This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Stop: c000021a Fatal Error, appletx.class Trojan.Gen. Norton Shutdown

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I am having multiple problems with my HP Pavilion DV5 (product # NA425AV) laptop. Here are the details:

Running Vista Home Premium, 64 bit. ATI Mobility Radeon Graphics Driver. AMD Athlon x2 Dual Core QL-60. 1900 MHZ processor. 4096 MB memory. I have checked to see if my model is on the HP Limited Warranty Service Enhancement list and it's not.

The issues most prevalent for the last six months or so are:

• CPU running at 98 -100% almost all the time, very slow IE, IE and other programs like MS Word not responding.

• A couple of months ago, both my battery and volume icons disappeared. They are both checked on the Notification Area tab in the Taskbar and Start Menu Properties but will not reappear.

• It has always run hot but has gotten extreme in the last six months. It runs hot enough to burn your legs if it's sitting on your lap and lately it's even hot on top. This past week it started randomly shutting down which I assume was due to the heat issue. When I would restart, it would run for a bit and then shut down again. I have used compressed air to try to clean the vent but it has not helped. I started to try to take it apart to get to the fan but after removing all the screws and getting as far as lifting the keyboard, I decided it is over my head. Further research online confirms this - HP really buried the fan in this unit.

• Last week after one of the restarts, I got a warning from Norton that my antivirus was turned off. I tried to turn it back on but it would come back and say that it had failed. I ended up doing a chat with a Norton tech and authorized remote access. Norton said they were going to remove my Norton 2009 software and update it with the 2010 version. The tech was working for just a short time and suddenly a BSOD appeared saying:
Stop: c000021a {Fatal System Error}
The Initial Session Process or System Process
terminated unexpectedly with a status of
0xc00000000 (0xc0000001 0x001005a0).
The system has been shut down.


• I ended up working on my own trying to restart without the BSOD - tried safe mode last known good config multiple times but kept getting the BSOD. I finally was able to start normally but then it would shut down because of the overheating issue (again, I'm assuming that's why). I put some freezer packs under the bottom to cool it down and eventually was able to install the updated Norton. When I then started up IE, my homepage was hijacked and I was redirected to MSN.com.

• Decided to contact HP to check on the overheat issue. Hours online with a tech (using my BF's laptop to chat), tech had me update the BIOS and reinstall Power Management to no avail. Tech said he believed the motherboard and the controllers had gone bad. Of course it's out of warranty by 6 month and he offered a repair at $400. Also said I could try a system recovery. When I asked him about known heat issues w/Pavilion models, he gave me a phone number to call customer support. I have not bothered to do that.

After dealing with the HP tech, I experienced additional errors:

• I went in to try to back up my data and my cd/dvd drive had disappeared. I ended up putting in a SanDisk into a USB hub and the cd/dvd drive reappeared but won't function. It tells me to put in a writable CD which of course is what I have put in already. I tried using a Microsoft Fixit solution but when I try to download, it tells me there was an error in downloading (nothing specific) and tells me to try again later.

• Catalyst Control Centre Host Application has stopped working.

• hpCaslNotification has stopped working. A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available.

• Error 1601: Windows Installer Service could not be accessed. This can occur if Windows Installer is not correctly installed. Check Problem Reports and Solutions in Control Panel. I checked and there was nothing listed under Reports and Solutions. I then looked at System Info and it showed Windows Error Reporting as disabled. I have since enabled it.

• 251 CMOS Checksum Error

• msiexec.exe Application Error Application failed to initialize properly (0xc0000142)

• Yesterday Norton found a trojan called appletx.class Trojan.Gen. Last night I got another Norton error that my antivirus was turned off and could not be repaired. Did another chat with a tech and had a repeat of last week with the same BSOD mentioned above. After several hours, I got rid of the BSOD and am out of safe mode.

Where I'm at now:

• Besides Norton, I have Malwarebytes, Super AntiSpyware, ATF and Spybot installed.

• Malwarebytes scan didn't turn up anything when I did a quick scan yesterday. I did get an error with Malwarebytes: (OpenEvent) Failed to perform desired action. Error Code 2.
• Super Antispyware found 4 cookies.

• ESET online scan nothing found

• Prevx online scan nothing found in either.

• Panda ActiveScan took about 12 hours to run - two threats found - a cookie and Generic trojan virus is listed as "Not disinfectable".
00167647 Cookie/Yadro c:\users\nadine\appdata\roaming\microsoft\windows\cookies\low\nadine@yadro[2].txt
05241074 Generic Trojan c:\swsetup\sp43325\data1.cab[cl264dec.ax]
•

• I downloaded DDS from the link provided on whatthetech.com and when I clicked the desktop icon, Norton popped up and said the file is “untrustworthy” and “not safe”.

Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:40:30 PM, on 7/1/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\PROGRA~2\Java\jre6\bin\jp2launcher.exe
C:\Program Files (x86)\Java\jre6\bin\java.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files (x86)\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\Users\Nadine\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {31c7d459-9cc3-44f2-9dca-fc11795309b4} - (no file)
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (file missing)
O2 - BHO: IEPlus - {045E075D-9C55-42F5-81C2-67D4A26F39AC} - C:\Program Files (x86)\IEPlus\shendoo\IEPlus.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (file missing)
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files (x86)\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files (x86)\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (file missing)
O15 - Trusted Zone: http://www.convergysworkathome.com
O16 - DPF: {03290DF3-5034-11D0-BC8C-524153480000} (StlView Control) - http://www.dpt-fast.com/stlview/astlview2005.dpt
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_17) -
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} (WNICheck2 Class) - http://www.convergysworkathome.com/AppHardT.CAB
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_a02f3f3d\AESTSr64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Netlogon - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Procedure Call (RPC) Locator (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_8adfd0a8\STacSV64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 12486 bytes

Hope I didn't give too much info! I've tried everything I know and am so frustrated! Where do I go from here?

Thanks much,

Dutchie
Posted Image

Beings you're running 64 bit will limit what tools we can run.

I can see if I see anything bad concerning Malware but as you know, you're having hardware issues.
When you're finished here, I'll send you over to our Tech Team,

Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in:
    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and include them in your next post.
Please include the following in your next post:
  • OTL and Extras logs
To be very honest with you, you should take your laptop into a known trusted repair shop. Any computer that is over heating like yours is, will end up totally dead.
Thanks much for your replies LDTate.

I failed to mention that I got a laptop chiller/fan unit that has significantly reduced the heat and I've had no more shutdowns, I will take it to my computer repairman to disasemble and clean the fan but he is in Germany until the second week in August so I really want to try to fix the other issues if at all possible.

I ran the scan as you directed and the OTL and Extras logs are posted below.

OTL logfile created on: 7/1/2010 6:41:05 PM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\Nadine\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
8.00 Gb Paging File | 5.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 287.17 Gb Total Space | 182.93 Gb Free Space | 63.70% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.82 Gb Free Space | 16.69% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MY-PC
Current User Name: Nadine
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Nadine\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Windows\SMINST\BLService.exe ()
PRC - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Nadine\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\asoehook.dll (Symantec Corporation)
MOD - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\microsoft.vc90.crt\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\microsoft.vc90.crt\msvcp90.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_8adfd0a8\STacSV64.exe (IDT, Inc.)
SRV:64bit: - (Ati External Event Utility) – C:\Windows\SysNative\Ati2evxx.exe (ATI Technologies Inc.)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\Hpservice.exe (Hewlett-Packard Corporation)
SRV:64bit: - (AESTFilters) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_a02f3f3d\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Apple Mobile Device) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2010/03/26 11:41:34 | 000,000,000 | —D | M]
SRV - (aspnet_state) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (Recovery Service for Windows) – C:\Windows\SMINST\BLService.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()
SRV - (IDriverT) – C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SYMTDIv) – C:\Windows\SysNative\Drivers\NISx64\1107000.00C\SYMTDIV.SYS (Symantec Corporation)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\Ironx64.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\SYMEFA64.SYS (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\Drivers\NISx64\1107000.00C\SRTSP64.SYS (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\SRTSPX64.SYS (Symantec Corporation)
DRV:64bit: - (ccHP) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\ccHPx64.sys (Symantec Corporation)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\SYMDS64.SYS (Symantec Corporation)
DRV:64bit: - (Revoflt) – C:\Windows\SysNative\DRIVERS\revoflt.sys (VS Revo Group)
DRV:64bit: - (pavboot) – C:\Windows\SysNative\drivers\pavboot64.sys (Panda Security, S.L.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RMCAST) RMCAST (Pgm) – C:\Windows\SysNative\DRIVERS\RMCAST.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (RTSTOR) – C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.)
DRV:64bit: - (enecir) – C:\Windows\SysNative\DRIVERS\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (athr) – C:\Windows\SysNative\DRIVERS\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (ahcix64s) – C:\Windows\SysNative\DRIVERS\ahcix64s.sys (AMD Technologies Inc.)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\DRIVERS\hpdskflt.sys (Hewlett-Packard Corporation)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\DRIVERS\Accelerometer.sys (Hewlett-Packard Corporation)
DRV:64bit: - (btwavdt) – C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) – C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) – C:\Windows\SysNative\DRIVERS\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\DRIVERS\serscan.sys (Microsoft Corporation)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (HSFHWAZL) – C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (Amddfltr64) – C:\Windows\SysNative\DRIVERS\Amddfltr64.sys (Advanced Micro Devices)
DRV:64bit: - (HpqRemHid) – C:\Windows\SysNative\DRIVERS\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\SysNative\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\DRIVERS\nvm60x64.sys (NVIDIA Corporation)
DRV:64bit: - (BCM43XV) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corporation)
DRV - (DrvAgent64) – C:\Windows\SysWOW64\drivers\DrvAgent64.SYS (Phoenix Technologies)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\VirusDefs\20100701.018\EX64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\VirusDefs\20100701.018\ENG64.SYS (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\IPSDefs\20100630.006\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\BASHDefs\20100619.001\BHDrvx64.sys (Symantec Corporation)
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
IE - HKLM\..\URLSearchHook: {31c7d459-9cc3-44f2-9dca-fc11795309b4} - Reg Error: Key error. File not found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {31c7d459-9cc3-44f2-9dca-fc11795309b4} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\IPSFFPlgn\ [2010/06/23 13:39:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\coFFPlgn\ [2010/06/20 05:49:10 | 000,000,000 | —D | M]


O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll File not found
O2 - BHO: (IEPlusBHO Class) - {045E075D-9C55-42F5-81C2-67D4A26F39AC} - C:\Program Files (x86)\IEPlus\shendoo\IEPlus.dll (shendoo)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll File not found
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\AdvancedOptions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\InfoDelivery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DontSetAutoplayCheckbox = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserFolderInStartMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMyGames = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogOff = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSearchCommInStartMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSearchInternetInStartMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAVolume = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCABattery = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesRecycleBin = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O8:64bit: - Extra context menu item: Check &Spelling; - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8:64bit: - Extra context menu item: Lookup on Wikipedia - C:\Program Files (x86)\ieSpell\wikipedia.HTM ()
O8:64bit: - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Check &Spelling; - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files (x86)\ieSpell\wikipedia.HTM ()
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth; Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: convergysworkathome.com ([www] http in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {03290DF3-5034-11D0-BC8C-524153480000} http://www.dpt-fast.com/stlview/astlview2005.dpt (StlView Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…/swdir8d204.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Value error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} http://www.convergysworkathome.com/AppHardT.CAB (WNICheck2 Class)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\Silhouette.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Silhouette.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/01/20 22:08:35 | 000,000,000 | —D | M]

Drivers32:64bit: aux - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi3 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midimapper - midimap.dll (Microsoft Corporation)
Drivers32:64bit: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer3 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32:64bit: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: wave - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave3 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wavemapper - msacm32.drv (Microsoft Corporation)
Drivers32: aux - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi3 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\Windows\SysWow64\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer3 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - C:\Windows\SysWow64\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\Windows\SysWow64\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\Windows\SysWow64\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\Windows\SysWow64\msgsm32.acm (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.iyuv - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\Windows\SysWow64\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\Windows\SysWow64\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\Windows\SysWow64\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave3 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\Windows\SysWow64\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 90 Days ==========

[2010/07/01 18:37:44 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Users\Nadine\Desktop\OTL.exe
[2010/07/01 15:27:55 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Local\Apple
[2010/06/30 21:39:28 | 000,921,512 | —- | C] (Symantec Corporation) – C:\Users\Nadine\Desktop\Norton_Removal_Tool.exe
[2010/06/30 12:17:27 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Roaming\Tific
[2010/06/29 10:55:13 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Roaming\SUPERAntiSpyware.com
[2010/06/29 10:55:13 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/06/29 10:54:42 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010/06/29 10:54:31 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/06/29 10:48:01 | 008,776,240 | —- | C] (SUPERAntiSpyware.com) – C:\Users\Nadine\Desktop\SUPERAntiSpyware.exe
[2010/06/29 05:56:45 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/06/29 05:56:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/06/27 15:45:23 | 000,033,800 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\pavboot64.sys
[2010/06/27 13:18:03 | 000,000,000 | R–D | C] – C:\Users\Nadine\Contacts
[2010/06/27 11:49:49 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/06/26 15:22:51 | 000,000,000 | —D | C] – C:\BiosSwSetup6-26-10
[2010/06/26 13:14:38 | 000,000,000 | —D | C] – C:\Users\Nadine\Desktop\ReInstall
[2010/06/26 12:52:27 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Local\CrashDumps
[2010/06/26 11:46:41 | 000,000,000 | —D | C] – C:\BiosSwSetup
[2010/06/26 10:19:27 | 000,000,000 | —D | C] – C:\ProgramData\{DA06AA03-DF24-4ECE-939E-1B0939235C66}
[2010/06/24 15:20:44 | 000,021,712 | —- | C] (Phoenix Technologies) – C:\Windows\SysWow64\drivers\DrvAgent64.SYS
[2010/06/24 15:20:42 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Local\eSupport.com
[2010/06/20 10:29:46 | 000,451,120 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symtdiv.sys
[2010/06/20 10:29:45 | 000,221,232 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symefa64.sys
[2010/06/20 10:29:44 | 000,433,200 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symds64.sys
[2010/06/20 10:29:44 | 000,032,304 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtspx64.sys
[2010/06/20 10:29:43 | 000,505,392 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtsp64.sys
[2010/06/20 10:29:42 | 000,150,064 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\ironx64.sys
[2010/06/20 10:29:41 | 000,615,040 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\cchpx64.sys
[2010/06/20 10:28:09 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NISx64\1107000.00C
[2010/06/20 05:32:00 | 000,173,104 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010/06/20 05:30:22 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/06/20 05:27:27 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NISx64
[2010/06/20 05:27:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton Internet Security
[2010/06/20 05:26:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller
[2010/06/20 02:41:37 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Local\ICS
[2010/06/20 00:32:34 | 000,000,000 | —D | C] – C:\ProgramData\SITEguard
[2010/06/20 00:28:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\STOPzilla!
[2010/06/20 00:28:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\iS3
[2010/06/20 00:28:18 | 000,000,000 | —D | C] – C:\ProgramData\STOPzilla!
[2010/06/18 10:32:38 | 000,000,000 | —D | C] – C:\Program Files\iPod(507)
[2010/06/18 10:32:38 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/06/18 10:30:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes(454)
[2010/06/18 10:30:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2010/06/18 10:30:54 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/06/18 10:00:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Panda Security
[2010/06/18 08:21:14 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/06/18 08:21:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2010/06/16 07:27:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live SkyDrive
[2010/06/16 07:24:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2010/06/16 00:12:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2010/06/15 18:40:43 | 000,000,000 | —D | C] – C:\ProgramData\HP Product Assistant
[2010/06/15 16:10:14 | 000,000,000 | —D | C] – C:\Program Files\HP
[2010/06/11 14:57:37 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Roaming\IrfanView
[2010/06/10 14:07:46 | 000,000,000 | —D | C] – C:\Users\Nadine\Documents\HP Photosmart Projects
[2010/06/07 09:04:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2010/05/14 10:06:10 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Local\VS Revo Group
[2010/05/14 10:05:59 | 000,031,800 | —- | C] (VS Revo Group) – C:\Windows\SysNative\drivers\revoflt.sys
[2010/05/14 10:05:55 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/05/14 09:11:55 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Local\NeoSmart_Technologies
[2010/05/14 09:08:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\NeoSmart Technologies
[2010/05/14 07:19:06 | 000,000,000 | —D | C] – C:\Program Files\Defraggler
[2010/05/14 07:03:55 | 000,000,000 | —D | C] – C:\Users\Nadine\Desktop\Tools
[2010/05/14 06:29:27 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/05/14 05:58:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010/05/13 22:39:26 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/05/13 22:39:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/05/13 19:44:02 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Roaming\NBC Direct
[2010/05/13 19:43:49 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Roaming\IDM
[2010/05/13 19:43:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Pando Networks
[2010/05/13 19:42:49 | 000,000,000 | —D | C] – C:\ProgramData\NBC Direct
[2010/05/13 19:42:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\NBC Direct
[2010/05/13 17:42:08 | 000,000,000 | —D | C] – C:\Windows\CheckSur
[2010/05/13 17:30:58 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Roaming\hpqLog
[2010/05/13 10:06:44 | 000,000,000 | —D | C] – C:\Windows\pss
[2010/05/12 13:35:54 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Adobe
[2010/05/09 02:22:06 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2010/05/09 01:26:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2010/05/07 12:29:37 | 000,000,000 | —D | C] – C:\ProgramData\WindowsSearch
[2010/04/20 17:54:07 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Roaming\HpUpdate
[2010/04/20 17:53:56 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2010/04/13 11:35:57 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Local\ElevatedDiagnostics
[2010/04/13 11:27:37 | 000,000,000 | —D | C] – C:\Windows\SysWow64\WindowsPowerShell
[2010/04/13 11:27:34 | 000,000,000 | —D | C] – C:\Windows\SysNative\WindowsPowerShell
[2010/04/13 11:16:35 | 000,000,000 | —D | C] – C:\Program Files\Microsoft ATS
[2010/04/08 10:55:19 | 000,000,000 | —D | C] – C:\ProgramData\{8C881E6D-E5A1-4765-AF9A-1AE1E78B41CD}
[2010/04/07 16:28:28 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/04/07 16:27:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Registry Mechanic
[2010/04/07 11:51:56 | 000,000,000 | —D | C] – C:\Users\Nadine\AppData\Local\IsolatedStorage
[2010/04/07 09:51:18 | 000,430,080 | —- | C] (Atheros) – C:\Windows\SysNative\athi1519.rra
[2010/04/06 16:03:14 | 002,231,606 | —- | C] (Macromedia, Inc.) – C:\ProgramData\Games.exe

========== Files - Modified Within 90 Days ==========

[2010/07/01 20:02:48 | 002,425,208 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\Cat.DB
[2010/07/01 19:45:54 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/01 19:45:54 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/01 18:42:49 | 009,175,040 | -HS- | M] () – C:\Users\Nadine\ntuser.dat
[2010/07/01 18:42:30 | 000,000,436 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{D71E26B4-F06E-49CC-9BE1-8FB60AFBF9E9}.job
[2010/07/01 18:38:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Users\Nadine\Desktop\OTL.exe
[2010/07/01 15:09:38 | 000,001,074 | —- | M] () – C:\Users\Nadine\Desktop\Internet Options.lnk
[2010/07/01 13:22:34 | 000,019,191 | —- | M] () – C:\Users\Nadine\Desktop\BSOD Forum Post.docx
[2010/07/01 12:40:30 | 000,012,488 | —- | M] () – C:\Users\Nadine\Documents\hijackthis7-1-10-001
[2010/07/01 07:49:16 | 000,000,402 | —- | M] () – C:\Windows\tasks\AWC AutoSweep.job
[2010/07/01 07:45:54 | 000,000,414 | —- | M] () – C:\Windows\tasks\AWC Update.job
[2010/07/01 07:45:54 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/01 07:45:06 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/01 06:54:54 | 000,524,288 | -HS- | M] () – C:\Users\Nadine\ntuser.dat{cccd52fd-7c45-11df-b4ef-c4981a535f34}.TMContainer00000000000000000001.regtrans-ms
[2010/07/01 06:54:54 | 000,065,536 | -HS- | M] () – C:\Users\Nadine\ntuser.dat{cccd52fd-7c45-11df-b4ef-c4981a535f34}.TM.blf
[2010/06/30 23:26:34 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/06/30 23:25:16 | 001,653,624 | -H– | M] () – C:\Users\Nadine\AppData\Local\IconCache.db
[2010/06/30 21:39:35 | 000,921,512 | —- | M] (Symantec Corporation) – C:\Users\Nadine\Desktop\Norton_Removal_Tool.exe
[2010/06/30 10:04:25 | 000,010,073 | —- | M] () – C:\Users\Nadine\Desktop\Scan notes.docx
[2010/06/29 11:42:58 | 000,215,552 | —- | M] () – C:\Users\Nadine\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/29 10:54:40 | 000,001,756 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/29 10:48:02 | 008,776,240 | —- | M] (SUPERAntiSpyware.com) – C:\Users\Nadine\Desktop\SUPERAntiSpyware.exe
[2010/06/29 08:32:21 | 000,000,000 | —- | M] () – C:\Users\Nadine\Desktop\.lock
[2010/06/29 08:23:19 | 000,001,824 | —- | M] () – C:\Users\Nadine\Desktop\Yahoo! SiteBuilder2.6-J.lnk
[2010/06/28 12:49:37 | 000,000,254 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/06/27 12:57:16 | 000,643,046 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/27 12:57:15 | 000,759,226 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/27 12:57:15 | 000,119,206 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/27 12:36:27 | 000,012,542 | —- | M] () – C:\Users\Nadine\Documents\hijackthis-26-June-10-002
[2010/06/27 12:26:20 | 000,012,566 | —- | M] () – C:\Users\Nadine\Documents\hijackthis26-June-10
[2010/06/27 10:35:02 | 000,000,629 | —- | M] () – C:\Users\Nadine\Documents\feeds.opml
[2010/06/27 10:34:58 | 000,313,320 | —- | M] () – C:\Users\Nadine\Documents\bookmark.htm
[2010/06/26 10:40:22 | 000,001,004 | —- | M] () – C:\Users\Public\Desktop\HP Support Assistant.lnk
[2010/06/26 06:30:00 | 000,000,690 | —- | M] () – C:\Windows\tasks\Norton Internet Security - Run Full System Scan - Nadine.job
[2010/06/25 10:27:25 | 000,011,504 | —- | M] () – C:\Users\Nadine\Documents\hijackthis 10-06-25-001
[2010/06/24 15:20:44 | 000,021,712 | —- | M] (Phoenix Technologies) – C:\Windows\SysWow64\drivers\DrvAgent64.SYS
[2010/06/23 08:01:42 | 000,002,279 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010/06/20 05:30:22 | 000,173,104 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010/06/20 05:30:22 | 000,007,440 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010/06/20 05:30:22 | 000,000,854 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010/06/20 04:02:43 | 000,524,288 | -HS- | M] () – C:\Users\Nadine\ntuser.dat{cccd52fd-7c45-11df-b4ef-c4981a535f34}.TMContainer00000000000000000002.regtrans-ms
[2010/06/20 03:58:01 | 000,518,296 | —- | M] () – C:\Users\Nadine\Documents\ccleanerBackUpFiles_20100620_035723.reg
[2010/06/20 03:31:52 | 000,524,288 | -HS- | M] () – C:\Users\Nadine\ntuser.dat{7d3957f8-7c42-11df-b9fc-e675d58c8b3b}.TMContainer00000000000000000002.regtrans-ms
[2010/06/20 03:31:52 | 000,524,288 | -HS- | M] () – C:\Users\Nadine\ntuser.dat{7d3957f8-7c42-11df-b9fc-e675d58c8b3b}.TMContainer00000000000000000001.regtrans-ms
[2010/06/20 03:31:52 | 000,065,536 | -HS- | M] () – C:\Users\Nadine\ntuser.dat{7d3957f8-7c42-11df-b9fc-e675d58c8b3b}.TM.blf
[2010/06/20 03:08:35 | 000,524,288 | -HS- | M] () – C:\Users\Nadine\ntuser.dat{d81784b4-7c33-11df-a9e8-ad9a4eb50b34}.TMContainer00000000000000000001.regtrans-ms
[2010/06/20 03:08:35 | 000,065,536 | -HS- | M] () – C:\Users\Nadine\ntuser.dat{d81784b4-7c33-11df-a9e8-ad9a4eb50b34}.TM.blf
[2010/06/20 02:57:50 | 000,524,288 | -HS- | M] () – C:\Users\Nadine\ntuser.dat{d81784b4-7c33-11df-a9e8-ad9a4eb50b34}.TMContainer00000000000000000002.regtrans-ms
[2010/06/20 01:26:53 | 000,524,288 | -HS- | M] () – C:\Users\Nadine\ntuser.dat{0e32ecdd-30b0-11df-b9d3-002186d6fad5}.TMContainer00000000000000000001.regtrans-ms
[2010/06/20 01:26:53 | 000,065,536 | -HS- | M] () – C:\Users\Nadine\ntuser.dat{0e32ecdd-30b0-11df-b9d3-002186d6fad5}.TM.blf
[2010/06/18 10:55:30 | 000,001,804 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/06/16 09:15:34 | 000,391,744 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/06/16 00:08:25 | 000,107,520 | —- | M] () – C:\Users\Nadine\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/06/15 18:34:34 | 000,001,218 | —- | M] () – C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/06/15 18:09:13 | 000,002,203 | —- | M] () – C:\Users\Public\Desktop\Windows Live Photo Gallery.lnk
[2010/06/14 11:45:48 | 000,632,782 | —- | M] () – C:\Users\Nadine\Documents\ccleanerBackUpFiles_20100614_112842.reg
[2010/06/10 16:42:59 | 000,000,732 | —- | M] () – C:\Users\Nadine\AppData\Local\d3d9caps64.dat
[2010/06/03 11:10:30 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2010/05/14 10:03:35 | 000,000,496 | —- | M] () – C:\Users\Nadine\Documents\Backup Passwords.crd
[2010/05/14 09:12:19 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\tviresource.val
[2010/05/14 06:16:30 | 000,754,664 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/14 01:32:01 | 000,000,172 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\isolate.ini
[2010/05/13 20:37:16 | 000,147,921 | —- | M] () – C:\Windows\hpwins05.dat
[2010/05/13 16:46:20 | 000,090,674 | —- | M] () – C:\Users\Nadine\LLC.docx
[2010/05/12 00:42:19 | 000,000,410 | —- | M] () – C:\Windows\tasks\SmartDefrag.job
[2010/05/05 23:01:59 | 000,451,120 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symtdiv.sys
[2010/05/05 23:01:43 | 000,001,473 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symnetv.inf
[2010/05/05 23:01:43 | 000,001,445 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symnet.inf
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/29 00:03:51 | 000,150,064 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\ironx64.sys
[2010/04/29 00:03:51 | 000,007,402 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\iron.cat
[2010/04/29 00:03:51 | 000,000,771 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\iron.inf
[2010/04/26 03:18:45 | 000,007,829 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symefa64.cat
[2010/04/24 06:31:04 | 000,003,373 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symefa.inf
[2010/04/21 22:02:36 | 000,007,787 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symnetv64.cat
[2010/04/21 22:02:36 | 000,007,368 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symnet64.cat
[2010/04/21 22:02:20 | 000,221,232 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symefa64.sys
[2010/04/21 22:01:56 | 000,007,406 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symds64.cat
[2010/04/21 21:29:51 | 000,505,392 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtsp64.sys
[2010/04/21 21:29:51 | 000,032,304 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtspx64.sys
[2010/04/21 21:29:51 | 000,007,414 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtspx64.cat
[2010/04/21 21:29:51 | 000,001,421 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtspx64.inf
[2010/04/21 21:29:50 | 000,007,410 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtsp64.cat
[2010/04/21 21:29:50 | 000,001,437 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtsp64.inf
[2010/04/21 07:33:36 | 000,000,680 | —- | M] () – C:\Users\Nadine\AppData\Local\d3d9caps.dat
[2010/04/13 11:18:08 | 003,211,264 | —- | M] () – C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2010/04/13 11:18:08 | 000,196,608 | —- | M] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2010/04/13 11:18:08 | 000,065,536 | —- | M] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[2010/04/06 16:03:16 | 002,231,606 | —- | M] (Macromedia, Inc.) – C:\ProgramData\Games.exe

========== Files Created - No Company Name ==========

[2010/07/01 15:08:05 | 000,001,074 | —- | C] () – C:\Users\Nadine\Desktop\Internet Options.lnk
[2010/07/01 13:22:27 | 000,019,191 | —- | C] () – C:\Users\Nadine\Desktop\BSOD Forum Post.docx
[2010/07/01 12:40:28 | 000,012,488 | —- | C] () – C:\Users\Nadine\Documents\hijackthis7-1-10-001
[2010/06/30 10:04:07 | 000,010,073 | —- | C] () – C:\Users\Nadine\Desktop\Scan notes.docx
[2010/06/29 10:54:39 | 000,001,756 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/28 12:49:37 | 000,000,254 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/06/27 12:36:22 | 000,012,542 | —- | C] () – C:\Users\Nadine\Documents\hijackthis-26-June-10-002
[2010/06/27 12:26:18 | 000,012,566 | —- | C] () – C:\Users\Nadine\Documents\hijackthis26-June-10
[2010/06/27 10:35:02 | 000,000,629 | —- | C] () – C:\Users\Nadine\Documents\feeds.opml
[2010/06/27 10:32:01 | 000,313,320 | —- | C] () – C:\Users\Nadine\Documents\bookmark.htm
[2010/06/26 10:40:21 | 000,001,004 | —- | C] () – C:\Users\Public\Desktop\HP Support Assistant.lnk
[2010/06/25 10:27:24 | 000,011,504 | —- | C] () – C:\Users\Nadine\Documents\hijackthis 10-06-25-001
[2010/06/23 07:48:55 | 002,425,208 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\Cat.DB
[2010/06/20 10:29:46 | 000,007,787 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symnetv64.cat
[2010/06/20 10:29:46 | 000,007,368 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symnet64.cat
[2010/06/20 10:29:46 | 000,001,473 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symnetv.inf
[2010/06/20 10:29:46 | 000,001,445 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symnet.inf
[2010/06/20 10:29:45 | 000,007,829 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symefa64.cat
[2010/06/20 10:29:45 | 000,003,373 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symefa.inf
[2010/06/20 10:29:44 | 000,007,406 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symds64.cat
[2010/06/20 10:29:44 | 000,002,793 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\symds.inf
[2010/06/20 10:29:43 | 000,007,414 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtspx64.cat
[2010/06/20 10:29:43 | 000,007,410 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtsp64.cat
[2010/06/20 10:29:43 | 000,001,437 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtsp64.inf
[2010/06/20 10:29:43 | 000,001,421 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\srtspx64.inf
[2010/06/20 10:29:42 | 000,007,402 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\iron.cat
[2010/06/20 10:29:42 | 000,000,771 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\iron.inf
[2010/06/20 10:29:41 | 000,007,358 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\cchpx64.cat
[2010/06/20 10:29:41 | 000,001,838 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\cchpx64.inf
[2010/06/20 10:28:09 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1107000.00C\isolate.ini
[2010/06/20 05:32:00 | 000,007,440 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010/06/20 05:32:00 | 000,000,854 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010/06/20 05:29:45 | 000,002,279 | —- | C] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2010/06/20 03:57:50 | 000,518,296 | —- | C] () – C:\Users\Nadine\Documents\ccleanerBackUpFiles_20100620_035723.reg
[2010/06/20 03:48:38 | 000,524,288 | -HS- | C] () – C:\Users\Nadine\ntuser.dat{cccd52fd-7c45-11df-b4ef-c4981a535f34}.TMContainer00000000000000000002.regtrans-ms
[2010/06/20 03:48:38 | 000,524,288 | -HS- | C] () – C:\Users\Nadine\ntuser.dat{cccd52fd-7c45-11df-b4ef-c4981a535f34}.TMContainer00000000000000000001.regtrans-ms
[2010/06/20 03:48:38 | 000,065,536 | -HS- | C] () – C:\Users\Nadine\ntuser.dat{cccd52fd-7c45-11df-b4ef-c4981a535f34}.TM.blf
[2010/06/20 03:29:38 | 000,524,288 | -HS- | C] () – C:\Users\Nadine\ntuser.dat{7d3957f8-7c42-11df-b9fc-e675d58c8b3b}.TMContainer00000000000000000002.regtrans-ms
[2010/06/20 03:29:38 | 000,524,288 | -HS- | C] () – C:\Users\Nadine\ntuser.dat{7d3957f8-7c42-11df-b9fc-e675d58c8b3b}.TMContainer00000000000000000001.regtrans-ms
[2010/06/20 03:29:38 | 000,065,536 | -HS- | C] () – C:\Users\Nadine\ntuser.dat{7d3957f8-7c42-11df-b9fc-e675d58c8b3b}.TM.blf
[2010/06/20 01:39:27 | 000,524,288 | -HS- | C] () – C:\Users\Nadine\ntuser.dat{d81784b4-7c33-11df-a9e8-ad9a4eb50b34}.TMContainer00000000000000000002.regtrans-ms
[2010/06/20 01:39:27 | 000,524,288 | -HS- | C] () – C:\Users\Nadine\ntuser.dat{d81784b4-7c33-11df-a9e8-ad9a4eb50b34}.TMContainer00000000000000000001.regtrans-ms
[2010/06/20 01:39:26 | 000,065,536 | -HS- | C] () – C:\Users\Nadine\ntuser.dat{d81784b4-7c33-11df-a9e8-ad9a4eb50b34}.TM.blf
[2010/06/18 10:55:30 | 000,001,804 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/06/15 18:34:34 | 000,001,218 | —- | C] () – C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/06/15 18:09:13 | 000,002,203 | —- | C] () – C:\Users\Public\Desktop\Windows Live Photo Gallery.lnk
[2010/06/14 11:30:52 | 000,632,782 | —- | C] () – C:\Users\Nadine\Documents\ccleanerBackUpFiles_20100614_112842.reg
[2010/06/10 16:42:56 | 000,000,732 | —- | C] () – C:\Users\Nadine\AppData\Local\d3d9caps64.dat
[2010/06/03 11:10:30 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/05/14 10:03:35 | 000,000,496 | —- | C] () – C:\Users\Nadine\Documents\Backup Passwords.crd
[2010/05/14 09:12:19 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\tviresource.val
[2010/05/13 20:37:16 | 000,012,616 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/05/13 18:09:58 | 000,000,371 | —- | C] () – C:\ProgramData\HPWALog.txt
[2010/05/13 17:20:51 | 000,000,436 | -H– | C] () – C:\Windows\tasks\User_Feed_Synchronization-{D71E26B4-F06E-49CC-9BE1-8FB60AFBF9E9}.job
[2010/05/13 16:46:12 | 000,090,674 | —- | C] () – C:\Users\Nadine\LLC.docx
[2010/04/29 00:26:43 | 000,000,414 | —- | C] () – C:\Windows\tasks\AWC Update.job
[2010/04/29 00:26:41 | 000,000,402 | —- | C] () – C:\Windows\tasks\AWC AutoSweep.job
[2010/04/13 11:16:46 | 003,211,264 | —- | C] () – C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2010/04/13 11:16:46 | 000,196,608 | —- | C] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2010/04/13 11:16:46 | 000,065,536 | —- | C] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[2009/09/14 19:48:52 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/09/14 19:47:05 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/01/25 20:51:53 | 000,754,664 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini

========== LOP Check ==========

[2009/05/12 10:19:36 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\7Wonders
[2010/02/16 00:28:41 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\cerasus.media
[2010/05/13 22:21:46 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\IDM
[2010/02/12 10:20:10 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\ieSpell
[2010/01/20 14:37:27 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\Image Zone Express
[2010/03/26 13:05:13 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\IObit
[2010/06/26 13:15:57 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\IrfanView
[2009/10/13 13:55:54 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\IronCode
[2009/05/04 18:26:04 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\iWin
[2010/05/13 22:21:49 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\NBC Direct
[2009/10/14 09:30:03 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\PlayFirst
[2009/09/04 13:33:07 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\Printer Info Cache
[2010/06/30 12:17:27 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\Tific
[2010/05/13 12:11:34 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\Uniblue
[2008/12/19 09:26:36 | 000,000,000 | —D | M] – C:\Users\Nadine\AppData\Roaming\WildTangent
[2010/07/01 07:49:16 | 000,000,402 | —- | M] () – C:\Windows\Tasks\AWC AutoSweep.job
[2010/07/01 07:45:54 | 000,000,414 | —- | M] () – C:\Windows\Tasks\AWC Update.job
[2010/06/30 23:26:35 | 000,032,602 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/05/12 00:42:19 | 000,000,410 | —- | M] () – C:\Windows\Tasks\SmartDefrag.job
[2010/07/01 18:42:30 | 000,000,436 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{D71E26B4-F06E-49CC-9BE1-8FB60AFBF9E9}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/12/13 23:26:28 | 000,000,368 | -H– | M] () – C:\IPH.PH
[2006/12/02 01:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2002/10/17 23:23:14 | 000,008,200 | —- | M] () – C:\opa12.bak
[2009/01/09 16:21:54 | 000,008,422 | —- | M] () – C:\opa12.dat
[2010/07/01 07:44:39 | 042,885,119 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\user32.dll /md5 >
[2009/04/11 01:26:45 | 000,648,704 | —- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 – C:\Windows\SysWOW64\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/01/20 21:50:35 | 000,179,200 | —- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B – C:\Windows\SysWOW64\ws2_32.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:D1B5B4F1
< End of report >

OTL Extras logfile created on: 7/1/2010 6:41:05 PM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\Nadine\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
8.00 Gb Paging File | 5.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 287.17 Gb Total Space | 182.93 Gb Free Space | 63.70% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.82 Gb Free Space | 16.69% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MY-PC
Current User Name: Nadine
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 00 6B 4A 8F 72 73 CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02486718-D2C7-45EB-B81A-CC57EDFEB7A9}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{06D06B4B-6682-46FF-B5F7-47FFB810A475}" = lport=138 | protocol=17 | dir=in | app=system |
"{7BDF11AB-0A70-40A6-BDBD-ED316B82A559}" = lport=445 | protocol=6 | dir=in | app=system |
"{8CA37866-60F4-44A5-AE69-6CBE61AD7D39}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{8E615250-7C32-459B-8CD4-F807FB72FAC3}" = rport=137 | protocol=17 | dir=out | app=system |
"{929A3EDC-0838-405D-8475-4FB1905CFCB5}" = rport=139 | protocol=6 | dir=out | app=system |
"{9E5AB530-A0F4-467B-BDB9-3738E2C64B43}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A304742D-E1B4-4C88-8FCD-EEE1012CBF12}" = lport=137 | protocol=17 | dir=in | app=system |
"{C8F16154-6336-46DF-B682-854131D7DBBC}" = rport=138 | protocol=17 | dir=out | app=system |
"{D4E1D6A7-DA73-4C09-990B-ECB614B06229}" = lport=139 | protocol=6 | dir=in | app=system |
"{DE07A106-DDCC-4F24-B3DA-895773FE5054}" = rport=445 | protocol=6 | dir=out | app=system |
"{FDB37242-BF57-4F6D-AD87-24B22A298CF5}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01B59414-5D1B-4783-B7E9-0D781C86F531}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{06799911-0F40-4EC7-BC5E-C5C648B7F1B1}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{0B5C320D-BDEC-4255-BF77-AF70D58DF221}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe |
"{29C54CE4-DC88-4E35-97D6-0CF47FE17739}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{371204D6-E16E-43C5-9BD2-E590AB8A81B3}" = dir=in | app=c:\program files (x86)\hp\quickplay\qpservice.exe |
"{39FBA481-2638-43FF-8574-EA7F0C42B186}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe |
"{3D9FE1ED-33CD-4BB0-82C8-B466BF04E6DF}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{444355D6-3F6A-4CCC-871D-5CB2DD6C3156}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe |
"{45058200-7BF9-4EA6-93A7-2FA2346B88A5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{45CACE90-B88D-4975-A966-EEEE235AEDCE}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{47DBFFC3-192C-4C1E-92C0-8CEB275A13F5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{4889D7C0-173D-499F-9198-B3E17B338DE5}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{5110A6C5-D9C1-4104-BF30-02D511C4068F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{540B2A5F-F238-4729-8D69-600C92D2CE19}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{566D7C72-3D16-4ED2-B374-8E3A8BA3AD2A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{569A73EA-4112-42C0-BC52-E3F9F0092FCD}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |
"{59052650-AD7A-430F-B765-A1B071BB930A}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{5CB1660D-E679-40A3-9520-CAF41B40C9DB}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{5D7FAC21-BB5F-4146-85EF-3F9FC1A22229}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{5F77F681-1FF3-4552-801D-563385BACCB8}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{62A8A233-E58E-4C1E-A8A7-A08FE1C9F229}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{661C867C-0D81-4D5C-B4EF-0B170068EDC6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{6D41F80A-35FE-41CC-8FF0-A4483CA2F4CD}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqnrs08.exe |
"{6EF67BBF-FF84-48BC-8BC9-84B8C304F979}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{73ED6DD9-FDF8-4C38-A696-CF36859D0F6A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{9CA29CB8-30FD-4A8F-A5D0-F4DEE39910BA}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{9E4871FC-D995-4299-9289-E31A7712431B}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{A258625F-0496-4AD4-B975-D3760159D1D4}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{A2EF74A9-D912-42DA-93C0-1C325FE859C0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpse.exe |
"{A91A5A79-6D01-4F72-8B9C-D5149EF23031}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{AAB5B7EF-8FE3-47F0-B308-5B69F371260B}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{B6AEBD4A-345E-4748-9BC0-B0E53EEEE06B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe |
"{BAC10CCE-4614-4691-A169-76B029857D54}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{BAC6860A-4A15-46A2-A125-6883B6CCA4DC}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{CBB1FD68-97FD-4209-8F1E-7B15DE380F39}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |
"{D79129B2-06E0-40B9-A118-1929087C947F}" = dir=in | app=c:\program files (x86)\hp\quickplay\qp.exe |
"{D9F0CF00-8BFE-4B8A-9797-EFA44D435FAA}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{DB27317C-C2BC-46AC-9B1F-3AFFC14AEB90}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe |
"{DC76CBC6-8514-4843-A4A7-054705403D51}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{DCB2D2D9-3C25-4A4F-B247-572A25B0F3D2}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe |
"{DE8BA1D0-1FE9-4C43-9AF0-B2E76ECDDBE8}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{DFB80FE9-C3BB-4295-ACB9-9D5D0C097BF3}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |
"{E2C84228-80EA-4DFE-AFCB-CB5409DBAC33}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E55F716A-1D1B-4A24-B287-B7AB0B2A3060}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{EC7A957E-F408-41BB-BFB3-E33F11A345AB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F075762C-2E03-4563-92A4-3F31170DFB43}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{F2152404-622E-4BAB-9E23-350A7E761FF5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqscnvw.exe |
"{F4248205-F489-47F2-9208-6A545C5E756A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe |
"{FEFE3825-919E-494B-9779-AD04C9AD5660}" = dir=in | app=e:\setup\hpznui40.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.6200
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{17E02F38-FF2D-4c3d-83DF-ECE2A1D20A5E}" = AIO_CDB_ToolboxIni64
"{1AD2F8FE-A357-4728-BDF8-B92D794CE793}" = HP QuickTouch 1.00 D2
"{2323253C-33E7-821A-2826-B3CF44DF959C}" = ccc-utility64
"{26A24AE4-039D-4CA4-87B4-2F86416020FF}" = Java™ 6 Update 20 (64-bit)
"{2F97CE84-9C33-4631-821B-85EA371EA254}" = ProtectSmart Hard Drive Protection
"{328CC232-CFDC-468B-A214-2E21300E4CB5}" = Apple Mobile Device Support
"{4BFA6EEB-AAED-4334-8E98-A907DE4DD5CF}" = AMD Driver Support for HP 3D DriverGuard
"{53529DAD-F7C9-476E-87CC-1547C4E3E821}" = iTunes
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{5FB58283-FF2A-813F-423E-57DF0C60FB10}" = ATI Catalyst Install Manager
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.2.0
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}" = HP Officejet Pro All-In-One Series
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}" = Bonjour
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F83779DF-E1F5-43A2-A7BE-732F856FADB7}" = Microsoft SQL Server Compact 3.5 SP1 x64 English
"07B260955637F1FF7587ED2AA87459040DD09BF7" = Windows Driver Package - ENE (enecir) HIDClass (09/04/2008 2.6.0.0)
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Defraggler" = Defraggler
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{024D1716-9F42-0039-06E5-F4279D6C4382}" = CCC Help Russian
"{04556846-E511-3FE9-E824-3588075C8036}" = Catalyst Control Center Graphics Full Existing
"{05CD72BE-7783-AAB9-0C05-2D8DBD2DD444}" = Catalyst Control Center Localization Dutch
"{0612E132-33FF-4488-9C31-F8D485D6866D}" = Catalyst Control Center Graphics Light
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{0B3DB1B2-404C-AAA8-B32E-E65520EDE74D}" = CCC Help Polish
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{10504622-2818-C312-55CC-A72D36A31DBC}" = CCC Help Swedish
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{1FCC7185-DCF3-4478-86AD-C2F2D1116BE3}" = 7300
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 17
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2A34320A-56F9-9C4F-D325-77AC8A54C8B6}" = Catalyst Control Center Localization Japanese
"{2C9FF444-79C0-C0C4-7B21-0E77C872AF53}" = CCC Help Danish
"{2CA3E0A5-9281-6E67-1843-A6CC0B00BD74}" = Catalyst Control Center Localization French
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{31775690-0E29-2AB1-75DE-C406152CBD1D}" = Catalyst Control Center Localization Chinese Standard
"{32257980-61DF-4685-A72B-08683838233B}" = 7300_Help
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3466C4D1-508A-0E36-EB05-2E53766F27E0}" = CCC Help Italian
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 D3
"{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}" = muvee autoProducer 6.1
"{377739AE-00D9-4E80-8ECB-4C8A7EFFE526}" = 7300Trb
"{38DCD6F5-C4DC-25E5-C113-0A909558FC2C}" = CCC Help Norwegian
"{3FA160E2-066B-8D77-FCF4-F001F236E8E7}" = CCC Help Spanish
"{3FA93E4C-CB3B-4B25-B091-9DB0FCC56A74}" = Catalyst Control Center - Branding
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{431CED44-A6D3-4E4A-2B76-04D1A861FCCE}" = Catalyst Control Center Localization Swedish
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.7
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{475144D0-A4D6-C553-42B5-7BB60FCEF9EC}" = Catalyst Control Center Localization German
"{49BA6327-744C-3D20-16DB-6E98BF66D0FD}" = Catalyst Control Center Localization Danish
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4B4D411D-E363-7E6B-68C3-C8E2EF02B7C6}" = CCC Help Chinese Traditional
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{50DB0F17-4180-31F7-F26B-B40CBA8BA6E0}" = CCC Help German
"{5396C246-53B5-4BBA-62DC-8308C7357EFE}" = Catalyst Control Center Localization Polish
"{54CAEF60-0258-2D8E-F01F-24BC689EA8A9}" = Catalyst Control Center Localization Portuguese
"{54CC7901-804D-4155-B353-21F0CC9112AB}" = HP Wireless Assistant
"{560BB29B-41C5-88E4-4847-B4B1DDB47B9B}" = Catalyst Control Center Localization Czech
"{59748B12-406B-7EA4-355D-3BBD62E97C69}" = Catalyst Control Center Localization Turkish
"{5B4E5823-7265-9A19-A871-36E75824F7BE}" = CCC Help French
"{5EBC76DA-573E-7D96-A6F8-F4B9DE97A15F}" = Catalyst Control Center Localization Greek
"{623AD94E-1621-5AA1-BD6D-0EF08C9D7851}" = Catalyst Control Center Core Implementation
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6DBCFFF6-2A7B-4AE4-8FC8-1216442E2814}" = CCC Help Korean
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6FCBD7F7-6A29-089F-E5DB-E33EFCF306CD}" = Catalyst Control Center Localization Spanish
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{762D9F20-593B-436E-CAC3-B3D9F4DA7A90}" = Catalyst Control Center Localization Chinese Traditional
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{8436F8D7-AA62-83DA-3BC5-E04871BF5F61}" = CCC Help Portuguese
"{84F40C39-1E61-B3A7-833A-3A376AB53394}" = CCC Help Japanese
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISER_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{931FB38C-D5D4-4DBD-3723-50140A67F276}" = CCC Help Turkish
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96A959C9-51E1-C920-A9FA-269BB462A940}" = CCC Help Czech
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A102E7E3-2A4E-F509-3EF6-019F45C83196}" = CCC Help Dutch
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{A55F4F9F-CCA8-4732-AA1F-0390A4A50947}" = C4700
"{A57222BD-51E3-7765-A008-9B6428402A59}" = CCC Help Hungarian
"{A8ACD338-255C-B53D-7F19-ED7293B291E8}" = Catalyst Control Center Localization Norwegian
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B60DCA15-56A3-4D2D-8747-22CF7D7B588B}" = HP Support Assistant
"{BD41A0CF-79B4-98D8-B9B9-3DE8BEC8A861}" = Catalyst Control Center Localization Finnish
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C4B2636B-D76D-7C23-3010-99E96693F0B5}" = Catalyst Control Center Graphics Previews Vista
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C9E9386A-7E81-796A-3465-8471A239A8A0}" = CCC Help Chinese Standard
"{CA4498C8-5146-E527-27A7-1B4F81C9BF05}" = CCC Help Thai
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DEC3A80C-49D3-2885-2A03-3FBA61A5D40F}" = Catalyst Control Center Localization Italian
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E0B276B1-97D7-7AD2-548F-248A7745A1ED}" = CCC Help Greek
"{E2ADC6FA-4233-54E6-29EC-E60EAD096A50}" = Catalyst Control Center Localization Hungarian
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3EA025D-29A0-530C-9CA7-DBB5C49BB6DB}" = Skins
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{E96FFA19-E94B-D32B-E103-E78A0877245A}" = Catalyst Control Center Localization Thai
"{EAE4AD65-89F2-3DE8-DF46-CCB34393CAA0}" = Catalyst Control Center Localization Russian
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F31E534B-4199-4552-8154-5C130710D68E}" = HP Total Care Advisor
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F447BD4C-65C3-A6D9-8A5F-5E822E32E1BC}" = Catalyst Control Center Localization Korean
"{F48098CD-2D66-4861-85EC-DC1D4D09D5F9}" = HP User Guides 0102
"{F48FEA7A-2B87-8270-927C-20A0E7E5EBC2}" = CCC Help English
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FCC92CBC-F520-A906-C002-9A6236308916}" = Catalyst Control Center Graphics Full New
"{FEC99680-66C4-C8C7-084B-2FB1B257777C}" = CCC Help Finnish
"{FEEDAB32-F937-8319-D3F1-FFFC98C2111E}" = ccc-core-static
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AIM_6" = AIM 6
"CCleaner" = CCleaner
"ENTERPRISER" = Microsoft Office Enterprise 2007
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IEPlus_is1" = IEPlus 1.5.0
"ieSpell" = ieSpell
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NIS" = Norton Internet Security
"PIXresizer_is1" = PIXresizer 2.0.4
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! SiteBuilder2.6-J" = Yahoo! SiteBuilder2.6-J

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/30/2010 1:24:47 PM | Computer Name = My-PC | Source = Application Error | ID = 1000
Description = Faulting application hpCaslNotification.exe, version 3.0.31.1, time
stamp 0x4a79f9a4, faulting module KERNEL32.dll, version 6.0.6002.18005, time stamp
0x49e041d1, exception code 0xe0434f4d, fault offset 0x00000000000176fd, process
id 0x¼ m ¼ m , application start time 0x¼ m ¼ m .

Error - 6/30/2010 1:40:21 PM | Computer Name = My-PC | Source = Application Error | ID = 1000
Description = Faulting application hpCaslNotification.exe, version 3.0.31.1, time
stamp 0x4a79f9a4, faulting module KERNEL32.dll, version 6.0.6002.18005, time stamp
0x49e041d1, exception code 0xe0434f4d, fault offset 0x00000000000176fd, process
id 0xÄ m Ä m , application start time 0xÄ m Ä m .

Error - 6/30/2010 4:49:02 PM | Computer Name = My-PC | Source = System Restore | ID = 8193
Description =

Error - 6/30/2010 4:49:02 PM | Computer Name = My-PC | Source = System Restore | ID = 8210
Description =

Error - 6/30/2010 10:28:49 PM | Computer Name = My-PC | Source = Bonjour Service | ID = 100
Description = WSARecvMsg failed (10022)

Error - 6/30/2010 10:29:36 PM | Computer Name = My-PC | Source = Application Error | ID = 1000
Description = Faulting application hpCaslNotification.exe, version 3.0.31.1, time
stamp 0x4a79f9a4, faulting module KERNEL32.dll, version 6.0.6002.18005, time stamp
0x49e041d1, exception code 0xe0434f4d, fault offset 0x00000000000176fd, process
id 0xÜ m Ü m , application start time 0xÜ m Ü m .

Error - 6/30/2010 10:29:38 PM | Computer Name = My-PC | Source = Application Error | ID = 1000
Description = Faulting application hpCaslNotification.exe, version 3.0.31.1, time
stamp 0x4a79f9a4, faulting module KERNEL32.dll, version 6.0.6002.18005, time stamp
0x49e041d1, exception code 0xe0434f4d, fault offset 0x00000000000176fd, process
id 0x m  m , application start time 0x m  m .

Error - 7/1/2010 12:08:34 AM | Computer Name = My-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/1/2010 12:21:05 AM | Computer Name = My-PC | Source = Application Error | ID = 1000
Description = Faulting application hpCaslNotification.exe, version 3.0.31.1, time
stamp 0x4a79f9a4, faulting module KERNEL32.dll, version 6.0.6002.18005, time stamp
0x49e041d1, exception code 0xe0434f4d, fault offset 0x00000000000176fd, process
id 0x m m , application start time 0x m m .

Error - 7/1/2010 12:37:06 AM | Computer Name = My-PC | Source = WinMgmt | ID = 10
Description =

[ Media Center Events ]
Error - 4/30/2009 12:37:19 AM | Computer Name = Nadine-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 6/9/2009 10:21:02 AM | Computer Name = Nadine-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ OSession Events ]
Error - 5/4/2009 7:01:32 PM | Computer Name = Nadine-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.

Error - 5/7/2009 8:31:27 PM | Computer Name = Nadine-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 95647
seconds with 3240 seconds of active time. This session ended with a crash.

Error - 5/13/2009 1:37:34 PM | Computer Name = Nadine-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 12
seconds with 0 seconds of active time. This session ended with a crash.

Error - 5/19/2009 10:49:31 AM | Computer Name = Nadine-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 7/1/2010 8:48:01 AM | Computer Name = My-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 7/1/2010 8:48:01 AM | Computer Name = My-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/1/2010 8:49:23 AM | Computer Name = My-PC | Source = DCOM | ID = 10010
Description =

Error - 7/1/2010 8:50:08 AM | Computer Name = My-PC | Source = DCOM | ID = 10010
Description =

Error - 7/1/2010 8:50:19 AM | Computer Name = My-PC | Source = DCOM | ID = 10005
Description =

Error - 7/1/2010 8:50:19 AM | Computer Name = My-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 7/1/2010 8:50:19 AM | Computer Name = My-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/1/2010 8:56:41 AM | Computer Name = My-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 7/1/2010 2:33:10 PM | Computer Name = My-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.104 for the Network Card with network
address 00234E25D2CF has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 7/1/2010 10:30:19 PM | Computer Name = My-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.101 for the Network Card with network
address 00234E25D2CF has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).


< End of report >


Thanks again!

Durchie
I am still getting:

• Catalyst Control Centre Host Application has stopped working.

• hpCaslNotification has stopped working. A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available.

• I tried to download the MS Fixit Solution again and still get the download error but for some reason now my dvd driver shows up and IS working.

I have not had the following errors again although I don't remember exactly what I was doing when they popped up to start with so I can't replicate and say for sure that they are gone:

• IError 1601: Windows Installer Service could not be accessed. This can occur if Windows Installer is not correctly installed. Check Problem Reports and Solutions in Control Panel.

• 251 CMOS Checksum Error

• msiexec.exe Application Error Application failed to initialize properly (0xc0000142)

Improvements:

I have not had the BSOD error since I recovered from the Norton fiasco two days ago.

The CPU usage seems to have dropped dramatically - running between 15 - 35% right now.

IE is running much better - faster and not much in the way of hourglassing. I have not had a "not responding" message.

Even the overheating seems to be HUGELY improved - right now I'd actually be able to work with it on my bare legs if I wanted to.

I not quite sure what happened to cause these improvements but I'm keeping my fingers crossed that it lasts!
Great :thumbup:
At this point I'd suggest you start a new topic in our Hardware Forum
and post the issues you're still having and see if one of our Tech Team members can help you.

• Catalyst Control Centre Host Application has stopped working.

• hpCaslNotification has stopped working. A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available.

• I tried to download the MS Fixit Solution again and still get the download error but for some reason now my dvd driver shows up and IS working.


http://forums.whatthetech.com/index.php?showforum=126
Glad to see the thumbs up from you - I was afraid you were going to tell me that my excitement by the improments was premature. Can you direct me on what I should title my new post in the Hardware forum? And how much of the this post should I include to give them the history? I'm not certain how to draw the line between which issues are virus/malware related. which are hardware and which might be related to both. Also, I forgot to ask you again about the Malwarebytes error (Error Code 2) that I mentioned in my first post. I have received it several times. Does the program need to be installed? Thanks, Dutchie
Name your topic something like Multiple Issues
Add a link to your topic here:
http://forums.whatthetech.com/index.php?sh…mp;#entry663915

Post whatever issues you're still having, like:
• Catalyst Control Centre Host Application has stopped working.

• hpCaslNotification has stopped working. A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available.

and anything else other than Malware.

For: Malwarebytes error (Error Code 2)
you can google it:
http://forums.malwarebytes.org/index.php?showtopic=11856
Ok, I'll go ahead and post there now. Thanks so much for your help LDTate - I really appreciate it! Hope you have a great 4th! Dutchie

Ok, I'll go ahead and post there now.

Thanks so much for your help LDTate - I really appreciate it!

Hope you have a great 4th!

Dutchie

You're more than welcome.
Glad we were able to help

Peace be with you :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI