OTL Extras logfile created on: 8/29/2011 12:25:06 PM - Run 1 OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\John\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19120) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.00 Gb Total Physical Memory | 1.71 Gb Available Physical Memory | 56.94% Memory free 6.23 Gb Paging File | 4.81 Gb Available in Paging File | 77.19% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 289.04 Gb Total Space | 75.16 Gb Free Space | 26.00% Space Free | Partition Type: NTFS Drive D: | 9.05 Gb Total Space | 1.23 Gb Free Space | 13.61% Space Free | Partition Type: NTFS Drive E: | 298.09 Gb Total Space | 229.71 Gb Free Space | 77.06% Space Free | Partition Type: NTFS Drive F: | 4.63 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF Computer Name: HOME-2 | User Name: John | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (All) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- C:\Windows\System32\mshta.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .inf [@ = inffile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\Windows\System32\rundll32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) .reg [@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation) .txt [@ = txtfile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-3452593512-2370901467-3437361607-1001\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\system32\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "E:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "E:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 1 "InternetSettingsDisableNotify" = 1 "AutoUpdateDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink -- (EarthLink, Inc.) [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{14DEE5E8-5F93-4CB1-9B1D-06F95A63F23C}" = lport=1900 | protocol=17 | dir=in | name=intel(r) viiv(tm) media server upnp discovery | "{2DF2CF5F-F1EE-4ADF-99E5-F3F6DF4F4516}" = lport=9442 | protocol=17 | dir=in | name=intel(r) viiv(tm) media server discovery | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{011E587B-E51C-49BA-B14A-2DFF32D015B7}" = protocol=17 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\mediaserver.exe | "{0823BAE8-1360-40D5-84A0-4F217E4D1109}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{08BD6D6E-0DCF-4E16-93B3-0DA5C843EE2C}" = protocol=6 | dir=in | app=e:\program files\ventrilo\ventrilo.exe | "{09F00489-7DDD-4A6E-AA9A-7612CE0711FA}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{0B23B5F9-D565-4638-83ED-AF3E246A717A}" = protocol=6 | dir=in | app=c:\program files\electronic arts\the lord of the rings, the rise of the witch-king\game.dat | "{0B35845D-A227-45A2-8A58-58FD7B62102E}" = protocol=17 | dir=in | app=c:\program files\intel\inteldh\intel media server\shells\remote ui service.exe | "{11A719BB-69DC-479E-AE6B-319A3668BFFA}" = protocol=6 | dir=in | app=c:\program files\curse\curseclient.exe | "{11B60A19-CAB5-47EC-8FB0-9BC0BACA9051}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{19C99A72-695E-47E0-92D4-E14A30BFBBC5}" = protocol=17 | dir=in | app=c:\program files\id software\enemy territory - quake wars\etqwded.exe | "{27533F1C-3209-4AEA-A0D0-5D89029E9DD6}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{280FE1A3-3849-485B-80A7-0FD103E35CA2}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{300FEFEA-E8C6-4DFC-95CD-04C22D59B398}" = protocol=17 | dir=in | app=c:\program files\curse\curseclient.exe | "{3041B941-63CD-486A-968A-600DED330A10}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{308B9EFE-8350-4792-AF5A-6EE70A031D19}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{30E72723-FDCA-461D-B20C-0346C56B343F}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{32C70C3B-C59C-4C5B-B0E5-E8FF73C0C86D}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{340C16FF-04A7-4645-9DEC-930CF285E933}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{3C5F0B09-0378-4918-959B-1EBFD024095F}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe | "{44E54F58-6E4F-46FC-AC8F-26E7BB94842A}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{451DFEC9-D6D3-4E0B-AD6E-D103C324451A}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{463DF688-B9D3-464C-9D2F-3AE7D7A7AE76}" = protocol=17 | dir=in | app=c:\program files\firaxis games\sid meier's civilization 4\civilization4.exe | "{4B849AC5-D3C7-4ADE-8198-0EA8C71FFB5C}" = protocol=17 | dir=in | app=e:\program files\ventrilo\ventrilo.exe | "{4D40FB41-7607-468D-AD32-2687DCF8AE22}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{4ED1D0F1-11DF-45CC-8C0A-66B7B931DEEC}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{5448DF4B-7068-49AE-9368-E2DAB0C4A9DE}" = protocol=6 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\tshwmdtcp.exe | "{582FD025-A577-4FF2-BD04-102BE021010F}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{5BF757D4-930B-45FC-8D8D-C35A4FF094E7}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{643C29B1-896C-494F-9A13-32FC6CA81A23}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{651AF546-7635-448C-BD4F-43316541B904}" = protocol=17 | dir=in | app=c:\program files\id software\enemy territory - quake wars\etqw.exe | "{678DF7E7-9945-4112-BCA7-167A1B422965}" = protocol=17 | dir=in | app=c:\program files\ea games\the battle for middle-earth (tm)\game.dat | "{69D8A558-5BD4-4E15-9C2A-5385A6F4B89A}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{6C710352-767E-44E5-A0A0-9CAF49250D9E}" = protocol=6 | dir=in | app=c:\program files\flagship studios\hellgate london\launcher.exe | "{6CDB3960-AEDF-4AC5-984E-8712F7F726BE}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{6DF2A9FC-D678-41CB-AF26-B439BDC1DA27}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe | "{7412AEF9-9EB7-4515-8E88-1543889ACD21}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{745E35E1-C444-4A19-9E4B-0975B74BC45D}" = protocol=17 | dir=in | app=c:\program files\electronic arts\the lord of the rings, the rise of the witch-king\game.dat | "{750727CA-4B7F-4AD0-AA87-899C231E9D6D}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{794234C6-52E6-4EAE-912A-F362847908E2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{7DF64627-9F14-4CB2-A783-F93B5D45FD62}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{85081B59-42E0-44F2-8877-F53B1D4758BE}" = protocol=6 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\mediaserver.exe | "{8A10C341-637D-4A61-97C2-D0E7E8A15E10}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{8B17A902-9604-40D1-A0E7-78201ABAEEFE}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{8D1EC51C-5E30-4550-A4D3-5FDEA02FC626}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{94B0314D-6E0D-470E-B3DA-C1C8FF4F6507}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{9803720D-89A2-4337-BBFD-502C71FBFC70}" = protocol=6 | dir=in | app=c:\program files\ea games\the battle for middle-earth (tm)\game.dat | "{9B1F0D74-99A0-4FF1-837E-49CB24944A10}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{A74B5952-CA52-451A-A364-C6519BA7A00C}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{A9502D8C-DC84-4B27-8B3B-4E96684BCEC7}" = protocol=17 | dir=in | app=c:\users\john\appdata\local\apps\2.0\voj11vgc.jp0\gnqj01mx.whr\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\curseclient.exe | "{A985A142-C976-4035-B40C-9C6904A90C45}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{ACEE9CA4-413A-4AD5-96B3-7F6A6E90BC29}" = protocol=17 | dir=in | app=c:\program files\electronic arts\the battle for middle-earth (tm) ii\game.dat | "{ACF520D8-FE70-49F1-AC52-25CDCC8A27EA}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{B079D55C-C290-4F2B-8531-E538017A891A}" = dir=in | app=c:\program files\itunes\itunes.exe | "{B335ABF7-E2B9-43DB-84BC-652EBFD8BE38}" = protocol=6 | dir=in | app=c:\program files\electronic arts\the battle for middle-earth (tm) ii\game.dat | "{B62A101A-BA0F-479A-AEF9-ACFAA394CB5D}" = protocol=17 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\tshwmdtcp.exe | "{B849DA94-D8C8-409F-91A6-56742B1AA2D2}" = protocol=6 | dir=in | app=c:\program files\intel\inteldh\intel media server\shells\remote ui service.exe | "{BB5AFF76-0196-4699-A31A-F44A8233C37E}" = protocol=6 | dir=in | app=c:\program files\id software\enemy territory - quake wars\etqw.exe | "{C05C2001-70DA-4AF5-BC30-A910C68B2719}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{C393EFBF-FF7F-425A-882F-36CA6B5B782A}" = protocol=6 | dir=in | app=c:\program files\id software\enemy territory - quake wars\etqwded.exe | "{C624E554-9B8B-4BDB-B6FB-81876FDABCD6}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{C8720F13-AAA7-4A6F-89EE-AD92927A807D}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{CA5E4DEA-D6DD-483C-AE7A-0F441532A4DD}" = protocol=17 | dir=in | app=c:\program files\flagship studios\hellgate london\launcher.exe | "{CDB7B93B-E67F-4264-8221-B53DF10DD12F}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe | "{D0995B3A-8EA9-4E31-932C-1BC9F0FC414C}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{D31692C9-2D81-4742-9251-51CFC3580674}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{D46FCFF5-A81D-42A4-B356-FA8D1C77B4C1}" = protocol=6 | dir=in | app=c:\users\john\appdata\local\apps\2.0\voj11vgc.jp0\gnqj01mx.whr\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\curseclient.exe | "{D5E46D76-D434-451D-A45B-18908B05344F}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{D6CACB16-A3C2-4D47-BE92-1CEC598944A0}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{DA7BA5EB-B223-48F0-9CEF-6A538D531960}" = protocol=6 | dir=in | app=c:\program files\firaxis games\sid meier's civilization 4\civilization4.exe | "{DBBB3F97-EA23-4629-97F9-2E001E55BA8F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{DCAE6722-36C2-4505-839D-179FEA045E31}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{DFF8F54B-AEC2-4323-A213-83F1B60DBE7E}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{E4B7462E-D461-4198-ABA4-8BC4433766D6}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{E4DA6B17-D260-4B61-8748-629C9F1119E0}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{E6508050-EA30-4363-ABFC-9D1F9CA324B4}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe | "{EA037B6B-40F1-4987-BAE7-D37BF9CD3148}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{EB9EBA88-560A-4AAE-8E85-CB75DF532303}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{EE0F4F19-5D93-4483-8EAF-93F8E34CB397}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{FC408BAC-2E63-45D7-BC42-C4A76FC5B084}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{FC562563-8159-44BC-92B7-D8026E2E63B2}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{FDC636B6-DF27-4FC1-A237-6C2B2CE1B128}" = dir=in | app=c:\program files\skype\phone\skype.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Professional "{027B17C7-C291-6FB5-0C82-8BC157599201}" = Catalyst Control Center "{02EBDBB9-4600-41D3-B566-40CB861511D2}" = World of Warcraft FREE Trial "{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{07D3F755-05A0-934E-6F48-706C43927AA9}" = CCC Help English "{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5 "{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data "{0DDA7620-4F8B-43B3-8828-CA5EE292FA3B}" = HP Total Care Advisor "{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration "{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive "{13A63CE1-102E-0F29-1461-BD793DCB0766}" = HydraVision "{152B782A-05F3-48EC-9AAC-4D3EB68D9E20}" = Quake 4(TM) "{186A63A2-4256-43C6-8061-95EF77A5CDB6}" = Sid Meier's Civilization 4 "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{19A492A0-888F-44A0-9B21-D91700763F62}" = Catalyst Control Center - Branding "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget "{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20 "{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour "{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}" = The Battle for Middle-earth (tm) II "{2CD2C0DB-81C3-416B-9FA6-589B9235359B}" = OpenOffice.org 2.4 "{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine "{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1 "{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java(TM) 6 Update 4 "{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Roxio Activation Module "{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend "{42FB5A75-286D-4854-A84E-419A28DD437B}" = WebEx Support Manager for Firefox or Chrome "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4F661F5D-A485-48CE-837C-6B55D1915827}" = Call of Duty(TM) Game of the Year Edition "{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{582D2A53-F426-4C5E-A2E6-43C1AB36B907}" = Safari "{5BF5F9C5-E95B-4AFA-94BE-F2A9CA73B61D}" = Apple Mobile Device Support "{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library "{5F00DF7E-418B-4CD9-8EC5-781156BCC49E}" = Microsoft Money Shared Libraries "{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3 "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7 "{6BCC0A09-6235-C2DE-4E3D-09F7793C6FB3}" = Catalyst Control Center Graphics Previews Common "{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}" = HP Active Support Library 32 bit components "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works "{6E7BF6EC-C3E7-43A7-8A03-0D204E3EC01B}" = Intel® Viiv™ Software "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{74E2CD0C-D4A2-11D3-95A6-0000E86CFDE5}" = SSH Secure Shell "{7694E0B1-2332-448B-9235-929F84B41E3F}" = Active@ ISO Burner "{775B9052-3517-47FA-817D-1BB28363D43A}" = muvee autoProducer 6.0 "{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client "{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01 "{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01 "{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio "{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs "{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial "{8BCAFB73-49AE-4AC4-00A1-70E4EC38BD4E}" = The Lord of the Rings, The Rise of the Witch-king "{8C2690CF-5B74-4F93-8139-7B5644CD6A3B}" = MobileMe Control Panel "{8E9D71EC-A34B-4af8-A320-34891813DE34}" = PictureMover "{8EA79DBF-D637-448A-89D6-410A087A4493}" = Samsung_MonSetup "{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003 "{938B1CD7-7C60-491E-AA90-1F1888168240}" = Roxio MyDVD Basic v9 "{962E05CF-3394-496D-0091-850CF1762F6B}" = The Battle for Middle-earth (tm) "{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback "{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime "{A2B4455D-1046-4732-BFBC-0821BEFC07BC}" = Hellgate: London "{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2 "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 "{AAD47011-8518-4608-9656-951DA35B587B}" = iTunes "{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements "{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2 "{B6ADA0E4-9451-43EB-B86E-878AD9E68D4F}" = LightScribe 1.6.45.1 "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars "{B7A585C8-CE4E-4150-84C6-A13C3CB1379F}" = Enemy Territory - Quake Wars(TM) "{B8FA4B2B-67A0-18D0-77DD-F08405016F37}" = ATI Catalyst Install Manager "{C1392D78-3958-03C8-E747-51DE7CEE8E03}" = Catalyst Control Center InstallProxy "{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4 "{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2 "{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility "{D751FC11-146D-9848-6993-9A567E05B1EF}" = ccc-utility "{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007 "{E0FA1DC5-FEBF-4E7B-8FA3-DB94233E952D}" = Razer Lycosa "{EB1B8449-CD8F-485B-ADB6-02FBCFE180D3}" = Razer DeathAdder(TM) Mouse "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support "{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE "{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "7-Zip" = 7-Zip 4.65 "ActiveTouchMeetingClient" = WebEx "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2 "avast" = avast! Internet Security "CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP "HP Photosmart Essential" = HP Photosmart Essential 2.01 "InstallShield_{152B782A-05F3-48EC-9AAC-4D3EB68D9E20}" = Quake 4(TM) "InstallShield_{4F661F5D-A485-48CE-837C-6B55D1915827}" = Call of Duty(TM) Game of the Year Edition "InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2 "InstallShield_{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3 "Intel(R) Configuration Center" = Intel® Viiv™ Software "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Money2007b" = Microsoft Money 2007 "Mozilla Firefox (3.6.20)" = Mozilla Firefox (3.6.20) "OfficeTrial" = Microsoft Office Home and Student 60 day trial "OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator "PC-Doctor 5 for Windows" = Hardware Diagnostic Tools "PROSet" = Intel(R) Network Connections Drivers "PunkBusterSvc" = PunkBuster Services "Rhapsody" = Rhapsody "Steam App 220" = Half-Life 2 "Steam App 380" = Half-Life 2: Episode One "Steam App 400" = Portal "Steam App 420" = Half-Life 2: Episode Two "Steam App 440" = Team Fortress 2 "Warcraft III" = Warcraft III "WildTangent hp Master Uninstall" = My HP Games "winscp3_is1" = WinSCP 4.2.7 "World of Warcraft" = World of Warcraft "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Search Defender" = Yahoo! Search Protection "Yahoo! Toolbar" = Yahoo! Toolbar "Zoo Tycoon 1.0" = Microsoft Zoo Tycoon [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-3452593512-2370901467-3437361607-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "090215de958f1060" = Curse Client "ActiveTouchMeetingClient" = WebEx [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Antivirus Events ] Error - 1/1/2008 1:41:39 AM | Computer Name = Home-2 | Source = avast! | ID = 33554522 Description = Error - 4/6/2008 10:05:00 AM | Computer Name = Home-2 | Source = avast! | ID = 33554522 Description = Error - 6/30/2008 6:36:51 PM | Computer Name = Home-2 | Source = avast! | ID = 33554522 Description = Error - 7/22/2009 8:07:02 PM | Computer Name = Home-2 | Source = avast! | ID = 33554522 Description = Error - 7/22/2009 8:07:02 PM | Computer Name = Home-2 | Source = avast! | ID = 33554522 Description = Error - 9/1/2009 11:56:15 PM | Computer Name = Home-2 | Source = avast! | ID = 33554522 Description = Error - 9/1/2009 11:56:15 PM | Computer Name = Home-2 | Source = avast! | ID = 33554522 Description = Error - 2/17/2010 9:35:21 PM | Computer Name = Home-2 | Source = avast! | ID = 33554522 Description = Error - 2/17/2010 9:35:21 PM | Computer Name = Home-2 | Source = avast! | ID = 33554522 Description = [ Application Events ] Error - 10/20/2009 10:28:56 PM | Computer Name = Home-2 | Source = Windows Search Service | ID = 3013 Description = Error - 10/20/2009 10:28:56 PM | Computer Name = Home-2 | Source = Windows Search Service | ID = 3013 Description = Error - 10/20/2009 10:28:56 PM | Computer Name = Home-2 | Source = Windows Search Service | ID = 3013 Description = Error - 10/20/2009 10:28:56 PM | Computer Name = Home-2 | Source = Windows Search Service | ID = 3013 Description = Error - 10/20/2009 10:28:56 PM | Computer Name = Home-2 | Source = Windows Search Service | ID = 3013 Description = Error - 10/20/2009 10:28:56 PM | Computer Name = Home-2 | Source = Windows Search Service | ID = 3013 Description = Error - 10/20/2009 10:28:56 PM | Computer Name = Home-2 | Source = Windows Search Service | ID = 3013 Description = Error - 10/20/2009 10:28:56 PM | Computer Name = Home-2 | Source = Windows Search Service | ID = 3013 Description = Error - 10/20/2009 10:28:56 PM | Computer Name = Home-2 | Source = Windows Search Service | ID = 3013 Description = Error - 10/27/2009 10:20:40 PM | Computer Name = Home-2 | Source = VSS | ID = 8194 Description = [ Media Center Events ] Error - 10/11/2009 5:19:15 PM | Computer Name = Home-2 | Source = Media Center Guide | ID = 0 Description = Event Info: ERROR: SqmApiWrapper.TimerAccumulate failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide Error - 10/11/2009 5:20:38 PM | Computer Name = Home-2 | Source = Media Center Guide | ID = 0 Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide Error - 11/23/2009 8:41:09 PM | Computer Name = Home-2 | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. Error - 10/2/2010 2:34:36 PM | Computer Name = Home-2 | Source = Media Center Guide | ID = 0 Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide [ System Events ] Error - 8/24/2011 1:13:36 AM | Computer Name = Home-2 | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.0.100 for the Network Card with network address 001D6052D8E4 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message). Error - 8/25/2011 1:27:04 AM | Computer Name = Home-2 | Source = DCOM | ID = 10010 Description = Error - 8/25/2011 1:52:42 PM | Computer Name = Home-2 | Source = BROWSER | ID = 8032 Description = Error - 8/26/2011 4:15:48 AM | Computer Name = Home-2 | Source = DCOM | ID = 10010 Description = Error - 8/26/2011 11:14:38 AM | Computer Name = Home-2 | Source = BROWSER | ID = 8032 Description = Error - 8/27/2011 7:11:01 AM | Computer Name = Home-2 | Source = DCOM | ID = 10010 Description = Error - 8/27/2011 2:24:27 PM | Computer Name = Home-2 | Source = BROWSER | ID = 8032 Description = Error - 8/28/2011 9:26:01 PM | Computer Name = Home-2 | Source = DCOM | ID = 10010 Description = Error - 8/28/2011 10:00:24 PM | Computer Name = Home-2 | Source = BROWSER | ID = 8032 Description = Error - 8/29/2011 8:51:35 AM | Computer Name = Home-2 | Source = DCOM | ID = 10010 Description = < End of report >