OTL Extras logfile created on: 6/21/2014 10:51:22 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Crystal\Desktop 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17126) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 5.88 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 68.03% Memory free 7.51 Gb Paging File | 5.60 Gb Available in Paging File | 74.59% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 453.38 Gb Total Space | 417.63 Gb Free Space | 92.12% Space Free | Partition Type: NTFS Drive D: | 22.48 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Drive E: | 14.91 Gb Total Space | 13.53 Gb Free Space | 90.73% Space Free | Partition Type: FAT32 Computer Name: EMBROIDERY | User Name: Crystal | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1078037324-1729035448-2320955734-1001\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{03239A77-77A1-4FE6-930F-739A0770B752}" = rport=10243 | protocol=6 | dir=out | app=system | "{0DCEE370-F975-442E-82DA-430BE0A8CE7F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{29C79355-99CF-42F3-A863-0D79B316661F}" = lport=10243 | protocol=6 | dir=in | app=system | "{39056ADB-E817-4A35-B77E-06191D4DACC8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{614D6F82-466F-455E-8AB9-07EE71506F02}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6BFE9624-7145-49CA-9869-21FE5C083F20}" = lport=2869 | protocol=6 | dir=in | app=system | "{81287C01-7F16-489E-BC5A-4825628B5B6A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BBE63937-40D3-45B9-9D7F-47FB2359F45D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C7C6F5B0-4D88-4B3B-ABA3-AA9D21D720A6}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\outlook.exe | "{D6D1DC0E-7C30-450E-9A2A-02AD312558B1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{061C70E7-2C07-49CD-9B83-368264EE6A48}" = dir=in | name=sonicwall mobile connect | "{0B433CF2-10E6-4183-ADA9-12F561584681}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{0FBEAFFC-D35D-469E-A8AC-0203928CB8B2}" = dir=out | name=@{microsoft.bingmaps_1.6.1821.2624_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{0FF62D3D-644F-4CEE-98ED-1037C371A6D1}" = dir=out | name=ebay | "{12D10F49-BE85-41BC-ADB6-DB41A45AA6A6}" = dir=out | name=netflix | "{14BE4C17-3B0D-4924-A833-46FEE3DF9001}" = dir=out | name=vimeo | "{181ADE56-3B08-41A2-8609-4E6A8906AC01}" = dir=out | name=@{microsoft.bingsports_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{1936CEC4-262F-4255-B10D-DA503E667735}" = dir=out | name=@{microsoft.bingnews_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{22932B52-FACD-4EC2-8DD9-B9B001CE4EC1}" = dir=in | name=check point vpn | "{24B5E24B-E6B8-42D1-905F-1432E6FDD685}" = dir=out | name=juniper networks junos pulse | "{25174F1D-FE8E-42C0-AE0E-2E2F71475E3E}" = dir=in | name=juniper networks junos pulse | "{28153B0E-616F-48CC-97D8-7F65451210EE}" = dir=out | name=@{microsoft.bingsports_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} | "{3247199F-F281-468C-BF7C-CB1F6348C4A8}" = dir=in | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{336DA497-187A-4240-89BC-75D3E63FAC2A}" = dir=out | name=@{microsoft.bingnews_3.0.2.261_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | "{34E01426-735B-47B7-B81E-F1BD82DB1223}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{3567D204-25AA-4221-A1B5-6477D3A5035B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{37C20694-2A55-49C6-90D3-8F90895C713C}" = dir=out | name=book place | "{38E558E5-58CD-46D7-9327-1212D46EA9CD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{417D96D4-553C-4D97-948B-F9D5D2025B44}" = dir=out | name=@{microsoft.zunevideo_2.2.902.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | "{428A7FF8-26BD-479B-B6BC-622E4BBAC8B8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{48778D49-8562-4688-8005-D1BEF4676433}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{4FDD9092-2CD9-4F74-AF1F-A2B352E948F2}" = dir=in | app=c:\users\crystal\appdata\local\microsoft\skydrive\skydrive.exe | "{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | "{56EA2532-A36B-45FB-AFDF-826B1597F270}" = dir=out | name=f5 vpn | "{56F341BA-0D95-459D-B4DC-396068B5BA6B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{57251BCF-66CE-4C7D-B6ED-2003DEDA3A1C}" = dir=out | name=deals & offers | "{57C9E0D6-4277-4D79-AAB2-4EEDE6C8127F}" = dir=out | name=evernote touch | "{58EC523D-7755-4A3A-9817-6DDA479BB54B}" = dir=out | name=norton studio | "{593BB7AF-D7F9-419D-A863-C94F3D72828D}" = dir=out | name=@{microsoft.bingfinance_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} | "{5A342927-35F2-4E8D-AE50-B2DFA9D2678C}" = dir=out | name=windows_ie_ac_001 | "{5B9BFEED-23F8-4878-983C-364B57217376}" = dir=out | name=@{microsoft.xboxlivegames_1.3.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | "{5FBAE6DF-55BE-4D8C-A9D1-34C9269AB5A2}" = dir=out | name=toshiba central | "{6284CC55-BF60-4C07-8704-45F38E39B3B3}" = dir=out | name=@{microsoft.bingmaps_2.1.2922.2139_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{62A4EF57-A79D-44C5-9A87-B1F4BB337D6E}" = dir=out | name=- games app - | "{62C7DDE9-96FE-405C-B2F4-909A60740126}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4396.311_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{66E98A05-9348-40D4-AD26-5FDED12622AC}" = dir=out | name=toshiba media player by smedio truelink+ | "{6712F166-4075-4740-AE31-56C3799A47D4}" = dir=in | name=skype | "{6848B93B-9AC1-45B3-9E31-C5FCA340EF4D}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | "{749FDFDA-1F61-48F0-9B16-58ED21B6870C}" = dir=in | name=f5 vpn | "{75B20DFA-525C-4058-8F8B-BA19A39D711A}" = dir=out | name=stumbleupon | "{75CC5196-69CF-48F9-ADA1-F85F64049574}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | "{791E5F89-73FE-419A-A888-166DA1BB6BCA}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{7CB6C071-8176-4B9E-8F14-2CAF2493F167}" = dir=out | name=windows_ie_ac_001 | "{7FBCC356-39D6-4985-9F6A-595B3BD3AE24}" = dir=out | name=skype | "{80668B75-13C1-4030-9E26-582EDC7CEEF1}" = dir=out | name=amazon | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{84086317-77EB-492F-B384-72DBD04E474F}" = dir=out | name=@{microsoft.windowsphotos_16.4.4396.311_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{8CE9A3C6-DD93-4BB2-9654-03CDBB010674}" = dir=in | name=@{microsoft.windowsphotos_16.4.4396.311_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{8FAB5C1E-BBD1-4518-AB3B-A86947E0C8E3}" = dir=out | name=@{microsoft.bingweather_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{93FC1AD4-82F2-4F42-9C7B-4EE2797F2C20}" = dir=out | name=@{microsoft.zunemusic_1.5.216.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{9564F1DC-3443-45C2-A1B8-AD75B0E846EA}" = dir=out | name=@{microsoft.zunevideo_1.5.902.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{9A2AE5A5-F4CB-4612-99A7-080A4C607397}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{9A4652AF-593D-4A1B-98F9-24BDA9C526D2}" = dir=out | name=check point vpn | "{9C1DA6C0-7501-40C7-9573-E3C1B3FFF4C8}" = dir=in | name=evernote touch | "{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{A3845B6E-44D6-4C05-82E0-D86FD302999C}" = dir=out | name=@{microsoft.bingweather_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{A5F222C3-D7E9-4755-82DF-6B7B48A36B4A}" = dir=out | name=@{microsoft.bingtravel_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{AAEE4D32-330E-42AE-A6AC-0033EF1A834D}" = dir=out | name=@{microsoft.zunemusic_2.2.903.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{B6DFB0EF-4E8E-44C9-9AF7-461AB549B66F}" = dir=out | name=onenote | "{C09D9F11-44AD-407B-8097-FFDB8C41B6D0}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{C0BF0C3D-C1FC-4914-818A-2A19EDF144AC}" = dir=out | name=hulu plus | "{C216A7C3-CA04-4F86-AC8B-E94C484A24C7}" = protocol=6 | dir=out | app=system | "{C3CA013B-18EB-4454-965F-7B8EAABBF0D7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C4A08538-87F8-4F9D-99D7-DFF5B71F44D3}" = dir=out | name=news place | "{CBA702CD-9AEE-4707-9441-AA470B96C737}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20349_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{D101ED23-6E94-4816-B577-6F2455E082F8}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | "{D9FB4A0B-4C85-41CD-858C-CAA984900FEB}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{EA6AD8A9-6946-4138-B752-25F78D0E562E}" = dir=out | name=windows_ie_ac_001 | "{EBE20CCB-3EC2-4F80-9539-D36DD883DB71}" = dir=out | name=iheartradio | "{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | "{ED82296B-5729-40AB-8C81-33806E5F0CD5}" = dir=out | name=@{microsoft.bingtravel_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | "{EDCBC655-A5BF-4386-9C31-CB0B2217C6CB}" = dir=out | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | "{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | "{F9621D57-F5AB-4A14-BAB1-1009F5032167}" = dir=in | name=onenote | "{F96C9E70-3817-4650-8275-99F47D02A7BE}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20349_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{F97C011A-B47C-4653-97FE-3C022BA8755C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{FB92C595-4065-4971-884A-A00D21E90024}" = dir=out | name=sonicwall mobile connect | "{FE84C695-42BB-4A63-9D8C-6D82BA72817E}" = dir=out | name=@{microsoft.bingfinance_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{FF0867D9-0F30-4062-BDCF-450E32419972}" = dir=in | name=toshiba media player by smedio truelink+ | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1515F5E3-29EA-4CD1-A981-032D88880F09}" = TOSHIBA Audio Enhancement "{16562A90-71BC-41A0-B890-D91B0C267120}" = TOSHIBA Function Key "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{2EF33396-F041-49F5-BA3D-39425529CE9C}" = Intel(R) Rapid Storage Technology "{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology "{5944B9D4-3C2A-48DE-931E-26B31714A2F7}" = TOSHIBA eco Utility "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{90150000-008F-0000-1000-0000000FF1CE}" = Office 15 Click-to-Run Licensing Component "{95CCACF0-010D-45F0-82BF-858643D8BC02}" = TOSHIBA Desktop Assist "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 "{CD06BE8E-4E09-4FC6-9098-94F0D6FE86F1}_is1" = Embrilliance version BriTon Leap Embrilliance 1.124 "{DB4D9937-0B14-4EF1-BF9A-BB7E3B9DCB04}" = TOSHIBA HDD Accelerator "{E9F0BCD8-6BD5-1ED7-EDA3-9FCF2A478AA1}" = Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64) "{FA00A3CC-7440-4938-A271-F186F50DD40D}" = Intel® Trusted Connect Service Client "{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}" = TOSHIBA Service Station "{FF07604E-C860-40E9-A230-E37FA41F103A}" = TOSHIBA VIDEO PLAYER "O365HomePremRetail - en-us" = Microsoft Office 365 - en-us "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{90150000-008C-0000-0000-0000000FF1CE}" = Office 15 Click-to-Run Extensibility Component "{90150000-008C-0409-0000-0000000FF1CE}" = Office 15 Click-to-Run Localization Component "{AC76BA86-7AD7-FFFF-7B44-AB0000000001}" = Adobe Reader XI (11.0.07) MUI "{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "Google Chrome" = Google Chrome "HijackThis" = HijackThis 1.99.1 "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.2.1012 "NBRTWizard" = Norton Bootable Recovery Tool Wizard "NIS" = Norton Internet Security [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1078037324-1729035448-2320955734-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "OneDriveSetup.exe" = Microsoft OneDrive [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 4/29/2014 11:29:13 AM | Computer Name = Embroidery | Source = Office 2013 Licensing Service | ID = 0 Description = Error - 4/30/2014 10:29:26 AM | Computer Name = Embroidery | Source = Office 2013 Licensing Service | ID = 0 Description = Error - 5/2/2014 11:48:50 AM | Computer Name = Embroidery | Source = Office 2013 Licensing Service | ID = 0 Description = Error - 5/2/2014 8:40:08 PM | Computer Name = Embroidery | Source = Office 2013 Licensing Service | ID = 0 Description = Error - 5/3/2014 4:07:59 PM | Computer Name = Embroidery | Source = Application Error | ID = 1000 Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16537, time stamp: 0x512347f7 Faulting module name: ntdll.dll, version: 6.2.9200.16578, time stamp: 0x515fac6e Exception code: 0xc0000374 Fault offset: 0x000daa3c Faulting process id: 0x9790 Faulting application start time: 0x01cf63e387871f6f Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: C:\windows\SYSTEM32\ntdll.dll Report Id: 9f6da947-d2fe-11e3-be82-008cfa6ba363 Faulting package full name: Faulting package-relative application ID: Error - 5/3/2014 10:11:10 PM | Computer Name = Embroidery | Source = Office 2013 Licensing Service | ID = 0 Description = Error - 5/3/2014 10:36:59 PM | Computer Name = Embroidery | Source = Application Error | ID = 1000 Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16537, time stamp: 0x512347f7 Faulting module name: jscript9.dll, version: 10.0.9200.16859, time stamp: 0x53117222 Exception code: 0xc0000005 Fault offset: 0x0007d19b Faulting process id: 0x411c Faulting application start time: 0x01cf670cd6bf3a91 Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: C:\Windows\SYSTEM32\jscript9.dll Report Id: f708d735-d334-11e3-be82-008cfa6ba363 Faulting package full name: Faulting package-relative application ID: Error - 5/4/2014 5:28:48 AM | Computer Name = Embroidery | Source = Application Error | ID = 1000 Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16537, time stamp: 0x512347f7 Faulting module name: ntdll.dll, version: 6.2.9200.16578, time stamp: 0x515fac6e Exception code: 0xc0000374 Fault offset: 0x000daa3c Faulting process id: 0x23e8 Faulting application start time: 0x01cf670b5d94f1fb Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: C:\windows\SYSTEM32\ntdll.dll Report Id: 7e615ec2-d36e-11e3-be82-008cfa6ba363 Faulting package full name: Faulting package-relative application ID: Error - 5/4/2014 7:21:51 AM | Computer Name = Embroidery | Source = Application Error | ID = 1000 Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16537, time stamp: 0x512347f7 Faulting module name: jscript9.dll, version: 10.0.9200.16859, time stamp: 0x53117222 Exception code: 0xc0000005 Fault offset: 0x000391a7 Faulting process id: 0x3494 Faulting application start time: 0x01cf670b7bc18e29 Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: C:\Windows\SYSTEM32\jscript9.dll Report Id: 49c44808-d37e-11e3-be82-008cfa6ba363 Faulting package full name: Faulting package-relative application ID: Error - 5/6/2014 8:28:54 PM | Computer Name = Embroidery | Source = Office 2013 Licensing Service | ID = 0 Description = Error - 5/6/2014 8:40:21 PM | Computer Name = Embroidery | Source = Office 2013 Licensing Service | ID = 0 Description = [ System Events ] Error - 6/16/2014 4:16:03 PM | Computer Name = Embroidery | Source = Service Control Manager | ID = 7000 Description = The Computer Backup (MyPC Backup) service failed to start due to the following error: %%1053 Error - 6/16/2014 5:34:54 PM | Computer Name = Embroidery | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installation Failure: Windows failed to install the following update with error 0x80070005: Update for Windows 8 for x64-based Systems (KB2934016). Error - 6/17/2014 3:17:18 AM | Computer Name = Embroidery | Source = Service Control Manager | ID = 7023 Description = The Windows Modules Installer service terminated with the following error: %%5 Error - 6/17/2014 3:18:43 AM | Computer Name = Embroidery | Source = Service Control Manager | ID = 7009 Description = A timeout was reached (30000 milliseconds) while waiting for the Computer Backup (MyPC Backup) service to connect. Error - 6/17/2014 3:18:43 AM | Computer Name = Embroidery | Source = Service Control Manager | ID = 7000 Description = The Computer Backup (MyPC Backup) service failed to start due to the following error: %%1053 Error - 6/17/2014 3:20:34 AM | Computer Name = Embroidery | Source = Service Control Manager | ID = 7009 Description = A timeout was reached (30000 milliseconds) while waiting for the Computer Backup (MyPC Backup) service to connect. Error - 6/17/2014 3:20:34 AM | Computer Name = Embroidery | Source = Service Control Manager | ID = 7000 Description = The Computer Backup (MyPC Backup) service failed to start due to the following error: %%1053 Error - 6/17/2014 10:40:41 AM | Computer Name = Embroidery | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installation Failure: Windows failed to install the following update with error 0x80070005: Update for Windows 8 for x64-based Systems (KB2934016). Error - 6/17/2014 10:45:03 AM | Computer Name = Embroidery | Source = Service Control Manager | ID = 7043 Description = The Windows Update service did not shut down properly after receiving a preshutdown control. Error - 6/17/2014 10:45:04 AM | Computer Name = Embroidery | Source = Service Control Manager | ID = 7038 Description = The WerSvc service was unable to log on as NT AUTHORITY\SYSTEM with the currently configured password due to the following error: %%1352 To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). < End of report >