OTL Extras logfile created on: 14/02/2014 16:56:57 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\catherine\Desktop 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16798) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 3,96 Gb Total Physical Memory | 2,31 Gb Available Physical Memory | 58,32% Memory free 5,71 Gb Paging File | 3,96 Gb Available in Paging File | 69,38% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 447,31 Gb Total Space | 397,40 Gb Free Space | 88,84% Space Free | Partition Type: NTFS Drive D: | 16,97 Gb Total Space | 2,12 Gb Free Space | 12,47% Space Free | Partition Type: NTFS Drive E: | 297,52 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive G: | 931,48 Gb Total Space | 401,03 Gb Free Space | 43,05% Space Free | Partition Type: NTFS Drive H: | 1862,98 Gb Total Space | 90,23 Gb Free Space | 4,84% Space Free | Partition Type: NTFS Computer Name: CATHY | User Name: catherine | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{012C3283-5393-4810-A29E-3F34BF567075}" = rport=139 | protocol=6 | dir=out | app=system | "{15703596-B720-47CE-A362-78D0FC442A9B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{17E5D068-37AF-4542-8F12-C4DCF1C1F056}" = rport=445 | protocol=6 | dir=out | app=system | "{1E46A651-5BC9-439F-8B8E-E47630E330C2}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2D9D0D6A-ADC9-4340-B16A-FE12AC204463}" = lport=10243 | protocol=6 | dir=in | app=system | "{39BB5C8B-F2E6-423B-A0BF-B02B904E25DD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{3F1BF332-11A6-42A4-8F12-D9C0AFC0ABF1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4481DB91-84CD-4EE1-9706-A4D2509B95B7}" = lport=53000 | protocol=6 | dir=in | name=hpconnectedremoteservice.exe | "{46D60BCD-AEA0-4534-9246-5DF8C8266613}" = lport=445 | protocol=6 | dir=in | app=system | "{4CEF84DE-8896-429F-B2E4-B79FEEED988B}" = lport=2869 | protocol=6 | dir=in | app=system | "{50D381B0-A553-419A-8ED3-3DB05DEC69A8}" = rport=137 | protocol=17 | dir=out | app=system | "{52E46454-26DC-44AF-A52F-ABC96930E416}" = lport=52000 | protocol=6 | dir=in | name=hpconnectedremoteuser.exe | "{57CAB047-3440-4E4B-9777-B42F75795633}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5F1901C9-F658-4E3E-AE77-8C09A0597CF9}" = lport=138 | protocol=17 | dir=in | app=system | "{80EB5F58-C952-4F77-A981-EE182B234224}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{A7ED86E9-85C1-4DB8-B5CD-EDDB0B5A7512}" = lport=137 | protocol=17 | dir=in | app=system | "{AB625F27-8291-427D-8155-CBA34BF79D09}" = rport=138 | protocol=17 | dir=out | app=system | "{ADF86AB5-D2EA-4E24-B7F1-8AFE6AE657AA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{B897A057-08E2-4D89-BFD0-B77E012B4691}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{BC291AD4-450A-422A-8521-E9EF0E6ABEB0}" = rport=10243 | protocol=6 | dir=out | app=system | "{CFDE43B3-5316-49B9-8D17-CD3EB9FFA356}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{D618F5EC-99CC-404D-BF4B-E84743D83331}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D9988B0A-AC38-4B61-A68E-BA0F350C2BA4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{DA4E3081-7699-415E-9560-74377F9E7B4C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E989C1DC-E6AC-402B-9074-F0F64006B57B}" = lport=139 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{015913EE-85D3-4F19-B0BA-BB7ACEE344AA}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{0BCA39F2-A40C-46D3-83FF-A293EB86C765}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{109F6C94-6416-4E6E-8C93-8DF7067E2477}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{1464F269-375D-4325-9A5F-F4994C6D28CC}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{161BF58E-AAA0-461D-9F90-47A52414D420}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{189CF0B4-9E35-4FB8-9448-3C51699F254A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{191D6658-EDAB-428D-80D6-EF8702124ACA}" = dir=in | name=hp connected photo powered by snapfish | "{2039B9F8-044E-437E-A002-D8529BC5616D}" = protocol=6 | dir=out | app=system | "{205402C7-7341-49D7-9AAC-7A166D121959}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector10\pdr10.exe | "{2B7B34C5-E328-4058-937B-E53CF05B5ABD}" = dir=out | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{30F77235-D025-4DDF-90C9-221F0DD15925}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{31E8DA4A-1D9B-4C40-88B0-E00DFC3763B8}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe | "{3277C3C6-0056-48D8-9B74-F558D0B7A505}" = dir=in | name=skype | "{337AFB69-2850-4E6C-A622-61A1289E599F}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{399AFB12-7393-428C-802F-C15898692BC1}" = dir=out | name=@{microsoft.zunemusic_1.5.216.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{3F38D6E1-05E8-4B5E-8FDF-15A6614A43FB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{42E975FB-239A-42C6-98E3-A65ADA54C0CD}" = dir=out | name=@{microsoft.bingmaps_1.6.1821.2624_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{46693260-9E21-4FD5-8991-B20DA37C22CC}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{488BD80D-459A-42F8-9C32-92F463A7095E}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{4A92D34E-F40D-46FB-8DB8-C21722AFB905}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{4C2425B1-3C32-4F85-8EC2-01F093AE5CC5}" = dir=out | name=skype | "{52FA91CC-819C-454F-AB00-B8D385734EA3}" = dir=out | name=hp games | "{56BB50AA-64EF-4B34-89FE-89811CDF2027}" = dir=out | name=hp connected photo powered by snapfish | "{5C1B2833-441E-4488-B1F8-1E4FA186EA4E}" = dir=out | name=norton studio | "{5D2A4362-C6F8-4E31-959D-C2B4CAFDCD03}" = dir=out | name=hp registration | "{5D65745F-A1D0-4976-A947-ABEF1F0BE281}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{6D56FFDB-B7DE-49E5-8C01-D8D91D4078A5}" = protocol=17 | dir=in | name=hpconnectedremoteservice.exe | "{6EC77B66-889A-4AB9-8C30-91FD7C8F90FA}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{6F2FE06A-961C-4B80-8466-0129B7BDEF67}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{76CD91DD-9FE4-4574-90FA-8478956237E7}" = dir=out | name=ebay | "{78C86E5A-5645-47EB-B04E-A32C446FEF0F}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{79FB54B0-D8D0-4381-AC40-6F5EA8C94039}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{8195CFF2-2CB2-4E37-9E6C-C1F77730C19D}" = dir=out | name=@{microsoft.xboxlivegames_1.3.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{87445F31-115E-4BED-8B77-BF246C824F25}" = dir=in | app=c:\users\administrator\appdata\local\microsoft\skydrive\skydrive.exe | "{88445DA8-C38A-49DB-B6D8-0D04F54C7420}" = dir=out | name=@{microsoft.zunevideo_1.5.444.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{8DD58C63-CE21-408A-8A99-44743EBDEC12}" = dir=out | name=@{microsoft.bingweather_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{91D359BF-871A-4D6A-B4F6-FF32046974A9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{92F40F55-DCC1-4183-BCB0-4D46E8F6FFD6}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{96F20741-DBDE-4616-8C0A-B3F83812CDA0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{9724A8D0-48FE-4D38-BC02-8FD90165B0A0}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{97B4057C-4092-4C20-826F-E8CA55CFDC96}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{9ED8E8E5-06D7-46FA-9772-41C8ADFF1B54}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{A0101BB0-2693-4CBB-AAB2-A350C15A6268}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{A1255452-349F-405B-A4AF-1B8C4BEAB737}" = dir=out | name=windows_ie_ac_001 | "{A3AA20EF-9251-4FCE-8D87-CEA78A15EF20}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{AC4E415C-0C38-4A8B-B6D8-1198C98AE09B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{B47ED7BE-E7AA-4B53-86A7-D5FFCF44D608}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{B57F8E7D-280E-4C9E-A80C-1C982E5AB3C2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{BC8D7EEF-0791-42B0-82C7-2EA548BF7799}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{BE9A3F2E-20FD-4F3F-A1F4-2E46F20F695A}" = dir=in | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{BF9DDF0E-9B83-4E61-947D-AC6FC04ABE40}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe | "{CD7DD750-6576-4637-9FF1-A0EBBAFE183D}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{D4A1A5EF-911F-4189-B44A-DE7F8A8E1917}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{E7223F71-A280-444E-A1C1-CA13AFD5A4D4}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{E81CA6D8-C50F-4917-89E5-537DC3A3E10B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E87627D7-D59C-4D8E-AE0A-F5B4CF84F967}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{EA32F579-B73E-4AD8-9721-3B2EAD8F99C9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{F4409A6D-AB55-44B2-969F-AD946D070108}" = dir=out | name=getting started with windows 8 | "{F47136AE-6C43-4FAA-8509-78FDF9C4DD72}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "TCP Query User{AFBB588F-C262-46FC-B6FB-870746CAC91B}C:\users\catherine\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\catherine\appdata\roaming\spotify\spotify.exe | "UDP Query User{3ED0A604-DE51-4003-A34F-A855EE8E62AC}C:\users\catherine\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\catherine\appdata\roaming\spotify\spotify.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}" = HP Postscript Converter "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panneau de configuration NVIDIA 311.41 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Pilote graphique 311.41 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Logiciel système PhysX 9.12.1031 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Pilote audio HD : 1.3.23.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{C2E428EB-116E-41C0-9E84-B22DE9CCA42F}" = HP Registration Service "{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client "{F842F8B0-6942-4930-821F-543E976B2C66}" = MSVCRT110_amd64 "CCleaner" = CCleaner "Unlocker" = Unlocker 1.9.2 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements "{1057511B-F8FE-4230-9ED3-AB949A57EE4A}" = Windows Live PIMT Platform "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10 "{233B918E-99FD-4643-BEDD-A9855A56FC3A}" = Windows Live UX Platform Language Pack "{29315CEC-E6CE-4394-84DC-6F862E8D9A52}" = Windows Live UX Platform "{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8 "{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App "{35BD47F4-C19B-474F-AACC-E8C0BE38148A}" = Photo Common "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager "{46037DC7-F927-46DF-935F-D6F122BDD34B}_is1" = Connected Music powered by Universal Music Group version 1.0 "{4689F012-C8E3-4F6E-BDEF-13671D53A6DC}" = Windows Live UX Platform Language Pack "{4862344A-A39C-4897-ACD4-A1BED5163C5A}" = CyberLink PhotoDirector "{4C0D8B3E-63F0-4773-83F5-C5B7795B0FB8}" = Photo Gallery "{4F9A382F-4478-4036-905C-F77DF2EA0370}" = Windows Live SOXE "{4FA8F084-C42F-45E1-B7E5-E0C8A1083DC5}" = Windows Live SOXE Definitions "{61889FC7-9738-439A-96B3-17AF981BDDEF}" = Movie Maker "{64DF7404-9D46-44AF-AFA1-A2F8D5648C2D}" = Windows Live Photo Common "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1 "{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{76EE8FE7-1957-4C51-9074-4930A8CFB1AF}" = Windows Live Installer "{78F35489-621D-4FFD-BCE7-2C7C3897E47C}" = Windows Live "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110 "{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT5390R 802.11bgn Wi-Fi Adapter "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office "{9846E46F-07E0-4BDF-985A-E3FBA8C15877}" = Movie Maker "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B2E55F8-5BA8-4A45-9682-ACB6F2CC0DA5}" = Photo Gallery "{9C244239-ED8E-40f1-937F-51C706CD2160}" = Les Sims™ 2 Deluxe "{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}" = Les Sims™ 2 Kit Glamour "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10 "{B2B7B1C8-7C8B-476C-BE2C-049731C55992}" = HP Support Information "{B9494F9E-5EA9-4C70-9F38-659F5E6C0BF3}" = HP Quick Start "{BA73469B-D8C7-4FE3-B33C-1340D09F0709}" = Windows Live Communications Platform "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint "{D531FC91-6F4E-49A7-B912-15289D05B6F8}" = Photo Common "{D71BC54E-A4E6-4E06-866C-FD6EE16EA187}" = Movie Maker "{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio "{EBFCBD05-77A3-4FC3-A6D2-27218B61D957}" = Windows Live Essentials "{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F243A34B-AB7F-4065-B770-B85B767C247C}" = HP Connected Remote "{FE8DFDD0-A543-4A83-B7A9-C411138194D5}" = Galerie de photos "Bandicam" = Bandicam "BandiMPEG1" = Bandisoft MPEG-1 Decoder "Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 2.2 "Free Sound Recorder_is1" = Free Sound Recorder v9.6.1 "Free Video Converter_is1" = Free Video Converter V 3.2 "Freemake Video Downloader_is1" = Freemake Video Downloader "Google Chrome" = Google Chrome "HotspotShield" = Hotspot Shield 3.23 "InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10 "InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8 "InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}" = CyberLink PhotoDirector "InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10 "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint "InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD "NIS" = Norton Internet Security "TI xHCI Filter Driver" = TI xHCI Filter Driver 1.0.0.4 "VLC media player" = VLC media player 2.1.3 "WildTangent hp Master Uninstall" = HP Games "WildTangent wildgames Master Uninstall" = WildTangent Games "WinLiveSuite" = Windows Live Essentials "WinPcapInst" = WinPcap 4.1.2 "WTA-01b84049-0646-4212-a6d2-2ae048b76724" = Final Drive Fury "WTA-04396d8c-2c97-4800-aacc-489cc4d9bad3" = Trinklit Supreme "WTA-07471cf9-3e7e-4fdb-a2a7-7d25d552a91f" = Governor of Poker 2 Premium Edition "WTA-1b56a11e-a988-4369-af31-cf4ad3ac5c8f" = Royal Envoy 2 Collector's Edition "WTA-3897a039-c1b5-49b0-98e6-3afd6041b4ba" = Polar Bowler "WTA-395a9364-5c50-46a9-8d64-c3c61c99a951" = Cradle of Rome 2 "WTA-3ca26d11-7a48-4c0f-9698-a38ce7bf5054" = Build-a-lot 4 - Power Source "WTA-4027486c-03bb-431f-9fa7-7fbd4516bbf5" = Bejeweled 3 "WTA-40cef5eb-eb8d-46b6-a6e7-5fc38bd8940e" = Crazy Chicken Soccer "WTA-46878c83-1b42-466e-a4a3-9e3b1c0652ea" = Gardenscapes: Mansion Makeover "WTA-4921d3f9-4446-404c-947c-bc8c375cb6f5" = Ranch Rush 2 - Premium Edition "WTA-498d8f60-7cd9-43fa-814a-6c9526e159ac" = Aloha TriPeaks "WTA-5368bb0d-3f9d-48e0-9870-d7dfcc7ad1f8" = Wedding Dash "WTA-66e5f2d0-5b76-41f9-9c61-f4fa9529460f" = Zuma's Revenge "WTA-851cfa52-b667-4cd0-87b2-af960e7a1555" = Mystery of Mortlake Mansion "WTA-8e05a206-cfd4-49f2-852a-c31b8ac8f8ae" = Jewel Match 3 "WTA-afa52746-dcb3-478c-aa36-19d84ca45cc7" = Mahjongg Artifacts "WTA-da0a55b3-fafb-4592-8327-6568b9a131b1" = Youda Jewel Shop "WTA-e57827c2-e5a8-4df4-8639-c4ed737a64c2" = Jewel Quest II "WTA-ea5ce6a4-bce8-4e2e-b393-ec8ada897a93" = Farm Frenzy [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Spotify" = Spotify [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 11/02/2014 04:38:38 | Computer Name = cathy | Source = Windows Search Service | ID = 3007 Description = Error - 11/02/2014 04:38:39 | Computer Name = cathy | Source = Windows Search Service | ID = 10021 Description = Error - 11/02/2014 05:39:37 | Computer Name = cathy | Source = SideBySide | ID = 16842830 Description = La création du contexte d’activation a échoué pour « C:\Users\catherine\Downloads\SoftonicDownloader_pour_spotify.exe ». Erreur dans le fichier de manifeste ou de stratégie «  » à la ligne . Une version de composant nécessaire à l’application est en conflit avec une autre version de composant déjà active. Les composants en conflit sont : Composant 1 : C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f.manifest. Composant 2 : C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985.manifest. Error - 11/02/2014 05:39:37 | Computer Name = cathy | Source = SideBySide | ID = 16842830 Description = La création du contexte d’activation a échoué pour « C:\Users\catherine\Downloads\SoftonicDownloader_pour_spotify.exe ». Erreur dans le fichier de manifeste ou de stratégie «  » à la ligne . Une version de composant nécessaire à l’application est en conflit avec une autre version de composant déjà active. Les composants en conflit sont : Composant 1 : C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f.manifest. Composant 2 : C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985.manifest. Error - 11/02/2014 05:39:44 | Computer Name = cathy | Source = SideBySide | ID = 16842830 Description = La création du contexte d’activation a échoué pour « C:\Users\catherine\Downloads\SoftonicDownloader_pour_spotify.exe ». Erreur dans le fichier de manifeste ou de stratégie «  » à la ligne . Une version de composant nécessaire à l’application est en conflit avec une autre version de composant déjà active. Les composants en conflit sont : Composant 1 : C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f.manifest. Composant 2 : C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985.manifest. Error - 11/02/2014 05:39:53 | Computer Name = cathy | Source = SideBySide | ID = 16842830 Description = La création du contexte d’activation a échoué pour « C:\Users\catherine\Downloads\SoftonicDownloader_pour_spotify.exe ». Erreur dans le fichier de manifeste ou de stratégie «  » à la ligne . Une version de composant nécessaire à l’application est en conflit avec une autre version de composant déjà active. Les composants en conflit sont : Composant 1 : C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f.manifest. Composant 2 : C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985.manifest. Error - 11/02/2014 06:05:49 | Computer Name = cathy | Source = SideBySide | ID = 16842830 Description = La création du contexte d’activation a échoué pour « C:\Users\catherine\Downloads\SoftonicDownloader_pour_spotify.exe ». Erreur dans le fichier de manifeste ou de stratégie «  » à la ligne . Une version de composant nécessaire à l’application est en conflit avec une autre version de composant déjà active. Les composants en conflit sont : Composant 1 : C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f.manifest. Composant 2 : C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985.manifest. Error - 11/02/2014 06:07:02 | Computer Name = cathy | Source = SideBySide | ID = 16842830 Description = La création du contexte d’activation a échoué pour « C:\Users\catherine\Downloads\SoftonicDownloader_pour_spotify.exe ». Erreur dans le fichier de manifeste ou de stratégie «  » à la ligne . Une version de composant nécessaire à l’application est en conflit avec une autre version de composant déjà active. Les composants en conflit sont : Composant 1 : C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f.manifest. Composant 2 : C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985.manifest. Error - 11/02/2014 09:37:06 | Computer Name = cathy | Source = SideBySide | ID = 16842830 Description = La création du contexte d’activation a échoué pour « C:\Users\catherine\Downloads\SoftonicDownloader_pour_spotify.exe ». Erreur dans le fichier de manifeste ou de stratégie «  » à la ligne . Une version de composant nécessaire à l’application est en conflit avec une autre version de composant déjà active. Les composants en conflit sont : Composant 1 : C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f.manifest. Composant 2 : C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985.manifest. Error - 12/02/2014 07:30:57 | Computer Name = cathy | Source = SideBySide | ID = 16842830 Description = La création du contexte d’activation a échoué pour « C:\Users\catherine\Downloads\SoftonicDownloader_pour_spotify.exe ». Erreur dans le fichier de manifeste ou de stratégie «  » à la ligne . Une version de composant nécessaire à l’application est en conflit avec une autre version de composant déjà active. Les composants en conflit sont : Composant 1 : C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f.manifest. Composant 2 : C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985.manifest. [ HP Software Framework Events ] Error - 14/02/2014 11:46:28 | Computer Name = cathy | Source = CaslSmBios | ID = 5 Description = 2014/02/14 16:46:28.629|000015E8|Error |[CaslWmi]CommandSmartAdapter::GetSmartAdapterStatusFromBIOS{hpCasl.enReturnCode(bool&,int&)}|Error 597 from BIOS WMI call Read/0Fh while getting SmartAdapter state Error - 14/02/2014 11:46:35 | Computer Name = cathy | Source = CaslSmBios | ID = 5 Description = 2014/02/14 16:46:35.443|000015E8|Error |[CaslWmi]CommandDiags::A{hpCasl.enReturnCode(System.DateTime&)}|Error executing wmiBIOS.ExecMethodClient, eRetCode: 597 Error - 14/02/2014 11:46:39 | Computer Name = cathy | Source = CaslSmBios | ID = 5 Description = 2014/02/14 16:46:39.576|000015E8|Error |[CaslWmi]CommandDiags::C{bool()}|Error, eRet: 597 Error - 14/02/2014 11:46:41 | Computer Name = cathy | Source = CaslSmBios | ID = 5 Description = 2014/02/14 16:46:41.095|000015E8|Error |[CaslWmi]CommandDiags::C{bool()}|Error, eRet: 597 Error - 14/02/2014 11:46:42 | Computer Name = cathy | Source = CaslSmBios | ID = 5 Description = 2014/02/14 16:46:42.672|000015E8|Error |[CaslWmi]CommandDiags::C{bool()}|Error, eRet: 597 Error - 14/02/2014 11:46:44 | Computer Name = cathy | Source = CaslSmBios | ID = 5 Description = 2014/02/14 16:46:44.189|000015E8|Error |[CaslWmi]CommandDiags::C{bool()}|Error, eRet: 597 Error - 14/02/2014 11:46:45 | Computer Name = cathy | Source = CaslSmBios | ID = 5 Description = 2014/02/14 16:46:45.705|000015E8|Error |[CaslWmi]CommandDiags::C{bool()}|Error, eRet: 597 Error - 14/02/2014 11:46:47 | Computer Name = cathy | Source = CaslSmBios | ID = 5 Description = 2014/02/14 16:46:47.252|000015E8|Error |[CaslWmi]CommandDiags::C{bool()}|Error, eRet: 597 Error - 14/02/2014 11:46:48 | Computer Name = cathy | Source = CaslSmBios | ID = 5 Description = 2014/02/14 16:46:48.765|000015E8|Error |[CaslWmi]CommandDiags::C{bool()}|Error, eRet: 597 Error - 14/02/2014 11:46:50 | Computer Name = cathy | Source = CaslSmBios | ID = 5 Description = 2014/02/14 16:46:50.423|000015E8|Error |[CaslWmi]CommandDiags::C{bool()}|Error, eRet: 597 [ System Events ] Error - 10/02/2014 09:27:05 | Computer Name = cathy | Source = volmgr | ID = 262190 Description = L'initialisation du fichier de vidage sur incident a échoué. Error - 10/02/2014 16:11:37 | Computer Name = cathy | Source = Microsoft-Windows-Kernel-Power | ID = 137 Description = Error - 11/02/2014 04:35:49 | Computer Name = cathy | Source = EventLog | ID = 6008 Description = L’arrêt système précédant à 22:45:56 le ?10/?02/?2014 n’était pas prévu. Error - 11/02/2014 04:31:34 | Computer Name = cathy | Source = Microsoft-Windows-Kernel-Boot | ID = 29 Description = Error - 11/02/2014 18:00:14 | Computer Name = cathy | Source = Service Control Manager | ID = 7034 Description = Le service GamesAppIntegrationService s’est terminé de façon inattendue pour la 1ème fois. < End of report >