Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-07-2015 Ran by romain at 2015-07-17 12:05:32 Running from C:\Users\romain\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrateur (S-1-5-21-2474900282-185326158-1464080906-500 - Administrator - Disabled) HomeGroupUser$ (S-1-5-21-2474900282-185326158-1464080906-1002 - Limited - Enabled) Invité (S-1-5-21-2474900282-185326158-1464080906-501 - Limited - Disabled) romain (S-1-5-21-2474900282-185326158-1464080906-1000 - Administrator - Enabled) => C:\Users\romain ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-PDF Printer 9.1.0.1456 (HKLM\...\7-PDF Printer_is1) (Version: 9.1.0.1456 - 7-PDF, Germany - Th. Hodes) ABBYY FineReader 11 Corporate Edition (HKLM\...\{F1100000-0010-0000-0000-074957833700}) (Version: 11.0.460 - ABBYY) Acrobat.com (HKLM\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.2.443 - Adobe Systems Incorporated) Acrobat.com (Version: 0.0.0 - Adobe Systems Incorporated) Hidden Adobe AIR (HKLM\...\Adobe AIR) (Version: 1.1.0.5790 - Adobe Systems Inc.) Adobe Creative Suite 4 Master Collection (HKLM\...\Adobe_b2d6abde968e6f277ddbfd501383e02) (Version: 4.0 - Adobe Systems Incorporated) Adobe Flash Player 18 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated) Adobe Media Player (HKLM\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated) Adobe Reader XI (11.0.12) - Français (HKLM\...\{AC76BA86-7AD7-1036-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated) Advertising Center (Version: 0.0.0.1 - Nero AG) Hidden Analyseur et SDK MSXML 4.0 SP2 (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) Assistant de téléchargement (HKLM\...\{92154A3C-9BB7-49D7-A571-4EB6373FA5AD}) (Version: 6.65.13 - Druide informatique inc.) Atheros Client Installation Program (HKLM\...\{D1434266-0486-4469-B338-A60082CC04E1}) (Version: 1.0.2.1119 - Atheros) Autodesk Backburner 2011.0.0 (HKLM\...\{3D347E6D-5A03-4342-B5BA-6A771885F379}) (Version: 2011.0.0 - Autodesk, Inc.) Autodesk DirectConnect 2010 R1 (HKLM\...\{702EC1FF-A081-48AE-8363-8D78A0919F86}) (Version: 4.0.418.0 - Autodesk) Autodesk MatchMover 2011 32-bit (HKLM\...\{8A864555-554E-4DE2-BB36-BC4810355525}) (Version: 13.00.0000 - Autodesk) Avira (HKLM\...\{8467e01f-0496-42ce-b247-88ef205b4880}) (Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG) Hidden Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.11.579 - Avira Operations GmbH & Co. KG) AVS Video Editor 6.5 (HKLM\...\AVS Video Editor_is1) (Version: 6.5.1.246 - Online Media Technologies Ltd.) BatteryBar (remove only) (HKLM\...\BatteryBar) (Version: - ) BatteryLifeExtender (HKLM\...\{853F8A41-A3C9-43FA-87FA-1AE74FC6F3F7}) (Version: 1.0.1 - Samsung) Blender (HKLM\...\Blender) (Version: 2.73a - Blender Foundation) Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 5.60.48.44 - Broadcom Corporation) Camtasia Studio 7 (HKLM\...\{DE042823-C359-4B87-B66B-308057E8B6AF}) (Version: 7.0.1 - TechSmith Corporation) CCleaner (HKLM\...\CCleaner) (Version: 5.04 - Piriform) ChargeableUSB (HKLM\...\{92D50865-FC60-4EA8-BA7A-5581B0D13EFB}) (Version: 1.0.0.0 - SAMSUNG) Composite 2011 (HKLM\...\{6406E3EA-9777-45B7-A0C0-89741E629352}) (Version: 6.0.0 - Autodesk) Connect (Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden Contents (Version: 1.6.1.109 - Corel Corporation) Hidden Corel PaintShop Photo Pro X3 (HKLM\...\_{D1AEB5DB-04FA-489D-94EF-8600898B93EE}) (Version: 1.6.1.109 - Corel Corporation) Corel PaintShop Photo Pro X3 (Version: 1.00.0000 - Corel Corporation) Hidden CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version: 3.0 - Acro Software Inc.) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden DeviceIO (Version: 1.6.1.109 - Corel Corporation) Hidden Dictionnaire Freelang (liste de mots) (HKLM\...\{14B380D6-8205-4F9D-81D8-515235929F2A}_is1) (Version: - Freelang) Dictionnaire Freelang 3.74 beta (HKLM\...\{F53C4192-71DE-4B21-BE03-D6F8CBB5A238}_is1) (Version: - Freelang) DolbyFiles (Version: 0.1 - Nero AG) Hidden Dropbox (HKU\S-1-5-21-2474900282-185326158-1464080906-1000\...\Dropbox) (Version: 2.6.7 - Dropbox, Inc.) Easy Display Manager (HKLM\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.1 - Samsung Electronics Co., Ltd.) Easy SpeedUp Manager (HKLM\...\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 2.1.0.10 - Samsung Electronics Co.,Ltd.) EasyBatteryManager (HKLM\...\{607DA1C8-34EC-4D7A-AD83-F8E5C70736DF}) (Version: 4.0.0.4 - Samsung) EasyRecovery Professional (HKLM\...\InstallShield_{268723B7-A994-4286-9F85-B974D5CAFC7B}) (Version: 6.04.08 - Ontrack Data Recovery, Inc.) EasyRecovery Professional (Version: 6.04.08 - Ontrack Data Recovery, Inc.) Hidden EfficientPIM Free 3.81 (HKLM\...\EfficientPIM Free_is1) (Version: - Efficient Software) e-verbe version 1.11 (HKLM\...\e-verbe_is1) (Version: - ) Fast Booting SW (HKLM\...\{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}) (Version: 1.6.0.0 - SAMSUNG) File Restore Professional 3.1 (HKLM\...\{9D79188E-8FDF-4187-BE92-418DB5EB656C}_is1) (Version: - PC Recovery Ltd) Folder Colorizer version 1.2.0 (HKLM\...\{A133E9CD-2879-4F30-87D4-1604AFD5C5CC}_is1) (Version: 1.2.0 - Softorino) Free PDF Unlocker (HKLM\...\Free PDF Unlocker_is1) (Version: - Free PDF Unlocker) Free Video Converter V 3.2 (HKLM\...\Free Video Converter_is1) (Version: 3.2.0.0 - Koyote Soft) Freemake Video Converter version 4.0.4 (HKLM\...\Freemake Video Converter_is1) (Version: 4.0.4 - Ellora Assets Corporation) Galerie de photos Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Garmin BaseCamp (HKLM\...\{31A67F6C-D79D-47B9-9F0B-13C0FCF3C3A8}) (Version: 4.4.6 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM\...\{ABA5E381-EC46-425C-86C5-5CD15BBFB4BF}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries) Gestionnaire de Connexion SFR 3.2 (HKLM\...\{FC48747D-095F-4CF6-B54E-37D4F4738A15}_is1) (Version: 3.2.64.1707 - SFR) Google Chrome (HKLM\...\Google Chrome) (Version: 43.0.2357.134 - Google Inc.) Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden ICA (Version: 1.6.1.109 - Corel Corporation) Hidden ImagXpress (Version: 7.0.74.0 - Nero AG) Hidden InCD Help (Version: 6.4.0.0 - Nero AG) Hidden Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.14.10.2230 - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) IPM_PSP_Pro (Version: 1.00.0000 - Corel Corporation) Hidden Java 8 Update 40 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation) JavaFX 2.1.0 (HKLM\...\{1111706F-666A-4037-7777-210328764D10}) (Version: 2.1.0 - Oracle Corporation) Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden kuler (Version: 2.0 - Adobe Systems Incorporated) Hidden Light Image Resizer 4.3.2.2 (HKLM\...\{EBE030DD-D404-4D92-85E9-8C3624820808}_is1) (Version: 4.3.2.2 - ObviousIdea) Marvell Miniport Driver (HKLM\...\Marvell Miniport Driver) (Version: 11.22.3.3 - Marvell) MediaInfo 0.7.67 (HKLM\...\MediaInfo) (Version: 0.7.67 - MediaArea.net) Mes tables (HKU\S-1-5-21-2474900282-185326158-1464080906-1000\...\021a9351b65e92e8) (Version: 1.3.9.0 - SC@LPA PRODUCTION) Micro Application - 38 Dictionnaires et Recueils de Correspondance (HKLM\...\{B410328C-0E8C-4DD2-9DB4-DE7766D0DFE0}) (Version: 1.0.0.0 - ) Microsoft .NET Framework 4.5.1 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2010 (HKLM\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Access database engine 2007 (French) (HKLM\...\{90120000-00D1-040C-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2007 (HKLM\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mise à jour Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-040C-0000-0000000FF1CE}_PROPLUS_{B761869A-B85C-40E2-994C-A1CE78AC8F2C}) (Version: - Microsoft) Mise à jour Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-040C-0000-0000000FF1CE}_PROPLUS_{51EFB347-1F3D-4BAC-8B79-F056B904FE21}) (Version: - Microsoft) Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-040C-0000-0000000FF1CE}_PROPLUS_{C3DCA38E-005E-41BA-A52A-7C3429F351C3}) (Version: - Microsoft) Mise à jour Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-040C-0000-0000000FF1CE}_PROPLUS_{81536A04-DBFB-4DB3-978F-0F284590C223}) (Version: - Microsoft) MLE (Version: 1.0.0.23 - Corel Corporation) Hidden Mozilla Firefox 39.0 (x86 fr) (HKLM\...\Mozilla Firefox 39.0 (x86 fr)) (Version: 39.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MP Manager (HKLM\...\{211775DE-4BBE-4296-A0F5-DF957AA9F7F6}) (Version: 1.0.4813 - MPMAN) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyDriveConnect 3.3.0.1812 (HKLM\...\MyDriveConnect) (Version: 3.3.0.1812 - TomTom) Nero 9 Essentials (HKLM\...\{94d1cd80-c7f7-45ad-8602-4a181bbc695f}) (Version: - Nero AG) NFO viewer v 2.1 (HKLM\...\NFO viewer_is1) (Version: - ) NXPowerLite (HKLM\...\{767FB3D2-9B60-439B-8092-5E1152CAA00A}) (Version: 3.7.2 - Neuxpower Solutions Ltd) Openfietsmap Lite (HKLM\...\Openfietsmap Lite) (Version: - ) PDF Password Remover v5.0 Final (PreActivated) Full (HKLM\...\PDF Password Remover v5.0 Final (PreActivated) Full) (Version: (PreActivated) Full - S.P.D.) PDF Settings CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge) PDFTK Builder 3.5.3 (HKLM\...\PDFTK Builder_is1) (Version: - ) PerfectDisk 10 Professional (HKLM\...\{7B738CD9-D107-48C7-8E65-2E6639A39C8D}) (Version: 10.0.93 - Raxco Software Inc.) Petit Larousse 2010 (HKLM\...\{422FADA9-FED2-41D7-B5FA-472BB98B7784}) (Version: - ) Photoshop Camera Raw (Version: 5.0 - Adobe Systems Incorporated) Hidden Pixel Bender Toolkit (Version: 1.0 - Adobe Systems Incorporated) Hidden Poser Pro (HKLM\...\Poser Pro_is1) (Version: - ) PSPH10Pro (Version: 1.00.0000 - Corel Corporation) Hidden PSPPContent (Version: 1.00.0000 - Corel Corporation) Hidden PSPPRO_DCRAW (Version: 13.0.0 - Corel Corporation) Hidden PureHD (Version: 1.6.1.109 - Corel Corporation) Hidden Questy 3.3 (HKLM\...\Questy) (Version: - ) QuickTime (HKLM\...\{8DC42D05-680B-41B0-8878-6C14D24602DB}) (Version: 7.55.90.70 - Apple Inc.) Rainlendar2 (remove only) (HKLM\...\Rainlendar2) (Version: - ) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6083 - Realtek Semiconductor Corp.) REALTEK PCIE Wireless LAN Software (HKLM\...\{A5C8BFF2-0044-4500-8BB5-BEB0D2335885}) (Version: 0136.10.0325 - REALTEK Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.34 - Piriform) RocketDock 1.3.5 (HKLM\...\RocketDock_is1) (Version: - Punk Software) Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.0.0.11044_11 - Samsung Electronics Co., Ltd.) Samsung Kies (Version: 2.0.0.11044_11 - Samsung Electronics Co., Ltd.) Hidden Samsung Recovery Solution 4 (HKLM\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 4.0.0.6 - Samsung) Samsung Support Center (HKLM\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.0.2 - Samsung) Samsung Update Plus (HKLM\...\{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}) (Version: 2.0 - Samsung Electronics Co., Ltd.) SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.2300.0 - SAMSUNG Electronics Co., Ltd.) Setup (Version: 1.6.1.109 - Corel Corporation) Hidden Share (Version: 1.6.1.109 - Corel Corporation) Hidden Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) Steganos Safe 11 (HKLM\...\{AC5CEC91-F421-4D5F-86EA-5D51E815B8EC}) (Version: 11.1.1 - Steganos GmbH) Suite Shared Configuration CS4 (Version: 1.0 - Adobe Systems Incorporated) Hidden Sweet Home 3D version 4.6 (HKLM\...\Sweet Home 3D_is1) (Version: - eTeks) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.10.0 - Synaptics Incorporated) Tables de multiplications Version 1.0 (HKLM\...\Tables de multiplications_is1) (Version: - Olivier RAVET) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) User Guide (HKLM\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.0 - ) Vegas Pro 11.0 (HKLM\...\{6B966A40-8DF1-11E1-931A-F04DA23A5C58}) (Version: 11.0.682 - Sony) VIO (Version: 1.6.1.109 - Corel Corporation) Hidden Visual Studio C++ 10.0 Runtime (HKLM\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) Visuel intégré (HKLM\...\{D6A48C7F-A0F8-46A5-A1ED-F45A62FE93BF}) (Version: 1.0.0003 - Druide informatique inc.) VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN) Votre PC prend la parole (HKLM\...\{1335A7E0-6055-47B8-92FC-714D65117CAA}) (Version: 1.0.0 - Nom de société par défaut) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.4500 - Broadcom Corporation) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin) Windows Live (HKLM\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live FolderShare (HKLM\...\{76810709-A7D3-468D-9167-A1780C1E766C}) (Version: 14.0.8117.416 - Microsoft Corporation) Windows Media Encoder 9 Series (HKLM\...\Windows Media Encoder 9) (Version: - ) Windows Movie Maker 2.6 (HKLM\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation) Windows Process Security 2.1 (HKLM\...\WindowsProcessSecurity) (Version: 2.1 - WindowsProcessSecurity Software Inc) WinPcap 4.1.2 (HKLM\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinRAR 4.01 (32-bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) XMind 2013 (v3.4.0) (HKLM\...\XMind_is1) (Version: 3.4.0.201311050558 - XMind Ltd.) XnView 1.99.5 (HKLM\...\XnView_is1) (Version: 1.99.5 - Gougelet Pierre-e) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2474900282-185326158-1464080906-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\romain\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2474900282-185326158-1464080906-1000_Classes\CLSID\{2A235D7E-0358-40E2-B51A-DE22F8F5C50D}\InprocServer32 -> C:\windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2474900282-185326158-1464080906-1000_Classes\CLSID\{34DC7834-8FAC-DA69-366B-9164FA4402BF}\InprocServer32 -> C:\windows\system32\ole32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2474900282-185326158-1464080906-1000_Classes\CLSID\{672CDBDB-0270-4EB9-83EC-216377522D21}\InprocServer32 -> C:\windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2474900282-185326158-1464080906-1000_Classes\CLSID\{869C14C8-1830-491F-B575-5F9AB40D2B42}\InprocServer32 -> C:\Program Files\MediaInfo\MediaInfo_InfoTip.dll (http://MediaArea.net/MediaInfo) CustomCLSID: HKU\S-1-5-21-2474900282-185326158-1464080906-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\romain\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2474900282-185326158-1464080906-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\romain\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2474900282-185326158-1464080906-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\romain\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2474900282-185326158-1464080906-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\romain\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2474900282-185326158-1464080906-1000_Classes\CLSID\{FEAE356E-68E9-4B88-EC20-86C2CFBBFB05}\InprocServer32 -> C:\windows\system32\ole32.dll (Microsoft Corporation) ==================== Restore Points ========================= 16-07-2015 21:09:06 Point de contrôle planifié ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {050E2861-2713-4D87-BD91-10EC908C8E71} - System32\Tasks\{55B5B087-5EED-449C-A088-66EF1D6D37B4} => pcalua.exe -a C:\Users\romain\Downloads\converter.exe -d C:\Users\romain\Downloads Task: {053B161E-DCC8-474D-A614-083F86FBBC7E} - System32\Tasks\BatteryLifeExtender => C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2009-11-19] (Samsung Electronics. Co. Ltd.) Task: {26EA33AE-D617-488F-B02D-4E222238D254} - System32\Tasks\{77A72724-C33A-47AC-92EF-C7AB17C38A95} => C:\Program Files\Skype\\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.) Task: {436040AD-1E88-48C5-BD8E-8F165EAC8435} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {610D66E6-4C75-4ACF-AA36-90AA4DEE70D6} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-03-29] (SAMSUNG Electronics co., LTD.) Task: {6CBA98B9-13F5-4B05-9F45-6957B0A6C76B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-23] (Google Inc.) Task: {90D2E624-7936-4F25-9D41-B9682E27A772} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-23] (Google Inc.) Task: {A24B83AA-AAE7-4599-9594-3F00589F4021} - System32\Tasks\{580D5179-6C9F-446C-A0BA-5A8D001A42B1} => pcalua.exe -a "D:\Logiciels Installés\Corel Paint Shop Photo Pro x3\setup.exe" -d "D:\Logiciels Installés\Corel Paint Shop Photo Pro x3" Task: {A43B382E-D87D-426C-8482-F5ADF5285F47} - System32\Tasks\SamsungSupportCenter => C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [2010-05-06] (SAMSUNG Electronics) Task: {C4FAC50C-20E5-46D1-BF03-EB18BE85C19F} - System32\Tasks\advSRS4 => C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC) Task: {C71C2536-D675-4677-B648-4E84B11D0E2A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd) Task: {CEC6A19F-5106-4ED5-B5E1-38F643869487} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2010-04-07] (Samsung Electronics Co., Ltd.) Task: {CF2D3008-0A2E-49CA-B6D5-6A79F666805C} - System32\Tasks\EasySpeedUpManager => C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager2.exe [2010-04-20] (Samsung Electronics) Task: {DA91662B-89B4-44F1-B746-1E4CC704DCA5} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-15] (Adobe Systems Incorporated) Task: {DB3EEBEC-1DBB-4948-8048-96CC58BACB31} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe [2010-04-20] () Task: {F84A9DCE-3B37-45E8-89C7-80B6D3871B0F} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SFB\SmartRestarter.exe [2010-05-01] (Samsung Electronics Co., Ltd.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2015-06-28 14:59 - 2013-10-23 15:23 - 00089136 _____ () C:\windows\System32\cpwmon2k.dll 2010-09-17 20:57 - 2007-09-02 13:57 - 00069632 _____ () C:\Program Files\RocketDock\RocketDock.dll 2010-09-17 20:56 - 2011-05-28 22:04 - 00140288 _____ () C:\Program Files\WinRAR\rarext.dll 2010-05-20 06:17 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll 2010-09-17 20:57 - 2007-09-02 13:58 - 00495616 _____ () C:\Program Files\RocketDock\RocketDock.exe 2015-03-13 15:54 - 2015-03-13 15:54 - 00065536 _____ () C:\Program Files\CCleaner\lang\lang-1036.dll 2015-07-15 12:17 - 2015-07-15 12:17 - 17448624 _____ () C:\windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll 2012-09-23 21:43 - 2012-09-23 21:43 - 00313992 _____ () C:\Program Files\Adobe\Reader 11.0\Reader\sqlite.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Program Files\Common Files\System:us15k7EeCTxuOLSL33GGJoB AlternateDataStreams: C:\ProgramData\Microsoft:4YTLlzkVdSwGPEAHGJ04384S AlternateDataStreams: C:\ProgramData\Microsoft:Xdfov0tBY0Vlf84lYRTG1ixUpw AlternateDataStreams: C:\Users\romain\AppData\Roaming\default.rss:OECustomProperty ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\plsapp => ""="service" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2474900282-185326158-1464080906-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\romain\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: Uvnc_service => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk => C:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\windows\pss\Bluetooth.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Hyperappel du Petit Larousse 2010.lnk => C:\windows\pss\Hyperappel du Petit Larousse 2010.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^romain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\windows\pss\Dropbox.lnk.Startup MSCONFIG\startupfolder: C:^Users^romain^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^EfficientPIM Free.lnk => C:\windows\pss\EfficientPIM Free.lnk.Startup MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: AdobeCS4ServiceManager => "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: Adobe_ID0ENQBO => C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE MSCONFIG\startupreg: AgentAntidote32 => "C:\Program Files\Druide\Antidote 8\Programmes32\AgentAntidote.exe" /LancementSession MSCONFIG\startupreg: APLangApp => "C:\Program Files\AnyPC Client\APLangApp.exe" MSCONFIG\startupreg: avgnt => "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min MSCONFIG\startupreg: Bonus.SSR.FR11 => "C:\Program Files\ABBYY FineReader 11\Bonus.ScreenshotReader.exe" /autorun MSCONFIG\startupreg: Corel File Shell Monitor => c:\Program Files\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe MSCONFIG\startupreg: Corel Photo Downloader => "c:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: HotKeysCmds => C:\windows\system32\hkcmd.exe MSCONFIG\startupreg: IgfxTray => C:\windows\system32\igfxtray.exe MSCONFIG\startupreg: KiesHelper => C:\Program Files\Samsung\Kies\KiesHelper.exe /s MSCONFIG\startupreg: KiesPDLR => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: LMDVox => C:\Program Files\Micro Application\Votre PC prend la parole\LMDVox.exe Lancement MSCONFIG\startupreg: MediaDICO38 => C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\LanceMediaDICO38.exe Lancement MSCONFIG\startupreg: msnmsgr => "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background MSCONFIG\startupreg: MyDriveConnect.exe => "C:\Program Files\MyDrive Connect\MyDriveConnect.exe" MSCONFIG\startupreg: Persistence => C:\windows\system32\igfxpers.exe MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: Rainlendar2 => C:\Program Files\Rainlendar2\Rainlendar2.exe MSCONFIG\startupreg: RocketDock => "C:\Program Files\RocketDock\RocketDock.exe" MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s MSCONFIG\startupreg: SAFE2009 File Redirection Starter => "C:\Program Files\Steganos Safe 11\fredirstarter.exe" MSCONFIG\startupreg: SAFE2009 HotKeys => "C:\Program Files\Steganos Safe 11\SteganosHotKeyService.exe" MSCONFIG\startupreg: ShowBatteryBar => "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized MSCONFIG\startupreg: SpywareTerminator => "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" MSCONFIG\startupreg: SpywareTerminatorShield => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe MSCONFIG\startupreg: SpywareTerminatorUpdater => C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe MSCONFIG\startupreg: SSS2007 HotKeys => "C:\Program Files\Steganos Security Suite 2007\SteganosHotKeyService.exe" MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SuperCopier2.exe => C:\Program Files\SuperCopier2\SuperCopier2.exe MSCONFIG\startupreg: swg => "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [TCP Query User{AEE7F6FA-500A-4D95-89DA-342E4EA35E3E}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{FE899B17-F047-4A68-A34F-E8D1E94E55C4}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [{A02F807E-F784-4480-9945-13EEE8F438FC}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{E0531B12-D155-4A07-8249-207BB18FD39D}] => (Allow) svchost.exe FirewallRules: [{B8FC27FA-0031-4A7C-ABE9-4A035E5FB763}] => (Allow) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [{3C71AE0B-D304-4B09-B125-01B488908906}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe FirewallRules: [{13618F6C-8F84-4BF9-9118-F157DC17A0C8}] => (Allow) LPort=2869 FirewallRules: [{8825832D-18CA-4819-8047-89F4B62461F8}] => (Allow) LPort=1900 FirewallRules: [TCP Query User{CAEF3B27-699F-4731-A10A-0FF3263D6B94}C:\program files\smith micro\poser pro\poserpro.exe] => (Allow) C:\program files\smith micro\poser pro\poserpro.exe FirewallRules: [UDP Query User{172D685F-65D1-402A-974E-FBACC1382CC8}C:\program files\smith micro\poser pro\poserpro.exe] => (Allow) C:\program files\smith micro\poser pro\poserpro.exe FirewallRules: [{FFD077C5-5E87-40A5-BA75-3899F459CA42}] => (Block) C:\program files\smith micro\poser pro\poserpro.exe FirewallRules: [{8309DC4B-9900-4EDF-A9FB-4F22E2D96371}] => (Block) C:\program files\smith micro\poser pro\poserpro.exe FirewallRules: [{A74EEF40-D2F9-41A1-8320-B7B993273C53}] => (Allow) C:\Windows\System32\muzapp.exe FirewallRules: [{830A3C17-2317-4FF7-9F92-CA27CB43CF9A}] => (Allow) C:\Windows\System32\muzapp.exe FirewallRules: [{926C5ACF-1B09-441C-BFDA-9017B75143C4}] => (Allow) C:\Program Files\Autodesk\Backburner\monitor.exe FirewallRules: [{C6DA4FAA-B8B6-4942-BF3E-34ECDD0B39C0}] => (Allow) C:\Program Files\Autodesk\Backburner\monitor.exe FirewallRules: [{0D28B473-B25B-4B01-B690-DCD10F4406ED}] => (Allow) C:\Program Files\Autodesk\Backburner\manager.exe FirewallRules: [{BA90CEB8-CF0C-412C-AAE1-09466730E1EE}] => (Allow) C:\Program Files\Autodesk\Backburner\manager.exe FirewallRules: [{F62BA608-0AFD-4B62-A376-DBF4B5977A4D}] => (Allow) C:\Program Files\Autodesk\Backburner\server.exe FirewallRules: [{6C099E26-C523-4ED9-BC72-E08F7D6E88C0}] => (Allow) C:\Program Files\Autodesk\Backburner\server.exe FirewallRules: [{24C4F12B-C66D-4526-99DB-DBD68D40397B}] => (Allow) LPort=5353 FirewallRules: [{535B1206-6196-47FB-9025-4B48324A2277}] => (Allow) C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe FirewallRules: [{923A0BC8-36CE-4055-AB1F-2C834D42878E}] => (Allow) C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe FirewallRules: [{99EB8C2A-A68C-4656-BA5C-7776032B8E05}] => (Allow) LPort=3703 FirewallRules: [{23EDBAEC-0AE8-4744-9BB0-73239D1D74DB}] => (Allow) LPort=3704 FirewallRules: [{8305A2F7-C2F0-4F0B-9E64-FE73EB764DED}] => (Allow) LPort=51000 FirewallRules: [{164CF2FA-8932-4F05-8321-B56C4EF32094}] => (Allow) LPort=51001 FirewallRules: [{D94D84FA-54C2-4B11-B3AD-D24CB08AC506}] => (Allow) C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe FirewallRules: [{A03132D9-1F2E-42FA-9F91-A539ABE03154}] => (Allow) C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe FirewallRules: [{85B422BE-CDD6-4920-B9F5-584C37012AB3}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [{6E5891A7-736E-4C1F-B4C4-6CBB6A1D554D}] => (Allow) C:\Program Files\PANDORA.TV\PanService\PandoraService.exe FirewallRules: [{3E7A5D89-0A83-491C-9317-780690375F88}] => (Allow) C:\Program Files\PANDORA.TV\PanService\PandoraService.exe FirewallRules: [{4FB0F68A-057E-4C81-A536-E5AC9602D128}] => (Allow) D:\Logiciels Installés\utorrent.exe FirewallRules: [{C46A8EFC-C4A8-443E-B4BB-16AA21C17F6D}] => (Allow) D:\Logiciels Installés\utorrent.exe FirewallRules: [{C656CEFA-8C15-4B0E-B483-FA471AE9C574}] => (Allow) C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{CFE1DC9F-8978-4530-97D8-DC0EB3078263}] => (Allow) C:\Users\romain\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{322688B2-FF32-4309-A613-91709CCEADBA}] => (Allow) C:\Users\romain\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{738DC6F9-D99E-4E12-844C-4D324205D4A2}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{D6D3AE27-5CFB-4E0F-B6BF-E1EB3C4CC86E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{88D9EDE0-4E67-474F-A587-96E2400A8BE7}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{D33A0139-679C-4FD0-89A0-8675F2D134A0}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [{7E620453-E2EF-445C-9A13-77CD51ABF0CC}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/15/2015 07:47:06 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Le programme EXCEL.EXE version 12.0.6718.5000 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance. ID de processus : 11dc Heure de début : 01d0bec15ea54681 Heure de fin : 94 Chemin d’accès de l’application : C:\Program Files\Microsoft Office\Office12\EXCEL.EXE ID de rapport : c39ae748-2ab4-11e5-8bee-e839df1d25b6 Error: (07/13/2015 06:11:54 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: La création du contexte d’activation a échoué pour « assemblyIdentity1 ». Erreur dans le fichier de manifeste ou de stratégie « assemblyIdentity2 » à la ligne assemblyIdentity3. La valeur « MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR » de l’attribut « version » de l’élément « assemblyIdentity » n’est pas valide. Error: (07/13/2015 06:11:28 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: La création du contexte d’activation a échoué pour « Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1 ». Assembly dépendant Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé. Error: (07/13/2015 06:07:04 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: La création du contexte d’activation a échoué pour « Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1 ». Assembly dépendant Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé. Error: (07/13/2015 06:04:31 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: La création du contexte d’activation a échoué pour « assemblyIdentity1 ». Erreur dans le fichier de manifeste ou de stratégie « assemblyIdentity2 » à la ligne assemblyIdentity3. La valeur « MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR » de l’attribut « version » de l’élément « assemblyIdentity » n’est pas valide. Error: (07/13/2015 06:01:34 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: La création du contexte d’activation a échoué pour « Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1 ». Assembly dépendant Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé. Error: (07/13/2015 06:01:33 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: La création du contexte d’activation a échoué pour « Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1 ». Assembly dépendant Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé. Error: (07/13/2015 05:59:58 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: La création du contexte d’activation a échoué pour « Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1 ». Assembly dépendant Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé. Error: (07/13/2015 05:58:58 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: La création du contexte d’activation a échoué pour « Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1 ». Assembly dépendant Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé. Error: (07/13/2015 05:58:58 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: La création du contexte d’activation a échoué pour « Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1 ». Assembly dépendant Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé. System errors: ============= Error: (07/16/2015 10:45:44 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (07/15/2015 10:43:56 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (07/15/2015 09:28:48 PM) (Source: volsnap) (EventID: 36) (User: ) Description: Les clichés instantanés du volume C: ont été annulés car le stockage du cliché instantané n’a pas pu s’agrandir en raison d’une limite utilisateur. Error: (07/15/2015 05:31:20 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Le service Windows Search est en attente de démarrage. Error: (07/15/2015 05:23:04 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Le service Service de transfert intelligent en arrière-plan s’est arrêté avec l’erreur service particulière %%-2147023781. Error: (07/15/2015 05:23:04 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16392) (User: AUTORITE NT) Description: Échec du démarrage du service BITS. Erreur 2147943515. Error: (07/15/2015 05:22:55 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1000) (User: AUTORITE NT) Description: L’initialisation du client CBS a échoué. Dernière erreur : 0x8007045b Error: (07/15/2015 01:13:22 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (07/14/2015 09:56:08 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (07/14/2015 11:48:46 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Microsoft Office: ========================= Error: (04/29/2015 07:57:33 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6718.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5 seconds with 0 seconds of active time. This session ended with a crash. Error: (11/11/2014 07:44:29 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 29 seconds with 0 seconds of active time. This session ended with a crash. Error: (11/11/2014 07:43:05 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 79 seconds with 60 seconds of active time. This session ended with a crash. Error: (04/06/2013 08:31:48 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 8774 seconds with 660 seconds of active time. This session ended with a crash. Error: (03/31/2013 10:29:25 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 236 seconds with 120 seconds of active time. This session ended with a crash. Error: (02/14/2013 01:01:08 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 11500 seconds with 1200 seconds of active time. This session ended with a crash. Error: (02/07/2013 09:10:05 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 913 seconds with 840 seconds of active time. This session ended with a crash. Error: (12/08/2012 09:48:37 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 11857 seconds with 2400 seconds of active time. This session ended with a crash. Error: (11/14/2012 11:01:41 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 11106 seconds with 5580 seconds of active time. This session ended with a crash. Error: (10/23/2012 05:11:25 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 5184 seconds with 3120 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Processor: Intel(R) Atom(TM) CPU N450 @ 1.66GHz Percentage of memory in use: 64% Total physical RAM: 2037.3 MB Available physical RAM: 727 MB Total Virtual: 4074.59 MB Available Virtual: 2151.4 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:112 GB) (Free:9.07 GB) NTFS Drive d: () (Fixed) (Total:165.99 GB) (Free:27.54 GB) NTFS Drive e: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive g: (RECOVERY) (Fixed) (Total:20 GB) (Free:6.66 GB) NTFS ==>[system with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 298.1 GB) (Disk ID: FFB87A66) Partition 1: (Not Active) - (Size=20 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=112 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=166 GB) - (Type=OF Extended) ==================== End of log ============================