OTL Extras logfile created on: 5/15/2014 10:24:34 AM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\OfficeA\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17041) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.91 Gb Total Physical Memory | 1.12 Gb Available Physical Memory | 58.57% Memory free 3.81 Gb Paging File | 2.65 Gb Available in Paging File | 69.41% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 217.69 Gb Total Space | 171.75 Gb Free Space | 78.90% Space Free | Partition Type: NTFS Computer Name: OFFICEA | User Name: OfficeA | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02FDC0DA-232A-4155-9690-CE03D5AF6006}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{0B824E1E-E21A-4F41-89A4-9105B2CFD07E}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{1BBCA444-E17D-45EC-BC51-665B0E412DDB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1D2CEBB2-BD6F-4E0B-AB72-CDB433DD7528}" = rport=445 | protocol=6 | dir=out | app=system | "{1E3E0047-94DA-42D6-9A46-558C204DC64D}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{3627A3CD-DB05-4AF5-B1F0-196EB49EDCE4}" = lport=138 | protocol=17 | dir=in | app=system | "{3CA29CA5-DDF6-4460-8A58-8A787F456B5F}" = lport=61116 | protocol=6 | dir=in | name=trend micro client/server security agent update | "{48CC7D7D-9942-45F0-85BA-94CA1F77844B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{4E433039-6891-4BC8-928F-1B73826F8D3A}" = rport=138 | protocol=17 | dir=out | app=system | "{56FA4A28-F857-44F2-853A-231422280644}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{59D7801D-ECAC-4835-B1A3-EBB3BF2BB2F7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5C7CEABB-C073-444F-9B5B-CEC66B13360C}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{6A1C7B29-7313-4348-9783-004E5807BB91}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{6B5634AF-4138-4547-ABB2-4236F67E8AA0}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{7E222BDD-6D8F-4002-85F6-21FA9376DF85}" = lport=61117 | protocol=17 | dir=in | name=trend micro client/server security agent broadcast | "{87F15265-1C76-4B7D-B969-304E3351ADA5}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{8E75EACF-EF37-4A8E-A4BD-C5D772E4EF9B}" = lport=139 | protocol=6 | dir=in | app=system | "{8EBF7C86-4186-4D90-84A5-2D7D62ED1A71}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{96A6BADF-443B-4ECB-BDBD-AC1730183F3E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{AD7A89F7-0628-4412-826A-08A2BB01CA72}" = lport=137 | protocol=17 | dir=in | app=system | "{B9D7A208-4EA9-4064-B0CA-637C15F7CF42}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{BE92796A-865D-4A60-B9D9-94E2284F425C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D9D09BDC-63D4-47D6-8B93-B8EE979CE519}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E3EBFBBE-3889-4815-95D1-B33CA5532EE2}" = lport=21112 | protocol=6 | dir=in | name=trend micro client/server security agent listener | "{E8377A22-5D23-4DC2-9F5C-135AE63252C3}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{EA6A1AB0-4234-4503-BD35-30F4D298FADC}" = rport=139 | protocol=6 | dir=out | app=system | "{F5665660-0E14-4B6B-A679-9D73E4F92842}" = rport=137 | protocol=17 | dir=out | app=system | "{FA8B5590-368B-4A87-A642-8E3A94933F69}" = lport=445 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0501E290-E712-4EDC-86B4-6E9F45B8B899}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{1477A9D3-B9F1-43C3-BE1C-A4587A21E4A2}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | "{14E07A4B-3107-4249-B553-9499F77D9A5A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{1555980B-6F9C-4B03-B032-308CDC436F21}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{1B60E36E-55DE-43F7-89ED-C10FFB12D018}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{1C09DDD4-8F98-40A7-9BC7-8E4F134561E7}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe | "{27743257-FFB5-4C32-9B0B-0DEA6977802A}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{2A1F029B-34FA-4AE9-9845-9F7D2954B21C}" = dir=in | app=c:\program files\cyberlink\powerdvd9\powerdvd cinema\powerdvdcinema.exe | "{31568BD4-3D90-4EF0-B2BE-A26FF33C64D1}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{4D840685-6B46-4C62-8091-B34F91A5ECE9}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{5DCF28ED-1ADC-4E51-B4AD-90947AB661AD}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{6E98FF04-92B7-4D4B-B738-A9850CD12581}" = dir=in | app=c:\program files\cyberlink\powerdvd9\powerdvd9.exe | "{7577FDFD-0581-4921-AE4A-9845D0194E0E}" = dir=in | app=c:\program files\windows live\mesh\moe.exe | "{88B398ED-9ACC-495B-AEAC-0F31E5402D04}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{8AD26DA5-CFED-4BAD-8103-A5FD1ADB016C}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{A30D0BFA-DDC9-45EB-ADA2-26755651EDF2}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe | "{A36A8D1C-A9F7-46B2-915D-7BCBCBDA6088}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{ACDA607C-CDCF-46C1-AC9F-B986E144D8AB}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{AFFC0DFB-F47C-4CEB-BA00-2D3FAA9E8B78}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | "{C6BFD87C-D7C7-47FC-A025-5966E2F5D57D}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | "{CF0D30C1-ABEE-43DF-A986-3277E6A65073}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{CF16B1D3-2DA1-4AFB-82EA-7F9FAB5FBA25}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{E0DE3F2E-2E21-4B9E-802C-5CAF44FAEF54}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | "{ED03C17F-C1D1-4F71-86FB-821072EC37BF}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{FBCDA905-466E-4646-921E-F8EB5C4A440E}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{FEC565CA-F1F1-4A59-BDA4-AC44625D3418}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{04566294-A6B6-4462-9721-031073EB3694}" = Dell Client System Update "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1945A4B5-73B6-4DE9-99A3-05261B7FDED0}" = Shared C Run-time for x86 "{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 55 "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{418BAAD1-754D-48B4-B078-46EF4F25AF42}" = Google Drive "{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources "{4903D172-DCCB-392F-93A3-34CA9D47FE3D}" = Microsoft .NET Framework 4.5.1 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010 "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010 "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010 "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010 "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010 "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010 "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010 "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9BB9ACB5-5731-4445-A476-1571FA22A3D2}" = Hawaiian Unicode "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9.5 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.9) "{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter "{B7FB9195-E9FC-4316-930E-D799D5D712F7}" = Dell Backup and Recovery Manager "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}" = Realtek Ethernet Controller All-In-One Windows Driver "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX "CNXT_AUDIO_HDA" = Conexant HD Audio "Corel Applications" = Corel Applications "Fitbit Connect" = Fitbit Connect "Google Chrome" = Google Chrome "InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9.5 "McAfee Security Scan" = McAfee Security Scan Plus "MSC" = McAfee AntiVirus "Office14.SingleImage" = Microsoft Office Professional 2010 "WinLiveSuite" = Windows Live Essentials [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 5/8/2014 8:50:20 PM | Computer Name = OfficeA | Source = Application Hang | ID = 1002 Description = The program EXCEL.EXE version 14.0.7109.5000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: e9c Start Time: 01cf6b209b03d826 Termination Time: 16 Application Path: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Report Id: dff375bd-d713-11e3-a3fa-d4bed9bae7e1 Error - 5/9/2014 4:32:24 PM | Computer Name = OfficeA | Source = Application Hang | ID = 1002 Description = The program WINWORD.EXE version 14.0.7121.5004 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 18c Start Time: 01cf6bc29c98595c Termination Time: 0 Application Path: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Report Id: dc0bc778-d7b8-11e3-a3fa-d4bed9bae7e1 Error - 5/9/2014 5:02:11 PM | Computer Name = OfficeA | Source = WinMgmt | ID = 10 Description = Error - 5/9/2014 6:21:41 PM | Computer Name = OfficeA | Source = Application Hang | ID = 1002 Description = The program WINWORD.EXE version 14.0.7121.5004 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: da4 Start Time: 01cf6bd4cda8e49b Termination Time: 15 Application Path: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Report Id: 3d16d2d7-d7c8-11e3-872f-d4bed9bae7e1 Error - 5/12/2014 6:56:26 PM | Computer Name = OfficeA | Source = Microsoft-Windows-Defrag | ID = 257 Description = Error - 5/12/2014 9:42:37 PM | Computer Name = OfficeA | Source = Application Hang | ID = 1002 Description = The program WINWORD.EXE version 14.0.7121.5004 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 48a0 Start Time: 01cf6e4c56281ccf Termination Time: 16 Application Path: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Report Id: c90466cf-da3f-11e3-872f-d4bed9bae7e1 Error - 5/13/2014 2:03:45 PM | Computer Name = OfficeA | Source = WinMgmt | ID = 10 Description = Error - 5/14/2014 9:07:28 AM | Computer Name = OfficeA | Source = Windows Search Service | ID = 3007 Description = Error - 5/14/2014 9:26:27 AM | Computer Name = OfficeA | Source = WinMgmt | ID = 10 Description = Error - 5/15/2014 4:05:32 PM | Computer Name = OfficeA | Source = Application Hang | ID = 1002 Description = The program OTL.exe version 3.2.69.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 14f0 Start Time: 01cf7078808bc960 Termination Time: 6 Application Path: C:\Users\OfficeA\Desktop\OTL.exe Report Id: [ System Events ] Error - 5/7/2014 9:53:48 PM | Computer Name = OfficeA | Source = DCOM | ID = 10016 Description = Error - 5/8/2014 7:28:38 PM | Computer Name = OfficeA | Source = DCOM | ID = 10016 Description = Error - 5/8/2014 7:28:39 PM | Computer Name = OfficeA | Source = DCOM | ID = 10016 Description = Error - 5/10/2014 12:01:56 AM | Computer Name = OfficeA | Source = DCOM | ID = 10016 Description = Error - 5/10/2014 12:01:57 AM | Computer Name = OfficeA | Source = DCOM | ID = 10016 Description = Error - 5/12/2014 1:30:00 AM | Computer Name = OfficeA | Source = DCOM | ID = 10010 Description = Error - 5/13/2014 8:34:53 PM | Computer Name = OfficeA | Source = DCOM | ID = 10016 Description = Error - 5/13/2014 8:34:53 PM | Computer Name = OfficeA | Source = DCOM | ID = 10016 Description = Error - 5/13/2014 11:00:52 PM | Computer Name = OfficeA | Source = DCOM | ID = 10016 Description = Error - 5/13/2014 11:00:53 PM | Computer Name = OfficeA | Source = DCOM | ID = 10016 Description = < End of report >