OTL Extras logfile created on: 5/11/2013 1:58:04 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\NXOS\Downloads 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16540) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 7.87 Gb Total Physical Memory | 3.10 Gb Available Physical Memory | 39.40% Memory free 15.87 Gb Paging File | 9.43 Gb Available in Paging File | 59.45% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 674.35 Gb Total Space | 220.20 Gb Free Space | 32.65% Space Free | Partition Type: NTFS Drive D: | 234.83 Gb Total Space | 213.55 Gb Free Space | 90.94% Space Free | Partition Type: NTFS Computer Name: XOS | User Name: NXOS | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-4194786825-1476187563-3098043754-1002\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0113C4EA-6016-4213-9A8E-394687AAF1E6}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{03218990-B1B8-41D8-9D61-957D54D82605}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{05FF0681-D04B-4B7D-AA03-1AAC40E0E6C0}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{0A9E621C-8A12-435B-8703-BD63C8BC46B5}" = rport=2869 | protocol=6 | dir=out | app=system | "{0DCA3F6B-FF1C-47E9-AF64-72C57AEFD0F1}" = lport=138 | protocol=17 | dir=in | app=system | "{1A5D39EF-1F9F-40C1-A66D-EA2BA93E7293}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{1D4B1580-F197-4D8C-9F09-7F69B536EC2E}" = rport=2869 | protocol=6 | dir=out | app=system | "{27967249-2E17-406E-8E77-65A3ACAFC4FC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{281F203E-BF3A-4E53-A128-D4C2CA46C46C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2C652F0C-7242-477E-9F24-211002DE53CC}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{37C9294D-0FD9-4472-8D35-449698BC238D}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{534A9971-666E-47BC-874C-A7CA1968A0A9}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{5D0673B9-A357-49FD-9507-508F055B45D4}" = lport=2869 | protocol=6 | dir=in | app=system | "{60D04A22-0DE5-423F-895A-91CD0E557C18}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{6887D91F-12CE-47F7-B16E-59AA9680D78D}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{6D7EF279-D6B9-459C-BBD9-B8758D36B959}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\dashost.exe | "{739071DB-00AD-4785-8922-35657EB84AD5}" = lport=139 | protocol=6 | dir=in | app=system | "{747ED84B-4D6B-497B-B2E8-BBBF0280E2F1}" = rport=445 | protocol=6 | dir=out | app=system | "{7583975F-2267-4977-BE78-06EA1B3CE061}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{76C1A5E8-6950-43A4-8062-501ED00E0F52}" = lport=2869 | protocol=6 | dir=in | app=system | "{7B798D52-F269-4958-8005-014205153E70}" = lport=445 | protocol=6 | dir=in | app=system | "{8350FD01-DBBC-4B5B-84C7-7708E6E6B59A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{8A298603-EE04-47A1-A028-38F50C2EC7AE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{977F06F5-84A5-4069-B090-2F8293CF72BF}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{A772CB89-3D4C-486B-B931-306996CDB048}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{A794EF56-6B18-467F-B041-EAF048D4038F}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{B7CC7D59-717E-441B-B395-F9C217B1F89C}" = rport=138 | protocol=17 | dir=out | app=system | "{BB913732-A0D7-4263-9FBD-26E61712541A}" = lport=137 | protocol=17 | dir=in | app=system | "{BFDC81F8-C514-41E6-A180-8C97A241FEE0}" = rport=2869 | protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{C0E783B6-4F97-43E1-A4C1-3D668631DD60}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C161FCFA-069A-4450-ADD4-B132FA37E27F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{C2EFF806-5A93-44BC-841A-B0AA516108F0}" = rport=139 | protocol=6 | dir=out | app=system | "{C477D382-50A0-4BFE-9887-480E9D1EE6E8}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{C86704B8-3E63-4B3E-8C4F-1004EDDEB212}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{D399114F-E9CB-42B3-B325-56A2E030669C}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{DA679A83-66F3-4AAB-9DE9-E6A2167D8311}" = rport=137 | protocol=17 | dir=out | app=system | "{E462C822-5413-4EEB-A8E2-4DD2DE67EE65}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{FA576337-4721-44B9-A92D-AD5BE291B91D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{FE42A06C-F69C-4138-80E1-691CBAF9213F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{03560ADA-9E5D-4357-8860-F51EFCCC5270}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{08E56720-5421-4DDE-A1E0-CA7E12257D47}" = dir=out | name=@{microsoft.zunevideo_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{0CFB86BF-7D44-4DE3-A526-BA4722772DF3}" = dir=in | app=c:\users\NXOS\appdata\local\facebook\video\skype\facebookvideocalling.exe | "{10EE2ED8-7510-4DBC-892F-B4BC1F68E459}" = dir=in | name=ebay | "{12298E26-1A4F-45E5-827A-C9D08088F6EC}" = protocol=17 | dir=in | app=c:\users\NXOS\appdata\local\temp\kmsnano\qemu-system-i386.exe | "{14091848-338C-4129-8520-2E31CD3A76A5}" = dir=out | name=mcafee security advisor for lenovo | "{15525355-B18F-400D-8B18-7F1D9A82BBAD}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{15B424A9-76C9-496E-8B5C-672D61079AE0}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{1F27B487-D05F-46DA-8591-8EAC0D44A2F6}" = dir=out | name=ebay | "{202DDCCD-0F0D-46CA-A17B-905F8A000F41}" = protocol=6 | dir=in | app=c:\program files (x86)\tango\tango.exe | "{21589371-7F00-4BC3-830D-114300A67BF9}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\panprocess.exe | "{23070C03-BDCE-48B4-9821-5377E8EEE9FE}" = dir=out | name=@{microsoft.bingfinance_1.5.1.406_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{27C7856F-94D0-4019-91EF-AF293D9122B2}" = dir=in | name=evernote | "{289EAF5E-E6F3-4C9B-98DA-2F12F138399C}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | "{2C3C3A42-725E-4595-802A-F19C75424D24}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{2FA37870-C74B-4EBF-BF14-CFA371F5F982}" = dir=out | name=@{microsoft.bingnews_1.5.1.409_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{3103F336-7E03-4DDD-A52A-4C1E55670F37}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{31EF9A3C-D31C-4361-99BA-0626666DC08E}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{32AEAC25-CD72-48CF-AC84-660D5C1A4B6E}" = dir=out | name=mcafee security advisor for lenovo | "{3458C678-21F9-4E21-988E-0D560525F9FA}" = dir=in | app=c:\program files (x86)\lenovo\powerdvd10\powerdvd10.exe | "{361BE238-36D2-457F-A3B1-3761ADA08048}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{3830F7FF-F718-49D8-AEDB-EF5292850D2C}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{3976DD2B-B27A-4AA4-AD46-369D5D0EE449}" = dir=in | name=evernote | "{4118AE9F-A3AE-4A2B-8B83-C2A4F8CF5AA7}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{425F7D36-D6DC-4E65-AA17-DE89D1605CA3}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{4516BA65-7429-4C3B-A354-4342E4C7F0B3}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{452CFA1B-29C2-4B90-8BBC-4C74363BEA3D}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{48AC0410-872A-4151-8233-35E27B2C6DE7}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{48DEA070-7762-49FC-92D1-FA79886BC850}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | "{49AC353C-18C3-4FCB-84B3-C25E25199B98}" = dir=out | name=lenovo companion | "{4E7CCCD3-C63C-4EEB-A24C-D3CB687FFFC5}" = dir=in | name=@{microsoft.reader_6.2.9200.20523_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{51D62640-78AB-47E5-A657-015F787089A9}" = dir=out | name=lenovo support | "{5452A927-A5D9-4EB8-A9E7-51FC3F2A69A7}" = dir=in | name=ebay | "{56EF867B-94ED-45D9-918F-F715B24870FD}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe | "{61A31A6C-8FE1-49C5-BC25-6C1A313C0B82}" = dir=out | name=@{microsoft.bingtravel_1.5.1.248_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{6435C00A-020B-41B9-BC6F-9213E11C25F3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{66B77266-1243-431A-92E1-21828382CEBD}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{6858BE11-F591-4096-94CC-CE73E28A00C9}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | "{6AA02750-B265-4F5F-ACAE-4A029756E717}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4396.1016_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{6AA64676-F082-41B9-B2C0-CF66C1EE644C}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{6AB20692-117C-4CDF-AB9F-9B6C7EFE1B9D}" = protocol=6 | dir=in | app=c:\users\NXOS\appdata\local\temp\kmsnano\qemu-system-i386.exe | "{6AEBF51F-5F29-4B0E-A550-BC41EE8DC6AD}" = dir=out | name=evernote | "{6D7FDDD3-EA34-4647-923B-139A482C2FE9}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe | "{6F24C392-B0A7-476F-B84F-EB739E1DD265}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4396.1016_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{6F4474EE-A94A-4B75-AAE5-BBDEBC8EF3DD}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{710A1FA4-972F-406C-BFC5-175FD602E448}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{721AA0B9-A3CB-44D7-9D08-7D799966D533}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "{752A068D-FEDA-45D2-BB21-B209D042B02C}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{78D4083A-153C-4C6F-AF80-BEFF1D59EDC5}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe | "{7D993B00-7007-4BE5-94F8-A2C2C008DE13}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{831503D6-CD86-4DAA-9D63-376919C2C368}" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe | "{83DA4DD9-91C6-48BB-BEFB-8A885C19D4D5}" = dir=in | app=c:\program files (x86)\lenovo\powerdvd10\powerdvd cinema\powerdvdcinema10.exe | "{8691A568-BDA6-43F1-B77A-26B097E05C8F}" = protocol=6 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe | "{88275462-0AF0-468E-B2E8-6A1E4FE4F49D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{8B463980-9B3A-4AAE-8E76-4AE614DB623D}" = dir=out | name=skype | "{8B67C530-A720-447A-9DB1-72BE03C0B522}" = dir=out | name=accuweather for windows 8 | "{8CA08143-CF04-4506-BFE4-21208E076BD6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{907999D6-B947-455A-B9D4-55CB82BD30D4}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{90D14F8C-5E61-4DED-B135-B7258060511A}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{92E64170-7F9F-4F8F-8783-C1D860679187}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{995076D6-4280-42F3-865D-7BC86BA96228}" = dir=out | name=@{microsoft.zunemusic_1.1.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{9B0907D2-C76F-459C-A726-140A6376BC48}" = protocol=17 | dir=in | app=c:\program files (x86)\tango\tango.exe | "{9C59EF74-F56E-47D1-AA3E-84933B453E4B}" = dir=out | name=@{microsoft.bingmaps_1.5.1.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{9F7E6188-A256-4D36-AFCB-23223841A154}" = dir=in | name=skype | "{9FF10D4B-5F56-4B4C-8DFF-C417D8007CB2}" = dir=out | name=@{microsoft.bing_1.5.1.251_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{A013F819-251C-4B8C-A42A-AF2AFF518F71}" = dir=out | name=lenovo support | "{A33D4873-C6B6-4FA2-B436-62F758DFB6D3}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe | "{A5B38BBD-512D-4903-A215-8171175E8312}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{A7E1B4EE-45B0-46BC-9E41-31D5CD8034B1}" = protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectify.exe | "{B16DD7A0-5C43-477A-9927-A19A60405C95}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{B7564CBA-2CC6-4E16-A8B9-4A19EC77E38B}" = dir=out | name=accuweather for windows 8 | "{B7F37D93-90DB-4BC5-B899-F5D3E4DCD3E3}" = dir=out | name=powerdvd for lenovo idea | "{BACE241F-03E6-47B4-98FD-98E6DC0036A8}" = dir=out | name=@{microsoft.reader_6.2.9200.20523_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{BB2B22D9-DA7C-4E54-B8A2-9899404CAA4E}" = protocol=6 | dir=in | app=c:\program files (x86)\connectify\connectify.exe | "{BCB1C89E-8D1A-47FD-A610-9A60E5B51876}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{BF8C25A2-C9A6-4579-8C54-ED19C532AF57}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{C159356D-2363-41A3-B08A-75F0FDC4D68D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{C1B10CA6-6C6D-4C8F-841D-C446A6D18EE3}" = dir=out | name=ebay | "{C23923EB-AF14-4362-9FED-DADBBA85CB4D}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{C2FB9C7C-E2FB-4B75-AF9B-C9043F2BA950}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{C5D1FDA3-6DE5-446F-8269-2C9B69758523}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{C6DD3E16-979F-4675-B40A-7CB115E016F6}" = dir=out | name=@{microsoft.bingweather_1.5.1.245_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{CA1047E5-57A4-4B7B-B062-A97C36F5F70F}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "{CD1EB415-3210-42EC-8A5A-3E2F3D0F869F}" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe | "{D1266A06-BA05-4CAC-81E4-EBBD4303C532}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | "{D416816F-85FA-4605-8AF7-5EA52AC53771}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{D4264A89-3627-4B10-8851-C7ABC1A4AE8A}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{D5AE1E78-26EE-45CE-BD1D-629FAF4C8AF5}" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe | "{D643E5A6-B354-402B-9A38-E31500D397E3}" = dir=out | name=evernote | "{D6670387-FA04-4B6F-B9AA-0E484B37790B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{D7465A22-C9BF-410E-B7F2-2FF77F15878E}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{D8F3C44C-52CD-4381-8B44-6F02B117EBE6}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{DB3DE57C-2D9B-49B3-8203-35E5F19713BD}" = dir=out | name=@{microsoft.bingsports_1.5.1.249_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{DC5261B3-F7AE-40DF-AB09-1D0F722016B6}" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe | "{DCB0042B-A1AA-4117-9ED0-B82D42360D50}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{DD19D124-FCFD-4B10-A56A-BCFFAE43B90A}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{DD443700-17A9-4F60-AF0C-C95E86352FBF}" = dir=in | name=@{microsoft.skypeapp_1.1.0.25_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{DE524813-C6F7-4BCD-80AE-3D249EA30B98}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{DF84DEBF-79DD-48AA-853B-EBA28BFFEC44}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\pandoraservice.exe | "{DFDA208D-D75F-479F-9FC0-0BCB34604007}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{E2D2726E-4D35-4D72-92F1-CB4C416483DF}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{E300AB2E-1155-436F-B7D0-FE32BD988E18}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{E56132AA-FCDD-4CE1-85DA-5BA6883614B0}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{E7E23AC1-CCC1-4534-B1D4-EF79CD35DD52}" = dir=out | name=@{microsoft.skypeapp_1.1.0.25_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{E9A51DFE-6D49-42D8-A42E-246BD5337A0D}" = protocol=17 | dir=in | app=c:\program files (x86)\pandora.tv\panservice\panprocess.exe | "{EF0B4B08-18E4-4326-81B3-D4E85437E915}" = dir=out | name=lenovo companion | "{F21B171A-00BA-426B-A41F-79716C546008}" = dir=out | name=@{microsoft.xboxlivegames_1.1.134.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{F4F10874-BD11-48BC-A2AF-DCFC5087EDE4}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{F4FD0950-FBD6-48C1-BA4B-E546100252E1}" = dir=out | name=google search | "{FA38778A-0967-477C-BA1D-CCB58A6FFC54}" = dir=out | name=windows_ie_ac_001 | "{FFE3A3BF-04F3-41D0-A4C9-F0A3FDF7B36A}" = dir=out | name=powerdvd for lenovo idea | "TCP Query User{0AE9CCC3-35B8-489C-A8C2-766265196249}C:\program files\gns3\dynamips.exe" = protocol=6 | dir=in | app=c:\program files\gns3\dynamips.exe | "TCP Query User{23051B97-33A9-463C-A769-2DB52140B971}C:\program files\oracle\virtualbox\virtualbox.exe" = protocol=6 | dir=in | app=c:\program files\oracle\virtualbox\virtualbox.exe | "TCP Query User{703417BB-1336-4881-BFD2-1E3C454D4ED1}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | "TCP Query User{9EDB17EA-D506-4B22-9406-634D2D02D76A}C:\program files\gns3\qemu.exe" = protocol=6 | dir=in | app=c:\program files\gns3\qemu.exe | "TCP Query User{EDF65027-67F5-4407-B6FF-DF9889E15D28}C:\program files (x86)\connectify\connectify.exe" = protocol=6 | dir=in | app=c:\program files (x86)\connectify\connectify.exe | "UDP Query User{5A521EB1-73AF-4D9E-AD6C-3AF24B1B2213}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | "UDP Query User{A916E078-52B7-4010-87B5-30A549E06BD0}C:\program files\gns3\dynamips.exe" = protocol=17 | dir=in | app=c:\program files\gns3\dynamips.exe | "UDP Query User{B5C91A87-B9DA-4F15-9DF7-3A55D0DFD5A6}C:\program files (x86)\connectify\connectify.exe" = protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectify.exe | "UDP Query User{B61686F4-21FC-443C-8429-902FCC52F436}C:\program files\gns3\qemu.exe" = protocol=17 | dir=in | app=c:\program files\gns3\qemu.exe | "UDP Query User{BCE6AFB0-0A33-48FA-8E3A-92CF6CBC8C2E}C:\program files\oracle\virtualbox\virtualbox.exe" = protocol=17 | dir=in | app=c:\program files\oracle\virtualbox\virtualbox.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}" = VMware Workstation "{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{2329D187-A58A-4395-8B6E-791A312667AF}" = Lenovo Solution Center "{2698AD3E-EF23-46E6-B084-A40239D719F5}" = VanDyke Software SecureCRT 7.0 "{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007 "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 "{A8A0B1C1-FBC7-4790-8E26-9DA1A6A95452}" = Oracle VM VirtualBox 4.2.6 "{B0A5A6EE-F8BA-48B1-BB32-BAC17E96C2B4}" = Microsoft Visual J# 2.0 Redistributable Package - SE (x64) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 306.97 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 306.97 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0613 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}" = Lenovo Bluetooth with Enhanced Data Rate Software "{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support "{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64 "{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client "71BC3FD63F450BA0A957AAECBDB4A000C4F2BE42" = Windows Driver Package - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) "8A223E56FB1ED4F697B54E5BF96F1EB63B512684" = Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) "CNXT_AUDIO_HDA" = Conexant HD Audio "Microsoft Visual J# 2.0 Redistributable Package - SE (x64)" = Microsoft Visual J# 2.0 Redistributable Package - SE (x64) "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = WinRAR 4.20 (64-bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam "{09DC364B-A77A-49A0-972B-E43F0DACC5E3}" = VMware vSphere Client 5.1 "{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR "{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5 "{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0 "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3 "{560985FB-4B76-4121-9189-7A2CDC7886D6}" = Kaspersky Internet Security 2013 "{5D642A72-8194-4A22-80DA-11FE610CCA8E}" = Lenovo_Wireless_Driver "{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}" = NVIDIA PhysX "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{8E9832A9-1F37-4BB2-ABEF-EE254D53D1D2}" = WebEx Recorder and Player "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris "{AC76BA86-1033-FFFF-7760-000000000006}" = Adobe Acrobat XI Pro "{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}" = Lenovo EasyCamera "{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k "{B49874A9-4D85-44B7-AB84-B51D33160167}" = Cisco IPS Manager Express "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287 "{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}" = Dolby Advanced Audio v2 "{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support "{CCF298AF-9CE1-4B26-B251-486E98A34789}" = Windows 7 USB/DVD Download Tool "{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management "{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux "{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = Lenovo PowerDVD10 "{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = UserGuide "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F3FDA09C-57AA-40CC-A555-FED7EF421E7E}" = Angry Birds Seasons "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package "{FDA24BB0-8462-4356-B30E-C74FDC25C6DF}" = Network Recording Player "{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Babylon" = Babylon "BitTorrent" = BitTorrent "ENTERPRISE" = Microsoft Office Enterprise 2007 "FileZilla Server" = FileZilla Server "Free YouTube Download_is1" = Free YouTube Download version 3.1.42.1212 "GNS3" = GNS3 0.8.3.1 "Google Chrome" = Google Chrome "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam "InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery "InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management "InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = Lenovo PowerDVD10 "InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = UserGuide "InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}" = Kaspersky Internet Security 2013 "KLiteCodecPack_is1" = K-Lite Codec Pack 4.0.0 (Full) "Mozilla Firefox 18.0 (x86 en-US)" = Mozilla Firefox 18.0 (x86 en-US) "MozillaMaintenanceService" = Mozilla Maintenance Service "PowerISO" = PowerISO "PumpKIN" = Klever PumpKIN 2.7.2 "Subway Surfers 1.0" = Subway Surfers 1.0 "TeamViewer 8" = TeamViewer 8 "Visual CertExam Suite_is1" = Visual CertExam Suite "VLC media player" = VLC media player 2.0.5 "VMware_Workstation" = VMware Workstation "WinPcapInst" = WinPcap 4.1.2 "Wireshark" = Wireshark 1.6.8 (32-bit) "Yahoo! Messenger" = Yahoo! Messenger "Yahoo! Software Update" = Yahoo! Software Update [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-4194786825-1476187563-3098043754-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only) "Tango" = Tango "Windows Essentials Codec Pack Packages" = Windows Essentials Codec Pack Packages [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 4/14/2013 10:39:25 AM | Computer Name = XOS | Source = Application Error | ID = 1000 Description = Faulting application name: iexplore.exe, version: 10.0.9200.16537, time stamp: 0x5123410e Faulting module name: DefaultTabWrap64.dll, version: 1.3.2.0, time stamp: 0x510bf548 Exception code: 0xc0000005 Fault offset: 0x0000000000023b80 Faulting process id: 0x14d4 Faulting application start time: 0x01ce391dda5662c9 Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Users\NXOS\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap64.dll Report Id: 1a3dfd96-a511-11e2-beb6-e41b46d84b25 Faulting package full name: Faulting package-relative application ID: Error - 4/14/2013 10:39:50 AM | Computer Name = XOS | Source = Application Error | ID = 1000 Description = Faulting application name: iexplore.exe, version: 10.0.9200.16537, time stamp: 0x5123410e Faulting module name: DefaultTabWrap64.dll, version: 1.3.2.0, time stamp: 0x510bf548 Exception code: 0xc0000005 Fault offset: 0x0000000000023b80 Faulting process id: 0x1968 Faulting application start time: 0x01ce391dea98efb1 Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Users\NXOS\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap64.dll Report Id: 28c60d44-a511-11e2-beb6-e41b46d84b25 Faulting package full name: Faulting package-relative application ID: Error - 4/14/2013 5:34:16 PM | Computer Name = XOS | Source = Application Hang | ID = 1002 Description = The program ime.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1fd4 Start Time: 01ce395777613530 Termination Time: 4294967295 Application Path: C:\Program Files (x86)\Cisco Systems\Cisco IPS Manager Express\ime.exe Report Id: 0dd2be44-a54b-11e2-beb7-bf7ee6f1931c Faulting package full name: Faulting package-relative application ID: Error - 4/14/2013 5:46:28 PM | Computer Name = XOS | Source = Application Error | ID = 1000 Description = Faulting application name: iexplore.exe, version: 10.0.9200.16537, time stamp: 0x5123410e Faulting module name: DefaultTabWrap64.dll, version: 1.3.2.0, time stamp: 0x510bf548 Exception code: 0xc0000005 Fault offset: 0x0000000000023b80 Faulting process id: 0x2084 Faulting application start time: 0x01ce395982f03d6a Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Users\NXOS\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap64.dll Report Id: c2b5da91-a54c-11e2-beb7-bf7ee6f1931c Faulting package full name: Faulting package-relative application ID: Error - 4/14/2013 5:46:53 PM | Computer Name = XOS | Source = Application Error | ID = 1000 Description = Faulting application name: iexplore.exe, version: 10.0.9200.16537, time stamp: 0x5123410e Faulting module name: DefaultTabWrap64.dll, version: 1.3.2.0, time stamp: 0x510bf548 Exception code: 0xc0000005 Fault offset: 0x0000000000023b80 Faulting process id: 0x1dcc Faulting application start time: 0x01ce39599307e3eb Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Users\NXOS\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap64.dll Report Id: d12e304f-a54c-11e2-beb7-bf7ee6f1931c Faulting package full name: Faulting package-relative application ID: Error - 4/14/2013 6:35:30 PM | Computer Name = XOS | Source = Application Hang | ID = 1002 Description = The program Explorer.EXE version 6.2.9200.16433 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: fc8 Start Time: 01ce39602a901762 Termination Time: 0 Application Path: C:\windows\Explorer.EXE Report Id: 8d37dc0d-a553-11e2-beb8-e327afa45daa Faulting package full name: Faulting package-relative application ID: Error - 4/14/2013 6:41:05 PM | Computer Name = XOS | Source = Google Update | ID = 20 Description = Error - 4/14/2013 8:47:37 PM | Computer Name = XOS | Source = Application Error | ID = 1000 Description = Faulting application name: vmware-vmrc.exe, version: 8.0.0.20447, time stamp: 0x5000cb95 Faulting module name: vmwarecui.dll, version: 8.0.0.20447, time stamp: 0x5000ca42 Exception code: 0xc0000005 Fault offset: 0x002f7a73 Faulting process id: 0xbfc Faulting application start time: 0x01ce396e7481b01c Faulting application path: C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.1\Internet Explorer\vmware-vmrc.exe Faulting module path: C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.1\Internet Explorer\vmwarecui.dll Report Id: 11233634-a566-11e2-beb9-9a103de8ed4c Faulting package full name: Faulting package-relative application ID: Error - 4/15/2013 5:18:17 AM | Computer Name = XOS | Source = Application Error | ID = 1000 Description = Faulting application name: vmware-vmrc.exe, version: 8.0.0.20447, time stamp: 0x5000cb95 Faulting module name: vmwarecui.dll, version: 8.0.0.20447, time stamp: 0x5000ca42 Exception code: 0xc0000005 Fault offset: 0x002f7a73 Faulting process id: 0x1ecc Faulting application start time: 0x01ce39b9619eef91 Faulting application path: C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.1\Internet Explorer\vmware-vmrc.exe Faulting module path: C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.1\Internet Explorer\vmwarecui.dll Report Id: 68160aee-a5ad-11e2-beb9-9a103de8ed4c Faulting package full name: Faulting package-relative application ID: Error - 4/15/2013 7:37:54 AM | Computer Name = XOS | Source = Application Error | ID = 1000 Description = Faulting application name: vmware-vmrc.exe, version: 8.0.0.20447, time stamp: 0x5000cb95 Faulting module name: vmwarecui.dll, version: 8.0.0.20447, time stamp: 0x5000ca42 Exception code: 0xc0000005 Fault offset: 0x002f7a73 Faulting process id: 0x2720 Faulting application start time: 0x01ce39cd53a73b3f Faulting application path: C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.1\Internet Explorer\vmware-vmrc.exe Faulting module path: C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.1\Internet Explorer\vmwarecui.dll Report Id: e90a960b-a5c0-11e2-beb9-9a103de8ed4c Faulting package full name: Faulting package-relative application ID: [ System Events ] Error - 5/2/2013 11:56:25 AM | Computer Name = XOS | Source = Schannel | ID = 36888 Description = A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 51. The Windows SChannel error state is 900. Error - 5/2/2013 12:02:09 PM | Computer Name = XOS | Source = Schannel | ID = 36888 Description = A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 51. The Windows SChannel error state is 900. Error - 5/2/2013 12:23:49 PM | Computer Name = XOS | Source = Schannel | ID = 36888 Description = A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 51. The Windows SChannel error state is 900. Error - 5/2/2013 12:29:29 PM | Computer Name = XOS | Source = Schannel | ID = 36888 Description = A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 51. The Windows SChannel error state is 900. Error - 5/2/2013 12:34:54 PM | Computer Name = XOS | Source = Schannel | ID = 36888 Description = A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 51. The Windows SChannel error state is 900. Error - 5/2/2013 5:16:31 PM | Computer Name = XOS | Source = DCOM | ID = 10010 Description = Error - 5/2/2013 5:16:31 PM | Computer Name = XOS | Source = DCOM | ID = 10010 Description = Error - 5/3/2013 4:34:55 AM | Computer Name = XOS | Source = DCOM | ID = 10010 Description = Error - 5/3/2013 11:14:32 AM | Computer Name = XOS | Source = DCOM | ID = 10010 Description = Error - 5/3/2013 6:23:06 PM | Computer Name = XOS | Source = DCOM | ID = 10010 Description = < End of report >