OTL Extras logfile created on: 8/10/2012 11:04:32 AM - Run 1 OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\victor\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.96 Gb Total Physical Memory | 1.93 Gb Available Physical Memory | 65.01% Memory free 5.93 Gb Paging File | 4.84 Gb Available in Paging File | 81.72% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 138.28 Gb Total Space | 32.33 Gb Free Space | 23.38% Space Free | Partition Type: NTFS Drive E: | 120.73 Mb Total Space | 119.54 Mb Free Space | 99.01% Space Free | Partition Type: FAT Computer Name: VICTOR-PC | User Name: victor | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- "C:\Program Files\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{005D33CB-E25A-4878-A423-47359FFE876A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{09293821-39A0-4B65-AD4A-E98BE4145F7A}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{0C7B3250-E256-42DD-A986-4126F5D0BBE5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{134B6C4E-2B61-4F62-BA50-2F6A24052EE7}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe | "{1C0BCF94-129E-4054-A92C-2ECE2A64E0AD}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{28C87A49-8FA4-465F-8DEE-16B67D8A7061}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{29678E66-2447-4732-90C7-FF6BBF855EB8}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface | "{2F56F797-6CD1-41CA-8960-472FECF8F661}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{3270111E-B02C-431E-B33E-172CADD2A152}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3BF5B388-C52A-447B-B055-2F26F693E6FF}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{41071776-7490-4B5A-87FD-79D91269A3FC}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{52C1CC5E-9D5C-4493-B756-E82849F6BD5E}" = rport=2869 | protocol=6 | dir=out | app=system | "{5CF07F73-6862-4B7B-9B27-D2B1CE468C5C}" = lport=10243 | protocol=6 | dir=in | app=system | "{604C72C6-E1B4-44C0-8766-28A70DAD09CB}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{76B309F7-D64F-43D8-9792-593D1963FCA2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{7BD25212-B2BA-40A8-BD8E-584BE2B20478}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{7D92F4F7-7C19-4742-AABE-D62418DEA9B4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{87149E1F-80EE-441A-9064-1C1149CD6040}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{91078EEA-1572-4D93-B3DB-1145DD0D73F6}" = lport=2869 | protocol=6 | dir=in | app=system | "{92B0461E-859E-4909-B8C2-53B0BA18596C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{940F21E4-E145-4E60-AA38-F4A099A760A5}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{A44F6A98-B3C3-47C3-AC27-C55F5C0783F0}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{B19AA99C-86DD-4B47-B08A-775901427742}" = lport=2869 | protocol=6 | dir=in | app=system | "{B31E82D6-81BE-4A53-8647-4AB34E34CE8F}" = rport=10243 | protocol=6 | dir=out | app=system | "{BB018BFC-CA3D-4FE9-BB47-316D4930E004}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C80A4F84-560B-412D-8862-BC194C693545}" = lport=52897 | protocol=6 | dir=in | name=akamai netsession interface | "{CBFE70A5-8AD8-4DCE-92B7-8E3C8AD19FA1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D15D60D7-2D35-4520-B8D4-878F8D202C9E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D732AA82-1DCF-4F09-B0F9-E0B8BAA64104}" = lport=2869 | protocol=6 | dir=in | app=system | "{E8526FCC-50A5-4687-865F-701FAA4D5F2E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{EBF4C578-A28C-4D3F-90BA-49C6AD325F52}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{EFC53397-79D0-4A40-B49C-DCDA8BD3F370}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{F3981EB2-7B03-434E-B8A2-84879EC70B83}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{FA76E040-0BEE-4FA1-8C0E-4B8699718E58}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{075D1ACE-1D42-4505-B882-AA8470D341A0}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe | "{08FA3506-6C3C-4C68-97AB-1A7A4593815E}" = protocol=17 | dir=in | app=c:\program files\google\google talk\googletalk.exe | "{0C7D4BCE-4368-48EF-BF00-DD65F28309D5}" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe | "{0F9C4B89-7E52-4200-8DB5-C96888655899}" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe | "{0FB053F4-2917-48CC-A511-416A7493B219}" = protocol=6 | dir=in | app=c:\users\victor\appdata\local\google\google talk plugin\googletalkplugin.exe | "{1375E66D-2AFC-4D50-A28B-3E16D178F459}" = protocol=17 | dir=in | app=c:\program files\epsonnet\epsonnet setup\tool09\eneasyapp.exe | "{195E2111-2D5A-4ABB-AB37-2A180EB93085}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{2B9A544B-E42A-4F41-9FB9-DC45B4838DF8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{2DBA27B9-BF90-4D45-991B-EF3863ABA240}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{3BFFF5A7-FB68-4232-9664-5921B61A69DC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{3D08AC51-4104-4F78-8AC5-8BE3E5194910}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{3D7E748C-D442-4025-A716-2124E1156336}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{46B0BCA0-579B-451C-8D4A-03CD72B764E8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{49FB8F6A-BC44-432A-A7B4-D6E066C30947}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{4B917204-4C39-4CA7-BB86-C1821AE47698}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{4CDEA990-EDCF-4F4C-BFE1-2CCD372CDAC1}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{4EBEBF89-2042-4965-AB2C-1DFC2862D96C}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe | "{4F71A4CD-431C-40E7-9422-74C4FB295951}" = protocol=6 | dir=in | app=c:\program files\google\google talk\googletalk.exe | "{4FC27BC6-10F1-4FC0-ADD1-E0268A1328E3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{55A3C1B6-9BAC-410F-AC67-6EC5EB8F90FB}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe | "{5988768F-5166-4929-9EC9-BC20244B099E}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe | "{5A4333D6-399A-409C-B23E-BC156A6B6CB3}" = protocol=17 | dir=in | app=c:\users\victor\appdata\local\google\google talk plugin\googletalkplugin.exe | "{5BE4DDB2-523D-413A-8E37-574B9F9E32E1}" = protocol=17 | dir=in | app=c:\program files\frostwire\frostwire.exe | "{5C8E32AE-5083-470B-9823-F63A75809828}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe | "{5E537C50-439F-4524-B2F9-A8A1FF8ED38F}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{6AA33158-B7E3-48AE-8A0B-62503DFC370F}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe | "{6EA851F0-82BD-4F0F-834F-7A934DF6F40E}" = protocol=6 | dir=out | app=system | "{7222F704-0483-40AB-B3A2-DF05DB42DDEF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{738502C9-D79E-4406-8DFA-9ED4C62A36D0}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe | "{7FC2C3EF-112A-4775-B8FA-988FA5CDE4A0}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe | "{8346B1C4-722C-4786-862D-12BDA7A83F34}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{839793EB-22AD-41D5-B66F-818A97942119}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe | "{8FF2E934-21CF-4763-B856-5DDDC6E79E5C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{92840A8C-92D8-447A-9942-C6EFD6F4AF2F}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgam.exe | "{9342C2A7-477C-45A8-A3E9-BE889DE7EF76}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{959B570C-2D82-4207-A0A8-C22089E099F8}" = dir=in | app=c:\program files\finalmediaplayer\fmpcheckforupdates.exe | "{95F8BC56-ABE9-4CEA-8A8F-63174742A061}" = protocol=6 | dir=in | app=c:\program files\epsonnet\epsonnet setup\tool09\eneasyapp.exe | "{A34375F5-C874-4373-82AA-EB4D2AE2242C}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgam.exe | "{A9CBE6D9-D8CA-40E1-9F3A-749603EE065E}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe | "{ADD113A9-7888-4E8F-88DC-CEFDE1B39BA1}" = protocol=6 | dir=in | app=c:\program files\frostwire\frostwire.exe | "{B0FCA196-9662-4396-BFD1-D075C7E0EEFD}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "{C26F7C78-85EA-4082-97DF-DA58DCBF0916}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe | "{C58BAEF3-7CB8-4B18-99D7-488C5452A3D7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{CD29664D-4F70-46B4-B08C-26704C3FBF49}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{DB3FF948-0242-4A68-87EB-0FD48D3526B8}" = dir=in | app=c:\program files\itunes\itunes.exe | "{E03EB20A-BFB8-4BCB-B7CE-065008A2224A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E11E6734-6E49-4980-B525-B129C6F3E549}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe | "{E5B74597-F188-4936-BD72-AEFB61826394}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "{EFCDF79E-BD80-46EE-85CA-B0A756C40EDC}" = dir=in | app=c:\users\victor\appdata\local\facebook\video\skype\facebookvideocalling.exe | "{F77AF452-FEE3-4E99-B5E2-BF5698D36523}" = protocol=17 | dir=in | app=c:\users\victor\appdata\local\google\google talk plugin\googletalkplugin.exe | "{FB8F7917-B507-4FF5-80C8-4DC227D5CA60}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe | "{FC2F3E9A-F0EA-44A6-A0CD-5712277607EA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{FEB96043-8278-466E-9A9B-8E027B584146}" = protocol=6 | dir=in | app=c:\users\victor\appdata\local\google\google talk plugin\googletalkplugin.exe | "TCP Query User{17BA553B-2CE4-4853-AE8F-35E098502E70}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "TCP Query User{19DA40E9-B545-47AD-AEE8-D760CB8348E0}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "TCP Query User{25316F2E-C1C3-489E-80D9-6816C51478B9}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe | "TCP Query User{2F9E2D90-0BC7-4AA6-A6A0-182A34D7AB98}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "TCP Query User{42C730DC-5BD0-4592-B93E-E197B9405F33}C:\program files\research in motion\blackberry desktop\rim.desktophelper.exe" = protocol=6 | dir=in | app=c:\program files\research in motion\blackberry desktop\rim.desktophelper.exe | "TCP Query User{4911908F-BBE9-4A6E-98F9-54352892BDF4}C:\program files\nero\nero8\nero home\nerohome.exe" = protocol=6 | dir=in | app=c:\program files\nero\nero8\nero home\nerohome.exe | "TCP Query User{67C3AEC0-21C8-4AEB-96AC-2DFF4DEF68CC}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{86464EAA-C139-448E-AE59-72F3E31FF21A}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe | "TCP Query User{B049FE9F-71DE-4105-9D2F-5FD1F6C1CBFA}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe | "TCP Query User{C48D1810-C62E-4268-BBEB-E9F9000B8271}C:\program files\limewire plus+\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire plus+\limewire.exe | "TCP Query User{D1BA451C-F7A2-4490-9B13-3E24685989A9}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "TCP Query User{D222CBE4-A714-488B-BE6E-6E0284018D4C}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "TCP Query User{E99A30DB-C7CB-44DB-AF9D-4625DC6D3606}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe | "TCP Query User{FC719189-05B9-4BE6-A3C2-F191684B98BC}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe | "UDP Query User{035FC118-B31B-4CAB-8876-BADB2F517626}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | "UDP Query User{094880E3-237C-43F2-BC72-7A1D4A0DCE5A}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe | "UDP Query User{218E3543-F1B5-458D-A45A-E93C629399DD}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "UDP Query User{221B6CDC-62CF-41C0-8200-746C51B45F20}C:\program files\research in motion\blackberry desktop\rim.desktophelper.exe" = protocol=17 | dir=in | app=c:\program files\research in motion\blackberry desktop\rim.desktophelper.exe | "UDP Query User{25704383-4B74-49F0-B3B3-2194A3D9D696}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe | "UDP Query User{37A8D44D-2178-4E83-A01F-68FEF01B7427}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe | "UDP Query User{49744933-2863-43D5-90A6-F66D2D4DC8B0}C:\program files\limewire plus+\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire plus+\limewire.exe | "UDP Query User{594769BE-28D3-4733-9D5A-2AA7925F993C}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "UDP Query User{75DBFCE7-A6FA-4028-AE85-5685ECA68506}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{96E6FB9C-C12A-44E2-A542-4A23E958B8BC}C:\program files\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files\epson software\event manager\eeventmanager.exe | "UDP Query User{C289C86E-71FE-4F81-A50D-D4CF569BBA40}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe | "UDP Query User{C821E270-39D8-4EB3-A59E-62C01CDDB195}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "UDP Query User{CAAD8352-E71F-49DA-94AE-0CFC3175A291}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe | "UDP Query User{D2E9B309-8058-4474-93DE-248DD34D3C9F}C:\program files\nero\nero8\nero home\nerohome.exe" = protocol=17 | dir=in | app=c:\program files\nero\nero8\nero home\nerohome.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0 "{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518) "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86 "{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime "{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86 "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only) "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{245FCF81-55BA-4AB9-A7C1-37411595676D}" = Nuance PaperPort 12 "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 29 "{331C9768-BAD9-F31B-8DA2-0268D346C702}" = Times Reader "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print "{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0 "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{46A6DEEF-50AD-7EF3-9F6A-9062D2C2021A}" = The Complete National Geographic "{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth "{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86 "{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes "{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER "{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}" = PaperPort Image Printer "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{7B63B2922B174135AFC0E1377DD81EC2}" = "{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{912CED74-88D3-4C5B-ACB0-132318649765}" = PressReader "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 "{942E5031-2BD6-4C1B-918C-C8A1CBAE7B8C}" = Microsoft IntelliPoint 8.2 "{94A90C69-71C1-470A-88F5-AA47ECC96B40}" = TOSHIBA HDD Protection "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9692FD03-6662-4E62-B08C-30DFF51651E1}" = Actiontec Gateway "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9C633BAC-9A34-4BFD-B311-787D37F3EAFB}" = Nuance PDF Viewer Plus "{9E384B32-59C8-46EF-BEA6-4DC8F27CDB8E}" = InstallVC90Support "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{ABD39060-5F6C-470A-A891-73ACC92ED8DB}" = TOSHIBA WWAN Manager "{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1 "{B014EE44-9197-4513-9613-71E6EB1B514E}" = Nikon Message Center 2 "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0 "{B46E0571-DE58-4D5C-8D77-64070C6EACDA}" = Qualcomm Gobi Single Installer Package for Toshiba "{BA31F48A-C811-30B4-AD93-1986C7838442}" = Google Talk Plugin "{BCE46757-7674-4416-BEDB-68205A60409E}" = CanoScan Toolbox Ver4.1 "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant "{C8E95BF5-C07F-4D98-BB42-F58FC98BC03E}" = Google Apps "{C96FF998-45BD-411E-9253-B7F2660FE280}" = Qwest Installer "{CD95F661-A5C4-44F5-A6AA-ECDD91C240D2}" = WinZip 16.5 "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86 "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86 "{DDD62492-32A7-412B-8AF1-2CF032AD42E3}" = ViewNX 2 "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E487EE7D-EAAA-4E2A-9116-E3B477D8A74F}" = TOSHIBA USB Sleep and Charge Utility "{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5 "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "{FFFAE01B-466F-4C07-9821-A94FD753BDDA}" = EpsonNet Setup "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind "BitTorrent" = BitTorrent "com.nationalgeographic.products.cng120.68B1CC4249876152EBE333BD4B7514ADB4D94062.1" = The Complete National Geographic "com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1" = Times Reader "EPSON NX510 Series" = EPSON NX510 Series Printer Uninstall "EPSON Scanner" = EPSON Scan "FinalMediaPlayer_is1" = Final Media Player 2011 "GraphCalc v4.0.1_is1" = GraphCalc v4.0.1 "HDMI" = Intel(R) Graphics Media Accelerator Driver "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "ImgBurn" = ImgBurn "InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center "InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2 "NAV" = Norton AntiVirus "Picasa 3" = Picasa 3 "ProSeries Basic Edition 2009" = ProSeries Basic Edition 2009 "QwestQuickCare_is1" = Qwest Quickcare 2.7 "Scrivener 1220" = Scrivener "Trusted Software Assistant_is1" = File Type Assistant "TVWiz" = Intel(R) TV Wizard "WinLiveSuite" = Windows Live Essentials [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-2712941158-3131102933-1011039749-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 8/9/2012 1:06:04 PM | Computer Name = victor-PC | Source = Application Hang | ID = 1002 Description = The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 610 Start Time: 01cd764efb3af825 Termination Time: 5515 Application Path: C:\Windows\Explorer.EXE Report Id: 5271334a-e244-11e1-80ca-00261840192c Error - 8/9/2012 1:26:17 PM | Computer Name = victor-PC | Source = Application Hang | ID = 1002 Description = The program iexplore.exe version 9.0.8112.16447 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: f20 Start Time: 01cd7653fbef3cef Termination Time: 31 Application Path: C:\Program Files\Internet Explorer\iexplore.exe Report Id: 4cf7b8cb-e247-11e1-a95b-00261840192c Error - 8/9/2012 2:10:09 PM | Computer Name = victor-PC | Source = Application Hang | ID = 1002 Description = The program iexplore.exe version 9.0.8112.16447 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 2dc Start Time: 01cd765a245b46c2 Termination Time: 19 Application Path: C:\Program Files\Internet Explorer\iexplore.exe Report Id: 6d75c484-e24d-11e1-be29-00261840192c Error - 8/9/2012 3:51:34 PM | Computer Name = victor-PC | Source = VSS | ID = 8193 Description = Error - 8/9/2012 4:15:32 PM | Computer Name = victor-PC | Source = VSS | ID = 8193 Description = Error - 8/9/2012 4:55:02 PM | Computer Name = victor-PC | Source = Application Hang | ID = 1002 Description = The program GoogleUpdate.exe version 1.2.131.7 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 15fc Start Time: 01cd767105c62517 Termination Time: 16 Application Path: C:\Program Files\Google\Update\GoogleUpdate.exe Report Id: 73df50a6-e264-11e1-8452-00261840192c Error - 8/9/2012 5:34:27 PM | Computer Name = victor-PC | Source = VSS | ID = 8193 Description = Error - 8/10/2012 1:43:05 PM | Computer Name = victor-PC | Source = Google Update | ID = 20 Description = Error - 8/10/2012 1:47:00 PM | Computer Name = victor-PC | Source = Google Update | ID = 20 Description = Error - 8/10/2012 2:07:14 PM | Computer Name = victor-PC | Source = VSS | ID = 8193 Description = [ OSession Events ] Error - 2/1/2011 6:14:00 PM | Computer Name = victor-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1279 seconds with 1260 seconds of active time. This session ended with a crash. Error - 2/1/2011 6:36:55 PM | Computer Name = victor-PC | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 9 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 8/10/2012 1:48:41 PM | Computer Name = victor-PC | Source = Service Control Manager | ID = 7000 Description = The Windows Font Cache Service service failed to start due to the following error: %%1079 Error - 8/10/2012 1:48:43 PM | Computer Name = victor-PC | Source = Service Control Manager | ID = 7000 Description = The Windows Font Cache Service service failed to start due to the following error: %%1079 Error - 8/10/2012 1:49:30 PM | Computer Name = victor-PC | Source = Service Control Manager | ID = 7000 Description = The Windows Font Cache Service service failed to start due to the following error: %%1079 Error - 8/10/2012 1:56:33 PM | Computer Name = victor-PC | Source = Service Control Manager | ID = 7000 Description = The Windows Font Cache Service service failed to start due to the following error: %%1079 Error - 8/10/2012 2:03:46 PM | Computer Name = victor-PC | Source = WMPNetworkSvc | ID = 866300 Description = Error - 8/10/2012 2:03:46 PM | Computer Name = victor-PC | Source = Service Control Manager | ID = 7000 Description = The SSDP Discovery service failed to start due to the following error: %%1079 Error - 8/10/2012 2:03:46 PM | Computer Name = victor-PC | Source = Service Control Manager | ID = 7000 Description = The SSDP Discovery service failed to start due to the following error: %%1079 Error - 8/10/2012 2:03:46 PM | Computer Name = victor-PC | Source = Service Control Manager | ID = 7001 Description = The UPnP Device Host service depends on the SSDP Discovery service which failed to start because of the following error: %%1079 Error - 8/10/2012 2:03:46 PM | Computer Name = victor-PC | Source = Service Control Manager | ID = 7000 Description = The SSDP Discovery service failed to start due to the following error: %%1079 Error - 8/10/2012 2:03:46 PM | Computer Name = victor-PC | Source = Service Control Manager | ID = 7001 Description = The UPnP Device Host service depends on the SSDP Discovery service which failed to start because of the following error: %%1079 < End of report >