Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Laptop is acting crazy either malware or reg problems


  • Please log in to reply

#1
ctnhill02

ctnhill02

    Member

  • Member
  • PipPip
  • 20 posts
I have another post http://www.geekstogo..._1#entry2325056 but figured out it has nothing to do with ie but something messing with probably the registries.... but mostly i think it is malware.

my laptop will not update properly and it will not downgrade ie 10 to 9, ive tried revo uninstaller, cmd prompts, had arise.com techs look at it via remote access they tried everything has well.... contacted the dealer who sold my fiance the laptop and he said he'd help me for free to a point with was advising me to go to microsoft fix-it and that didnt work either.... went to major geeks and dowloaded ie fixit tool..... no avail.

downloaded OTL

OTL.TxT:
OTL logfile created on: 1/26/2014 10:32:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Clifton Work\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16750)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.39 Gb Available Physical Memory | 19.39% Memory free
4.43 Gb Paging File | 2.50 Gb Available in Paging File | 56.34% Paging File free
Paging file location(s): c:\pagefile.sys 2500 3000e:\pagef [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.43 Gb Total Space | 9.04 Gb Free Space | 12.14% Space Free | Partition Type: NTFS

Computer Name: SHAWN-LAPTOP | User Name: Clifton Work | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2014/01/26 10:26:05 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Clifton Work\Downloads\OTL.exe
PRC - [2014/01/11 05:29:23 | 000,866,584 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2013/12/21 01:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/12/18 20:21:48 | 002,154,496 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\Windstream_BCUC\pcTrayApp.exe
PRC - [2013/12/17 14:13:18 | 005,271,040 | ---- | M] (Joyent, Inc) -- C:\Program Files\Windstream\8.3.1.7\ma\bin\node.exe
PRC - [2013/12/17 14:13:18 | 000,321,024 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\Windstream\8.3.1.7\ma\bin\MAHostService.exe
PRC - [2013/12/17 12:50:28 | 000,369,152 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\Common Files\Motive\pcCMService.exe
PRC - [2013/10/30 16:51:34 | 002,838,568 | ---- | M] (The Nielsen Company) -- C:\Program Files\NetRatingsNetSight\NetSight\NielsenUpdate.exe
PRC - [2013/10/30 16:51:30 | 000,091,688 | ---- | M] (The Nielsen Company) -- C:\Program Files\NetRatingsNetSight\NetSight\nielsenonline.exe
PRC - [2013/10/23 15:01:10 | 000,280,288 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2013/10/23 15:01:10 | 000,022,208 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2013/10/23 14:55:28 | 000,948,440 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2013/10/06 22:14:31 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2013/10/01 15:29:04 | 001,505,608 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\Receiver\Receiver.exe
PRC - [2013/08/14 14:19:24 | 000,039,056 | ---- | M] () -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2013/06/28 17:48:04 | 000,014,624 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
PRC - [2013/06/19 22:13:16 | 002,445,304 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2013/06/19 21:41:38 | 000,073,832 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
PRC - [2013/06/18 02:34:34 | 000,054,160 | ---- | M] (Check Point Software Technologies, Ltd.) -- C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013/03/17 22:41:44 | 001,070,080 | ---- | M] (iolo technologies, LLC) -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
PRC - [2012/11/29 21:55:25 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2012/11/22 21:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/11/22 09:33:18 | 000,497,320 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
PRC - [2012/11/22 09:32:54 | 000,738,984 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
PRC - [2012/08/20 03:18:20 | 007,065,224 | ---- | M] () -- C:\Program Files\Backup Assistant Plus\V CAST Backup Scheduler.exe
PRC - [2012/04/09 08:34:50 | 000,334,920 | ---- | M] (Juniper Networks") -- C:\Users\Clifton Work\AppData\Roaming\Juniper Networks\Host Checker\dsHostChecker.exe
PRC - [2012/04/09 03:24:18 | 000,571,256 | ---- | M] (Juniper Networks, Inc.) -- C:\Users\Clifton Work\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClient.exe
PRC - [2011/12/06 16:00:14 | 000,784,240 | ---- | M] () -- C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
PRC - [2011/12/06 16:00:14 | 000,214,896 | ---- | M] () -- C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
PRC - [2011/10/13 22:28:20 | 010,315,064 | ---- | M] (Radialpoint SafeCare Inc.) -- C:\Program Files\Windstream\Service Agent\ServicepointService.exe
PRC - [2011/04/25 14:34:34 | 001,393,976 | ---- | M] (Windstream) -- C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe
PRC - [2011/04/25 14:34:32 | 002,037,048 | ---- | M] (Windstream) -- C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe
PRC - [2011/02/25 00:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/08/23 20:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2009/04/02 16:33:16 | 000,128,232 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe


========== Modules (No Company Name) ==========

MOD - [2014/01/11 05:29:21 | 000,399,640 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\32.0.1700.76\ppgooglenaclpluginchrome.dll
MOD - [2014/01/11 05:29:19 | 013,615,896 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\32.0.1700.76\PepperFlash\pepflashplayer.dll
MOD - [2014/01/11 05:29:17 | 004,055,320 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\32.0.1700.76\pdf.dll
MOD - [2014/01/11 05:28:15 | 000,715,544 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\32.0.1700.76\libglesv2.dll
MOD - [2014/01/11 05:28:14 | 000,100,120 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\32.0.1700.76\libegl.dll
MOD - [2014/01/11 05:28:11 | 001,634,584 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\32.0.1700.76\ffmpegsumo.dll
MOD - [2013/12/18 10:14:42 | 000,851,968 | ---- | M] () -- C:\Program Files\NetRatingsNetSight\NetSight\meter6\npfirefoxprocessor.dll
MOD - [2013/12/18 10:14:14 | 001,246,720 | ---- | M] () -- C:\Program Files\NetRatingsNetSight\NetSight\meter6\npffaddons.dll
MOD - [2013/12/18 10:13:34 | 000,224,768 | ---- | M] () -- C:\Program Files\NetRatingsNetSight\NetSight\meter6\npwmi.dll
MOD - [2013/12/18 10:13:20 | 000,228,864 | ---- | M] () -- C:\Program Files\NetRatingsNetSight\NetSight\meter6\npsurvey.dll
MOD - [2013/12/18 10:13:08 | 000,150,528 | ---- | M] () -- C:\Program Files\NetRatingsNetSight\NetSight\meter6\npsp1.dll
MOD - [2013/12/18 10:12:44 | 000,504,832 | ---- | M] () -- C:\Program Files\NetRatingsNetSight\NetSight\meter6\communication.dll
MOD - [2013/10/30 16:49:40 | 000,504,320 | ---- | M] () -- C:\Program Files\NetRatingsNetSight\NetSight\nsmmc.dll
MOD - [2013/09/05 00:14:10 | 004,300,456 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2012/08/20 03:18:20 | 007,065,224 | ---- | M] () -- C:\Program Files\Backup Assistant Plus\V CAST Backup Scheduler.exe
MOD - [2012/08/20 03:17:50 | 000,310,272 | ---- | M] () -- C:\Program Files\Backup Assistant Plus\swscale-2.dll
MOD - [2012/08/20 03:17:48 | 002,535,936 | ---- | M] () -- C:\Program Files\Backup Assistant Plus\avformat-54.dll
MOD - [2012/08/20 03:17:48 | 000,142,848 | ---- | M] () -- C:\Program Files\Backup Assistant Plus\avutil-51.dll
MOD - [2012/08/20 03:17:46 | 013,766,656 | ---- | M] () -- C:\Program Files\Backup Assistant Plus\avcodec-54.dll
MOD - [2012/08/20 03:17:42 | 000,684,032 | ---- | M] () -- C:\Program Files\Backup Assistant Plus\libexpat.dll
MOD - [2012/08/20 03:17:40 | 000,466,975 | ---- | M] () -- C:\Program Files\Backup Assistant Plus\sqlite3.dll
MOD - [2012/05/25 03:25:00 | 000,921,600 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2011/12/06 16:00:14 | 000,784,240 | ---- | M] () -- C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
MOD - [2010/10/20 14:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\Reimage\Reimage Repair\ReiGuard.exe -- (ReimageRealTimeProtection)
SRV - [2014/01/22 22:26:37 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/01/03 02:08:14 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/12/21 01:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/12/17 14:13:18 | 000,321,024 | ---- | M] (Alcatel-Lucent) [Auto | Running] -- C:\Program Files\Windstream\8.3.1.7\ma\bin\MAHostService.exe -- (Windstream MAHostService)
SRV - [2013/12/17 12:50:28 | 000,369,152 | ---- | M] (Alcatel-Lucent) [Auto | Running] -- C:\Program Files\Common Files\Motive\pcCMService.exe -- (pcCMService)
SRV - [2013/10/30 16:51:34 | 002,838,568 | ---- | M] (The Nielsen Company) [Auto | Running] -- C:\Program Files\NetRatingsNetSight\NetSight\NielsenUpdate.exe -- (NielsenUpdate)
SRV - [2013/10/23 15:01:10 | 000,280,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/10/23 15:01:10 | 000,022,208 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2013/08/14 14:19:24 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2013/06/28 17:48:04 | 000,014,624 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2013/06/19 22:13:16 | 002,445,304 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon)
SRV - [2013/06/18 02:34:34 | 000,054,160 | ---- | M] (Check Point Software Technologies, Ltd.) [Auto | Running] -- C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe -- (ZAPrivacyService)
SRV - [2013/06/04 04:15:04 | 002,337,320 | ---- | M] (NCH Software) [On_Demand | Stopped] -- C:\Program Files\NCH Software\ExpressInvoice\expressinvoice.exe -- (ExpressInvoiceService)
SRV - [2013/05/26 23:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/03/17 22:41:44 | 001,070,080 | ---- | M] (iolo technologies, LLC) [Auto | Running] -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe -- (ioloSystemService)
SRV - [2013/03/09 00:10:32 | 030,798,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2012/11/22 09:33:18 | 000,497,320 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe -- (IswSvc)
SRV - [2012/05/05 12:21:33 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/12/06 16:00:14 | 000,214,896 | ---- | M] () [Auto | Running] -- C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe -- (MotoHelper)
SRV - [2011/11/14 14:13:36 | 000,563,104 | ---- | M] (Affinegy, Inc.) [Disabled | Stopped] -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe -- (AffinegyService)
SRV - [2011/10/13 22:28:20 | 010,315,064 | ---- | M] (Radialpoint SafeCare Inc.) [Auto | Running] -- C:\Program Files\Windstream\Service Agent\ServicepointService.exe -- (ServicepointService)
SRV - [2011/04/25 14:34:34 | 001,393,976 | ---- | M] (Windstream) [Auto | Running] -- C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe -- (HsdService)
SRV - [2011/04/01 11:14:30 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/03/28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010/08/23 20:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
SRV - [2009/07/13 20:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/13 20:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 20:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


========== Driver Services (SafeList) ==========

DRV - File not found [Adapter | Unavailable | Unknown] -- -- (PnSson)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS -- (MRENDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS -- (MREMPR5)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\dsNcAdpt.sys -- (dsNcAdpt)
DRV - [2013/12/18 10:11:56 | 000,023,080 | ---- | M] (The Nielsen Company) [Kernel | System | Running] -- C:\Program Files\NetRatingsNetSight\NetSight\meter6\nnfwdk.sys -- (nnfwdk)
DRV - [2013/09/27 09:53:06 | 000,104,768 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2013/06/13 15:34:14 | 000,455,704 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\Windows\System32\drivers\vsdatant.sys -- (Vsdatant)
DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013/03/17 22:36:22 | 000,068,464 | ---- | M] (Raxco Software, Inc.) [File_System | Auto | Running] -- C:\Windows\System32\drivers\PDFsFilter.sys -- (PDFsFilter)
DRV - [2013/03/17 22:36:16 | 000,026,248 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\ElRawDsk.sys -- (ElRawDisk)
DRV - [2012/11/22 09:33:30 | 000,027,056 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
DRV - [2012/11/15 20:06:10 | 000,587,096 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV - [2012/08/23 09:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012/08/23 09:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2012/03/19 09:18:46 | 000,064,800 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2011/11/08 11:59:04 | 000,011,008 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motusbdevice.sys -- (motusbdevice)
DRV - [2010/11/20 07:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 07:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 07:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 04:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 04:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 04:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/02/02 15:09:42 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2010/02/02 15:09:42 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2010/01/29 01:03:58 | 000,030,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nx6000.sys -- (MSHUSBVideo)
DRV - [2009/09/09 17:19:16 | 000,069,664 | ---- | M] (O2Micro) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\oz776.sys -- (guardian2)
DRV - [2009/07/13 17:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32)
DRV - [2007/02/03 10:32:36 | 000,041,504 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007/02/03 10:25:56 | 001,075,360 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Camdrl.sys -- (CamDrL)
DRV - [2005/07/19 17:42:22 | 000,073,152 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cur_serd.sys -- (cur_serd)
DRV - [2005/07/19 17:40:56 | 000,093,328 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cur_mdm.sys -- (cur_mdm)
DRV - [2005/07/19 17:40:52 | 000,008,336 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cur_mdfl.sys -- (cur_mdfl)
DRV - [2005/07/19 17:39:24 | 000,057,744 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cur_bus.sys -- (cur_bus)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?ilc=8
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{5a1d0d31-749c-4186-a295-4106e6e7b26a}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A8 95 CB CB D7 17 CF 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search By ZoneAlarm"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo....h?fr=mkg030&p="
FF - prefs.js..browser.search.order.1: "Search By ZoneAlarm"
FF - prefs.js..browser.search.selectedEngine: "Search By ZoneAlarm"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.zoneal...&tstsId=&ver=&"
FF - prefs.js..extensions.enabledAddons: donottrack%40checkpoint.com:2.2.5.1213
FF - prefs.js..extensions.enabledAddons: %7B7affbfae-c4e2-4915-8c0f-00fa3ec610a1%7D:5.74.1.9660
FF - prefs.js..extensions.enabledAddons: %7BDF153AFF-6948-45d7-AC98-4FC4AF8A08E2%7D:1.3.3
FF - prefs.js..extensions.enabledAddons: %7BE0B8C461-F8FB-49b4-8373-FE32E9252800%7D:5.9.1
FF - prefs.js..extensions.enabledAddons: netsight%40nielsen.com:2.3.4
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0
FF - prefs.js..keyword.URL: "http://search.zoneal...&tstsId=&ver=&"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@Citrix.com/npican: C:\Users\Clifton Work\AppData\Local\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Windstream\8.3.1.7\ma\bin\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@Motive.com/npMotiveRequest,version=1.0: C:\Program Files\Common Files\Motive\npMotiveRequest.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@nielsen/FirefoxTracker: C:\Program Files\NetRatingsNetSight\NetSight\meter6\FirefoxAddOns\npfirefoxtracker.dll (Nielsen)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Windstream\Service Agent\nprpspa.dll (Windstream)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Clifton Work\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Clifton Work\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Clifton Work\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Clifton Work\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Clifton Work\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Clifton Work\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/10/06 22:16:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2013/07/22 10:58:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/10/06 22:16:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\NetRatingsNetSight\NetSight\meter6\FirefoxAddOns\[email protected] [2014/01/26 10:15:35 | 000,009,382 | ---- | M] ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014/01/22 13:42:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014/01/22 22:36:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 2.13.1\extensions\\Components: C:\Program Files\SeaMonkey\components [2012/10/24 12:55:23 | 000,000,000 | ---D | M]

[2014/01/22 12:11:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Clifton Work\AppData\Roaming\Mozilla\Extensions
[2014/01/09 10:45:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Clifton Work\AppData\Roaming\Mozilla\Firefox\Profiles\467btbau.default\extensions
[2013/08/21 08:06:18 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Clifton Work\AppData\Roaming\Mozilla\Firefox\Profiles\467btbau.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013/09/20 22:38:27 | 000,000,000 | ---D | M] (AOL Toolbar) -- C:\Users\Clifton Work\AppData\Roaming\Mozilla\Firefox\Profiles\467btbau.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}
[2014/01/09 10:45:39 | 000,000,000 | ---D | M] (Evernote Web Clipper) -- C:\Users\Clifton Work\AppData\Roaming\Mozilla\Firefox\Profiles\467btbau.default\extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}
[2013/01/17 12:31:52 | 000,000,000 | ---D | M] (ZoneAlarm Do Not Track) -- C:\Users\Clifton Work\AppData\Roaming\Mozilla\Firefox\Profiles\467btbau.default\extensions\[email protected]
[2014/01/23 11:47:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Clifton Work\AppData\Roaming\Mozilla\SeaMonkey\Profiles\3cmrq7rx.default\extensions
[2014/01/23 11:47:26 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\Clifton Work\AppData\Roaming\Mozilla\SeaMonkey\Profiles\3cmrq7rx.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2014/01/23 11:47:24 | 000,000,000 | ---D | M] (DOM Inspector) -- C:\Users\Clifton Work\AppData\Roaming\Mozilla\SeaMonkey\Profiles\3cmrq7rx.default\extensions\[email protected]
[2013/01/17 12:22:29 | 000,007,919 | ---- | M] () (No name found) -- C:\Users\Clifton Work\AppData\Roaming\Mozilla\Firefox\Profiles\467btbau.default\extensions\[email protected]\chrome\content\ff\view_expiry.js
[2013/08/28 11:56:25 | 000,001,502 | ---- | M] () -- C:\Users\Clifton Work\AppData\Roaming\Mozilla\Firefox\Profiles\467btbau.default\searchplugins\zonealarm.xml
[2014/01/12 14:22:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/01/23 09:54:22 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014/01/26 10:15:35 | 000,009,382 | ---- | M] () (No name found) -- C:\PROGRAM FILES\NETRATINGSNETSIGHT\NETSIGHT\METER6\FIREFOXADDONS\[email protected]
[2013/10/06 22:16:51 | 000,000,000 | ---D | M] (RealDownloader) -- C:\PROGRAMDATA\REALNETWORKS\REALDOWNLOADER\BROWSERPLUGINS\FIREFOX\EXT
[2012/03/28 02:04:52 | 000,124,864 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CCMSDK.dll
[2012/03/28 02:06:54 | 000,071,104 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CgpCore.dll
[2012/03/28 02:05:52 | 000,092,096 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\confmgr.dll
[2012/03/28 02:05:28 | 000,022,976 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\ctxlogging.dll
[2012/01/12 03:58:30 | 000,917,816 | ---- | M] (BitComet) -- C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll
[2012/03/28 02:48:16 | 000,489,384 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npicaN.dll
[2013/10/06 22:14:46 | 000,124,504 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/03/28 02:06:48 | 000,024,512 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\TcpPServ.dll

========== Chrome ==========

CHR - default_search_provider: Bing (Enabled)
CHR - default_search_provider: search_url = http://www.bing.com/...q={searchTerms}
CHR - default_search_provider: suggest_url = http://api.bing.com/...uage={language},
CHR - Extension: Motive Extension = C:\Users\Clifton Work\AppData\Local\Google\Chrome\User Data\Default\Extensions\edmgmpmklgfbohogafcfobonnkogchec\1.2.2_1\
CHR - Extension: RealDownloader = C:\Users\Clifton Work\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.3_1\
CHR - Extension: Nielsen = C:\Users\Clifton Work\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgceplfonlgodadnpognljgdjlcnpjnh\1.8.1_2\
CHR - Extension: Radialpoint SPD Extension = C:\Users\Clifton Work\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmmhpfbhngkongobaoibpmnijjokabmj\1.0_1\
CHR - Extension: Google Wallet = C:\Users\Clifton Work\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0\

O1 HOSTS File: ([2014/01/17 12:01:07 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\PROGRA~1\SITERA~1\SiteRank.dll File not found
O2 - BHO: (Zonealarm Helper Object) - {2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} - C:\Program Files\Check Point Software Technologies LTD\zonealarm\1.8.22.0\bh\zonealarm.dll (Check Point Software Technologies LTD)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (ZoneAlarm Do Not Track Me) - {6E45F3E8-2683-4824-A6BE-08108022FB36} - C:\Program Files\Check Point Software Technologies LTD\zonealarm\AbineSDK\IE\DNTPAddon.dll (Abine)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Toolbar) - {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - C:\Program Files\Check Point Software Technologies LTD\zonealarm\1.8.22.0\zonealarmTlbr.dll (Check Point Software Technologies LTD)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [CitrixReceiver] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk" File not found
O4 - HKLM..\Run: [ConnectionCenter] C:\Users\Clifton Work\AppData\Local\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [DiagnosticTools.exe] C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\nielsenonline.exe (The Nielsen Company)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windstream_BCUC_McciTrayApp] C:\Program Files\Windstream_BCUC\pcTrayApp.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [BitComet] C:\Program Files\BitComet\BitComet.exe /tray File not found
O4 - HKCU..\Run: [HLBackupScheduler] C:\Program Files\Backup Assistant Plus\V CAST Backup Scheduler.exe ()
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: adobeconnect.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: adobeconnect.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: adobeconnect.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: directv.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: directv.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: directv.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: exodusvipdesk.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: newcorp.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: newcorp.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: newcorp.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: vipdesk.com ([]* in Trusted sites)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://ns.arise.com...SetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{30DF12E7-4CA7-4345-9E19-7D1109C11D63}: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1E3C20F-576A-4C0C-9562-12AB69E9727C}: DhcpNameServer = 192.168.254.254
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\BelarcAdvisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll File not found
O18 - Protocol\Handler\rebinfo - No CLSID value found
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{b470621d-285d-11e2-996b-001c232150bb}\Shell - "" = AutoRun
O33 - MountPoints2\{b470621d-285d-11e2-996b-001c232150bb}\Shell\AutoRun\command - "" = "E:\EasySuite .exe" bootup
O33 - MountPoints2\{b55ab518-0ad3-11e3-9511-001c232150bb}\Shell - "" = AutoRun
O33 - MountPoints2\{b55ab518-0ad3-11e3-9511-001c232150bb}\Shell\AutoRun\command - "" = "E:\EasySuite .exe" bootup
O33 - MountPoints2\{df9d9824-a77f-11e2-8e30-001c232150bb}\Shell - "" = AutoRun
O33 - MountPoints2\{df9d9824-a77f-11e2-8e30-001c232150bb}\Shell\AutoRun\command - "" = E:\setup.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2014/01/25 23:47:28 | 000,000,000 | ---D | C] -- C:\Users\Clifton Work\AppData\Roaming\Malwarebytes
[2014/01/25 23:47:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2014/01/25 23:47:12 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2014/01/25 23:47:12 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2014/01/24 22:06:45 | 000,000,000 | ---D | C] -- C:\Users\Clifton Work\AppData\Local\SlimWare Utilities Inc
[2014/01/24 22:05:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdate
[2014/01/24 22:05:45 | 000,000,000 | ---D | C] -- C:\Program Files\DriverUpdate
[2014/01/24 22:04:52 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Downloaded Installers
[2014/01/24 22:04:48 | 000,000,000 | ---D | C] -- C:\ProgramData\CDB
[2014/01/24 22:03:12 | 000,000,000 | ---D | C] -- C:\Program Files\Reimage
[2014/01/24 22:03:04 | 000,000,000 | ---D | C] -- C:\rei
[2014/01/24 21:32:45 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Installer Clean Up
[2014/01/24 20:36:29 | 000,000,000 | ---D | C] -- C:\Users\Clifton Work\AppData\Roaming\TeamViewer
[2014/01/23 12:59:09 | 000,000,000 | ---D | C] -- C:\Users\Clifton Work\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Juniper Networks
[2014/01/22 22:35:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2014/01/22 22:22:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014/01/22 18:53:07 | 002,617,648 | ---- | C] (VS Revo Group Ltd.) -- C:\Users\Clifton Work\Desktop\revosetup.exe
[2014/01/22 13:11:06 | 001,417,888 | ---- | C] (Juniper Networks, Inc.) -- C:\Users\Clifton Work\Desktop\JuniperSetupClientInstaller.exe
[2014/01/22 12:15:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lunascape6
[2014/01/22 09:40:16 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2014/01/17 22:00:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TurboTax 2012
[2014/01/17 21:10:01 | 000,000,000 | ---D | C] -- C:\Users\Clifton Work\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2014/01/17 21:10:00 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2014/01/12 14:21:54 | 000,000,000 | ---D | C] -- C:\Program Files\Windstream_BCUC
[2014/01/12 14:16:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Motive
[2014/01/12 14:15:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Motive
[2014/01/10 15:57:48 | 000,000,000 | R--D | C] -- C:\Users\Clifton Work\Documents\Scanned Documents
[2014/01/10 15:57:46 | 000,000,000 | ---D | C] -- C:\Users\Clifton Work\Documents\Fax
[2014/01/10 01:40:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\HP
[2014/01/07 19:07:00 | 000,000,000 | -HSD | C] -- C:\found.009
[2014/01/07 11:42:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Citrix
[2014/01/07 11:39:19 | 000,000,000 | ---D | C] -- C:\Program Files\Citrix
[2014/01/06 08:15:00 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2014/01/03 13:17:34 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2014/01/03 02:06:24 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox

========== Files - Modified Within 30 Days ==========

[2014/01/26 10:23:57 | 000,019,312 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/01/26 10:23:57 | 000,019,312 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/01/26 10:23:54 | 000,000,408 | ---- | M] () -- C:\Windows\tasks\DriverUpdate Startup.job
[2014/01/26 10:19:01 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3888922825-2840281166-3677602912-1006UA.job
[2014/01/26 10:14:48 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/01/26 10:11:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/01/26 10:11:44 | 1602,838,528 | -HS- | M] () -- C:\hiberfil.sys
[2014/01/26 10:11:04 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/01/26 10:00:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/01/25 23:47:20 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/01/25 17:19:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3888922825-2840281166-3677602912-1006Core.job
[2014/01/24 22:17:10 | 000,000,163 | ---- | M] () -- C:\Windows\Reimage.ini
[2014/01/24 22:08:48 | 427,058,007 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2014/01/24 22:05:47 | 000,002,457 | ---- | M] () -- C:\Users\Public\Desktop\DriverUpdate.lnk
[2014/01/24 21:18:06 | 000,369,424 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/01/24 10:01:06 | 000,003,640 | ---- | M] () -- C:\Users\Clifton Work\Desktop\moovie.xspf
[2014/01/23 17:07:34 | 000,001,417 | ---- | M] () -- C:\Users\Clifton Work\Desktop\Internet Explorer.lnk
[2014/01/23 09:54:50 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2014/01/22 23:06:36 | 000,007,597 | ---- | M] () -- C:\Users\Clifton Work\AppData\Local\resmon.resmoncfg
[2014/01/22 22:36:37 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014/01/22 18:32:58 | 000,000,288 | ---- | M] () -- C:\Users\Clifton Work\Documents\012214regbackup.reg
[2014/01/22 14:55:09 | 001,417,888 | ---- | M] (Juniper Networks, Inc.) -- C:\Users\Clifton Work\Desktop\JuniperSetupClientInstaller.exe
[2014/01/22 13:43:38 | 000,002,859 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Online plug-in.lnk
[2014/01/17 22:00:02 | 000,002,503 | ---- | M] () -- C:\Users\Public\Desktop\TurboTax 2012.lnk
[2014/01/17 17:12:43 | 074,369,926 | ---- | M] () -- C:\Users\Clifton Work\Documents\011714regbackup.reg
[2014/01/17 15:03:06 | 000,001,331 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2014/01/15 05:04:40 | 000,002,129 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/01/14 10:39:10 | 000,007,849 | -H-- | M] () -- C:\Windows\System32\BTImages.dat
[2014/01/10 15:59:51 | 000,001,210 | ---- | M] () -- C:\Users\Clifton Work\Desktop\Windows Fax and Scan.lnk
[2014/01/10 01:45:16 | 000,143,050 | ---- | M] () -- C:\Windows\hpwins28.dat
[2014/01/06 11:55:37 | 000,662,634 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/01/06 11:55:37 | 000,122,470 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/01/06 11:48:36 | 000,417,570 | ---- | M] () -- C:\Windows\System32\drivers\vsconfig.xml
[2014/01/03 13:25:11 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif

========== Files Created - No Company Name ==========

[2014/01/25 23:47:20 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/01/24 22:07:10 | 000,000,408 | ---- | C] () -- C:\Windows\tasks\DriverUpdate Startup.job
[2014/01/24 22:05:47 | 000,002,457 | ---- | C] () -- C:\Users\Public\Desktop\DriverUpdate.lnk
[2014/01/24 22:02:02 | 000,000,163 | ---- | C] () -- C:\Windows\Reimage.ini
[2014/01/24 21:32:46 | 000,002,885 | ---- | C] () -- C:\Users\Clifton Work\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Install Clean Up.lnk
[2014/01/24 10:01:06 | 000,003,640 | ---- | C] () -- C:\Users\Clifton Work\Desktop\moovie.xspf
[2014/01/23 17:07:34 | 000,001,417 | ---- | C] () -- C:\Users\Clifton Work\Desktop\Internet Explorer.lnk
[2014/01/22 23:06:17 | 000,007,597 | ---- | C] () -- C:\Users\Clifton Work\AppData\Local\resmon.resmoncfg
[2014/01/22 22:36:37 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2014/01/22 22:36:37 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014/01/22 20:07:42 | 000,001,417 | ---- | C] () -- C:\Users\Clifton Work\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014/01/22 18:32:58 | 000,000,288 | ---- | C] () -- C:\Users\Clifton Work\Documents\012214regbackup.reg
[2014/01/22 13:43:38 | 000,002,859 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Online plug-in.lnk
[2014/01/17 22:00:02 | 000,002,503 | ---- | C] () -- C:\Users\Public\Desktop\TurboTax 2012.lnk
[2014/01/17 17:12:25 | 074,369,926 | ---- | C] () -- C:\Users\Clifton Work\Documents\011714regbackup.reg
[2014/01/17 16:20:26 | 000,002,526 | ---- | C] () -- C:\Users\Public\Desktop\Morph 2012.lnk
[2014/01/14 23:02:49 | 427,058,007 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2014/01/10 15:59:51 | 000,001,210 | ---- | C] () -- C:\Users\Clifton Work\Desktop\Windows Fax and Scan.lnk
[2014/01/10 01:28:01 | 000,143,050 | ---- | C] () -- C:\Windows\hpwins28.dat
[2014/01/10 01:28:01 | 000,000,418 | ---- | C] () -- C:\Windows\hpwmdl28.dat
[2014/01/08 18:34:59 | 000,000,418 | ---- | C] () -- C:\Windows\hpwmdl28.dat.temp
[2014/01/08 18:08:18 | 000,001,096 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bolt PDF Printer.lnk
[2014/01/03 13:18:05 | 000,002,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013/07/27 21:08:41 | 000,007,849 | -H-- | C] () -- C:\Windows\System32\BTImages.dat
[2013/07/07 23:38:46 | 000,499,712 | ---- | C] () -- C:\Windows\iwexec.exe
[2013/06/18 12:41:37 | 000,000,697 | ---- | C] () -- C:\Users\Clifton Work\Libraries - Shortcut.lnk
[2013/04/19 14:13:38 | 000,057,344 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2013/04/01 14:33:40 | 000,074,703 | ---- | C] () -- C:\Windows\System32\mfc45.dat
[2013/03/13 13:22:31 | 000,000,211 | ---- | C] () -- C:\Windows\btw.ini
[2013/03/13 13:22:27 | 000,111,104 | ---- | C] () -- C:\Windows\System32\MVCL13N.DLL
[2013/03/09 14:31:29 | 000,044,544 | ---- | C] () -- C:\Windows\System32\gif89.dll
[2013/03/09 14:28:34 | 000,000,555 | ---- | C] () -- C:\Windows\SIERRA.INI
[2013/01/09 15:13:21 | 000,001,109 | ---- | C] () -- C:\Users\Clifton Work\Pictures - Shortcut.lnk
[2012/11/27 19:25:35 | 000,000,120 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2012/11/27 19:07:12 | 000,001,331 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2012/11/06 14:50:28 | 000,000,362 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012/08/20 03:18:30 | 000,602,112 | ---- | C] () -- C:\Windows\System32\xvid.dll
[2012/05/05 18:09:55 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012/05/05 03:46:31 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll

========== ZeroAccess Check ==========

[2009/07/13 23:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 20:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 07:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/13 20:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/10/18 10:02:34 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\.mono
[2012/11/27 10:27:40 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\24x7 Help
[2013/12/22 19:30:36 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\BitComet
[2013/04/29 12:16:38 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\Check Point Software Technologies LTD
[2012/11/27 10:23:23 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\CheckPoint
[2012/12/19 12:31:05 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\ICAClient
[2013/04/01 15:35:52 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\iolo
[2014/01/22 13:56:25 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\Juniper Networks
[2013/08/13 15:44:44 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\Lunascape
[2013/04/19 12:19:39 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\Motorola
[2013/06/13 16:43:31 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\OnlineVault
[2013/03/22 08:06:12 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\Opera
[2014/01/12 12:39:48 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\Radialpoint
[2013/07/05 10:37:05 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\SystemRequirementsLab
[2014/01/24 20:36:29 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\TeamViewer
[2013/04/01 22:59:19 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\Unity
[2013/07/06 16:43:08 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\Windows Live Writer
[2013/09/17 14:19:24 | 000,000,000 | ---D | M] -- C:\Users\Clifton Work\AppData\Roaming\Windstream

========== Purity Check ==========



< End of report >

extra.txt
OTL Extras logfile created on: 1/26/2014 10:32:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Clifton Work\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16750)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.39 Gb Available Physical Memory | 19.39% Memory free
4.43 Gb Paging File | 2.50 Gb Available in Paging File | 56.34% Paging File free
Paging file location(s): c:\pagefile.sys 2500 3000e:\pagef [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.43 Gb Total Space | 9.04 Gb Free Space | 12.14% Space Free | Partition Type: NTFS

Computer Name: SHAWN-LAPTOP | User Name: Clifton Work | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = SeaMonkeyHTML] -- C:\Program Files\SeaMonkey\seamonkey.exe (mozilla.org)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0538E8AE-6ADC-465C-86C9-39C420E932BB}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{09828B6A-FFD6-4074-8644-DE786E3F5857}" = lport=139 | protocol=6 | dir=in | app=system |
"{11E660D5-DDE2-422F-86F3-48720DBDEBF3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{14F05E5B-ACA3-4AB1-81A6-B08E0202B885}" = lport=137 | protocol=17 | dir=in | app=system |
"{1DBC21CB-A833-48E4-B5EF-31F2476389E4}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service v4\intuitupdateservice.exe |
"{2194A64B-515F-4324-BCC6-43F43F466DD5}" = rport=2869 | protocol=6 | dir=out | app=system |
"{32CED2C1-2731-44EE-9157-F09FFC1F2392}" = lport=2869 | protocol=6 | dir=in | app=system |
"{33C4C63E-2694-4B76-A5B3-0C43C5E771FA}" = rport=9100 | protocol=6 | dir=out | name=hp 4500 g |
"{4273FC26-C53E-4E00-8E9C-47171B143B39}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{4A709676-A62C-4933-BA0D-EF687477CC48}" = rport=445 | protocol=6 | dir=out | app=system |
"{4AC461D5-56F4-46D9-8E57-88508F81807B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{50002531-6E55-43D1-BF6F-4DE52084C5B9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{527CAA2D-D4CC-4AC1-8982-F6890EB47261}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdater.exe |
"{59D31165-D319-4A20-A528-EAD353E1FCCF}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{603FAED1-672B-41CC-BB17-F98C39FDE5F1}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{614D984B-9055-4403-9CF3-9C20FD26503C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{63F75998-E6F0-466A-A64C-5413BCC06679}" = rport=138 | protocol=17 | dir=out | app=system |
"{68BA8A0F-4587-4ABC-BDA7-08EB7F6F0A8B}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service v4\intuitupdater.exe |
"{745D0718-37DF-45F4-9086-4FF42D5724F8}" = rport=139 | protocol=6 | dir=out | app=system |
"{753D14D9-20C3-496A-A00D-5E5D75ED6375}" = rport=137 | protocol=17 | dir=out | app=system |
"{77649E9E-D757-4DC6-8696-52BA5BCE56B3}" = lport=445 | protocol=6 | dir=in | app=system |
"{80E751F2-8814-4A3B-9C66-1452912819FF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8127C3EB-D659-42C3-A564-A006C68F9A30}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{843A82EB-DEE0-4FFF-A65A-99F3FB1DC8FB}" = lport=138 | protocol=17 | dir=in | app=system |
"{87F3FEF7-EB02-4FA5-A715-07BA13E6348E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{9C27519B-73B5-4729-ACC7-89C35C2BE6D4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AC52F4FA-8497-455D-BEB8-8CCCE4B37124}" = lport=10243 | protocol=6 | dir=in | app=system |
"{ADED7AA2-BE85-45FC-ABFF-7008C8CFF3D9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B9DD3A0B-31C5-48C7-91DB-701213F97E55}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{C678D412-6E03-4D3A-9EEC-BB028B1F50F5}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C8E2DE59-BD83-4B79-B2AF-C15AD14CB045}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CA1E12AF-329A-427F-9B44-8D76C96B0459}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CA4D9D57-7904-4339-96AC-2AD891309FA6}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{CD4A1FBB-3727-4449-82CC-3851B403D902}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{CF9F4556-DFDF-4A6B-B761-B28647590CA0}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{D3179598-7817-40C8-93F5-D0CF529F3DBD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D5567579-0672-48F5-A9A4-3D90C31C760C}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdateservice.exe |
"{E31442A5-FA77-454B-B8F8-961203FB0EB0}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{EA60F4A3-41F2-44DA-BAE2-9F61EC5C7D43}" = rport=10243 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02A01C7C-0DCC-4CC0-8AC3-51663C4E2498}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{0696A4B2-DFDE-41B0-BD4C-1D21287B22A8}" = protocol=17 | dir=in | app=c:\users\clifton work\appdata\local\temp\7zs5937\hpdiagnosticcoreui.exe |
"{06EB5EA2-B405-4473-9506-7A3C0563DC3E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxm08.exe |
"{0882319F-B85D-4A54-B44E-8D7F1E4509FB}" = protocol=6 | dir=out | app=system |
"{0DD397E6-1D13-4C9C-BBF2-3E9E0A551F54}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{0FBF4991-35F5-4CA2-B5A5-08884614A63F}" = dir=in | app=c:\program files\belkin\router setup and monitor\belkinsetup.exe |
"{1BDB2D67-4BC1-44D8-9522-1F7419FF5AA1}" = protocol=17 | dir=in | app=c:\users\clifton work\appdata\local\temp\7zs4f82\hppiw.exe |
"{1CFA0ECD-1DF8-4A05-9194-A66701735CED}" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |
"{22CBBC96-E064-4355-86C7-703DFA25F8CA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{23DEE816-3B3A-4F5E-B509-9E6C6AF8BD5A}" = protocol=6 | dir=in | app=c:\users\clifton work\appdata\local\temp\7zs4f82\hppiw.exe |
"{25AD06D6-9F66-4407-9305-CE3FDF26BC3D}" = protocol=6 | dir=in | app=c:\program files\backup assistant plus\v cast backup scheduler.exe |
"{279A7BD3-E3EE-4560-93F3-02C998580885}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{2ABCAC70-64A9-48AE-BD5B-A936B867F581}" = protocol=17 | dir=in | app=c:\users\clifton work\appdata\local\temp\7zs4ed2\hpdiagnosticcoreui.exe |
"{2C9A6DC3-556A-4548-A35F-07BA3141D3B2}" = protocol=6 | dir=in | app=c:\users\clifton work\appdata\local\temp\7zs51ee\hpdiagnosticcoreui.exe |
"{2D7ADB4A-B052-4740-A9BB-ABBDA1F3D23E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2F316EDB-DCAF-4BB1-9757-BAAA7BD449BD}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposfx08.exe |
"{349E0C3C-581D-4085-8EB6-B9588E559EEB}" = protocol=17 | dir=in | app=c:\program files\windstream\service agent\servicepointservice.exe |
"{3521E0FF-B686-4C1B-B01C-E7DC6AA718D3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe |
"{366B8E06-5618-419B-B149-B56603FA07E7}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 1000 j110 series\bin\usbsetup.exe |
"{3E4D8448-3270-48C6-8452-B9A1401644AF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{419DA4F0-0A57-44CB-A119-118C5AF04794}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{4810484D-8BC6-4A74-9DC9-4D4ABC232319}" = protocol=17 | dir=in | app=c:\program files\belkin\router setup and monitor\belkinsetup.exe |
"{499CFF02-5606-4DA9-9A89-92D45F153D71}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{49A98E69-E81D-4723-A9C1-964C0872E126}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{4A41A4B0-7B06-4DFB-8363-265A4F31356A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4C8A6068-8A66-4F43-BC82-D7391166888D}" = protocol=17 | dir=in | app=c:\program files\belkin\router setup and monitor\belkinsetup.exe |
"{60BD85C9-DA91-4406-BF33-A39DE8758332}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpzwiz01.exe |
"{639052C2-94A7-4D5F-957B-108E4A2674BE}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"{65954ACC-EA9D-447A-86EB-3709568236C1}" = protocol=17 | dir=in | app=c:\users\clifton work\appdata\local\temp\7zs2f1f\hpdiagnosticcoreui.exe |
"{687DEFF5-62DF-4EA1-8BF0-80D8D2130403}" = dir=in | app=d:\setup\hpznui01.exe |
"{6A71C7C7-D746-4867-9674-D675D01A16CA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6DA10CB1-1BBD-48A2-A645-90CF79C0DA1E}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{6DB28CF9-FB53-4504-871B-197ED3BEB47E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{6DE090FB-88FE-4F27-B3E6-856F63CE1B75}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{746D673C-064B-4191-847F-F91986282DB0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7515243A-B31F-4137-8320-6910EC7121B6}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 1000 j110 series\bin\usbsetup.exe |
"{76582735-D83B-4EAA-A5B5-81C56C01376F}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{79D4693C-8F35-4C3E-ADED-6A0130C3C108}" = protocol=1 | dir=out | [email protected],-28544 |
"{83155746-74DB-4821-8C4E-1EE413BFD40D}" = protocol=17 | dir=in | app=c:\program files\backup assistant plus\v cast backup scheduler.exe |
"{85E36B03-7D7E-4E4A-A370-F0268718B9A6}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{8D2FC11B-CC13-4985-A516-8D8B50A5442D}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9A25F7C2-ABEC-48EC-958B-3664F13306F3}" = protocol=17 | dir=in | app=c:\users\clifton work\appdata\local\temp\7zs51ee\hpdiagnosticcoreui.exe |
"{9C1464CA-5F89-488B-A1BC-F741BC917700}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{9D0154FB-3FC0-40A7-9B2A-EE9B66F01CBC}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{9D8C1A66-9437-4D08-B6DD-3C1E69D64F7D}" = protocol=58 | dir=in | [email protected],-148 |
"{9E265860-DD1B-445A-BDDE-78FD14E212B1}" = dir=in | app=c:\users\clifton work\appdata\local\microsoft\skydrive\skydrive.exe |
"{A5D5C095-3A3F-4A0B-A59D-3C4D75D3F806}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqfxt08.exe |
"{AE16C4DF-1D19-4204-B0EA-F526DC6172F9}" = protocol=6 | dir=in | app=c:\users\clifton work\appdata\local\temp\7zs4ed2\hpdiagnosticcoreui.exe |
"{AF1036A5-FA3C-4DCE-97B9-036C10661376}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{B3255AB0-9CFD-40FC-B015-A8BE5F350383}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"{B3B6085D-490B-4436-B1DD-00A836669D19}" = protocol=6 | dir=in | app=c:\users\clifton work\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{B440CDBA-2D9B-4036-B0EC-2C595D4C6A4C}" = protocol=6 | dir=in | app=c:\users\clifton work\appdata\local\temp\7zs2f1f\hpdiagnosticcoreui.exe |
"{B445CF2F-BB8B-4BD8-92AD-923F935D33FE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B6CCC0E4-AD5D-495D-803D-228ED8E03E99}" = protocol=58 | dir=out | [email protected],-28546 |
"{B8E3C093-0990-411D-9C6B-C1BFE4512CBC}" = protocol=6 | dir=in | app=c:\program files\windstream\service agent\servicepointservice.exe |
"{BD3899D0-024B-453E-8D02-119A18E11452}" = protocol=58 | dir=in | [email protected],-28545 |
"{BE5A8DF4-DA33-4CFD-B543-5852D2148D7C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C1307DC1-B0BC-4B67-8045-9BA0ED004E55}" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |
"{C2416F39-2BE9-4D89-8E15-C1D03490B46F}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{C3486108-1A0C-4B51-B864-E352BA32CBE5}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{C74CF964-E461-41E9-BBF8-E266D5A2CDE0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CAB61283-B861-4CD4-AEDE-DBD46CA400E8}" = protocol=6 | dir=in | app=c:\program files\belkin\router setup and monitor\belkinsetup.exe |
"{CD2FEAA7-0B16-4639-AEC0-9A5D97A70212}" = protocol=17 | dir=in | app=c:\users\clifton work\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{D7BFDB1E-A12B-48BC-9CD4-CDC208D2F6A4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{E18B80FB-2B61-4589-88DD-7450483B5F1D}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{E1DFAEDA-0F96-4616-BFA2-60CF7C9F38A3}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxs08.exe |
"{E4288BD0-6104-44A5-A12B-E8A7172C3D21}" = protocol=6 | dir=in | app=c:\users\clifton work\appdata\local\temp\7zs5937\hpdiagnosticcoreui.exe |
"{E58C644E-A35F-4151-8A9B-4E77870D8C53}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{E7E7316A-31D3-4F67-9875-5E17523CF14F}" = protocol=1 | dir=in | [email protected],-28543 |
"{EA06AA1B-FE13-40B5-8A4B-B98B50E329FF}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{EA1A1431-7A53-4A53-8861-6EEB331471B7}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{F845B64F-7844-4918-B691-6CB5124848AF}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{F8C0B4BD-8C99-40EA-9795-5A7DF23241C4}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{FCF7B80B-88BE-438F-AD96-387D10526B34}" = protocol=6 | dir=in | app=c:\program files\belkin\router setup and monitor\belkinsetup.exe |
"TCP Query User{5C121E21-9A8A-405E-A7EE-22ED12810972}C:\program files\backup assistant plus\v cast backup scheduler.exe" = protocol=6 | dir=in | app=c:\program files\backup assistant plus\v cast backup scheduler.exe |
"TCP Query User{6B0D1932-3537-4867-B1A8-DC4C68B64256}C:\program files\backup assistant plus\verizon.exe" = protocol=6 | dir=in | app=c:\program files\backup assistant plus\verizon.exe |
"UDP Query User{49256C6E-3049-43B3-83A7-93D532696116}C:\program files\backup assistant plus\v cast backup scheduler.exe" = protocol=17 | dir=in | app=c:\program files\backup assistant plus\v cast backup scheduler.exe |
"UDP Query User{726931AF-698D-42B0-AD68-89448EAEBFAB}C:\program files\backup assistant plus\verizon.exe" = protocol=17 | dir=in | app=c:\program files\backup assistant plus\verizon.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{026C3D27-9BE1-46BE-BEAE-6DE38A0F4FBE}" = RealNetworks - Microsoft Visual C++ 2005 Runtime
"{02A0375F-61CA-4C5A-A872-2CA47BB4F6DE}" = TurboTax 2011 wtniper
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{03D2295C-BC43-4567-9477-DA8587DA851C}" = TurboTax 2012 wndiper
"{03DF638A-D61C-4893-B8B9-845900C03163}" = TurboTax 2010 wnyiper
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{04BA3D07-B94F-4AF5-8EB3-F4E69DB40116}" = TurboTax 2012 widiper
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{0A7DD94B-B746-4FB0-8688-8598C22793A0}" = TurboTax 2013 WinPerFedFormset
"{0CD47142-BA4F-46B0-AA92-2675864928B8}" = Microsoft Security Client
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{0D557AE9-1484-4E22-978F-A372EE04F16F}" = TurboTax 2010 wmoiper
"{0E794924-17AC-4565-96C7-960D40F8B61E}" = TurboTax 2010 wcoiper
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{0F7319A9-083D-40B3-8256-00A6F3C2AAA2}" = Citrix online plug-in (SSON)
"{10DA2BD7-EFFC-420D-8689-CAEA577CAB7C}" = TurboTax 2011 wmiiper
"{113AC946-0CEB-49C7-828A-230FF9EB1DBB}" = TurboTax 2010 wmdiper
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{133236FE-E2F7-4313-8BF8-A10ACAAA7CB9}" = Citrix online plug-in (USB)
"{157EE23B-E16C-44A1-B678-E4F7D31E9138}" = TurboTax 2012 wlaiper
"{166EABB1-F073-40CD-866B-E457C35A41BC}" = TurboTax 2012 wwiiper
"{18272881-CFC0-434D-A975-E5BE44206AA0}" = Windows Live UX Platform Language Pack
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}" = iSEEK AnswerWorks English Runtime
"{18DD5ADB-4839-4057-8586-C9304AEFC580}" = TurboTax 2011 wksiper
"{1990DE06-9769-46E7-8B9E-1631165F2859}" = TurboTax 2011 wneiper
"{1B868720-ED88-4531-8892-3A35A76E48FE}" = TurboTax 2010 wfliper
"{1B947146-366B-42CD-86D5-219993CE3EE2}" = Windows Live MIME IFilter
"{1D0C8FEA-F9E6-4272-8465-58903F1946D0}" = TurboTax 2011 wnyiper
"{1E7941DC-32F1-467D-8351-8955A038A76E}" = RSA SecurID Software Token
"{1EA7C505-E6DA-4B85-9432-EBD3C70D510D}" = Windows Live Messenger
"{1EF082D0-2DEF-4D45-98C8-64365D58D240}" = TurboTax 2012 wohiper
"{1FE80E58-0774-4EC3-B6BA-68876B88D4B9}" = TurboTax 2011 wvaiper
"{21CBD20D-D287-49AF-8866-E5653E45AC5C}" = TurboTax 2010 wwviper
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A3E560-069F-4CFC-8F6C-1B526EC735FC}" = Windows Live Writer Resources
"{24ADC5BE-8B82-426F-8779-2308B54B00EE}" = ZoneAlarm Antivirus
"{250F2B64-1729-4A6F-A3A4-17B478C03431}" = TurboTax 2010 woriper
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 51
"{27FBE6D3-F96E-44AA-A07B-2A51EE626635}" = TurboTax 2010 wsciper
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{293B2D75-5735-4DFE-8642-F0EDEE9EB064}" = TurboTax 2010 wgaiper
"{2A4EEB5C-3BA6-4299-A87F-783861B567D9}" = TurboTax 2013 WinPerReleaseEngine
"{2A83AD05-56E6-3FBD-8752-B4143162EF59}" = Google Talk Plugin
"{2A8F9255-F4AB-4a37-8F39-7C6E15B5158B}" = 4500G510nz_web
"{2AF8BF32-F080-4B90-A795-9770610EE29C}" = TurboTax 2012 wdciper
"{2C045D2C-667D-4494-9684-E4B071C2C7FF}" = TurboTax 2010 wohiper
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FC7287D-39DD-4A84-9806-D27D3CCDC51B}" = Citrix online plug-in (Web)
"{2FC983F7-B7EA-484F-A3F6-51680A4B348A}" = TurboTax 2012 wriiper
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery
"{33D7E36F-ECFC-4DE9-8D19-648A3CA36CB7}" = TurboTax 2011 wmeiper
"{33E108CF-38B7-4EF6-827D-9AC055D22C06}" = System Requirements Lab
"{358C44FD-6943-4CDD-B947-7F7C4ADC8A8F}" = TurboTax 2013 WinPerTaxSupport
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{39417F21-6193-4349-AE25-8813A6273546}" = TurboTax 2012 wiliper
"{3A4D5E2D-988D-4ee9-8E7F-3AC200A2B8F5}" = 4500G510nz_Software_Min
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3CD1180C-B583-49E8-9726-6835F7095921}" = TurboTax 2012 wnmiper
"{3D361D8F-5521-421F-B3AB-495D2BFB29CA}" = TurboTax 2011 wriiper
"{400C31E4-796F-4E86-8FDC-C3C4FACC6847}" = Junk Mail filter update
"{40E472D2-907F-4ED4-9819-AAF8DACEBB33}" = TurboTax 2012 wgaiper
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{44432BD5-D968-460E-8DA4-1FFCC29DC692}" = TurboTax 2011 winiper
"{449CE12D-E2C7-4B97-B19E-55D163EA9435}" = Bing Bar
"{45F8CDEE-7F2D-4601-B300-EB83DEE8F156}" = TurboTax 2010 wnciper
"{4647B1E4-9907-4A58-963C-E785DF674C3E}" = TurboTax 2010 wpaiper
"{46805428-E44F-4529-8008-867DD190D506}" = TurboTax 2012 wvaiper
"{48990BE7-BA87-4DFA-B7F5-31396CD72E9A}" = TurboTax 2010 wiaiper
"{48ACC631-9C6C-4183-9D31-1EFAF377D78E}" = TurboTax 2012 wwviper
"{4903D172-DCCB-392F-93A3-34CA9D47FE3D}" = Microsoft .NET Framework 4.5.1
"{4926AA2D-3C66-443D-A456-53AE3FA44144}" = Windows Live Family Safety
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CA54C97-67B1-4507-9BE0-0ED39C24FA32}" = TurboTax 2012 wpaiper
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{4D0AF541-AEB5-42C0-ADB5-09F7D6F7640F}" = TurboTax 2010 whiiper
"{4E00EC3D-F349-4FA2-829C-CD55E67F7D92}" = TurboTax 2011 wariper
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{510DE38F-8FEC-4AFE-8C8C-8095C55C1DDC}" = TurboTax 2011 waliper
"{5389A026-79C3-4D20-8E9F-94F8BD4F87EE}" = TurboTax 2010 wdeiper
"{551F657B-9D5A-4499-845E-9924AB5232D2}" = TurboTax 2010 wmtiper
"{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1" = iolo technologies' System Mechanic
"{569E6C05-AFFA-4C58-BFB6-B289203572CD}" = VIPdesk Scan Utility
"{57287FDF-27E6-45BC-9DD2-A33545C46C1A}" = Citrix online plug-in (HDX)
"{596ECF31-381D-406D-9C22-6B805C3D7A8F}" = TurboTax 2011 wgaiper
"{5BABDA39-61CF-41EE-992D-4054B6649A9B}" = Movie Maker
"{5E8AC853-65BB-4C99-A09E-19B81851E14C}" = Citrix Receiver Updater
"{5F29D5E7-8C01-4695-8A38-9F94BC3EAD40}" = TurboTax 2011 wmniper
"{5F52D23D-91E5-4DDA-888A-82B98BCA0754}" = TurboTax 2012 wiaiper
"{5FE545A1-D215-4216-9189-E7B39C9D1CC1}" = Quicken 2011
"{606EB5EB-AADF-4E21-B715-1CAD291181D6}" = TurboTax 2013 wrapper
"{6142632E-6119-4117-AF54-A5366ACEC899}" = TurboTax 2011 wutiper
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62205FCA-B858-4503-87B4-884CEBCDC062}" = TurboTax 2012 wneiper
"{6346B2AE-0DBB-45A3-9ECA-D23CAC27AB7E}" = TurboTax 2011 wiliper
"{63661EBF-B4DC-4993-AF40-9F81178A3404}" = TurboTax 2011 wndiper
"{63AA581B-DD3A-4C3B-8FA4-CE05534C7AB2}" = TurboTax 2012 wfliper
"{65AF6E26-80A7-45F2-A7DA-9FBF407398BE}" = TurboTax 2010 wriiper
"{65C0F43C-5F3B-4AB5-BFC9-ABA1C8F4AA7D}" = TurboTax 2011 wohiper
"{65C92136-6AF0-4E70-88D2-D19E739CE285}" = DriverUpdate
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{66DAE93A-9A8A-4B94-9FBF-5B78EF34C2EC}" = TurboTax 2011 wmsiper
"{67A7AA84-1525-4AFF-9200-E763C4C4E1BA}" = TurboTax 2012 wariper
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6A02A7A6-0EC5-4CD7-84EB-520546B5CA8D}" = TurboTax 2012 wutiper
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{6BB075CD-FC09-4360-978E-DA09DC76CA59}" = TurboTax 2012 wmtiper
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6C12B6BF-3891-497B-B5CA-3D64DA093947}" = Motorola Mobile Drivers Installation 5.4.0
"{6C528316-05A0-4594-A949-94B792EC396C}" = TurboTax 2011 wpaiper
"{6DEEA6A7-AC84-4C08-9944-E06E08DF98B4}" = TurboTax 2010 wctiper
"{6F2FDD50-E0F3-4117-B575-78E77F8D11EF}" = Citrix online plug-in (DV)
"{70632C41-BDAC-4128-9FBF-287F9FF53DE5}" = TurboTax 2010 wiliper
"{70854FE6-3BF1-4C69-94D0-BEB821102E34}" = Windows Live Mail
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7269695A-88FE-47CB-9AE5-D787460DEEBB}" = TurboTax 2012 wksiper
"{7406AF9C-8D39-4E74-93C2-87FCB5527928}" = TurboTax 2012 wdeiper
"{75247E38-5C9B-45D6-ADF8-E11CB56B4990}" = Network
"{755F8988-A63D-4FDF-AAF2-D77BDEF55113}" = TurboTax 2011 wmtiper
"{7748A531-DACF-4B0A-B927-804EBC2CB5FE}" = TurboTax 2011 wmoiper
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7860BB9E-C4AC-4648-9C3A-C38FD7B4657D}" = TurboTax 2011 wwviper
"{7A475EF0-35F9-46AA-AD6F-FD3D8E568D9D}" = TurboTax 2011 wwiiper
"{7B0C5EF6-DE4C-4E20-8889-C17604FFE5CD}" = Windows Live Family Safety
"{7B5A3A53-1F50-4831-9922-4C30C80417AB}" = TurboTax 2012 wokiper
"{7BCCA95E-ADAA-44BA-AC39-D732240132B0}" = TurboTax 2012 wmiiper
"{7CE9654D-78E7-4C95-9F8D-0E8C38D4FB10}" = TurboTax 2012 wcoiper
"{822B325F-9CDD-4E78-87A2-35E6F0DDEEA2}" = HP Deskjet 1000 J110 series Product Improvement Study
"{8256F87F-8554-4457-8C3D-3F3324697D9F}" = Windows Live ID Sign-in Assistant
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83B48E1F-F38A-4169-A83A-71C7814512F9}" = TurboTax 2010 wnmiper
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{843BD817-4551-451C-AB7A-EF113BF9C036}" = 4500_G510nz_Help_Web
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{84BC4E89-97BB-41A3-9254-06E7C675B945}" = TurboTax 2010 wmsiper
"{852FD55C-9C56-4830-9F9F-7BFC3CE13B65}" = TurboTax 2010 wariper
"{854F7259-6FF4-445C-B322-1DBA16B567D2}" = TurboTax 2010 wmeiper
"{86C40513-B5A4-476E-9EAB-EC118DCF4502}" = Windows Live Writer
"{8720C829-3BD5-4CC5-AD1F-AD54FB928DCB}" = TurboTax 2011 wcoiper
"{87A51331-4FB9-4A50-B08D-D3D8420F068A}" = TurboTax 2012 wtniper
"{87FF0E39-8490-4EB4-A557-FF12F712EF7E}" = TurboTax 2010 wcaiper
"{89EC099E-958D-462E-972C-385591946978}" = TurboTax 2012 WinPerFedFormset
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A5CC6AC-5807-4348-B963-87CE46DACA3F}" = TurboTax 2011 waziper
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8EA5860B-9027-4864-81D0-2A5B82D41821}" = TurboTax 2010 wmniper
"{8EB39AA7-4019-4550-AF6C-BE51BB27B446}" = TC Web Conferencing
"{8F0C2E48-B51C-45FD-87CC-AA985D216D9C}" = TurboTax 2011 wdciper
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{9021848E-F315-44C7-8D45-3B16162AA73A}" = TurboTax 2010 wneiper
"{913778D3-E1D8-4B55-9246-3308C54D3162}" = Citrix online plug-in (PNA)
"{9255148F-EF3D-4241-8CCC-5A46D79F9511}" = TurboTax 2011 wvtiper
"{92C95E2D-4971-49FF-A73E-FBF61FA40BE5}" = TurboTax 2011 wiaiper
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96165A0E-F058-4303-B701-A91C219E3967}" = TurboTax 2010 wtniper
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{97C79BEC-43F7-4BD8-A6A7-85C0257E488A}" = Windows Live Writer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A40C41B-D7CF-41A8-BD66-5D701D317C23}" = TurboTax 2011 wfliper
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CC57E3F-0478-4005-98D3-4C6850C5A6E7}" = TurboTax 2011 wkyiper
"{9D459B94-7E90-46A5-B76B-5A712E7A3529}" = TurboTax 2010 waliper
"{A0087DDE-69D0-11E2-AD57-43CA6188709B}" = Adobe AIR
"{A2B26CD0-4185-4906-8ABA-5D1CFD542194}" = TurboTax 2012 woriper
"{A33D199B-D385-46E3-B438-62FDC1901DC4}" = TurboTax 2012 wvtiper
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A6D659BE-795D-4726-AEE8-91EB25CF26F7}" = TurboTax 2012 wnjiper
"{A7D9103B-5F49-4A43-9887-9EFC1CE79A38}" = TurboTax 2010 wokiper
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A8B1F076-965D-4663-A9D4-C2FB58A42AE4}" = TurboTax 2012 WinPerTaxSupport
"{A925E9E4-3DBC-4B87-A138-4CCB8A0FB5D0}" = TurboTax 2012 wkyiper
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9AFDD7C-F4A0-4E23-B73D-2BB23EE359D0}" = TurboTax 2010 wnhiper
"{AA935592-5463-434F-B044-DE18705F9912}" = TurboTax 2011 wnhiper
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{ABBE458D-C10D-4B36-8C95-92DE9D196B1B}" = TurboTax 2012 wmdiper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.06)
"{AE29CC62-C835-40FD-99C6-292F90D58DF8}" = TurboTax 2010 widiper
"{AEE512CE-2D5B-4E87-B729-2FBD7718EED7}" = TurboTax 2010 wksiper
"{B14E295B-939D-4CE0-99CD-CB8C3B4FFF2E}" = TurboTax 2012 wmniper
"{B1C2F918-9852-4BCB-BCC1-F837D8C70182}" = TurboTax 2012 waziper
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B3EFD663-41BD-40C3-ABCE-7DD80DAFAACD}" = TurboTax 2010 wndiper
"{B515962D-C979-44AC-9912-F7BB499B4B2C}" = VirtualDJ Home FREE
"{B80D3EA9-A252-4AE5-AC51-81729F5C586F}" = Windows Live Mail
"{BB830F9E-53B3-492F-B39C-2DF615D1C9E1}" = TurboTax 2010 wvaiper
"{BFCA7375-81A2-44F8-BFC1-0DC5A3D23405}" = TurboTax 2010 wutiper
"{C034A6F9-6569-491B-B3BF-F5D15221A708}" = Windows Live Essentials
"{C07C18F6-80A3-492F-B651-676A3496073E}" = TurboTax 2012 wctiper
"{C14201FD-245D-4CA9-A582-47D842C6AC59}" = TurboTax 2010 wmiiper
"{C383CBAD-61FA-417E-B784-2E9F1E843DF2}" = TurboTax 2010 wmaiper
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C47B36EC-0639-4462-A9CE-7809CF2F6100}" = ZoneAlarm Security
"{C6D442EC-14C6-4E5B-8378-305BAE7EDBBF}" = TurboTax 2011 wmdiper
"{C7010632-E5EE-4263-B80E-BC9D45439EB0}" = TurboTax 2010 winiper
"{C82F54A0-FB7A-4A5D-BCA2-9992EB7ED122}" = TurboTax 2011 widiper
"{C89269D9-DD02-45DD-99DD-6AE592F6C447}" = TurboTax 2011 wcaiper
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C8B63671-0A2E-4C9C-8A86-B64C4CBF4561}" = TurboTax 2011 whiiper
"{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}" = RealDownloader
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{CA19AEA3-B949-41DA-AFBA-692356230F6E}" = TurboTax 2010 wnjiper
"{CA32CD83-2627-40DB-B16B-43D4752A4A4C}" = TurboTax 2012 wmaiper
"{CAF5B770-082F-40C4-853D-3973BB81BDAA}" = TurboTax 2011 WinPerTaxSupport
"{CBD6CD44-B27D-4649-B649-2A1E73177DF5}" = TurboTax 2010 wdciper
"{D0EE2F91-CC20-426F-A4D5-7FFE54E55015}" = TurboTax 2010 wkyiper
"{D2C146B1-948D-47EF-8387-5D1C6B980F7C}" = Windows Live Writer
"{D46F9B7B-24C6-410F-A995-A2D4E541B610}" = TurboTax 2012 wnciper
"{D4FB136D-2802-4578-A023-E7243BD0D7D5}" = ZoneAlarm Firewall
"{D888F114-7537-4D48-AF03-5DA9C82D7540}" = Photo Common
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DCED0AD4-784D-4667-B4A0-6FE953FAC4BB}" = TurboTax 2011 wnjiper
"{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}" = HP Deskjet 1000 J110 series Help
"{DDEEA588-FE34-495F-B974-66EACAB93678}" = TurboTax 2012 winiper
"{DEAB8BC6-96A9-48D2-B1C8-64F72265D4A4}" = TurboTax 2012 wmeiper
"{E0939D9A-D336-46C8-8EE6-FA2988AB0053}" = TurboTax 2011 wsciper
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1B617EF-2DBF-45A0-9359-774031FEA769}" = TurboTax 2010 wwiiper
"{E2C15C1A-0E65-4821-BB42-C8C24B621EBA}" = TurboTax 2011 wnciper
"{E463E171-4082-4744-A466-F7CBE8502789}" = TurboTax 2011 WinPerReleaseEngine
"{E83F5F27-43F3-4163-ABE5-F68C989286ED}" = TurboTax 2012 wrapper
"{E90F8E55-A3EE-41AF-88E3-ED2EA0ECE46C}" = TurboTax 2010 waziper
"{E9DE0A38-3378-4A72-94A2-2DC680E95757}" = TurboTax 2012 wnhiper
"{EA973416-0C1D-401C-BC81-325F209D247F}" = TurboTax 2011 woriper
"{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker
"{EE556A3E-EB37-4392-9637-BAA8EC2F47FA}" = TurboTax 2011 wrapper
"{EFD2807A-C66B-4C13-8FB8-42FCA6DEF171}" = TurboTax 2012 wcaiper
"{F014B696-28C5-4554-802F-A15380418F53}" = TurboTax 2012 WinPerReleaseEngine
"{F03DCC1D-C2C3-412A-BB0C-6DD098DCF275}" = TurboTax 2011 wnmiper
"{F050C3B4-007B-4963-8DC4-C5949801424B}" = TurboTax 2011 wokiper
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F20211A6-DCCE-4A4A-87E6-638717417B48}" = TurboTax 2010 wlaiper
"{F2235E5E-7881-4293-9B6F-04B2609FBFF0}" = Windows Live Messenger
"{F27CFD16-939A-4232-98CD-180898D14713}" = HP Officejet 4500 G510n-z
"{F4B1B985-F308-4DBA-BFD7-CCCB8839234B}" = HP Deskjet 1000 J110 series Basic Device Software
"{F6E63EBE-DFAC-4925-A343-531DCB4630AF}" = TurboTax 2012 wsciper
"{F73C47CA-879E-4906-9298-D93D6FCEC4D0}" = TurboTax 2012 wnyiper
"{F7856182-449B-43AB-BD00-0D0F7FFC7070}" = TurboTax 2011 wdeiper
"{FA57CBC1-487B-4B77-B2CB-F2BDD21AE82D}" = TurboTax 2012 waliper
"{FAD08D20-3781-4E86-B228-02A883505D48}" = TurboTax 2012 wmsiper
"{FAD3D68B-2F9C-459B-AA79-C04B9090FD72}" = TurboTax 2011 WinPerFedFormset
"{FBA641F3-7A87-4179-8E4E-F77D25BC1067}" = TurboTax 2012 wmoiper
"{FC65A49B-D0F4-4CFE-9304-4C6B4412433F}" = TurboTax 2011 wlaiper
"{FC6C7107-7D72-41A1-A031-3CE751159BAB}" = Photo Gallery
"{FDB97C1E-ADF2-43BA-B513-6BE144D977D7}" = TurboTax 2011 wctiper
"{FE60B87C-63A2-4A45-AC06-FFEFD5DB7846}_is1" = Online Vault
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFC62F9E-327E-415B-947C-CF20FF8F2AF4}" = TurboTax 2012 whiiper
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin
"Backup Assistant Plus" = Backup Assistant Plus
"Belarc Advisor" = Belarc Advisor 8.3
"Belkin Setup and Router Monitor_is1" = Belkin Setup and Router Monitor
"BlackBerry_{86B32074-0F48-4CF9-BA4B-529B470FB47F}" = BlackBerry Desktop Software 5.0
"BoltPDF" = Bolt PDF Printer
"Express" = Express Dictate
"ExpressInvoice" = Express Invoice
"FastFox" = FastFox
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"FileFort" = FileFort Backup
"FileHippo.com" = FileHippo.com Update Checker
"Garden Encyclopedia" = Sierra Garden Encyclopedia
"Google Chrome" = Google Chrome
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Photo Creations" = HP Photo Creations
"Lunascape6" = Lunascape6 (All Users)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft Security Client" = Microsoft Security Essentials
"MotoHelper" = MotoHelper 2.1.32 Driver 5.4.0
"Mozilla Firefox 26.0 (x86 en-US)" = Mozilla Firefox 26.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NetSight" = NCP Connect
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Opera 12.16.1860" = Opera 12.16
"RadialpointClientGateway_is1" = Windstream Service Agent 4.1.15
"RadialpointHomeSecurityDashboard_is1" = Windstream Diagnostic Tools 3.0.21
"RadialpointSecurityAdvisorService_is1" = Radialpoint Security Advisor 2.5.15
"RadialpointServicepointDashboardExtensions_is1" = Radialpoint Servicepoint Dashboard Extensions version 13.7.12.30922
"RealPlayer 16.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.93
"Scribe" = Express Scribe
"SeaMonkey 2.13.1 (x86 en-US)" = SeaMonkey 2.13.1 (x86 en-US)
"SelectRebatesUninstall" = ShopAtHome.com Toolbar
"Sierra Home Architect" = Sierra Home Architect
"TurboTax 2009" = TurboTax 2009
"TurboTax 2010" = TurboTax 2010
"TurboTax 2011" = TurboTax 2011
"TurboTax 2012" = TurboTax 2012
"TurboTax 2013" = TurboTax 2013
"TVWiz" = Intel® TV Wizard
"VLC media player" = VLC media player 2.1.2
"WinLiveSuite" = Windows Live Essentials
"WinZip" = WinZip
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"ZoneAlarm Do Not Track Add-on_is1" = ZoneAlarm Do Not Track Add-on 2.2.5.1213
"ZoneAlarm Free Firewall" = ZoneAlarm Free Firewall
"ZoneAlarm LTD Toolbar" = ZoneAlarm LTD Toolbar
"ZoneAlarm Security Toolbar" = ZoneAlarm Security Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Connect 9 Add-in" = Adobe Connect 9 Add-in
"Adobe Connect Add-in" = Adobe Connect Add-in
"Juniper_Setup_Client" = Juniper Networks, Inc. Setup Client
"Neoteris_Host_Checker" = Juniper Networks Host Checker
"SkyDriveSetup.exe" = Microsoft SkyDrive
"UnityWebPlayer" = Unity Web Player
"UserTestingPlugin" = UserTesting.com Recorder Plugin

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/4/2013 1:24:58 AM | Computer Name = Shawn-Laptop | Source = MsiInstaller | ID = 11706
Description =

Error - 9/4/2013 1:45:14 AM | Computer Name = Shawn-Laptop | Source = MsiInstaller | ID = 11706
Description =

Error - 9/4/2013 4:57:33 AM | Computer Name = Shawn-Laptop | Source = MsiInstaller | ID = 11706
Description =

Error - 9/4/2013 7:29:09 AM | Computer Name = Shawn-Laptop | Source = MsiInstaller | ID = 11706
Description =

Error - 9/4/2013 7:49:25 AM | Computer Name = Shawn-Laptop | Source = MsiInstaller | ID = 11706
Description =

Error - 9/4/2013 9:04:30 AM | Computer Name = Shawn-Laptop | Source = Application Error | ID = 1000
Description = Faulting application name: V CAST Backup Scheduler.exe, version: 0.0.0.0,
time stamp: 0x5031f2cb Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x680d8966 Faulting process id:
0x1638 Faulting application start time: 0x01cea7e17538abde Faulting application path:
C:\Program Files\Backup Assistant Plus\V CAST Backup Scheduler.exe Faulting module
path: unknown Report Id: 88d2817d-1562-11e3-9515-001c232150bb

Error - 9/4/2013 9:05:22 AM | Computer Name = Shawn-Laptop | Source = Application Error | ID = 1000
Description = Faulting application name: V CAST Backup Scheduler.exe, version: 0.0.0.0,
time stamp: 0x5031f2cb Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x680d8966 Faulting process id:
0x1638 Faulting application start time: 0x01cea7e17538abde Faulting application path:
C:\Program Files\Backup Assistant Plus\V CAST Backup Scheduler.exe Faulting module
path: unknown Report Id: a783b4aa-1562-11e3-9515-001c232150bb

Error - 9/4/2013 9:50:42 AM | Computer Name = Shawn-Laptop | Source = MsiInstaller | ID = 11706
Description =

Error - 9/4/2013 1:33:03 PM | Computer Name = Shawn-Laptop | Source = MsiInstaller | ID = 11706
Description =

Error - 9/4/2013 1:53:20 PM | Computer Name = Shawn-Laptop | Source = MsiInstaller | ID = 11706
Description =

[ Media Center Events ]
Error - 3/9/2013 10:43:50 AM | Computer Name = Shawn-Laptop | Source = MCUpdate | ID = 0
Description = 9:43:50 AM - Error connecting to the internet. 9:43:50 AM - Unable
to contact server..

Error - 3/9/2013 10:44:02 AM | Computer Name = Shawn-Laptop | Source = MCUpdate | ID = 0
Description = 9:43:56 AM - Error connecting to the internet. 9:43:56 AM - Unable
to contact server..

Error - 3/9/2013 10:32:40 PM | Computer Name = Shawn-Laptop | Source = MCUpdate | ID = 0
Description = 9:32:36 PM - Error connecting to the internet. 9:32:37 PM - Unable
to contact server..

Error - 3/9/2013 10:32:56 PM | Computer Name = Shawn-Laptop | Source = MCUpdate | ID = 0
Description = 9:32:48 PM - Error connecting to the internet. 9:32:48 PM - Unable
to contact server..

Error - 3/10/2013 10:36:25 AM | Computer Name = Shawn-Laptop | Source = MCUpdate | ID = 0
Description = 10:36:25 AM - Error connecting to the internet. 10:36:25 AM - Unable
to contact server..

Error - 3/10/2013 10:36:38 AM | Computer Name = Shawn-Laptop | Source = MCUpdate | ID = 0
Description = 10:36:31 AM - Error connecting to the internet. 10:36:31 AM - Unable
to contact server..

Error - 3/17/2013 10:05:07 PM | Computer Name = Shawn-Laptop | Source = MCUpdate | ID = 0
Description = 10:04:23 PM - Error connecting to the internet. 10:04:23 PM - Unable
to contact server..

Error - 3/17/2013 11:05:37 PM | Computer Name = Shawn-Laptop | Source = MCUpdate | ID = 0
Description = 11:05:36 PM - Error connecting to the internet. 11:05:36 PM - Unable
to contact server..

Error - 3/18/2013 12:06:07 AM | Computer Name = Shawn-Laptop | Source = MCUpdate | ID = 0
Description = 12:06:06 AM - Error connecting to the internet. 12:06:06 AM - Unable
to contact server..

Error - 3/18/2013 1:06:44 AM | Computer Name = Shawn-Laptop | Source = MCUpdate | ID = 0
Description = 1:06:38 AM - Error connecting to the internet. 1:06:38 AM - Unable
to contact server..

[ System Events ]
Error - 1/26/2014 7:03:36 AM | Computer Name = Shawn-Laptop | Source = ipnathlp | ID = 31004
Description =

Error - 1/26/2014 10:34:46 AM | Computer Name = Shawn-Laptop | Source = ipnathlp | ID = 31004
Description =

Error - 1/26/2014 11:11:46 AM | Computer Name = Shawn-Laptop | Source = Microsoft-Windows-Kernel-General | ID = 5
Description =

Error - 1/26/2014 11:12:31 AM | Computer Name = Shawn-Laptop | Source = Service Control Manager | ID = 7000
Description = The Reimage Real Time Protection service failed to start due to the
following error: %%2

Error - 1/26/2014 11:12:46 AM | Computer Name = Shawn-Laptop | Source = ipnathlp | ID = 30013
Description =

Error - 1/26/2014 11:14:54 AM | Computer Name = Shawn-Laptop | Source = ipnathlp | ID = 34001
Description =

Error - 1/26/2014 11:18:10 AM | Computer Name = Shawn-Laptop | Source = DCOM | ID = 10000
Description =

Error - 1/26/2014 11:20:45 AM | Computer Name = Shawn-Laptop | Source = Microsoft-Windows-Kernel-General | ID = 5
Description =

Error - 1/26/2014 11:28:32 AM | Computer Name = Shawn-Laptop | Source = ipnathlp | ID = 31004
Description =

Error - 1/26/2014 11:41:36 AM | Computer Name = Shawn-Laptop | Source = ipnathlp | ID = 31004
Description =


< End of report >


help me fix this... i need for work, i log into a vpn for work and once on the site a host checker installs to make sure i have the correct programs on system.... cant get past the host checker due to system problems.
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP