 | reply to daparker
Re: [Malware] Malware Issue OTL Extras logfile created on: 4/3/2013 7:51:49 AM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\David\Desktop 64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 3.87 Gb Available Physical Memory | 64.60% Memory free 12.11 Gb Paging File | 9.48 Gb Available in Paging File | 78.27% Paging File free Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 683.57 Gb Total Space | 340.73 Gb Free Space | 49.84% Space Free | Partition Type: NTFS Drive D: | 15.00 Gb Total Space | 8.67 Gb Free Space | 57.83% Space Free | Partition Type: NTFS Drive E: | 679.10 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: ARTHAS | User Name: David | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
[color=#E56717]========== File Associations ==========[/color]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[color=#E56717]========== Shell Spawning ==========[/color]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[color=#E56717]========== Security Center Settings ==========[/color]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data] "VistaSp2" = 9B D1 9F 3E 8D 7B CA 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2110277994-200745889-587813472-1000] "EnableNotifications" = 0 "EnableNotificationsRef" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "oobe_av" = 1
[color=#E56717]========== Firewall Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0
[color=#E56717]========== Authorized Applications List ==========[/color]
[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1492C3AC-95FE-4CC1-BECD-C0F9792A03B4}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{1B4897F4-14CE-4EEF-8E88-236604867784}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{1BFF714C-D1D0-4B3D-B7FC-C1E00D7ABCDF}" = lport=139 | protocol=6 | dir=in | app=system | "{3459EEA8-7FA0-43E8-97A2-4A3A3C2A5B81}" = lport=10243 | protocol=6 | dir=in | app=system | "{35A853CE-29F2-4FA7-B243-B62B7B4FB55A}" = rport=137 | protocol=17 | dir=out | app=system | "{37CCC15D-630F-4024-B70E-F17C5221C496}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{491D8236-D804-42EE-9B91-833A06030586}" = lport=137 | protocol=17 | dir=in | app=system | "{4E2D0EEA-CBCB-4DE9-9AA4-6FC65EE124CD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{528347D9-9F0A-4B2C-9AE9-BBB4F7200F05}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{55B03EA5-3BD7-41A4-BA4B-2AB2FA0145D1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5A561EF0-7BCF-4BEF-A89A-B98C36527322}" = lport=445 | protocol=6 | dir=in | app=system | "{62685B0B-2294-45F4-AB96-2B04EE7C476E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{69FAC688-7987-4DC6-A178-54D5EF9E0113}" = rport=138 | protocol=17 | dir=out | app=system | "{8EB002E7-5E32-4DB0-84F6-62D2551044D7}" = rport=445 | protocol=6 | dir=out | app=system | "{993115A3-23B1-4427-AD0E-5AE4A66F64CF}" = rport=139 | protocol=6 | dir=out | app=system | "{B51E229B-82AC-4DE6-9BB0-57E6679A0CB5}" = lport=2869 | protocol=6 | dir=in | app=system | "{C877BE74-89F3-4A8E-959D-3EB69DE9BC57}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{D0B4B689-16E2-4EA0-9495-BFFC7F5551C3}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{E4F1BF8C-F888-40E3-9784-F83431DA3D15}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{EA2100FA-2094-4708-8E96-15C6D2C28E97}" = lport=138 | protocol=17 | dir=in | app=system | "{F7B69DA3-A9ED-4B43-B993-C385ACD90871}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F8D3AD25-1EC7-47F6-BFA8-7EEF238C85B4}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe | "{FBEA1A86-94C5-4BB2-8563-29E12393A3EE}" = rport=10243 | protocol=6 | dir=out | app=system |
[color=#E56717]========== Vista Active Application Exception List ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02ED5BA6-CBC7-444D-BC13-632DD44A7A69}" = protocol=17 | dir=in | app=c:\program files (x86)\stardock games\sins of a solar empire - trinity\sins of a solar empire diplomacy.exe | "{03F9274E-C3E3-4578-BD61-D5335E7ADB30}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{04A52230-9E12-4F32-91CC-DBF7EBBABA68}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{05CDE446-F990-40D0-BB51-4E4F56CDFCA5}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe | "{097283FE-BB5E-4838-B4E5-060BC929D9BB}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifetray.exe | "{0D633C01-FD47-42FB-9967-B44BEA149830}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe | "{0E9ACFA9-8C13-4858-B7F7-962874493C38}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1B081F64-1C45-459F-896C-0F373DF556F9}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1DA6CCDE-A456-4F68-8607-3CDDDFCB29CD}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe | "{1DB8C62E-1FE5-4FD2-B5DF-91CCC86D1379}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{1E273987-15FC-4195-B67C-2A3D46881760}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe | "{20008480-ED9C-4E3F-83B1-15E678C98D50}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{2009BBF5-AF22-4FDE-A56E-99BE16953875}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{2158B821-9014-4376-A28B-4E40B9423352}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{22E095FE-36D3-44BC-8D56-EEA86B381DAE}" = protocol=6 | dir=in | app=c:\program files (x86)\stardock games\sins of a solar empire - trinity\sins of a solar empire entrenchment.exe | "{2389261B-7D08-4124-A971-1282770DC8D4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{23B1AE6F-2F22-49B5-9441-6ECAAD233678}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{2682D885-E9A7-443F-A849-79D2A0AA766E}" = protocol=17 | dir=in | app=c:\program files (x86)\stardock games\sins of a solar empire - trinity\sins of a solar empire entrenchment.exe | "{29F9BF50-9B54-4653-A0B5-D76B1EFAD332}" = protocol=17 | dir=in | app=c:\program files (x86)\curse\curseclient.exe | "{2F120FE9-3CEE-404F-8133-5D4AC5BA0BB1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{30956F46-8D2E-48D2-8420-AEDB3AB7BDA3}" = protocol=6 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe | "{32B567FC-DD95-4BAC-AE14-9E5CDDCF85D8}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe | "{39045769-5CCF-4554-8D75-A93335CE45E1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{39108953-D1B3-404A-852A-44607EF47988}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeenc2.exe | "{3A9F74B4-2817-4CDA-9B27-517D1B13A37E}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe | "{3AFF9294-FA0A-4D13-8605-D3594D97BC8F}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe | "{3DA4147E-311E-499E-AEDF-AFD2E3ADADFA}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeexp.exe | "{3E92AB30-CAD2-4042-A49D-B90DEFE0E666}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{3F546677-4E83-408D-BF81-E43E7080E8DC}" = protocol=17 | dir=in | app=c:\windows\system32\migwiz\migwiz.exe | "{42A2E94C-9256-4680-9EBC-E029356724F5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{43D08D4D-3AC6-4C85-B8F9-D8E42BB6C6F6}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{47B64D6C-5EB2-4290-9D94-7A2360FCF00A}" = protocol=17 | dir=in | app=c:\program files (x86)\curse\curseclient.exe | "{47D33A8D-7134-4FCB-9DAC-5864B1193CA4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{4D0A9736-9091-41C6-A63A-ACA1F9E37327}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{4D858409-E8F9-4349-B7FD-467C8A3366E5}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe | "{4E23BBFD-76DF-4653-B935-7F6BF855DD55}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{4F666692-7331-4846-90B1-911A5DD8C9E6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe | "{50277AF5-EA5B-472D-B8EA-8C2A9C616B58}" = protocol=6 | dir=in | app=c:\windows\system32\migwiz\migwiz.exe | "{513B95C6-1A1F-4920-9A3A-EA0D5C25E0B6}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe | "{5DCE37A6-469D-42F4-9FF2-A8323D077DAD}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{67EA2212-1A04-4400-AF50-86D6F2170242}" = protocol=17 | dir=in | app=c:\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe | "{6E032618-1FB5-4884-BD4C-610781862A5E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{6E057131-FB16-45ED-90F5-18E857ABC909}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{6F2FDABB-4EB5-41FB-9F6A-03BD7795F0D8}" = protocol=17 | dir=in | app=c:\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe | "{75F18A3E-3F56-41AC-A726-5FBDFA176278}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{7815F732-3C1D-41F3-B02E-FAA478B85865}" = dir=in | app=c:\program files (x86)\avg\avg8\avgupd.exe | "{797D34B3-AE80-486B-B9D2-6C73B29377B4}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{7F700B8A-DCA5-47A7-A155-AB06D86EF204}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifecam.exe | "{832F1CCC-41A2-43AA-B554-DCE67894E92C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{83CC208C-2C83-40EC-BCE6-E17FA55F2747}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{84732F19-3C66-454F-B953-3D56A7476A40}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{868DCFA3-F249-494F-A464-DC452D01E5E1}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeexp.exe | "{89047F96-8E88-4F79-9B54-7A226D8B183F}" = protocol=6 | dir=in | app=c:\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe | "{89349441-52ED-4D56-A12B-A987A692C423}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{89C229B4-BA1C-4778-B5A8-5441455AB9AF}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{8A23AFF4-EEBC-4144-949F-57D44B2D218E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{8D9F7FDC-5CAC-4068-9E02-4826C39A506B}" = dir=in | app=e:\setup\hpznui40.exe | "{9623004B-B553-4651-96F6-0B3E388C9CC7}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifecam.exe | "{978E80FA-A4E6-4EE9-84D5-1566C02DC856}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{A113021B-CCB1-41E2-BD56-266E6978BA48}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifeenc2.exe | "{A2BC099B-B613-4987-A4DD-787576D2B9FC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{A5E7A57B-3685-40BF-8354-1160AE8DCD44}" = protocol=6 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe | "{A800144D-7D89-4FB0-8CEB-D932171D9070}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{A88524A0-A55B-4B55-9EE6-7B677BC1C871}" = protocol=6 | dir=in | app=c:\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe | "{AA8354E5-CBEA-4720-B10F-795C4FC5B545}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{B34B6E50-9F78-44CD-BFAF-98CA38715700}" = protocol=17 | dir=in | app=c:\program files (x86)\stardock games\sins of a solar empire - trinity\sins of a solar empire.exe | "{B4A46B2A-0E75-47F4-867B-A0836C483187}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{B54936FE-17F8-4B49-A92A-E090C6C281CC}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{BB0CFB0E-2CA1-427D-8132-792FBA18A65F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{BBE4164D-CA0D-4CC1-BA40-635201DC8D0D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C06D1BEA-EF0D-4428-B5A0-6D4E5B260E27}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{C0796D6F-C56D-4239-8591-2B68971C31E5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe | "{C2597DC8-7357-4F9C-9BC6-B98013B6331E}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{C2D553FF-9042-4CC3-888F-F08EB8258B21}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C449BF02-C0E8-4886-AE92-87C858F6A368}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{C6D91B38-0D78-4896-9DEB-7C224423E6B8}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{C7897442-FDD8-4FDD-A07A-0ECBC993DA80}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{C7C027FF-4C3D-43F5-9E0C-3FF3000D460F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{CD6FC9F4-1898-46D1-93A4-2C999E3B5D7E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{CDAE93D6-3895-49E3-BD62-FB50386C77DA}" = protocol=6 | dir=in | app=c:\program files (x86)\stardock games\sins of a solar empire - trinity\sins of a solar empire.exe | "{CE521825-B209-4F27-9170-19B08110D64F}" = protocol=17 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe | "{D0CC646B-9FB1-47AC-AD5F-BD7DAAB789C4}" = protocol=6 | dir=in | app=c:\program files (x86)\stardock games\sins of a solar empire - trinity\sins of a solar empire diplomacy.exe | "{D1200188-E3CB-4E5B-A6F1-8A687BE4F78C}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe | "{D123C02D-DCC4-4F8A-A1CD-5F0FEF52ED22}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{D3B8D6F6-FE79-4175-9F9E-C1CF277C8A7F}" = protocol=6 | dir=in | app=c:\program files (x86)\curse\curseclient.exe | "{D5AAA3D4-BE4C-4CD9-A92D-3A81F76444DE}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe | "{D5DB04AE-233C-4A8B-9527-FA8F08314165}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{D6714521-7871-4C6A-98DF-88FAEEA85B9D}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe | "{D90938D2-A897-4D7D-9266-45CE4663F40A}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{D9A6F16F-31C5-49C6-B728-2CBBD9B475C7}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe | "{DB6A760A-3535-4389-AF4A-60DFCC0062AD}" = protocol=17 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe | "{DB6D4990-3221-408A-B538-BFAB1F88F269}" = protocol=6 | dir=in | app=c:\program files (x86)\curse\curseclient.exe | "{E027B2DA-3A24-4C1F-AA4D-C87CD31A7D39}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{E703F2FF-9DA5-4A82-9A7A-702C96C89B58}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{E7BE7BAA-A982-4B98-AFCF-6DF49BF05FCC}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{EA9D0DAE-964C-47A6-B18B-533F2D54CCD0}" = protocol=6 | dir=out | app=system | "{EF6E3C73-E327-4D6A-9AFB-0E268D500C29}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft lifecam\lifetray.exe | "{F0341BEB-8698-4CAC-852A-66765A20013E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{F0BC12C9-E194-4D51-BC3E-3F2DCF8312ED}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{F1BD062D-81D7-4C8B-AAAF-846B66D27F9E}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe | "{F30C2E24-D99C-4C04-80DB-BC98AC43F8D5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe | "{F3FB4688-1A41-47F0-8BAF-2384227EE47E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{FBFA182B-A948-4E43-9C04-652FADBF70BE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{FE9A7BDF-6E6B-462A-B3D9-FD16DE5EEEDD}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{FEC747FC-5D86-4DA8-8F60-B6DA07503D5E}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "TCP Query User{30DB92EA-3022-479F-9805-1E057E707BA2}C:\world of warcraft\wow-3.3.2.11403-to-3.3.3.11685-enus-downloader.exe" = protocol=6 | dir=in | app=c:\world of warcraft\wow-3.3.2.11403-to-3.3.3.11685-enus-downloader.exe | "TCP Query User{440D0E9C-2419-4237-869E-720F354892E8}C:\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\world of warcraft\launcher.exe | "TCP Query User{57C8E35F-84A7-4BDC-95DD-F4F8C959D549}C:\world of warcraft\wow-3.3.0.11159-to-3.3.2.11403-enus-downloader.exe" = protocol=6 | dir=in | app=c:\world of warcraft\wow-3.3.0.11159-to-3.3.2.11403-enus-downloader.exe | "TCP Query User{6352F6C1-A977-4CE2-9447-B95D3E4C3B6C}C:\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\world of warcraft\backgrounddownloader.exe | "TCP Query User{6F744055-5F84-4C1C-AE2C-BDBF286B8060}C:\users\david\appdata\local\temp\blizzard launcher temporary - ff5705b0\launcher.exe" = protocol=6 | dir=in | app=c:\users\david\appdata\local\temp\blizzard launcher temporary - ff5705b0\launcher.exe | "TCP Query User{799413DC-7F1F-4193-99F9-7B4B7E99E624}C:\users\david\appdata\local\temp\blizzard launcher temporary - 6f504da8\launcher.exe" = protocol=6 | dir=in | app=c:\users\david\appdata\local\temp\blizzard launcher temporary - 6f504da8\launcher.exe | "TCP Query User{A80EB71E-777B-44FF-A284-E06664461AB0}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "TCP Query User{C5E191DE-7368-4689-A541-BE248646443F}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "TCP Query User{C9B73159-EC38-4CCA-B478-066034ABE89F}C:\world of warcraft\wow-3.3.3.11685-to-3.3.3.11723-enus-downloader.exe" = protocol=6 | dir=in | app=c:\world of warcraft\wow-3.3.3.11685-to-3.3.3.11723-enus-downloader.exe | "UDP Query User{1A3A3924-5590-4681-A0E7-EA3D56B1A40E}C:\world of warcraft\wow-3.3.2.11403-to-3.3.3.11685-enus-downloader.exe" = protocol=17 | dir=in | app=c:\world of warcraft\wow-3.3.2.11403-to-3.3.3.11685-enus-downloader.exe | "UDP Query User{6154FDDB-BACE-4EC9-AE9E-9032AF85BCBA}C:\users\david\appdata\local\temp\blizzard launcher temporary - 6f504da8\launcher.exe" = protocol=17 | dir=in | app=c:\users\david\appdata\local\temp\blizzard launcher temporary - 6f504da8\launcher.exe | "UDP Query User{828630BC-5013-420B-97FD-BAAAE893636A}C:\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\world of warcraft\backgrounddownloader.exe | "UDP Query User{86F909A2-E908-4FDF-B1F5-CDB86059DA0A}C:\world of warcraft\wow-3.3.3.11685-to-3.3.3.11723-enus-downloader.exe" = protocol=17 | dir=in | app=c:\world of warcraft\wow-3.3.3.11685-to-3.3.3.11723-enus-downloader.exe | "UDP Query User{A24CC550-D099-4D09-B46F-287C949A17B7}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "UDP Query User{A9B85F91-54D8-4A88-8674-FCE62196AE07}C:\world of warcraft\wow-3.3.0.11159-to-3.3.2.11403-enus-downloader.exe" = protocol=17 | dir=in | app=c:\world of warcraft\wow-3.3.0.11159-to-3.3.2.11403-enus-downloader.exe | "UDP Query User{AB51DB74-7D21-485F-9FE4-C11333370B72}C:\users\david\appdata\local\temp\blizzard launcher temporary - ff5705b0\launcher.exe" = protocol=17 | dir=in | app=c:\users\david\appdata\local\temp\blizzard launcher temporary - ff5705b0\launcher.exe | "UDP Query User{D6EFAD1E-F5ED-4CD1-B785-476F294E13AB}C:\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\world of warcraft\launcher.exe | "UDP Query User{DC888761-5800-46B3-A9B2-9CA097BC3184}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0031FC73-643E-19DB-0A34-F7FF70B2F1E7}" = ccc-utility64 "{129E42AF-AE8D-9834-4759-713A0418E048}" = ccc-utility64 "{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{1C89932F-1D9D-4776-AD7A-9156FF792539}" = Modem Diagnostic Tool "{416C48C5-0E99-493D-AE4B-67AB3896095D}" = Microsoft LifeCam "{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety "{48C0866E-57EB-444C-8371-8E4321066BC3}" = Network64 "{4BE9F0B8-FF3D-5CAA-9BF2-CB6F3DF75D3B}" = ccc-utility64 "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{52FB2985-F3AD-DAA7-7645-4E38A5B96E17}" = AMD Catalyst Install Manager "{550331CC-C34B-494F-BCDA-37CE4EF6E924}" = Garmin Communicator Plugin x64 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{812F5B09-D0BA-4036-A63E-69238EF22ECA}" = Microsoft Corporation "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 "{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007 "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software "{C1164ED0-EF08-4B0B-8084-3BDAEAAEFD8D}" = HP Photosmart Prem C410 All-In-One Driver Software 14.0 Rel. 7 "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{DFA48C6E-A32B-4FC6-8170-4212DDCF7284}" = Microsoft LifeChat "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "CCleaner" = CCleaner "CNXT_MODEM_PCI_HSF" = Conexant D850 PCI V.92 Modem "HP Imaging Device Functions" = HP Imaging Device Functions 14.0 "HP Smart Web Printing" = HP Smart Web Printing 4.60 "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0 "HPOCR" = OCR Software by I.R.I.S. 14.0 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "PDF Creator" = PDF Creator "Shop for HP Supplies" = Shop for HP Supplies
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR "{019D7B6B-1123-40E5-AD82-73DC6FE78B30}" = NTI Shadow for ReadyNAS "{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}" = Visual C++ 8.0 Runtime Setup Package (x64) "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier "{03B25762-461B-22C8-9AF0-170F3D749061}" = Catalyst Control Center Graphics Previews Vista "{03BF49A6-A643-A836-0732-2467E9A6B911}" = Catalyst Control Center Localization Korean "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan "{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data "{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE "{0AC7F464-85E9-337D-B100-DC178C14A699}" = Catalyst Control Center Core Implementation "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0BC1B842-C298-99E6-D0A8-FA3B33A07C5C}" = Catalyst Control Center Localization German "{0BF215E3-C97F-7BF3-96D0-9C7D3F5FF9B4}" = Catalyst Control Center Localization Chinese Traditional "{0D1303D7-3918-3014-E119-33DBB649BE86}" = Catalyst Control Center Localization Spanish "{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime "{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1 "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support "{138BF761-BFAA-29BB-B755-91262DE91A19}" = ccc-core-static "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant "{162981A5-050A-3DDA-2477-49724E334DEF}" = CCC Help Spanish "{19A492A0-888F-44A0-9B21-D91700763F62}" = Catalyst Control Center - Branding "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1BF82343-8EE6-8B76-90CF-31059B9D1842}" = CCC Help English "{1DDDFDF2-4A92-4E77-959F-59D196B99C0C}" = C410 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FECF5F8-8E75-432C-9FF7-1C04F1956B54}" = Realtek Ethernet Network Card Diagnostic tool for Windows Vista "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{237CD223-1B9D-47E8-A76C-E478B83CCEA2}" = File Uploader "{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31 "{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7 "{276B965A-AC01-955C-E678-C8D25C58A42B}" = Catalyst Control Center Graphics Previews Common "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox "{2B83C858-A352-1E5D-0052-C326C815F3C4}" = CCC Help Japanese "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update "{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64) "{301CC8D1-FE75-41ED-9B11-41F006110950}" = Garmin City Navigator North America NT 2010.10 Update "{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34962E5E-FAC1-D8DF-7070-AA2B58971E31}" = Catalyst Control Center Graphics Previews Common "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3D374523-CFDE-461A-827E-2A102E2AB365}" = Star Wars Battlefront II "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}" = Google Earth "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion "{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1" = Data Lifeguard Diagnostic for Windows 1.22 "{5370D92F-CF5A-4A38-DE84-151F9F58BCB2}" = Catalyst Control Center Localization Italian "{565E7B0E-B76B-4EAD-9753-F1E72A5CF12E}" = HPAppStudio "{56CDA83B-BC0B-A4A7-BD48-1176A6C97033}" = Catalyst Control Center Graphics Light "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}" = Status "{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{63EB4545-0CB5-35FE-D20C-F8E6995703F3}" = Catalyst Control Center Localization French "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{712A51A2-68F2-17D2-E3EB-C199DA0E0BE0}" = Catalyst Control Center Localization Portuguese "{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{7B08D306-7266-4647-A926-2F78817ED1E0}" = Microsoft Corporation "{7F831576-6246-42C7-B523-55B3F96509CC}" = LogMeIn "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility "{88477E65-A679-2CAE-645A-5073ED86715B}" = CCC Help Portuguese "{88DCB080-7A56-5697-4407-21BD03DCE401}" = Catalyst Control Center Graphics Full New "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8AC7ACAD-10E5-E7F4-481A-29C4C8B19990}" = Catalyst Control Center Graphics Full Existing "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISER_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{9294F169-72EE-4D74-AE92-CA25F64B4FF8}" = Fax "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector "{99D8CE0E-20C7-3761-5F90-0E1329A55824}" = CCC Help Hungarian "{9AAD03E8-4F65-4DE2-8F6C-1B079C0C8521}" = Garmin Lifetime Updater "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C2F79E2-4B21-E840-CF5B-FF1EE52E5B9F}" = Catalyst Control Center Localization Chinese Standard "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A029AD64-F8F2-09AD-E29B-623B4BBF872C}" = CCC Help French "{A044C900-5DE1-4986-B0B8-D6A40271A929}" = Sound Effects "{A09B8374-BD00-63EB-9616-E624A44EF877}" = CCC Help German "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A28D08AE-3FBD-EBDB-BA28-CE719F699E48}" = CCC Help Chinese Standard "{A3111537-BA7A-C129-1E6B-E2C77DCA3AD2}" = CCC Help Italian "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101 "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply "{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.4 "{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9 "{AE133141-825E-440E-AAE5-898ACE8E33C1}" = Scrapbook Factory Deluxe 4.0 "{B2050314-D2DF-6589-E155-5E4E8F8AB3D4}" = Catalyst Control Center Localization Turkish "{B3056450-CA4E-46EC-8BB6-0FACE481A413}" = PERRLA "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2 "{BC5DD87B-0143-4D14-AAE6-97109614DC6B}" = SolutionCenter "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{C2112C02-1BCA-A86F-F6E1-264CCE43F451}" = CCC Help Chinese Traditional "{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp "{CDA2EBE1-999C-48FB-DF9A-81C789900BFF}" = CCC Help Turkish "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D68F16A7-9447-8A92-7EF3-A4E26B2A95EE}" = CCC Help English "{D94A8E22-DF2B-4107-9E51-608A60A7671D}" = Personal Ancestral File 5 "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DE27264D-7CA0-3317-7192-C64F0B7D9AB3}" = Catalyst Control Center Localization Japanese "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E044161D-75F5-3EC5-2BDA-42D106E602D2}" = CCC Help Korean "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E112EC9E-B411-F3E0-EF02-C0D21C09F329}" = Catalyst Control Center Localization Hungarian "{E517094C-06B6-419F-8FFD-EF4F57972130}" = QuickTransfer "{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect "{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer "{E9A1960E-7756-2299-C700-DC7CA6EDD6E4}" = Catalyst Control Center InstallProxy "{E9D98510-A8B6-E39C-B8BA-BA9A511E040C}" = Catalyst Control Center Graphics Previews Common "{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse® "{EA778E78-0B7B-05AE-A72F-AF484D201DFB}" = Skins "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype 5.10 "{EFABB945-0D32-C208-897A-F611F63A19D4}" = CCC Help English "{F007CBCE-D714-4C0B-8CE9-9B0D78116468}" = ViewNX "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F217D8AF-965B-4D3E-8F14-AC47B9CA535B}" = PS_AIO_07_C410_SW_Min "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm "{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "0591-8077-9297-0833" = FamilySearch Indexing 3.11.0 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "ENTERPRISER" = Microsoft Office Enterprise 2007 "FileZilla Client" = FileZilla Client 3.5.0 "GameSpy Arcade" = GameSpy Arcade "Google Chrome" = Google Chrome "HP Photo Creations" = HP Photo Creations "Impulse®" = Impulse® "Logitech Vid" = Logitech Vid HD "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100 "Math Blaster" = Math Blaster "Mozilla Firefox 19.0.2 (x86 en-US)" = Mozilla Firefox 19.0.2 (x86 en-US) "MozillaMaintenanceService" = Mozilla Maintenance Service "N360" = Norton Security Suite "NetDevil_LEGO_Universe_is1" = LEGO Universe "PackMaster 2010" = PackMaster 2010 "Picasa 3" = Picasa 3 "RealPlayer 12.0" = RealPlayer "Sins of a Solar Empire - Trinity" = Sins of a Solar Empire - Trinity "Trillian" = Trillian "TroopMaster 2010" = TroopMaster 2010 "WinLiveSuite" = Windows Live Essentials "Xfire" = Xfire (remove only)
[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "ActiveTouchMeetingClient" = WebEx "Oregon Trail 5th Edition" = Oregon Trail 5th Edition "UnityWebPlayer" = Unity Web Player
[color=#E56717]========== Last 20 Event Log Errors ==========[/color]
[ Application Events ] Error - 3/15/2013 12:05:41 AM | Computer Name = Arthas | Source = Windows Search Service | ID = 3013 Description =
Error - 3/15/2013 12:05:41 AM | Computer Name = Arthas | Source = Windows Search Service | ID = 3013 Description =
Error - 3/15/2013 12:05:41 AM | Computer Name = Arthas | Source = Windows Search Service | ID = 3013 Description =
Error - 3/15/2013 12:05:42 AM | Computer Name = Arthas | Source = Windows Search Service | ID = 3013 Description =
Error - 3/15/2013 12:05:42 AM | Computer Name = Arthas | Source = Windows Search Service | ID = 3013 Description =
Error - 3/15/2013 12:19:56 AM | Computer Name = Arthas | Source = WinMgmt | ID = 10 Description =
Error - 3/15/2013 12:43:00 AM | Computer Name = Arthas | Source = WinMgmt | ID = 10 Description =
Error - 3/15/2013 7:43:16 PM | Computer Name = Arthas | Source = WinMgmt | ID = 10 Description =
Error - 3/16/2013 10:18:15 AM | Computer Name = Arthas | Source = Application Error | ID = 1000 Description = Faulting application Shadow.exe, version 3.7.9.73, time stamp 0x48903bad, faulting module msxml3.dll, version 8.100.5006.0, time stamp 0x50939e6e, exception code 0xc0000005, fault offset 0x000236fb, process id 0x1274, application start time 0x01ce224a6fbf6be8.
Error - 3/17/2013 11:08:15 AM | Computer Name = Arthas | Source = ESENT | ID = 215 Description = WinMail (12260) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.
Error - 3/20/2013 7:10:39 PM | Computer Name = Arthas | Source = ESENT | ID = 215 Description = WinMail (20404) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.
[ Media Center Events ] Error - 11/28/2012 6:12:28 AM | Computer Name = Arthas | Source = MCUpdate | ID = 0 Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
Error - 12/1/2012 6:12:31 AM | Computer Name = Arthas | Source = MCUpdate | ID = 0 Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
Error - 12/4/2012 6:12:14 AM | Computer Name = Arthas | Source = MCUpdate | ID = 0 Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
Error - 12/9/2012 9:33:41 PM | Computer Name = Arthas | Source = MCUpdate | ID = 0 Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
Error - 12/10/2012 6:12:31 AM | Computer Name = Arthas | Source = MCUpdate | ID = 0 Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
Error - 12/11/2012 6:12:31 AM | Computer Name = Arthas | Source = MCUpdate | ID = 0 Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
Error - 12/12/2012 6:12:31 AM | Computer Name = Arthas | Source = MCUpdate | ID = 0 Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
Error - 12/15/2012 6:12:29 AM | Computer Name = Arthas | Source = MCUpdate | ID = 0 Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
Error - 12/18/2012 6:12:23 AM | Computer Name = Arthas | Source = MCUpdate | ID = 0 Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
Error - 12/24/2012 2:47:23 PM | Computer Name = Arthas | Source = MCUpdate | ID = 0 Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
[ OSession Events ] Error - 2/14/2009 1:25:10 AM | Computer Name = Arthas | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 52038 seconds with 360 seconds of active time. This session ended with a crash.
Error - 10/10/2011 2:35:21 AM | Computer Name = Arthas | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 94199 seconds with 7800 seconds of active time. This session ended with a crash.
Error - 11/27/2011 3:06:21 AM | Computer Name = Arthas | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4961 seconds with 3840 seconds of active time. This session ended with a crash.
Error - 3/12/2012 11:55:08 PM | Computer Name = Arthas | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 8, Application Name: Microsoft Office Publisher, Application Version: 12.0.6652.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 3145 seconds with 1680 seconds of active time. This session ended with a crash.
[ System Events ] Error - 4/1/2013 12:07:12 PM | Computer Name = Arthas | Source = DCOM | ID = 10010 Description =
Error - 4/2/2013 11:23:40 PM | Computer Name = Arthas | Source = DCOM | ID = 10010 Description =
Error - 4/2/2013 11:47:18 PM | Computer Name = Arthas | Source = Service Control Manager | ID = 7031 Description =
Error - 4/2/2013 11:47:18 PM | Computer Name = Arthas | Source = Service Control Manager | ID = 7034 Description =
Error - 4/2/2013 11:54:01 PM | Computer Name = Arthas | Source = netbt | ID = 4321 Description = The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.1.4. The computer with the IP address 192.168.1.1 did not allow the name to be claimed by this computer.
Error - 4/3/2013 12:30:58 AM | Computer Name = Arthas | Source = netbt | ID = 4321 Description = The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.1.4. The computer with the IP address 192.168.1.1 did not allow the name to be claimed by this computer.
Error - 4/3/2013 12:32:50 AM | Computer Name = Arthas | Source = Service Control Manager | ID = 7009 Description =
Error - 4/3/2013 12:32:50 AM | Computer Name = Arthas | Source = Service Control Manager | ID = 7000 Description =
Error - 4/3/2013 12:38:05 AM | Computer Name = Arthas | Source = Service Control Manager | ID = 7022 Description =
Error - 4/3/2013 9:54:15 AM | Computer Name = Arthas | Source = netbt | ID = 4321 Description = The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.1.4. The computer with the IP address 192.168.1.1 did not allow the name to be claimed by this computer. |