OTL Extras logfile created on: 3/6/2014 11:44:56 AM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\bf\Downloads 64bit- Enterprise Edition (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.16476) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 5.47 Gb Total Physical Memory | 4.11 Gb Available Physical Memory | 75.02% Memory free 7.04 Gb Paging File | 5.44 Gb Available in Paging File | 77.30% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465.42 Gb Total Space | 448.04 Gb Free Space | 96.27% Space Free | Partition Type: NTFS Computer Name: BB | User Name: bf | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{012C34F8-D560-4FDA-B2BE-8BCB4E5898A0}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{3509F085-788F-48E0-95CE-AFF9B2D8F9CF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{3EF77A83-9270-464A-ABED-4A3543A0DF59}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{641BEE4D-282E-48C2-B7D4-1D7940A3D07C}" = rport=2869 | protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{673ECBBE-5E6C-4B67-94EA-6F1B03951A19}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{741D0A12-7974-4C72-BDC7-95A57970B22A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{BFAF58D2-8851-4A35-9926-CA4D3B482BF9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C78065ED-FCFA-4344-BB03-C6087AE43CBD}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{C8A19D34-9F90-47B2-A2B0-2F3FBAFF5DBD}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\dashost.exe | "{C945F1A4-CD81-488C-8097-04BB6E623520}" = lport=1688 | protocol=6 | dir=in | app=c:\windows\kms\kms.exe | "{C9A99F19-7CD9-4142-9312-29E311A9FADF}" = lport=1688 | protocol=6 | dir=out | app=c:\windows\kms\kms.exe | "{F0FB5C5E-E66F-4356-B18C-EA07A46C57B6}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04EC8586-9D06-4D42-8813-DFD42B235EA6}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.1.177_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | "{1F08E63B-25CE-44CF-BEE8-2DCDAD2F56E3}" = dir=out | name=@{microsoft.bingweather_3.0.1.174_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{2166BCDE-2C21-453E-9E92-8816BC4C12A1}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.4.9600.16384_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{2EE27D55-BA28-4F39-A494-B4C739A060FA}" = dir=out | name=@{microsoft.zunevideo_2.2.41.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{30EA2870-5539-4E24-A511-EAD298C5BEA3}" = dir=out | name=kmsblock | "{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | "{51B1EBFA-DCA8-4B55-B39F-3D8C248AA2D8}" = dir=out | name=skype | "{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=store | "{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | "{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=store | "{9E58E2E6-A5C0-4E54-8314-9A4D69DF4AEF}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.4.9600.16384_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{A787CF5F-FE24-4DDE-90EF-6CA2135A1847}" = dir=out | name=@{microsoft.bingmaps_2.0.2009.2356_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{A8C91BEE-5E2A-496E-AF4A-BEEE75E72F58}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9600.16384_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{B2CE49C3-11D6-4D0F-90DB-4F5E52CFB3EE}" = dir=out | name=@{microsoft.zunemusic_2.2.41.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{BCDC2704-75A9-44CD-9F87-3F397D82B637}" = dir=out | name=@{microsoft.bingfinance_3.0.1.174_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{CC07C1C6-C8FF-4F48-B400-5B9741D0B9B3}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.1.176_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | "{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | "{E04887F1-6BCF-412A-8AB1-31503A521D60}" = dir=out | name=@{microsoft.bingtravel_3.0.1.174_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{E2A18DD0-8C23-4CB2-87BB-66B50CA49488}" = dir=in | name=skype | "{E4093DAB-2E9C-4604-9D3D-E62A532F6604}" = dir=out | name=@{microsoft.xboxlivegames_2.0.20.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{E626E7B4-0352-4761-A3F0-EC83DC4390A6}" = dir=out | name=@{microsoft.bingsports_3.0.1.174_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | "{F208CDC4-1912-42B9-8BE5-DBE3D669F63B}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9600.16384_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | "{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | "{F80D00AA-1BD4-4773-8259-F368C91CF8E6}" = dir=out | name=@{microsoft.bingnews_3.0.1.174_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{345841F8-F9F9-9910-134E-49162B7FDDAD}" = ccc-utility64 "{7EB99D77-F222-B208-C0AE-1E5D4E887532}" = AMD Fuel "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 "{1812E293-E2D1-3072-0ED4-C15163533D7E}" = CCC Help Swedish "{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 "{25087F13-EBE7-C817-CA31-08C196F73B23}" = CCC Help Hungarian "{29043AAA-3A1A-D36B-C1CB-E201FA72C16A}" = CCC Help Dutch "{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 "{3C7F465C-765F-A038-60BE-03B7301B0161}" = CCC Help Norwegian "{42321261-5D40-644C-1235-927141D4FA20}" = CCC Help Portuguese "{446CF7B3-EE4D-1C10-E2B7-87C1C8517FE8}" = CCC Help Korean "{450BED09-F405-87EE-CD52-5055B1EF8F72}" = CCC Help Chinese Standard "{4D628C2E-D9F7-2D3A-E610-00F4D52F219F}" = CCC Help Polish "{553B5DE6-496A-4328-DE0B-D1C83F7FE4D8}" = CCC Help Turkish "{5EA2099A-0249-1D98-5387-0BEF207D72AA}" = AMD Catalyst Control Center "{632396AA-8A78-A9A4-0945-7E24DF3F5B6C}" = CCC Help French "{64592305-22DF-6756-FD51-1B7234D4C6AB}" = CCC Help Russian "{6DC13EFF-D4FF-65B6-7538-8B3E6075853F}" = Catalyst Control Center InstallProxy "{7BC48761-EE54-AA23-5607-0D11B7550CFB}" = CCC Help Italian "{7C58E0C8-89FB-7E36-158C-5DC0B57027D9}" = CCC Help Czech "{87270A4A-EDE9-BFDF-AE0C-0FBDEEA5D4BD}" = CCC Help Thai "{8B1A559A-FB9D-42F5-A8A7-2F132CF28414}" = Catalyst Control Center "{8F1ABC89-3D34-1D8B-DF69-EC9198604283}" = CCC Help Spanish "{96DAF3C6-C2D4-5804-E219-86C034A02355}" = CCC Help Japanese "{9BB69BDB-FE40-24D2-3822-828FB6DF6DE2}" = CCC Help German "{A71019D0-8C9D-DB8D-2801-CBFC736FF307}" = CCC Help Danish "{B99E1A30-E349-FA3B-80F7-FB55EBC40996}" = CCC Help Chinese Traditional "{C28E9DF6-C68D-18DF-076C-7E92B9F30A96}" = CCC Help English "{C68D4599-2D2A-2060-39D0-0B3DEA861657}" = Catalyst Control Center Localization All "{CB79256B-C0E0-40C6-8EB7-BDD796203581}" = Catalyst Control Center - Branding "{F940E929-2FFF-1F4E-7ECB-DE1B0377D627}" = CCC Help Finnish "{FB8AF07B-42FB-4746-058A-B6A063472452}" = CCC Help Greek "{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300 [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 3/6/2014 1:11:01 PM | Computer Name = bb | Source = Software Protection Platform Service | ID = 8200 Description = License acquisition failure details. hr=0x80072EE7 Error - 3/6/2014 1:11:01 PM | Computer Name = bb | Source = Software Protection Platform Service | ID = 8208 Description = Acquisition of genuine ticket failed (hr=0x80072EE7) for template Id {99d92734-d682-4d71-983e-d6ec3f16059f} Error - 3/6/2014 1:32:14 PM | Computer Name = bb | Source = Software Protection Platform Service | ID = 8200 Description = License acquisition failure details. hr=0x80072EE7 Error - 3/6/2014 1:32:14 PM | Computer Name = bb | Source = Software Protection Platform Service | ID = 8208 Description = Acquisition of genuine ticket failed (hr=0x80072EE7) for template Id {99d92734-d682-4d71-983e-d6ec3f16059f} Error - 3/6/2014 2:31:29 PM | Computer Name = bb | Source = Application Error | ID = 1000 Description = Faulting application name: IEXPLORE.EXE, version: 11.0.9600.16384, time stamp: 0x52157231 Faulting module name: atidxx32.dll, version: 8.17.10.525, time stamp: 0x52a23862 Exception code: 0xc0000005 Fault offset: 0x00023f0e Faulting process id: 0xce0 Faulting application start time: 0x01cf3965ec287aaf Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: C:\Windows\SYSTEM32\atidxx32.dll Report Id: 881e4a3c-a55d-11e3-824f-e02ea7579001 Faulting package full name: Faulting package-relative application ID: [ System Events ] Error - 3/6/2014 1:03:40 PM | Computer Name = windows-mrt14b2 | Source = volmgr | ID = 262190 Description = Crash dump initialization failed! Error - 3/6/2014 1:04:38 PM | Computer Name = windows-mrt14b2 | Source = Service Control Manager | ID = 7023 Description = The IP Helper service terminated with the following error: %%1058 Error - 3/6/2014 1:04:45 PM | Computer Name = windows-mrt14b2 | Source = Service Control Manager | ID = 7023 Description = The Network List Service service terminated with the following error: %%21 Error - 3/6/2014 1:06:15 PM | Computer Name = bb | Source = DCOM | ID = 10010 Description = Error - 3/6/2014 1:10:16 PM | Computer Name = bb | Source = Service Control Manager | ID = 7030 Description = The Printer Extensions and Notifications service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. Error - 3/6/2014 2:32:42 PM | Computer Name = bb | Source = Service Control Manager | ID = 7023 Description = The Interactive Services Detection service terminated with the following error: %%1 < End of report >