Hi bamajim,
Thanks for your help I appriciate it
New Hijackthis log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:06:40, on 07/06/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\mobsync.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\Rachel\Program Files\DNA\btdna.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://uk.rd.yahoo.c...://uk.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://en.uk.acer.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://en.uk.acer.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://en.uk.acer.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://uk.rd.yahoo.c...://uk.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Updates] c:\windows\system\Update.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Rachel\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Windows Updates] c:\windows\system\Update.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BM330d8f45] Rundll32.exe "C:\Users\Rachel\AppData\Local\Temp\cqjiwlmb.dll",s
O4 - HKCU\..\Run: [303ebcd9] rundll32.exe "C:\Users\Rachel\AppData\Local\Temp\xmptlhrm.dll",b
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: PCM Media Sharing.lnk = C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O13 - Gopher Prefix:
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) -
http://zone.msn.com/...UI.cab55579.cabO16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) -
http://zone.msn.com/...dy.cab55579.cabO16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg...l_v1-0-3-48.cabO16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) -
http://zone.msn.com/...at.cab55579.cabO16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
https://h20436.www2....re/HPDEXAXO.cabO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl-esd.su...ows-i586-jc.cabO16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (MSN Games – Hearts) -
http://zone.msn.com/...tz.cab70018.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn...ro.cab56649.cabO16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://www.adobe.com...obat/nos/gp.cabO16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) -
http://zone.msn.com/...xy.cab55579.cabO23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 9582 bytes
Temp Fix log file
========================================
TempFix
Version 1.0
By bamajim @ bamajim.com
========================================
C:\Users\Rachel\AppData\Local\Temp\7ZipError.log
C:\Users\Rachel\AppData\Local\Temp\AAX26C6.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX26F5.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX2C01.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX2C21.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX3C6F.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX3C90.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX3CB0.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX3CD0.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX5AE0.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX5B0F.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX7EF3.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX7FDE.tmp
C:\Users\Rachel\AppData\Local\Temp\AAX8E.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXA2C9.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXA3E3.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXB10B.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXB13A.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXB85A.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXB88A.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXBE.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXC219.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXC239.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXC302.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXC332.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXCB41.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXCC3B.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXFBA3.tmp
C:\Users\Rachel\AppData\Local\Temp\AAXFBE3.tmp
C:\Users\Rachel\AppData\Local\Temp\AppCoreInst.dat
C:\Users\Rachel\AppData\Local\Temp\AutoRun.exe
C:\Users\Rachel\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Rachel\AppData\Local\Temp\b120x240.tmp
C:\Users\Rachel\AppData\Local\Temp\b120x600.tmp
C:\Users\Rachel\AppData\Local\Temp\b120x90.tmp
C:\Users\Rachel\AppData\Local\Temp\b125x125.tmp
C:\Users\Rachel\AppData\Local\Temp\b160x600.tmp
C:\Users\Rachel\AppData\Local\Temp\b180x150.tmp
C:\Users\Rachel\AppData\Local\Temp\b234x60.tmp
C:\Users\Rachel\AppData\Local\Temp\b240x400.tmp
C:\Users\Rachel\AppData\Local\Temp\b250x250.tmp
C:\Users\Rachel\AppData\Local\Temp\b300x100.tmp
C:\Users\Rachel\AppData\Local\Temp\b300x250.tmp
C:\Users\Rachel\AppData\Local\Temp\b336x280.tmp
C:\Users\Rachel\AppData\Local\Temp\b468x60.tmp
C:\Users\Rachel\AppData\Local\Temp\b720x300.tmp
C:\Users\Rachel\AppData\Local\Temp\b728x90.tmp
C:\Users\Rachel\AppData\Local\Temp\bfguni.exe
C:\Users\Rachel\AppData\Local\Temp\BurnEngineInstall.txt
C:\Users\Rachel\AppData\Local\Temp\byXPGYQj.dll
C:\Users\Rachel\AppData\Local\Temp\CdMkr70.ini
C:\Users\Rachel\AppData\Local\Temp\CF_Register_Action.dat
C:\Users\Rachel\AppData\Local\Temp\cqjiwlmb.dll
C:\Users\Rachel\AppData\Local\Temp\D653F3EC.TMP
C:\Users\Rachel\AppData\Local\Temp\ddcDsrQk.dll
C:\Users\Rachel\AppData\Local\Temp\DefInstAction.dat
C:\Users\Rachel\AppData\Local\Temp\drmtemp008CDC3D.htm
C:\Users\Rachel\AppData\Local\Temp\drmtemp008CE0B0.htm
C:\Users\Rachel\AppData\Local\Temp\drmtemp008D35C2.htm
C:\Users\Rachel\AppData\Local\Temp\drmtemp008D39D7.htm
C:\Users\Rachel\AppData\Local\Temp\dumlsloh.dll
C:\Users\Rachel\AppData\Local\Temp\esusdnya.dll
C:\Users\Rachel\AppData\Local\Temp\F2002T1L1_install_log.txt
C:\Users\Rachel\AppData\Local\Temp\F2290T1L1_install_log.txt
C:\Users\Rachel\AppData\Local\Temp\F2364T1L1_install_log.txt
C:\Users\Rachel\AppData\Local\Temp\F2452T1L1_install_log.txt
C:\Users\Rachel\AppData\Local\Temp\F2462T1L1_install_log.txt
C:\Users\Rachel\AppData\Local\Temp\F2473T1L1_install_log.txt
C:\Users\Rachel\AppData\Local\Temp\fccDVMEX.dll
C:\Users\Rachel\AppData\Local\Temp\FW_Register_Plugin_Action.dat
C:\Users\Rachel\AppData\Local\Temp\gamemanager_install_log.txt
C:\Users\Rachel\AppData\Local\Temp\gamestub_install_log.txt
C:\Users\Rachel\AppData\Local\Temp\HPDriverSetup.log
C:\Users\Rachel\AppData\Local\Temp\hpzpdu.log
C:\Users\Rachel\AppData\Local\Temp\IDSinst.LOG
C:\Users\Rachel\AppData\Local\Temp\isDel.bat
C:\Users\Rachel\AppData\Local\Temp\JcMkr40.ini
C:\Users\Rachel\AppData\Local\Temp\liruskoi.dll
C:\Users\Rachel\AppData\Local\Temp\logfile.txt
C:\Users\Rachel\AppData\Local\Temp\lwbbgjhx.dll
C:\Users\Rachel\AppData\Local\Temp\mcrh.tmp
C:\Users\Rachel\AppData\Local\Temp\Microsoft Office 2003 Setup(0001).txt
C:\Users\Rachel\AppData\Local\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt
C:\Users\Rachel\AppData\Local\Temp\mrhltpmx.ini
C:\Users\Rachel\AppData\Local\Temp\MSI423a6.LOG
C:\Users\Rachel\AppData\Local\Temp\MSI423a7.LOG
C:\Users\Rachel\AppData\Local\Temp\MSI79a49.LOG
C:\Users\Rachel\AppData\Local\Temp\MSI79a4a.LOG
C:\Users\Rachel\AppData\Local\Temp\MSI79a4b.LOG
C:\Users\Rachel\AppData\Local\Temp\MSI8200b.LOG
C:\Users\Rachel\AppData\Local\Temp\MSI8200c.LOG
C:\Users\Rachel\AppData\Local\Temp\msvcxpxx.dll
C:\Users\Rachel\AppData\Local\Temp\NapsterSDKInst.log
C:\Users\Rachel\AppData\Local\Temp\NCInstallLog.txt
C:\Users\Rachel\AppData\Local\Temp\Norton Internet Security 2007 Uninstall 6-5-2008 16h22m17s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Internet Security 2008 6-5-2008 16h36m2s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Internet Security 2008 6-5-2008 16h57m6s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Internet Security 2008 6-5-2008 17h49m58s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Internet Security 2008 Uninstall 6-5-2008 16h46m55s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Internet Security 2008 Uninstall 6-5-2008 17h13m0s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Setup 10,1,0 6-5-2008 16h22m14s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Setup 15,0,0 6-5-2008 16h35m16s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Setup 15,0,0 6-5-2008 16h46m53s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Setup 15,0,0 6-5-2008 16h57m3s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Setup 15,0,0 6-5-2008 17h12m59s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Setup 15,0,0 6-5-2008 17h45m55s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Setup 15,0,0 6-5-2008 17h49m57s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Stub 4,0,0 6-5-2008 16h35m15s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Stub 4,0,0 6-5-2008 16h57m2s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Stub 4,0,0 6-5-2008 17h45m26s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Stub 4,0,0 6-5-2008 17h49m48s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Stub 4,0,1 6-5-2008 17h45m54s.log
C:\Users\Rachel\AppData\Local\Temp\Norton Stub 4,0,1 6-5-2008 17h49m57s.log
C:\Users\Rachel\AppData\Local\Temp\nsbFE9E.tmp
C:\Users\Rachel\AppData\Local\Temp\nsbFE9E.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nsd5340.tmp
C:\Users\Rachel\AppData\Local\Temp\nsd5340.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nsdDE36.tmp
C:\Users\Rachel\AppData\Local\Temp\nsdDE36.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nsgF300.tmp
C:\Users\Rachel\AppData\Local\Temp\nsgF300.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nsiEE71.tmp
C:\Users\Rachel\AppData\Local\Temp\nsiEE71.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nslCC87.tmp
C:\Users\Rachel\AppData\Local\Temp\nslCC87.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nso5B20.tmp
C:\Users\Rachel\AppData\Local\Temp\nso5B20.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nspD684.tmp
C:\Users\Rachel\AppData\Local\Temp\nspD684.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nspDDD7.tmp
C:\Users\Rachel\AppData\Local\Temp\nspDDD7.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nsqEC39.tmp
C:\Users\Rachel\AppData\Local\Temp\nsqEC39.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nsrC5A2.tmp
C:\Users\Rachel\AppData\Local\Temp\nsrC5A2.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nsx6960.tmp
C:\Users\Rachel\AppData\Local\Temp\nsx6960.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\nsx719D.tmp
C:\Users\Rachel\AppData\Local\Temp\nsx719D.tmp.xml
C:\Users\Rachel\AppData\Local\Temp\NtiJewel.ini
C:\Users\Rachel\AppData\Local\Temp\offcln11.log
C:\Users\Rachel\AppData\Local\Temp\OneNote_MigrationLog.txt
C:\Users\Rachel\AppData\Local\Temp\otffufwb.dll
C:\Users\Rachel\AppData\Local\Temp\pdfnkqxt.ini
C:\Users\Rachel\AppData\Local\Temp\ppcrlui_4264_2
C:\Users\Rachel\AppData\Local\Temp\ppcrlui_4288_2
C:\Users\Rachel\AppData\Local\Temp\PreScan.log
C:\Users\Rachel\AppData\Local\Temp\QBackupInst.dat
C:\Users\Rachel\AppData\Local\Temp\QTInstallCode.log
C:\Users\Rachel\AppData\Local\Temp\qtplugin.log
C:\Users\Rachel\AppData\Local\Temp\Rachel.bmp
C:\Users\Rachel\AppData\Local\Temp\rem628B.tmp
C:\Users\Rachel\AppData\Local\Temp\removalfile.bat
C:\Users\Rachel\AppData\Local\Temp\SetupExe(200804221706281590).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(2008042221161915E8).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(20080423082112D2C).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(200804250719201054).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(2008042613355016A0).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(2008042808265515C0).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(20080430212309E34).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(2008043021242912A4).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(20080501073328474).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(20080504211855A7C).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(2008050509221815DC).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(20080513123211C8C).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(20080513124930AFC).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(200805131252031E8).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(200805191619371578).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(200805201556191564).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(200805201846261144).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(20080520191603DAC).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(20080520192044BD0).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(200805201921141718).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(20080520192711150C).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(200805201927439D8).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(200805201928501314).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(2008052207273315B0).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(2008052318295014C0).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(200805231854431704).log
C:\Users\Rachel\AppData\Local\Temp\SetupExe(20080523185607730).log
C:\Users\Rachel\AppData\Local\Temp\setupprop.dat
C:\Users\Rachel\AppData\Local\Temp\Silverlight0.log
C:\Users\Rachel\AppData\Local\Temp\SilverlightMSI.log
C:\Users\Rachel\AppData\Local\Temp\SilverlightMSI63E0.txt
C:\Users\Rachel\AppData\Local\Temp\SilverlightUI63E0.txt
C:\Users\Rachel\AppData\Local\Temp\SNDunin.log
C:\Users\Rachel\AppData\Local\Temp\srtUnin.log
C:\Users\Rachel\AppData\Local\Temp\swt-awt-win32-3346.dll
C:\Users\Rachel\AppData\Local\Temp\swt-win32-3346.dll
C:\Users\Rachel\AppData\Local\Temp\SYMEVENT.LOG
C:\Users\Rachel\AppData\Local\Temp\symlcsv1.exe
C:\Users\Rachel\AppData\Local\Temp\tDgiQqru.ini
C:\Users\Rachel\AppData\Local\Temp\tDgiQqru.ini2
C:\Users\Rachel\AppData\Local\Temp\tempmessage.bfg
C:\Users\Rachel\AppData\Local\Temp\tmp00008e4a
C:\Users\Rachel\AppData\Local\Temp\tmp00009a7a
C:\Users\Rachel\AppData\Local\Temp\tmp00009bb2
C:\Users\Rachel\AppData\Local\Temp\tmp0000d96d
C:\Users\Rachel\AppData\Local\Temp\tmp000101b4
C:\Users\Rachel\AppData\Local\Temp\tmp000141fe
C:\Users\Rachel\AppData\Local\Temp\tmp000181cc
C:\Users\Rachel\AppData\Local\Temp\tmpCBC3D.FOT
C:\Users\Rachel\AppData\Local\Temp\tmpCDC3D.FOT
C:\Users\Rachel\AppData\Local\Temp\tmpD9C3D.FOT
C:\Users\Rachel\AppData\Local\Temp\tmpE6C3D.FOT
C:\Users\Rachel\AppData\Local\Temp\txqknfdp.dll
C:\Users\Rachel\AppData\Local\Temp\url.txt
C:\Users\Rachel\AppData\Local\Temp\urqnLETn.dll
C:\Users\Rachel\AppData\Local\Temp\urqQigDt.dll
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(200804221706301590).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(2008042221162015E8).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(20080423082114D2C).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(200804250719241054).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(2008042613355116A0).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(2008042808265715C0).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(20080430212310E34).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(2008043021243012A4).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(20080501073329474).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(20080504211856A7C).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(2008050509222415DC).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(20080513123216C8C).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(20080513124931AFC).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(200805131252041E8).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(200805191619391578).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(200805201556201564).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(200805201846271144).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(20080520191604DAC).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(20080520192045BD0).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(200805201921151718).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(20080520192712150C).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(200805201927449D8).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(200805201928511314).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(2008052207273415B0).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(2008052318295114C0).log
C:\Users\Rachel\AppData\Local\Temp\UserInfoSetup(200805231854441704).log
C:\Users\Rachel\AppData\Local\Temp\vcredist32_6-5-2008_16h35m17s.log
C:\Users\Rachel\AppData\Local\Temp\vtUNeeCu.dll
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080331_180702.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080401_181505.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080402_183111.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080403_191811.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080403_195350.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080404_201326.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080421_095513.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080421_121731.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080421_183200.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080424_185809.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080425_133006.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080425_161528.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080427_101257.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080428_182503.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080429_165905.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080430_131415.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080505_094839.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080506_094431.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080506_205818.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080507_100600.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080508_145226.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080512_172529.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080515_100940.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080519_073134.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080520_175425.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080521_141607.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080522_185557.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080523_180702.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080527_080913.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080527_151249.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080527_165402.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080528_185951.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080529_031115.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080530_175343.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080531_141531.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080601_153033.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080602_155517.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080603_164649.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080604_145044.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080605_170521.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080605_174343.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080605_191839.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080605_201239.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080606_203247.mvu
C:\Users\Rachel\AppData\Local\Temp\wcesmgr_20080607_085439.mvu
C:\Users\Rachel\AppData\Local\Temp\wmplog00.sqm
C:\Users\Rachel\AppData\Local\Temp\wmplog01.sqm
C:\Users\Rachel\AppData\Local\Temp\wmplog02.sqm
C:\Users\Rachel\AppData\Local\Temp\wmplog03.sqm
C:\Users\Rachel\AppData\Local\Temp\wmplog04.sqm
C:\Users\Rachel\AppData\Local\Temp\wmplog05.sqm
C:\Users\Rachel\AppData\Local\Temp\wmplog06.sqm
C:\Users\Rachel\AppData\Local\Temp\wmplog07.sqm
C:\Users\Rachel\AppData\Local\Temp\wmplog08.sqm
C:\Users\Rachel\AppData\Local\Temp\wmplog09.sqm
C:\Users\Rachel\AppData\Local\Temp\wmsetup.log
C:\Users\Rachel\AppData\Local\Temp\xhjgbbwl.ini
C:\Users\Rachel\AppData\Local\Temp\xmptlhrm.dll
C:\Users\Rachel\AppData\Local\Temp\{D3CFA2A2-FF53-4F16-8C2E-590430D3CB5A}
C:\Users\Rachel\AppData\Local\Temp\~0000001.TMP
C:\Users\Rachel\AppData\Local\Temp\~DF476D.tmp
C:\Users\Rachel\AppData\Local\Temp\~DF67F1.tmp
C:\Users\Rachel\AppData\Local\Temp\~DF7C43.tmp
C:\Users\Rachel\AppData\Local\Temp\~DF82A8.tmp
C:\Users\Rachel\AppData\Local\Temp\~DF8845.tmp
C:\Users\Rachel\AppData\Local\Temp\~DF8B8E.tmp
C:\Users\Rachel\AppData\Local\Temp\~DF96F.tmp
C:\Users\Rachel\AppData\Local\Temp\~DFABE6.tmp
C:\Users\Rachel\AppData\Local\Temp\~DFC59B.tmp
C:\Users\Rachel\AppData\Local\Temp\~DFD995.tmp
C:\Users\Rachel\AppData\Local\Temp\~e5d141.tmp
308 files deleted
Thanks
Rachel