OTL Extras logfile created on: 8/14/2013 8:26:05 PM - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Cart\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.75 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 47.98% Memory free 7.49 Gb Paging File | 4.93 Gb Available in Paging File | 65.89% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 450.41 Gb Total Space | 243.54 Gb Free Space | 54.07% Space Free | Partition Type: NTFS Drive D: | 15.05 Gb Total Space | 1.88 Gb Free Space | 12.51% Space Free | Partition Type: NTFS Unable to calculate disk information. Drive F: | 99.02 Mb Total Space | 88.87 Mb Free Space | 89.74% Space Free | Partition Type: FAT32 Drive G: | 465.73 Gb Total Space | 204.21 Gb Free Space | 43.85% Space Free | Partition Type: NTFS Drive H: | 7.67 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: CART-HP | User Name: Cart | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (All) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation) .hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation) .txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .bat [@ = batfile] -- "%1" %* .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cmd [@ = cmdfile] -- "%1" %* .com [@ = comfile] -- "%1" %* .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .exe [@ = exefile] -- "%1" %* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .pif [@ = piffile] -- "%1" %* .reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation) .scr [@ = scrfile] -- "%1" /S .txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = ChromeHTML.WVSHOE3JAHSJ5Y5EOENACSJWKM] -- C:\Users\Cart\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04083C5D-14AC-4017-89F8-BDAC8809CE0C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{0BC5B5B3-AD69-4E8E-A2EF-70A51B9BF7B1}" = lport=10243 | protocol=6 | dir=in | app=system | "{0F586CDE-D3A0-47F9-BE30-D2C5D5FCD8F2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{154D8ABF-D7E2-4879-BFED-EA3A6F99C6A3}" = lport=58183 | protocol=6 | dir=in | name=akamai netsession interface | "{1ACD5177-EA8F-417B-BD4B-F56EB5B45AD8}" = rport=138 | protocol=17 | dir=out | app=system | "{1BDC66B0-30F3-4B90-BB8B-9262ADCBE330}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{28995E79-3DB2-4B7D-812F-14337FD0BEA0}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3207D85B-1967-46CD-8AE8-F3F93E4D31F3}" = lport=137 | protocol=17 | dir=in | app=system | "{384C9B59-4C15-4DD4-9ACA-4C498EB6DC33}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{3A689601-FE4F-463D-95A5-C3FB9D892939}" = rport=139 | protocol=6 | dir=out | app=system | "{3C345B4C-A3D2-4808-B1D1-9A5FD71837D7}" = lport=138 | protocol=17 | dir=in | app=system | "{41535748-AD52-4E04-81E5-909244508415}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{46C3742A-E492-4F30-8FF5-800E17E75F5A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{48643332-02F9-4B49-860B-E54C159423D0}" = rport=445 | protocol=6 | dir=out | app=system | "{55072669-D0C7-49AD-B105-A9D455D5EC4E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{577038D9-024E-4CAE-A182-6181415DC01E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{608F7AC6-A29F-4B28-9B70-4F6E5493C4FF}" = rport=137 | protocol=17 | dir=out | app=system | "{644C5775-82A5-482E-97FE-9752BD0BE190}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{6729F62C-D547-4857-BCD6-082E60D3B0B7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{72A9D679-AD0C-4F13-9493-FB94E3F710E6}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{799B3521-F9C3-41A6-A64C-6965FE77582C}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{80CE85F0-F1E0-4324-92AD-96E3AA9FC481}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{8FCE226E-B1DD-4CB1-A9E6-B3333DF659E7}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{91C733BF-F9A3-4CCB-A33C-726D737927D7}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface | "{963998AA-0E3A-4CE0-B5E8-8E041152B23A}" = lport=2869 | protocol=6 | dir=in | app=system | "{9ABD4507-D388-4DF6-BB67-0357329FF9AD}" = lport=445 | protocol=6 | dir=in | app=system | "{A891C589-0DD4-4CEF-A66C-79CAC67C2390}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{B321CC9F-AE88-41B5-B559-3B2E1F33FAB2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B6EE035F-5AD8-442B-94FD-0AFA9B3BE496}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{BFB55236-6BFC-4632-8219-AB98BF957FE7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C317C033-0F96-4036-9450-5AA1F88FEDAA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D9B2091D-B74E-46E9-9F63-79E1A54FC68C}" = rport=10243 | protocol=6 | dir=out | app=system | "{E182CD64-5A07-48FA-857B-94E95F3A98DD}" = lport=139 | protocol=6 | dir=in | app=system | "{E82E512C-87D1-4C12-BE89-21656E79BFA1}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F165087A-827B-4942-AC5C-BFE1BD6EA18A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{F82C527D-6B0E-4888-A237-95CCB9D0E059}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{05F3A140-5756-4674-AF63-D8334B66B877}" = dir=out | app=c:\program files (x86)\hewlett-packard\hp clouddrive\zumodrive.exe | "{0A6642AC-FAD9-4B7F-BB98-DD0D7EB52CA6}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe | "{0C357B57-3D0E-46FE-9B11-5DD2ACD3F72F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nation red\nationred.exe | "{0C89F51F-1C04-46FA-83BD-8550DD78DDDC}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect 2\masseffect2launcher.exe | "{0E7D7902-1B5C-47C6-8E55-9A03CC15879A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{1AE45C64-A54D-432D-9D71-4012C79D00AE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{1B047DFD-45E7-4613-8A14-6077CCA905A4}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{1BBC95BA-6C86-40D4-822C-C7DD6205B857}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "{1F0ADB6D-9DA9-4D1A-BC8D-B19CBF47C783}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe | "{21DEA4C5-7D36-4367-A0B4-91B4EEEFAE01}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{2A548CE8-4E2E-4C7F-A457-1FBEA029B4E8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{2B1949EF-0C44-4C0F-A06B-EC8F651A0B88}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{2BDCC799-AB49-44B7-AC46-7CB908C7228A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe | "{2C2CD090-8FEB-43CF-8938-96579C9DA52C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\realm of the mad god\realm of the mad god.exe | "{2D0DEBDE-B8B7-429D-9C06-001B1D8C3CEB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{2EA44B75-48BB-4BFB-B870-EE003481A000}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe | "{377126C2-6D54-4189-B49E-CB046D7CFEF2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{39753F81-D909-4F0A-87E3-CD1D77A400A5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\iron grip marauders\prism.exe | "{3D03FBCF-F55D-4DE5-81ED-CF1FFBEAECEB}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{3DE2473E-9CDB-4411-AD1C-A26A45B6DD9F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallen earth f2p\feupdater.exe | "{3EF2670C-776C-4A07-AA48-74E54DF40C6E}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe | "{407E6920-243A-4980-B1AD-4E945CFE47A1}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{49AFB88A-8D32-424D-B032-FA48E193C6F0}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires ii\age2_x1\age2_x1.icd | "{4BC32E20-74EE-4D8E-9523-E271046DBFB7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{4C8409BF-BC98-4F96-B299-933A030D6B2D}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{4E9D75E4-3F3D-4824-BE27-2EFC198BBD75}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{502643A0-FE2E-4F72-915E-4F815235736A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{56B43DF6-A991-4B32-BEB7-133FFA0769AE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nation red\nationred.exe | "{583C5CBC-F48A-4430-9957-3FA3F3172B01}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3.exe | "{59D3B3B8-E455-4894-9F05-5539605895D6}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires ii\age2_x1\age2_x1.icd | "{59E5BBDF-04EF-406E-93E9-2CD302EAFB75}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\realm of the mad god\realm of the mad god.exe | "{5FDC6616-6A60-43C5-BF5B-B4625561B479}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect 2\masseffect2launcher.exe | "{62516746-8015-4616-B907-5CF3B41C7661}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | "{63B23284-2D2B-4020-8017-D81C5A2DFD14}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "{683350C6-38CC-47B6-A662-278E6017F096}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe | "{6B64DAF5-BBFC-484B-8BB1-E5C631237968}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{6DA68BB3-5EEB-40B9-AFB6-7123AEE32B08}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\front mission evolved\frontmissionevolved.exe | "{6ED4A591-B154-43E7-A23C-EB027C851DC0}" = protocol=6 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe | "{7108C684-0396-42EC-9708-9043F7FDBA1E}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "{7AD92EBE-5309-417F-95D6-41D72E77E5C0}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "{7C7254A9-23C4-4163-870F-853D5B845053}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe | "{854AAD51-A7E4-469C-940F-BBD82DE02DB4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallen earth f2p\feupdater.exe | "{86880448-8989-4033-A902-9DBED6F324A7}" = dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe | "{8F299641-2849-4211-9026-ADA792EB5E7F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{9130F6CA-E928-4916-8287-7ABE60BD85B6}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{95B7E1A3-455E-45B1-AA63-98EE897A3EDA}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{9B0D42E7-CF6E-4F24-8A0F-8B9CE7EC6D5F}" = protocol=6 | dir=in | app=e:\common\epsonnet setup\eneasyapp.exe | "{A3F76AEF-5B7D-4048-A83A-0AD42D4D5B67}" = protocol=6 | dir=out | app=system | "{A48D4682-0A69-4435-B012-3D8DBB8DA2E3}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{A9C5D70D-5106-4C6D-AFB8-7853F0E7DB85}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{AC3FBB44-FD24-4679-923E-93B346C78580}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{ACF01951-F0B6-46B3-B98E-F7DEA7ECDCFC}" = protocol=6 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe | "{AF7DAE52-F403-4221-8318-B22F2B05A06F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\front mission evolved\frontmissionevolved.exe | "{B2CC6439-9BAE-453F-98BF-3894221E26EC}" = protocol=17 | dir=in | app=e:\common\epsonnet setup\eneasyapp.exe | "{B4F73685-86BC-4F84-8502-7E1B21D0F039}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | "{B4FDD7FF-DC68-4FCF-987D-6672C6C33191}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\iron grip marauders\prism.exe | "{B9EE4996-66A3-418A-9DD1-40163B68B5E0}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp clouddrive\zumodrive.exe | "{BD63BCF8-737F-4AD3-8BB5-5F5C734B896C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{C13F28DA-8FD4-44DA-B33E-50173AEDD6E1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star trek online\star trek online.exe | "{C23FFD35-6309-45B4-8497-A406F288FE8C}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{C2AC2D91-22F1-49BA-9B62-FEB7625645A9}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe | "{C6DD6256-09C6-4FEE-816E-1A5DA7628BF9}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe | "{CB158EF3-0386-4A34-830A-7430FB680B2C}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{CB9D06C3-EE47-416A-ABF0-E619950F2FEE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{CD5B8E11-E3EC-4D32-95C3-1E4CF22C895F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{DA0E47D6-8D65-4388-BF34-F0214A61446D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{DA78998D-C846-4218-807C-F5CAA6A4741C}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{DE37ABA3-8668-4EED-908E-1B4BB5D25C3D}" = protocol=6 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe | "{E10C18D3-2291-4B3D-935C-6499DF0ED925}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E58E4014-A0C2-4873-8F9F-701FAC6954A6}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{E71AF484-4A35-4DF7-B674-D23E82A12DA6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star trek online\star trek online.exe | "{E79FAE30-01E8-4300-858D-8060C95D9D58}" = protocol=17 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe | "{EA1F63DB-6C19-4AA2-9ACB-304E41D06DC7}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect 2\binaries\masseffect2.exe | "{EA213DEB-8BBF-44A9-9EDF-F78BD38AA932}" = protocol=17 | dir=in | app=c:\program files (x86)\belkin\router setup and monitor\belkinsetup.exe | "{ECAC8F2E-8145-416D-B37F-3A17134F76C9}" = protocol=17 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe | "{EDCAD485-9586-41D8-BA55-6B4A6F03C70E}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{EE3BFE13-192F-4B56-9FC1-7EA27B0393A2}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect 2\binaries\masseffect2.exe | "{F31808A5-3DC4-404D-9EEC-F20BBCFC1EA4}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{F3B88A05-BC84-4520-8EEB-F2F9437CC853}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe | "{F6B5D8D3-D0C5-4807-A3B6-428AE2694C86}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe | "{F81E84B0-2EFD-490C-8893-29415229C26F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3.exe | "{FA2D8B90-B426-4D0E-8ECF-3A9ADDB16B8E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "TCP Query User{19BFAC4E-620C-4558-B115-2AB255C75F0C}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | "TCP Query User{615FBFBC-B55C-4DD4-AA10-B5E1E4FDCD90}C:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe | "TCP Query User{84DD50FB-3943-4307-BD86-B159636459B6}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | "TCP Query User{87CD236B-24AD-4B4A-89E1-15562352C7FD}C:\program files (x86)\microsoft office\office12\groove.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "TCP Query User{8A7DDB5F-EA86-46D2-9396-2BE7567ECC75}C:\users\cart\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\cart\appdata\local\akamai\netsession_win.exe | "TCP Query User{91237DFA-D14D-40AF-A730-D689E26B2810}C:\program files (x86)\starcraft ii\versions\base23260\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base23260\sc2.exe | "TCP Query User{9DC710BE-D511-45CB-9775-8D2C1BAAF477}C:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe | "TCP Query User{A56D80E2-CDB1-43B0-980E-7C5A9FFDD7E1}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | "TCP Query User{CE0C1C45-14CA-4BFA-96E9-2EF96A69F9EC}C:\users\cart\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\cart\appdata\local\akamai\netsession_win.exe | "TCP Query User{E85C8C47-8508-4729-89C1-43F8624A07B7}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "TCP Query User{F2FD62C3-58BD-4C29-922F-2A1872456810}C:\program files (x86)\microsoft games\age of empires ii\age2_x1\age2_x1.icd" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires ii\age2_x1\age2_x1.icd | "UDP Query User{0A18F4BA-C1F9-4D7E-9EC2-3D4F98C3E5F3}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | "UDP Query User{12940DDE-18B4-4ED1-B9FA-0B2D5F4136B7}C:\program files (x86)\starcraft ii\versions\base23260\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base23260\sc2.exe | "UDP Query User{4E5D0C5C-E4A5-442D-81C4-26D5000CE59D}C:\program files (x86)\microsoft games\age of empires ii\age2_x1\age2_x1.icd" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires ii\age2_x1\age2_x1.icd | "UDP Query User{50DB87FA-6F5A-4569-91C1-E6E8A8D8774A}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe | "UDP Query User{5FDEC4B8-9605-4451-BCEA-672434F16EC7}C:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe | "UDP Query User{665D29F9-C510-4C4D-ABE3-5B923D0973A3}C:\users\cart\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\cart\appdata\local\akamai\netsession_win.exe | "UDP Query User{8352580C-7B86-4AA6-BD76-AC81DA5A098E}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "UDP Query User{8E8BA90D-A93E-44A3-83B7-5D6C4AE0E436}C:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star trek online\star trek online\live\gameclient.exe | "UDP Query User{9BB2AA69-0B73-41FD-9A9D-1FD46C75BFED}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | "UDP Query User{B1939C34-D884-457E-B0F5-38261ED5D94F}C:\users\cart\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\cart\appdata\local\akamai\netsession_win.exe | "UDP Query User{E97DE529-E70D-441D-BE84-7BB089CE51CD}C:\program files (x86)\microsoft office\office12\groove.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector "{13DCC2C7-454D-42F0-A892-E0E9A5DE4E67}" = HP Wireless Assistant "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant "{1B6E46D9-BD48-F831-D337-64397E7EA1DB}" = ccc-utility64 "{224EC8DF-BC76-4CE4-32B8-4D174318F7ED}" = WMV9/VC-1 Video Playback "{26A24AE4-039D-4CA4-87B4-2F86416022FF}" = Java(TM) 6 Update 22 (64-bit) "{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{814FA673-A085-403C-9545-747FC1495069}" = Epson Customer Participation "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007 "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{E18E155E-73A9-0CCA-B796-05B09A1B5D97}" = ATI Catalyst Install Manager "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FE87BA4F-9866-8332-0A4F-59864BE2196A}" = AMD Fuel "Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter "CCleaner" = CCleaner "Defraggler" = Defraggler "EPSON NX430 Series" = EPSON NX430 Series Printer Uninstall "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{0428932D-FEAE-4FA2-953B-0437ABE9ADF3}_is1" = Movie Subtitles Searcher 1.0 "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements "{0A9A553D-A324-4C3C-B6E9-2464480BAE50}" = Catalyst Control Center - Branding "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0C107330-16DF-4D39-AA74-0E5448AED9E8}" = HP Documentation "{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime "{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player "{0F7254A8-4D75-979A-4445-EBC2EE90B6D2}" = CCC Help English "{10F63395-157F-4B93-AB4D-702A2FF11942}" = Epson Download Navigator "{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore "{14D9E133-37C6-B9CB-36C5-EB76DBE80F5C}" = Catalyst Control Center Graphics Previews Common "{1760F404-9A2B-4CD5-9A5C-7F9DCC627741}" = MechWarrior Online "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{264FE20A-757B-492a-B0C3-4009E2997D8A}" = PictureMover "{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21 "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7 "{3B834B54-EC4B-48E2-BFC6-03FF5DA06F62}" = Adobe Shockwave Player 11.5 "{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{431D963B-16AA-FAB8-3E72-82CDB466FDD8}" = CCC Help Swedish "{439A51F7-84B1-4603-BEC8-647EB2AC307F}" = WD Drive Utilities "{49F633C6-1247-3052-F1F1-C3DC271A6E92}" = CCC Help Danish "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion "{53B17A98-5BF0-40BC-AAFF-850A357975AC}" = HP Quick Launch "{54C024E2-4761-EB23-88C5-77EE8977B854}" = CCC Help Polish "{54D4EAF5-4C80-4878-B4AC-5AE454A02E3C}_is1" = Trend Micro RUBotted 2.0 Beta "{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5A018BC8-CEC4-C0E2-5EB1-4DFF3CD5E052}" = CCC Help Japanese "{5FE4D5BB-0B56-DC7D-E5A4-49DB989983CC}" = CCC Help French "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{64BA551C-9AF6-495C-93F3-D1270E0045FC}" = Epson Connect "{675D093B-815D-47FD-AB2C-192EC751E8E2}" = HP Software Framework "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1 "{6F388ED3-8C2B-222D-9CA6-38C44A3F4569}" = CCC Help Italian "{70E09E33-5C83-F272-17D5-93858F2063F2}" = CCC Help Dutch "{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2 "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{7D12AB72-6A28-A280-0637-485760AFDBDC}" = ccc-core-static "{802C068E-0576-4F25-8137-D54B7DB0FC5E}" = HP Setup "{81BAE41F-EF43-4902-773E-64B105245EE0}" = CCC Help Chinese Standard "{82F6A47B-6651-0044-F871-AF99C15E4871}" = CCC Help German "{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8ED43F7E-A8F6-4898-AF11-B6158F2EDF94}" = Epson Event Manager "{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}" = Google Earth "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{98218567-28F7-0D1F-BD48-3041677E5CD4}" = CCC Help Hungarian "{994406A3-EA5C-B7C9-B0C0-E9019ADD3521}" = CCC Help Korean "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A671E7CA-23EA-A86E-A61F-E518143670C0}" = CCC Help Thai "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9AED85D-2194-F13C-EE99-F013DB2BD44F}" = CCC Help Russian "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB32E35A-3CBE-6747-06A9-453469EF9CD2}" = CCC Help Chinese Traditional "{ABAF4569-6EDD-EA43-1574-EBA8911859BE}" = CCC Help Greek "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.7) "{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager "{B949352B-D05B-5670-836E-430CCAAE28FA}" = CCC Help Spanish "{BC08BEE3-1503-0173-B7A5-8765AA20C08A}" = CCC Help Portuguese "{BCB2219D-A452-80E9-5C27-F497128DE10A}" = CCC Help Norwegian "{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}" = Energy Star Digital Logo "{BD302920-E48F-EE44-4DBF-F58994C8BDF3}" = CCC Help Finnish "{C1080852-065E-4991-9260-F3756E3CC182}" = CursorFX "{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{C7231F7C-6530-4E65-ADA6-5B392CF5BEB1}" = Recovery Manager "{C761FF0D-677F-4A40-9338-CF44EAB1F02E}" = Vuze Remote Toolbar v7.4 "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86 "{CD95F661-A5C4-44F5-A6AA-ECDD91C240BE}" = WinZip 15.0 "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D2AC41BC-CA8B-846C-A711-42A2C8BC05BB}" = Catalyst Control Center InstallProxy "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D647F06F-2908-487E-9CDA-DE52148CBF49}" = OverDrive Media Console "{D8BCE5B9-67CF-4F3F-93AE-3ACC754C72EB}" = HP Power Manager "{D902BADB-499C-EF9E-B5D3-48B36566C3A6}" = Catalyst Control Center Localization All "{DA7B4F2B-0099-EEB6-6FB8-8F794248E982}" = CCC Help Czech "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{ED1BD69A-07E3-418C-91F1-D856582581BF}" = HP On Screen Display "{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FE2D627E-D7E0-46EA-93A6-8583420285FA}" = Aeria Ignite "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "{ffbbd184-8eba-469f-bb26-ea4e1f6bfd4c}" = MechWarrior Online "8461-7759-5462-8226" = Vuze "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "Aeria Ignite" = Aeria Ignite "Aeria Ignite 1.13.3296" = Aeria Ignite "Age of Empires 2.0" = Microsoft Age of Empires II "Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion "BandiMPEG1" = Bandisoft MPEG-1 Decoder "Bejeweled 31.0" = Bejeweled 3 "Belkin Setup and Router Monitor_is1" = Belkin Setup and Router Monitor "conduitEngine" = Conduit Engine "CursorFX" = CursorFX "Delta Chrome Toolbar" = Delta Chrome Toolbar "ENTERPRISE" = Microsoft Office Enterprise 2007 "EPSON Scanner" = EPSON Scan "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "KLiteCodecPack_is1" = K-Lite Codec Pack 3.9.0 Standard "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300 "Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US) "MozillaMaintenanceService" = Mozilla Maintenance Service "OpenIt Open It!" = Open It! "Scarlet Blade" = Scarlet Blade "SpeedFan" = SpeedFan (remove only) "StarCraft II" = StarCraft II "Steam App 113420" = Fallen Earth "Steam App 200210" = Realm of the Mad God "Steam App 31740" = Iron Grip: Marauders "Steam App 39160" = Dungeon Siege III "Steam App 43000" = Front Mission Evolved "Steam App 9900" = Star Trek Online "Trusted Software Assistant_is1" = File Type Assistant "Vivitar Experience Image Manager" = Vivitar Experience Image Manager "VLC media player" = VLC media player 1.1.11 "Vuze_Remote Toolbar" = Vuze Remote Toolbar "WildTangent hp Master Uninstall" = HP Games "Winamp" = Winamp "Winamp Essentials Pack" = Winamp Essentials Pack "Winamp Toolbar" = Winamp Toolbar "WinLiveSuite" = Windows Live Essentials "WinPcapInst" = WinPcap 4.1.3 "WinRAR archiver" = WinRAR 4.01 (32-bit) "WT015792" = FATE "Yahoo! Messenger" = Yahoo! Messenger "Yahoo! Software Update" = Yahoo! Software Update "YTdetect" = Yahoo! Detect "ZumoDrive" = HP CloudDrive [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface "Google Chrome" = Google Chrome "IGG Web3D Player_is1" = IGG Web3D Player version 1.0.0.38 "Mozilla Firefox 16.0.2 (x86 en-US)" = Mozilla Firefox 16.0.2 (x86 en-US) "soe-Wizardry Online" = Wizardry Online "UnityWebPlayer" = Unity Web Player "Winamp Detect" = Winamp Detector Plug-in "Winamp Toolbar" = Winamp Toolbar [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 6/27/2013 2:22:01 PM | Computer Name = Cart-HP | Source = Application Hang | ID = 1002 Description = The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: d8c Start Time: 01ce6e002709b352 Termination Time: 0 Application Path: C:\Windows\Explorer.EXE Report Id: 6c385bcf-df56-11e2-a21d-2c27d7ce1387 Error - 6/27/2013 8:18:06 PM | Computer Name = Cart-HP | Source = Application Error | ID = 1000 Description = Faulting application name: Azureus.exe, version: 4.8.0.0, time stamp: 0x50a12bac Faulting module name: utp.dll, version: 0.0.0.0, time stamp: 0x4d3dad8e Exception code: 0xc0000409 Fault offset: 0x000034be Faulting process id: 0x17f8 Faulting application start time: 0x01ce6e17d31cf77b Faulting application path: C:\Program Files (x86)\Vuze\Azureus.exe Faulting module path: C:\Users\Cart\AppData\Roaming\Azureus\plugins\azutp\win32\utp.dll Report Id: 33aa8b40-df88-11e2-a21d-2c27d7ce1387 Error - 6/30/2013 5:28:57 PM | Computer Name = Cart-HP | Source = Application Error | ID = 1000 Description = Faulting application name: googleearth.exe, version: 7.1.1.1871, time stamp: 0x51caca06 Faulting module name: QtCore4.dll, version: 4.6.1.0, time stamp: 0x4e00f869 Exception code: 0xc0000005 Fault offset: 0x00036a80 Faulting process id: 0x179c Faulting application start time: 0x01ce75d038375664 Faulting application path: C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe Faulting module path: C:\Program Files (x86)\Google\Google Earth\client\QtCore4.dll Report Id: 11be1c62-e1cc-11e2-bdaa-2c27d7ce1387 Error - 7/2/2013 12:06:20 AM | Computer Name = Cart-HP | Source = Application Error | ID = 1000 Description = Faulting application name: firefox.exe, version: 16.0.2.4680, time stamp: 0x50882871 Faulting module name: xul.dll, version: 16.0.2.4680, time stamp: 0x508827d6 Exception code: 0xc0000005 Fault offset: 0x00130ef7 Faulting process id: 0x1550 Faulting application start time: 0x01ce76c6e87b4752 Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Faulting module path: C:\Program Files (x86)\Mozilla Firefox\xul.dll Report Id: bfdd379b-e2cc-11e2-a08c-2c27d7ce1387 Error - 7/7/2013 6:31:14 PM | Computer Name = Cart-HP | Source = Application Error | ID = 1000 Description = Faulting application name: eEBSVC.exe, version: 2.3.4.0, time stamp: 0x4587e0bf Faulting module name: eEBSVC.exe, version: 2.3.4.0, time stamp: 0x4587e0bf Exception code: 0xc0000005 Fault offset: 0x00003e16 Faulting process id: 0x628 Faulting application start time: 0x01ce76e9929479aa Faulting application path: C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe Faulting module path: C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe Report Id: ee77308d-e754-11e2-8fc9-2c27d7ce1387 Error - 7/15/2013 1:26:23 PM | Computer Name = Cart-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Failed extract of third-party root list from auto update cab at: with error: The data is invalid. . Error - 7/15/2013 1:26:25 PM | Computer Name = Cart-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Failed extract of third-party root list from auto update cab at: with error: The data is invalid. . Error - 7/15/2013 1:26:33 PM | Computer Name = Cart-HP | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Failed extract of third-party root list from auto update cab at: with error: The data is invalid. . Error - 7/17/2013 6:06:14 AM | Computer Name = Cart-HP | Source = Windows Search Service | ID = 3007 Description = Error - 7/19/2013 8:58:13 PM | Computer Name = Cart-HP | Source = Application Hang | ID = 1002 Description = The program SC2.exe version 2.0.9.26147 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 269c Start Time: 01ce84e3c4d4cb02 Termination Time: 66 Application Path: C:\Program Files (x86)\StarCraft II\Versions\Base24944\SC2.exe Report Id: 3750156e-f0d7-11e2-8b43-2c27d7ce1387 [ Hewlett-Packard Events ] Error - 9/20/2012 3:02:01 PM | Computer Name = Cart-HP | Source = HPSF.exe | ID = 4000 Description = Error - 9/20/2012 3:02:26 PM | Computer Name = Cart-HP | Source = HPSF.exe | ID = 4000 Description = Error - 10/8/2012 3:42:28 PM | Computer Name = Cart-HP | Source = HPSF.exe | ID = 4000 Description = Error - 10/8/2012 3:45:01 PM | Computer Name = Cart-HP | Source = HPSF.exe | ID = 4000 Description = Error - 10/8/2012 3:48:26 PM | Computer Name = Cart-HP | Source = HPSF.exe | ID = 4000 Description = Error - 10/8/2012 3:49:14 PM | Computer Name = Cart-HP | Source = HPSF.exe | ID = 4000 Description = Error - 10/8/2012 3:51:20 PM | Computer Name = Cart-HP | Source = HPSF.exe | ID = 4000 Description = HP Error ID: -2147467261HPSF.exe at HP.SupportFramework.Communicator.MessengerComm.MessengerPublisher.closeConnection() at HP.SupportAssistant.UI.MessengerCommunication.initializeCommunication() at HP.SupportAssistant.UI.MessengerCommunication.sendTimerUpdate() Message: Object reference not set to an instance of an object. StackTrace: at HP.SupportFramework.Communicator.MessengerComm.MessengerPublisher.closeConnection() at HP.SupportAssistant.UI.MessengerCommunication.initializeCommunication() at HP.SupportAssistant.UI.MessengerCommunication.sendTimerUpdate() Source: HP.SupportFramework.Communicator Name: HPSF.exe Version: 06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US RAM: 3834 Ram Utilization: 70 TargetSite: Void closeConnection() Error - 10/8/2012 3:51:52 PM | Computer Name = Cart-HP | Source = HPSF.exe | ID = 4000 Description = Error - 10/8/2012 3:52:06 PM | Computer Name = Cart-HP | Source = HPSF.exe | ID = 4000 Description = Error - 10/15/2012 3:02:14 PM | Computer Name = Cart-HP | Source = HPSF.exe | ID = 4000 Description = [ HP Software Framework Events ] Error - 4/30/2012 5:01:32 PM | Computer Name = Cart-HP | Source = CaslWmi | ID = 5 Description = 2012/04/30 14:01:32.342|000009BC|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error 0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state Error - 4/30/2012 5:01:45 PM | Computer Name = Cart-HP | Source = CaslWmi | ID = 5 Description = 2012/04/30 14:01:45.733|00000500|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error 0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state Error - 4/30/2012 5:01:52 PM | Computer Name = Cart-HP | Source = CaslWmi | ID = 5 Description = 2012/04/30 14:01:52.808|000016D8|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error 0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state Error - 5/7/2012 2:04:32 PM | Computer Name = Cart-HP | Source = CaslWmi | ID = 5 Description = 2012/05/07 11:04:32.090|00000498|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error 0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state Error - 5/14/2012 3:03:47 PM | Computer Name = Cart-HP | Source = CaslWmi | ID = 5 Description = 2012/05/14 12:03:46.999|000010D4|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error 0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state Error - 6/6/2012 12:15:49 AM | Computer Name = Cart-HP | Source = CaslWmi | ID = 5 Description = 2012/06/05 21:15:49.896|00000E4C|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error 0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state Error - 6/6/2012 12:27:51 AM | Computer Name = Cart-HP | Source = CaslWmi | ID = 5 Description = 2012/06/05 21:27:51.108|00001AF4|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error 0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state Error - 6/6/2012 12:27:55 AM | Computer Name = Cart-HP | Source = CaslWmi | ID = 5 Description = 2012/06/05 21:27:55.989|00001774|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error 0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state Error - 6/6/2012 12:28:11 AM | Computer Name = Cart-HP | Source = CaslWmi | ID = 5 Description = 2012/06/05 21:28:11.058|0000077C|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error 0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state Error - 6/11/2012 2:08:01 PM | Computer Name = Cart-HP | Source = CaslWmi | ID = 5 Description = 2012/06/11 11:08:01.780|000004B0|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error 0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state [ HP Wireless Assistant Events ] Error - 7/28/2011 11:02:39 PM | Computer Name = Cart-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Call was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED)) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObjectSearcher.Initialize() at System.Management.ManagementObjectSearcher.Get() at HPPA_Service.CurrentConfiguration.FindDevice(String hostPath, String portName) at HPPA_Service.CurrentConfiguration.b__9(RadioHardware radio) at System.Linq.Enumerable.WhereSelectListIterator`2.MoveNext() at System.Linq.Enumerable.WhereSelectEnumerableIterator`2.MoveNext() at HPPA_Service.CurrentConfiguration.ReloadRadioList() Error - 9/3/2011 6:00:40 PM | Computer Name = Cart-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Call was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED)) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) at HPPA_Service.CurrentConfiguration.b__c() Error - 11/29/2011 10:58:17 PM | Computer Name = Cart-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Call was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED)) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) at HPPA_Service.CurrentConfiguration.b__c() Error - 12/26/2011 12:36:31 PM | Computer Name = Cart-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Call was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED)) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObjectSearcher.Initialize() at System.Management.ManagementObjectSearcher.Get() at HPPA_Service.CurrentConfiguration.FindDevice(String hostPath, String portName) at HPPA_Service.CurrentConfiguration.b__9(RadioHardware radio) at System.Linq.Enumerable.WhereSelectListIterator`2.MoveNext() at System.Linq.Enumerable.WhereSelectEnumerableIterator`2.MoveNext() at HPPA_Service.CurrentConfiguration.ReloadRadioList() Error - 1/8/2012 6:15:47 PM | Computer Name = Cart-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException Call was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED)) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObjectSearcher.Initialize() at System.Management.ManagementObjectSearcher.Get() at HPPA_Service.CurrentConfiguration.FindDevice(String hostPath, String portName) at HPPA_Service.CurrentConfiguration.b__9(RadioHardware radio) at System.Linq.Enumerable.WhereSelectListIterator`2.MoveNext() at System.Linq.Enumerable.WhereSelectEnumerableIterator`2.MoveNext() at HPPA_Service.CurrentConfiguration.ReloadRadioList() Error - 1/22/2012 11:03:29 PM | Computer Name = Cart-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) at System.Management.ManagementObject.Initialize(Boolean getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) at HPPA_Service.CurrentConfiguration.b__c() Error - 1/24/2012 2:34:07 PM | Computer Name = Cart-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) at System.Management.ManagementObject.Initialize(Boolean getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) at HPPA_Service.CurrentConfiguration.b__c() Error - 1/26/2012 1:51:57 PM | Computer Name = Cart-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) at System.Management.ManagementObject.Initialize(Boolean getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) at HPPA_Service.CurrentConfiguration.b__c() Error - 2/7/2012 12:17:26 AM | Computer Name = Cart-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) at System.Management.ManagementObject.Initialize(Boolean getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) at HPPA_Service.CurrentConfiguration.b__c() Error - 2/10/2012 8:19:11 PM | Computer Name = Cart-HP | Source = HP WA Service | ID = 0 Description = System.Runtime.InteropServices.COMException at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) at System.Management.ManagementObject.Initialize(Boolean getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String propertyName) at HPPA_Service.CurrentConfiguration.b__c() [ System Events ] Error - 8/10/2013 1:26:54 PM | Computer Name = Cart-HP | Source = Service Control Manager | ID = 7024 Description = The Windows Search service terminated with service-specific error %%-1073473535. Error - 8/10/2013 1:26:54 PM | Computer Name = Cart-HP | Source = Service Control Manager | ID = 7031 Description = The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error - 8/12/2013 4:16:17 PM | Computer Name = Cart-HP | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk1\DR4. Error - 8/14/2013 2:13:26 AM | Computer Name = Cart-HP | Source = Application Popup | ID = 1060 Description = \SystemRoot\SysWow64\drivers\pxtdi.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error - 8/14/2013 2:13:26 AM | Computer Name = Cart-HP | Source = Application Popup | ID = 1060 Description = \??\C:\Windows\SysWow64\drivers\pxrd.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error - 8/14/2013 2:14:39 AM | Computer Name = Cart-HP | Source = Application Popup | ID = 1060 Description = \SystemRoot\SysWow64\drivers\pxtdi.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error - 8/14/2013 2:14:40 AM | Computer Name = Cart-HP | Source = Application Popup | ID = 1060 Description = \??\C:\Windows\SysWow64\drivers\pxrd.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error - 8/14/2013 2:15:09 AM | Computer Name = Cart-HP | Source = Service Control Manager | ID = 7026 Description = The following boot-start or system-start driver(s) failed to load: PrevxDriver PrevxTdi PXRDDriver Error - 8/14/2013 12:04:05 PM | Computer Name = Cart-HP | Source = bowser | ID = 8003 Description = Error - 8/14/2013 11:10:18 PM | Computer Name = Cart-HP | Source = Service Control Manager | ID = 7034 Description = The Application Updater service terminated unexpectedly. It has done this 1 time(s). < End of report >