OTL Extras logfile created on: 7/11/2014 5:52:13 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\SEAN\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17207) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 5.93 Gb Total Physical Memory | 4.40 Gb Available Physical Memory | 74.18% Memory free 11.86 Gb Paging File | 10.35 Gb Available in Paging File | 87.28% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 917.33 Gb Total Space | 681.51 Gb Free Space | 74.29% Space Free | Partition Type: NTFS Computer Name: SEAN-PC | User Name: SEAN | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-3327738456-3466891826-1031852044-1000\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{05295B5A-4AB2-4084-B935-11FA4E67F33A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{0D89D9A0-E76F-4639-ACD7-C24BADA0AD66}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1C08E8A3-2A05-4030-BD97-31F033D5D04D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{305F738F-6DB7-45E8-8605-D8324EEC7673}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{46E0580E-4353-4167-A1E5-D973FD104EDB}" = rport=445 | protocol=6 | dir=out | app=system | "{487D901B-E774-46A3-AE0F-9D8D3C80169E}" = rport=137 | protocol=17 | dir=out | app=system | "{4CB888CD-9762-4474-9416-469BFF272C77}" = lport=137 | protocol=17 | dir=in | app=system | "{4DCC4AA9-7244-4E55-9AF2-E7EFBD7C85C0}" = lport=2869 | protocol=6 | dir=in | app=system | "{51C44C42-C6D3-411F-A6D4-A08FE6D41E84}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{65B26EB7-D165-4FD6-8271-972DB2320EF6}" = lport=139 | protocol=6 | dir=in | app=system | "{754FB184-82B6-415A-A81B-340356BC975D}" = rport=138 | protocol=17 | dir=out | app=system | "{75AACA83-2314-4C9D-945C-70456419E65D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{8C1E2BFB-150C-4936-850A-45079BD8B6B4}" = lport=138 | protocol=17 | dir=in | app=system | "{A2D728CD-4EC9-4E3A-97EE-D73FA1E7CF41}" = lport=445 | protocol=6 | dir=in | app=system | "{B50E305B-D1A3-4101-B084-DFE0E7A39D34}" = rport=139 | protocol=6 | dir=out | app=system | "{BAEDCE8E-0C4C-472D-8C8E-F3E7706AC504}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BE2928FA-A12F-4C67-8836-499CD4D35A81}" = lport=10243 | protocol=6 | dir=in | app=system | "{C5101AF2-A5B7-45FC-A2E6-83986F590550}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{C7F82EFD-964D-434A-BBA5-7EE36C0C2098}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D6FEB73D-9655-4AF8-8326-9A2C1081C1E7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D958A239-FA35-4111-83D5-33C126250DDF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{DDE8916F-DAB9-4995-8BA2-06ACAFC8F87B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{DE7C6931-074D-4C21-9A34-AC97EF3DE477}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{FA57011D-C632-4967-BB3C-485A53FE99B3}" = rport=10243 | protocol=6 | dir=out | app=system | "{FBCC27AF-DBAF-4CF5-9887-9982B7BF29E6}" = lport=2869 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0129349C-40EF-4955-92D4-47CEBA0F3D43}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe | "{02BC98C4-C81E-44F5-92B5-6707C937140C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{0426CD86-FAAC-4FAA-AB02-1397146489AE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\bevsattic@earthlink.net\day of defeat\hl.exe | "{0F7AEE1E-1399-4017-AAC6-CF1B5DFEC8A6}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1124E10C-9B52-4488-9090-750263E15CAF}" = protocol=6 | dir=out | app=system | "{12C9D767-2A31-4C87-9D1D-75664F22AD58}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{1C01B3C7-BB7F-4050-A079-24D640F9F56B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{214DD1EE-C716-4162-BA1B-6AC291048BC6}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{222E6C10-245E-4029-8C40-72CA81EB5D24}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{28A38C1D-96DD-4424-BCFE-6ADEC9928FAA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{309BC90B-13B9-41BD-8853-602A9F6D5806}" = protocol=17 | dir=in | app=c:\program files (x86)\cyanide\blood bowl\bb.exe | "{31A915FD-35B0-4B7D-8F77-65F91F4D7E28}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{34B86C57-565E-4AA4-90DF-D3F1D3A680CD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{3BD85BA7-F530-4869-8B57-63FB49E719EC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{3F9A044D-BAAD-40E9-967A-97F4875030B1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{40BE9FE8-4486-42E7-8DE8-516C5BA794B2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{434C6A86-1520-4C6E-8DAF-45DBCE1E9F2F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{43C38D25-5233-431B-B995-2A544F9EF239}" = protocol=17 | dir=in | app=c:\program files (x86)\army builder\armybuilder.exe | "{47002A38-E5D8-4851-9197-947EA5C6C962}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{48FDA22C-C7D7-482E-872A-1342C10D58E5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\warman099\day of defeat source\hl2.exe | "{4A829D2C-8F16-4048-B9E7-95C47A140D90}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{4C7ED71C-4BEB-4842-8A86-181A4B1FBE41}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{568509D9-57E1-4316-B267-EC1B0C9F39A6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes 2\reliccoh2.exe | "{5B3B48C7-3F30-452C-859D-EFC57CEB4A60}" = protocol=17 | dir=in | app=c:\program files (x86)\trion worlds\end of nations\rtsclientg.exe | "{6010FBD0-49F6-470A-ABB8-34DB8566D9DC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes 2\reliccoh2.exe | "{62522FAC-7188-49E8-915A-7F5DBC69A5F7}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "{71B51A83-8755-40B0-883A-01F4870D8192}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\warman099\day of defeat source\hl2.exe | "{75FD412E-ECCB-4D48-BE10-2D843B4AA1BB}" = protocol=6 | dir=in | app=c:\program files (x86)\army builder\armybuilder.exe | "{762F67D6-B791-472D-A761-577E8D99645B}" = protocol=6 | dir=in | app=c:\program files (x86)\trion worlds\end of nations\rtsclientg.exe | "{7ED33111-8FEB-4063-8D92-B278993B3E9B}" = protocol=17 | dir=in | app=c:\program files (x86)\cyanide\blood bowl\autorun\exe\autorun.exe | "{7EEF1FC2-3088-4F69-8655-18740A2DD3B7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\bevsattic@earthlink.net\day of defeat\hl.exe | "{828FAB68-6A9F-4181-95B1-86E3BC24966C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\warman099\empires\hl2.exe | "{839C0FA8-B0AA-469D-9A17-F62BAE881614}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\warman099\empires\hl2.exe | "{8DFC3B17-6678-461F-A346-FEB6D79EAC68}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe | "{98097406-A5D2-457B-B1A8-624FE36CD265}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warhammer 40,000 space marine demo\spacemarine.exe | "{9F89B7AD-1BDA-4EB5-8764-A3CB154E6398}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warhammer 40,000 space marine demo\spacemarine.exe | "{A0439AB2-4EFD-4AC0-8F60-1784D3821E46}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{A47CA34C-FBD7-46DE-B5D2-1879EE0EE7E1}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{AAC7E494-911E-476D-8F79-5A274ACF42EC}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe | "{B027D837-99A4-4B4B-9ACA-971AFD27F7AB}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe | "{BA9888EA-E541-441E-AED5-96EBE4E303FB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{BC9FEFA2-3013-4096-85C7-5A7DDF40787F}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe | "{BEE82FEA-7751-4C00-84E3-016F0380C3C1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\warman099\source sdk base 2007\hl2.exe | "{BFA695AA-333B-4D1E-916A-E97846F4F06C}" = protocol=6 | dir=in | app=c:\program files (x86)\heroes & generals\live\hng.exe | "{C4EEBB47-3A01-451E-86A4-81D9EFFA27AB}" = protocol=6 | dir=in | app=c:\program files (x86)\cyanide\blood bowl\bb.exe | "{CA5CED81-4B1F-484D-A41F-E91F47F536D8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\warman099\source sdk base 2007\hl2.exe | "{D01A1CE1-7F7A-48F9-8E95-8A2E766EC824}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{D808D00F-41B2-472E-9F2A-46E1733A9395}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{DAC5B3D0-3D69-459D-9D00-5F8E259359C0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{DEE071D2-1D59-496B-8E81-96C674C34C39}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetary annihilation\pa.exe | "{E014A00B-6D85-4D2D-B84C-D839C9D3C99E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{E0E45973-2B89-4989-9BF0-30B9A860D2AF}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe | "{E11155B5-2FBD-41E3-A0D7-E4DEECAC92C2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{E5C740BC-6DE5-4FE2-8BB8-CC58E307EFB8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E8B2243E-29B0-4710-A146-E2568EF9F853}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetary annihilation\pa.exe | "{E97500DF-D488-4125-93B5-64C759BF5653}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | "{ECB9AF75-A052-46BC-85AA-8C4A5C8EF987}" = protocol=17 | dir=in | app=c:\program files (x86)\heroes & generals\live\hng.exe | "{ED481594-5950-48CA-9532-89E78B8E1148}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{FA229E17-C594-414D-8B3E-DB82BA5FD71E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{FB0EA81E-68F1-4F62-8673-D005B8FFC83B}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{FB6435C0-E1DF-4833-89D8-92907685AB36}" = protocol=6 | dir=in | app=c:\program files (x86)\cyanide\blood bowl\autorun\exe\autorun.exe | "{FEC5CC43-DC9E-4C03-AF82-1CDE47744996}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "TCP Query User{0338D0D6-26E1-4B2C-AA48-C684CF92A1C1}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | "TCP Query User{1ABBF256-3108-486A-8E99-BAE3A6F51E7B}C:\program files (x86)\ea\bioware\star wars - the old republic\betatest\retailclient\swtor.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ea\bioware\star wars - the old republic\betatest\retailclient\swtor.exe | "TCP Query User{37C015F5-9BE4-4719-B7C4-4ADF6E838FA4}C:\program files (x86)\battle for wesnoth 1.10.7\wesnothd.exe" = protocol=6 | dir=in | app=c:\program files (x86)\battle for wesnoth 1.10.7\wesnothd.exe | "TCP Query User{3B80F7A5-7BE1-467A-9413-4B857C7F14D0}C:\program files (x86)\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xfire\xfire.exe | "TCP Query User{5A360757-76C1-436F-933E-1D0057B40B8E}C:\program files (x86)\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xfire\xfire.exe | "TCP Query User{7026942F-767B-4374-A9DA-2460ED8B885D}C:\games\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | "TCP Query User{83BA77C0-C9DE-4B98-A0FF-D5C9C8F78B90}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe | "TCP Query User{8DC4328B-7F4E-422B-AE6F-17F0584FAF00}C:\program files (x86)\hi-rez studios\games\global agenda live\binaries\globalagenda.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hi-rez studios\games\global agenda live\binaries\globalagenda.exe | "TCP Query User{8DE86634-3392-4F11-AB46-3AD2E9B3F7A5}C:\users\public\sony online entertainment\installed games\planetside 2\planetside2.exe" = protocol=6 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2\planetside2.exe | "TCP Query User{949BC129-2C4C-4FE0-94D7-BD5B1BB90DEB}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe | "TCP Query User{9C6147EB-87EC-4A0E-BB4A-581AD3F241AC}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe | "TCP Query User{ADBFDBFB-C704-422D-A3CE-5F694D1083B8}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe | "TCP Query User{AE2F72F3-8C3D-4AB6-ADAF-876EF4C38F15}C:\program files (x86)\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "TCP Query User{BDA1FA36-FF02-429E-8726-921C6F5802C4}C:\program files (x86)\hi-rez studios\games\tribes alpha\binaries\win32\tribesascend.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hi-rez studios\games\tribes alpha\binaries\win32\tribesascend.exe | "TCP Query User{D3B1AD14-91D9-4638-8533-290F0EF62FA2}C:\program files (x86)\starcraft ii\versions\base19132\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19132\sc2.exe | "TCP Query User{E6CEC24C-245D-4066-B0F3-1D013FD30A83}C:\games\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\games\warcraft iii\war3.exe | "TCP Query User{F00FB0A0-E9C8-4DAD-A1B6-4412A9005321}C:\program files (x86)\steam\steamapps\warman099\counterstrike source beta\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\warman099\counterstrike source beta\hl2.exe | "TCP Query User{F25D410F-E3BC-463F-ACDC-9F486C974232}C:\program files (x86)\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe | "TCP Query User{F88E8E3C-AA1D-4C84-8961-5F3FFD4C6C80}C:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe | "UDP Query User{015CE494-A246-4BAC-B239-737D6C573B3B}C:\users\public\sony online entertainment\installed games\planetside 2\planetside2.exe" = protocol=17 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2\planetside2.exe | "UDP Query User{02A00042-3BA9-4681-9A23-73ACC22EEE94}C:\program files (x86)\steam\steamapps\warman099\counterstrike source beta\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\warman099\counterstrike source beta\hl2.exe | "UDP Query User{0AE28925-FD1E-4434-9C76-430495DAA395}C:\program files (x86)\starcraft ii\versions\base19132\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base19132\sc2.exe | "UDP Query User{1267D2C5-A2F2-4881-9BD9-8D1ED0033219}C:\program files (x86)\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xfire\xfire.exe | "UDP Query User{2EC068DB-52FE-4562-AD15-1AE6F3A9E183}C:\program files (x86)\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe | "UDP Query User{4CD17743-FE6D-4A55-A3C1-6D4227842337}C:\program files (x86)\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "UDP Query User{57BEA488-E2BA-4AC2-9803-457F70ED52D4}C:\program files (x86)\ea\bioware\star wars - the old republic\betatest\retailclient\swtor.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ea\bioware\star wars - the old republic\betatest\retailclient\swtor.exe | "UDP Query User{673F0BDE-B848-41C7-93FC-B94571549A8C}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe | "UDP Query User{6D50D0FA-EED7-4B42-98AF-704BADC32EE9}C:\games\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\games\warcraft iii\war3.exe | "UDP Query User{94E60838-9838-48F8-835B-D296BCA49FB6}C:\program files (x86)\hi-rez studios\games\global agenda live\binaries\globalagenda.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hi-rez studios\games\global agenda live\binaries\globalagenda.exe | "UDP Query User{97E50254-CD49-4C71-A8AF-64AABB2873F5}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe | "UDP Query User{AEE238C5-BC6E-428F-8600-142AE6029514}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe | "UDP Query User{B8884CFB-F2F7-4FEC-9454-6EB3E3BEBF6B}C:\games\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | "UDP Query User{BC9EA22E-9B00-4E2E-B806-255FC6B1124C}C:\program files (x86)\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xfire\xfire.exe | "UDP Query User{E84B4C5B-90DC-4F98-ABFF-CE00823AEC22}C:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe | "UDP Query User{EA58C632-4E08-4423-9FA4-09242D2DF6BD}C:\program files (x86)\hi-rez studios\games\tribes alpha\binaries\win32\tribesascend.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hi-rez studios\games\tribes alpha\binaries\win32\tribesascend.exe | "UDP Query User{EC2EEAFC-5AF4-4F3B-9D51-21427062AB7F}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | "UDP Query User{FA5BA39B-8C5F-455C-ABEA-A7B0F203A66E}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe | "UDP Query User{FC9C85EA-D94C-4FC7-BDBD-46B67E4AAC4A}C:\program files (x86)\battle for wesnoth 1.10.7\wesnothd.exe" = protocol=17 | dir=in | app=c:\program files (x86)\battle for wesnoth 1.10.7\wesnothd.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety "{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{9301985B-D116-4A93-A93D-94580084FF86}" = 64 Bit HP CIO Components Installer "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 311.06 "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 311.06 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 311.06 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.1.13.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{124C9BD0-8C52-40AB-8238-0605703B1C28}" = ASUS Backup Wizard "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool Help "{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help "{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 24 "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{335efe23-626a-4398-92db-35a92a73a7ff}" = Nero 9 Essentials "{3365E735-48A6-4194-9988-CE59AC5AE503}" = Bing Bar "{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2 "{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF001}" = Global Agenda Live "{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF010}" = Tribes Ascend Closed Beta "{3FA7A919-87DA-42B1-814B-86DE8DCA17C2}" = gmax "{43867B63-C464-4570-823D-D92DC08E3400}_is1" = Army Builder 3.4c "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4AF95DE2-B54D-4C3F-9494-FD3B558E2C2D}" = AI Manager "{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform "{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion "{55E61709-D7D4-43C0-B45D-BFAF5C09A02D}" = OpenOffice 4.0.0 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate "{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress "{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack "{6F6F39E3-D24D-4EEE-9AEA-DEDAF991385D}" = DWA-130 "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{722AF0E9-9BAB-4556-9AA6-B5240D46E4B3}" = Global Agenda Launcher "{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart "{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.16 "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8F66047B-1AF3-40D9-80D7-106E2EDC2C2A}" = EPU-4 Engine "{924DAFFB-CA84-43a3-8205-A6E94461EC79}_is1" = Registry Reviver "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0) "{AEB719FD-EDB0-43E9-B524-90F97C1E6499}" = System Update kb70007 "{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync "{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center "{B4E343DD-BAAB-4D59-AD9C-DEA0AFE09DF1}" = Mumble 1.2.3 "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX "{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed Help "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade "{DBD1FF41-F438-4D0A-A3F1-999930B5BC52}" = Command & Conquer™ Red Alert™ 3 Demo "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed Help "{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F3D2DEDC-4732-4188-8A3A-1A3FFBD4D6C8}" = ebi.BookReader3J "{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter "{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights Help "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "Adobe Flash Player ActiveX" = Adobe Flash Player 14 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 14 Plugin "ASUS VIBE" = ASUS VIBE "ATC_is1" = Advanced Tactical Center™ 1.0 "Avast" = avast! Free Antivirus "Battle for Wesnoth 1.10.7" = Battle for Wesnoth 1.10.7 "BloodBowl_is1" = Blood Bowl version 1.2.0.1 "FeedReader_is1" = FeedReader "Heroes & Generals" = Heroes & Generals "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.2.1012 "Mozilla Firefox 30.0 (x86 en-US)" = Mozilla Firefox 30.0 (x86 en-US) "MozillaMaintenanceService" = Mozilla Maintenance Service "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "Precision" = EVGA Precision 2.0.3 "PunkBusterSvc" = PunkBuster Services "StarCraft II" = StarCraft II "Steam App 17740" = Empires "Steam App 231430" = Company of Heroes 2 "Steam App 233250" = Planetary Annihilation "Steam App 240" = Counter-Strike: Source "Steam App 260" = Counter-Strike: Source Beta "Steam App 271290" = HAWKEN "Steam App 30" = Day of Defeat "Steam App 300" = Day of Defeat: Source "Steam App 55410" = Warhammer 40,000: Space Marine Demo "TeamSpeak 3 Client" = TeamSpeak 3 Client "VASSAL (3.2.8)" = VASSAL (3.2.8) "Warcraft III" = Warcraft III "WinGimp-2.0_is1" = GIMP 2.6.11 "WinLiveSuite" = Windows Live Essentials "WinRAR archiver" = WinRAR 5.01 (32-bit) "World of Warcraft" = World of Warcraft "Xfire" = Xfire (remove only) [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-3327738456-3466891826-1031852044-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "48e4cff94f039634" = Best Buy pc app "GoToMeeting" = GoToMeeting 4.5.0.457 "RIFT" = RIFT "SOE-PlanetSide 2" = PlanetSide 2 "Warcraft III" = Warcraft III: All Products [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 6/27/2014 2:07:54 PM | Computer Name = SEAN-PC | Source = Microsoft Security Client Setup | ID = 100 Description = HRESULT:0x8004FF0A Description:Microsoft Security Essentials installation was canceled. You canceled the Security Essentials installation on your computer. Error code:0x8004FF0A. Error - 6/27/2014 2:08:17 PM | Computer Name = SEAN-PC | Source = Application Hang | ID = 1002 Description = The program firefox.exe version 30.0.0.5269 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: fe4 Start Time: 01cf92320328ef85 Termination Time: 66 Application Path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Report Id: 00010f4e-fe26-11e3-b20a-20cf30e790ce Error - 6/27/2014 8:27:48 PM | Computer Name = SEAN-PC | Source = Microsoft-Windows-CAPI2 | ID = 512 Description = The Cryptographic Services service failed to initialize the VSS backup "System Writer" object. Details: Could not query the status of the EventSystem service. System Error: A system shutdown is in progress. . Error - 6/28/2014 11:46:59 PM | Computer Name = SEAN-PC | Source = Application Error | ID = 1000 Description = Faulting application name: mbam.exe, version: 1.0.0.532, time stamp: 0x53518532 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x681ec4d6 Faulting process id: 0xbb0 Faulting application start time: 0x01cf934cb9a61551 Faulting application path: C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe Faulting module path: unknown Report Id: 0550669e-ff40-11e3-b210-20cf30e790ce Error - 7/1/2014 9:29:10 PM | Computer Name = SEAN-PC | Source = System Restore | ID = 8193 Description = Error - 7/1/2014 10:31:13 PM | Computer Name = SEAN-PC | Source = Microsoft-Windows-CAPI2 | ID = 512 Description = The Cryptographic Services service failed to initialize the VSS backup "System Writer" object. Details: Could not query the status of the EventSystem service. System Error: A system shutdown is in progress. . Error - 7/5/2014 4:16:49 PM | Computer Name = SEAN-PC | Source = Application Error | ID = 1000 Description = Faulting application name: mbam.exe, version: 1.0.0.532, time stamp: 0x53518532 Faulting module name: mbamcore.dll, version: 1.0.11.0, time stamp: 0x536d8027 Exception code: 0xc0000005 Fault offset: 0x0006ed38 Faulting process id: 0xa24 Faulting application start time: 0x01cf988de9ac551f Faulting application path: C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe Faulting module path: C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamcore.dll Report Id: 4b1004fa-0481-11e4-9275-20cf30e790ce Error - 7/6/2014 8:58:26 PM | Computer Name = SEAN-PC | Source = Application Error | ID = 1000 Description = Faulting application name: mbam.exe, version: 1.0.0.532, time stamp: 0x53518532 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x00013ece Faulting process id: 0xc1c Faulting application start time: 0x01cf997e7e731243 Faulting application path: C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe Faulting module path: unknown Report Id: ccf6e5a5-0571-11e4-91ed-20cf30e790ce Error - 7/7/2014 10:32:34 PM | Computer Name = SEAN-PC | Source = Application Error | ID = 1000 Description = Faulting application name: mbam.exe, version: 1.0.0.532, time stamp: 0x53518532 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x00000000 Faulting process id: 0xa98 Faulting application start time: 0x01cf9a54ca93560c Faulting application path: C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe Faulting module path: unknown Report Id: 1dcafe33-0648-11e4-9f53-20cf30e790ce Error - 7/9/2014 7:21:50 AM | Computer Name = SEAN-PC | Source = Application Error | ID = 1000 Description = Faulting application name: mbam.exe, version: 1.0.0.532, time stamp: 0x53518532 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x6e690101 Faulting process id: 0x190 Faulting application start time: 0x01cf9b67db47d6fe Faulting application path: C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe Faulting module path: unknown Report Id: 3843b659-075b-11e4-b8b1-20cf30e790ce [ System Events ] Error - 7/11/2014 6:49:44 PM | Computer Name = SEAN-PC | Source = Service Control Manager | ID = 7001 Description = The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: %%1068 Error - 7/11/2014 6:51:41 PM | Computer Name = SEAN-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 7/11/2014 6:51:41 PM | Computer Name = SEAN-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 7/11/2014 6:51:41 PM | Computer Name = SEAN-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 7/11/2014 6:56:41 PM | Computer Name = SEAN-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 7/11/2014 6:56:41 PM | Computer Name = SEAN-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 7/11/2014 6:56:41 PM | Computer Name = SEAN-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 7/11/2014 6:58:49 PM | Computer Name = SEAN-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 7/11/2014 6:58:49 PM | Computer Name = SEAN-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 7/11/2014 6:58:49 PM | Computer Name = SEAN-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 < End of report >