Solved how to uninstall notepad.exe?

June 20, 2014 at 14:51:15
Specs: Windows XP
how to uninstall windows xp sp3 notepad.exe? need to kill this program. just searching and deleting the file doesn't remove it. ait immediately shows back up in windows and windows\system32 directories. where is the real source of notepad.exe?

message edited by bob9139


See More: how to uninstall notepad.exe?

Report •


✔ Best Answer
June 20, 2014 at 19:18:53
Let me have look to see if i can any relevant info from these logs.

Download OTL, save & run from your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
http://oldtimer.geekstogo.com/OTL.exe
Double click the OTL icon to start the tool. (Note: If you are running on Vista or Windows 7 accept UAC alert)
1: When the window appears, underneath Output at the top, make sure Standard output is selected.
2: Select Scan all users
3: Change Drivers to All
4: Under the Extra Registry section, check Use SafeList
5: In the lower right corner, checkmark "LOP Check" and checkmark "Purity Check".
6: Click Run Scan and let the program run uninterrupted.
Screenshots ( SS ) of 1 - 6
http://i.imgur.com/rvTDUlL.gif
When the scan is complete, two text files will be created on your Desktop
OTL.Txt <- this one will be opened
Extras.txt <- this one will be minimized

Upload the logs using this. I upload to Imgur.com for images & load.to for files ( neither need an account ) Give us the links please.

Image Uploader
http://www.softpedia.com/get/Intern...
http://www.softpedia.com/progScreen...
http://zenden.ws/imageuploader_ru
How to use for files.
http://i.imgur.com/FhtnM6c.gif
http://i.imgur.com/yBtjlpb.gif
http://i.imgur.com/txFkgpT.gif

Free file sharing sites come & go, if Imgur.com & load.to are too busy ( or not working ) here are others to try.
free file upload no account needed
http://is.gd/ije9W6
http://www.zippyshare.com/
http://www.speedyshare.com/
http://www.filedropper.com/index.php
http://www.wikisend.com/
https://www.sendspace.com/
http://www.megafileupload.com/



#1
June 20, 2014 at 15:07:53
Notepad does live in the system32 folder. Whereas the majority of other applications are typically installed in the "Program Files" folder.

There is good reason for this, Windows does not want you to remove notepad.exe. In fact anything in the system32 folder (with the exception of malware) is best left alone.

There might be a good explanation why you wish to remove notepad but you haven't really given it. You say you need to kill notepad? Does it run in task manager when you haven't initiated it to run? Or you would just like it gone, killed off? Notepad doesn't hog system resources, nor does it run all by itself. If you are having trouble with notepad you might need a helper here to assist you with malware removal.

I would highly advise against removing notepad. If you are having trouble with it try using a scanner such as Malwarebytes Antimalware. It may be that it is infected or malware calls upon it to do its dirty deeds.


message edited by btk1w1


Report •

#2
June 20, 2014 at 16:02:16
"The file notepad.exe is infected. Do you want to active your antivirus software now?"
If you are getting a message similar to the above, run Rkill first & then Malwarebytes.

Please download Rkill from any one of these links and save it to your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop. Copy & Paste the contents of the log in your reply.
http://www.bleepingcomputer.com/dow...
Double click on Rkill to run it. If the first one doesn't work try the next one.
This will help remove certain processes and should restore any file associations and your desktop. Note: Your system is still infected as Rkill does not delete files - it merely helps to temporarily disable the infections, allowing us to start the cleansing process.
Do NOT reboot your machine. Each time you reboot, Rkill is disabled and you would have to run it again in order for it to be effective.

Run Malwarebytes' Anti-Malware ( MBAM ) Free Version. Use Quick scan. Copy and Paste the contents of the log, in your reply please.

http://i.imgur.com/U9IqcVj.gif
http://i.imgur.com/zHMG6J9.gif
Or,
http://i.imgur.com/eLcvyZD.gif
Malwarebytes' Anti-Malware
http://www.softpedia.com/get/Antivi...
http://www.softpedia.com/progScreen...
http://www.malwarebytes.org/free/
Make sure you uncheck > Enable free trial < at the END of the install.
http://i.imgur.com/tUFCbYz.gif
If your MBAM log indicates "No action taken". That's usually a result of NOT clicking the Apply Actions button after the scan. In most cases, a restart will be required.
Quick Scan versus Full Scan
http://forums.malwarebytes.org/inde...


Report •

#3
June 20, 2014 at 18:53:24
OK. I wanted to keep notepad from starting because I had a message every time I restarted the computer that something called install_msi came up asking what program windows should use to open it. I finally told it to open with notepad so as to see what it looked like. from then on it tried repeatedly to open in notepad and kept a window open with garbage in the window. I just wanted to get back where i started . I renamed all the notepad .exe locations as mynotepad.exe to keep the program available when i corrected the original problem. I routinely run ccleaner and malwarebytes, but they don't recognize the install_msi thing as a problem.
Thanks for your answers but they didn't help me kill notepad for a while.

Report •

Related Solutions

#4
June 20, 2014 at 19:18:53
✔ Best Answer
Let me have look to see if i can any relevant info from these logs.

Download OTL, save & run from your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
http://oldtimer.geekstogo.com/OTL.exe
Double click the OTL icon to start the tool. (Note: If you are running on Vista or Windows 7 accept UAC alert)
1: When the window appears, underneath Output at the top, make sure Standard output is selected.
2: Select Scan all users
3: Change Drivers to All
4: Under the Extra Registry section, check Use SafeList
5: In the lower right corner, checkmark "LOP Check" and checkmark "Purity Check".
6: Click Run Scan and let the program run uninterrupted.
Screenshots ( SS ) of 1 - 6
http://i.imgur.com/rvTDUlL.gif
When the scan is complete, two text files will be created on your Desktop
OTL.Txt <- this one will be opened
Extras.txt <- this one will be minimized

Upload the logs using this. I upload to Imgur.com for images & load.to for files ( neither need an account ) Give us the links please.

Image Uploader
http://www.softpedia.com/get/Intern...
http://www.softpedia.com/progScreen...
http://zenden.ws/imageuploader_ru
How to use for files.
http://i.imgur.com/FhtnM6c.gif
http://i.imgur.com/yBtjlpb.gif
http://i.imgur.com/txFkgpT.gif

Free file sharing sites come & go, if Imgur.com & load.to are too busy ( or not working ) here are others to try.
free file upload no account needed
http://is.gd/ije9W6
http://www.zippyshare.com/
http://www.speedyshare.com/
http://www.filedropper.com/index.php
http://www.wikisend.com/
https://www.sendspace.com/
http://www.megafileupload.com/


Report •

#5
June 20, 2014 at 19:50:31
change the file name to installer_msi_win. where did this come from? That's my real problem.
Thanks

Report •

#6
June 20, 2014 at 19:53:31
An msi file is a windows file extension to install software.

Going from the file name it is impossible to say exactly what software is being installed, unless you downloaded the software.

Because you have pointed the msi file to notepad to open this is what it will do by default.

The easiest way I can think of off hand to revert your settings back to the way they were is to run "system restore" back to a date prior to telling the msi file to open in notepad.

Have you installed service pack 2 on your XP system? I'm not 100% sure, but I think prior to service pack 2 XP won't run msi files as an executable.

Follow Johnw's instructions so he can analyse your system for anything that appears to be amiss.


Report •

#7
June 20, 2014 at 20:00:36
"where did this come from?"
Without the logs, no idea, malware usually.

Try these possible fixes, I will still need logs to try & find the source of the problem.

http://www.tweaking.com/content/pag...
http://support.microsoft.com/kb/971187


Report •

#8
June 20, 2014 at 20:09:05
I have xp-pro sp3 did all the last updates from ms,etc. I don't know when that msi thing tarted. i could not open the oldtimer site. I'll keep trying. thanks.cc

Report •

#9
June 20, 2014 at 20:24:07
Looks like a problem with that site, try this link.

http://www.majorgeeks.com/mg/get/ot...


Report •

#10
June 20, 2014 at 21:04:59
got it! i'll try it tomorrow. thanks

Report •

#11
June 20, 2014 at 22:39:34
Also if it prompts you without initiation whenever you start your computer have a look in the startup folder.

C:\Documents and Settings\(user)\Start Menu\Programs\Startup

Delete it from there to prevent the prompts during startup.

Also look in msconfig to see if it starts there and remove it.

If you haven't told this executable to run then chances are there might be an infection as Johnw suggests.


Report •

#12
June 20, 2014 at 22:45:16
"got it! i'll try it tomorrow. thanks"
Ok, may get it before I go to bed tonight, if not, when I wake up.

I'm here.
http://www.timeanddate.com/worldclo...

message edited by Johnw


Report •

#13
June 20, 2014 at 23:27:26
Me Brisbane. Same landmass but a world apart. Lol.

message edited by btk1w1


Report •

#14
June 21, 2014 at 00:34:14
"Me Brisbane"
If you follow AFL, I'll be watching the Dockers V Brisbane game soon.

Report •

#15
June 21, 2014 at 00:51:14
Lol. Being a Kiwi expat. As much as I admire the ball skills and the distance players cover I'm still learning to love the game.

Go the Lions nonetheless!!!!

;-)


Report •

#16
June 21, 2014 at 06:24:50
"Go the Lions nonetheless!!!!"
Young team, they will get their turn.

Report •

#17
June 21, 2014 at 12:53:37
Associating msi with NotePad was incorrect as was trying to remove NotePad - two wrongs do not make a right. I'm wondering if the best way forward might have been to do System Restore, so that you were back where you started, then do malware checks as per Johnw.

Whatever, I'm just thinking aloud (maybe with 20-20 hindsight LOL).

Always pop back and let us know the outcome - thanks


Report •

#18
June 21, 2014 at 14:38:57
John. The Lions got shown how to play the game I think! Lol

I agree Derek. Fix up the file associations first with system restore then let Johnw work his magic.


Report •

#19
June 21, 2014 at 15:25:18
here is the OTL log:

OTL Extras logfile created on: 6/7/2014 6:46:13 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\bob\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.49 Gb Total Physical Memory | 2.64 Gb Available Physical Memory | 75.69% Memory free
5.33 Gb Paging File | 4.67 Gb Available in Paging File | 87.72% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 41.93 Gb Free Space | 28.13% Space Free | Partition Type: NTFS

Computer Name: EMA14 | User Name: bob | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.cmd [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.com [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.cpl [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.hlp [@ = HLP_auto_file] -- C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Microsoft Corporation)
.hta [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.inf [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.ini [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.url [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.js [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.jse [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.pif [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.scr [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.txt [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.vbe [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.vbs [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.wsf [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.wsh [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[color=#E56717]========== Security Center Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[color=#E56717]========== System Restore Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"54925:UDP" = 54925:UDP:*:Enabled:BrotherNetwork Scanner

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\IPCamera.exe" = C:\WINDOWS\system32\IPCamera.exe:*:Enabled:IPCamera -- ()
"C:\Documents and Settings\bob\Application Data\mjusbsp\magicJack.exe" = C:\Documents and Settings\bob\Application Data\mjusbsp\magicJack.exe:*:Enabled:magicJack -- (magicJack L.P.)
"C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe" = C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe:*:Enabled:nimdnsResponder -- (National Instruments Corporation)
"C:\Documents and Settings\bob\Local Settings\Application Data\Akamai\netsession_win.exe" = C:\Documents and Settings\bob\Local Settings\Application Data\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Client -- (Akamai Technologies, Inc.)
"C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe" = C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe:*:Enabled:NI Application Web Server -- (National Instruments Corporation)
"C:\Program Files\National Instruments\Shared\NI WebServer\SystemWebServer.exe" = C:\Program Files\National Instruments\Shared\NI WebServer\SystemWebServer.exe:*:Enabled:NI System WebServer -- (National Instruments Corporation)
"C:\Program Files\National Instruments\Shared\nisvcloc\nisvcloc.exe" = C:\Program Files\National Instruments\Shared\nisvcloc\nisvcloc.exe:*:Enabled:NI Service Locator -- (National Instruments Corporation)


[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01AC4D6A-05F0-4158-95E7-FC299961B50A}" = NI Math Kernel Libraries
"{063DF3AF-6F03-4C36-BC44-7B1BBCE4AFE6}" = NI LabWindows/CVI Shared Components
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{06897ACD-84E1-4F9E-8848-3E3BF27D2D99}" = NI LabVIEW 2012 SP1 Run-Time Engine Non-English Support.
"{077AFCFF-E88B-4A52-98AE-38BB38590A53}" = NI LabVIEW Run-Time Engine 2012 SP1 f4
"{08505CC2-EA7F-4818-9C45-B74EDA7227F8}" = NI Visual C++ 2008 Redistributable Package
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0AF8A008-7141-40DD-BB99-10B7F0C4769A}" = NI GMP Windows 32-bit Installer 13.0.0
"{0CE5F45E-F6CC-4638-B0DD-BB7F6EF56713}" = HP Deskjet D1500 Printer Driver Software 10.0 Rel .3
"{0DEB89CF-6DBC-42E4-8603-B657E7898D27}" = NI LabWindows/CVI 2013 Patch 1 SxS TDMS Library
"{0DEEF8A0-A14B-4058-96E2-59B00C581A42}" = NI LabWindows/CVI 2013 Low-Level Driver (Updated)
"{0E5A6C9B-E5F6-4BBD-8942-FC9BFC287F68}" = NI System API Web-Service 32-bit 5.5.0
"{0E6CDC70-8C32-4A9F-B66D-902DDC609748}" = NI LabWindows/CVI 2013 Documentation
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{1179FFB4-726B-4200-BF02-0387C86C429B}" = NI OPCEnum Shared
"{1478F207-677B-443B-B305-E924A6289F1B}" = NI LabVIEW Run-Time Engine 2010 SP1
"{1669F2CD-E15C-4F53-A1F0-FBFC37B391D5}" = Yamaha USB-MIDI Driver
"{18468218-DFBA-4B46-B67E-02B8E9E392C1}" = NI EulaDepot
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{199E33DE-B255-4B98-ABE9-434F681E6D93}" = NI-VISA Runtime 5.4.0
"{1C3B75E1-DA30-404C-B2C2-9BD31AB64909}" = NI Visual C++ 2010 Redistributable Package
"{1C6C18A7-65C4-4AB8-BEB9-DD4DC7238EF8}" = NI LabWindows/CVI 2013 SxS NS Library
"{1D44ADDA-37B7-4DB0-B7F0-E733C54EECF1}" = NI-APAL 2.2.1 Error Files for LabVIEW RT
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{1F7F5330-D1C5-49D8-85A3-75E29C2434FE}" = NI mDNS Responder 2.2.0
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{21610B0E-501E-4EBB-9BC9-482982C5CF55}" = NI LabWindows/CVI 2013 SxS TDMS Library
"{21D50100-7B63-4610-9CEE-23E77E769DF6}" = WindO/I-NV3
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 55
"{27367777-A95D-4014-B73B-18D4838E54A4}" = NI TDM Streaming 2.5
"{28656860-4728-433C-8AD4-D1A930437BC8}" = Nuance PDF Viewer Plus
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2931F00C-6417-4BFE-B3C5-26D90ABE8189}" = NI LabVIEW Run-Time Engine Interop 2013
"{29E46600-E19D-42D1-9AE1-44D93337478A}" = WindO/I-NV2
"{29EF3691-08F2-4B61-BE7D-8FF83BDEB933}" = NI LabWindows/CVI Side-By-Side Run-Time Engine 2013
"{2BC9B2CE-D569-4ADC-A8A0-170F2FD57139}" = NI LabVIEW 2010 Real-Time NBFifo
"{2C77FBC4-79E2-4D25-86FB-CF7AAE02425E}" = NI Measurement Studio ComponentWorks UI
"{2CB15350-C073-4A5B-A706-59E1F69DE11C}" = NI Xalan Delay Load 1.10.2
"{2D7BEBFE-EDD6-45C1-BF6B-67EA7E3DDC0C}" = NI Network Browser 5.5.0
"{2DD33997-3C3E-4517-9D98-0CC5802D6D53}" = NI Curl 13.0.0
"{305468A6-DE2D-43ba-A168-2F45A97A89DA}" = DJ_SF_03_D1500_Software_Min
"{3056DC05-6D38-47E0-9DAE-68CAD903E16B}" = NI MAX CVI Support 5.5.0
"{3174B721-5400-4259-900D-C804356B0010}" = NI LabVIEW Run-Time Engine 2009 SP1
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{32735AA3-B1A1-4ED2-96C3-BE7B8EB93F2E}" = Automation Organizer
"{32D5858D-5BCE-407A-93CD-897E867ABA51}" = Reset NI Config 5.5.0
"{330EBF62-0A08-4F4D-8672-CEB9C2410E89}" = VISA Shared Components
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{356BD6F1-8B87-458D-8176-9AEF511CE4D8}" = NI PXI SystemAPI Expert 3.2.3
"{36A345C9-0691-45A1-AEEF-29ECEC8B5014}" = Microsoft Security Client
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{3777557E-E955-4CD7-BE88-1CE668FFBB51}" = Icom CS-80/880
"{37CBF405-7780-4D61-BA64-048229E7CAEE}" = NI Registration Wizard
"{38436888-9EAA-4cec-A56F-65B73D9D423C}" = D1500
"{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}" = Brother MFL-Pro Suite DCP-7065DN
"{3BCD0085-B478-48B3-8323-77E8BD493062}" = Microsoft Silverlight 5.1
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C717C2C-A9F4-4236-A539-89592B0652A7}" = NI LabVIEW 2012 Run-Time Engine Web Server
"{3DFE81D3-F8A9-4746-BC91-1C219EDEC95A}" = NI-ORB 3.0
"{3F3AD4AD-A2B1-448C-8FB9-AB83324C6762}" = NI-VISA 5.4.0
"{3F742BAF-569A-4A9F-B3D6-5D3771936998}" = NI MetaSuite Installer
"{4098334C-5D36-48EA-B734-80F6B3F106CD}" = NI LabWindows/CVI 2013 Network Variable Library
"{4123CCD7-4C7A-428A-901C-C965AB121D81}" = NI PXI Platform Services 3.2.3 Configuration Support
"{415780C0-4A19-4567-AAAE-10CCB9832B13}" = NI-RPC 4.2.2f0 for Phar Lap ETS
"{41785C66-90F2-40CE-8CB5-1C94BFC97280}" = Microsoft Chart Controls for Microsoft .NET Framework 3.5
"{431D35A4-9D29-4477-8BBA-4C24C13332F7}" = NI LabVIEW Run-Time Engine Interop 2012 SP1
"{43FAB0DE-AC5C-4C17-87EF-608D37A9FB6B}" = NI-VISA 5.4.0 MAX Provider
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4845B7A3-DDC3-44F9-A7DB-C50C94017129}" = NI Web Application Server 13.0
"{4847F967-5CB6-4458-8223-4C08E273CBF4}" = NI PXI Platform Framework 1.6.3
"{49F05354-04F7-4AE4-8434-9E7B5462C727}" = NI DN 2.0 SP1 installer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A1BCB81-2F91-451D-BEC6-59FAB0ADB8F0}" = NI Example Finder 13.0
"{4B877FC6-F44C-4B39-B0B6-CE15ADC63997}" = NI VC2005MSMs x86
"{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}" = Google Earth
"{4DDC3BED-CC68-44AA-B435-D727B620CA5B}" = Linksys Wireless-G PCI Adapter
"{4EDA6809-BAD6-416D-AACD-1EC39BF6DD41}" = NI Remote Provider for MAX 5.5.0
"{4EE7E947-1E5E-4314-970E-68B91AA18D38}" = NI LabWindows/CVI 2013 Patch 1 SxS .NET Library
"{4FCBCF89-1823-4D97-A6F2-0E8DD66E273A}" = Broadcom Wireless Network Adapter
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{53606225-A1A8-4A74-BA4B-00206F38DB60}" = NI ActiveX Container
"{54244B15-8A6A-425C-8D1F-DF9C4D2EB792}" = NI MDF Support
"{556653E7-A474-4D05-AA00-D555DF8609C6}" = NI System API .NET 5.5.0
"{56D9B44A-0864-43CA-BD22-8871A45DBCF5}" = Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7
"{575746CE-FF0A-4BF8-B3FB-05ABABB72426}" = KPG-134D
"{57B70100-8F21-4795-9394-981A8C8A5472}" = WindLDR
"{57D93790-7763-4065-97E4-26BE6B9504FE}" = USB Autorun Definition File Creation Tool
"{5825CCDA-913F-4083-833B-78CB74AF1810}" = NI System Monitor 3.2.3
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate
"{5A073702-D6E0-4D28-B43B-4C4D5DFB752D}" = NI MAX Remote Configuration Installer 5.5
"{5A60B78C-0AC1-4D49-9D74-1B3C8D8734EA}" = NI Atomic PXIe Peripheral Module Driver 2.3.0
"{5AA17000-948F-4044-AD57-E35302352287}" = WindCFG
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5B5AD300-751C-11D4-AF06-0080C884200F}" = WindLDR
"{5C0BBD9F-2D3F-4093-AD7B-3F7377E0EDCA}" = NI LabVIEW Real-Time NBFifo
"{5CC95D76-A798-4722-AE76-E494D9664907}" = NI .NET Framework 4.0
"{5DDAA4FE-66E2-47ED-8041-4AC3C6E3EB02}" = NI LabWindows/CVI 2013 f1 Patch
"{6246AACB-D78A-4563-B76E-34C722A8A715}" = NI System Web Server 13.0
"{63495F25-850C-4127-8BA6-1DFD5144723C}" = NI Trace Engine
"{639C20B2-5F6C-4139-96EA-A206EEA6F995}" = NI Variable Engine 2.6.0
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{646550E5-F469-410B-9721-01E3DCAFA7D2}" = NI Portable Configuration 5.5.0
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6731A6AD-434C-4B1F-8836-A746BFF118BD}" = NI LabWindows/CVI 2013
"{67EC0571-4B4E-40C2-8A81-8C1B02D87DB0}" = iDEN Phonebook Manager
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6894C972-A9DC-4535-B260-73E693D0B0B2}" = NI LabWindows/CVI Run-Time Engine 2013 (Updated)
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69D447B3-1B3F-42A9-9605-A8533BE06D17}" = NI System Web Server Base 13.0.0
"{6A3C1BCB-DF39-46A7-AA0C-9DB62B7D0C0D}" = KPG-56D
"{6A996EAF-F118-4C11-AD14-8029547085CB}" = NI Measurement & Automation Explorer 5.5.0
"{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}" = Nuance PaperPort 12
"{6C4E5692-4447-41EF-B792-D6795681B6AD}" = NI-MDBG 3.0.0f0
"{6CB3DA3D-C753-423D-AB3B-670C5C2FE6C4}" = NI Authentication 13.0.0
"{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}" = PaperPort Image Printer
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
"{6F3933B2-DA98-43EF-950E-CF2373918A12}" = NI-PAL 2.9.1 Error Files
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70400242-737B-4BB1-A951-4FACC011A5D9}" = NI LabWindows/CVI 2013 Low-Level Driver (Original)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{721A642C-4769-11D8-8F88-0050DA8F812F}" = KPG-89D
"{7247ABF1-C9E4-4242-8DA5-D0DF6977B018}" = NI LabVIEW Run-Time Engine Interop 2010
"{745877DC-8FFE-4E4C-ABBC-589B887A47D1}" = Virtual Sound Canvas DXi
"{756CB3EB-A763-4C4E-BB55-DA7CDEDAF941}" = NI LabWindows/CVI 2013 Instrument Driver Wizard Templates
"{766303A5-3C5D-440F-9577-3DE160F84F6F}" = NI-488.2 3.1.2
"{76D698A4-B9FF-4746-8780-EB7FB72AAC1F}" = KPG-99D
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7B3E802F-10E8-47D1-92EF-E343754AE0CF}" = NI LabWindows/CVI Shared Run-Time Engine 2013
"{7F93F26A-E5F7-4AE1-840F-F88DFE2DE3A5}" = NI-Mesa
"{7FDAF457-06ED-4F02-96A3-91610339382F}" = NI LabWindows/CVI 2013 Libraries
"{82C113AD-486F-4bd5-A2EA-2383AF57D084}" = D1500_Help
"{830FE55E-14FD-4664-A6BA-7E2948127933}" = NI LabWindows/CVI 2013 Compiler Support
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{843AA365-C682-4540-9E7C-9B9A10C6A539}" = NI Error Reporting Interface Installer 5.5
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87392509-BFBD-4780-9170-E0106DB472DF}" = NI SSL Support
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{88098056-C07B-4264-A824-C90D5BF3935E}" = NI DataSocket 5.1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8B8240B3-891D-4965-AA51-8799622D44FF}" = DJ_SF_03_D1500_ProductContext
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8EC653A0-0D75-4F97-9B03-85065F1EFBBA}" = KPG-135D
"{8F56BB24-82F2-400B-AEE5-046E5DE8312B}" = DeltaPRG
"{8F8AB076-3E25-4B2E-8E8B-B77DF232D2B5}" = NI PXI Platform Services 3.2.3
"{8F8D9297-FDD2-405A-97E7-E52C7B2F97B3}" = Ulead VideoStudio SE DVD
"{8FBAA717-6C1C-4BA1-B446-AA5118BA6401}" = NI Update Service 2.3
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90BE560D-88E1-4DD0-8630-1C0D7F722B33}" = NI LabWindows/CVI 2013 SxS .NET Library
"{90EB9FED-CBF7-40E2-BE27-E4E71E79CDD9}" = NI-488.2 3.1.2 Development Support
"{9125CF98-08A9-41AA-96B9-A7A7A255E3DC}" = NI-RPC 4.4.0f0
"{92AE2189-B5BF-409E-A6BB-BB2D390CCD8E}" = NI Certificates Deployment Support
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96F342D9-C361-4976-9DFF-7B07FB71E090}" = NI LabWindows/CVI 2013 Patch 1 SxS NV Library
"{96F8514D-1673-47AE-BD16-A8E22EF0A6FD}" = NI LabWindows/CVI 2013 Network Streams Library
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{980D31D8-888F-47C6-B8AC-E390F0D91201}" = Hurrevac2010
"{98F6A0F3-4944-4A7E-9ABE-B4E716D7AB09}" = NI LabWindows/CVI 2013 Interface to Win32 API Support
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B7F4E37-64DC-4B50-A504-124C665AD3FA}" = NI-DIM 1.13.0f0
"{9BA381D6-F63D-4C03-BE13-940F39068E01}" = NI LabVIEW 2013 Run-Time Engine Non-English Support.
"{9BA528A0-F33B-4162-993A-538CF56A005E}" = Math Kernel Libraries
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CF01499-669E-472A-89E3-54CC30C4FDBB}" = NI-RPC 4.4.0f0 for Phar Lap ETS
"{9D87E77C-45F2-432F-80A3-E0B730948677}" = NI PXI Platform Services 3.2.3 Expert
"{9DD60D2E-18C6-448C-A443-EF703A035013}" = NI LabWindows/CVI 2013 Patch 1 SxS Analysis Library
"{A0087DDE-69D0-11E2-AD57-43CA6188709B}" = Adobe AIR
"{A05EFB3F-19E2-4F9E-8380-BE095CCF0BE4}" = NI Logos XT Support
"{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}" = Status
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1E8BAD0-F70C-443B-B061-793E7D1B2B69}" = NI Service Locator 13.0
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{A6025DDF-67EF-4B5D-8365-907295F5D469}" = NI Software Provider for MAX 5.5.0
"{A8371D82-90A4-4DB1-A915-1E88F3739AD5}" = NI-APAL 2.2.1 Error Files
"{A8490B70-08B4-40F8-84FE-CCE239901EA1}" = NI License Manager
"{A8779088-85BA-4CC0-8205-1C7AF40FCDBD}" = NI System API Windows 32-bit 5.5.0
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{AB55A100-AAC9-43EA-845E-2DCDC0D4D2B8}" = NI Math Kernel Libraries
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABAB4094-01FF-4C8D-A7C3-CBBCA1E24195}" = NI LabWindows/CVI 2013 Samples
"{ABD79E99-F9E3-413B-8D18-11070754355F}" = NI Math Kernel Libraries
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.07)
"{ADC16943-45BD-4E47-89CD-A9CA790DE09C}" = NI LabVIEW 2013 Run-Time Engine Web Server
"{AE20D525-5D10-475F-9115-963DB67D49DF}" = NI System State Publisher
"{B1421599-A42D-47ef-B512-B9B0317BD599}" = DJ_SF_03_D1500_Software
"{B34624AE-C43F-416E-B22A-F3B561EB9760}" = NI OPC Support
"{B4A772D4-ED42-4484-8C0E-663A52D07A2F}" = NI LabVIEW 2012 Real-Time NBFifo
"{B745C947-0436-41D8-80AE-5EBE3967EA02}" = PA090
"{B82851CD-7715-4AA6-BCAF-390E75E229CF}" = NI I/O Trace 3.1.1
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD267361-DA07-4D0B-B476-1AA62E19B4EE}" = NI LabWindows/CVI 2013 Patch 1 SxS NS Library
"{BF324FB5-4C39-4FDC-B023-19AEFFAE116A}" = NI SSL LabVIEW RTE 2013 Support
"{C0446EC0-D69F-44C3-B3AD-E04EA7FAE72B}" = NI LabVIEW Run-Time Engine 2013
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}" = RealDownloader
"{C9A0D47F-9A68-4917-868C-79E384E4DEE6}" = NI Help Assistant 2.0
"{CA533BA0-E6F9-4349-B0EC-ABDEB0481E77}" = NI Logos 5.5
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CE26F10F-C80F-4377-908B-1B7882AE2CE3}" = Crystal Reports Basic Runtime for Visual Studio 2008
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0D82E7B-8456-4FE7-A09C-0B3A49C2A4C5}" = NI-PAL 2.9.1f0
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D361B9E5-E918-48CB-BEC3-8E44A5F6E624}" = NI LabVIEW 2009 SP1 Run-Time Engine Web Services
"{D3AE6649-8717-4103-9731-1B1707CC94D1}" = NI LabWindows/CVI 2013 SxS Analysis Library
"{D426844E-2735-4881-BD41-29F7530FA06C}" = NI Remote PXI Provider for MAX 5.5.0
"{D7FBD47D-565E-4D03-974D-8ED6C76D887E}" = NI-MXDF 3.0.0f0
"{D9C13100-441E-4A53-9BA5-999AAB740825}" = Pass-Through Tool
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DB29F1F4-113E-45E0-B1E9-90A188DAF0AD}" = NI-APAL 2.1 Error Files for LabVIEW RT
"{DB68B420-5382-48EE-9A2A-CB984FEBB192}" = NI LabVIEW Web Server for Run-Time Engine
"{DB974CAC-E29F-4F36-9343-6B589DF80593}" = NI MXS 5.5.0
"{DCA53D09-472F-48FB-9670-0AC2614B9F04}" = NI LabWindows/CVI 2013 .NET Library
"{DCF54484-DC2B-4DD9-ABD4-9FB4B01FA6F6}" = NI LabWindows/CVI 2013 TDMS Library
"{DF549FB9-B94F-4B8D-B007-39281EDB9A52}" = NI Error Reporting 2013
"{DFC813B0-1C9B-4C9D-B218-6F4FBAD37D14}" = NI LabWindows/CVI 2013 SxS NV Library
"{DFEB5AEC-611E-466F-A072-956751A66880}" = NI SSL LabVIEW RTE 2012 SP1 Support
"{E05E5413-FFE7-4E83-92AB-C5F6BCE25F6C}" = NI Uninstaller
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E1D60C68-016C-4951-8C1F-52E24DFE7836}" = NI CodeSignAPI
"{E337B156-DF81-48D8-8977-B1574EE87BCF}" = USB2.0 Capture Device
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E6068691-1FBC-4EF0-87E8-609CDB32038A}" = NI Xerces Delay Load 2.7.3
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E71784F9-5B67-4052-A5FC-55C038396936}" = Math Kernel Libraries
"{E84997A1-4D6F-4C0B-B60D-F85B360D2666}" = NI VC2008MSMs x86
"{EA289B2D-80CE-486A-935D-FC3F088AB5C7}" = NI LabVIEW 2013 Real-Time Error Dialog
"{EAE4A00B-D290-4B65-8287-B82A80FC0619}" = Linksys Wireless-G PCI Network Adapter with SpeedBooster
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{EDC84FD0-B62B-462D-B0C9-101C67E9C0B4}" = NI-488.2 Provider for MAX version 3.1.2
"{EE372D3C-8CDE-4141-8DE9-05A0734B63E4}" = NI LabVIEW 2013 Deployment Framework
"{EEDB0927-3BD8-4349-856E-425A146CC680}" = NI LabVIEW 2012 Real-Time NBFifo
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F2273FA7-117C-43D7-BD59-00B025535442}" = NI VC2010SP1MSMs x86
"{F278392D-547E-4E67-AD1C-2576C2852B50}" = NI Measurement Studio ComponentWorks 3D Graph
"{F2C35605-B41A-4139-93FE-9052FD30BD8B}" = NI LabWindows/CVI 2013 Analysis Library
"{F84B1D74-CC60-48AC-9C77-8D53F3EA0B8A}" = NI LabWindows/CVI Side-By-Side Run-Time Engine 2013 Patch 1
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.7
"{FC348F0A-7C7C-11D6-B34A-0050DA8F8110}" = KPG-44D
"{FC3B72CB-AD15-4A1F-A400-6C9463E7FC11}" = NI Launcher
"{FC3DE99A-2D6A-428D-ADA5-6A86717E6129}" = NI TDM Excel Add-In 3.5
"{FC89B79E-AE5F-495F-A2B5-4469E5E2E284}" = NI Network Discovery 5.5
"{FCBEDF17-375A-4963-B6BC-B8DD66036D2F}" = NI System Configuration Runtime 5.5.0
"{FE24BCDF-9231-450D-AA08-D3550B81EE41}" = NI LabVIEW Web Server for Run-Time Engine
"{FE82D7AF-0A22-40E8-B7A5-9D7615296BA6}" = NI USI 2.0.1
"{FEA545A1-9CAA-415E-81D8-49951ED44F22}" = NI Distributed System Manager 2013
"{FF82AEC3-C821-4716-BD9C-10434178EA39}" = NI LabVIEW Run-Time Engine Interop 2009
"{FFD30100-0DEA-4699-A4EE-DE53873E20E5}" = Downloader
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
"BB_is1" = Band-in-a-Box 2008
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.63.0
"DirMagic" = DirMagic
"Generic USB 106 Sound" = USB Multi-Channel Audio Device
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photo & Imaging" = HP Image Zone 4.2
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{1669F2CD-E15C-4F53-A1F0-FBFC37B391D5}" = Yamaha USB-MIDI Driver
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{32735AA3-B1A1-4ED2-96C3-BE7B8EB93F2E}" = Automation Organizer
"IP Camera" = IP Camera
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.2.1012
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Developer Network - Visual Studio 6.0a" = MSDN Library - Visual Studio 6.0a
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 30.0 (x86 en-US)" = Mozilla Firefox 30.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NI Uninstaller" = National Instruments Software
"PG Music DirectX Plugins_is1" = PG Music DirectX Plugins 2.0.0.0
"PTW80_is1" = PowerTracks Pro Audio 12
"RealPlayer 16.0" = RealPlayer
"Recuva" = Recuva
"SLABCOMM&10C4&EA60" = Silicon Laboratories CP210x USB to UART Bridge (Driver Removal)
"ST5UNST #1" = Hurrevac2000
"ST6UNST #1" = Kurlewin
"UI-View32_is1" = UI-View32
"VISASharedComponents" = VISA Shared Components
"Visual Basic 6.0 Professional Edition" = Microsoft Visual Basic 6.0 Professional Edition
"WebPost" = Microsoft Web Publishing Wizard 1.53
"WinDjView" = WinDjView 2.0.2
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows Password Finder_Windows Password Finder_is1" = Spotmau Windows Password Finder 6.0.1
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"Akamai" = Akamai NetSession Interface
"magicJack" = magicJack

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 5/2/2014 1:21:10 PM | Computer Name = EMA14 | Source = Application Hang | ID = 1001
Description = Fault bucket 736166847.

Error - 5/10/2014 6:03:24 PM | Computer Name = EMA14 | Source = Application Hang | ID = 1002
Description = Hanging application notepad.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/13/2014 5:44:21 PM | Computer Name = EMA14 | Source = Application Hang | ID = 1002
Description = Hanging application notepad.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/13/2014 5:44:29 PM | Computer Name = EMA14 | Source = Application Hang | ID = 1002
Description = Hanging application notepad.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/29/2014 3:28:54 PM | Computer Name = EMA14 | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 11.0.7.79, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5/31/2014 8:54:04 PM | Computer Name = EMA14 | Source = Application Hang | ID = 1002
Description = Hanging application notepad.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/6/2014 1:53:16 PM | Computer Name = EMA14 | Source = Application Hang | ID = 1002
Description = Hanging application notepad.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/6/2014 1:53:55 PM | Computer Name = EMA14 | Source = Application Hang | ID = 1002
Description = Hanging application notepad.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/6/2014 7:16:57 PM | Computer Name = EMA14 | Source = Application Hang | ID = 1002
Description = Hanging application notepad.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/6/2014 9:52:03 PM | Computer Name = EMA14 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

[ System Events ]
Error - 6/6/2014 1:55:50 PM | Computer Name = EMA14 | Source = Microsoft Antimalware | ID = 2041
Description = The support for your operating system has expired. Running %%860 on
an out of support operating system is not an adequate solution to protect against
threats.

Error - 6/6/2014 1:55:58 PM | Computer Name = EMA14 | Source = W32Time | ID = 39452706
Description = The time service has detected that the system time needs to be changed
by +1203422 seconds. The time service will not change the system time by more than
+54000 seconds. Verify that your time and time zone are correct, and that the time
source time.windows.com (ntp.m|0x1|192.168.5.106:123->64.4.10.33:123) is working
properly.

Error - 6/6/2014 1:57:07 PM | Computer Name = EMA14 | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 6/6/2014 2:05:48 PM | Computer Name = EMA14 | Source = Microsoft Antimalware | ID = 2041
Description = The support for your operating system has expired. Running %%860 on
an out of support operating system is not an adequate solution to protect against
threats.

Error - 6/6/2014 2:05:51 PM | Computer Name = EMA14 | Source = Microsoft Antimalware | ID = 2041
Description = The support for your operating system has expired. Running %%860 on
an out of support operating system is not an adequate solution to protect against
threats.

Error - 6/6/2014 2:08:24 PM | Computer Name = EMA14 | Source = Microsoft Antimalware | ID = 2041
Description = The support for your operating system has expired. Running %%860 on
an out of support operating system is not an adequate solution to protect against
threats.

Error - 6/6/2014 2:08:26 PM | Computer Name = EMA14 | Source = Service Control Manager | ID = 7000
Description = The WMP54GSSVC service failed to start due to the following error:
%%3

Error - 6/6/2014 2:10:09 PM | Computer Name = EMA14 | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 6/6/2014 11:45:01 PM | Computer Name = EMA14 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.5.106
with the system having network hardware address 00:0F:66:E4:BF:FC. Network operations
on this system may be disrupted as a result.

Error - 6/6/2014 11:45:01 PM | Computer Name = EMA14 | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.5.106
with the system having network hardware address 00:0F:66:E4:BF:FC. Network operations
on this system may be disrupted as a result.


< End of report >


Report •

#20
June 21, 2014 at 15:43:48
By renaming Notepad.exe to something else, if you then ran the CCleaner registry cleaner this would have removed what were then seen as "invalid entries", wrecked NotePad and created quite a mess. But maybe you didn't do this.

My advice, System Restore back to before you changed the msi association then submit a new log for Johnw. He would then have only the original problem to contend with.

Always pop back and let us know the outcome - thanks

message edited by Derek


Report •

#21
June 21, 2014 at 15:52:15
oh yeah; I did, but nothing changed and notepad still comes up, as this log report was in notepad. I'm re-scanning for all users this time.
Bob in LA (lower Alabama)

Report •

#22
June 21, 2014 at 16:04:25
"nothing changed"
I think plenty will have changed within the system, only the symptoms are the same.

Whatever, I've said my piece so it's up to you now.

Always pop back and let us know the outcome - thanks

message edited by Derek


Report •

#23
June 21, 2014 at 16:46:37
"OTL Extras logfile created on: 6/7/2014 6:46:13 PM - Run 1"
Thanks, still need the OTL log, refer my post #4

Report •

#24
June 21, 2014 at 17:28:51
it's too big for this window. I noticed that the notepad window with the garbage only comes up 2-3 times. maybe something has improved. I don't need to take up any more of your time. I thought I could just stop notepad for a while so the problem could be redirected or ignored. I didn't know I lost control when I sent it to notepad.

I'll let you know what I find out.

OTL indicated nothing in it's error window.

Thanks again,
Bob


Report •

#25
June 21, 2014 at 17:45:10
"it's too big for this window"
Correct, read my post #4

" I don't need to take up any more of your time"
No problem, your first log gave a lot of info, but need to confirm with the OTL log.


Report •

#26
Report •

#27
June 21, 2014 at 18:55:06
"hhere they are"
Thanks, I will now start a cleanup process. there is a lot to be sorted out, with a bit of luck, they will fix your problem.
At least you will have a clean comp which is the first basis to sort out problems.
I will tell you when all the problems I can see in your logs are sorted out.

Step 1: Run AdwCleaner
http://www.softpedia.com/get/Antivi...
http://www.softpedia.com/progScreen...
How to download from Softpedia
http://i.imgur.com/BWELEfV.gif
http://i.imgur.com/4luY3rU.gif
http://www.raymond.cc/blog/adwclean...
http://www.bleepingcomputer.com/dow...
Author's site
http://general-changelog-team.fr/en...
Tutorial
http://general-changelog-team.fr/en...
Please download AdwCleaner by Xplode onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Clean.
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please Copy & Paste the contents of that logfile with your next answer.
You can find the logfile at C:\AdwCleaner[S1].txt as well.

Step 2: Run Junkware Removal Tool
http://www.softpedia.com/get/Securi...
http://www.softpedia.com/progScreen...
How to download from Softpedia
http://i.imgur.com/qO92huz.gif
http://i.imgur.com/qzTUYkX.gif
http://www.bleepingcomputer.com/dow...
http://thisisudax.blogspot.com.au/2...
Download Junkware Removal Tool onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
Warning! Once the scan is complete JRT will shut down your browser with NO warning.
Shut down your protection software now to avoid potential conflicts.
Temporarily disable your antivirus and any antispyware real time protection before performing a scan.
Click this link to see a list of security programs that should be disabled and how to disable them.
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
Run the tool by double-clicking it. If you are using Windows Vista or Windows 7/8, right-click JRT and select Run as Administrator.
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved onto your Desktop and will automatically open.
Copy and Paste the contents of the JRT.txt log please.

message edited by Johnw


Report •

#28
June 21, 2014 at 19:41:23
here it is:

# AdwCleaner v3.212 - Report created 21/06/2014 at 21:35:08
# Updated 05/06/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : bob - EMA14
# Running from : C:\Documents and Settings\bob\Desktop\adwcleaner_3.212.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\Ask
Folder Deleted : C:\Program Files\Ask.com
Folder Deleted : C:\Program Files\targus
Folder Deleted : C:\WINDOWS\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}
Folder Deleted : C:\Documents and Settings\bob\Local Settings\Application Data\apn
Folder Deleted : C:\Documents and Settings\bob\Local Settings\Application Data\AskToolbar
Folder Deleted : C:\Documents and Settings\bob\Local Settings\Application Data\eSupport.com
Folder Deleted : C:\Documents and Settings\bob\Local Settings\Application Data\PackageAware
Folder Deleted : C:\Documents and Settings\bob\Application Data\Mozilla\Firefox\Profiles\vyp8rcis.default\Extensions\toolbar@ask.com
File Deleted : C:\Documents and Settings\bob\Application Data\Mozilla\Firefox\Profiles\vyp8rcis.default\searchplugins\Askcom.xml
File Deleted : C:\Program Files\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml
File Deleted : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\AskToolbar
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\Zugo
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\PIP
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v30.0 (en-US)

[ File : C:\Documents and Settings\bob\Application Data\Mozilla\Firefox\Profiles\vyp8rcis.default\prefs.js ]

Line Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Line Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");
Line Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "");
Line Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=CPUID&o=14650&locale=en_US&apn_uid=22585cd1-77c7-4f0e-b057-06d158800552&apn_ptnrs=%5ECU&apn_sauid=53FD335B-8B7E-485A-833[...]

-\\ Google Chrome v

[ File : C:\Documents and Settings\bob\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=CPUID&o=14650&locale=en_US&apn_uid=22585cd1-77c7-4f0e-b057-06d158800552&apn_ptnrs=%5ECU&apn_sauid=53FD335B-8B7E-485A-833C-A3B793450916&apn_dtid=%5EYYYYYY%5EYY%5EUS&q={searchTerms}
Deleted [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej
Deleted [Extension] : kincjchfokkeneeofpeefomkikfkiedl

*************************

AdwCleaner[R0].txt - [9218 octets] - [21/06/2014 21:34:32]
AdwCleaner[S0].txt - [9305 octets] - [21/06/2014 21:35:08]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9365 octets] ##########


Report •

#29
June 21, 2014 at 19:52:42
after turning MSE off:

# AdwCleaner v3.212 - Report created 21/06/2014 at 21:46:03
# Updated 05/06/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : bob - EMA14
# Running from : C:\Documents and Settings\bob\Desktop\adwcleaner_3.212.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v30.0 (en-US)

[ File : C:\Documents and Settings\bob\Application Data\Mozilla\Firefox\Profiles\vyp8rcis.default\prefs.js ]


-\\ Google Chrome v

[ File : C:\Documents and Settings\bob\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [9218 octets] - [21/06/2014 21:34:32]
AdwCleaner[R1].txt - [1065 octets] - [21/06/2014 21:45:35]
AdwCleaner[S0].txt - [9445 octets] - [21/06/2014 21:35:08]
AdwCleaner[S1].txt - [988 octets] - [21/06/2014 21:46:03]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1047 octets] ##########


Report •

#30
June 21, 2014 at 20:03:56
JRT will not run

Report •

#31
June 21, 2014 at 20:08:46
"JRT will not run"
Ok, we can always come back to that.

"after turning MSE off"
That is what I use.

Step 3: Make sure ALL your Regional and Language Options settings are Ok. Let me know if they were wrong please.
How do I change the system locale so I can use my language of choice?
http://moosenose.com/Enabling%20Int...
http://java.com/en/download/help/lo...
http://www.lipikaar.com/unicode-and...

Screen 4: 2 instances of United States.

Screen 5: 2 instances of United States.

Scroll down to > Changing Language for non-Unicode Programs
Advanced > 2 instances of United States ( may only have 1 available )


Report •

#32
June 21, 2014 at 20:30:55
I have gone back in to the house. I had to get something to eat.
What would change my location settings?
I'm on another computer now. The problem child is about 200 feet away in my trailer.
Have you seen anything seriously wrong?

Report •

#33
June 21, 2014 at 20:34:56
Have seen some contradictions in the logs, can't assume anything without checking that all those settings are correct.

Report •

#34
June 21, 2014 at 20:49:38
by the way, what time is shown in this site? I am on central daylight time GMT-5 hours.1050 pm.

Report •

#35
June 22, 2014 at 06:00:24
Note: In the future, if you select a file to 'open with', unless you are sure, uncheck the box that says "Always use...' so that you do not permanently change the file association. This is a good practice to follow.

You have to be a little bit crazy to keep you from going insane.


Report •

#36
June 22, 2014 at 07:31:42
I'll be back tomorrow (Monday, US CDT.
Thanks

Report •

#37
June 23, 2014 at 09:09:27
It looks like all my location settings are English and US

Report •

#38
June 23, 2014 at 14:58:32
Step 4: Update & Run Malwarebytes' Anti-Malware ( MBAM ) Free Version. Use Quick scan. Copy and Paste the contents of the log, in your reply please.

Report •

#39
June 23, 2014 at 15:59:43
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 6/23/2014
Scan Time: 5:44:51 PM
Logfile:
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.06.23.13
Rootkit Database: v2014.06.20.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows XP Service Pack 3
CPU: x86
File System: NTFS
User: bob

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 297281
Time Elapsed: 11 min, 30 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)


Report •

#40
June 23, 2014 at 16:07:52
From your first Extra's log.
"Error - 6/6/2014 1:55:58 PM | Computer Name = EMA14 | Source = W32Time | ID = 39452706
Description = The time service has detected that the system time needs to be changed
by +1203422 seconds. The time service will not change the system time by more than
+54000 seconds. Verify that your time and time zone are correct, and that the time
source time.windows.com (ntp.m|0x1|192.168.5.106:123->64.4.10.33:123) is working
properly"

Step 5: Make sure your Time Zone is correct.
Try & test a different Server.
Double click on time ( bottom r/h side of screen )
Click on > Internet Time.
Tick > Automatically synchronize.
Server, select by clicking on the button > time.nist.gov
Click Apply & OK.
http://www.windows-help-central.com...

Step 6: Download Security Check by screen317 from one of the following links and save it onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
http://screen317.spywareinfoforum.o...
http://screen317.changelog.fr/Secur...
Please restart the computer before running this security check..
* Double click SecurityCheck.exe. If you run Windows Vista or 7/8, right click and choose 'Run as Administrator'.
o If you are asked by Windows to run this program or not, please click 'Yes' or 'Run'.
o When you see a console window, press any key to continue scanning.
o Wait while it scans.
o If your firewall alerts you of Security Check, please press 'Allow' or similar.
* A Notepad document should open automatically after scan is completed. It will be called checkup.txt; Please Copy and Paste the contents into your reply.
Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.


Report •

#41
June 23, 2014 at 17:31:34
can you tell me how to run BAT files in windows?
screen317 will not run in windows.
Thanks
Bob

Do you have SKYPE so we could talk?


Report •

#42
June 23, 2014 at 17:45:27
"can you tell me how to run BAT files in windows?"
It's not, it's an EXE.
http://i.imgur.com/77iuVUt.gif

"Do you have SKYPE so we could talk?"
Nope, sorry Bob


Report •

#43
June 23, 2014 at 17:52:41
On my computer it says after starting sc317 windows doesn't know what program to use to run SecurityCheck.BAT. ???

Report •

#44
June 23, 2014 at 17:58:58
Did you try both links?

Report •

#45
June 23, 2014 at 18:08:05
I just zipped it up & uploaded it. You can now download it from this link.

http://speedy.sh/Byj75/SecurityChec...


Report •

#46
June 23, 2014 at 18:24:59
same results. windows needs a program to execute bat files.
I downloaded the file.
went to the directory it downloaded to.
clicked on the file name
new window opened to extract files.
extracted file was securitycheck317.exe
dragged this to desktop
double click
windows needs to know what program created this file
securitycheck.bat
here we sit.

Report •

#47
June 23, 2014 at 18:30:49
"I downloaded the file"
Is that my file?

Report •

#48
June 23, 2014 at 18:33:46
yes it is from speedyshare

Report •

#49
June 23, 2014 at 18:34:51
Step 7: Run Tweaking.com - Windows Repair Start at Step 1 & when you get to the final step, check/tick all the boxes.
Disable your antivirus program before running Windows Repair.
http://www.softpedia.com/get/Tweak/...
http://www.softpedia.com/progScreen...
http://www.tweaking.com/
http://www.tweaking.com/content/pag...
Copy and Paste the contents of the following log in your reply:
C:\Program Files\Tweaking.com\Windows Repair (All in One)\Tweaking.com_Windows_Repair_Logs\_Windows_Repair_Log.txt

message edited by Johnw


Report •

#50
June 23, 2014 at 20:51:23

System Variables
--------------------------------------------------------------------------------
OS: Microsoft Windows XP
OS Architecture: 32-bit
OS Version: 5.1.2600
OS Service Pack: Service Pack 3
Computer Name: EMA14
Windows Drive: C:\
Windows Path: C:\WINDOWS
Current Profile: C:\Documents and Settings\bob
Current Profile SID: S-1-5-21-329068152-448539723-839522115-1003
Current Profile Classes: S-1-5-21-329068152-448539723-839522115-1003_Classes
Profiles Location: C:\Documents and Settings
Profiles Location 2: C:\WINDOWS\ServiceProfiles
Local Settings AppData: C:\Documents and Settings\bob\Local Settings\Application Data
--------------------------------------------------------------------------------

System Information
--------------------------------------------------------------------------------
System Up Time: 0 Days 00:18:50

Process Count: 61
Commit Total: 363.85 MB
Commit Limit: 5.33 GB
Commit Peak: 439.45 MB
Handle Count: 14336
Kernel Total: 48.36 MB
Kernel Paged: 37.45 MB
Kernel Non Paged: 10.91 MB
System Cache: 498.54 MB
Thread Count: 635
--------------------------------------------------------------------------------

Memory Before Cleaning with CleanMem
--------------------------------------------------------------------------------
Memory Total: 3.49 GB
Memory Used: 530.41 MB(14.8402%)
Memory Avail.: 2.97 GB
--------------------------------------------------------------------------------

Cleaning Memory Before Starting Repairs...

Memory After Cleaning with CleanMem
--------------------------------------------------------------------------------
Memory Total: 3.49 GB
Memory Used: 381.28 MB(10.6678%)
Memory Avail.: 3.12 GB
--------------------------------------------------------------------------------

Starting Repairs...
Start (6/23/2014 9:42:28 PM)

01 - Reset Registry Permissions 01/03
HKEY_CURRENT_USER & Sub Keys
Start (6/23/2014 9:42:32 PM)
Running Repair Under Current User Account
Done (6/23/2014 9:42:41 PM)

01 - Reset Registry Permissions 02/03
HKEY_LOCAL_MACHINE & Sub Keys
Start (6/23/2014 9:42:41 PM)
Running Repair Under System Account
Done (6/23/2014 9:44:15 PM)

01 - Reset Registry Permissions 03/03
HKEY_CLASSES_ROOT & Sub Keys
Start (6/23/2014 9:44:15 PM)
Running Repair Under System Account
Done (6/23/2014 9:45:04 PM)

03 - Reset Service Permissions
Start (6/23/2014 9:45:04 PM)
Running Repair Under System Account
Done (6/23/2014 9:45:51 PM)

04 - Register System Files
Start (6/23/2014 9:45:51 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:48:14 PM)

05 - Repair WMI
Start (6/23/2014 9:48:14 PM)

Starting Security Center So We Can Export The Security Info.

Exporting Antivirus Info...
Microsoft Security Essentials Exported.

Exporting 3rd Party Firewall Info...
No 3rd Party Firewall Products Reported.

Running Repair Under Current User Account
Done (6/23/2014 9:53:07 PM)

06 - Repair Windows Firewall
Start (6/23/2014 9:53:07 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:53:19 PM)

07 - Repair Internet Explorer
Start (6/23/2014 9:53:19 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:55:32 PM)

08 - Repair MDAC/MS Jet
Start (6/23/2014 9:55:32 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:55:49 PM)

09 - Repair Hosts File
Start (6/23/2014 9:55:49 PM)
Running Repair Under System Account
Done (6/23/2014 9:55:52 PM)

10 - Remove Policies Set By Infections
Start (6/23/2014 9:55:52 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:55:56 PM)

11 - Repair Start Menu Icons Removed By Infections
Start (6/23/2014 9:55:56 PM)
Running Repair Under System Account
Done (6/23/2014 9:55:59 PM)

12 - Repair Icons
Start (6/23/2014 9:55:59 PM)
Running Repair Under Current User Account
Done (6/23/2014 9:56:01 PM)

13 - Repair Winsock & DNS Cache
Start (6/23/2014 9:56:01 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:56:14 PM)

15 - Repair Proxy Settings
Start (6/23/2014 9:56:14 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:56:18 PM)

17 - Repair Windows Updates
Start (6/23/2014 9:56:18 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:56:52 PM)

18 - Repair CD/DVD Missing/Not Working
Start (6/23/2014 9:56:52 PM)
iTunes not found, not applying UpperFilters iTunes Reg Key
Done (6/23/2014 9:56:52 PM)

19 - Repair Volume Shadow Copy Service
Start (6/23/2014 9:56:52 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:57:11 PM)

21 - Repair MSI (Windows Installer)
Start (6/23/2014 9:57:11 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:57:26 PM)

23.01 - Repair bat Association
Start (6/23/2014 9:57:26 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:57:31 PM)

23.02 - Repair cmd Association
Start (6/23/2014 9:57:31 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:57:35 PM)

23.03 - Repair com Association
Start (6/23/2014 9:57:35 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:57:40 PM)

23.04 - Repair Directory Association
Start (6/23/2014 9:57:40 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:57:44 PM)

23.05 - Repair Drive Association
Start (6/23/2014 9:57:44 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:57:49 PM)

23.06 - Repair exe Association
Start (6/23/2014 9:57:49 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:57:54 PM)

23.07 - Repair Folder Association
Start (6/23/2014 9:57:54 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:57:58 PM)

23.08 - Repair inf Association
Start (6/23/2014 9:57:58 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:58:03 PM)

23.09 - Repair lnk (Shortcuts) Association
Start (6/23/2014 9:58:03 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:58:07 PM)

23.10 - Repair msc Association
Start (6/23/2014 9:58:07 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:58:12 PM)

23.11 - Repair reg Association
Start (6/23/2014 9:58:12 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:58:17 PM)

23.12 - Repair scr Association
Start (6/23/2014 9:58:17 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:58:21 PM)

24 - Repair Windows Safe Mode
Start (6/23/2014 9:58:21 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:58:26 PM)

25 - Repair Print Spooler
Start (6/23/2014 9:58:26 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:58:43 PM)

26 - Restore Important Windows Services
Start (6/23/2014 9:58:43 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:58:54 PM)

27 - Set Windows Services To Default Startup
Start (6/23/2014 9:58:54 PM)
Running Repair Under Current User Account
Running Repair Under System Account
Done (6/23/2014 9:59:10 PM)

Skipping Repair.
Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
Current version: 5.1

Skipping Repair.
Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
Current version: 5.1

Skipping Repair.
Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
Current version: 5.1

Cleaning up empty logs...

All Selected Repairs Done.
Done (6/23/2014 9:59:11 PM)
Total Repair Time: 00:16:45


...YOU MUST RESTART YOUR SYSTEM...
Running Repair Under Current User Account


Report •

#51
June 23, 2014 at 21:44:51
Have you rebooted & tried Security Check by screen317 again?

Report •

#52
June 24, 2014 at 03:45:45
no, but I will today.
thanks

Report •

#53
June 24, 2014 at 09:41:52
Here it is.
Did not have the garbage notepad today. maybe we are through. Sorry to take up so much of your time.
Thanks,
Bob


Results of screen317's Security Check version 0.99.85
Windows XP Service Pack 3 x86
Internet Explorer 8
[b][u]``````````````Antivirus/Firewall Check:``````````````[/b][/u]
Please wait while WMIC compiles updated MOF files.d
i
s
p
l
a
y
N
a
m
e
ECHO is off.
M
i
c
r
o
s
o
f
t
ECHO is off.
S
e
c
u
r
i
t
y
ECHO is off.
E
s
e
n
t
i
a
l
s
ECHO is off.
Antivirus up to date! (On Access scanning [b]disabled[/b]!)
[b][u]`````````Anti-malware/Other Utilities Check:`````````[/b][/u]
CCleaner
Java 7 Update 55
[color=red][b]Java version out of Date![/b][/color]
Adobe Flash Player 13.0.0.214 [b][color=red]Flash Player out of Date![/color][/b]
Adobe Reader XI
Mozilla Firefox (30.0)
[b][u]````````Process Check: objlist.exe by Laurent````````[/b][/u]
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamscheduler.exe
[b][u]`````````````````System Health check`````````````````[/b][/u]
Total Fragmentation on Drive C:: 7%
[b][u]````````````````````End of Log``````````````````````[/b][/u]

message edited by bob9139


Report •

#54
June 24, 2014 at 16:11:42
"Did not have the garbage notepad today. maybe we are through"
We are getting very close Bob, well done.

"Sorry to take up so much of your time"
This is my hobby & I love the challenge, I fix 2 or 3 comps a week for the community.

Important: Java & Flash need updating for security reasons. Both are high risk security wise.


Report •

#55
June 24, 2014 at 16:14:09
Step 8: Try Junkware Removal Tool again. Log please.
Note: When it stops at the Press any key to continue message, make sure you do so.
http://i.imgur.com/RsVXOEr.gif

Report •

#56
June 24, 2014 at 18:54:19
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Microsoft Windows XP x86
Ran by bob on Tue 06/24/2014 at 20:48:03.56
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


~~~ Services

~~~ Registry Values

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{1C2C5F7A-690C-40DB-9CA6-4DD669E9D57F}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5098333E-DE48-4BAC-9734-3F46F3D6DFB4}
Successfully deleted: [Registry Key] "hkey_current_user\software\microsoft\internet explorer\low rights\elevationpolicy\{a5aa24ea-11b8-4113-95ae-9ed71deaf12a}"

~~~ Files

~~~ Folders

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 06/24/2014 at 20:50:53.04
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Report •

#57
June 24, 2014 at 19:05:12
Let me know when you have finished steps 9 & 10 please.

Step 9: I use these on every comp I work on, multi times a day. Run both, in this order. ( Yes, I know you have CCleaner, which I also use )

Run Wise Disk Cleaner ( Run the 1st three tabs, left to right. I use default settings, leave boxes that are unchecked, unchecked )
http://www.softpedia.com/get/System...
http://www.softpedia.com/progScreen...
http://www.wisecleaner.com/download...
http://i.imgur.com/Jecnfvb.gif
http://i.imgur.com/0xHwdom.gif
http://i.imgur.com/JZLYOLf.gif
http://i.imgur.com/4kfaeGW.gif

Run Wise Registry Cleaner ( Only use Registry Cleaner & with default settings. Don't use System Tuneup, that is for Experts, you really have to know what you are doing )
http://www.softpedia.com/get/Tweak/...
http://www.softpedia.com/progScreen...
http://www.wisecleaner.com/wiseregi...
http://i.imgur.com/Qy7HWcA.gif

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Step 10: RunTFC
http://www.geekstogo.com/forum/file...
http://www.bleepingcomputer.com/dow...
http://oldtimer.geekstogo.com/TFC.exe
http://www.itxassociates.com/OT-Too...
Please double-click TFC.exe to run it. Note: If you are running on Vista/Windows 7/8, right-click on the file and choose Run As Administrator).
It will close all programs when run, so make sure you have saved all your work before you begin.
Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

message edited by Johnw


Report •

#58
June 24, 2014 at 19:45:58
I don't want to delete some of my old program files just because I haven't used them in a while. I don't need the disk space. I have a 2 TB network drive I can access. I hope I didn't lose any old files yet. I'm old too. I depend on these files to help me work on some old equipment still in use.
Maybe we had better stop while I'm ahead.

I would like a summery of the things we did, to use on my old laptops running XP.

By the way we got rid of that MS popup telling me they don't support XP anymore.Hooray!

I will continue using CCleaner and malwarebytes and I guess MSE as long as they work.

I think MS software is designed to fail. That way they can sell new versions. They make everything so complicated in hiding features the average user will never see and forcing use of features they think are time saving but I find obtrusive.

I'm glad people like you have taken the time to try and get to the problems some of these features cause for regular users. I'm glad I found this site and all who use it. I hope I can help someone myself someday.

I don't know where to mark the best solution to my problem. It went away after yesterday's efforts abut I don't know which one or ones exactly. Maybe this wont happen to anyone else.


Thanks again,
Bob


Report •

#59
June 24, 2014 at 19:49:22
Step 11: As you can see from your logs, you had a lot of stuff installed, that you did not know had been installed.
A lot of programs, now give you the choice to install toolbars & other during the install. Either uncheck these items during install, or use Custom install. No more click, click during an install, you have to read after each click.

I use Softpedia, down the bottom of the page, they make you aware what Ad-supported programs the author of the program has included.
Sample pages
http://www.softpedia.com/get/CD-DVD...
http://www.softpedia.com/get/Multim...
Users are advised to pay attention while installing this ad-supported application:
· Offers to change the homepage for web browsers installed in the system
· Offers to change the default search engine for web browsers installed in the system
· Offers to install StartNow Toolbar that the program does not require to fully function
SS ( screenshots ) of above
http://i.imgur.com/CSBplyA.gif
http://i.imgur.com/3eWWoXm.gif

Use Unchecky to help prevent these third party installs. Nothing is perfect, the badies are always ahead of the goodies.
http://www.softpedia.com/get/System...
http://www.softpedia.com/progScreen...
http://unchecky.com/
How to download from Softpedia
http://i.imgur.com/iZ3Fzmc.gif
http://i.imgur.com/NNgm1rF.gif
A reliable application that aims to protect your computer against third-party components often offered during software installations.

/////////////////////////////////////////////////////////

Open Device Manager & click on the + alongside Disk drives. Tell me the EXACT model of your Hard Drive please.
http://www.cybertechhelp.com/tutori...

message edited by Johnw


Report •

#60
June 24, 2014 at 20:14:44
SAMSUNG HD160JJ is the hard drive

Report •

#61
June 24, 2014 at 20:24:42
"SAMSUNG HD160JJ"
Thanks Bob, wanted to make sure it wasn't a SSD ( Solid State Drive ) which are not to be defragged.

Step 12: System Restore will have infected files in it, turning System Restore OFF & then ON will remove them.
How to Turn On and Turn Off System Restore in Windows XP
http://support.microsoft.com/kb/310...

Step 13: "Total Fragmentation on Drive C:: 7%"
Final steps, defrag your hard drive & registry.
Run Wise Disk Cleaner, click on > Disk Defrag
Run Wise Registry Cleaner, click on > Registry Defrag


Report •

#62
June 24, 2014 at 21:38:34
that's done.
I'm going inside now. I'll check back tomorrow.
Goodnight
Bob

Report •

#63
June 24, 2014 at 22:28:52
"Goodnight"
Figured you would be close going to bed.

We have just had 4 days of sunshine, at the moment 18 deg C, not a cloud in the sky. Allowed me to get all my outside jobs done.

"By the way we got rid of that MS popup telling me they don't support XP anymore.Hooray!"
Good one.

"I don't know where to mark the best solution to my problem"
OTL gave me all the clues.

"I guess MSE as long as they work"
I have installed this one on many XP comps.

Baidu Antivirus
http://www.softpedia.com/get/Antivi...
http://www.softpedia.com/progScreen...
http://antivirus.baidu.com/en/



Report •

#64
June 25, 2014 at 10:14:14
Another nice effort down to Bob and John - well done. Good choice for Best Answer too.

Always pop back and let us know the outcome - thanks


Report •

#65
June 25, 2014 at 14:31:57
+1 What Derek said :-)

This is a perfect example of how the repair process goes when you have a skilled helper and the OP is vigilant and sees the process through to the end.

Far too many times we see the OP disappear when the symptoms are gone without realising they are still carrying malware in their system.


Report •

#66
June 25, 2014 at 16:39:18
Thanks Derek & btk1w1. Yes nice to get one finished.

btk1w1, I see the West Coast Eagles are playing Brisbane soon, that should be a closer result.

I barrack for both Eagles & Dockers, but in the Derby this weekend, I shall be barracking for the Dockers.


Report •

#67
June 26, 2014 at 06:52:47
Hmmm.... Should I?
Oh what the heck!
Go the Lions!!!! Lol

Report •


Ask Question