OTL Extras logfile created on: 22/09/2015 15:57:05 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\stephan\Downloads\Programs 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17843) Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy 3,99 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 50,22% Memory free 7,98 Gb Paging File | 5,68 Gb Available in Paging File | 71,16% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 195,31 Gb Total Space | 11,56 Gb Free Space | 5,92% Space Free | Partition Type: NTFS Drive D: | 931,51 Gb Total Space | 32,37 Gb Free Space | 3,48% Space Free | Partition Type: NTFS Drive E: | 736,10 Gb Total Space | 8,87 Gb Free Space | 1,20% Space Free | Partition Type: NTFS Drive F: | 1671,93 Gb Total Space | 4,46 Gb Free Space | 0,27% Space Free | Partition Type: NTFS Drive H: | 191,08 Gb Total Space | 4,81 Gb Free Space | 2,51% Space Free | Partition Type: NTFS Computer Name: STEPHAN-PC | User Name: stephan | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (All) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation) .hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation) .txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .bat [@ = batfile] -- "%1" %* .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cmd [@ = cmdfile] -- "%1" %* .com [@ = comfile] -- "%1" %* .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .exe [@ = exefile] -- "%1" %* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .pif [@ = piffile] -- "%1" %* .reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation) .scr [@ = scrfile] -- "%1" /S .txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-300713147-3753241163-474006113-1001\SOFTWARE\Classes\] .html [@ = ChromiumHTM.TULTN4GP226F4YUWJNYVKPII5E] -- C:\Users\stephan\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [ACDBrowse] -- "C:\Program Files (x86)\ACD Systems\ACDSee\8.0.Pro\ACDSee8Pro.exe" "%1" (ACD Systems Ltd.) Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Parcourir avec Corel PaintShop Pro X4] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\Corel PaintShop Pro.exe" "%L" (Corel, Inc.) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [ACDBrowse] -- "C:\Program Files (x86)\ACD Systems\ACDSee\8.0.Pro\ACDSee8Pro.exe" "%1" (ACD Systems Ltd.) Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Parcourir avec Corel PaintShop Pro X4] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\Corel PaintShop Pro.exe" "%L" (Corel, Inc.) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Windows\SysWOW64\svchost.exe" = C:\Windows\SysWOW64\svchost.exe:*:Enabled:Windows Messanger -- (Microsoft Corporation) "C:\Windows\SysWOW64\svchost.exe" = C:\Windows\SysWOW64\svchost.exe:*:Enabled:Windows Messanger -- (Microsoft Corporation) [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{36F25A84-3BD7-4DFD-A0F3-EC2BC12A1839}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{6135CADA-9D70-481C-8617-2D7CEFF452C8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{6B0116A1-5C8B-4D1E-ABF9-A16866A275F1}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | "{8752531A-D360-49E3-AAB5-A3851029AB5E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8F3CF119-9215-45F2-B569-C68FC734448E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{90815B9A-7E67-4E51-B8EF-E374C61BEC1B}" = lport=10243 | protocol=6 | dir=in | app=system | "{A25A938E-C826-4590-BB5F-7E217DE8084D}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{AA58D1E6-E80A-4317-A7A7-861C7B39BE9E}" = rport=10243 | protocol=6 | dir=out | app=system | "{D2ED97B9-7BCB-4072-9DBF-EF46D76DAFC0}" = lport=2869 | protocol=6 | dir=in | app=system | "{D36A3AF6-C88D-4050-9989-D5750EF51E68}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{D982E011-4312-4734-A952-A3F783839F28}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{EC5443C1-764B-43B2-B7B6-4C45155B61EA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{057E92A1-DA2E-4230-8504-E85F825B3860}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | "{1A9DF849-19BD-4DE9-92E1-74E49AB5F30D}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{232A7225-FD31-49B6-B331-F2320A3A34F9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{2906073C-51FF-48AF-80E3-1993AE535628}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{2BBC83FB-97D3-4FB7-B546-D64CE6D5F8B9}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{2D935844-B6DA-4FF9-9B9B-FBDC2EF7839C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{2EDD1107-DAD3-4914-B072-37E2BF95FCAA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{2F9B07A3-2280-4C7B-9A6E-257DDE34F290}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{3743C355-ED38-4F46-ADAF-54CE62607981}" = dir=out | app=c:\program files (x86)\apowersoft\streaming video recorder\streaming video recorder.exe | "{37C22C85-DEEC-4C83-91B3-A898E2A61C9F}" = dir=in | app=c:\program files (x86)\apowersoft\streaming video recorder\streaming video recorder.exe | "{381E04BA-2636-40E5-A9D7-A1BCE6287B29}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{3B3AB986-88F3-49C7-B760-0B6C9F0D15E7}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | "{42E6889C-7E0A-4BDC-97DA-08B49FA5AC44}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\apowersoftdump.dll | "{452F18B7-9DCF-488F-8242-68C3614DA8E2}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\apowersofthdsdump.dll | "{51A6F4CC-8B14-42F4-B991-1357DB0722D5}" = dir=in | app=c:\program files (x86)\apowersoft\streaming video recorder\apowersoftdump.dll | "{53A5A254-9D38-4EDF-9960-C897CD872578}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{5B856FC2-8692-4D6D-9A5D-008AF060A981}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{6245A162-E014-4A4D-BE8F-5509CBEDB0A3}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe | "{66350295-730E-4763-89AA-664E407142D5}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | "{67BF710C-00F6-4D77-8750-987ABBD2E6AD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{680923BE-7E8A-489C-A61A-5237EC3054E3}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{69F05596-4044-4822-B1C0-57337A4EAE39}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\apowersoftplayer.dll | "{6A4B4B20-6BD1-4AB6-A903-06E94447B85A}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | "{6D5EA1F2-70DC-468A-B3DD-7E9357EDC21C}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsvsvr.exe | "{6DD0B0CF-CF2A-40DD-BD5C-9C74D9842A05}" = dir=in | app=c:\program files (x86)\apowersoft\streaming video recorder\apowersoftdownloaderhelp.dll | "{74F7D29B-FB4C-4BE0-8ED0-60E6FD6CFB47}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{754E6EEF-36EB-449A-BCAB-75F2AFB957A8}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsasvr.exe | "{79539810-7D3A-4FAE-9467-BBF4BDE137A2}" = protocol=6 | dir=in | app=c:\users\stephan\appdata\roaming\utorrent\utorrent.exe | "{871AFBF7-98AC-4DEC-8321-BE0064B19768}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | "{916EAFC2-0F19-425F-9A6E-2DF139B167F3}" = dir=out | app=c:\program files (x86)\apowersoft\streaming video recorder\apowersoftdump.dll | "{9336A8EB-CD48-4E0A-A312-CDE0B9789FA3}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\apowersoftdownloaderhelp.dll | "{963CD5F1-9878-46DB-930B-68BA331CE966}" = dir=out | app=c:\program files (x86)\apowersoft\streaming video recorder\apowersoftdownloaderhelp.dll | "{9A1A4DD4-7651-4408-8E46-BFD1383F9CE7}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\apowersoftac.dll | "{9AEE57BB-9D8B-4EA0-B51B-EAC10C349F31}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\apowersoftsrv.dll | "{9EF84253-5A68-4090-82A1-F821A4C29FF8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{A8DE8D5F-C498-4A93-8B18-A877DBD4535C}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\apowersofthdsdump.dll | "{AC35A8C8-0FF9-4E36-9FB4-2B24818AB29E}" = protocol=17 | dir=in | app=c:\users\stephan\appdata\roaming\utorrent\utorrent.exe | "{B431BB4A-9A34-4227-8E1B-2C6F15B53237}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\apowersoftdownloaderhelp.dll | "{B5BFBDDE-A345-4EED-8B1A-20ADA2564DD5}" = protocol=6 | dir=out | app=system | "{B66F2BC6-385D-4717-9B30-969DB0C62DCC}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\apowersoftsrv.dll | "{BAAB7E3D-7D81-4C8B-8FD7-576211FFA590}" = dir=out | app=c:\program files (x86)\apowersoft\streaming video recorder\apowersoftplayer.dll | "{BDC56959-BDAF-42A6-9AFF-EDE2085AD4AA}" = dir=out | app=c:\program files (x86)\apowersoft\streaming video recorder\apowersoftac.dll | "{C1701362-37E2-42D1-8F7C-FEC627716D63}" = dir=in | app=c:\program files (x86)\apowersoft\streaming video recorder\apowersoftsrv.dll | "{C4B2BB4C-34E2-406E-9565-4A179D9E9864}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe | "{CD6FCAD9-BBE2-4A78-AA67-FE836CC68A03}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\apowersoftac.dll | "{CEFD3004-09E3-4A34-8549-B3FC6A0E9036}" = dir=in | app=c:\program files (x86)\apowersoft\streaming video recorder\apowersoftac.dll | "{D39B07CD-B157-4FA4-AB1D-A34C665021F3}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | {D4247DCB-EE81-4784-9E5F-67B885D0E8C4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D7E6BD6C-7F7A-429C-85A1-88680FF8761D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{DFA4D68B-85C8-4A52-BBA7-8CF949EA4C98}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{E046473A-2D36-4A7E-9F35-E52F7F532256}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\apowersoftdump.dll | "{E77054B2-9A18-4EB9-9815-109486BAD5C6}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\video download capture.exe | "{E777EECB-E454-4339-981F-297B454A54AC}" = dir=out | app=c:\program files (x86)\apowersoft\video download capture\apowersoftplayer.dll | "{E7ADD886-8A57-4B26-9FBC-2D3FF19072F0}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | "{EB392F22-BB77-4B8D-B4ED-65E66B3B8A16}" = dir=in | app=c:\program files (x86)\apowersoft\video download capture\video download capture.exe | "{EBF2DA4C-0C16-46E3-B6ED-D7BACC984696}" = dir=in | app=c:\program files (x86)\apowersoft\streaming video recorder\apowersoftplayer.dll | "{EDB07ED5-BE98-4231-BF27-F9F16C641220}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{F4B125A8-7AC7-443E-AA0B-19E0295EC8DD}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsasvr.exe | "{F714AA47-AA3F-45ED-ACE0-5BDB6F9D7105}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{F82D74BE-5677-4DDE-87C6-2DBBD187DE44}" = dir=out | app=c:\program files (x86)\apowersoft\streaming video recorder\apowersoftsrv.dll | "{F8EA8585-3A29-448C-AE7D-1FA5E348744B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{F8FC4C1A-B065-4516-B2C6-94D00922AED0}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\samsung new pc studio\npsvsvr.exe | "TCP Query User{30ED34A7-D991-474D-8F0E-10216813F14B}C:\use "TCP Query User{CFA93732-775D-4453-814B-075543E1166C}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=6 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe | "UDP Query User{B6E325B1-F13A-49E6-9004-4AEADFECDA3C}C:\users\stephan\desktop\mratio4.5\mratio.exe" = protocol=17 | dir=in "UDP Query User{FAB42DC2-FD5B-42FB-BBC1-750B635D8B90}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=17 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0015DE8E-8D9F-403E-8E5A-4098410E6125}" = PSPPro64 "{143CC532-8A89-4D56-8F91-F1AFF6244FE3}" = x64crt "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 "{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{770EA7C3-0B5A-C557-E641-A09244603B84}" = AMD Catalyst Install Manager "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0015-040C-1000-0000000FF1CE}" = Microsoft Office Access MUI (French) 2010 "{90140000-0016-040C-1000-0000000FF1CE}" = Microsoft Office Excel MUI (French) 2010 "{90140000-0018-040C-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (French) 2010 "{90140000-0019-040C-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (French) 2010 "{90140000-001A-040C-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (French) 2010 "{90140000-001B-040C-1000-0000000FF1CE}" = Microsoft Office Word MUI (French) 2010 "{90140000-001F-0401-1000-0000000FF1CE}" = Microsoft Office Proof (Arabic) 2010 "{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-0413-1000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2010 "{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 "{90140000-002C-040C-1000-0000000FF1CE}" = Microsoft Office Proofing (French) 2010 "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010 "{90140000-0043-040C-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (French) 2010 "{90140000-0044-040C-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (French) 2010 "{90140000-006E-040C-1000-0000000FF1CE}" = Microsoft Office Shared MUI (French) 2010 "{90140000-00A1-040C-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (French) 2010 "{90140000-00BA-040C-1000-0000000FF1CE}" = Microsoft Office Groove MUI (French) 2010 "{901D1D88-408D-48E5-80DD-CC3145BD8456}" = COMODO Firewall "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036" = Microsoft .NET Framework 4.5.1 (Français) "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{95140000-0081-040C-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64 bits "{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{BFAE8D5B-F918-486F-B74E-90762DF11C5C}" = Microsoft Security Client "{C21E3979-74A1-B58C-7D22-36E82B86E785}" = AMD Wireless Display v3.0 "{C22759DB-BA8B-30E7-99EE-8B47DB43AE56}" = Microsoft .NET Framework 4.5.1 (FRA) "{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{F43B8BED-811A-6556-D548-0F3B1DDD78E3}" = AMD Drag and Drop Transcoding "CCleaner" = CCleaner "CyberGhost 5_is1" = CyberGhost 5 "Heredis 2015_is1" = Heredis 2015 "MediaInfo" = MediaInfo 0.7.64 "Microsoft Security Client" = Microsoft Security Essentials "Office14.PROPLUS" = Microsoft Office Professionnel Plus 2010 "PDF Creator" = PDF Creator "SecurityKISS Tunnel_is1" = SecurityKISS Tunnel v0.3.0 "sp6" = Logitech SetPoint 6.52 "TAP-Windows" = TAP-Windows 9.9.2 "VLC media player" = VLC media player 2.0.6 "WinRAR archiver" = WinRAR 4.11 (64-bit) "XnViewMP_is1" = XnViewMP 0.72 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "_{00580795-581C-4587-B9F2-37320D7AB37F}" = Corel PaintShop Pro X4 "{00580795-581C-4587-B9F2-37320D7AB37F}" = ICA "{006CAAEF-CA96-4181-AC22-FE56D61432E4}" = PSPPContent "{00AE1A2D-7BC2-4359-A0EC-E19F36E391BB}" = Corel PaintShop Pro X4 "{00BEE329-BAAB-49FF-9B66-55E4B12B9ADD}" = IPM_PSP_COM "{00D13418-7DDF-4D3D-A237-E297B103BB6B}" = Setup "{00D74A7A-F7AD-4D00-ABD2-0973836292C7}" = PSPPHelp "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{05366B44-A2DD-436C-AD1B-532156CCC619}_is1" = MiniTool Partition Wizard Professional Edition 5.2 "{078A8C00-412A-45C2-8A44-49DD736D3318}_is1" = Objectif Tarot 4 "{0F7CBF80-96FF-D59E-6CB5-93A35D40D1A1}" = CCC Help Italian "{11087D24-567D-7D88-69C6-D7A08B5F4C47}" = Catalyst Control Center - Branding "{128A4748-2438-CCE2-7A2D-EBCB6CAD4145}" = Catalyst Control Center Graphics Previews Common "{133742BA-6F46-4D3E-85AF-78631D9AD8B8}" = Installation Windows Live "{14A487F2-1259-4E6C-AE3C-3C888DDBCB60}_is1" = Guitar Pro 6 "{14E51EE2-64B1-E950-9042-5B0542ED4DEF}" = CCC Help Dutch "{19208C1C-9ED3-6E67-1CAF-17D6977B5B32}" = CCC Help Greek "{198B31C8-0670-4479-8044-E0CBDDC5C2CF}_is1" = F1 2013 update 6 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Outil de téléchargement Windows Live "{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform "{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{231ABC1A-D27E-3642-9EC4-073A11B63D8B}" = CCC Help Danish "{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 7.0 "{254E1A18-D912-992A-9996-9A1CB95AD4C2}" = CCC Help Spanish "{26A24AE4-039D-4CA4-87B4-2F03217067FF}" = Java 7 Update 67 "{2CD65167-671F-49A3-B6C7-3B919DF028E2}_is1" = Streaming Video Recorder V4.5.2 "{2F3EBEAE-E981-0F2F-E3DF-51652B49F81D}" = Catalyst Control Center Localization All "{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver "{3C9D008D-3716-4C3F-90CD-38ED57568FAB}_is1" = Video Download Capture version 4.9.3 "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg "{445B183D-F4F1-45C8-B9DB-F11355CA657B}" = Windows Live Messenger "{4840B728-D26C-85D9-1A56-5FD51D703404}" = CCC Help Swedish "{491D92A9-69CA-4EB4-81D3-0106F9337957}" = TurboV EVO "{49F56830-C5F7-1FC5-DB84-C7EBA5A939E5}" = CCC Help Portuguese "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CBF3C32-BB4B-465D-3888-5C30F102615C}" = CCC Help Chinese Standard "{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}" = Google Earth "{4ED40090-5A38-415F-B222-26DD6D3C1AEF}" = calibre "{50CBA9D7-4A12-44CA-8E75-9FD7374FBD12}" = x86crt "{55B85A06-5293-9262-F492-6F38656FBA49}" = CCC Help Hungarian "{56B83336-FBC1-4C46-8613-90A9E3B440D6}" = EPU-6 Engine "{5BBFE8AA-18F2-A41E-F6F3-4F035E4FFEC1}" = CCC Help Czech "{5DD76286-9BE7-4894-A990-E905E91AC818}" = Windows Live Mail "{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper "{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7 "{6DE20125-6C25-46DD-8743-9C731E25ABA5}" = ACDSee Pro "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = Analyseur et SDK MSXML 4.0 SP2 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{79BBB47F-F148-4A81-3761-5296D091CBC9}" = CCC Help Chinese Traditional "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{85CEACAF-A84C-933B-AC01-8B0881B70A24}" = CCC Help Thai "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver "{88ACE193-FA96-C954-4BC5-11A2094C9B44}" = CCC Help Finnish "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update "{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A0D82FA4-A1CB-2FA4-9B7E-1B1175A3305D}" = CCC Help Russian "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A8F9370F-3847-617C-84DC-C9597F51BFE8}" = AMD Catalyst Control Center "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1036-7B44-A93000000001}" = Adobe Reader 9.3 - Français "{B3B487E7-6171-4376-9074-B28082CEB504}" = Windows Live Call "{B96D2269-568B-4CBF-9332-12FAE8B158F7}" = Medieval CUE Splitter "{BB5D8339-5A8D-BE2F-A250-5F96DFFE18A6}" = CCC Help English "{BBC57E85-BD83-BB98-78D7-E1A4AF7C4D1A}" = CCC Help German "{C4D27B44-5423-46C9-991A-A12D29475800}_is1" = PaintShop Pro version X4 "{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 "{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.11 Game "{D93AB0C2-4CA3-BF26-2C4D-F1D07164157F}" = CCC Help Polish "{D961304C-0ABB-F70B-02ED-1DB9D9B48FCC}" = CCC Help Norwegian "{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}" = Assistant de connexion Windows Live "{EE370BAD-5C4D-1BC6-E700-AB037DE9D56C}" = CCC Help Japanese "{F03BA3F0-9DF3-D250-160B-29E1EF2A1D12}" = CCC Help Turkish "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0C62866-D7C3-42EA-9BDB-F3E44B98BF40}_is1" = The Elder Scrolls V - Skyrim "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio "{F915BA35-D0BE-55B4-CC1A-E199619089FC}" = CCC Help French "{FA255A2B-F1B2-B28E-7533-920B2412B2E7}" = CCC Help Korean "{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 "Adobe Flash Player ActiveX" = Adobe Flash Player 18 ActiveX "Adobe Flash Player NPAPI" = Adobe Flash Player 18 NPAPI "Adobe Flash Player PPAPI" = Adobe Flash Player 18 PPAPI "Advanced SystemCare 8_is1" = Advanced SystemCare 8 "AIDA64 Extreme Edition_is1" = AIDA64 Extreme Edition v2.30 "aTube Catcher" = aTube Catcher "AVS4YOU Video Converter 7_is1" = AVS Video Converter 8 "Comodo Dragon" = Comodo Dragon "CrystalDiskInfo_is1" = CrystalDiskInfo 5.4.2 Shizuku Edition "CuteDJ_is1" = CuteDJ 4.2.8.0 "Desksoft EarthView 4.3.6" = Desksoft EarthView 4.3.6 "DFX" = DFX "Dxtory2.0_is1" = Dxtory version 2.0.127 "EarthView" = EarthView "Easy CD-DA Extractor 2010" = Easy CD-DA Extractor 2010 "Free AVI Video Converter_is1" = Free AVI Video Converter version 5.0.25.610 "Free Video Dub_is1" = Free Video Dub version 2.0.21.827 "Google Chrome" = Google Chrome "InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Gestionnaire de périphériques de plate-forme "InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio "Internet Download Manager" = Internet Download Manager "IObit Surfing Protection_is1" = Surfing Protection "J'apprends la guitare 1_is1" = J'apprends la guitare 1.0 "LHTTSFRF" = L&H TTS3000 Français "LHTTSGED" = L&H TTS3000 Deutsch "LHTTSRUR" = L&H TTS3000 Russian "LHTTSSPE" = L&H TTS3000 Español "MagicDisc 2.7.106" = MagicDisc 2.7.106 "Revo Uninstaller" = Revo Uninstaller 1.95 "Rockstar Games Social Club" = Rockstar Games Social Club "scrabbleproB_is1" = scrabbleproB 1.1.3 "SFR_Kit" = SFR - Kit de connexion "SolveigMM Video Splitter 3.6.1308.22" = SolveigMM Video Splitter "SpeedFan" = SpeedFan (remove only) "SuperCopier2" = SuperCopier2 "TextAloud3_is1" = TextAloud 3.0 "Visual Studio Tools for the Office system 3.0 Runtime" = Runtime de Visual Studio Tools pour Office 3.0 "Winamp" = Winamp "WinLiveSuite_Wave3" = Installation Windows Live "ZHPFix_is1" = ZHPFix 2015 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-300713147-3753241163-474006113-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Chromium" = Chromium "uTorrent" = µTorrent "Winamp Detect" = Détection de l'application Winamp [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 21/07/2014 08:25:06 | Computer Name = stephan-PC | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante iexplore.exe, version : 9.0.8112.16561, horodatage : 0x539247f9 Nom du module défaillant : unknown, version : 0.0.0.0, horodatage : 0x00000000 Code d’exception : 0xc0000005 Décalage d’erreur : 0x74aefff6 ID du processus défaillant : 0x197c Heure de début de l’application défaillante : 0x01cfa4decd6673eb Chemin d’accès de l’application défaillante : C:\Program Files (x86)\Internet Explorer\iexplore.exe Chemin d’accès du module défaillant: unknown ID de rapport : 0b8540d9-10d2-11e4-af1e-e0cb4ea1e2a7 Error - 21/07/2014 10:43:46 | Computer Name = stephan-PC | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante unit.exe, version : 4.0.0.0, horodatage : 0x53c8eccc Nom du module défaillant : ntdll.dll, version : 6.1.7601.18247, horodatage : 0x521eaf24 Code d’exception : 0xc0000374 Décalage d’erreur : 0x00000000000c4102 ID du processus défaillant : 0x138c Heure de début de l’application défaillante : 0x01cfa4d8bf08dab2 Chemin d’accès de l’application défaillante : C:\Program Files\COMODO\GeekBuddy\unit.exe Chemin d’accès du module défaillant: C:\Windows\SYSTEM32\ntdll.dll ID de rapport : 6b0f213b-10e5-11e4-af1e-e0cb4ea1e2a7 Error - 21/07/2014 20:59:54 | Computer Name = stephan-PC | Source = IMFservice | ID = 0 Description = Error - 21/07/2014 20:59:55 | Computer Name = stephan-PC | Source = IMFservice | ID = 0 Description = Error - 22/07/2014 11:47:12 | Computer Name = stephan-PC | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante cmdagent.exe, version : 7.0.55655.4142, horodatage : 0x534eeb61 Nom du module défaillant : cmdurlflt.dll, version : 7.0.53315.4132, horodatage : 0x5331cecc Code d’exception : 0xc0000417 Décalage d’erreur : 0x00000000002112a8 ID du processus défaillant : 0x1bc Heure de début de l’application défaillante : 0x01cfa5a5b07b7070 Chemin d’accès de l’application défaillante : C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe Chemin d’accès du module défaillant: C:\Program Files\COMODO\COMODO Internet Security\cmdurlflt.dll ID de rapport : 71970aab-11b7-11e4-a055-e0cb4ea1e2a7 Error - 22/07/2014 20:45:06 | Computer Name = stephan-PC | Source = IMFservice | ID = 0 Description = Error - 22/07/2014 23:43:20 | Computer Name = stephan-PC | Source = IMFservice | ID = 0 Description = Error - 22/07/2014 23:43:21 | Computer Name = stephan-PC | Source = IMFservice | ID = 0 Description = Error - 23/07/2014 10:15:50 | Computer Name = stephan-PC | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante cmdagent.exe, version : 7.0.55655.4142, horodatage : 0x534eeb61 Nom du module défaillant : cmdurlflt.dll, version : 7.0.53315.4132, horodatage : 0x5331cecc Code d’exception : 0xc0000417 Décalage d’erreur : 0x00000000002112a8 ID du processus défaillant : 0x1dc Heure de début de l’application défaillante : 0x01cfa65b9f1efbd8 Chemin d’accès de l’application défaillante : C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe Chemin d’accès du module défaillant: C:\Program Files\COMODO\COMODO Internet Security\cmdurlflt.dll ID de rapport : d8bd7e65-1273-11e4-ad8c-e0cb4ea1e2a7 Error - 23/07/2014 22:42:14 | Computer Name = stephan-PC | Source = IMFservice | ID = 0 Description = [ COMODO Internet Security Events ] Error - 07/09/2014 12:51:13 | Computer Name = stephan-PC | Source = cistray | ID = 1 Description = Error - 10/09/2014 11:27:47 | Computer Name = stephan-PC | Source = cistray | ID = 1 Description = Error - 11/09/2014 08:02:02 | Computer Name = stephan-PC | Source = cistray | ID = 1 Description = Error - 11/09/2014 14:43:50 | Computer Name = stephan-PC | Source = cistray | ID = 1 Description = Error - 12/09/2014 09:04:54 | Computer Name = stephan-PC | Source = cis | ID = 1 Description = Error - 14/09/2014 11:51:14 | Computer Name = stephan-PC | Source = cistray | ID = 1 Description = Error - 15/09/2014 08:34:22 | Computer Name = stephan-PC | Source = cistray | ID = 1 Description = Error - 15/09/2014 11:48:06 | Computer Name = stephan-PC | Source = cistray | ID = 1 Description = Error - 19/09/2014 06:16:25 | Computer Name = stephan-PC | Source = cistray | ID = 1 Description = Error - 05/11/2014 19:59:53 | Computer Name = stephan-PC | Source = cis | ID = 1 Description = [ Media Center Events ] Error - 25/10/2014 11:09:50 | Computer Name = stephan-PC | Source = MCUpdate | ID = 0 Description = 17:09:42 - Échec de la récupération de Broadband (Erreur : Impossible de se connecter au serveur distant) Error - 26/10/2014 04:39:28 | Computer Name = stephan-PC | Source = MCUpdate | ID = 0 Description = 09:39:28 - Échec de la récupération de Directory (Erreur : Impossible de se connecter au serveur distant) Error - 26/10/2014 04:39:33 | Computer Name = stephan-PC | Source = MCUpdate | ID = 0 Description = 09:39:32 - Échec de la récupération de MCESpotlight (Erreur : Impossible de se connecter au serveur distant) Error - 26/10/2014 04:39:34 | Computer Name = stephan-PC | Source = MCUpdate | ID = 0 Description = 09:39:34 - Échec de la récupération de Broadband (Erreur : Impossible de se connecter au serveur distant) Error - 26/10/2014 05:40:57 | Computer Name = stephan-PC | Source = MCUpdate | ID = 0 Description = 10:40:55 - Échec de la récupération de MCEClientUX (Erreur : Impossible de se connecter au serveur distant) Error - 26/10/2014 05:41:05 | Computer Name = stephan-PC | Source = MCUpdate | ID = 0 Description = 10:40:58 - Échec de la récupération de Broadband (Erreur : Impossible de se connecter au serveur distant) Error - 26/10/2014 06:41:32 | Computer Name = stephan-PC | Source = MCUpdate | ID = 0 Description = 11:41:29 - Échec de la récupération de Broadband (Erreur : Impossible de se connecter au serveur distant) Error - 27/10/2014 05:20:33 | Computer Name = stephan-PC | Source = MCUpdate | ID = 0 Description = 10:20:24 - Échec de la récupération de Broadband (Erreur : Impossible de se connecter au serveur distant) Error - 30/10/2014 05:16:36 | Computer Name = stephan-PC | Source = MCUpdate | ID = 0 Description = 10:16:36 - Échec de la récupération de MCEClientUX (Erreur : Impossible de se connecter au serveur distant) Error - 30/10/2014 05:16:48 | Computer Name = stephan-PC | Source = MCUpdate | ID = 0 Description = 10:16:39 - Échec de la récupération de Broadband (Erreur : Impossible de se connecter au serveur distant) [ System Events ] Error - 21/09/2015 08:30:36 | Computer Name = stephan-PC | Source = Service Control Manager | ID = 7031 Description = Le service Windows Search s’est terminé de manière inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être effectuée dans 30000 millisecondes : Redémarrer le service. Error - 21/09/2015 08:30:36 | Computer Name = stephan-PC | Source = Service Control Manager | ID = 7031 Description = Le service Service Partage réseau du Lecteur Windows Media s’est terminé de manière inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être effectuée dans 30000 millisecondes : Redémarrer le service. Error - 21/09/2015 08:31:06 | Computer Name = stephan-PC | Source = Service Control Manager | ID = 7032 Description = Le Gestionnaire de services de contrôle a essayé d’entreprendre une action corrective (Redémarrer le service) après la fin inattendue du service Windows Search, mais cette action a échoué en raison de l’erreur suivante : %%1056 Error - 22/09/2015 02:44:22 | Computer Name = stephan-PC | Source = VDS Basic Provider | ID = 33554433 Description = Error - 22/09/2015 06:11:42 | Computer Name = stephan-PC | Source = Application Popup | ID = 1060 Description = Le chargement de \??\C:\Users\stephan\AppData\Local\Temp\catchme.sys a été bloqué en raison d’une incompatibilité avec ce système. Contactez l’éditeur de votre logiciel pour obtenir une version compatible du pilote. Error - 22/09/2015 06:11:44 | Computer Name = stephan-PC | Source = Application Popup | ID = 1060 Description = Le chargement de \??\C:\Users\stephan\AppData\Local\Temp\catchme.sys a été bloqué en raison d’une incompatibilité avec ce système. Contactez l’éditeur de votre logiciel pour obtenir une version compatible du pilote. Error - 22/09/2015 06:11:44 | Computer Name = stephan-PC | Source = Application Popup | ID = 1060 Description = Le chargement de \??\C:\Users\stephan\AppData\Local\Temp\catchme.sys a été bloqué en raison d’une incompatibilité avec ce système. Contactez l’éditeur de votre logiciel pour obtenir une version compatible du pilote. Error - 22/09/2015 08:14:34 | Computer Name = stephan-PC | Source = Service Control Manager | ID = 7026 Description = Le pilote de démarrage système ou d’amorçage suivant n’a pas pu se charger : cdrom Error - 22/09/2015 09:50:29 | Computer Name = stephan-PC | Source = Service Control Manager | ID = 7009 Description = Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la connexion du service Service Google Update (gupdate). Error - 22/09/2015 09:50:29 | Computer Name = stephan-PC | Source = Service Control Manager | ID = 7000 Description = Le service Service Google Update (gupdate) n’a pas pu démarrer en raison de l’erreur : %%1053 < End of report >