OTL Extras logfile created on: 3/2/2014 7:23:25 AM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Lewis\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.16518) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 5.91 Gb Total Physical Memory | 3.86 Gb Available Physical Memory | 65.33% Memory free 11.82 Gb Paging File | 9.50 Gb Available in Paging File | 80.36% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 451.01 Gb Total Space | 403.26 Gb Free Space | 89.41% Space Free | Partition Type: NTFS Computer Name: LEWIS-PC | User Name: Lewis | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .chm[@ = CHM] -- Reg Error: Key error. File not found .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .chm [@ = CHM] -- Reg Error: Key error. File not found .cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1422163307-3788927115-2030255185-1000\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0580E7CA-4339-4C6A-AD15-4F69FC372291}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{0AF4C540-D4F4-468C-B7D4-8B53CFEE365D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{0D437045-8700-4BAF-A4B7-B6EB9449E9E4}" = rport=139 | protocol=6 | dir=out | app=system | "{0EE57C56-DD86-4532-93B7-3577D75F4895}" = lport=7070 | protocol=6 | dir=in | name=c-print discovery | "{0F2E8119-62DB-450E-BBB9-BE9C70B61C8E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe | "{0F65512A-0C30-4DA6-86D9-11D6CCC3F4F9}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{19896ABE-6595-4EF9-BF98-46C6BF2305C1}" = lport=7000 | protocol=6 | dir=in | name=windows easy transfer tcp port | "{1AFC4225-4522-4211-824D-7B558D8D7CAC}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2EF4F5C0-DA21-4A39-9118-292EA0D0B382}" = rport=445 | protocol=6 | dir=out | app=system | "{3D4E2C94-4875-45C4-9DC2-811E4342587A}" = lport=137 | protocol=17 | dir=in | app=system | "{3DB4B043-CF73-41C6-BB2B-4F00FFF91382}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4F7058D3-E267-4FF6-B990-D99AC5F3405D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{4F98DC92-7231-43F9-BA02-4FC1AE5EA5C9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{518357AF-9F62-4883-86D8-BD66DC24C946}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{53B51EB8-1AD6-4BF3-B250-B4567ACC6EF8}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{5449BC6B-EAE7-402C-B7B2-34634C31A888}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{54595B9E-C3B7-4699-A139-D548B38F02B2}" = lport=138 | protocol=17 | dir=in | app=system | "{54B7C17F-5658-411B-AEA0-EFF43247A40A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{5B68883B-01F4-4BBA-BE2B-04C7B299FAD2}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface | "{63E77909-51C1-4CFB-BB32-5E6B38C7BAE5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{6D3EDAD6-8A7D-4117-8AFF-F1632373C357}" = rport=137 | protocol=17 | dir=out | app=system | "{78F09170-0AA0-4D4D-89CE-E31D716428BE}" = lport=7000 | protocol=17 | dir=in | name=windows easy transfer udp port | "{844A9D60-D926-44C5-AD7D-3FCC7901C2FA}" = lport=2869 | protocol=6 | dir=in | app=system | "{8C19BF0E-0CE3-4A71-80DC-5DAECF96071F}" = lport=139 | protocol=6 | dir=in | app=system | "{8C6ECC22-DBCB-4447-8B27-721AB8EECB89}" = rport=138 | protocol=17 | dir=out | app=system | "{8DDBEF2B-ABCA-4E3A-9C75-04173DC8E7F6}" = rport=10243 | protocol=6 | dir=out | app=system | "{96730737-B208-4762-AA4C-FAC9060EB5A5}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{BE3F0B29-6070-4C9E-B89F-0A1E456BA78C}" = lport=3030 | protocol=6 | dir=in | name=c-print xml | "{C72F4BA5-D873-4419-838A-F7D8CC39336A}" = lport=445 | protocol=6 | dir=in | app=system | "{CADFEA6D-4B0C-4AFE-8CEA-4C163984FB3B}" = lport=10000 | protocol=6 | dir=in | name=c-print client connection | "{CF2FF756-E9D3-40F0-B4B3-51856CD3B1C7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D14E2363-A8AB-4C28-AE91-12D1CFBDBFF2}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{D59EB71A-3EEE-4044-88FB-73C508589442}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{DCB4014A-89AF-4328-82DC-652C5B16AD37}" = lport=10243 | protocol=6 | dir=in | app=system | "{E5A1240D-BC69-4D9C-9614-74AA7B6B9977}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{EB066B2E-9D75-406B-8721-DED1EBF896C5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F21E5652-A56F-4BF2-80EB-CABD9A178CB1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F411E236-18CD-426B-90CA-01D957019C66}" = lport=49194 | protocol=6 | dir=in | name=akamai netsession interface | "{F8175360-B644-4B6C-8DC6-CED39046E87D}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{016C78DD-0D71-4588-A16A-9DA4EA9F5433}" = protocol=17 | dir=in | app=c:\windows\system32\migwiz\migwiz.exe | "{03D44C60-62ED-4061-BAF5-0E959747F9C6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{073C79D4-1720-4049-A942-7773FA164198}" = protocol=17 | dir=in | app=c:\program files\dell\dashboard\dl__dashboard.exe | "{0F44DEA1-B0BA-45D0-BFB4-017B52237483}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1003DACA-89DC-4ADE-AEE7-8DC3777DBE41}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{11ACB871-BB58-4190-B5C6-8BA5ED1F4A96}" = protocol=6 | dir=in | app=c:\program files\dell\dashboard\dl__dashboard.exe | "{13C34006-AD3B-4F8B-9DC4-2CE16C1E74E6}" = dir=in | app=c:\windows\system32\dleacoms.exe | "{1E5526DC-8778-4674-A325-8A9B0DE80CD2}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{20C5C546-0AE6-42F1-83ED-3C8CBC0401E4}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | "{28985ADC-6B5C-4EB6-A4EE-2445F13640C2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{2D6AD7F4-A005-4776-AF46-58754FFFE82F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{382D0E81-47F6-4CF7-A702-2AB5D9323C9F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{3B46CC8A-4B2A-4D56-87D7-98F626F1A8D7}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{3C0DCB9E-411B-486C-BB0F-11DBB449C0E8}" = dir=in | app=c:\windows\system32\dleacoms.exe | "{4B231554-0C47-4560-BC74-6E09F4E62E83}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{4D476F96-EB80-4CCE-99E9-258BC5D40D28}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v310-v510 series\dleafax.exe | "{4E539AF3-A0ED-400C-86F6-50D2275D4531}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{5BF4D522-9117-4058-97A6-FB6B3173274F}" = protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{5DBAB223-27BF-47D7-BCC1-01C9DA35A3DD}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{79F2D06E-AE86-433F-800B-3A19AE9DB1F9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7C80B9F5-1857-41ED-848D-6B0587F2B333}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{858785ED-3D7D-4687-ACAA-C9322C257AAC}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v310-v510 series\dleafax.exe | "{91162CBC-FB0F-497E-9719-DFC5222BFA3B}" = protocol=6 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{912FA7F5-62A5-4DA7-AE10-63BE822363BA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{93460404-3434-4D78-A0EF-65A490CF38B7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A3E00FD4-D85A-4B55-96F7-7D74AB397370}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{A7308F94-CF29-40B4-B426-4DE1012A4D12}" = protocol=6 | dir=in | app=c:\windows\system32\migwiz\migwiz.exe | "{A97E7586-1A6C-4EF9-AF8B-B4C636BE01A9}" = dir=in | app=c:\windows\system32\dleacoms.exe | "{BA08964D-2F43-4495-81D5-94D1CBB576B1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{BA3F8593-D95E-457E-88FB-82991BA41561}" = protocol=6 | dir=in | app=c:\program files (x86)\malwarebytes' anti-malware\mbam.exe | "{BA8442D6-8F9C-4336-9913-68BF01F48855}" = protocol=17 | dir=in | app=c:\program files (x86)\malwarebytes' anti-malware\mbam.exe | "{C8728DCC-1720-4E17-ADB7-E649FB44A1E1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{C8B2E2AC-0B28-472E-A7F4-CFE102805160}" = dir=in | app=c:\windows\system32\dleacoms.exe | "{D4BC1A75-993A-4D9E-91B9-99EA5424B7F6}" = dir=in | app=c:\program files (x86)\intel corporation\intel widi\widiapp.exe | "{D8D1400D-6FC6-4C20-82C7-F808A2708CEE}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{DA993D50-5E1D-47EC-AF65-EF54EBF667D0}" = protocol=6 | dir=out | app=system | "{E5B77A04-9FCA-4B1D-8389-937D355983E4}" = dir=in | app=c:\windows\system32\dleacoms.exe | "{EC995EB2-2D74-4857-8428-04C04C492016}" = dir=in | app=c:\windows\system32\dleacoms.exe | "{FAF00E91-A831-44DE-A386-4B2AB9C97350}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{FB295369-2A7E-4ADB-BEBD-C24714BD9BDD}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "TCP Query User{37C1316F-A736-43F8-99D2-437AFEE07D60}C:\users\lewis\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\lewis\appdata\local\akamai\netsession_win.exe | "TCP Query User{8E32FEC5-4BB1-4B81-AE71-C22BF39018F3}C:\users\lewis\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\lewis\appdata\local\akamai\netsession_win.exe | "UDP Query User{B3238130-3967-4DCF-B0B6-8FA127B9C9EA}C:\users\lewis\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\lewis\appdata\local\akamai\netsession_win.exe | "UDP Query User{B82CB4B5-285B-4A26-93E7-66C56B45E51B}C:\users\lewis\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\lewis\appdata\local\akamai\netsession_win.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center "{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel(R) Wireless Display "{295AEB79-B53A-4F1B-860F-7800BB7E3681}" = Intel(R) PROSet/Wireless WiFi Software "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{7CE8BE79-ABC3-4B2C-9543-28ED2B0A9EA8}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010 "{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad "{E102B843-786A-4F58-AF75-6504570E207B}" = Microsoft Security Client "CCleaner" = CCleaner "Dell V310-V510 Series" = Dell V310-V510 Series "HitmanPro.Alert" = HitmanPro.Alert "Malwarebytes Anti-Exploit_is1" = Malwarebytes Anti-Exploit version 0.09.5.0250 "Microsoft Security Client" = Microsoft Security Essentials "ProInst" = Intel PROSet Wireless [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0D98F04D-11A1-4B64-A406-43292B9EEE90}" = Dell PhotoStage "{0ECFCB07-9BFE-4970-ACA1-D568D982760B}" = Complete Care Business Service Agreement "{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup "{121634B0-2F4A-11D3-ADA3-00C04F52DD53}" = Windows Installer Clean Up "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser "{26A24AE4-039D-4CA4-87B4-2F83217040FF}" = Java 7 Update 51 "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{5228274E-59DC-4B9B-AF72-97AC81C09C8A}" = Malwarebytes Secure Backup "{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{781A93CD-1608-427D-B7F0-D05C07795B25}" = Intel(R) WiDi "{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide "{7FB00B6B-6843-97EC-EED6-78BD6D35370A}" = Zinio Reader 4 "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010 "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010 "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010 "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010 "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010 "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010 "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010 "{903679E8-44C8-4C07-9600-05C92654FC50}" = QualxServ Service Agreement "{91140000-001A-0000-0000-0000000FF1CE}" = Microsoft Office Outlook 2010 "{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector "{95140000-007C-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Facebook 32-bit "{95140000-007D-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A760067A-C07E-1033-0000-A764AC000002}" = Avery Template - U_0087_01_PlateauLines_0805_01_en "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software "{AB2FDE4F-6BED-4E9E-B676-3DCCEBB1FBFE}" = Dell Home Systems Service Agreement "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) "{AFC08A81-D3C5-46F4-8F08-876E4BA606EA}" = Dell Digital Delivery "{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR "{C33AA6D6-F5EC-48F3-AFDC-8141345D473A}" = Premium Service Agreement "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86 "{D2E707E8-090E-EC5B-4833-1CA694FB7460}" = Zinio Alert Messenger "{E2EBA7C0-8072-447F-856D-FFEE8D15B23B}" = Dell Stage "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio "{EF85FEF4-EB92-4075-A6D2-5F519BB30A2C}" = Accidental Damage Services Agreement "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F47C37A4-7189-430A-B81D-739FF8A7A554}" = Consumer In-Home Service Agreement "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin "Dell Webcam Central" = Dell Webcam Central "Google Chrome" = Google Chrome "GridinSoft Trojan Killer" = Trojan Killer "InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300 "Office14.OUTLOOKR" = Microsoft Outlook 2010 "Office14.SingleImage" = Microsoft Office Home and Student 2010 "SpywareBlaster_is1" = SpywareBlaster 5.0 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1422163307-3788927115-2030255185-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "9204f5692a8faf3b" = Dell System Detect "Akamai" = Akamai NetSession Interface "Amazon Kindle" = Amazon Kindle [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 3/1/2014 5:57:28 PM | Computer Name = Lewis-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002 Description = The performance counter explain text string value in the registry is not formatted correctly. The malformed string is . The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error - 3/1/2014 8:37:00 PM | Computer Name = Lewis-PC | Source = WinMgmt | ID = 10 Description = Error - 3/1/2014 9:37:02 PM | Computer Name = Lewis-PC | Source = WinMgmt | ID = 10 Description = Error - 3/1/2014 10:15:36 PM | Computer Name = Lewis-PC | Source = WinMgmt | ID = 10 Description = Error - 3/2/2014 3:51:14 AM | Computer Name = Lewis-PC | Source = WinMgmt | ID = 10 Description = Error - 3/2/2014 3:56:16 AM | Computer Name = Lewis-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002 Description = The performance counter explain text string value in the registry is not formatted correctly. The malformed string is . The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error - 3/2/2014 6:07:34 AM | Computer Name = Lewis-PC | Source = WinMgmt | ID = 10 Description = Error - 3/2/2014 6:11:42 AM | Computer Name = Lewis-PC | Source = Microsoft-Windows-LoadPerf | ID = 3002 Description = The performance counter explain text string value in the registry is not formatted correctly. The malformed string is . The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error - 3/2/2014 7:34:45 AM | Computer Name = Lewis-PC | Source = VSS | ID = 8194 Description = Error - 3/2/2014 7:34:59 AM | Computer Name = Lewis-PC | Source = VSS | ID = 8194 Description = [ Dell Events ] Error - 3/2/2012 5:03:27 PM | Computer Name = Lewis-PC | Source = DataSafe | ID = 17 Description = The process was interrupted before completion. Error - 3/2/2012 5:03:27 PM | Computer Name = Lewis-PC | Source = DataSafe | ID = 17 Description = The process was interrupted before completion. Error - 3/2/2012 5:22:38 PM | Computer Name = Lewis-PC | Source = DataSafe | ID = 17 Description = The process was interrupted before completion. Error - 3/2/2012 5:22:38 PM | Computer Name = Lewis-PC | Source = DataSafe | ID = 17 Description = The process was interrupted before completion. [ System Events ] Error - 3/1/2014 8:52:26 PM | Computer Name = Lewis-PC | Source = Service Control Manager | ID = 7006 Description = Error - 3/1/2014 9:36:53 PM | Computer Name = Lewis-PC | Source = Service Control Manager | ID = 7000 Description = Error - 3/1/2014 9:38:06 PM | Computer Name = Lewis-PC | Source = DCOM | ID = 10016 Description = Error - 3/1/2014 10:15:16 PM | Computer Name = Lewis-PC | Source = Service Control Manager | ID = 7000 Description = Error - 3/1/2014 10:16:28 PM | Computer Name = Lewis-PC | Source = WMPNetworkSvc | ID = 866300 Description = Error - 3/1/2014 10:16:37 PM | Computer Name = Lewis-PC | Source = DCOM | ID = 10016 Description = Error - 3/2/2014 3:51:01 AM | Computer Name = Lewis-PC | Source = Service Control Manager | ID = 7000 Description = Error - 3/2/2014 3:52:17 AM | Computer Name = Lewis-PC | Source = DCOM | ID = 10016 Description = Error - 3/2/2014 6:07:25 AM | Computer Name = Lewis-PC | Source = Service Control Manager | ID = 7000 Description = Error - 3/2/2014 6:08:44 AM | Computer Name = Lewis-PC | Source = DCOM | ID = 10016 Description = < End of report >