OTL Extras logfile created on: 7/13/2013 1:49:48 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Belinda\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16635) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.91 Gb Total Physical Memory | 2.29 Gb Available Physical Memory | 58.67% Memory free 7.82 Gb Paging File | 5.67 Gb Available in Paging File | 72.58% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 452.47 Gb Total Space | 383.46 Gb Free Space | 84.75% Space Free | Partition Type: NTFS Computer Name: BELINDA-PC | User Name: Belinda | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02303E89-92FC-4A21-8023-328034254A0C}" = lport=2869 | protocol=6 | dir=in | app=system | "{0B8AE602-2803-4E6E-A5D2-DE754393401F}" = rport=139 | protocol=6 | dir=out | app=system | "{11411372-4E5E-4A66-9D45-A234FEA1B5F4}" = lport=445 | protocol=6 | dir=in | app=system | "{1DAC6E2F-8241-4B26-8600-1CBF4D4CB3CA}" = lport=138 | protocol=17 | dir=in | app=system | "{1ECB1492-767B-4184-A31B-0EA972501810}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{20B7B992-8E49-4A92-96EB-77ECA16F8C99}" = rport=445 | protocol=6 | dir=out | app=system | "{3071F07D-B82C-4DBF-9033-937E2319C1FD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{378DCBFB-0A3D-4CAE-A858-C9B06A1EA5A1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{3EB1DD97-E5F5-47A5-A069-25819815D665}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{4141494D-A188-478A-9033-253C3E13371F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{53D8B569-FA26-4813-893C-5AFF0422904F}" = rport=10243 | protocol=6 | dir=out | app=system | "{64661C00-0416-49EA-851F-DF6D0D65263A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{6554BE4A-4689-4995-AC63-3D5955298718}" = lport=10243 | protocol=6 | dir=in | app=system | "{754B17B0-E152-4870-9A86-F86DFF5A8ACD}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{77915F37-5087-4841-9219-45D3E8FDE076}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{91DD773A-39DA-40AE-8523-160E72A71FBD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{ADB04CDA-F001-4C56-AF1A-9153337A3059}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{AEB65FF2-D8D6-4F41-A4A7-6DEF36C5E46A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{B9B81D54-68B2-4CE7-8882-A5BF4FD9F789}" = lport=139 | protocol=6 | dir=in | app=system | "{BBCDC99F-7AB2-4125-8D8D-793CEE8A110F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{BDA6D6A2-3F2C-486F-A6A4-9319F41ABE3E}" = rport=137 | protocol=17 | dir=out | app=system | "{CFE074E6-032C-44B8-9CCE-FCD56D5EA7B6}" = rport=138 | protocol=17 | dir=out | app=system | "{DFBD4ECC-E4AF-4F50-A5F9-905A983AA1B4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{EEC99DFA-BF8A-4861-97B6-D96AB5A3A1F4}" = lport=137 | protocol=17 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0710DFD3-4416-4588-B40E-FEDB9281247F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{29A8B32C-C873-497B-8C0E-67F78D450AC6}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{2A3088A2-3C08-4CFD-B9DF-2B289A6B7CA6}" = protocol=6 | dir=out | app=system | "{2C534F7A-EFA1-4B3A-8422-256B3C1BAE56}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{32D06D19-82E9-4363-BC60-56FB6A5F5EB6}" = protocol=17 | dir=in | app=c:\program files (x86)\mcafee\common framework\frameworkservice.exe | "{3472523B-ED24-4F7D-A5CC-32C4CDFE664D}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | "{3B791489-BD64-4262-AA81-C09906C5513B}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3BEE0A2C-5987-4782-A151-D9491896967E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{48FA0375-BDB2-424D-A528-64C0C939E50A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{491F9D1B-4BF6-4508-A8A9-53E46DCA2564}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{49218AB3-5180-44FC-A4A8-EB99C0D0FB99}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{58A2DE13-4F72-45F4-822D-3E8C648045D3}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{62D5C583-8F76-44F9-97F3-6E9A3FFC3D2E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{672E7184-910E-4D70-BF2B-8CA1AB8C8978}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{681E06C7-6172-4473-8C11-D79B424E725C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{7544C778-6B57-410D-A70A-343FDE960EDB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{83B1AF80-DDE4-4367-AC32-D67094A360F1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8B2B4EEA-B3B2-4450-B26A-A66C397BC75F}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{8D8D01ED-FCF5-4B85-94A1-34865CA599C4}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{9B1F4633-D42A-4A22-9926-0854A934CC79}" = protocol=6 | dir=in | app=c:\program files (x86)\mcafee\common framework\frameworkservice.exe | "{9B98D248-4802-4E6A-A8E7-EE1E57753C4D}" = protocol=6 | dir=in | app=c:\program files (x86)\mcafee\common framework\frameworkservice.exe | "{A11BF605-A9CD-463C-9FD7-6CAC391723C0}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{A91495E9-5805-4057-9C56-C3B33FC307AF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{AA5F9919-9CAF-44CD-BF8C-C48C4F279D32}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{AC8F367D-F300-44C9-97A3-26AE63F485DE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{B01FC24D-1B4A-4FD9-9B91-D178D49B288B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{B15F64F0-B429-408F-86F1-CD4FB517AABC}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{BFBAF2E1-433F-4EF9-B755-1CD6068E301C}" = protocol=17 | dir=in | app=c:\program files (x86)\mcafee\common framework\frameworkservice.exe | "{CA8709ED-CB19-426C-954A-DDBC47BEB243}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{D473A0DF-939B-42A4-BF84-7B8AED0AE6FB}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{EB371659-3736-486A-A1F9-8152A0AA476A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{EFA0161F-4171-4258-B160-6E95E5B110C4}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{F02C0131-E405-4696-B2C7-0A59E93C7EAB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{FC24D90D-355E-4E3D-B3C3-80EE7C5EA5E1}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{FFBCDE62-34B2-41B1-A2C8-F5DA0B0F671B}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "TCP Query User{0668E15C-6A2F-4166-B087-FB673D043548}C:\program files (x86)\lenovoemc storage manager\lenovoemcstoragemanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\lenovoemc storage manager\lenovoemcstoragemanager.exe | "TCP Query User{A2D4482D-B97A-4D4D-B463-3D0C3647623E}C:\program files (x86)\lenovoemc storage manager\lenovoemcstoragemanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\lenovoemc storage manager\lenovoemcstoragemanager.exe | "TCP Query User{E684FF50-0D3D-4661-AE74-5A7D2B5D0E8B}C:\program files\iomega\quikprotect\quikprotect.exe" = protocol=6 | dir=in | app=c:\program files\iomega\quikprotect\quikprotect.exe | "TCP Query User{E7D8EE7A-DD28-40CB-9802-6B1D98B41B8F}C:\program files (x86)\iomega storage manager\iomegastoragemanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\iomega storage manager\iomegastoragemanager.exe | "UDP Query User{485AB5A4-73ED-4BC5-9F98-DB0BAAA69F2B}C:\program files (x86)\lenovoemc storage manager\lenovoemcstoragemanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\lenovoemc storage manager\lenovoemcstoragemanager.exe | "UDP Query User{8E5BEFB7-DEC4-4538-BD5B-CF6B560C3805}C:\program files\iomega\quikprotect\quikprotect.exe" = protocol=17 | dir=in | app=c:\program files\iomega\quikprotect\quikprotect.exe | "UDP Query User{A4B4B356-08D0-4CDD-84F9-20D98403895A}C:\program files (x86)\lenovoemc storage manager\lenovoemcstoragemanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\lenovoemc storage manager\lenovoemcstoragemanager.exe | "UDP Query User{CC166EFB-4266-4E9B-968A-059D09CE4A23}C:\program files (x86)\iomega storage manager\iomegastoragemanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\iomega storage manager\iomegastoragemanager.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes "{295AEB79-B53A-4F1B-860F-7800BB7E3681}" = Intel(R) PROSet/Wireless WiFi Software "{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support "{3015F546-6C3E-4E6A-B564-BCDF88C0BA2A}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{76FF0F03-B707-4332-B5D1-A56C8303514E}" = iTunes "{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007 "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad "{B53FA0E4-739C-435F-9872-E3032F2E08FC}" = Iomega QuikProtect (64-Bit) "{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = Intel(R) Turbo Boost Technology Monitor 2.0 "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "LenovoEMC Storage Manager" = LenovoEMC Storage Manager "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "ProInst" = Intel PROSet Wireless [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{023D64D7-E7B4-47C7-BE6E-B7C2E8960D08}" = Citrix online plug-in (Web) "{1D9C5B1D-A090-CFEE-2615-016591D035C8}" = Picaboo Desktop "{2AAB21C2-4CDA-4189-A0EC-5ED666113F84}" = McAfee Agent "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.5 "{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support "{6F8EAC65-314D-4D86-9557-BC9312AACCB0}" = Citrix online plug-in (USB) "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{8144262B-25B4-44F6-8204-FCC8EF50179F}" = Citrix online plug-in (DV) "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90FF23FE-0E1B-40DF-A22E-B4C0372E5936}" = Iomega Product Registration "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A0087DDE-69D0-11E2-AD57-43CA6188709B}" = Adobe AIR "{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch "{CE15D1B6-19B6-4D4D-8F43-CF5D2C3356FF}" = McAfee VirusScan Enterprise "{EA74A293-3FAC-4D1B-AE3A-3BD47FADDC20}" = Citrix online plug-in (HDX) "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "CitrixOnlinePluginPackWeb" = Citrix online plug-in - web "com.picaboo.Picaboo.A382D4714709B456C4E0088DFC1F7243AF9EBF75.1" = Picaboo Desktop "Dell Webcam Central" = Dell Webcam Central "ENTERPRISE" = Microsoft Office Enterprise 2007 "ESET Online Scanner" = ESET Online Scanner v3 "Iomega Storage Manager" = Iomega Storage Manager "Juniper Network Connect 7.1.0" = Juniper Networks Network Connect 7.1.0 "Juniper_Setup_Client Activex Control" = Juniper Networks, Inc. Setup Client Activex Control "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300 "ProInst" = Intel PROSet Wireless [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Juniper_Setup_Client" = Juniper Networks, Inc. Setup Client [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 7/12/2013 2:46:18 PM | Computer Name = Belinda-PC | Source = McLogEvent | ID = 5051 Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe took longer than 90000 ms to complete a request. The process will be terminated. Thread id : 2824 (0xb08) Thread address : 0x00000000777F137A Thread message : Build VSCORE.14.3.0.464 / 5400.1158 Object being scanned = \Device\HarddiskVolume3\Program Files (x86)\McAfee\VirusScan Enterprise by C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe 17018(0)(0) 17017(0)(3) 7007(0)(0) 5006(0)(0) 5004(0)(0) 5003(0)(0) 5002(0)(1) 15002(0)(0) Error - 7/12/2013 2:56:00 PM | Computer Name = Belinda-PC | Source = McLogEvent | ID = 5051 Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe took longer than 90000 ms to complete a request. The process will be terminated. Thread id : 2396 (0x95c) Thread address : 0x00000000777F138A Thread message : Build VSCORE.14.3.0.464 / 5400.1158 Object being scanned = \Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.17803_none_28c0629c4da7ae41\journal.dll by C:\Windows\system32\svchost.exe 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0) Error - 7/12/2013 3:01:30 PM | Computer Name = Belinda-PC | Source = McLogEvent | ID = 5051 Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe took longer than 90000 ms to complete a request. The process will be terminated. Thread id : 6024 (0x1788) Thread address : 0x00000000777F138A Thread message : Build VSCORE.14.3.0.464 / 5400.1158 Object being scanned = \Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7601.21955_none_2915f05f66ec0c6e\journal.dll by C:\Windows\system32\svchost.exe 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0) Error - 7/12/2013 3:08:47 PM | Computer Name = Belinda-PC | Source = McLogEvent | ID = 5051 Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe took longer than 90000 ms to complete a request. The process will be terminated. Thread id : 492 (0x1ec) Thread address : 0x00000000777F138A Thread message : Build VSCORE.14.3.0.464 / 5400.1158 Object being scanned = \Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7600.21179_none_271dcae569d273db\journal.dll by C:\Windows\system32\svchost.exe 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0) Error - 7/12/2013 3:24:13 PM | Computer Name = Belinda-PC | Source = McLogEvent | ID = 5051 Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe took longer than 90000 ms to complete a request. The process will be terminated. Thread id : 5168 (0x1430) Thread address : 0x000007FEFF8E11BE Thread message : Build VSCORE.14.3.0.464 / 5400.1158 Object being scanned = \Device\HarddiskVolume3\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe by E:\OTL.exe 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0) Error - 7/12/2013 3:44:47 PM | Computer Name = Belinda-PC | Source = Application Hang | ID = 1002 Description = The program notepad.exe version 6.1.7600.16385 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 544 Start Time: 01ce7f3777e89754 Termination Time: 0 Application Path: C:\Windows\SysWOW64\notepad.exe Report Id: 303658be-eb2b-11e2-b580-bc77373f6acd Error - 7/12/2013 4:01:00 PM | Computer Name = Belinda-PC | Source = Application Hang | ID = 1002 Description = The program OTL.com version 3.2.69.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 15ac Start Time: 01ce7f39e2771e92 Termination Time: 16 Application Path: E:\OTL.com Report Id: c3451e4b-eb2d-11e2-b580-bc77373f6acd Error - 7/12/2013 4:15:47 PM | Computer Name = Belinda-PC | Source = Application Hang | ID = 1002 Description = The program mbam.exe version 1.75.0.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: c38 Start Time: 01ce7f3992d33487 Termination Time: 16 Application Path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe Report Id: Error - 7/12/2013 6:28:58 PM | Computer Name = Belinda-PC | Source = Application Error | ID = 1000 Description = Faulting application name: svchost.exe_WinDefend, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1 Faulting module name: mpengine.dll, version: 1.1.9302.0, time stamp: 0x5142bd22 Exception code: 0xc0000006 Fault offset: 0x000000000004f940 Faulting process id: 0xa70 Faulting application start time: 0x01ce7f2d39f3e046 Faulting application path: C:\Windows\System32\svchost.exe Faulting module path: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8355C2D8-9158-4C3C-A29C-ECA7F7EE75D6}\mpengine.dll Report Id: 717059c2-eb42-11e2-b580-bc77373f6acd Error - 7/12/2013 6:29:16 PM | Computer Name = Belinda-PC | Source = Application Error | ID = 1005 Description = Windows cannot access the file C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8355C2D8-9158-4C3C-A29C-ECA7F7EE75D6}\mpengine.dll for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program Host Process for Windows Services because of this error. Program: Host Process for Windows Services File: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8355C2D8-9158-4C3C-A29C-ECA7F7EE75D6}\mpengine.dll The error value is listed in the Additional Data section. User Action 1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again. 2. If the file still cannot be accessed and - It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from a backup copy. 5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance. Additional Data Error value: C00000B5 Disk type: 3 [ System Events ] Error - 7/12/2013 5:41:51 PM | Computer Name = Belinda-PC | Source = iaStor | ID = 262153 Description = The device, \Device\Ide\iaStor0, did not respond within the timeout period. Error - 7/12/2013 5:42:47 PM | Computer Name = Belinda-PC | Source = iaStor | ID = 262153 Description = The device, \Device\Ide\iaStor0, did not respond within the timeout period. Error - 7/12/2013 5:42:48 PM | Computer Name = Belinda-PC | Source = iaStor | ID = 262153 Description = The device, \Device\Ide\iaStor0, did not respond within the timeout period. Error - 7/12/2013 5:43:14 PM | Computer Name = Belinda-PC | Source = iaStor | ID = 262153 Description = The device, \Device\Ide\iaStor0, did not respond within the timeout period. Error - 7/12/2013 5:43:15 PM | Computer Name = Belinda-PC | Source = iaStor | ID = 262153 Description = The device, \Device\Ide\iaStor0, did not respond within the timeout period. Error - 7/12/2013 5:43:16 PM | Computer Name = Belinda-PC | Source = iaStor | ID = 262153 Description = The device, \Device\Ide\iaStor0, did not respond within the timeout period. Error - 7/12/2013 6:24:10 PM | Computer Name = Belinda-PC | Source = iaStor | ID = 262153 Description = The device, \Device\Ide\iaStor0, did not respond within the timeout period. Error - 7/12/2013 6:27:19 PM | Computer Name = Belinda-PC | Source = iaStor | ID = 262153 Description = The device, \Device\Ide\iaStor0, did not respond within the timeout period. Error - 7/12/2013 6:27:20 PM | Computer Name = Belinda-PC | Source = iaStor | ID = 262153 Description = The device, \Device\Ide\iaStor0, did not respond within the timeout period. Error - 7/12/2013 6:27:21 PM | Computer Name = Belinda-PC | Source = iaStor | ID = 262153 Description = The device, \Device\Ide\iaStor0, did not respond within the timeout period. < End of report >