OTL Extras logfile created on: 8/27/2012 5:01:50 PM - Run 1 OTL by OldTimer - Version 3.2.59.1 Folder = C:\Users\user\Desktop\Removal\Again 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 5.80 Gb Total Physical Memory | 3.81 Gb Available Physical Memory | 65.72% Memory free 11.61 Gb Paging File | 9.21 Gb Available in Paging File | 79.39% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 911.88 Gb Total Space | 847.14 Gb Free Space | 92.90% Space Free | Partition Type: NTFS Computer Name: USER-PC | User Name: user | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-2257964894-50073877-2741020953-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () "C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- () [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0119C2B9-FA8A-4712-9351-EF2314FD75FE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{0EAB80B1-D9DE-4B44-BA0E-29EB24AAC697}" = lport=445 | protocol=6 | dir=in | app=system | "{11397052-9C71-43A2-8D0D-061639EAC17D}" = lport=139 | protocol=6 | dir=in | app=system | "{135BFD64-0DDF-4A1E-98FC-E9DBAF485404}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{1E457601-7247-44E6-9525-4A12DD3F048C}" = lport=5353 | protocol=17 | dir=in | name=bonjour | "{213DA898-2A67-4B1B-85B3-AFD3C9361D26}" = lport=10243 | protocol=6 | dir=in | app=system | "{21418F1C-73DF-44C4-BE82-41415A26DFEC}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{30B5B823-44A2-4046-AD6B-03A4D576D3F2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{339C2F5D-6C1D-4376-9B5C-285C6070E901}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{39D4DD30-8FFA-4B91-B055-4FE06294BE77}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{3CB06CA2-FD19-409C-8B5F-97D691505475}" = rport=139 | protocol=6 | dir=out | app=system | "{41C5D435-E1B1-4C2F-B2AC-FE4F7109EE5C}" = lport=2869 | protocol=6 | dir=in | app=system | "{4A419F57-CB28-4E16-A0CD-97260E33C6A2}" = lport=137 | protocol=17 | dir=in | app=system | "{4A9B04D4-900F-4D54-9090-6F2A528344AE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{54A4DE70-A5FF-4613-AEED-2EAF89B4BAEC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{5619C748-9A35-4193-B40F-DCEBB3144F1C}" = rport=10243 | protocol=6 | dir=out | app=system | "{5A3F4C90-5C82-4F25-8122-D5C38244FB11}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6B1E8F62-9374-4BDB-BA17-17CCB2D986B5}" = rport=445 | protocol=6 | dir=out | app=system | "{70D2073B-4707-4E7E-8A64-F280E4146E92}" = rport=138 | protocol=17 | dir=out | app=system | "{7F0868F4-FA41-456D-BFC2-A4CBAA20EDE0}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe | "{958376D0-8DFF-4652-AA0B-F539C624C4C9}" = lport=5353 | protocol=17 | dir=in | name=bonjour | "{971F0D0E-AE57-42B9-A406-1A0E5C5D2989}" = rport=137 | protocol=17 | dir=out | app=system | "{9CE71B6C-2EED-413E-A3CB-DE193822751F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{A58B896D-D769-4FA1-BAFF-DD6C3D9DCCBD}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{A60A586C-2893-4AF1-B836-5DD7C66C81E5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{A652473D-8E54-4D3C-9D05-468584190BAD}" = lport=138 | protocol=17 | dir=in | app=system | "{B17A43EE-C28F-4D38-BB0F-A10D082E3D97}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{B4ECE0F9-0219-4914-9337-BA062348D780}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{D0CE2F95-F0AD-4A14-8387-28BD8FAE48B9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F97107EC-DD5A-4897-9082-8781AAF55A24}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0FD2F982-682A-439C-B1EC-49AC30B13A7B}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{1284FC3A-A2D4-4F2E-9324-B701ED3E9734}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremote.exe | "{12D70A4D-51E3-4286-A3F5-9D68A2C90FB3}" = protocol=6 | dir=in | app=c:\users\user\appdata\roaming\dropbox\bin\dropbox.exe | "{240100C2-CA6E-4385-B030-B2327366DBBE}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{25F4E6E0-55AF-43E0-B28C-2A6BE597DE37}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{2ADCC0BA-CE93-4E4B-B50E-4698997003C1}" = dir=in | app=c:\users\user\appdata\local\facebook\video\skype\facebookvideocalling.exe | "{2BB3A62E-E3DF-4932-B2EB-238804BD7F19}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{2EF164AF-2482-45BF-915B-B79E086DC9E7}" = dir=in | app=c:\program files\dell stage\dell stage\stage_primary.exe | "{2FC932B4-7568-48DF-B77E-532F74DA9180}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{2FC976A4-919A-462A-9F36-43DAB535E3C5}" = dir=in | app=c:\program files\dell stage\musicstage\musicstageengine.exe | "{38CA8932-ADB5-4B36-93CF-06923ED41083}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3CB97C0A-2331-4668-B291-BF625118C59D}" = dir=in | app=c:\program files\dell stage\dell stage\accuweather\accuweather.exe | "{4727344E-C5EC-4648-9402-9C2A113E3052}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{48938F9C-B993-4BD8-93A7-15E4948F681D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{4E667FC7-89A9-4B2A-BD4D-4E2BA19F668F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{54E6C368-8E5E-4ABB-9933-40CDE5FF68AA}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\dmr.exe | "{5BCA55B2-90BB-485F-9E99-26F27225736A}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{5C9FEEF1-AF4B-4DF9-8F91-642E55657E6B}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{63B0C256-26E1-4204-8D3A-27741F1CD611}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{66246561-7117-4840-9B65-0DAA70BF2BA9}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\controller.exe | "{68F5A73C-B059-48A7-8E8F-3D5B42DD9B9B}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{6E342DDE-F9FA-4172-8DBA-C8F3096FCEEA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{6EFDCD4B-CB97-4BB2-A678-3365142F2196}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{73DDEA8E-76D9-4B30-B0A9-286BEBFE1142}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremoteservice.exe | "{75C67BA3-408B-49A0-AEA9-8D161B99D917}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{7F5F8D9B-CB5D-4EF0-80B8-DC3130511B9A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{82A771DB-7AB3-4B32-A6CB-6D6F3D6CD5B3}" = dir=in | app=c:\program files (x86)\airport\apagent.exe | "{84A1A395-9495-431F-A5F9-DFDCD6B27D85}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{8B99A9C0-0234-4235-8C5A-C1133ED4C5DF}" = dir=in | app=c:\program files (x86)\dell\videostage\videostage.exe | "{8DDF65A3-AAB3-4751-82EB-147D0AE190B5}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremoteservice.exe | "{937414EC-A35B-4AC0-B980-3DEFB6147A9E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{95515829-3B8C-48B8-91AD-AA1BC8277AE9}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{9E9677F7-3767-42BD-88E3-10EF94000905}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{9FF25E16-A19F-4225-BB80-BC0B8631D7EE}" = protocol=17 | dir=in | app=c:\users\user\appdata\roaming\dropbox\bin\dropbox.exe | "{A325D2F6-35A6-4CA3-A7C3-A5772205505E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{A7F995EC-507D-446A-817D-7E12D9010161}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{A957770A-5C76-4D77-BD23-36C2C5C42ED4}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{B3580D8B-5F89-4346-835D-408370924FFE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{B85EDBC1-71DF-42CE-9F3B-062A7D245F6D}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\controller.exe | "{C2B5B623-923E-4BB7-8872-14806942CCDF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{C66297DB-2762-472C-AD0F-906CD7293F84}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremote.exe | "{CD11086B-6DE2-4788-B7AE-A5D04B6B8A85}" = protocol=6 | dir=out | app=system | "{D22D2F0F-188F-4998-8062-D8B35003B89B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{DE5D6CF4-AF12-4E4E-9BF2-969A6BA0F7F5}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\installerhelp.exe | "{E7878B19-1BA3-4458-A1B2-BFCFAD3260C4}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{EB96CE4E-98CC-4E7D-8DD6-1FFC631A1E40}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{F10F3DCC-3676-48D7-87EF-3BF8AE53D3DA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{F25FAEDC-DF63-4A24-AF86-E39BB194304F}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{FECF09F2-780A-4307-97DB-6ABDEB938E0C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{FEEAFD6E-5BB5-4090-A535-69C2EE87FBCE}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\dmr.exe | "{FF893464-6B3E-4483-88CC-496FDD53DCFB}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\installerhelp.exe | "TCP Query User{008AD699-865B-4EBF-98FA-71FF658319F5}C:\program files (x86)\airport\aputil.exe" = protocol=6 | dir=in | app=c:\program files (x86)\airport\aputil.exe | "TCP Query User{01363911-D154-4D44-AB69-E4F36DAB49AD}C:\users\user\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\roaming\dropbox\bin\dropbox.exe | "TCP Query User{237FD2A3-5CBE-4195-9A6F-3546E500DE7C}C:\program files (x86)\airport\aputil.exe" = protocol=6 | dir=in | app=c:\program files (x86)\airport\aputil.exe | "TCP Query User{47D6869D-8EFD-488F-B32C-BD109657A501}C:\program files (x86)\aji reader service\arservice.exe" = protocol=6 | dir=in | app=c:\program files (x86)\aji reader service\arservice.exe | "TCP Query User{63CFA7DA-1A30-4F74-96FD-B63525900824}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dell\dell datasafe online\nobuclient.exe | "TCP Query User{AEE017DD-CAD9-4D68-9A8B-BD67FB7D9821}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dell\dell datasafe online\nobuclient.exe | "TCP Query User{B2F3468D-1411-4C7F-8592-C597EA9BE058}C:\program files (x86)\dell\stage remote\stageremoteservice.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremoteservice.exe | "TCP Query User{C43BCCAD-D1D3-45D7-8E20-1B348771F484}C:\program files (x86)\airparrot\airparrot.exe" = protocol=6 | dir=in | app=c:\program files (x86)\airparrot\airparrot.exe | "UDP Query User{5FF4C2D7-3922-4245-BD6D-B89A6E2C889B}C:\program files (x86)\dell\stage remote\stageremoteservice.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremoteservice.exe | "UDP Query User{69EFFC80-32E3-4BB8-B23C-40DB629A0BB7}C:\program files (x86)\airparrot\airparrot.exe" = protocol=17 | dir=in | app=c:\program files (x86)\airparrot\airparrot.exe | "UDP Query User{86DA8902-8BC1-4751-9A29-01FD3C556201}C:\program files (x86)\airport\aputil.exe" = protocol=17 | dir=in | app=c:\program files (x86)\airport\aputil.exe | "UDP Query User{921E75F8-FB13-437E-BFAF-B1B3BEF0A0BC}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dell\dell datasafe online\nobuclient.exe | "UDP Query User{9548F6D2-F6E5-47B7-BD11-45BD0EABB131}C:\users\user\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\roaming\dropbox\bin\dropbox.exe | "UDP Query User{CC33CB81-EC2E-42B3-97EC-9FE178C6FF3C}C:\program files (x86)\aji reader service\arservice.exe" = protocol=17 | dir=in | app=c:\program files (x86)\aji reader service\arservice.exe | "UDP Query User{D48DE3A9-FAA2-4D56-9164-52A2087D7C65}C:\program files (x86)\airport\aputil.exe" = protocol=17 | dir=in | app=c:\program files (x86)\airport\aputil.exe | "UDP Query User{E0E550BE-8D97-4B42-A98A-C0F6E6A2BCB5}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dell\dell datasafe online\nobuclient.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0DA20600-6130-443B-9D4B-F30520315FA6}" = Bonjour Print Services "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8B485965-8EFE-464A-842F-CF8F18C3DFD7}" = iCloud "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010 "{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad "{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro Titanium Internet Security 2012 "{ABBD4BA9-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro Titanium "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft Security Client" = Microsoft Security Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0A44DDBC-C26B-4DB8-B04C-64216D7C761A}" = eTakeoff Plan Viewer Version 3.01-26 "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime "{0ECFCB07-9BFE-4970-ACA1-D568D982760B}" = Complete Care Business Service Agreement "{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup "{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1 "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F3A6960-8470-4C84-820C-EBFFAF4DA580}" = AT&T Connect Participant Application v9.0.82 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{2299EEBD-0A83-4B26-AA4A-057AE9E5BAE8}" = Dell Stage Remote "{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java(TM) 7 Update 5 "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{2A07AA78-79DB-11E1-8313-984BE15F174E}" = Evernote v. 4.5.4 "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3BD7DD08-991B-4A2F-A165-614ED14EAADD}" = Dell MusicStage "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement "{432EF6AF-78EE-4858-B62B-C41C7D60B9DC}" = Sales Access Manager Personal Edition "{451517F1-7E41-400B-AA36-FB7E2563526D}" = Dell Wireless Driver Installation "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7 "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159 "{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide "{7EC66A95-AC2D-4127-940B-0445A526AB2F}" = Dell DataSafe Online "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7 "{820B6609-4C97-3A2B-B644-573B06A0F0CC}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010 "{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010 "{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010 "{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 "{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010 "{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010 "{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 "{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 "{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010 "{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 "{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010 "{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 "{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010 "{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{903679E8-44C8-4C07-9600-05C92654FC50}" = QualxServ Service Agreement "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 "{AA68AAAE-41F0-40B5-8896-5947F5FD6889}" = AirPort "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB2FDE4F-6BED-4E9E-B676-3DCCEBB1FBFE}" = Dell Home Systems Service Agreement "{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.3) MUI "{AF4D3C63-009B-4A17-B02E-D395065DD3F0}" = Dell Stage Remote "{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR "{C33AA6D6-F5EC-48F3-AFDC-8141345D473A}" = Premium Service Agreement "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86 "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio "{E4335E82-17B3-460F-9E70-39D9BC269DB3}" = Dell PhotoStage "{E77A53A2-4623-4635-AE7F-702152168EE5}" = Google Drive "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{EF85FEF4-EB92-4075-A6D2-5F519BB30A2C}" = Accidental Damage Services Agreement "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F4597448-E8EF-4260-B7D8-1DDD10FDC8B0}" = AirParrot "{F47C37A4-7189-430A-B81D-739FF8A7A554}" = Consumer In-Home Service Agreement "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FE182796-F6BA-486A-8590-89B7E8D1D60F}" = Dell Stage "Adobe AIR" = Adobe AIR "Advanced Audio FX Engine" = Advanced Audio FX Engine "Dell Webcam Central" = Dell Webcam Central "ERUNT_is1" = ERUNT 1.1j "InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage "Office14.SingleImage" = Microsoft Office Home and Business 2010 "WinLiveSuite" = Windows Live Essentials [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-2257964894-50073877-2741020953-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "Google Chrome" = Google Chrome "GoToMeeting" = GoToMeeting 5.2.0.952 [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 8/15/2012 4:56:04 PM | Computer Name = user-PC | Source = Bonjour Service | ID = 100 Description = 1948: Could not write data to client after 488 seconds, 1 reply waiting Error - 8/15/2012 4:56:04 PM | Computer Name = user-PC | Source = Bonjour Service | ID = 100 Description = 1904: Could not write data to client after 488 seconds, 1 reply waiting Error - 8/15/2012 4:56:04 PM | Computer Name = user-PC | Source = Bonjour Service | ID = 100 Description = 2404: Could not write data to client after 492 seconds, 2 replies waiting Error - 8/15/2012 4:56:04 PM | Computer Name = user-PC | Source = Bonjour Service | ID = 100 Description = 2436: Could not write data to client after 492 seconds, 2 replies waiting Error - 8/15/2012 4:56:04 PM | Computer Name = user-PC | Source = Bonjour Service | ID = 100 Description = 2600: Could not write data to client after 488 seconds, 1 reply waiting Error - 8/15/2012 4:56:04 PM | Computer Name = user-PC | Source = Bonjour Service | ID = 100 Description = 2608: Could not write data to client after 488 seconds, 1 reply waiting Error - 8/15/2012 4:56:04 PM | Computer Name = user-PC | Source = Bonjour Service | ID = 100 Description = 2380: Could not write data to client after 488 seconds, 1 reply waiting Error - 8/15/2012 4:56:04 PM | Computer Name = user-PC | Source = Bonjour Service | ID = 100 Description = 2280: Could not write data to client after 488 seconds, 1 reply waiting Error - 8/15/2012 4:56:04 PM | Computer Name = user-PC | Source = Bonjour Service | ID = 100 Description = 1948: Could not write data to client after 488 seconds, 1 reply waiting Error - 8/15/2012 4:56:04 PM | Computer Name = user-PC | Source = Bonjour Service | ID = 100 Description = 1904: Could not write data to client after 488 seconds, 1 reply waiting [ System Events ] Error - 5/28/2012 3:55:12 PM | Computer Name = user-PC | Source = Service Control Manager | ID = 7009 Description = A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect. Error - 5/28/2012 3:55:12 PM | Computer Name = user-PC | Source = Service Control Manager | ID = 7000 Description = The Windows Search service failed to start due to the following error: %%1053 Error - 6/7/2012 5:38:40 PM | Computer Name = user-PC | Source = volsnap | ID = 393283 Description = The shadow copy of volume C: being created failed to install. Error - 6/28/2012 10:38:35 AM | Computer Name = user-PC | Source = volsnap | ID = 393283 Description = The shadow copy of volume C: being created failed to install. Error - 6/29/2012 9:02:30 AM | Computer Name = user-PC | Source = volsnap | ID = 393283 Description = The shadow copy of volume C: being created failed to install. Error - 7/4/2012 10:15:07 PM | Computer Name = user-PC | Source = Service Control Manager | ID = 7031 Description = The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error - 7/6/2012 10:32:11 AM | Computer Name = user-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk1\DR6. Error - 7/7/2012 2:36:38 AM | Computer Name = user-PC | Source = Service Control Manager | ID = 7031 Description = The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error - 7/30/2012 9:18:02 AM | Computer Name = user-PC | Source = Service Control Manager | ID = 7034 Description = The Google Update Service (gupdate) service terminated unexpectedly. It has done this 1 time(s). Error - 7/30/2012 9:18:30 AM | Computer Name = user-PC | Source = DCOM | ID = 10010 Description = < End of report >