This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HP DV2413cl laptop running S L O O O O W

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 10/3/2011 12:36:49 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Cleanup
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

957.94 Mb Total Physical Memory | 188.91 Mb Available Physical Memory | 19.72% Memory free
2.14 Gb Paging File | 1.54 Gb Available in Paging File | 71.93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 142.80 Gb Total Space | 114.04 Gb Free Space | 79.86% Space Free | Partition Type: NTFS
Drive D: | 6.25 Gb Total Space | 0.66 Gb Free Space | 10.53% Space Free | Partition Type: NTFS

Computer Name: LAPTOP | User Name: Raylin | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/10/03 12:26:10 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Cleanup\OTL.exe
PRC - [2009/04/10 23:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV - [2010/11/30 06:19:06 | 000,307,544 | —- | M] (BitDefender) [On_Demand | Stopped] – C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe – (Update Server)
SRV - [2010/08/23 20:21:40 | 000,013,672 | —- | M] (Intuit Inc.) [Auto | Stopped] – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe – (IntuitUpdateService)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Stopped] – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Stopped] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2008/10/16 19:30:28 | 000,634,880 | —- | M] (Hewlett-Packard Co.) [Auto | Stopped] – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HPSLPSVC32.DLL – (HPSLPSVC)
SRV - [2008/01/19 00:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/01/02 22:46:54 | 000,225,280 | —- | M] (Hewlett-Packard Co.) [On_Demand | Stopped] – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxs08.dll – (hpqcxs08)
SRV - [2006/12/10 23:29:24 | 000,131,072 | —- | M] (Hewlett-Packard Co.) [Auto | Stopped] – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqddsvc.dll – (hpqddsvc)
SRV - [2006/11/24 15:34:20 | 000,118,877 | —- | M] () [Auto | Stopped] – C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe – (CLSched) CyberLink Task Scheduler (CTS)
SRV - [2006/11/24 15:34:16 | 000,270,431 | —- | M] () [Auto | Stopped] – C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe – (CLCapSvc) CyberLink Background Capture Service (CBCS)
SRV - [2006/06/26 09:50:08 | 000,126,976 | —- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe – (AddFiltr)
SRV - [2004/10/22 03:24:18 | 000,073,728 | —- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT)
SRV - [2003/02/28 21:37:58 | 002,090,016 | —- | M] (BitDefender S.R.L.) [Auto | Stopped] – C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe – (VSSERV)
SRV - [2003/02/28 21:36:04 | 000,043,936 | —- | M] (BitDefender S.R.L.) [Auto | Stopped] – C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe – (Updatesrv)


========== Driver Services (SafeList) ==========

DRV - [2011/04/06 13:36:17 | 000,353,096 | —- | M] (BitDefender) [File_System | Boot | Stopped] – C:\Windows\system32\DRIVERS\bdfsfltr.sys – (bdfsfltr)
DRV - [2010/11/29 13:12:20 | 001,066,232 | —- | M] (BitDefender) [File_System | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\avckf.sys – (avckf)
DRV - [2010/11/29 13:12:14 | 000,535,824 | —- | M] (BitDefender) [File_System | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\avc3.sys – (avc3)
DRV - [2010/08/20 17:41:52 | 000,126,800 | —- | M] (BitDefender LLC) [Kernel | System | Running] – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys – (Bdftdif)
DRV - [2010/05/13 15:52:04 | 000,152,528 | —- | M] (BitDefender S.R.L. Bucharest, ROMANIA) [File_System | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\bdfm.sys – (BDFM)
DRV - [2007/08/10 11:08:48 | 000,024,456 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\swmsflt.sys – (swmsflt)
DRV - [2007/06/27 10:42:32 | 000,073,856 | —- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\swmx00.sys – (SWMX00) Sierra Wireless USB MUX Driver (#00)
DRV - [2007/06/27 10:41:46 | 000,101,248 | —- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\SWNC5E00.sys – (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00)
DRV - [2006/11/18 10:52:54 | 000,145,920 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\CHDART.sys – (HdAudAddService)
DRV - [2006/11/18 06:07:00 | 004,450,976 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2006/11/15 10:16:24 | 000,032,256 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2006/11/15 05:42:46 | 000,043,520 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2006/11/15 03:35:20 | 000,037,376 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2006/11/02 00:30:56 | 000,429,056 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\nvm60x32.sys – (NVENETFD)
DRV - [2006/09/15 01:44:18 | 000,011,520 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\nvsmu.sys – (nvsmu)
DRV - [2006/08/04 10:39:10 | 000,008,192 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Stopped] – C:\WINDOWS\System32\drivers\XAudio.sys – (XAudio)
DRV - [2006/06/28 09:57:00 | 000,008,192 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\eabfiltr.sys – (eabfiltr)
DRV - [2006/06/28 09:54:00 | 000,009,472 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\CPQBttn.sys – (HBtnKey)
DRV - [2003/02/28 21:38:09 | 000,122,552 | —- | M] (BitDefender LLC) [Kernel | On_Demand | Stopped] – C:\Program Files\BitDefender\BitDefender 2011\bdselfpr.sys – (bdselfpr)
DRV - [2003/02/28 21:36:12 | 000,306,320 | —- | M] (BitDefender S.R.L.) [File_System | Auto | Stopped] – C:\WINDOWS\System32\drivers\trufos.sys – (Trufos)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.samuelmerritt.edu/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2011\bdaphffext\ [2011/10/02 23:53:31 | 000,000,000 | —D | M]


O1 HOSTS File: ([2003/02/28 22:29:21 | 000,436,091 | R— | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 15011 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\ietoolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [BDAgent] C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe (BitDefender S.R.L.)
O4 - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2011\ieshow.exe (BitDefender S.R.L.)
O4 - HKLM..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKLM..\RunOnce: [Launcher] C:\WINDOWS\SMINST\Launcher.exe (soft thinks)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10o_ActiveX.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\Raylin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Raylin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{34F0675A-D3F2-4DED-AA0D-16B1C53D8E48}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\img22.jpg
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\img22.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/05/15 21:47:24 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 08:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{38085f26-b461-11df-b639-0016d39ca487}\Shell\AutoRun\command - "" = F:\setupSNK.exe
O33 - MountPoints2\{b8e96efc-41a4-11df-a35a-0016d39ca487}\Shell - "" = AutoRun
O33 - MountPoints2\{b8e96efc-41a4-11df-a35a-0016d39ca487}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{da6abb48-58fe-11d7-922e-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{da6abb48-58fe-11d7-922e-806e6f6e6963}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivXNetworks, Inc.)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/10/03 12:31:11 | 000,000,000 | —D | C] – C:\Cleanup
[2011/10/03 10:34:48 | 000,000,000 | —D | C] – C:\Users\Raylin\AppData\Roaming\Malwarebytes
[2011/10/03 10:34:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/03 10:34:22 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/10/03 10:34:16 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/10/03 10:34:16 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/10/03 10:32:08 | 000,000,000 | —D | C] – C:\Temp
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Raylin\Documents\*.tmp files -> C:\Users\Raylin\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/03 10:56:42 | 000,603,516 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/10/03 10:56:42 | 000,103,586 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/10/03 10:52:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/10/03 10:49:48 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/03 10:49:48 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/03 10:42:09 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/03 10:34:23 | 000,000,930 | —- | M] () – C:\Users\Raylin\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/10/03 10:34:23 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/03 09:46:27 | 000,000,146 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2011/10/03 09:46:12 | 000,023,240 | —- | M] () – C:\Users\Raylin\AppData\Roaming\nvModes.001
[2011/10/03 09:44:44 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/03 00:49:08 | 000,023,240 | —- | M] () – C:\Users\Raylin\AppData\Roaming\nvModes.dat
[2011/10/03 00:00:31 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{6ED4D45E-D31B-4445-B249-FAFBD5DD3F10}.job
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Raylin\Documents\*.tmp files -> C:\Users\Raylin\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/03 10:34:23 | 000,000,930 | —- | C] () – C:\Users\Raylin\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/10/03 10:34:23 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/20 15:43:34 | 000,000,000 | —- | C] () – C:\Windows\System32\imblacklist.dat
[2011/02/23 22:31:38 | 000,562,685 | —- | C] () – C:\ProgramData\bdinstall.bin
[2010/07/08 09:37:14 | 000,101,544 | —- | C] () – C:\Program Files\Common Files\LinkInstaller.exe
[2010/04/23 00:12:03 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/03/24 21:54:17 | 000,118,905 | —- | C] () – C:\Windows\hpoins31.dat
[2010/03/24 21:54:17 | 000,000,945 | —- | C] () – C:\Windows\hpomdl31.dat
[2010/03/20 23:18:46 | 000,136,341 | —- | C] () – C:\Windows\hpwins10.dat
[2010/03/06 21:15:54 | 000,001,356 | —- | C] () – C:\Users\Raylin\AppData\Local\d3d9caps.dat
[2010/03/03 18:00:54 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/03/02 12:35:26 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/03/02 12:35:26 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/02/21 12:55:24 | 000,003,584 | —- | C] () – C:\Users\Raylin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pcwords2.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pcwords.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_webproxy.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_video.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_tabloids.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_socialnetworks.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_searchengines.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_regionaltlds.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_pornography.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_onlineshop.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_onlinepay.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_onlinedating.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_news.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_im.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_illegal.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_hate.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_games.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_gambling.dat
[2010/01/28 14:03:57 | 000,000,000 | —- | C] () – C:\Windows\System32\pc_drugs.dat
[2010/01/25 23:41:52 | 000,000,016 | —- | C] () – C:\Windows\System32\asdict.dat
[2010/01/25 23:41:52 | 000,000,004 | —- | C] () – C:\Windows\System32\aspdict-en.dat
[2010/01/25 20:02:12 | 000,000,132 | —- | C] () – C:\Windows\System32\rezumatenoi.dat
[2010/01/25 18:10:55 | 000,023,240 | —- | C] () – C:\Users\Raylin\AppData\Roaming\nvModes.001
[2010/01/25 08:40:42 | 000,023,240 | —- | C] () – C:\Users\Raylin\AppData\Roaming\nvModes.dat
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2007/09/17 09:45:55 | 000,010,314 | —- | C] () – C:\Windows\hpwscr10.dat
[2007/09/17 09:45:15 | 000,001,042 | —- | C] () – C:\Windows\hpwmdl10.dat
[2007/08/10 11:08:48 | 000,024,456 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys
[2007/05/15 19:40:45 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007/01/31 13:50:32 | 000,913,408 | —- | C] () – C:\Windows\System32\xreglib.dll
[2006/11/29 00:32:42 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,371,536 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,603,516 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,103,586 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/09/18 23:02:40 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/18 23:02:40 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/03/09 17:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2004/09/16 13:24:26 | 003,375,104 | —- | C] () – C:\Windows\System32\qt-mt331.dll
[2003/03/06 02:01:47 | 000,000,000 | —- | C] () – C:\Windows\System32\imwords.dat
[2003/03/06 02:01:47 | 000,000,000 | —- | C] () – C:\Windows\System32\im_markovian.dat

========== LOP Check ==========

[2011/03/19 00:40:16 | 000,000,000 | —D | M] – C:\Users\Raylin\AppData\Roaming\BitDefender
[2011/10/03 09:47:35 | 000,000,000 | —D | M] – C:\Users\Raylin\AppData\Roaming\Dropbox
[2011/04/06 14:49:58 | 000,000,000 | —D | M] – C:\Users\Raylin\AppData\Roaming\Image Zone Express
[2011/04/06 14:50:02 | 000,000,000 | —D | M] – C:\Users\Raylin\AppData\Roaming\Printer Info Cache
[2011/02/23 22:35:01 | 000,000,000 | —D | M] – C:\Users\Raylin\AppData\Roaming\QuickScan
[2011/10/03 10:50:32 | 000,032,584 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/10/03 00:00:31 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{6ED4D45E-D31B-4445-B249-FAFBD5DD3F10}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/05/15 21:47:24 | 000,000,074 | —- | M] () – C:\autoexec.bat
[2011/10/03 10:50:23 | 000,068,373 | —- | M] () – C:\bdlog.txt
[2009/04/10 23:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/10/03 10:51:56 | 1319,047,168 | -HS- | M] () – C:\pagefile.sys
[2010/01/25 23:41:51 | 000,000,000 | —- | M] () – C:\pcconf.ini
[2010/01/28 14:03:58 | 000,000,000 | —- | M] () – C:\pcversion.txt
[2010/01/25 23:41:52 | 000,000,000 | —- | M] () – C:\pcwords.dat
[2010/01/25 23:41:52 | 000,000,000 | —- | M] () – C:\pcwords2.dat
[2010/01/25 23:41:52 | 000,000,000 | —- | M] () – C:\pc_sign.slf

< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/04/20 06:22:07 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/08/17 21:27:36 | 000,273,920 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpzpp4x6.dll
[2008/10/28 12:49:30 | 000,321,536 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpzpp696.dll
[2006/11/02 05:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/02/28 02:04:14 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 03:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 03:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 03:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/01/28 14:28:20 | 000,000,286 | -HS- | M] () – C:\Users\Raylin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/03/18 22:08:00 | 001,359,304 | —- | M] () – C:\Users\Raylin\Desktop\bitdefender_antivirus.exe
[2011/04/20 14:06:06 | 016,791,288 | —- | M] (Dropbox, Inc.) – C:\Users\Raylin\Desktop\Dropbox 1.1.24.exe
[2008/08/07 09:55:53 | 002,660,226 | —- | M] (Macromedia, Inc.) – C:\Users\Raylin\Desktop\Wilson.exe

< %PROGRAMFILES%\Common Files\*.* >
[2010/07/08 09:37:14 | 000,101,544 | —- | M] () – C:\Program Files\Common Files\LinkInstaller.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-09-02 05:12:38

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 10 bytes -> C:\Users\Raylin\Desktop\Dropbox 1.1.24.exe:BDU

< End of report >
__________________________________________________________________________
OTL Extras txt file
OTL Extras logfile created on: 10/3/2011 12:36:49 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Cleanup
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

957.94 Mb Total Physical Memory | 188.91 Mb Available Physical Memory | 19.72% Memory free
2.14 Gb Paging File | 1.54 Gb Available in Paging File | 71.93% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 142.80 Gb Total Space | 114.04 Gb Free Space | 79.86% Space Free | Partition Type: NTFS
Drive D: | 6.25 Gb Total Space | 0.66 Gb Free Space | 10.53% Space Free | Partition Type: NTFS

Computer Name: LAPTOP | User Name: Raylin | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04CC1427-85A4-49D5-86F3-19898FA9908B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1F70D0FA-4037-4342-963A-6480F0D83079}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{2C1A67BB-3C56-4882-9212-F16FDE17B389}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdateservice.exe |
"{3701F22C-388A-4677-BE7C-DE7FC0DD8EB3}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3BDAA01A-1585-4715-974C-406D3CE67FBC}" = rport=138 | protocol=17 | dir=out | app=system |
"{3F5E2804-668B-401F-8555-CB4C1A808F65}" = lport=138 | protocol=17 | dir=in | app=system |
"{47C4B449-E890-4DCE-BF9B-5E1B770BE5AB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{550C576B-298C-4218-8E5D-66F37F39BEF2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{556D6667-EC23-4448-94F8-A7836FC70027}" = lport=445 | protocol=6 | dir=in | app=system |
"{61BA00D1-29C0-44E7-9B34-193EA78AAF71}" = lport=137 | protocol=17 | dir=in | app=system |
"{7B0D8662-2F47-4199-A86D-FF87CAF24043}" = lport=139 | protocol=6 | dir=in | app=system |
"{7B4468EE-5330-4ED5-9CEF-D5D9704A381B}" = rport=137 | protocol=17 | dir=out | app=system |
"{B066C657-3151-4FE9-B278-0B3A484A6EBA}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{BD74103A-FDB0-4E8D-9949-995C7F0B3DAA}" = rport=445 | protocol=6 | dir=out | app=system |
"{C1293D6A-EFD1-4BC1-8DF3-E612FF01B24B}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{C3EFE53A-AC32-4C81-843D-86417322FF8E}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{CF9584E3-2E7F-4F62-8B0A-3D51E07B0E52}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D9006A58-1F75-4E6A-89FD-BB72E14A0C45}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FBDA8828-0170-4F0B-9783-84C8FCE1FD8E}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdater.exe |
"{FED46870-BCF8-4984-8D1D-327494F90EDC}" = rport=139 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0520E2E2-4BF1-4B0D-B40B-0C8EEAD6910A}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpoews01.exe |
"{06C8E8F9-AF5D-40C8-BE02-D99E7DCE8FA2}" = protocol=17 | dir=in | app=c:\users\raylin\appdata\local\temp\7zscdab.tmp\symnrt.exe |
"{258A2D11-5ECC-4C99-AA83-61A6C7F1B34F}" = protocol=17 | dir=in | app=c:\program files\hp connections\6811507\program\hp connections.exe |
"{2A512237-25A1-4ADE-A87D-2EFB4FAF8D3B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{326106D3-2252-4D8D-AF37-E07759D1C38C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3CA09621-D717-45E0-B3D8-B777795AA771}" = protocol=6 | dir=in | app=c:\program files\hp connections\6811507\program\hp connections.exe |
"{3EBD17CE-10E2-44C1-B2FD-F198C18C6856}" = dir=in | app=c:\program files\hp connections\6811507\program\hp connections |
"{4503F1E8-A3A3-4D8B-8BF6-E3552F0296C2}" = protocol=17 | dir=in | app=c:\users\raylin\appdata\roaming\dropbox\bin\dropbox.exe |
"{4A483DE1-9EAB-436D-A8A2-6971E6A85B08}" = protocol=6 | dir=in | app=c:\users\raylin\appdata\roaming\dropbox\bin\dropbox.exe |
"{4CA22166-0DC7-4112-818C-371FE2809408}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{5A093284-9758-4F87-A983-52277518077A}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hposid01.exe |
"{615B42C8-DD9E-4B9A-9C3E-AEFC0F60E8F7}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{68582BC7-21C3-4E84-BBB8-D76D6D0FC074}" = protocol=6 | dir=in | app=c:\users\raylin\appdata\local\temp\7zscdab.tmp\symnrt.exe |
"{6F34F00A-227D-4245-BAA8-4675B6F45080}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpofxm08.exe |
"{718D4FAF-B6AE-4B5F-94F6-8DEBF78BB834}" = protocol=6 | dir=in | app=c:\program files\hp connections\6811507\program\hp connections.exe |
"{71B1FB75-FED0-4387-8D17-883841F24522}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{74772220-A223-4322-A3D2-0D5E8CC40746}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpiscnapp.exe |
"{7C7BA221-F149-453C-B922-D36575BF5A07}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqkygrp.exe |
"{80F70377-1BA4-4215-B605-6D2477A88B30}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{845A6948-3885-4B9D-8370-7445257D90FA}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{85192BF1-E9B9-47FF-B741-D660F40C0D74}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8B0785D6-76C5-4C37-840F-96D61C4C87E5}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpfccopy.exe |
"{960485CA-C299-4168-B225-FAE00FE57890}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{96513F93-FD63-47F9-8F14-2F064B8BE46E}" = protocol=17 | dir=in | app=c:\program files\hp connections\6811507\program\hp connections.exe |
"{9F79781C-74DA-4BBD-9536-ADA5D792F3B6}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{A09E172C-5E74-4A46-B233-5967A791B31F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{AA96D62D-77E6-4146-BA9C-47E53438604B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{B1B81476-5CD0-47A8-83F4-0FB6A057ED67}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{B98FE1A9-42BA-46B8-93BB-B4CC4B2D86F7}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{C45E84AD-F4E3-4A56-8438-1D5A77D7AC90}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpzwiz01.exe |
"{C51539E2-DB4A-493A-9983-927B534FA755}" = protocol=6 | dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{D1635DAA-9BB2-46F5-9432-EA1455407778}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe |
"{DC95581D-263B-4F42-82D6-104C1BC32C24}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hposfx08.exe |
"{DE327EA8-C4A3-49E1-A7DC-2469AB476097}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{E31A1A33-5FA9-4CDE-B067-90BEC7F034B9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E76CBA4D-83D3-4697-B6F0-FA5903779C3E}" = protocol=6 | dir=in | app=c:\program files\hp connections\6811507\program\hp connections.exe |
"{EC70A2EB-A55F-494B-97FA-32B4C0B94720}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpofxs08.exe |
"{F3AFF681-DDCC-4CD7-922E-0A41EEB09FB4}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqste08.exe |
"{FDDB124D-D957-476B-9CA9-628C2C7E6FBF}" = protocol=17 | dir=in | app=c:\program files\hp\quickplay\qp.exe |
"TCP Query User{5E293B21-9248-4812-9F5A-A97CF31A568C}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{079D6456-D177-4560-A258-2F2C7127B0DD}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02F33FB0-F7D5-4C0A-B4AD-8CE5CE230BBE}" = HP Wireless Assistant
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{21E62565-8639-457C-B64C-A3FF0A8B4D80}" = HP Active Support Library
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 20
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}" = Roxio MyDVD Basic v9
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.10 B9
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C43EAE7-22C0-4b33-ABFB-3757ECA5FD7B}" = HP Officejet All-In-One Series
"{40BA976E-38B8-4C63-990C-50999C8C3521}" = BPD_Scan
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{41A96655-19FB-473c-AAB7-429E372527C8}" = ProductContext
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.0
"{47ECCB1F-2811-49C0-B6A7-26778639ABA0}" = 32 Bit HP CIO Components Installer
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5CA81D12-9EC2-4082-972B-43ECA63F41F2}" = HP Pavilion Webcam Driver for Vista v061.001.00006
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73FAD870-C7A8-4344-BA8F-DF8675276E91}" = BitDefender Antivirus Pro 2011
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{87A9A9A9-FAB7-4224-9328-0FA2058C0FD5}" = Network
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{87FF0E39-8490-4EB4-A557-FF12F712EF7E}" = TurboTax 2010 wcaiper
"{88D18C5E-5113-4A1E-8EC9-2B7E24688A14}" = PS_AIO_04_C6300_Software_Min
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91DBD16F-BA92-4B2E-A65A-56DB3EE67AC4}" = HP User Guide 0052
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{99C5770C-1C90-42E7-9B74-D47CFAF14621}" = muvee autoProducer 5.0
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CCCFD9C-248F-47FE-9496-1680E3E5C163}" = Scan
"{A12A3DED-CCDA-4F29-A1BA-00F0C6521CD5}" = HP Total Care Advisor
"{A2CC286B-BFE9-4D1F-9EDA-AA3E8289CA12}" = BPDSoftware_Ini
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC13BA3A-336B-45a4-B3FE-2D3058A7B533}" = Toolbox
"{AC76BA86-7AD7-1033-7B44-A80000000002}" = Adobe Reader 8
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BA8DF709-6BAB-4092-91E0-4D67EFC12A98}" = HP Photosmart C6300 All-In-One Driver 12.0 Rel .4
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{E4DDBA93-769B-49D8-BA33-8814E45ED0C1}" = HP Help and Support
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F3191469-842E-4AF5-9260-A8CC7C932F70}" = Evolve eBooks
"{F94234DB-FD06-42C3-B88D-6FC4DC9F988C}" = HP Easy Setup - Core
"{FAB0C302-CB18-4A7A-BA03-C3DC23101A68}" = ASL_HS_Installer32
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"BitDefender" = BitDefender Antivirus Pro 2011
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_AK_SH_VI_VEN_14F1&DEV;_5045" = HDAUDIO Soft Data Fax Modem with SmartCP
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"HPOOVClient-6811507 Uninstaller" = HP Connections (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TurboTax 2010" = TurboTax 2010
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/17/2003 10:43:50 PM | Computer Name = Laptop | Source = Application Error | ID = 1000
Description = Faulting application jaucheck.exe, version 2.0.2.1, time stamp 0x4b7d6dd6,
faulting module jaucheck.exe, version 2.0.2.1, time stamp 0x4b7d6dd6, exception
code 0xc0000005, fault offset 0x0000c940, process id 0x1748, application start time
0x01c2ecf8310e4217.

Error - 3/17/2003 11:37:23 PM | Computer Name = Laptop | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 3/17/2003 11:37:23 PM | Computer Name = Laptop | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 3/17/2003 11:37:24 PM | Computer Name = Laptop | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 9/1/2011 8:25:25 PM | Computer Name = Laptop | Source = MsiInstaller | ID = 11606
Description =

Error - 9/1/2011 8:25:25 PM | Computer Name = Laptop | Source = MsiInstaller | ID = 11606
Description =

Error - 10/3/2011 3:18:58 AM | Computer Name = Laptop | Source = Application Error | ID = 1000
Description = Faulting application HPWUCli.exe, version 4.0.3.1, time stamp 0x4533e870,
faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436, exception
code 0xc0000005, fault offset 0x000393b3, process id 0x1318, application start time
0x01cc819c8f80ac13.

Error - 10/3/2011 3:38:04 AM | Computer Name = Laptop | Source = Application Hang | ID = 1002
Description = The program HPAdvisor.exe version 1.0.94.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: c8 Start Time: 01cc819b39533e80 Termination Time: 718

Error - 10/3/2011 3:38:55 AM | Computer Name = Laptop | Source = Application Hang | ID = 1002
Description = The program hpqdirec.exe version 74.0.17.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1e0c Start Time: 01cc819e7a3831f7 Termination Time: 4

Error - 10/3/2011 1:56:02 PM | Computer Name = Laptop | Source = EventSystem | ID = 4609
Description =

[ System Events ]
Error - 10/3/2011 1:52:28 PM | Computer Name = Laptop | Source = DCOM | ID = 10005
Description =

Error - 10/3/2011 1:52:28 PM | Computer Name = Laptop | Source = LSM | ID = 1048
Description =

Error - 10/3/2011 1:53:44 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7001
Description =

Error - 10/3/2011 1:53:44 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7026
Description =

Error - 10/3/2011 1:55:53 PM | Computer Name = Laptop | Source = DCOM | ID = 10005
Description =

Error - 10/3/2011 1:56:02 PM | Computer Name = Laptop | Source = DCOM | ID = 10005
Description =

Error - 10/3/2011 1:56:05 PM | Computer Name = Laptop | Source = DCOM | ID = 10005
Description =

Error - 10/3/2011 1:56:08 PM | Computer Name = Laptop | Source = DCOM | ID = 10005
Description =

Error - 10/3/2011 1:56:08 PM | Computer Name = Laptop | Source = DCOM | ID = 10005
Description =

Error - 10/3/2011 2:58:31 PM | Computer Name = Laptop | Source = DCOM | ID = 10005
Description =


< End of report >
Have also done the following to troubleshoot: - Run already installed BitDefender to scan for viruses, none found, reran in Safe Mode, time for scan = 11+ hours, aborted scan - Downloaded/installed/updated MBAM, Performed quick scan with no infections found. - Found this site - can access Internet on the system OK. Standard mode = VERY slow, Safe Mode = not as slow? - Downloaded/ran OTL per WTT posted instructions and posted log txt files above. User (neighbor) says system may have been a Demo unit/Last One on the display shelf at the local Cost co, and it "seems" like this unit has been slow almost from the beginning? I am also scanning and cleaning 2 other systems in this household and will start new topic for at least one of them. I anticipate helping the users with some "safe-surfing/computing education" when systems finally cleaned, with info from this site, of course. TIA
Hi Arbee322,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Let's give this a try:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi, thanks for your help so far. Was working on the unit in the user's home, then took it with me and did not have her user password, hence the delay responding. Am working on the unit now and will perform what you recommended and post results. Thanks again, Russ
Had to uninstall BitDefender antivirus to run ComboFix. CF finally completed successfully. Here is the requested txt.


ComboFix 11-10-11.02 - Raylin 10/11/2011 13:17:00.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.958.228 [GMT -7:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Raylin\Documents\~WRL0373.tmp
c:\windows\HPCPCUninstaller-6.3.2.139-6811507.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-09-11 to 2011-10-11 )))))))))))))))))))))))))))))))
.
.
2011-10-11 20:24 . 2011-10-11 20:24 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-10-03 19:31 . 2011-10-03 19:43 ——– d—–w- C:\Cleanup
2011-10-03 17:34 . 2011-10-03 17:34 ——– d—–w- c:\users\Raylin\AppData\Roaming\Malwarebytes
2011-10-03 17:34 . 2011-10-03 17:34 ——– d—–w- c:\programdata\Malwarebytes
2011-10-03 17:34 . 2011-10-03 17:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-10-03 17:34 . 2011-09-01 00:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-10-03 17:32 . 2011-10-03 18:23 ——– d—–w- C:\Temp
2011-10-03 16:02 . 2011-08-10 12:14 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-11 19:55 . 2011-02-24 05:31 896024 —-a-w- c:\programdata\bdinstall.bin
2010-07-08 16:37 . 2010-07-08 16:37 101544 —-a-w- c:\program files\Common Files\LinkInstaller.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Raylin\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Raylin\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Raylin\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2006-11-21 1474560]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-23 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-11-24 167936]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2006-11-10 46704]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 317152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 472800]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2006-11-18 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-18 7753728]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-18 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
.
c:\users\Raylin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Raylin\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
HP Connections.lnk - c:\program files\HP Connections\6811507\Program\HP Connections.exe [2007-5-15 34520]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-04-23 135664]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-04-23 135664]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ sysagent
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-23 07:06]
.
2011-10-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-23 07:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
Trusted Zone: intuit.com\ttlc
TCP: DhcpNameServer = 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-11 13:25
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-10-11 13:29:06
ComboFix-quarantined-files.txt 2011-10-11 20:29
.
Pre-Run: 122,044,780,544 bytes free
Post-Run: 122,140,815,360 bytes free
.
- - End Of File - - D1F27584C14B5EF277E1C45709863A14


Thanks for your continued help!
Russ
Arbee322,

That took care of some dross and a little staightening up. I'm not really seeing any infection.

Let's try an online scan.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Ran ESET online scanner as you suggested. Appeared to start to run OK. Walked away from system for awhile to let it run. Came back and system appeared to have rebooted. Not entirely sure though if scan completed. :huh: ESET scanner log file contents ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK
Arbee322, That doesn't sound or look right. I'm thinking maybe it didn't complete and something else caused the reboot. Please try running it again. There should be no problem with walking away from it because it will probably take a couple hours.
User requested we "fix" this quickly. Offered to restore to factory settings with Recovery DVD's. User said go ahead. System restored, reinstalled antivirus and Malwarebytes, updated all hardware drivers and uninstalled all bloatware. User is happy with results at this time. Thanks for your help - feel free to close out this thread.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI