This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] email hijack YIKES

63 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Just noticed a bunch of email sending errors, checked my sent items and found odd emails with just a web address which ends up being different weird advertisements. I ran a malwarebytes deal and it found nothing. PLEASE HELP
Hello and :welcome: Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. I will post back shortly with instructions.
My antivirus (Avira) found 8 objects during it's nightly scan and quarantined them. Not sure if this is the culprit or not, a number of emails were sent from my account again this morning to people in my contact list. the objects found were all the same in a way. Details: The file 'C:\hp\recovery\wizard\fscommand\RecordnowLink_ret.exe' contained a virus or unwanted program 'TR/Spy.Agent.beaf' [trojan] Action(s) taken: The file was moved to '4bfff335.qua'! please help. thanks!
Hi,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 24 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________



You will need to right click and choose "Run as Administrator" to run the tools we will use.


Hi,

Go to a known clean computer and change all your online passwords immediately. Do not use easy to crack passwords such as your nickname, birthdays, etc.
Here is good discussion regarding using strong passwords: http://forums.whatthetech.com/Use_Strong_P…rds_t98701.html

–Next–

OTL:
  • Download OTL to your desktop.
  • Right click on the icon then choose "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
–Next–

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right click GMER.exe then choose "Run as Administrator" to run the tool. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


To post in your next reply:
1. OTL logs.
2. GMER log.
Hi, Since I had not heard from you yet and the stupid virus or whatever it is sent out another wave of emails, I downloaded stopzilla to see if it could help. it found numerous issues and hopefully fixed the problem? Should I still run these that you suggested, or will it be different now with the stopzilla on my system?
here are the OTL logs: #1:
OTL logfile created on: 3/15/2010 6:24:27 PM - Run 1
OTL by OldTimer - Version 3.1.37.1 Folder = C:\Users\HP_Administrator\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 189.00 Mb Available Physical Memory | 19.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 37.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 177.66 Gb Total Space | 40.28 Gb Free Space | 22.67% Space Free | Partition Type: NTFS
Drive D: | 8.63 Gb Total Space | 0.33 Gb Free Space | 3.77% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-4DACD0EA75
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files\Common Files\Iconix\IconixService.exe ()
PRC - C:\Program Files\Java\jre6\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\GmoteServer\GmoteServer.exe ()
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\MSN\MSNCoreFiles\msn.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Microsoft Location Finder\LocationFinder.exe (Microsoft Corporation)
PRC - C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe (Maxtor Corporation)
PRC - C:\Program Files\Maxtor\ManagerApp\OneTouch.exe (Maxtor Corporation)
PRC - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe ()
PRC - C:\Windows\System32\HPZipm12.exe (HP)
PRC - C:\Program Files\Maxtor\Utils\SyncServices.exe ( )
PRC - C:\Program Files\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe (ScanSoft, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (szserver) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (IconixService) – C:\Program Files\Common Files\Iconix\IconixService.exe ()
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (MaxBackServiceInt) – C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe ()
SRV - (ELService) Intel® – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\ELService.exe (Intel Corporation)
SRV - (Pml Driver HPZ12) – C:\Windows\System32\HPZipm12.exe (HP)
SRV - (NTService1) – C:\Program Files\Maxtor\Utils\SyncServices.exe ( )


========== Driver Services (SafeList) ==========

DRV - (szkgfs) – C:\Windows\system32\drivers\szkgfs.sys (iS3, Inc.)
DRV - (avgntflt) – C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (szkg5) – C:\Windows\system32\DRIVERS\szkg.sys (iS3 Inc.)
DRV - (is3srv) – C:\Windows\system32\drivers\is3srv.sys (iS3 Inc.)
DRV - (ssmdrv) – C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (NuidFltr) – C:\Windows\System32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (avipbb) – C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\Windows\System32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (USB_RNDIS) – C:\Windows\System32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (VSTHWBS2) – C:\Windows\System32\drivers\VSTBS23.SYS (Conexant Systems, Inc.)
DRV - (VST_DPV) – C:\Windows\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (ELmon) – C:\Windows\System32\drivers\Elmon.sys (Intel Corporation)
DRV - (ELkbd) – C:\Windows\System32\drivers\Elkbd.sys (Intel Corporation)
DRV - (ELmou) – C:\Windows\System32\drivers\Elmou.sys (Intel Corporation)
DRV - (ELhid) – C:\Windows\System32\drivers\Elhid.sys (Intel Corporation)
DRV - (Ps2) – C:\Windows\System32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (MXOPSWD) – C:\Windows\System32\drivers\mxopswd.sys (Maxtor Corp.)
DRV - (pfc) – C:\Windows\System32\drivers\pfc.sys (Padus, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:9022


[2009/03/01 14:59:45 | 000,000,000 | —D | M] – C:\Users\HP_Administrator\AppData\Roaming\Mozilla\Extensions
[2009/03/01 14:59:45 | 000,000,000 | —D | M] – C:\Users\HP_Administrator\AppData\Roaming\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (IconixBHOClass Class) - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_42.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Viewpoint Toolbar BHO) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.9.0\ViewBarBHO.dll (Viewpoint Corporation)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Viewpoint Toolbar) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.9.0\IEViewBar.dll (Viewpoint Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\OneTouch.exe (Maxtor Corporation)
O4 - HKLM..\Run: [mxomssmenu] C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe (Maxtor Corporation)
O4 - HKLM..\Run: [OpwareSE2] C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [PDUiP6600DMon] C:\Program Files\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe (CANON INC.)
O4 - HKLM..\Run: [Recguard] C:\Windows\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [Microsoft Location Finder] C:\Program Files\Microsoft Location Finder\LocationFinder.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe File not found
O4 - Startup: C:\Users\HP_Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GmoteServer.lnk = C:\Program Files\GmoteServer\GmoteServer.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra 'Tools' menuitem : Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_42.dll ()
O9 - Extra 'Tools' menuitem : About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_42.dll ()
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKCU\..Trusted Domains: //@mail.mar@/ ([]msn in Local intranet)
O15 - HKCU\..Trusted Domains: //@signup.mar@/ ([]msn in Computer)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\HP_Administrator\Desktop\Sheri's Folder\aLL FLOWERS\DSC01590.JPG
O24 - Desktop BackupWallPaper: C:\Users\HP_Administrator\Desktop\Sheri's Folder\aLL FLOWERS\DSC01590.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 08:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 00:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = comfile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/03/15 18:21:40 | 000,555,008 | —- | C] (OldTimer Tools) – C:\Users\HP_Administrator\Desktop\OTL.exe
[2010/03/14 09:53:03 | 000,000,000 | —D | C] – C:\ProgramData\SITEguard
[2010/03/14 09:49:54 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2010/03/14 09:49:49 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2010/03/14 09:49:39 | 000,000,000 | —D | C] – C:\ProgramData\STOPzilla!
[2010/03/12 22:52:12 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/03/11 04:02:00 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshhttp.dll
[2010/03/11 04:01:52 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\httpapi.dll
[2010/03/05 17:16:42 | 000,017,408 | R— | C] (iS3, Inc.) – C:\Windows\System32\SZIO5.dll
[2010/03/05 17:14:16 | 000,442,368 | R— | C] (iS3, Inc.) – C:\Windows\System32\SZBase5.dll
[2010/03/05 17:13:44 | 000,540,672 | R— | C] (iS3, Inc.) – C:\Windows\System32\SZComp5.dll
[2010/02/24 14:06:36 | 000,173,328 | R— | C] (iS3, Inc.) – C:\Windows\System32\drivers\SZKGFS.sys
[2010/02/24 04:54:47 | 000,473,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2010/02/24 04:54:47 | 000,472,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2010/02/24 04:54:46 | 000,435,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2010/02/24 04:54:45 | 000,523,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2010/02/24 04:54:45 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2010/02/24 04:54:44 | 000,431,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2010/02/24 04:54:43 | 000,312,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdrm.dll
[2010/02/24 04:54:43 | 000,154,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2010/02/24 04:54:43 | 000,154,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2010/02/24 01:03:19 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/02/21 16:32:36 | 000,000,000 | —D | C] – C:\Windows\System32\Registry Patrol
[2010/02/21 16:32:29 | 000,086,016 | —- | C] (MindVision Software) – C:\Windows\unvise32.exe
[2010/02/21 16:32:02 | 000,000,000 | —D | C] – C:\Program Files\Registry Patrol

========== Files - Modified Within 30 Days ==========

[2010/03/15 18:29:53 | 004,980,736 | -HS- | M] () – C:\Users\HP_Administrator\NTUSER.DAT
[2010/03/15 18:28:06 | 000,001,072 | —- | M] () – C:\Windows\System32\drivers\kgpfr2.cfg
[2010/03/15 18:21:33 | 000,555,008 | —- | M] (OldTimer Tools) – C:\Users\HP_Administrator\Desktop\OTL.exe
[2010/03/15 18:01:29 | 000,002,240 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/15 18:01:29 | 000,002,240 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/15 17:52:00 | 000,000,906 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/15 15:01:19 | 000,000,896 | —- | M] () – C:\Windows\System32\drivers\kgpcpy.cfg
[2010/03/14 22:50:59 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/14 19:02:44 | 000,000,565 | —- | M] () – C:\Users\HP_Administrator\Documents\My Sharing Folders.lnk
[2010/03/14 18:01:29 | 000,415,000 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/03/14 18:01:17 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/03/14 18:01:04 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/03/14 11:46:00 | 000,685,882 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/03/14 11:46:00 | 000,130,510 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/03/14 11:45:57 | 000,813,620 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/03/12 22:52:18 | 000,001,681 | —- | M] () – C:\Users\HP_Administrator\Desktop\CCleaner.lnk
[2010/03/12 19:46:05 | 000,000,284 | —- | M] () – C:\Windows\tasks\AppleSoftwareUpdate.job
[2010/03/12 18:11:13 | 000,057,460 | —- | M] () – C:\Users\HP_Administrator\AppData\Roaming\wklnhst.dat
[2010/03/07 15:24:12 | 000,045,568 | —- | M] () – C:\Users\HP_Administrator\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/05 17:16:42 | 000,017,408 | R— | M] (iS3, Inc.) – C:\Windows\System32\SZIO5.dll
[2010/03/05 17:14:16 | 000,442,368 | R— | M] (iS3, Inc.) – C:\Windows\System32\SZBase5.dll
[2010/03/05 17:13:44 | 000,540,672 | R— | M] (iS3, Inc.) – C:\Windows\System32\SZComp5.dll
[2010/02/25 04:27:29 | 000,122,080 | —- | M] () – C:\Users\HP_Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/02/24 14:06:36 | 000,173,328 | R— | M] (iS3, Inc.) – C:\Windows\System32\drivers\SZKGFS.sys
[2010/02/24 10:16:06 | 000,181,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/02/21 16:32:12 | 000,000,828 | —- | M] () – C:\Users\HP_Administrator\Desktop\Registry Patrol.lnk
[2010/02/20 18:54:40 | 000,024,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\nshhttp.dll
[2010/02/20 18:51:43 | 000,031,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\httpapi.dll

========== Files Created - No Company Name ==========

[2010/03/14 18:02:53 | 000,000,896 | —- | C] () – C:\Windows\System32\drivers\kgpcpy.cfg
[2010/03/12 22:52:18 | 000,001,681 | —- | C] () – C:\Users\HP_Administrator\Desktop\CCleaner.lnk
[2010/02/21 16:32:12 | 000,000,828 | —- | C] () – C:\Users\HP_Administrator\Desktop\Registry Patrol.lnk
[2009/08/31 15:00:22 | 000,021,504 | —- | C] () – C:\Windows\System32\WBCustomizer.dll
[2009/08/31 15:00:21 | 000,185,344 | —- | C] () – C:\Windows\System32\MemWarp.dll
[2008/03/25 16:56:08 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1461.dll
[2007/11/24 19:28:37 | 000,000,104 | —- | C] () – C:\Users\HP_Administrator\AppData\Local\fusioncache.dat
[2007/10/28 15:21:58 | 000,000,552 | —- | C] () – C:\Users\HP_Administrator\AppData\Local\d3d8caps.dat
[2007/10/28 15:21:33 | 000,045,568 | —- | C] () – C:\Users\HP_Administrator\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/28 08:30:28 | 000,000,680 | —- | C] () – C:\Users\HP_Administrator\AppData\Local\d3d9caps.dat
[2007/02/25 21:20:44 | 000,000,028 | —- | C] () – C:\Windows\pdf995.ini
[2007/02/25 16:13:00 | 000,000,121 | —- | C] () – C:\Windows\wpd99.drv
[2007/02/25 16:12:46 | 000,118,784 | —- | C] () – C:\Windows\System32\pdfmona.dll
[2007/02/25 16:12:46 | 000,051,716 | —- | C] () – C:\Windows\System32\pdf995mon.dll
[2007/02/11 13:19:00 | 000,000,000 | —- | C] () – C:\Windows\prestopm.INI
[2007/02/11 12:49:00 | 000,000,532 | —- | C] () – C:\Windows\MAXLINK.INI
[2007/02/11 12:47:32 | 000,040,960 | —- | C] () – C:\Windows\System32\IPPCPUID.DLL
[2007/02/11 12:47:32 | 000,000,105 | —- | C] () – C:\Windows\UMXADDIN.INI
[2007/02/11 12:47:26 | 000,011,776 | —- | C] () – C:\Windows\System32\pmsbfn32.dll
[2007/02/11 12:46:58 | 000,000,074 | —- | C] () – C:\Windows\PMINI.ini
[2006/12/23 19:07:05 | 000,057,460 | —- | C] () – C:\Users\HP_Administrator\AppData\Roaming\wklnhst.dat
[2006/12/22 23:24:26 | 000,684,032 | —- | C] () – C:\Windows\libeay32.dll
[2006/12/22 23:24:26 | 000,155,648 | —- | C] () – C:\Windows\ssleay32.dll
[2006/12/22 13:57:12 | 000,000,335 | —- | C] () – C:\Windows\lexstat.ini
[2006/12/21 23:52:40 | 000,000,029 | —- | C] () – C:\Windows\atid.ini
[2006/11/29 06:12:18 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1132.dll
[2006/11/29 05:37:12 | 000,467,264 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2006/11/02 07:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/10/20 12:38:42 | 000,000,061 | —- | C] () – C:\Windows\smscfg.ini
[2006/10/20 12:19:35 | 000,028,848 | —- | C] () – C:\Windows\System32\drivers\USBkey.sys
[2006/10/20 12:14:56 | 000,014,317 | —- | C] () – C:\Windows\System32\CHODDI.SYS
[2006/10/20 12:14:49 | 000,045,056 | —- | C] () – C:\Windows\System32\hpreg.dll
[2006/10/20 12:12:07 | 000,000,157 | —- | C] () – C:\Windows\QUICKEN.INI
[2006/10/20 12:01:48 | 000,000,058 | —- | C] () – C:\Windows\WININIT.INI
[2006/10/20 12:01:11 | 000,000,698 | —- | C] () – C:\Windows\NSSetDefaultBrowser.ini
[2006/10/20 11:52:44 | 000,000,753 | —- | C] () – C:\Windows\orun32.ini
[2006/10/20 11:31:31 | 000,323,584 | —- | C] () – C:\Windows\System32\pythoncom22.dll
[2006/10/20 11:31:31 | 000,094,208 | —- | C] () – C:\Windows\System32\pywintypes22.dll
[2006/10/20 11:31:15 | 000,016,896 | —- | C] () – C:\Windows\System32\bcbmm.dll
[2006/02/19 12:28:56 | 000,012,288 | —- | C] () – C:\Windows\Fonts\RandFont.dll
[2004/09/16 22:24:26 | 003,375,104 | —- | C] () – C:\Windows\System32\qt-mt331.dll
[2004/07/26 09:51:38 | 000,000,560 | —- | C] () – C:\Windows\System32\oeminfo.ini

========== LOP Check ==========

[2006/11/02 08:09:53 | 000,000,484 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 64 bytes -> C:\Users\HP_Administrator\Documents\DSCN0889.MOV:TOC.WMV
< End of report >
OTL log #2
OTL Extras logfile created on: 3/15/2010 6:24:27 PM - Run 1
OTL by OldTimer - Version 3.1.37.1 Folder = C:\Users\HP_Administrator\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 189.00 Mb Available Physical Memory | 19.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 37.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 177.66 Gb Total Space | 40.28 Gb Free Space | 22.67% Space Free | Partition Type: NTFS
Drive D: | 8.63 Gb Total Space | 0.33 Gb Free Space | 3.77% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-4DACD0EA75
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.bat [@ = batfile] – Reg Error: Key error. File not found
.cmd [@ = cmdfile] – Reg Error: Key error. File not found
.com [@ = comfile] – Reg Error: Key error. File not found
.exe [@ = exefile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – File not found
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) – (Microsoft Corporation)
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – File not found
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – File not found
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows – File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – File not found
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) – (Microsoft Corporation)
"C:\Program Files\MSN\MSNCoreFiles\msn.exe" = C:\Program Files\MSN\MSNCoreFiles\msn.exe:*:Enabled:msn – (Microsoft Corporation)
"C:\Program Files\Rhapsody\rhapsody.exe" = C:\Program Files\Rhapsody\rhapsody.exe:*:Enabled:Rhapsody – File not found
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – File not found
"C:\WINDOWS\system32\usmt\migwiz.exe" = C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard – File not found


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03390984-A990-4FB0-BDCF-FE3FEAE527B5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{051696D1-9046-4C82-8D26-65DD338B456B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{067E55D6-F0B6-4621-917A-ACB75EB9493D}" = rport=10243 | protocol=6 | dir=out | app=system |
"{0D05B6B3-4F65-4597-9B4F-57B886FCD704}" = lport=7777 | protocol=17 | dir=in | app=c:\windows\ehome\ehshell.exe |
"{25ED56C0-E265-4CC8-BEA0-A1DA218D73F5}" = lport=138 | protocol=17 | dir=in | app=system |
"{2AC6C10C-DBBF-44F1-BFBE-A959FECBD7AE}" = lport=10243 | protocol=6 | dir=in | app=system |
"{317DCAE6-F109-4A9B-8BA3-726A47282876}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{357D3BB7-D111-4BF2-8695-9E632CE15FFA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3CA5C0E5-EEF0-46E3-9485-3EEBB717F391}" = lport=10244 | protocol=6 | dir=in | app=system |
"{3D0759DA-EE40-43F7-B0A2-E394A22D6483}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3DF94F46-F9F6-4817-9D1A-C0B7081F81C0}" = rport=10244 | protocol=6 | dir=out | app=system |
"{3E2CEE38-8012-44F3-B43C-2A22E879E6E3}" = lport=3390 | protocol=6 | dir=in | app=system |
"{500EE5B2-B4DC-403A-A580-EC52695D548F}" = lport=137 | protocol=17 | dir=in | app=system |
"{558714BE-381E-4F5C-8B1B-2CE4BD3FCF35}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{64C5908A-6C27-47E4-AC1D-7222B2F19004}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{7049F41E-616A-4069-9F1E-EE1794F4725F}" = lport=139 | protocol=6 | dir=in | app=system |
"{832C4248-48A3-4E5A-A34D-E2FEC8B156A2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{84E7A3F3-4E57-45F4-8137-FCBDCFD3AD29}" = rport=138 | protocol=17 | dir=out | app=system |
"{88D5FB49-0756-47F6-8E39-2E5FE1041F3E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8C5F508D-AE39-4BCE-AC35-9AF742AC8D2F}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{904AE118-0F08-4385-AA73-FD43383D3727}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{908A9E9F-92F8-4787-A10D-9BD1415B05EC}" = lport=554 | protocol=6 | dir=in | app=c:\windows\ehome\ehshell.exe |
"{94735398-4E3E-401D-B9B7-C3A33D2418C9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{9C26851B-4DEB-4AD0-B7C6-59BC3FDC6D1B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A7161D43-1CA0-4C66-A024-91E927937AF0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A8DA55CD-03F5-43DF-9C3B-6EF9C293ACD1}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{AA6221AC-D636-4D8F-8B20-645CF5B99E45}" = lport=445 | protocol=6 | dir=in | app=system |
"{ACEF5258-188E-4AA5-B4FB-1DEFD1DEDCD4}" = rport=139 | protocol=6 | dir=out | app=system |
"{AFF041DB-A2B7-4F2E-ACD1-27F33437A199}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{B9E363EE-E4CF-448B-8AFC-FFD3F12502F7}" = rport=137 | protocol=17 | dir=out | app=system |
"{E939EBBF-AFA3-4AC5-A4DF-C7E8B18157BB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FBBA3B67-260B-4034-8828-404FDCD07846}" = rport=445 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A83231A-2239-4F9D-83AC-A9D3DF1F683F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{0E2B4DFB-F201-4D29-8C84-E69E03D6CD4B}" = protocol=6 | dir=out | app=c:\windows\ehome\ehshell.exe |
"{189E8627-9142-43BC-A55C-41E116AE7893}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1AD960B7-975C-4B63-A713-CE1413D83600}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{1C5B8426-5A73-477E-BDE7-0DF810D0A689}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{2FE99FA9-6C34-4A8F-B62C-B708B3FB4FEA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{40029817-EB22-4686-B9F4-0975EEBFBD53}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{42E93F6D-1067-496D-B6EC-3DDC5A18F4FD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5CB96142-3849-4AD1-B86A-072DF487E0BD}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{5D717A69-DBB6-4939-93C3-0320F7D17146}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{60759683-283B-4542-9732-8F09DE28DF84}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7439812D-1170-409A-9A0E-15EEF662D629}" = protocol=6 | dir=out | app=%systemroot%\system32\msra.exe |
"{77EDC3DD-7883-4505-85EC-FC1BA88A4BCD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{8C92F3F3-C6CB-4E44-8F31-23915403AAF3}" = protocol=6 | dir=in | app=c:\windows\network diagnostic\xpnetdiag.exe |
"{9A3BB0B0-5DEF-487B-8B7A-A6730DF061AD}" = protocol=17 | dir=out | app=c:\windows\ehome\ehshell.exe |
"{A4B9D01F-0162-4A95-BF2E-32665407E425}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A57B0FF6-9828-47A2-AB7B-DA3DC0B0F861}" = protocol=17 | dir=in | app=c:\windows\network diagnostic\xpnetdiag.exe |
"{A9D20B65-7DA2-4E51-9A06-8A30CEDAA7F3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AEDF06E4-0DCB-4C1F-BD2D-1202AB0E0003}" = protocol=6 | dir=in | app=%systemroot%\system32\msra.exe |
"{B2976955-D132-4DE1-AC02-02C8BC7AB401}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B2A0E3FD-2428-438F-B1AC-2639ECF0FF52}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B725C3E5-D07F-44FF-8769-79B914230623}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C6EE60A7-20B9-417F-BF70-0A536AA5222E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C795335F-DFE4-4963-B2C7-992911CF3317}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C8BF393F-8209-467D-94C9-2A9911E13030}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E801FD8C-B32D-4335-958F-FCBE66CCD11E}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{E9DEE8F7-2E45-4D05-BA67-ABD1D01DA2F6}" = protocol=6 | dir=out | app=system |
"{EA49F6CD-1003-4678-B6CE-38CFDEDBA28A}" = protocol=6 | dir=out | svc=mcx2svc | app=c:\windows\system32\svchost.exe |
"{ECEF91C9-2D9D-435D-908E-DE84C5F8F7AC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F1C1ACCF-0AAB-497C-A4D5-CFFDBC553BFB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{F9742DB5-5952-44C7-A026-E4A980C3D0E2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FDE3D9A1-82D7-4509-8263-30D4F45C8DFC}" = protocol=6 | dir=out | app=c:\windows\ehome\mcx2prov.exe |
"{FF029E58-D095-4F83-BD7C-3D41400FE355}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{5102D78B-1EFD-40CC-9F7E-1A05C1166802}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{D2D74754-EA9C-45BC-B0B8-1B37E24D5BAE}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{9324F905-53ED-466F-BDC4-DBAC06BDF192}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{DC962CB6-E199-488F-B0C1-D43D2EE74516}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0749256F-E98D-4EF1-A15B-AED26BCC1DC8}" = Sonic DVD for Photo Story 3 for Windows
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{12BE3579-A34B-47BD-A65C-82B1754E71E1}" = D4100
"{1341D838-719C-4A05-B50F-49420CA1B4BB}" = HP Boot Optimizer
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{18388EF8-E0A3-442B-8BFE-E2F1B3D05C91}" = iTunes
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{20749F76-4228-43AD-8AB5-E7B20D8040C4}" = hph_readme
"{22B3CC30-77B8-419C-AA4B-F571FDF5D66D}" = Windows Live Sign-in Assistant
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2EAF7E61-068E-11DF-953C-005056806466}" = Google Earth
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{353D20CC-719B-4A60-AD33-D03F88C10330}" = Microsoft Office Accounting PayPal Addin
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{36DC3E2F-CD8C-4953-9E8F-9A1916D10AA1}" = hph_software
"{3C97C9C5-1AF3-41B0-B61C-185C06C75EE6}" = D4100_Help
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{444B6A7B-0E26-4416-A43F-D1C9AAE6075D}" = Canon CanoScan Toolbox 4.8
"{44C05309-60F4-410B-BC32-31733CFF1A41}" = Microsoft Digital Image Starter Edition 2006 Editor
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{46614A49-222A-48EF-87A9-BFD603E608E1}" = Microsoft Office Accounting Fixed Asset Manager
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 for Windows
"{4FE542EB-FF0B-4739-94DD-25C8AE0AB251}" = Microsoft Digital Image Starter Edition 2006 Library
"{50CD421F-CAFD-46C4-BEFD-E1C46FE63062}" = Manual CanoScan 8400F
"{53A19323-917A-4822-B27E-A57D1EF6E9FC}" = H&R Block Deluxe + Efile + State 2009
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{5BE42A03-E7B8-42A9-B1BB-FC48B03D58B8}" = Presto! PageManager 6.11
"{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
"{5FDD0538-C67A-4F67-B3F8-09D1AAF04D99}" = muvee autoProducer unPlugged 2.0
"{61100673-2546-42E1-BF92-467B5CB2AC6D}" = DeductionPro 2008
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7373184D-8E8F-4308-912A-3901071FA1AD}" = LightScribe Applications
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE 2.0
"{7A2B077D-D7AC-4215-B0FB-5EA581E549E6}" = Windows Vista Upgrade Advisor
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{82081779-4175-4666-A457-AB711CD37EF0}" = cp_LightScribeConfig
"{829DAAD6-BB11-4BB7-921B-07FFB703F944}" = CP_Package_Variety3
"{82E55892-6FFD-403F-AA97-D726846768AA}" = CP_AtenaShokunin1Config
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{8377F24B-D4A7-4707-A468-DDF15A71056C}" = Qwest eChat Support Tools
"{866A0078-DEA7-4348-9C9A-999AF2991EAA}" = SlideShowMusic
"{866A1BDA-2FD1-4C8A-8E8D-7EAC52A40DC3}" = STOPzilla
"{86D28491-78AB-445C-A507-6F3FA81D7611}" = Canon iP6600D Memory Card Utility
"{86EF9FC4-F209-4520-B7E1-C7FF0EEBDFFF}" = Adobe Audition 1.5
"{8950D4E9-FC75-4F3F-B414-33F53F9B346A}" = TaxCut Minnesota 2008
"{8A534F71-3202-4464-A422-B767295E67B9}" = CP_Package_Variety2
"{8C711818-076E-475C-B95B-DF11CD9D8DBE}" = Microsoft Office Accounting Equifax Addin
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{93E5A317-24EC-4744-812C-16FECFE86E6A}" = CP_Package_Variety1
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{97F4D62E-5AEB-4649-BABF-4712C6EF6845}" = DeductionPro 2009
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C3F9580-F5CF-4288-894E-9FF0EB24A21C}" = Maxtor Backup
"{9F7AF7CD-E3D0-4C68-A3BA-C76C359B3AA8}" = LightScribe 1.4.105.1
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A4DB0F6C-851E-44E3-82EF-40D1C215A5FD}" = Maxtor Encryption
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.6
"{ACCCEE83-B49B-4964-8A4F-378B8FBC9F75}" = hph_ProductContext
"{B0717D5A-1976-482B-9ADF-F19631A541A4}" = Microsoft Office Accounting 2007
"{B19F9155-9337-4807-B5EF-ED471DDB2CCE}" = hph_software_req
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B5C209B1-8DDB-4642-A573-375B951514CB}" = Apple Mobile Device Support
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BBB33AD6-BCF7-4002-B6A0-6DC679AE5C18}" = TaxCut Premium + State + Efile 2008
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3FAA091-B278-44A7-BF48-190811C5F9F7}" = cp_UpdateProjectsConfig
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2261C4B-4D9B-4149-8472-31B7A2FEAB91}" = ArcSoft PhotoStudio 5.5
"{D2A3C9D5-0B56-4656-8277-7EDC65D62B6E}" = HP Photosmart and Deskjet 7.0 Software
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DE5DF44E-F8B1-480D-BC26-59410FACDBAC}" = ClientTools
"{E0D51394-1D45-460A-B62D-383BC4F8B335}" = QuickTime
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E9A7FC2C-D719-4897-8018-44B0A8ACEC73}" = H&R Block Minnesota 2009
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EC637522-73A5-4428-8B46-65A621529CC7}" = Microsoft Location Finder
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FB4740B3-2530-452D-A825-F7AB246CA7DF}" = muvee autoProducer 5.0
"{FCE50DB8-C610-4C42-BE5C-193F46C6F812}" = Windows Live Messenger
"{FF268652-B3E8-494F-8343-1FC6DD0FF523}" = Maxtor OneTouch III
"Abacast Client" = Abacast Client
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player
"Applian FLV Player2.0.24" = Applian FLV Player
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CANONBJ_Deinstall_CNMCP7D.DLL" = Canon iP6600D
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"DDA23392-9C73-4909-A221-BC12C6D2664D" = GmoteServer
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"EL" = Intel® Quick Resume Technology Drivers
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Photosmart for Media Center PC" = HP Photosmart for Media Center PC
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"Iconix eMail ID" = Iconix™ eMail ID
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"InstallShield_{9C3F9580-F5CF-4288-894E-9FF0EB24A21C}" = Maxtor Backup
"InstallShield_{A4DB0F6C-851E-44E3-82EF-40D1C215A5FD}" = Maxtor Encryption
"InstallShield_{FF268652-B3E8-494F-8343-1FC6DD0FF523}" = Maxtor OneTouch III
"Lexmark Z700-P700 Series" = Lexmark Z700-P700 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Office Accounting 2007" = Microsoft Office Accounting 2007
"Microsoft Office Accounting Equifax Addin" = Microsoft Office Accounting Equifax Addin
"Microsoft Office Accounting PayPal Addin" = Microsoft Office Accounting PayPal Addin
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"mIRC" = mIRC
"Money2006b" = Microsoft Money 2006
"MSNINST" = MSN
"OfficeTrial" = Microsoft Office Standard Edition 2003 60 days trial
"OJOsoft Total Video Converter_is1" = OJOsoft Total Video Converter
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"Pdf995" = Pdf995
"PdfEdit995" = PdfEdit995
"PictureItSuiteTrial_v12" = Microsoft Digital Image Starter Edition 2006
"Prism" = Prism Video Converter
"PROSet" = Intel® PRO Network Connections Drivers
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"RealPlayer 6.0" = RealPlayer
"Registry Patrol" = Registry Patrol
"Security Task Manager" = Security Task Manager 1.7e
"TaxCut Premium 2006" = TaxCut Premium 2006
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"Viewpoint Toolbar" = Viewpoint Toolbar
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent hpmedia Master Uninstall" = My HP Games
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinISD beta" = WinISD beta
"WinRAR archiver" = WinRAR archiver
"Your Image Jasmine Jones 1.0.5" = Your Image Jasmine Jones
"Your Image NICHOLAS WARREN 1.0.5" = Your Image NICHOLAS WARREN

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"HJ ProDigital" = HJ ProDigital
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/14/2010 1:08:50 PM | Computer Name = your-4dacd0ea75 | Source = Perflib | ID = 1008
Description = The Open Procedure for service "DFSR" in DLL "C:\Windows\System32\DfsrPerf.dll"
failed. Performance data for this service will not be available. The first four
bytes (DWORD) of the Data section contains the error code.

Error - 3/14/2010 1:09:58 PM | Computer Name = your-4dacd0ea75 | Source = Application Error | ID = 1000
Description = Faulting application IEXPLORE.EXE, version 7.0.6000.16982, time stamp
0x4b2b56f5, faulting module ophookSE2.dll, version 12.0.0.1, time stamp 0x3eba2acd,
exception code 0xc0000005, fault offset 0x00004eef, process id 0xb38, application
start time 0x01cac3992a0d91cc.

Error - 3/14/2010 1:18:10 PM | Computer Name = your-4dacd0ea75 | Source = Application Error | ID = 1000
Description = Faulting application IEXPLORE.EXE, version 7.0.6000.16982, time stamp
0x4b2b56f5, faulting module ophookSE2.dll, version 12.0.0.1, time stamp 0x3eba2acd,
exception code 0xc0000005, fault offset 0x00004eef, process id 0x1750, application
start time 0x01cac39a4ef7af1c.

Error - 3/14/2010 1:18:35 PM | Computer Name = your-4dacd0ea75 | Source = Application Error | ID = 1000
Description = Faulting application IEXPLORE.EXE, version 7.0.6000.16982, time stamp
0x4b2b56f5, faulting module ophookSE2.dll, version 12.0.0.1, time stamp 0x3eba2acd,
exception code 0xc0000005, fault offset 0x00004eef, process id 0xa78, application
start time 0x01cac39a609718fc.

Error - 3/14/2010 1:20:58 PM | Computer Name = your-4dacd0ea75 | Source = Application Error | ID = 1000
Description = Faulting application IEXPLORE.EXE, version 7.0.6000.16982, time stamp
0x4b2b56f5, faulting module ophookSE2.dll, version 12.0.0.1, time stamp 0x3eba2acd,
exception code 0xc0000005, fault offset 0x00004eef, process id 0x1460, application
start time 0x01cac39ab535d90c.

Error - 3/14/2010 1:25:57 PM | Computer Name = your-4dacd0ea75 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043c from line 45 of d:\vista_gdr\com\complus\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 3/14/2010 1:28:18 PM | Computer Name = your-4dacd0ea75 | Source = System Restore | ID = 8193
Description =

Error - 3/14/2010 6:59:49 PM | Computer Name = your-4dacd0ea75 | Source = Microsoft-Windows-CAPI2 | ID = 131584
Description =

Error - 3/15/2010 4:02:11 AM | Computer Name = your-4dacd0ea75 | Source = MsiInstaller | ID = 11706
Description =

Error - 3/15/2010 4:02:25 AM | Computer Name = your-4dacd0ea75 | Source = MsiInstaller | ID = 1023
Description =

[ IntelDH Events ]
Error - 2/11/2010 5:31:26 AM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 2/21/2010 10:54:59 AM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 2/21/2010 12:50:41 PM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 2/24/2010 6:57:54 PM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 2/25/2010 5:24:28 AM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 3/6/2010 10:46:36 AM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 3/7/2010 10:55:27 PM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 3/11/2010 5:29:20 AM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 3/14/2010 11:07:03 AM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 3/14/2010 12:38:50 PM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

[ System Events ]
Error - 3/15/2010 12:35:39 AM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 16 milliseconds.

Error - 3/15/2010 12:38:53 AM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 19 milliseconds.

Error - 3/15/2010 12:42:07 AM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 19 milliseconds.

Error - 3/15/2010 12:45:21 AM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 12 milliseconds.

Error - 3/15/2010 12:48:36 AM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 19 milliseconds.

Error - 3/15/2010 12:51:50 AM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 20 milliseconds.

Error - 3/15/2010 12:55:04 AM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 19 milliseconds.

Error - 3/15/2010 12:58:19 AM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 19 milliseconds.

Error - 3/15/2010 1:01:33 AM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 19 milliseconds.

Error - 3/15/2010 4:06:21 AM | Computer Name = your-4dacd0ea75 | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =


< End of report >
unable to run the GMER rootkit scan, first got the blue screen of death, followed by two additional attempts that froze up the system. I could not even use task manager to stop it, had to just turn it off and restart. Now the computer sounds like it has a million things going on and is painfully slow. HELP ! + the email bot sent another round of emails out to everyone in my email address list
I did try to run the GMER thing again, (4th time) same result basically. It began scanning, after about 10 minutes it caused a system error and the machine shut down and restarted. interesting, when the machine shuts down and restarts, it turns off the STOPzilla program and I cannot restart it unless I restart the whole system again. Dale Carnegie would be very disappointed in me, I don't think my incessant emails to friends and coworkers offering to sell them discount viagra is winning any friends…
Hi,

Do not install/uninstall anything on your computer unless advised.


Were you able to change your passwords from a clean computer?
You have to change your email password from a clean computer. Not on the infected one.

–Next–

Are you using a proxy server (127.0.0.1:9022)?

–Next–

You have µTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/d/security-centra…-p-id-theft-103

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

I would recommend that you uninstall µTorrent, via Control Panel -> Add or Remove Programs.

However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.

References for the risk of these programs can be found in these links:
http://www.esecurityguy.com/p2p_file_sharing
http://www.microsoft.com/protect/data/down…ilesharing.aspx

–Next–

Please go to the site below to scan the following files:
VirSCAN

Click on Browse, and upload the following file for analysis or copy/paste the text below into the browse box:
C:\Windows\System32\pmsbfn32.dll

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"

Repeat the procedure with the following file:
C:\Windows\unvise32.exe

Please post the results in your next reply.

–Next–

Please download exeHelper to your desktop.
Right-click on exeHelper.com then choose "Run as Administrator" to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

–Next–

Have you tried running GMER in safe mode? To do this,
  • Restart your computer.
  • Keep on tapping f8 when windows starts to boot. Do this before you see the windows screen.
  • When a list of menu appears, scroll to Safe Mode using the arrow keys then press Enter.
  • Log in with an Administrator account.
Try running GMER again and uncheck "Files" on the right hand column by clicking on the box beside it, if that still wont work then do the following:
We Need to check for Rootkits with RootRepeal
Please download RootRepeal one of these locations and save it to your desktop
Here
Here
Here
  • Right click [external image: Posted Image] then choose "Run as Administrator" on your desktop to run the tool.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check just these boxes:
  • [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:, and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.
To post in your next reply:
1. Have you changed your password?
2. Regarding the proxy server.
3. VirSCAN log.
4. exeHelper log.
5. GMER/RootRepeal log.
ok, I had typed out an entire page worth of info doing your fixes and typing the results as I went. stupid root repeal deal caused a system failure and made me shut down windows……GRRRRR anyway. I'll try again. Changed the password to the email from another computer. However logging in again today, the gargoyle must be watching and copying the new password. I unplugged the puter last night from the phone line and it still sent more carp** out afterwards, but not so far after I changed the password. So, I'm wondering if it was simply using my address and signin rather than my computer to send stuff? No idea on the proxy server question? my puter, MSN software, no AOL or anything so??? got rid of U torrent, no idea what it's associated with? VIR scan found nothing in either scan Root repeal didn't work and caused the MSN explorer system to crash as mentioned before, the thingy is still open, crash occured after I right clicked to run as admin. I'll try running it again after this posting so I don't have to type this whole thing again. by the way thanks for your help, sorry if I sound terse in my communications. I'm so fed up with this thing, it probably shows through.
Hi,

Have you uninstalled Avira when you installed Norton? Running more than one anti virus at the same time does not only slow down your computer but
provides less protection than they are programmed to do, due to the fact that they will be conflicting with each other rather than providing sufficient protection for your computer. Please uninstall one of your anti virus before proceeding with any of the fixes.

Could you also post Norton's log?

–Next–

Have you tried running GMER in safe mode?

Let's do another check:
Please download mbr.exe and save it to your root directory, usually C:\ <- (Important!).

  • Go to Start > Run and type: cmd.exe
  • press Ok.
  • At the command prompt type: c:\mbr.exe -t >>"C:\mbr.log"
  • press Enter.
  • A "DOS" box will open and quickly disappear. That is normal.
  • A log file named mbr.log will be created and saved to the root of the system drive (usually C:\).
  • Copy and paste the results of the mbr.log in your next reply.

If you want the log on the desktop and mbr.exe lives elsewhere, you need to append >"%userprofile%\desktop\mbr.log" to the command.

–Next–

Right click OTL.exe then choose "Run as Administrator" to run the tool.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    [2010/02/21 16:32:29 | 000,086,016 | —- | C] (MindVision Software) – C:\Windows\unvise32.exe
    @Alternate Data Stream - 64 bytes -> C:\Users\HP_Administrator\Documents\DSCN0889.MOV:TOC.WMV
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:9022
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • Then post the result and a new OTL log in your next reply. ( don't check the boxes beside LOP Check or Purity this time )
–Next–

Try changing your password again, this time from the computer we're cleaning.
To post in your next reply:
1. Norton log.
2. About GMER.
3. MBR log.
4. OTL fix log.
ok, I'll do this in sections so it it boots me, I'll be less irritated. Yes, I uninstalled Avira after installing Norton. Have not had any other emails sent so far, since I changed the password yesterday. upload of Norton's recent history should be attached.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI