OTL Extras logfile created on: 18/11/2012 16:39:38 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\LUKILADY\Documents\Downloads Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 2.00 Gb Total Physical Memory | 0.69 Gb Available Physical Memory | 34.76% Memory free 4.23 Gb Paging File | 2.84 Gb Available in Paging File | 67.29% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 69.78 Gb Total Space | 9.03 Gb Free Space | 12.93% Space Free | Partition Type: NTFS Drive D: | 69.51 Gb Total Space | 43.85 Gb Free Space | 63.08% Space Free | Partition Type: NTFS Drive F: | 983.22 Mb Total Space | 18.61 Mb Free Space | 1.89% Space Free | Partition Type: FAT Drive G: | 40.37 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: FREESPIRIT-VS | User Name: LUKILADY | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 1 "InternetSettingsDisableNotify" = 1 "AutoUpdateDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 1 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe" = C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu -- (Acer Inc.) "C:\Acer\Empowering Technology\eDataSecurity\encryption.exe" = C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption -- (HiTRUST) "C:\Acer\Empowering Technology\eDataSecurity\decryption.exe" = C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption -- (HiTRUST) "C:\Acer\Empowering Technology\eDataSecurity\eDSrf.exe" = C:\Acer\Empowering Technology\eDataSecurity\eDSrf.exe:*:Enabled:eDSrf -- (HITRUST) "C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Disabled:Spybot-S&D 2 Scanner Service "C:\Program Files\Spybot - Search & Destroy 2\SDFWSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFWSvc.exe:*:Enabled:Spybot-S&D 2 Firewall service "C:\Program Files\Spybot - Search & Destroy 2\SDMonSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDMonSvc.exe:*:Enabled:Spybot-S&D 2 On-Access monitor service "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon "C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater "C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{146EC89D-BD26-47A1-8FB7-3CECA63E38C3}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{35C59E58-C88C-46C2-8CA7-83E01A7D9D97}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{41DEECE4-3522-46A3-9017-C754E1E3013E}" = lport=2869 | protocol=6 | dir=in | app=system | "{5159581F-C85C-4965-9955-90511C68BC6D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{6EA1D985-482D-47EB-ADC9-C1D1D3C4DE88}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{9AED41BB-E244-43DD-8FA7-8D9511A9EBEE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{ACB17EE0-9383-40B8-9683-3FDFA4C8F4C9}" = lport=7777 | protocol=17 | dir=in | app=c:\windows\ehome\ehshell.exe | "{CAD7844B-F7FD-485E-B21E-916B4A44AF9D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{CFA780D2-E8FC-4FCB-AD03-E353BA99B287}" = lport=554 | protocol=6 | dir=in | app=c:\windows\ehome\ehshell.exe | "{D180E4AB-F36F-4BD1-AC9A-73E7F20AAD58}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{D6D4AE18-B355-4AB3-BB54-AA8605AD4DB7}" = lport=3390 | protocol=6 | dir=in | app=system | "{D809B449-E69D-4BFB-9709-D1787E392873}" = rport=10244 | protocol=6 | dir=out | app=system | "{DC62FBAB-BEB5-4A1A-96E5-60E6A50A4C54}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{EB23A438-34AA-421A-9DCA-EF88193764AF}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{F2735B7C-6422-40CF-A939-9155CF8CE0A2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{F4362002-C350-4393-82B2-EEBDF30DC0A6}" = lport=10244 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{06E4E7C9-83C7-451B-8977-D9F08D8A8852}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe | "{077F7CFD-C42C-48BD-8694-85220A946E6D}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe | "{11DD5610-7F84-4770-A11A-1AF76F2A8032}" = protocol=17 | dir=in | app=c:\program files\superantispyware\superantispyware.exe | "{232239AE-5E99-4965-B3FE-BED27F2E2A4B}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe | "{28FDF932-13D4-4D6C-9F05-C3BFA5E5B4E1}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{2BC00C2F-9FA2-4CAA-8075-D20669CAD05D}" = protocol=6 | dir=out | svc=mcx2svc | app=c:\windows\system32\svchost.exe | "{4466BA0C-A84B-47F4-BCA1-8C08F67C08D0}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe | "{570D6EE3-4C0F-4EC8-BEF5-882CC719710D}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe | "{5B63EF1A-2B85-492F-9CDE-6AE162F16802}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe | "{61581752-3445-43AB-8C6B-5F9DDC3A1B61}" = protocol=17 | dir=out | app=c:\windows\ehome\ehshell.exe | "{62DE2C39-124E-45D9-9A1D-0B6CC6C79F70}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{651E73DE-ACD8-4B9A-99EB-B4680B2942AB}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe | "{718DEC6E-AAC9-462A-ACD2-6017C27C9A48}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe | "{7B0EF680-E556-4D19-A49C-67E52E31024D}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe | "{7B1FEE43-18F8-4C18-8AE6-8A8839ADB214}" = protocol=6 | dir=out | app=c:\windows\ehome\ehshell.exe | "{82BA22E3-BD76-42FD-91FB-76411FC6990F}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe | "{87ED2D28-7749-4938-9D1D-163220FFAF8E}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe | "{88AD90B5-3C66-4CD3-A62E-38FCEECCD041}" = protocol=6 | dir=out | app=system | "{8BB7057D-C989-45F3-979C-09297184A9AC}" = dir=in | app=c:\program files\acer arcade deluxe\dvdivine\dvdivine.exe | "{9107BB8F-063E-4109-AC98-782CAA718CEC}" = protocol=6 | dir=out | app=c:\windows\ehome\mcx2prov.exe | "{9636CFBA-B7CD-41E8-B11E-4808ED4AA52F}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe | "{96ACAEC8-1283-4276-89EC-96D0254ED7B7}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe | "{9B9186CD-8F9A-40E7-959B-40A64227ED7F}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{A427CCFD-2D8D-4D93-BDAA-F8ADF96667C6}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{A82ABF6C-BA92-4F90-83B4-DC28405F93B6}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe | "{B1837B59-142C-4525-816A-092828568DF5}" = dir=in | app=c:\program files\windows live\mesh\moe.exe | "{B4C87850-6C9C-44DB-9A75-2F098B2ED6D9}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe | "{C5A7F907-5C83-4942-A886-C95B5327A98B}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{D8B62EE6-FFFD-42E9-BC3C-12FADE486B94}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe | "{F0484873-3879-456C-A434-2E39E03AE6F7}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe | "{F219D296-C87A-4618-BA58-48C272888BBB}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe | "{F6871E12-29F4-40D0-9F2C-EF3DABD1E397}" = protocol=6 | dir=in | app=c:\program files\superantispyware\superantispyware.exe | "{F7EF4A59-A912-4BDB-BD2C-73B610C4410F}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe | "TCP Query User{37F21DD2-72A4-48DC-90CD-6BA71F0FC80C}C:\program files\musicbrainz picard\picard.exe" = protocol=6 | dir=in | app=c:\program files\musicbrainz picard\picard.exe | "TCP Query User{4F86E80C-2F32-466F-9188-698CFC6D4046}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "TCP Query User{EAEF0ED8-00A1-4B75-B290-D251B0C29C57}C:\program files\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files\videolan\vlc\vlc.exe | "UDP Query User{52AC539A-A59E-4DBA-9DA0-55A14638CBEE}C:\program files\musicbrainz picard\picard.exe" = protocol=17 | dir=in | app=c:\program files\musicbrainz picard\picard.exe | "UDP Query User{858FD714-BBA5-46B6-829B-A18C58D58A2D}C:\program files\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files\videolan\vlc\vlc.exe | "UDP Query User{EDB4DF87-3DC9-41BB-AB50-39060854E0EE}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01F6C6F6-0D5A-45D0-83DB-38AB421D0BF5}" = Steganos Safe One "{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}" = Epson Event Manager "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0B480F9F-4D85-43CA-B189-FDF5347E427C}" = Macrium Reflect Free Edition "{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}" = Acer eLock Management "{11F5D779-7BD9-465A-BBC4-10701386BCB9}" = FW LiveUpdate "{13A5E785-5197-4EAD-8EE3-D660271E49BC}" = Feedback Tool "{166FCF01-AC98-4288-A01C-90BEB808C059}" = Sony RAW Driver "{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 3.5 "{1AEC7728-1640-4E98-AABC-5EBE3FB57FE4}" = SMSC Fast Infrared Driver "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service "{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 33 "{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5 "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{32A3A4F4-B792-11D6-A78A-00B0D0160290}" = Java(TM) SE Development Kit 6 Update 29 "{32A3A4F4-B792-11D6-A78A-00B0D0160330}" = Java(TM) SE Development Kit 6 Update 33 "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{39F58DDB-B2B8-4B86-AF20-4706A80EB30D}" = Epson Easy Photo Print 2 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis "{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources "{48165C86-E786-414F-8548-C77CEE2664DF}" = SlimComputer "{48E80C20-00B3-11D4-AA4A-00C0580802FD}" = USB CF Reader Ver 4.2.0.3 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4AEC24E4-373F-4E75-88DC-822E7F3E61E4}" = DiskUsageAnalyzer "{4BB1DCED-84D3-47F9-B718-5947E904593E}" = Acer OrbiCam "{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10 "{56B777D9-9D85-4A81-BF59-1EED7401ADC4}" = Google Cloud Connect for Microsoft Office "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management "{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}" = Vodafone Mobile Broadband Lite "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1" = Auslogics BoostSpeed "{73EC658D-A1C6-40CA-8E86-E05821BAACE7}" = Java DB 10.6.2.1 "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{8810F2B7-A26B-40C1-9527-58CE2C496B21}" = USB MultiMediaCard Reader Ver 1.02 Beta 3 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A41CFD3-A3F0-4501-94F2-D71661AFD6DF}" = AVG 2011 "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = 2007 Microsoft Office Suite Service Pack 3 (SP3) "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{98A24200-17D3-4F27-A3A8-02AAB25EB504}" = AVG 2011 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1 "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4) "{AEEAE013-92F1-4515-B278-139F1A692A36}" = Acer eDataSecurity Management "{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0 "{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE65A9A0-9686-45C6-9098-3C9543A412F0}" = Acer eSettings Management "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DD1DED37-2486-4F56-8F89-56AA814003F5}" = Acer OrbiCam "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{EF67AE1A-6B31-4C98-91A9-F195D8702150}" = Google Drive "{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Deluxe "{F02C0A8C-7409-437A-A587-588B02B3635E}" = Teaching-you Italian "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01 "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5 "{FCCC2E29-A6E0-4588-A0DE-38678E5F7904}" = Byki "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "AVG" = AVG 2011 "Byki Express" = Byki Express "CassetteMate" = CassetteMate "CCleaner" = CCleaner "Defraggler" = Defraggler "EPSON Scanner" = EPSON Scan "EPSON SX125 Series" = EPSON SX125 Series Printer Uninstall "EPSON SX125 Series Manual" = EPSON SX125 Series Manual "ffdshow_is1" = ffdshow v1.2.4475 [2012-07-12] "FileHippo.com" = FileHippo.com Update Checker "Foxit Reader_is1" = Foxit Reader "Free Spider_is1" = Free Spider Solitaire 2012 v3.0 "Glary Utilities_is1" = Glary Utilities 2.34.0.1190 "Google Chrome" = Google Chrome "HijackThis" = HijackThis 1.99.1 "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "MusicBrainz Picard" = MusicBrainz Picard "NVIDIA Drivers" = NVIDIA Drivers "Secunia PSI" = Secunia PSI (2.0.0.4003) "Semper Driver Backup_is1" = Semper Driver Backup "Speccy" = Speccy "SpywareBlaster_is1" = SpywareBlaster 4.6 "SugarSync" = SugarSync Manager "SynTPDeinstKey" = Synaptics Pointing Device Driver "VLC media player" = VLC media player 2.0.2 "Windows Essentials Media Codec Pack" = Windows Essentials Media Codec Pack 2.3d "WinLiveSuite" = Windows Live Essentials "ZhornStickies" = Stickies 7.0a [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "WavePad" = WavePad Sound Editor "WinDirStat" = WinDirStat 1.1.2 [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 16/11/2012 15:22:45 | Computer Name = FREESPIRIT-VS | Source = Windows Search Service | ID = 3058 Description = Error - 16/11/2012 16:25:24 | Computer Name = FREESPIRIT-VS | Source = VmbService | ID = 0 Description = conflictManagerTypeValue Error - 16/11/2012 16:25:41 | Computer Name = FREESPIRIT-VS | Source = ESENT | ID = 455 Description = Catalog Database (1620) Catalog Database: Error -1811 occurred while opening logfile C:\Windows\system32\CatRoot2\edb00178.log. Error - 16/11/2012 16:25:41 | Computer Name = FREESPIRIT-VS | Source = Microsoft-Windows-CAPI2 | ID = 131329 Description = Error - 17/11/2012 04:00:10 | Computer Name = FREESPIRIT-VS | Source = VmbService | ID = 0 Description = conflictManagerTypeValue Error - 17/11/2012 04:39:35 | Computer Name = FREESPIRIT-VS | Source = VmbService | ID = 0 Description = conflictManagerTypeValue Error - 17/11/2012 05:32:41 | Computer Name = FREESPIRIT-VS | Source = VmbService | ID = 0 Description = conflictManagerTypeValue Error - 31/05/2005 20:03:11 | Computer Name = FREESPIRIT-VS | Source = VmbService | ID = 0 Description = conflictManagerTypeValue Error - 18/11/2012 09:08:52 | Computer Name = FREESPIRIT-VS | Source = Windows Search Service | ID = 3006 Description = Error - 18/11/2012 09:08:52 | Computer Name = FREESPIRIT-VS | Source = Windows Search Service | ID = 3007 Description = Error - 18/11/2012 10:49:09 | Computer Name = FREESPIRIT-VS | Source = VmbService | ID = 0 Description = conflictManagerTypeValue [ OSession Events ] Error - 22/08/2010 01:39:01 | Computer Name = FREESPIRIT-VS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8 seconds with 0 seconds of active time. This session ended with a crash. Error - 01/09/2010 10:15:09 | Computer Name = FREESPIRIT-VS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 29 seconds with 0 seconds of active time. This session ended with a crash. Error - 13/09/2010 09:10:38 | Computer Name = FREESPIRIT-VS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 52 seconds with 0 seconds of active time. This session ended with a crash. Error - 26/09/2010 11:44:56 | Computer Name = FREESPIRIT-VS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8 seconds with 0 seconds of active time. This session ended with a crash. Error - 01/12/2010 09:29:53 | Computer Name = FREESPIRIT-VS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 32 seconds with 0 seconds of active time. This session ended with a crash. Error - 14/04/2011 13:05:32 | Computer Name = FREESPIRIT-VS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 22 seconds with 0 seconds of active time. This session ended with a crash. Error - 10/07/2011 08:47:32 | Computer Name = FREESPIRIT-VS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3211 seconds with 60 seconds of active time. This session ended with a crash. Error - 24/09/2011 14:50:24 | Computer Name = FREESPIRIT-VS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/11/2011 06:25:48 | Computer Name = FREESPIRIT-VS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 5548 seconds with 3780 seconds of active time. This session ended with a crash. Error - 03/04/2012 12:48:10 | Computer Name = FREESPIRIT-VS | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6612.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 16 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 18/11/2012 09:14:52 | Computer Name = FREESPIRIT-VS | Source = Service Control Manager | ID = 7000 Description = Error - 18/11/2012 09:16:22 | Computer Name = FREESPIRIT-VS | Source = Service Control Manager | ID = 7009 Description = Error - 18/11/2012 09:16:22 | Computer Name = FREESPIRIT-VS | Source = Service Control Manager | ID = 7000 Description = Error - 18/11/2012 09:33:31 | Computer Name = FREESPIRIT-VS | Source = Dhcp | ID = 1002 Description = The IP address lease 109.116.175.115 for the Network Card with network address 001E101F7FB6 has been denied by the DHCP server 109.112.142.193 (The DHCP Server sent a DHCPNACK message). Error - 18/11/2012 09:44:39 | Computer Name = FREESPIRIT-VS | Source = Dhcp | ID = 1002 Description = The IP address lease 109.114.82.201 for the Network Card with network address 001E101F1F81 has been denied by the DHCP server 31.26.199.33 (The DHCP Server sent a DHCPNACK message). Error - 18/11/2012 10:47:55 | Computer Name = FREESPIRIT-VS | Source = EventLog | ID = 6008 Description = The previous system shutdown at 15:43:40 on 18/11/2012 was unexpected. Error - 18/11/2012 10:49:08 | Computer Name = FREESPIRIT-VS | Source = Service Control Manager | ID = 7009 Description = Error - 18/11/2012 10:49:08 | Computer Name = FREESPIRIT-VS | Source = Service Control Manager | ID = 7000 Description = Error - 18/11/2012 10:50:20 | Computer Name = FREESPIRIT-VS | Source = Service Control Manager | ID = 7026 Description = Error - 18/11/2012 10:59:14 | Computer Name = FREESPIRIT-VS | Source = Dhcp | ID = 1002 Description = The IP address lease 109.116.176.82 for the Network Card with network address 001E101F8ED0 has been denied by the DHCP server 37.183.14.90 (The DHCP Server sent a DHCPNACK message). < End of report >