OTL Extras logfile created on: 12/20/2014 12:14:47 PM - Run 9 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\cass\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17501) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.75 Gb Total Physical Memory | 1.98 Gb Available Physical Memory | 52.77% Memory free 7.50 Gb Paging File | 4.07 Gb Available in Paging File | 54.32% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 687.76 Gb Total Space | 415.75 Gb Free Space | 60.45% Space Free | Partition Type: NTFS Drive D: | 10.77 Gb Total Space | 1.54 Gb Free Space | 14.27% Space Free | Partition Type: NTFS Drive F: | 1863.01 Gb Total Space | 362.45 Gb Free Space | 19.46% Space Free | Partition Type: NTFS Drive H: | 2794.51 Gb Total Space | 336.51 Gb Free Space | 12.04% Space Free | Partition Type: NTFS Computer Name: CASS-PC | User Name: cass | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (All) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .chm [@ = chm.file] -- "%SystemRoot%\hh.exe" %1 .cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation) .hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation) .txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .bat [@ = batfile] -- "%1" %* .chm [@ = chm.file] -- "%SystemRoot%\hh.exe" %1 .cmd [@ = cmdfile] -- "%1" %* .com [@ = ComFile] -- "%1" %* .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .exe [@ = exefile] -- "%1" %* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l .js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .pif [@ = piffile] -- "%1" %* .reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation) .scr [@ = scrfile] -- "%1" /S .txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{039A7B8C-ED07-485F-AF9E-F2E879C09F6B}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{041D1A5E-7011-4035-9BC8-985584CFDC24}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) | "{0563DC36-70D9-477F-9A28-F1104FC7207F}" = rport=5357 | protocol=6 | dir=out | app=system | "{06A45ECB-1145-4260-B405-B6FCA2EF6FB3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{08C4BF99-85B5-47FE-B5A7-911763DA1A8E}" = lport=rpc | protocol=6 | dir=in | svc=schedule | app=%systemroot%\system32\svchost.exe | "{0C874156-FF7B-4D7D-B5F3-FC8D5476BFDB}" = lport=rpc | protocol=6 | dir=in | svc=policyagent | app=%systemroot%\system32\svchost.exe | "{0EFB35F3-E69F-4B09-957A-77F8A2CB498A}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe | "{130C69E9-EDFE-4334-ABEF-DC6315C72036}" = lport=162 | protocol=17 | dir=in | svc=snmptrap | app=%systemroot%\system32\snmptrap.exe | "{15C77775-A520-42ED-A4E2-F2BD542ED0FE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{15E1221E-AA85-4C8D-9883-ECE9701D2604}" = lport=10243 | protocol=6 | dir=in | app=system | "{17BCC1B8-511A-47B7-88BE-B98B48373BEA}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{18908CD9-DB0C-4C21-88DC-23C12EAB08AE}" = lport=10244 | protocol=6 | dir=in | app=system | "{1960D59A-E70C-4826-B24C-F1CD3E32A227}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{1971234C-3C1F-4509-93B4-3726CB0CF90D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{19E556DC-88A9-4900-B655-EC53E4744EC3}" = lport=5358 | protocol=6 | dir=in | app=system | "{1BC3EE68-619D-4890-8E1E-EFD8B12C1725}" = lport=3390 | protocol=6 | dir=in | app=system | "{1BC63C2A-A0F4-4FA8-9270-194D16E7A096}" = lport=2869 | protocol=6 | dir=in | app=system | "{1E3D06D2-110C-4B17-93A5-1912B51B5A5D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=%systemroot%\system32\svchost.exe | "{217032AD-1790-4A54-ACC7-A9A062431896}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=%systemroot%\system32\svchost.exe | "{2418CE80-0B64-4782-8715-26732DAC0073}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{281AFCA0-8271-4556-964F-AA475394330A}" = lport=5985 | protocol=6 | dir=in | app=system | "{284A0B60-A1F5-462F-855D-F52C6D806D7B}" = lport=137 | protocol=17 | dir=in | app=system | "{28BB899C-ABA5-4D4B-9B07-F122E7F8F0F4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2BF4E92B-5141-4262-9679-2E19A1389ADA}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe | "{30FC3760-A1E8-47C4-AB40-87B2384946B3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{326B5F30-E835-4585-8AE8-1FBF1E03DCFB}" = rport=5358 | protocol=6 | dir=out | app=system | "{36D491EF-629C-473E-A793-E0F98C15090F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{3CD29D69-3BCD-4BDB-8686-77F59A9E3ADB}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe | "{3CE6A8FF-9B9C-4363-BB94-7B28FCFEEC88}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe | "{3CE93967-6133-4A4F-B461-6B3A31250EBE}" = lport=7679 | protocol=6 | dir=in | name=allshareframeworkdms service tcp port2 | "{3F7BF286-42DC-4351-817A-44A65265B6E8}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{409B1E0D-507C-4A7C-937B-467925AE515B}" = lport=5357 | protocol=6 | dir=in | app=system | "{453BCD73-BB6B-4E68-A811-9DA66D2E5BDE}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe | "{48D9539D-5E12-4497-83BE-51543E589A9C}" = lport=rpc | protocol=6 | dir=in | svc=vds | app=%systemroot%\system32\vds.exe | "{491122D5-E329-463A-A94D-64CE5D8343E0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{4EB7BE77-6720-4E99-912A-0CDD56BB3D85}" = lport=445 | protocol=6 | dir=in | app=system | "{50949562-3D5F-49E7-8748-86C026C1BDDB}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=%systemroot%\system32\svchost.exe | "{58686822-3545-4579-851D-C67594E22186}" = lport=10245 | protocol=6 | dir=in | app=system | "{6397EC8D-B263-40B9-8187-1F625E3966C7}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe | "{65D7BA1F-D308-4130-86AD-538D2090F337}" = lport=1723 | protocol=6 | dir=in | app=system | "{66E323B1-9C14-4E1B-B550-991907ED1D97}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe | "{66F822A1-B37B-4CFF-A48F-6F1CB8669BAF}" = lport=1701 | protocol=17 | dir=in | app=system | "{6D1F97A0-7D83-4A6E-83B2-D7ED895FE2E6}" = lport=138 | protocol=17 | dir=in | app=system | "{7312DCA4-215B-42A2-A0E5-86CE6DF74313}" = lport=8643 | protocol=6 | dir=in | name=allshareframeworkdms event tcp port | "{75AAD759-C6F9-42A5-9E23-53D493DC30B6}" = rport=1723 | protocol=6 | dir=out | app=system | "{79DE3EB3-FA73-4DF0-A533-85ADDA980F1C}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{7A78A0CC-EDF9-4680-9505-61B1D2AEA610}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{80229648-D342-4CEC-84CF-E757EFC7B82F}" = lport=2869 | protocol=6 | dir=in | app=system | "{80796F2A-0814-4DCC-AC21-A9F2C8EEE17B}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe | "{82DCF367-4766-4E11-A690-5468676EF86C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{85267C59-45D0-4C51-A9E6-7C839D9604E3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{859B1E67-7BDA-48A2-8D6E-13388DD62C07}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{874CC749-096C-491B-8E59-F0608079666A}" = rport=10243 | protocol=6 | dir=out | app=system | "{959E5535-6383-4807-BF7D-258033BA6FAE}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=%systemroot%\system32\svchost.exe | "{9777315F-D389-4F0D-A943-971AD7AFB3A5}" = lport=rpc | protocol=6 | dir=in | svc=ktmrm | app=%systemroot%\system32\svchost.exe | "{99C82F5F-3338-4D5B-B06C-6742CB42B614}" = lport=1900 | protocol=6 | dir=in | name=upnp multicast port | "{9D4731DD-4217-4088-BAFE-F14BE96A7211}" = lport=8743 | protocol=6 | dir=in | name=allshareframeworkdms action tcp port | "{9E4DFB56-1D98-44ED-8F37-8080D1D49F88}" = lport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{A0B119D5-8330-49D9-9F6D-FDDECC1AB940}" = lport=rpc | protocol=6 | dir=in | svc=eventlog | app=%systemroot%\system32\svchost.exe | "{A246DD5C-E4C5-43BD-A5CB-28430133DEF0}" = lport=80 | protocol=6 | dir=in | app=system | "{A949999D-A0D7-4CFC-8D21-67900716AA18}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{AB6502FA-A8D8-46E5-B879-0D5D65597C90}" = lport=7900 | protocol=6 | dir=in | name=allshareframework dms service udp port2 | "{AC069EE9-C4C9-4694-B3BA-F984E69B627D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{AD0D4942-9304-495A-AE60-29C86DD8E2E6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=%systemroot%\system32\svchost.exe | "{AD2E26BD-6FD2-4854-B01E-FE82734ACA82}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{AE2AE184-00C2-49E4-AF74-A7EA808059AA}" = lport=139 | protocol=6 | dir=in | app=system | "{B2BABE26-2AC2-4F20-8C2E-8E0B4D795B9D}" = lport=445 | protocol=6 | dir=in | app=system | "{B581DB79-8C8E-4EDC-B9BF-AE35B054D47C}" = rport=445 | protocol=6 | dir=out | app=system | "{B5B9E293-FF65-412B-B7F3-EA9AF3C3838D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B96BF336-AC38-4A1F-A115-42563603734F}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{BBAF6EA9-DAD3-4C48-8FE2-031D6FE9C6CA}" = lport=rpc | protocol=6 | dir=in | app=%systemroot%\system32\services.exe | "{BC81BEBE-AD53-48A5-9A8B-06BC04D597C2}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BF633137-B4E8-4B22-87AE-09055C7A76C8}" = rport=138 | protocol=17 | dir=out | app=system | "{C06BB1D0-3C79-4A0D-ABFC-5D435B01F33A}" = rport=1701 | protocol=17 | dir=out | app=system | "{C3FCED42-80F7-432B-ABE9-562290F9AEFD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{C5C1B774-38CD-4BC7-A8DB-7784FF8795CA}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=%systemroot%\system32\svchost.exe | "{C85842DC-FFAA-4CA4-8E1E-EE2231062B13}" = rport=139 | protocol=6 | dir=out | app=system | "{CB1A6FEB-29A5-4997-8ED7-89AEB1B417FB}" = lport=rpc | protocol=6 | dir=in | app=%systemroot%\system32\vdsldr.exe | "{CBDD39A7-808B-43C2-B5FC-7502B978526E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CD100045-1A43-41B1-A9C2-869A960B3F5E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CD970C46-E3BA-4D79-A059-87629430B26E}" = lport=7676 | protocol=6 | dir=in | name=allshareframeworkdms service tcp port1 | "{CFCEE8B3-DAB8-488F-A0A2-C60228ED8D4E}" = lport=445 | protocol=6 | dir=in | app=system | "{D505FFA6-58EF-4FAF-B4AD-DF0925806B62}" = rport=137 | protocol=17 | dir=out | app=system | "{D6DFF10B-58DB-4C53-AE21-4E0C2E7E92D8}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D939A8A3-E82A-4444-A579-8251697CD82B}" = lport=2869 | protocol=6 | dir=in | app=system | "{DA3B13AF-0BCE-47FA-9111-5E4B9F549C79}" = lport=445 | protocol=6 | dir=in | app=system | "{E7F6827A-A8F8-467E-8AF1-93ADE220891B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E933BB24-8004-4AB2-BD10-421F725F3E86}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{ED26C14B-9CC4-4C16-8BB8-365679C22026}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=%systemroot%\system32\svchost.exe | "{EFB6319A-F5D2-4809-B950-56BBB59127BC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F1844CF9-D87C-4646-84F6-7B8EA2953E62}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{F4F3FD0A-ADE2-424A-B91D-1E63139232AC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F785FBF1-8AAC-41AF-B9F1-ADC9AA1C9C92}" = lport=443 | protocol=6 | dir=in | app=system | "{F968D33C-6E34-46A0-88DB-A28E2AB00DEB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=%systemroot%\system32\svchost.exe | "{FC76BAB4-8D8D-4A2C-B1B8-8791C383A74E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{FF6FF4C4-468E-47B0-8587-E8F14A4DF732}" = lport=24234 | protocol=6 | dir=in | name=allshareframework dms service udp port1 | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04EC3B70-C4B9-41E6-A16F-B365A3595E99}" = protocol=17 | dir=in | app=c:\users\cass\appdata\local\temp\7zsd0f4.tmp\symnrt.exe | "{08561D5D-C3FB-4209-8BFA-5C548796E5C6}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{098C28E5-BE52-4105-9198-FC6CEF814AC2}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe | "{1469FD1D-BAD3-412B-A8E9-BD1BEF8115FA}" = protocol=17 | dir=in | app=c:\program files (x86)\riptiger\videodownloadapp_rtmp.exe | "{168EEF35-0DC9-40DA-A57A-BA1526C51A23}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{1F1CCEAC-9DFE-405B-A09A-C92937023344}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{20A8B450-A018-4A88-B907-419C0A8DB676}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{22ADDB4A-FD05-4A34-846C-7367F745DC4C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{257C24E3-40CE-4C2C-BDD5-5FC9867F6FC1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{267ABE75-746F-474B-A46B-923348F92555}" = protocol=6 | dir=out | app=%systemroot%\system32\msdtc.exe | "{29A3FC97-4B7B-4A5A-A19A-375034453E27}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe | "{2EBEAF5E-C8D7-4E3D-A204-16E57F3907CD}" = protocol=6 | dir=in | app=c:\users\cass\appdata\roaming\dropbox\bin\dropbox.exe | "{33D0A5C3-0679-4FC4-9069-B1082471138E}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe | "{347D4631-8913-4B37-9E02-F8E2F6B755FE}" = protocol=6 | dir=in | app=c:\program files\samsung\allshare framework dms\1.3.23\allshareframeworkdms.exe | "{48C2660A-390D-4FCE-922E-F8B72771F8FD}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{4BF2DD81-F732-4634-9AC6-86B325A9D095}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{4E6D75AE-CBE6-415B-AC4A-476C4FA3BEDF}" = protocol=6 | dir=in | app=c:\program files (x86)\riptiger\riptiger.exe | "{51E6C11E-08E1-49D6-9229-07BFFFF3D8A8}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe | "{52086676-EF5C-4F2B-8C26-F7C4671311A2}" = protocol=6 | dir=in | svc=winmgmt | app=%systemroot%\system32\svchost.exe | "{54F83CCF-495C-4DD0-925A-E868128EB01F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{57B7E301-566B-4F37-9E59-7166DEAF0FB0}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe | "{587387DD-14E1-4381-96D4-E59C9658DA9F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{58A53F29-E696-4F18-AC5A-7179FA2AE822}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{5B26E086-53B6-48DC-B056-EC286A44B34C}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 | "{600F20BE-A631-440F-BF55-B314CB7DC7E5}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe | "{60D94CAB-960A-4F10-BF15-A09FB3102C10}" = protocol=6 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{61B1C59E-D60E-413E-98AC-FFB13ABE39FF}" = protocol=17 | dir=in | app=c:\program files (x86)\riptiger\httpdownloaderapp.exe | "{629C73B8-DA38-4FDA-B1C1-DAC0ACD82A52}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{6331B6BD-33BB-4329-92CE-4D59F34D89D8}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) | "{667D55AA-E3A3-468C-9219-E0C1DA9A7D8B}" = protocol=47 | dir=in | app=system | "{67117759-3477-4F41-A206-139D86168930}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{6AA86536-0723-4632-81B6-E16F03A913A7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{6C4677D1-0800-4772-B5BE-E74C5F7EA325}" = protocol=6 | dir=in | app=c:\program files (x86)\riptiger\mmsdownloaderapp.exe | "{6C983719-0DFB-47BF-A571-04035E58230E}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{6DF779EC-3674-4F13-A6B9-234AA659B0B4}" = protocol=6 | dir=in | app=%systemroot%\system32\msdtc.exe | "{71E4E4BD-584B-4655-A3A2-E55FDB9A41A7}" = protocol=6 | dir=out | app=system | "{73D31826-892D-4C54-AE38-38B147B07EE4}" = dir=in | app=c:\program files\samsung\samsung link\samsung link.exe | "{7AA997DA-4989-450E-9793-796F831A4FAD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7B2CBCA6-7759-40A8-9B20-5C665A86A265}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{7EFA75DB-F20E-44E5-8FCA-76ABDB3DF764}" = protocol=6 | dir=in | app=c:\users\cass\appdata\local\temp\7zsd0f4.tmp\symnrt.exe | "{811CF50D-5841-4B88-A595-26F701256567}" = protocol=17 | dir=in | app=c:\users\cass\appdata\roaming\dropbox\bin\dropbox.exe | "{83C401CF-8DFD-4C87-B3CA-B09A22C3FB76}" = protocol=17 | dir=in | app=c:\program files (x86)\riptiger\rtmpdownloaderapp.exe | "{85E45A34-F3CF-459B-82C1-277E965FEA06}" = protocol=6 | dir=out | svc=msiscsi | app=%systemroot%\system32\svchost.exe | "{88CCD6A5-D1C0-47AF-8457-C6FF588DD0F0}" = protocol=6 | dir=in | svc=msiscsi | app=%systemroot%\system32\svchost.exe | "{8A3FCF7D-6EA9-4CCF-BF01-82FDC5AA29AF}" = protocol=17 | dir=in | app=c:\program files\samsung\allshare framework dms\1.3.23\allshareframeworkdms.exe | "{8D4EF865-FE41-4524-AAFC-913396757F2F}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcrmgr.exe | "{923DDB40-EC54-4EE9-9628-2005C05ED89C}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe | "{9EA7ADCE-E848-475D-BC39-CFED86F6FB7C}" = protocol=17 | dir=in | app=c:\program files (x86)\riptiger\mmsdownloaderapp.exe | "{9F1C849F-3419-41EA-87C1-B2C40BAC4950}" = protocol=17 | dir=in | app=c:\program files (x86)\riptiger\riptiger.exe | "{A09C8599-A181-4526-B9EF-AA0DF258BCB0}" = protocol=6 | dir=in | app=c:\program files (x86)\riptiger\videodownloadapp_rtmp.exe | "{A1EF8ABA-0911-4B1D-889C-74376DE46689}" = protocol=6 | dir=in | app=c:\program files (x86)\riptiger\rtmpdownloaderapp.exe | "{A2D9CECE-6E8D-4BDE-B6BF-7EFAC79BC85F}" = protocol=6 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{A3268975-3A01-4321-9093-F8B8358BEDFA}" = dir=out | app=c:\program files\samsung\samsung link\samsung link.exe | "{A6123B17-27C6-4B69-806A-FE4B9D35AC8B}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{A7852213-2E7E-481E-AE8E-E903B83DAE5D}" = protocol=17 | dir=in | app=c:\users\cass\appdata\local\temp\7zs6a76.tmp\symnrt.exe | "{A971D4FE-2856-4F72-AAEA-D10CC2B520C1}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe | "{ABA794E2-BF44-44F6-85FF-86B3184B848D}" = protocol=47 | dir=out | app=system | "{ADFD4DF5-1DBE-452C-8034-AB58EECDD5A9}" = protocol=58 | dir=in | app=system | "{B2FDDC45-C39B-4B51-A5CB-67B5CD7ACB5E}" = protocol=6 | dir=out | svc=winmgmt | app=%systemroot%\system32\svchost.exe | "{B4731C6A-0D6A-451D-906C-38A104A9522E}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe | "{B77A7B91-B8DD-41DB-8415-324EAFCA23E8}" = protocol=6 | dir=in | app=c:\users\cass\appdata\local\temp\7zs6a76.tmp\symnrt.exe | "{B96A3E81-5D48-4CB8-A37C-86EDAE8060DF}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) | "{C12513B1-A99A-40DD-AE7F-8B7B777C8CB0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{C73662A5-7DDF-407F-A6D0-DBA0F6642939}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{CA25AE2E-1F1D-4372-8F9B-F4357679DEFC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{CC5667D8-96DE-467B-AA04-D486CB560D94}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{D09480AB-2B3A-473D-99C7-577358116936}" = dir=in | app=c:\program files\samsung\samsung link\samsung link tray agent.exe | "{D361BE78-1B74-4624-AAE6-E228B7748A72}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{D58A1D11-33F9-4BD9-B8D4-B754AB07766D}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{D7BD9515-7A11-4ADB-AC50-3B22257DD62C}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) | "{D92ADF44-476E-469A-AF20-B482BA65C79C}" = dir=out | app=c:\program files\samsung\samsung link\samsung link tray agent.exe | "{D9EF89B9-170A-497A-AFC3-D533C72A5B4F}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) | "{DB5402FC-2DB8-4612-8E90-C3C9A774BD76}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe | "{E6DEF096-304D-45A0-B253-54ECE66459AD}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{E89C0254-03BC-43DE-9878-1FE8EA9DE543}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{EADFAE35-10B3-441F-8441-82DD2D67EF42}" = protocol=6 | dir=in | app=%systemroot%\system32\plasrv.exe | "{EAFB976E-BBE8-4D5F-8F3F-3F2AD1C1AF9A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{EE435F14-036E-4E9B-8AFC-9FE992DCF0C3}" = protocol=6 | dir=in | app=c:\program files (x86)\riptiger\httpdownloaderapp.exe | "{F11D4053-2A70-45D5-B88B-EE7C60B52C6B}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe | "{F41A5D41-687E-4C59-923F-68EB755DC454}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe | "{F8688258-49BA-4E32-9707-56CAD7709C1B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{F970BD63-C43E-4185-811E-8E3A3BF78924}" = protocol=6 | dir=in | app=%systemroot%\system32\wbem\unsecapp.exe | "TCP Query User{0A4C10AA-29AB-4212-9D3F-867534B78EC3}C:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe" = protocol=6 | dir=in | app=c:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe | "TCP Query User{730DE472-2433-42C9-AF2B-56B57E12EDBB}C:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicator.exe" = protocol=6 | dir=in | app=c:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicator.exe | "TCP Query User{891D2ACE-837A-4308-9A05-40CA673CE4F6}C:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe | "TCP Query User{909057BF-1921-48B3-9FDC-69EF17A1EF39}C:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicator.exe" = protocol=6 | dir=in | app=c:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicator.exe | "TCP Query User{920799E2-9B1C-48EF-8A2C-75F524E20708}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "TCP Query User{CB1453D3-4913-4FC6-991A-B613CFF728D3}C:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe" = protocol=6 | dir=in | app=c:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe | "TCP Query User{F3F5ED17-D90A-49F2-B473-7055F5FA6343}C:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicatorcom.exe" = protocol=6 | dir=in | app=c:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicatorcom.exe | "UDP Query User{11911F88-D708-42E1-9986-63D19C46AE39}C:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicator.exe" = protocol=17 | dir=in | app=c:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicator.exe | "UDP Query User{1F7C8FCA-1F92-4326-ABA3-91EBC41528DA}C:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe | "UDP Query User{2675551D-0A0B-4E7C-95CD-E7E178D456F9}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "UDP Query User{2AFC8699-D01D-4B29-939F-52534E1AC1A6}C:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe" = protocol=17 | dir=in | app=c:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe | "UDP Query User{9C3E2024-32EE-48AC-B7D4-01A26C2C3524}C:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicatorcom.exe" = protocol=17 | dir=in | app=c:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicatorcom.exe | "UDP Query User{D73EEAC6-294C-4BEB-8145-B25DC28D12EB}C:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe" = protocol=17 | dir=in | app=c:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe | "UDP Query User{F88A8C03-DED0-4B8C-8D35-B0C79DA510DA}C:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicator.exe" = protocol=17 | dir=in | app=c:\program files\hp\hp officejet 4620 series\bin\hpnetworkcommunicator.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector "{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant "{1CAFFEC6-23B4-484B-B17B-3200BE5C5636}" = Adblock Plus for IE (32-bit and 64-bit) "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{787136D2-F0F8-4625-AA3F-72D7795AC842}" = Apple Mobile Device Support "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{83232C27-8C3F-44A5-9EB2-BB7161228ADD}" = AllShare Framework DMS "{83F51BBA-48BE-4BB6-B96A-F4AAE4C462F9}" = HP Officejet 4620 series Product Improvement Study "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{88E60521-1E4E-4785-B9F1-1798A4BD0C30}" = HP MediaSmart SmartMenu "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007 "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A1B827F9-8A85-4DEE-8E72-3CF347F71999}" = Hightail Desktop App "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B411AD10-1BC9-4939-8848-BC5E66F662B7}" = HP Officejet 4620 series Basic Device Software "{B8BA155B-1E75-405F-9CB4-8A99615D09DC}" = iTunes "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "8461-7759-5462-8226" = Vuze "8474-7877-9059-0204" = Samsung Link 2.0.0.1411061504 "NVIDIA Drivers" = NVIDIA Drivers [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0071820F-09B0-4998-8320-F89629DCBC99}" = Nero BackItUp "{052A1E34-A54B-458C-A4E3-24C3E054754A}" = Nero Kwik Media "{0708FF30-78C0-47B0-81F0-C84604DC769C}" = Nero Express Help (CHM) "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0B311221-05A5-4766-8D03-7A6446794156}" = Nero RescueAgent Help (CHM) "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works "{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1896E712-2B3D-45eb-BCE9-542742A51032}" = PictureMover "{1943C3BD-4462-4612-92C3-D36DD917C447}" = Nero Recode "{1959CCD2-1227-4de4-97E7-04F29D526762}_is1" = AnyMedia Player 4.5.1 "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1B6F5E51-575E-4693-BCA2-7543570D076D}" = Nero Kwik Themes Basic "{1CB4ADE4-4B75-481A-BF77-EE69279DF30E}_is1" = 1Step DVD Copy 4.5.1 "{1F16820E-D0E7-4636-939E-45CBFEFB06E1}" = Nero Kwik Media Help (CHM) "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{2432E589-6256-4513-B0BF-EFA8E325D5F0}" = Nero SharedVideoCodecs "{2890E324-6F3B-4975-8B95-E7D6D80E0226}" = Nero Burning ROM Help (CHM) "{29F67D84-3A70-456E-806A-52301B02070B}" = Nero Effects Basic "{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{35021DFB-F9CA-402A-89A2-47F91E506465}" = HP MediaSmart/TouchSmart Netflix "{3AAB08A3-F129-4BD5-B409-AE674F93759D}" = Prerequisite installer "{3B10760F-86A3-4376-A668-AC304015D5ED}_is1" = Disk Burner 4.5.1 "{3C32FF23-6277-4183-B098-55E9AA61D001}" = AbleBits.com Merge Cells Wizard for Microsoft Excel "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager "{49351FE8-DB8F-4C56-9DA6-B2D6CE3F7BF8}" = ActiveState ActivePython 2.7.2.5 (32-bit) "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion "{560FC78C-A4B2-461D-9B47-820C1EEF87B8}" = Nero 12 "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5963F4B4-D138-47CD-ADEF-470E87E185BD}" = Nero Burning ROM "{5B79E730-D897-4B8F-A1AD-7BB2D1F22B96}" = Nero Blu-ray Player Help (CHM) "{606C37AB-EB04-4270-A592-201A03C2DB36}" = HP Officejet 4620 series Help "{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6D308A90-6C14-4A02-9B04-CB0EF17894A9}_is1" = Picture Collage Maker Pro 3.3.6 "{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}" = HP Update "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.2.3 "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{735C603C-B068-44E3-8711-826A5953057C}" = calibre "{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{828175FA-7307-4DBF-95AD-9CEE086B6F45}" = Welcome App (Start-up experience) "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{83FCCFCD-46E3-43FB-A397-78BFD5A8980A}" = Nero Video "{848A7C68-0ADC-4193-8A89-2CEA78E56A0C}" = Nero Express "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync "{8675BF55-B842-4E02-B3C8-7AA92C72D2C2}_is1" = SoundTaxi 4.5.1 "{86847081-B387-4F49-AED1-C9B0A090D66C}" = Nero Recode Help (CHM) "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 "{9453ED2E-3B9F-4683-BA6A-8FCB9F3E0065}" = Hightail Express "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English) "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9DEF9686-CCB2-47B7-BF83-B49EA21FA016}" = HP MediaSmart Demo "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A1A2E29A-683B-BB20-BB0D-B97E7E121012}_is1" = SoundTaxi Endless Music Player 4.5.1 "{A2FE691E-3F8E-4E30-AA7D-FF17AC77EA87}" = Nero Blu-ray Player "{A526332D-E81C-452D-9502-289F13BA1791}" = WORDsearch Installer "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A7A0BF2E-31CC-49E3-9913-52C503EB969D}" = Nero Audio Pack 1 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}" = Apple Application Support "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{ABC88553-8770-4B97-B43E-5A90647A5B63}" = Nero ControlCenter "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.10) "{ACE49D50-19CD-44A6-B192-46F985283B26}" = Nero PiP Effects Basic "{AFD4597D-56CC-447F-AA68-C1BF1AEA448E}_is1" = RipTiger 4.5.1 "{B128179D-A5E1-43AC-9422-12A109ECD2A0}" = Nero Video Help (CHM) "{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader "{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer "{B953732D-B623-4E84-B369-CFFF7B1AE06F}" = Nero RescueAgent "{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information "{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{C994C746-C6D0-4EBA-B09E-DF7B18381B69}" = Nero ControlCenter Help (CHM) "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E0E55FC1-C53D-4F8D-B14B-B59C312747C8}" = LightScribe System Software "{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}" = Nero Disc Menus Basic "{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}" = HP Support Assistant "{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004) "{EF0D1292-8FC1-41BE-9740-DBC134F66415}" = Nero BackItUp Help (CHM) "{EF4C657F-632F-4CED-A220-F4C1C724241C}_is1" = SoundTaxi Media Suite 4.5.1 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F6C84ED7-9CAC-423b-9E00-C9BFAFBD0593}_is1" = GetRadio 4.5.1 "{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video "{fd97d1e2-368a-4cd9-af63-8eeff938044a}" = Adblock Plus for IE "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "A24B23EB-0632-4D92-B087-011CAE348023" = Sigil "Adobe Digital Editions 2.0" = Adobe Digital Editions 2.0 "Adobe Flash Player ActiveX" = Adobe Flash Player 16 ActiveX "Adobe Flash Player NPAPI" = Adobe Flash Player 16 NPAPI "AI RoboForm" = AI RoboForm (All Users) "Aimersoft DRM Media Converter_is1" = Aimersoft DRM Media Converter(Build 1.5.5.0) "AudibleManager" = AudibleManager "Avast" = Avast Free Antivirus "B1Manager" = B1 Free Archiver "BN_DesktopReader" = NOOK for PC "Cambridge Ed" = Cambridge Ed "ENTERPRISE" = Microsoft Office Enterprise 2007 "ExtractNow" = ExtractNow "FairStars Audio Converter_is1" = FairStars Audio Converter 1.97 "FileZilla Client" = FileZilla Client 3.7.3 "FormatFactory" = FormatFactory 3.2.1.0 "Foxit Phantom" = Foxit Phantom "Google Chrome" = Google Chrome "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe "InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD "InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video "Internet Download Manager" = Internet Download Manager "KLiteCodecPack_is1" = K-Lite Codec Pack 9.3.0 (Basic) "MediaFire Desktop 0.10.18.9207" = MediaFire Desktop "MediaFire Express 0.15.4.4888" = MediaFire Express "Midnight Oil Solitaire_is1" = Midnight Oil Solitaire 3.20 "Mozilla Firefox 34.0.5 (x86 en-US)" = Mozilla Firefox 34.0.5 (x86 en-US) "MozillaMaintenanceService" = Mozilla Maintenance Service "Notepad++" = Notepad++ "uTorrent" = µTorrent "VLC media player" = VLC media player 2.1.3 "WildTangent hp Master Uninstall" = HP Games "WinLiveSuite" = Windows Live Essentials "WinPcapInst" = WinPcap 4.1.2 "WinRAR archiver" = WinRAR archiver [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Amazon Kindle" = Amazon Kindle "Dropbox" = Dropbox "HuluDesktop" = Hulu Desktop "uTorrent" = µTorrent [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 12/20/2014 8:21:43 AM | Computer Name = cass-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 11201 Error - 12/20/2014 8:21:43 AM | Computer Name = cass-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 11201 Error - 12/20/2014 8:21:44 AM | Computer Name = cass-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 12/20/2014 8:21:44 AM | Computer Name = cass-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 12231 Error - 12/20/2014 8:21:44 AM | Computer Name = cass-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 12231 Error - 12/20/2014 8:21:45 AM | Computer Name = cass-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 12/20/2014 8:21:45 AM | Computer Name = cass-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 13323 Error - 12/20/2014 8:21:45 AM | Computer Name = cass-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 13323 Error - 12/20/2014 11:28:48 AM | Computer Name = cass-PC | Source = Windows Search Service | ID = 3083 Description = Error - 12/20/2014 12:21:59 PM | Computer Name = cass-PC | Source = Windows Search Service | ID = 3083 Description = [ Hewlett-Packard Events ] Error - 3/27/2013 1:38:58 PM | Computer Name = cass-PC | Source = Hewlett-Packard | ID = 0 Description = en-US Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding) at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a(Object A_0, EventArgs A_1) [ System Events ] Error - 12/19/2014 8:47:19 PM | Computer Name = cass-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk2\DR2. Error - 12/19/2014 10:01:53 PM | Computer Name = cass-PC | Source = Service Control Manager | ID = 7023 Description = The Program Compatibility Assistant Service service terminated with the following error: %%126 Error - 12/19/2014 10:02:44 PM | Computer Name = cass-PC | Source = Service Control Manager | ID = 7023 Description = The Program Compatibility Assistant Service service terminated with the following error: %%126 Error - 12/19/2014 10:26:00 PM | Computer Name = cass-PC | Source = Service Control Manager | ID = 7023 Description = The Program Compatibility Assistant Service service terminated with the following error: %%126 Error - 12/20/2014 4:06:13 AM | Computer Name = cass-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Windows 7 for x64-based Systems (KB3024777). Error - 12/20/2014 6:00:23 AM | Computer Name = cass-PC | Source = Disk | ID = 262155 Description = The driver detected a controller error on \Device\Harddisk2\DR2. Error - 12/20/2014 7:48:42 AM | Computer Name = cass-PC | Source = Service Control Manager | ID = 7023 Description = The Program Compatibility Assistant Service service terminated with the following error: %%126 Error - 12/20/2014 7:53:35 AM | Computer Name = cass-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Windows 7 for x64-based Systems (KB3024777). Error - 12/20/2014 1:14:11 PM | Computer Name = cass-PC | Source = Service Control Manager | ID = 7023 Description = The Program Compatibility Assistant Service service terminated with the following error: %%126 Error - 12/20/2014 1:14:11 PM | Computer Name = cass-PC | Source = Service Control Manager | ID = 7023 Description = The Program Compatibility Assistant Service service terminated with the following error: %%126 < End of report >