OTL Extras logfile created on: 4/14/2015 11:13:54 AM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\dshin\Downloads 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17691) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.74 Gb Total Physical Memory | 1.65 Gb Available Physical Memory | 44.08% Memory free 7.49 Gb Paging File | 4.89 Gb Available in Paging File | 65.24% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 297.79 Gb Total Space | 241.77 Gb Free Space | 81.19% Space Free | Partition Type: NTFS Drive H: | 118.41 Gb Total Space | 57.47 Gb Free Space | 48.54% Space Free | Partition Type: NTFS Drive J: | 118.41 Gb Total Space | 57.47 Gb Free Space | 48.54% Space Free | Partition Type: NTFS Computer Name: HVSDR1 | User Name: dshin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UpdatesDisableNotify" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] "EnableFirewall" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0C7D7A8E-DF39-44F2-B498-5EA3FBB2D934}" = lport=162 | protocol=17 | dir=in | name=allow netfastalk | "{303F6ACB-F228-4E45-B8CA-B22BBDAF34A5}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{467362A7-A04B-4429-BD28-97FEE41EF1D2}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe | "{4B7DDE08-2418-4EB3-B2AC-C5587862724D}" = lport=21010 | protocol=6 | dir=in | name=trend micro client/server security agent listener | "{66DB6C7B-1993-44F4-8B79-DE283B28AC08}" = lport=4995 | protocol=6 | dir=in | name=allow local vnc | "{7F3D229B-CFE9-4EFE-A221-809C11CF3E57}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{B97BBF6E-914B-4997-86B2-99E33C024796}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{24C90648-9F56-4AB6-B813-83DFEB8D3BAE}" = dir=in | app=c:\windows\ltsvc\ltsvc.exe | "{30705D7F-5531-4813-8A26-D42F691F5095}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{3796F810-0437-4C1A-8643-BD7904F678E0}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe | "{38702362-3020-425A-A886-CF07179E14BA}" = protocol=6 | dir=in | name=allow local redir | "{41C3D229-CACA-47D9-81C9-A7D3E10F65AF}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe | "{43752EC2-AAD8-46D8-90E8-EED56F30EA5F}" = dir=out | app=c:\windows\ltsvc\ltsvc.exe | "{4A6DEF49-27B3-4ABE-A8A8-A3900B6FB37F}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{56F1C4B2-3E59-4755-8D76-F86AD39C3B4E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{781B751B-7AD0-46EF-8EA3-F9112E6F3490}" = dir=in | app=c:\program files (x86)\intel corporation\intel wireless display\widiapp.exe | "{79A985D1-A924-42BD-9200-69E4D18A08EB}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | "{87039676-5990-4482-A40B-2D9A1A145184}" = protocol=17 | dir=out | name=allow tunnel | "{88FC760A-7ED0-4D44-88A3-0C09456E3C5C}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{895CEFA2-D0A6-4888-A2C7-5B6B4D1945AA}" = dir=in | app=c:\windows\ltsvc\lttray.exe | "{8F294F22-E19E-455F-B8E5-A7FDA7D941AD}" = dir=in | app=c:\windows\ltsvc\ltsvcmon.exe | "{9567A14E-703E-44B6-A930-2296826DE20D}" = protocol=17 | dir=out | name=allow tunnel stunrelay | "{A7B7F92E-31A3-4E17-B827-296715072F8E}" = protocol=17 | dir=in | name=allow tunnel | "{B467F505-C505-4206-9892-11D266DF55C0}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe | "{BB88D1F3-D730-4B35-B7B7-BDE1BFD48731}" = dir=out | app=c:\windows\ltsvc\lttray.exe | "{BBFDFBC4-2DD0-493C-9BE7-7BA994FE539C}" = protocol=6 | dir=in | name=allow local redir | "{E2D14C40-7F7C-4357-8AC2-21E828431F1D}" = dir=in | app=c:\program files (x86)\cyberlink\makedisc\makedisc.exe | "{E473F1A6-B1D7-4990-B8B0-9DB806CE4FF8}" = dir=out | app=c:\windows\ltsvc\ltsvcmon.exe | "TCP Query User{701402A5-2280-4682-9872-A237C5BE38BE}C:\program files (x86)\facetcorp\facetwin\fwagent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\facetcorp\facetwin\fwagent.exe | "UDP Query User{E9385A47-C273-45AF-ADAB-E57F7CFBD098}C:\program files (x86)\facetcorp\facetwin\fwagent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\facetcorp\facetwin\fwagent.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0A07E717-BB5D-4B99-840B-6C5DED52B277}" = Trend Micro Worry-Free Business Security Agent "{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{26784146-6E05-3FF9-9335-786C7C0FB5BE}" = Microsoft .NET Framework 4.5.2 "{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel(R) Wireless Display "{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 "{4108974B-DE87-4AD4-9167-930C62C45691}" = Fujitsu Display Manager "{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = WIDCOMM Bluetooth Software "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{4E3AB08B-4203-4CDD-9F15-C016F1BC6453}" = Inst5672 "{5CB9660D-919E-421A-AE17-DD6C925E1AF3}" = O2Micro Flash Memory Card Windows Driver "{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources "{5F1DFCC1-595D-4235-A044-E05B706D800A}" = AuthenTec Fingerprint Software "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64) "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010 "{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.2 "{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A38F51ED-D01A-4CE4-91EB-B824A00A8BDF}" = Trend Micro Worry-Free Business Security Agent "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources "{B95CFA6A-E0E0-4437-A2F0-BE0948B68946}" = Intel(R) PROSet/Wireless WiFi Software "{BF925467-9E3A-492F-B80D-D8E88A282E67}" = Fujitsu Battery Swap Utility "{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}" = Fujitsu System Extension Utility "{EC314CDF-3521-482B-A21C-65AC95664814}" = Fujitsu MobilityCenter Extension Utility "{ED6D1938-2629-4298-9B31-8A75F7CEC8A0}" = Fujitsu Button Utilities "C1556C282D8A9FB37C3F3925E582B76545A344EF" = Windows Driver Package - Fujitsu America, Inc. (FjBtnDrv) HIDClass (08/27/2009 4.2.0827.2009) "eBridge Print Driver_is1" = eBridge Print Driver 4.3.11.0613 "HP LaserJet Professional P1100-P1560-P1600 Series" = HP LaserJet Professional P1100-P1560-P1600 Series "ISD Tablet Driver" = ISD Tablet "Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) "NEC IT3530/2530 Installer" = NEC IT3530/2530 "ProInst" = Intel PROSet Wireless "SynTPDeinstKey" = Synaptics Pointing Device Driver "Wofie" = Trend Micro Worry-Free Business Security Agent [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{012C59CF-074A-43DA-8085-B6E636733B59}" = Citrix Receiver(Aero) "{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0E1C5B43-1837-4F98-A96B-79A8A0A5955F}" = Citrix Receiver(USB) "{17F82182-0E3D-4A14-8843-5ECBFAF4F12F}" = Security Panel Application for Supervisor "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{26A24AE4-039D-4CA4-87B4-2F83218040F0}" = Java 8 Update 40 "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{2C12184B-F547-455E-8B36-D81ED4E17C46}" = Roxio Creator LJ "{2EA6C7A4-9178-4C04-887E-D3515F4AAC1B}" = Online Plug-in "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 "{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = FJ Camera "{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{3F460D4C-D217-46B4-80B6-B5ED50BD7CF5}" = LabTechAD "{45CA9B23-5EF8-43AA-9851-E9E062BF0147}" = Security Panel Application "{47117FCA-0D00-4B6D-9D68-00B763629463}" = Self-service Plug-in "{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "{549BF60D-FDDA-4E4C-ABE3-9E897BC09E79}" = Anytime USB Charge Utility "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5E8AC853-65BB-4C99-A09E-19B81851E14C}" = Citrix Receiver Updater "{6057E21C-ABE9-4059-AE3E-3BEB9925E660}" = Windows Live Messenger "{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper "{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{74DC8A26-4E05-40B6-AD11-C9428A1AE150}" = Roxio Creator LJ "{74EE471B-DF43-47F4-BB58-E02D55CF3A1C}" = Touch Notepad "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh "{89A15676-78AE-4D51-BF5B-DEE3E0D46C94}" = Roxio Creator LJ "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010 "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010 "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010 "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010 "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010 "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010 "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010 "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010 "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AC76BA86-0804-1033-1959-001802114130}" = Adobe Refresh Manager "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.10) "{ADE8A83D-BB70-4FB5-BA19-26C47EA31894}" = Citrix Receiver(DV) "{b145ec69-66f5-11d8-9d75-000129760d75}" = CyberLink MakeDisc "{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 "{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 "{C4E28723-0663-4012-9BDC-E21A14C1316C}" = Citrix Receiver (HDX Flash Redirection) "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common "{C8E4B31D-337C-483D-822D-16F11441669B}" = Fujitsu Hotkey Utility "{CA55005D-94AC-4596-9646-679D6CC0D620}" = Citrix Authentication Manager "{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D6C5A4CA-1EE8-4C73-9679-0BC2946D1353}" = Battery Utility "{D9EE360A-7C19-47EC-93C7-97DEFF64804B}" = Citrix Receiver Inside "{DDC49774-40B9-47AE-9C63-5569C08C4082}" = Pointing Device Utility "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F17C3DC2-2ACA-4B0E-BDBF-ACE61B14E7CD}" = Citrix Online Launcher "{F390D923-76F1-458E-8218-8C0C156CDCFD}" = Online Plug-in "{F84906ED-BB54-4889-B131-FED9C9056FC8}" = Intel(R) Wireless Display "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe Flash Player ActiveX" = Adobe Flash Player 17 ActiveX "CitrixOnlinePluginPackWeb" = Citrix Receiver "Google Chrome" = Google Chrome "InstallShield_{17F82182-0E3D-4A14-8843-5ECBFAF4F12F}" = Security Panel Application for Supervisor "InstallShield_{4108974B-DE87-4AD4-9167-930C62C45691}" = Fujitsu Display Manager "InstallShield_{45CA9B23-5EF8-43AA-9851-E9E062BF0147}" = Security Panel Application "InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver "InstallShield_{5CB9660D-919E-421A-AE17-DD6C925E1AF3}" = O2Micro Flash Memory Card Windows Driver "InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9 "InstallShield_{b145ec69-66f5-11d8-9d75-000129760d75}" = CyberLink MakeDisc "InstallShield_{C8E4B31D-337C-483D-822D-16F11441669B}" = Fujitsu Hotkey Utility "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "InstallShield_{DDC49774-40B9-47AE-9C63-5569C08C4082}" = Pointing Device Utility "InstallShield_{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}" = Fujitsu System Extension Utility "InstallShield_{EC314CDF-3521-482B-A21C-65AC95664814}" = Fujitsu MobilityCenter Extension Utility "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.2.1012 "Office14.SingleImage" = Microsoft Office Home and Business 2010 "Plaxo" = Plaxo Toolbar for Windows "ProInst" = Intel PROSet Wireless "WinLiveSuite" = Windows Live Essentials [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "GoToMeeting" = GoToMeeting 7.1.8.2553 "JoinMe" = join.me [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 3/11/2015 9:04:32 AM | Computer Name = HVSDR1.hvs.local | Source = Microsoft-Windows-LoadPerf | ID = 3001 Description = The performance counter name string value in the registry is not formatted correctly. The malformed string is 10360. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error - 3/11/2015 12:03:20 PM | Computer Name = HVSDR1.hvs.local | Source = Application Error | ID = 1000 Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.17229, time stamp: 0x54b478df Faulting module name: Flash32_16_0_0_305.ocx, version: 16.0.0.305, time stamp: 0x54cff11b Exception code: 0xc0000005 Fault offset: 0x006a85ea Faulting process id: 0x1818 Faulting application start time: 0x01d05bfb5c4915bd Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: C:\Windows\SysWOW64\Macromed\Flash\Flash32_16_0_0_305.ocx Report Id: 22c73507-c808-11e4-8802-60d819f1b6b6 Error - 3/12/2015 3:53:19 PM | Computer Name = HVSDR1.hvs.local | Source = Microsoft-Windows-RestartManager | ID = 10007 Description = Application or service 'LogMeIn Maintenance Service' could not be restarted. Error - 3/12/2015 3:53:19 PM | Computer Name = HVSDR1.hvs.local | Source = Microsoft-Windows-RestartManager | ID = 10007 Description = Application or service 'LMIGuardianSvc' could not be restarted. Error - 3/12/2015 3:53:19 PM | Computer Name = HVSDR1.hvs.local | Source = Microsoft-Windows-RestartManager | ID = 10007 Description = Application or service 'LogMeIn' could not be restarted. Error - 3/25/2015 9:58:18 AM | Computer Name = HVSDR1.hvs.local | Source = Application Error | ID = 1000 Description = Faulting application name: SC_svc64.exe, version: 1.3.0.11, time stamp: 0x54abb453 Faulting module name: SC_svc64.exe, version: 1.3.0.11, time stamp: 0x54abb453 Exception code: 0xc0000005 Fault offset: 0x0000000000174c7f Faulting process id: 0x74c Faulting application start time: 0x01d06703ba2baca4 Faulting application path: C:\Program Files (x86)\Spyware Clear\SC_svc64.exe Faulting module path: C:\Program Files (x86)\Spyware Clear\SC_svc64.exe Report Id: fcfa2e84-d2f6-11e4-85ec-60d819f1b6b6 Error - 4/1/2015 1:59:38 PM | Computer Name = HVSDR1.hvs.local | Source = MsiInstaller | ID = 10005 Description = Error - 4/14/2015 10:17:42 AM | Computer Name = HVSDR1.hvs.local | Source = Application Error | ID = 1000 Description = Faulting application name: FJPDAutoSet.exe, version: 1.0.1.0, time stamp: 0x4d48017b Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7 Exception code: 0xc0000005 Fault offset: 0x000222d2 Faulting process id: 0x1438 Faulting application start time: 0x01d076b7371c0745 Faulting application path: C:\Program Files (x86)\Fujitsu\PointingDeviceUtility\FJPDAutoSet.exe Faulting module path: C:\Windows\SysWOW64\ntdll.dll Report Id: 0338898f-e2b1-11e4-a9a0-60d819f1b6b6 Error - 4/14/2015 10:18:57 AM | Computer Name = HVSDR1.hvs.local | Source = Application Error | ID = 1000 Description = Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4 Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521eaf24 Exception code: 0xc0000024 Fault offset: 0x00000000000cd7e8 Faulting process id: 0x12ac Faulting application start time: 0x01d076b734469f79 Faulting application path: C:\Windows\Explorer.EXE Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 2fe3d70f-e2b1-11e4-a9a0-60d819f1b6b6 Error - 4/14/2015 10:48:23 AM | Computer Name = HVSDR1.hvs.local | Source = Microsoft-Windows-RestartManager | ID = 10007 Description = Application or service 'UpdateNaviInstallService' could not be restarted. [ RMM System Events ] Error - 4/13/2015 8:29:26 AM | Computer Name = HVSDR1.hvs.local | Source = Agent | ID = 5001 Description = UNCompress Error: Index was outside the bounds of the array. v60.276 Error - 4/14/2015 8:30:58 AM | Computer Name = HVSDR1.hvs.local | Source = Agent | ID = 5001 Description = WebRqst: http://173.227.105.149/LabTech/Agent.aspx?DEPS : ReceiveFailure : The underlying connection was closed: An unexpected error occurred on a receive. : v60.276 Error - 4/14/2015 8:31:49 AM | Computer Name = HVSDR1.hvs.local | Source = Agent | ID = 5001 Description = WebRqst: http://192.168.20.213/LabTech/Agent.aspx?DEPS : ReceiveFailure : The underlying connection was closed: An unexpected error occurred on a receive. : v60.276 Error - 4/14/2015 8:31:49 AM | Computer Name = HVSDR1.hvs.local | Source = Agent | ID = 5001 Description = UNCompress Error: Index was outside the bounds of the array. v60.276 Error - 4/14/2015 9:31:21 AM | Computer Name = HVSDR1.hvs.local | Source = Agent | ID = 5001 Description = WebRqst: http://173.227.105.149/LabTech/Agent.aspx?DEPS : ReceiveFailure : The underlying connection was closed: An unexpected error occurred on a receive. : v60.276 Error - 4/14/2015 9:32:12 AM | Computer Name = HVSDR1.hvs.local | Source = Agent | ID = 5001 Description = WebRqst: http://192.168.20.213/LabTech/Agent.aspx?DEPS : ReceiveFailure : The underlying connection was closed: An unexpected error occurred on a receive. : v60.276 Error - 4/14/2015 9:32:12 AM | Computer Name = HVSDR1.hvs.local | Source = Agent | ID = 5001 Description = UNCompress Error: Index was outside the bounds of the array. v60.276 Error - 4/14/2015 10:26:04 AM | Computer Name = HVSDR1.hvs.local | Source = Agent | ID = 5001 Description = WebRqst: http://173.227.105.149/LabTech/Agent.aspx?DEPS : ReceiveFailure : The underlying connection was closed: An unexpected error occurred on a receive. : v60.276 Error - 4/14/2015 10:26:55 AM | Computer Name = HVSDR1.hvs.local | Source = Agent | ID = 5001 Description = WebRqst: http://192.168.20.213/LabTech/Agent.aspx?DEPS : ReceiveFailure : The underlying connection was closed: An unexpected error occurred on a receive. : v60.276 Error - 4/14/2015 10:26:55 AM | Computer Name = HVSDR1.hvs.local | Source = Agent | ID = 5001 Description = UNCompress Error: Index was outside the bounds of the array. v60.276 [ System Events ] Error - 4/14/2015 11:03:26 AM | Computer Name = HVSDR1.hvs.local | Source = Service Control Manager | ID = 7034 Description = The O2FLASH service terminated unexpectedly. It has done this 1 time(s). Error - 4/14/2015 11:20:03 AM | Computer Name = HVSDR1.hvs.local | Source = NETLOGON | ID = 5719 Description = This computer was not able to set up a secure session with a domain controller in domain HVS due to the following: %%1311 This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. Error - 4/14/2015 11:20:03 AM | Computer Name = HVSDR1.hvs.local | Source = Service Control Manager | ID = 7000 Description = The LogMeIn Kernel Information Provider service failed to start due to the following error: %%3 Error - 4/14/2015 11:20:04 AM | Computer Name = HVSDR1.hvs.local | Source = Microsoft-Windows-GroupPolicy | ID = 1055 Description = The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: a) Name Resolution failure on the current domain controller. b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller). Error - 4/14/2015 11:20:35 AM | Computer Name = HVSDR1.hvs.local | Source = NetBT | ID = 4321 Description = The name "HVS :1d" could not be registered on the interface with IP address 192.168.60.100. The computer with the IP address 192.168.60.9 did not allow the name to be claimed by this computer. Error - 4/14/2015 11:20:36 AM | Computer Name = HVSDR1.hvs.local | Source = NetBT | ID = 4321 Description = The name "HVS :1d" could not be registered on the interface with IP address 192.168.60.100. The computer with the IP address 192.168.60.9 did not allow the name to be claimed by this computer. Error - 4/14/2015 11:20:36 AM | Computer Name = HVSDR1.hvs.local | Source = NetBT | ID = 4319 Description = A duplicate name has been detected on the TCP network. The IP address of the computer that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state. Error - 4/14/2015 12:00:24 PM | Computer Name = HVSDR1.hvs.local | Source = NETLOGON | ID = 5719 Description = This computer was not able to set up a secure session with a domain controller in domain HVS due to the following: %%1311 This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. Error - 4/14/2015 12:00:25 PM | Computer Name = HVSDR1.hvs.local | Source = Microsoft-Windows-GroupPolicy | ID = 1055 Description = The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: a) Name Resolution failure on the current domain controller. b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller). Error - 4/14/2015 12:00:30 PM | Computer Name = HVSDR1.hvs.local | Source = Service Control Manager | ID = 7000 Description = The LogMeIn Kernel Information Provider service failed to start due to the following error: %%3 < End of report >