you. I have a final today and a final on Friday, so maybe sometime over the weekend? In the meantime, I'm still crunching away with the standard software that WCG adds to my computer. And by the way, through all my computer trouble, no one from PCReview ever made me feel stupid, you all were the best! You are a very friendly group, and I haven't forgotten about going to the page where I introduce myself, I will as soon as finals are over. Thanks again for everyone's help and time, be back soon. Cindy
 
Joined
Jan 4, 2003
Messages
8,039
Reaction score
846
Fantastic glad your sorted.

Spread the word if you can lets get more of your friends and family crunching too maybe ?

Good luck with your finals aswell :thumb:
 
Joined
Nov 24, 2006
Messages
15
Reaction score
0
I'm telling everyone I know about the WCG, including the computer science department at the University. They have many computers on all day doing nothing. And I'm telling all my family as well. Once finals are over I will really make the push to everyone, I think it's just a fantastic thing to do, and have passed along the info to my molecular biology professor, etc. All I need now is to change to the BOINC. Thanks again, Cindy
 

Adywebb

Growing old....
Moderator
Joined
Jan 1, 2005
Messages
5,459
Reaction score
21
Hi Cindy - I am around all this weekend to help you set up BOINC on your PC to make use of both those CPU's, so if you PM me or shout here when you want to give it a go I will give you a hand
nod.gif


Good luck with your exams this week :thumb:

Ady
user.gif
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top