OTL Extras logfile created on: 09/12/2014 11:16:14 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\françois\Desktop 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17416) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 3,91 Gb Total Physical Memory | 2,06 Gb Available Physical Memory | 52,62% Memory free 7,91 Gb Paging File | 6,16 Gb Available in Paging File | 77,82% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 199,69 Gb Total Space | 96,38 Gb Free Space | 48,27% Space Free | Partition Type: NTFS Drive D: | 720,11 Gb Total Space | 464,49 Gb Free Space | 64,50% Space Free | Partition Type: NTFS Computer Name: T16-FRANÇOIS | User Name: françois | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl[@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-2659235129-2275843782-2206697212-1002\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\SysWow64\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\SysWow64\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [SpaceMonger] -- "C:\Program Files (x86)\SpaceMonger\SpaceMonger.exe" ; show-free-space false ; show-system-space false ; set-root "%l" (Sixty-Five Software, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\SysWow64\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\SysWow64\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [SpaceMonger] -- "C:\Program Files (x86)\SpaceMonger\SpaceMonger.exe" ; show-free-space false ; show-system-space false ; set-root "%l" (Sixty-Five Software, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0139693A-7E47-4AE2-BFD9-28DC54DF8CB1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{05CAB03C-0023-408C-B662-396FCE11B3A2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1C2F26D9-0A3A-4A39-8270-8EB004E0E2B8}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{315FE662-888C-4D14-B3EC-AFF1D7019BBB}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{395FCC92-3BD2-49F9-86C9-A5632B74310C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{431A1560-3F00-4651-BC05-5FEBEC10F5BC}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{4CCB3453-1833-4F31-96C2-91BF0D6C2024}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{52E8C274-0E95-4D66-B274-08AA14931B87}" = rport=139 | protocol=6 | dir=out | app=system | "{5B60C97C-9539-4D37-B6A1-EB3F756447C6}" = lport=137 | protocol=17 | dir=in | app=system | "{67B0076D-43DA-4F82-BE72-1628C32B5CAF}" = rport=138 | protocol=17 | dir=out | app=system | "{8609CA1A-C0A6-49B3-A52E-CD483BD09ED9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{8AD9077B-D48C-438D-B613-0E0BC67EB884}" = lport=2869 | protocol=6 | dir=in | app=system | "{95B93C45-57F6-4A79-A931-3097E69CDF77}" = rport=445 | protocol=6 | dir=out | app=system | "{9C0FD932-714F-4117-AFFC-A1386D186716}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{9F78BFDF-2209-46CC-8EAA-3E386289D368}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{A8110CA4-DCB5-496C-B894-842A4401F472}" = rport=10243 | protocol=6 | dir=out | app=system | "{AB4D8FD6-C736-4CD8-981E-F74F758B4B84}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{ACEF8CC5-2D6B-4E5B-94BF-02F5451F55C1}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{B5105BE4-9E6F-4BBB-A6C3-EE8286B5113F}" = lport=138 | protocol=17 | dir=in | app=system | "{B5E724E8-0474-4024-9B78-A613C86645CD}" = lport=10243 | protocol=6 | dir=in | app=system | "{BD9D4DFF-D557-457A-B729-466BDD8DE1A3}" = lport=139 | protocol=6 | dir=in | app=system | "{C718AD94-E765-417E-B53A-67F5CCB08705}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C876548B-B1D0-4FBF-B9BC-D52100BD8388}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{CC30C564-5C2C-44BE-8168-C9A2EBA3DA93}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{DB67369B-20D4-4842-A244-20703D36E5E6}" = lport=445 | protocol=6 | dir=in | app=system | "{DD5EB674-10AD-49A1-BC3F-BFC03C0C97B5}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{E6ADCC5B-CBF0-45C5-931E-09A4F0608848}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{F4EF0C6C-CD20-4A12-BB42-1DFB474F1D4C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{FA554898-D02D-48D4-97B2-2C88A58BDBA8}" = rport=137 | protocol=17 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0032ABD2-610B-40C2-A707-33ECA789248D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{02F39E06-6F52-47C6-A617-C2AEA8CC565B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{0E805083-A174-427B-904E-AB30E5FE85BF}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{162FBA96-6A7A-4C80-A8A9-E28827E4460B}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{18BDB0B2-731E-46A2-81C4-402BBCC8F1DF}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{19373CF4-6E1B-4B03-86AF-A24C68A1AF3D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{204FB9F1-D5BF-46A1-BB0B-D5A7A1238D76}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{28B6FE14-C016-46C4-AAF9-114E60599A36}" = dir=out | name=facebook | "{2C0E029A-240F-4C4A-A7DA-C7494482CE7B}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{30A662AA-5C78-4DCB-A9B3-0FACA5E0FF5B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{3D4F2D50-4689-4681-B554-1EDACC738E82}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{3E4F90F4-DE5D-4DBA-BD74-1E3E0248A756}" = dir=in | name=intel appup® center – toshiba europe edition | "{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | "{4431BD54-523B-4EC7-AEBB-6EAAB56063C2}" = protocol=6 | dir=in | app=c:\users\françois\appdata\roaming\dropbox\bin\dropbox.exe | "{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | "{56DA786F-D4CA-4869-AC08-171DFF6ACD98}" = protocol=6 | dir=out | app=system | "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | "{6AC2CC97-0038-4BB4-A507-069A7E3969B5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{70C8031B-3D20-4031-83C6-0ED56686A3CC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{7280BB79-D903-4510-B877-B2DDC715DFD7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{82408C62-E945-449E-AADC-4E66178280B8}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{85F4535D-55AB-41E2-88AB-C2B5C2177066}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8DDEB31E-6324-4311-A74E-18D6CB64176B}" = dir=out | name=formation windows 8 freemium - toshiba | "{9401D0CD-3AAF-4C34-85EA-F7B250F5DA35}" = dir=out | name=my toshiba | "{94C40F15-2F1F-45CB-B62B-38CB98EF0302}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{9542B5A9-2CB7-4064-87E4-FF8FD9C482A6}" = dir=out | name=intel appup® center – toshiba europe edition | "{9804AB8F-80F3-4327-BE0B-D427CDBC430E}" = protocol=17 | dir=in | app=c:\users\françois\appdata\roaming\dropbox\bin\dropbox.exe | "{99B99761-5D63-4A7D-B2D8-CE5961735790}" = protocol=17 | dir=in | app=c:\users\françois\appdata\roaming\bittorrent\bittorrent.exe | "{9C7709A3-03F6-4ED4-9706-904D086A329F}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{9C9DBF06-96F2-459C-B30C-FD92CDCA6FAD}" = protocol=6 | dir=in | app=c:\users\françois\appdata\roaming\bittorrent\bittorrent.exe | "{9EC7FA48-8594-425D-9EA3-BB7A00603C25}" = dir=in | app=c:\windows\explorer.exe | "{A2B9EBEE-D6CD-48E7-8028-FED87161E411}" = dir=in | name=skype | "{A4CA3D11-7D4F-457D-A6A1-67374102A972}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{A894F127-F33B-4FA6-A1DF-69057BD49178}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{AE5122CE-009E-487D-A869-2973FBBBD952}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{AEC27161-A15B-4EF6-8BA5-0DEE82B64876}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe | "{B26083FD-8672-4F7D-BBB2-0E6947D329C6}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe | "{B372B57F-5BA2-4188-B09A-B27047F4A295}" = dir=out | app=%programfiles% (x86)\kmplayer\kmplayer.exe | "{B944620B-F707-4282-846F-DEE8910856EC}" = dir=out | name=skype | "{BFD0ED40-96DA-4879-92A4-DAC276775C5B}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{C567AE1C-2BD9-4BEE-BCBE-697BFD5A9BCA}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{CB24C1D0-715F-4477-AD69-98EDC33E3A20}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{CBBBCD77-1B6F-4748-B943-A68F39E11036}" = dir=out | name=@{microsoft.bingweather_3.0.4.249_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} | "{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | "{DC516D02-025B-4093-B28B-B4A4F09A3CA7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E48EE552-84CD-4CF9-A80F-71D06B3F1014}" = dir=out | name=windows_ie_ac_001 | "{E8B77894-0AC2-474B-9F5E-374273288FB8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | "{ECE7A503-9DBB-4453-92A6-546B70A76FAD}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | "{F6EDC238-61DC-4181-BA6E-0E6A9959368B}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | "{FBB48991-2836-413E-9B57-AB6802EC65EF}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "TCP Query User{2D4D8C8C-5B5B-4DB8-85F3-0A9F69664317}C:\users\françois\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\françois\appdata\roaming\dropbox\bin\dropbox.exe | "UDP Query User{A59A7C7B-65E7-4EB0-812A-57D37C84F9B3}C:\users\françois\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\françois\appdata\roaming\dropbox\bin\dropbox.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series" = Canon MG5100 series MP Drivers "{16562A90-71BC-41A0-B890-D91B0C267120}" = TOSHIBA Function Key "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}" = iTunes "{34FE5428-54F4-3883-9372-AD81FFD14F69}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.20617 "{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology "{588A747E-CFF6-46B3-9207-CD754F9473AF}" = IDT Audio Driver "{5944B9D4-3C2A-48DE-931E-26B31714A2F7}" = TOSHIBA eco Utility "{5B56292B-D158-4C6C-A004-61584D6CABBB}" = ESET NOD32 Antivirus "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{84FA4D2D-4273-4C66-BD3D-ADD3FE48DFA2}" = TOSHIBA Display Utility "{89AFB053-A343-46EF-97E4-D593AD7184E6}" = Intel® Trusted Connect Service Client "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A1B1B44-D41D-473A-AD26-3DAF1A596E8F}" = hubiC - x64 "{8B49CDB9-824C-44D6-A5D3-D0235D3030B8}" = AxCrypt 1.7.3156.0 "{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables "{8DCF8C8F-4ADA-3395-BF10-A3437F9929D4}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.20617 "{93F692D4-0C4D-4EED-9BFE-657C1D5959FE}" = Intel(R) Rapid Storage Technology "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{95CCACF0-010D-45F0-82BF-858643D8BC02}" = TOSHIBA Desktop Assist "{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 "{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64) "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panneau de configuration NVIDIA 344.11 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Pilote graphique 344.11 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 2.1.2 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus Update 16.13.42 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Logiciel système PhysX 9.14.0702 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Mises à jour NVIDIA 16.13.42 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService" = NVIDIA GeForce Experience Service "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 16.13.42 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController" = SHIELD Wireless Controller Driver "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.25 "{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}" = Apple Mobile Device Support "{D0360940-CCC6-11E3-B9C6-F04DA23A5C58}" = Vegas Pro 13.0 (64-bit) "{D10D0851-CCC6-11E3-9ED2-F04DA23A5C58}" = MSVCRT Redists "{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64 "{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}" = TOSHIBA Service Station "{FF07604E-C860-40E9-A230-E37FA41F103A}" = TOSHIBA VIDEO PLAYER "CutePDF Writer Installation" = CutePDF Writer 3.0 "PerformanceTest 8_is1" = PerformanceTest v8.0 "PhotomatixPro42x64_is1" = Photomatix Pro version 4.2.4 "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = WinRAR 5.20 (64-bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}" = Windows Live UX Platform "{05A55927-DB9B-4E26-BA44-828EBFF829F0}" = TOSHIBA System Settings "{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1" = MiniTool Partition Wizard Home Edition 8.1.1 "{068A5D84-8419-4BDE-9689-FE65F412EFBB}_is1" = Syncios version 4.1.2 "{07AAB66E-4718-422D-9218-4AFB3C922A71}" = Photo Gallery "{10B9C608-BF7C-4CCF-A658-C01D969DCA21}_is1" = gpedt.msc 1.0 "{13f707f4-410d-4c85-95ea-a373458d9c98}" = hubiC "{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 "{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}" = Windows Live Photo Common "{1E6A96A1-2BAB-43EF-8087-30437593C66C}" = TOSHIBA System Driver "{1F2DC3EA-9682-3AAA-BB63-D9BC1AC17960}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.20617 "{1f407217-9aec-4146-8504-e64ac959c534}" = Microsoft Visual C++ 2013 Preview Redistributable (x86) - 12.0.20617 "{21764A96-6748-4B83-89E7-7A5063BF156C}" = Movie Maker "{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 "{2DFA9084-CEB3-4A48-B9F7-9038FEF1B8F4}" = DTS Sound "{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 "{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver "{33B992ED-B59B-4E25-9F3F-CF2D79BBA914}" = Windows Live UX Platform Language Pack "{3751BF9B-5F23-4976-AA62-1BF4D791DCFE}" = Photo Common "{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}" = QuickTime 7 "{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}" = Microsoft ASP.NET MVC 4 Runtime "{41C61308-6CFD-4D54-AB6A-7136ED08A18E}" = Windows Live Communications Platform "{420ED767-62A5-462F-9DDA-AE3A95D4BF32}" = Alcor Micro USB Card Reader "{439B34FF-F74E-4807-B5E2-4B758551DA6B}" = Galerie de photos "{448652c1-f5f3-4230-98c6-68c10c88b1fb}" = Microsoft Visual C++ 2013 Preview Redistributable (x64) - 12.0.20617 "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{659CB81C-B54E-4DF1-B618-F35777393A54}" = Windows Live Installer "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{74D52476-2E1E-3F1B-8460-E4ECF2FB6491}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.20617 "{78931270-BC9E-441A-A52B-73ECD4ACFAB5}" = TOSHIBA Password Utility "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}" = Apple Application Support "{8A7D0970-C0A4-4B56-94D4-E3A175AB45BB}" = ArcSoft Panorama Maker 6 "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110 "{9011040C-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{90120000-0020-040C-0000-0000000FF1CE}" = Module de compatibilité pour Microsoft Office System 2007 "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}" = TOSHIBA Manuals "{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A3D5DF0A-FEA8-4872-9491-CDA50AF01E56}" = NameWiz "{AC76BA86-1033-FFFF-7760-000000000006}" = Adobe Acrobat XI Pro "{AC76BA86-7AD7-2530-0000-A00000000049}" = Extended Asian Language font pack for Adobe Reader XI "{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}" = Windows Live PIMT Platform "{B455E95A-B804-439F-B533-336B1635AE97}" = NVIDIA PhysX "{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator "{B99F248C-B4B3-4D61-9FFC-AE59A1F13723}" = Windows Live "{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program "{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}" = Windows Live SOXE "{CE0374A6-B204-4336-8293-63FBB1DADBF4}" = TOSHIBA Addendum "{D1893000-EA77-493C-8DDD-E262436E959B}" = Windows Live SOXE Definitions "{DD67BE4B-7E62-4215-AFA3-F123A800A389}" = Movie Maker "{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics DiskDefrag "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E6B58BFB-18F0-4BCC-9FF7-378D783DA758}" = TOSHIBA Addendum "{EBE030DD-D404-4D92-85E9-8C3624820808}_is1" = Light Image Resizer 4.6.5.0 "{EEC010D0-1252-4E1D-BAD9-F1B8F414535C}" = PL-2303 Vista Driver Installer "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F76F5214-83A8-4030-80C9-1EF57391D72A}" = Toshiba TEMPRO "{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin "Algobox" = Algobox "AmUStor" = Alcor Micro USB Card Reader "Anki" = Anki "CanonMyPrinter" = Canon My Printer "CanonSolutionMenuEX" = Canon Solution Menu EX "CodecInstaller" = CodecInstaller 2.10.4 "Duplicate Cleaner Pro" = Duplicate Cleaner Pro 3.2.5 "Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX "Family Tree Builder" = MyHeritage Family Tree Builder "FileZilla Client" = FileZilla Client 3.9.0.6 "FormatFactory" = FormatFactory 3.3.5.0 "GeoSetter_is1" = GeoSetter 3.4.16 "Glary Utilities 5" = Glary Utilities 5.13 "InstallShield_{78931270-BC9E-441A-A52B-73ECD4ACFAB5}" = TOSHIBA Password Utility "KLiteCodecPack_is1" = K-Lite Mega Codec Pack 10.8.5 "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.4.1028 "MiKTeX 2.9" = MiKTeX 2.9 "Movavi Screen Capture Studio 5" = Movavi Screen Capture Studio 5 "Mozilla Firefox 34.0 (x86 fr)" = Mozilla Firefox 34.0 (x86 fr) "Mozilla Thunderbird 31.3.0 (x86 fr)" = Mozilla Thunderbird 31.3.0 (x86 fr) "MozillaMaintenanceService" = Mozilla Maintenance Service "MP Navigator EX 4.0" = Canon MP Navigator EX 4.0 "Mp3tag" = Mp3tag v2.64 "Picasa 3" = Picasa 3 "SpaceMonger" = SpaceMonger 2.1.1 "TeamViewer 9" = TeamViewer 9 "The KMPlayer" = KMPlayer (remove only) "Wenlin_is1" = Wenlin 3.4 "WinLiveSuite" = Windows Live "WinRAR archiver" = WinRAR 5.11 beta 1 (32-bit) "ZHPDiag_is1" = ZHPDiag 2014 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-2659235129-2275843782-2206697212-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "BitTorrent" = BitTorrent "Dropbox" = Dropbox [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 05/12/2014 13:47:38 | Computer Name = T16-françois | Source = Application Hang | ID = 1002 Description = Le programme backgroundTaskHost.exe version 6.3.9600.16384 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance. ID de processus : dd0 Heure de début : 01d010b2d492fc85 Heure de fin : 4294967295 Chemin d’accès de l’application : C:\Windows\system32\backgroundTaskHost.exe ID de rapport : c9a25bd5-7ca6-11e4-8320-0c54a5334dbb Nom complet du package défaillant : Facebook.Facebook_1.4.0.9_x64__8xx8rvfyw5nnt ID de l’application relative au package défaillant : App Error - 05/12/2014 17:12:58 | Computer Name = T16-françois | Source = NvStreamSvc | ID = 131073 Description = Error - 06/12/2014 12:53:52 | Computer Name = T16-françois | Source = Application Hang | ID = 1002 Description = Le programme backgroundTaskHost.exe version 6.3.9600.16384 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance. ID de processus : 14a0 Heure de début : 01d011747ab08abe Heure de fin : 4294967295 Chemin d’accès de l’application : C:\Windows\system32\backgroundTaskHost.exe ID de rapport : 7119abb3-7d68-11e4-8323-0c54a5334dbb Nom complet du package défaillant : Facebook.Facebook_1.4.0.9_x64__8xx8rvfyw5nnt ID de l’application relative au package défaillant : App Error - 06/12/2014 13:38:12 | Computer Name = T16-françois | Source = Application Hang | ID = 1002 Description = Le programme ZHPFix.exe version 2014.10.24.12 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance. ID de processus : 1834 Heure de début : 01d0117b4e15670d Heure de fin : 109 Chemin d’accès de l’application : C:\Program Files (x86)\ZHPDiag\ZHPFix\ZHPFix.exe ID de rapport : a403b9dc-7d6e-11e4-8323-0c54a5334dbb Nom complet du package défaillant : ID de l’application relative au package défaillant : Error - 06/12/2014 13:49:37 | Computer Name = T16-françois | Source = Windows Search Service | ID = 7040 Description = Error - 06/12/2014 13:49:37 | Computer Name = T16-françois | Source = Windows Search Service | ID = 7042 Description = Error - 06/12/2014 14:11:34 | Computer Name = T16-françois | Source = .NET Runtime | ID = 1022 Description = Error - 06/12/2014 14:46:19 | Computer Name = T16-françois | Source = NvStreamSvc | ID = 131073 Description = Error - 06/12/2014 15:07:09 | Computer Name = T16-françois | Source = Application Hang | ID = 1002 Description = Le programme backgroundTaskHost.exe version 6.3.9600.16384 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance. ID de processus : 488 Heure de début : 01d011871e01f222 Heure de fin : 4294967295 Chemin d’accès de l’application : C:\Windows\system32\backgroundTaskHost.exe ID de rapport : 11d8f9a7-7d7b-11e4-8324-0c54a5334dbb Nom complet du package défaillant : Facebook.Facebook_1.4.0.9_x64__8xx8rvfyw5nnt ID de l’application relative au package défaillant : App Error - 06/12/2014 16:02:47 | Computer Name = T16-françois | Source = .NET Runtime | ID = 1022 Description = [ System Events ] Error - 05/12/2014 11:46:22 | Computer Name = T16-françois | Source = Service Control Manager | ID = 7000 Description = Le service PenTablet Bus Enumerator n’a pas pu démarrer en raison de l’erreur : %%123 Error - 05/12/2014 11:46:22 | Computer Name = T16-françois | Source = Service Control Manager | ID = 7000 Description = Le service WinTab Service n’a pas pu démarrer en raison de l’erreur : %%2 Error - 05/12/2014 17:13:47 | Computer Name = T16-françois | Source = Service Control Manager | ID = 7000 Description = Le service sbapifs n’a pas pu démarrer en raison de l’erreur : %%2 Error - 05/12/2014 17:14:08 | Computer Name = T16-françois | Source = Service Control Manager | ID = 7000 Description = Le service PenTablet Bus Enumerator n’a pas pu démarrer en raison de l’erreur : %%123 Error - 05/12/2014 17:14:08 | Computer Name = T16-françois | Source = Service Control Manager | ID = 7000 Description = Le service WinTab Service n’a pas pu démarrer en raison de l’erreur : %%2 Error - 06/12/2014 03:04:07 | Computer Name = T16-françois | Source = Service Control Manager | ID = 7000 Description = Le service sbapifs n’a pas pu démarrer en raison de l’erreur : %%2 Error - 06/12/2014 03:04:27 | Computer Name = T16-françois | Source = Service Control Manager | ID = 7000 Description = Le service PenTablet Bus Enumerator n’a pas pu démarrer en raison de l’erreur : %%123 Error - 06/12/2014 03:04:27 | Computer Name = T16-françois | Source = Service Control Manager | ID = 7000 Description = Le service WinTab Service n’a pas pu démarrer en raison de l’erreur : %%2 Error - 06/12/2014 04:58:32 | Computer Name = T16-françois | Source = DCOM | ID = 10010 Description = Error - 06/12/2014 04:59:02 | Computer Name = T16-françois | Source = DCOM | ID = 10010 Description = < End of report >