OTL Extras logfile created on: 1/31/2014 11:58:46 PM - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\drinus\Desktop Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.16476) Locale: 00000409 | Country: France | Language: FRA | Date Format: dd/MM/yyyy 2.93 Gb Total Physical Memory | 1.28 Gb Available Physical Memory | 43.52% Memory free 5.86 Gb Paging File | 3.87 Gb Available in Paging File | 65.91% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files Drive C: | 141.49 Gb Total Space | 93.18 Gb Free Space | 65.85% Space Free | Partition Type: NTFS Drive D: | 141.50 Gb Total Space | 141.23 Gb Free Space | 99.81% Space Free | Partition Type: NTFS Computer Name: DRINUS-PC | User Name: drinus | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (All) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .bat [@ = batfile] -- "%1" %* .chm [@ = chm.file] -- C:\windows\hh.exe (Microsoft Corporation) .cmd [@ = cmdfile] -- "%1" %* .com [@ = comfile] -- "%1" %* .cpl [@ = cplfile] -- C:\windows\System32\control.exe (Microsoft Corporation) .exe [@ = exefile] -- "%1" %* .hlp [@ = hlpfile] -- C:\windows\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- C:\windows\System32\mshta.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .inf [@ = inffile] -- C:\windows\System32\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\windows\System32\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\windows\System32\rundll32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\windows\System32\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\windows\System32\WScript.exe (Microsoft Corporation) .pif [@ = piffile] -- "%1" %* .reg [@ = regfile] -- C:\windows\regedit.exe (Microsoft Corporation) .scr [@ = scrfile] -- "%1" /S .txt [@ = txtfile] -- C:\windows\System32\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\windows\System32\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\windows\System32\WScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\windows\System32\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\windows\System32\WScript.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\System32\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\windows\system32\rundll32.exe" "C:\windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- Reg Error: Key error. https [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0005C686-A33B-423A-B59C-97553627AAD4}" = rport=445 | protocol=6 | dir=out | app=system | "{03E3F9E7-3E84-4079-A68A-316DB80A3C3F}" = lport=137 | protocol=17 | dir=in | app=system | "{06785053-0E37-4BE8-81C1-108732FF0248}" = rport=137 | protocol=17 | dir=out | app=system | "{1510DC41-0F3C-4D3B-9A13-B5FEC8D232A4}" = lport=138 | protocol=17 | dir=in | app=system | "{1B61689B-A994-47C9-BB47-9204E07485CE}" = lport=2869 | protocol=6 | dir=in | app=system | "{1CEFEABC-BBED-46D8-8A30-C72CA1E8A9DA}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{1DE5EB16-1C5B-4ED3-AFB8-1BC73A88BAF7}" = lport=10243 | protocol=6 | dir=in | app=system | "{34560A83-2AD2-4AB0-9E1E-28F199005217}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{3836D45E-6A76-45AC-A111-4EFA384DE8CF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{3C9EA929-FB9B-42F6-BB92-0FF84A93BEDD}" = rport=10243 | protocol=6 | dir=out | app=system | "{5209287C-74A4-47EE-A20F-3FE01924E41F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{5B307AF8-5287-49D7-9755-54847C593089}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5BD024AE-62D1-4377-9796-2EC8CCF1CF98}" = lport=139 | protocol=6 | dir=in | app=system | "{6D97190F-5C08-41FD-888D-1582A8152BE8}" = rport=138 | protocol=17 | dir=out | app=system | "{6F688A15-118C-458B-8D54-E1EA6A1E4C58}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{7CD58C29-55E2-46F3-AFA5-F352D6C0BE35}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{7F03F016-AC68-43C1-8D6B-9FC7016F2DE3}" = lport=445 | protocol=6 | dir=in | app=system | "{84F0D991-501D-4378-80C6-584F771DC85A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{916AD9A5-DF58-42D1-98EE-010388B39828}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A5828C84-8266-4CCE-9E38-552EB4C97C8B}" = lport=2869 | protocol=6 | dir=in | app=system | "{AA302B38-4B2F-468E-B8CC-A97F0785BC20}" = rport=139 | protocol=6 | dir=out | app=system | "{AE644DB4-143E-48A2-8C2C-0272050D12CA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B477B231-1A38-4683-B327-51E5989525C2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CEED2447-6492-4BF2-9799-ADE9ABEABFAF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{D588C9EC-AF3B-4105-B339-1D27BCE0E4F3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{DD142939-099B-4B61-9504-DC6A37A2EDD4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{F327931A-AFC2-4C0A-9CA6-365F34C28E49}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0701D2F8-6EB9-43B1-B9D4-3E546CA3B2F7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{0D00B097-43B4-45D3-892D-9FD3C9E7580D}" = protocol=17 | dir=in | app=c:\users\drinus\appdata\local\microsoft\skydrive\skydrive.exe | "{1370F09D-DD16-43F5-B1AA-1992CCF3DCE8}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{1D5242DB-6B47-4571-8D24-05C37E9B0DD4}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | "{305F9C3B-6616-42C0-A09C-602E3015B637}" = dir=in | app=c:\program files\cyberlink\powerdvd8\powerdvd8.exe | "{3BFAEB96-BA82-4C51-B532-D099593BEB85}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe | "{42A3BD5B-A670-4B0D-A91C-F3DF0A24708C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{761B7127-3B7E-44E4-8629-A794DCF1C1F1}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{808E1420-3E26-400A-A677-295705D86A4B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{817C69CB-CB30-41AD-8154-3B1CEA1B5842}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{839E7D53-036D-4C49-9775-5FB50F418AE8}" = protocol=6 | dir=in | app=c:\users\drinus\appdata\local\microsoft\skydrive\skydrive.exe | "{84BA1A43-5D4C-4EB4-895F-8F0E8DB2B5C0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{85479FE6-5065-4093-BF43-E9E9F73C10B5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{895FD37D-B4E0-46AB-88FB-684517B522C2}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{92C4183D-83CF-44CE-B438-96A8E4D3E96E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{94490341-D93A-4C49-8402-0EB73A5C0C20}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{9F0B8C7A-F634-4B9C-9D0D-E6D8FEC0391E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A32D9A1D-D7DB-46A9-ABD2-7841C70AF4BE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{BD9EF6A0-34DA-42A0-BC5B-464AB25B0A1F}" = protocol=6 | dir=in | app=c:\windows\system32\muzapp.exe | "{C44EF3A6-073A-4905-8B46-5816816745C0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{D87ADA99-4094-4F73-BF7F-94E2A3808402}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{D8DBAADC-B78A-4ADC-88B6-51564AD3926D}" = protocol=6 | dir=out | app=system | "{E92E9420-C573-4E2D-A9DF-A593DC05ADF3}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{ECD0CA76-406B-4F21-81E0-D08832B3322F}" = protocol=17 | dir=in | app=c:\windows\system32\muzapp.exe | "{F3632A5C-FCD1-45E7-9BC8-CC774642D321}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{56AF8A30-072B-461F-9FFE-0F4493859DB8}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | "TCP Query User{6554FA61-BCB1-4281-8362-71F09A259996}C:\program files\ares\ares.exe" = protocol=6 | dir=in | app=c:\program files\ares\ares.exe | "TCP Query User{90B06506-C41A-4592-A777-F9B5D5D8ED25}C:\program files\ares\ares.exe" = protocol=6 | dir=in | app=c:\program files\ares\ares.exe | "UDP Query User{0B0F7D42-2071-4A08-ADEE-6247FAB325BE}C:\program files\ares\ares.exe" = protocol=17 | dir=in | app=c:\program files\ares\ares.exe | "UDP Query User{364D57F0-5A7A-4F09-8A28-4272B7515C7B}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe | "UDP Query User{EE2E6E3F-12D0-45CB-9936-87D3EC62E00B}C:\program files\ares\ares.exe" = protocol=17 | dir=in | app=c:\program files\ares\ares.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP240_series" = Canon MP240 series MP Drivers "{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution 4 "{16E79B1D-D1C2-4CA6-8B23-F4D890E0DCB9}" = Orange Plug-in messagerie vocale 888 "{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager "{178EE5F4-0F86-4BF0-A0D1-9790AFF409D1}" = EasyBatteryManager "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1AFA1FEF-8CF9-4A51-AC46-64FAA7F3D9E2}" = AnyPC Client "{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{2075CB0A-D26F-4DAA-B424-5079296B43BA}" = Windows Live FolderShare "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live "{3B160861-7250-451E-B5EE-8B92BF30A710}" = Microsoft Works "{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live "{4903D172-DCCB-392F-93A3-34CA9D47FE3D}" = Microsoft .NET Framework 4.5.1 "{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources "{63eafc52-b963-4297-a7eb-d412944e7065}_is1" = Game Pack "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{698BBAD8-B116-495D-B879-0F07A533E57F}" = Samsung Story Album Viewer "{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker "{6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}" = Complément Messenger "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114072167}" = Go-Go Gourmet "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}" = Dairy Dash "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}" = Farm Frenzy 2 "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{83CF5DBB-EA0D-0100-0000-0000004F0022}" = Android Manager "{853F8A41-A3C9-43FA-87FA-1AE74FC6F3F7}" = BatteryLifeExtender "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{90120000-0020-040C-0000-0000000FF1CE}" = Module de compatibilité pour Microsoft Office System 2007 "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{95120000-00AF-040C-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (French) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail "{A5675A9E-F073-414A-9A04-F9BCD50459D7}" = Easy Network Manager "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AB61A2E9-37D3-485D-9085-19FBDF8CEF4A}" = Windows Live Messenger "{AC76BA86-7AD7-1036-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) - Français "{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9 "{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer "{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant "{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "{CCC2B140-B47A-45FA-AAE3-BD60DA41AE00}" = Samsung Support Center "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones "{D1434266-0486-4469-B338-A60082CC04E1}" = Atheros Client Installation Program "{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}" = Samsung Update Plus "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5 "Adobe Flash Player ActiveX" = Adobe Flash Player 12 ActiveX "Ares" = Ares 2.1.5 "Avast" = avast! Free Antivirus "CanonMyPrinter" = Canon Utilities My Printer "CanonSolutionMenu" = Canon Utilities Solution Menu "CCleaner" = CCleaner "Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX "Enregistrement utilisateur de Canon MP240 series" = Enregistrement utilisateur de Canon MP240 series "HDMI" = Intel(R) Graphics Media Accelerator Driver "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go "InstallShield_{698BBAD8-B116-495D-B879-0F07A533E57F}" = Samsung Story Album Viewer "InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies "InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300 "Marvell Miniport Driver" = Marvell Miniport Driver "MP Navigator EX 2.0" = Canon MP Navigator EX 2.0 "Office8.0" = Microsoft Office 97 Professional "Recuva" = Recuva "SynTPDeinstKey" = Synaptics Pointing Device Driver "TBSB05488.TBSB05488Toolbar" = eBuyClub "WinLiveSuite" = Windows Live [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-1871111397-3539990770-1974983793-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "AI RoboForm" = AI RoboForm "Notification de cadeaux MSN" = Notification de cadeaux MSN "PhotoFiltre" = PhotoFiltre [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 11/17/2012 2:31:58 PM | Computer Name = drinus-PC | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante iexplore.exe, version : 8.0.7601.17514, horodatage : 0x4ce79912 Nom du module défaillant : AcroIEHelper.dll_unloaded, version : 0.0.0.0, horodatage : 0x5016fff4 Code d’exception : 0xc0000005 Décalage d’erreur : 0x73a9556c ID du processus défaillant : 0x2878 Heure de début de l’application défaillante : 0x01cdc4f0ac6e6233 Chemin d’accès de l’application défaillante : C:\Program Files\Internet Explorer\iexplore.exe Chemin d’accès du module défaillant: AcroIEHelper.dll ID de rapport : 118e64e3-30e5-11e2-95a8-00245460adf6 Error - 11/17/2012 6:16:37 PM | Computer Name = drinus-PC | Source = Application Hang | ID = 1002 Description = Le programme iexplore.exe version 8.0.7601.17514 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance. ID de processus : 29e8 Heure de début : 01cdc4f9adf27d84 Heure de fin : 47 Chemin d’accès de l’application : C:\Program Files\Internet Explorer\iexplore.exe ID de rapport : 7003cbdb-3104-11e2-95a8-00245460adf6 Error - 11/17/2012 6:16:56 PM | Computer Name = drinus-PC | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante iexplore.exe, version : 8.0.7601.17514, horodatage : 0x4ce79912 Nom du module défaillant : msxml3.dll, version : 8.110.7601.17857, horodatage : 0x4fcee2f0 Code d’exception : 0xc0000005 Décalage d’erreur : 0x0002e64f ID du processus défaillant : 0x3524 Heure de début de l’application défaillante : 0x01cdc511391e8c22 Chemin d’accès de l’application défaillante : C:\Program Files\Internet Explorer\iexplore.exe Chemin d’accès du module défaillant: C:\windows\System32\msxml3.dll ID de rapport : 7f1dada8-3104-11e2-95a8-00245460adf6 Error - 11/18/2012 6:15:04 AM | Computer Name = drinus-PC | Source = SideBySide | ID = 16842785 Description = La création du contexte d’activation a échoué pour « C:\Program Files\Samsung\Samsung Support Center\Drv\drv2x64\KStartMem.exe.Manifest ». Assembly dépendant Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé. Error - 11/18/2012 6:15:38 AM | Computer Name = drinus-PC | Source = SideBySide | ID = 16842785 Description = La création du contexte d’activation a échoué pour « C:\Program Files\Samsung\BatteryLifeExtender\Drv\SABI2x64\KStartMem.exe.Manifest ». Assembly dépendant Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé. Error - 11/18/2012 5:40:53 PM | Computer Name = drinus-PC | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante iexplore.exe, version : 8.0.7601.17514, horodatage : 0x4ce79912 Nom du module défaillant : uxcontacts.dll, version : 15.4.3555.308, horodatage : 0x4f5960ea Code d’exception : 0xc0000005 Décalage d’erreur : 0x0006512c ID du processus défaillant : 0x144c Heure de début de l’application défaillante : 0x01cdc580809baac1 Chemin d’accès de l’application défaillante : C:\Program Files\Internet Explorer\iexplore.exe Chemin d’accès du module défaillant: C:\Program Files\Windows Live\Shared\uxcontacts.dll ID de rapport : 9fdeeb6e-31c8-11e2-9bf1-00245460adf6 Error - 11/18/2012 5:40:57 PM | Computer Name = drinus-PC | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante iexplore.exe, version : 8.0.7601.17514, horodatage : 0x4ce79912 Nom du module défaillant : uxcontacts.dll, version : 15.4.3555.308, horodatage : 0x4f5960ea Code d’exception : 0xc0000005 Décalage d’erreur : 0x0006512c ID du processus défaillant : 0x144c Heure de début de l’application défaillante : 0x01cdc580809baac1 Chemin d’accès de l’application défaillante : C:\Program Files\Internet Explorer\iexplore.exe Chemin d’accès du module défaillant: C:\Program Files\Windows Live\Shared\uxcontacts.dll ID de rapport : a28fbda4-31c8-11e2-9bf1-00245460adf6 Error - 11/18/2012 5:42:00 PM | Computer Name = drinus-PC | Source = Application Hang | ID = 1002 Description = Le programme iexplore.exe version 8.0.7601.17514 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance. ID de processus : 15c0 Heure de début : 01cdc5807f1a0bd5 Heure de fin : 159 Chemin d’accès de l’application : C:\Program Files\Internet Explorer\iexplore.exe ID de rapport : Error - 11/19/2012 2:04:43 PM | Computer Name = drinus-PC | Source = SideBySide | ID = 16842785 Description = La création du contexte d’activation a échoué pour « C:\Program Files\Samsung\Samsung Support Center\Drv\drv2x64\KStartMem.exe.Manifest ». Assembly dépendant Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé. Error - 11/19/2012 2:05:09 PM | Computer Name = drinus-PC | Source = SideBySide | ID = 16842785 Description = La création du contexte d’activation a échoué pour « C:\Program Files\Samsung\BatteryLifeExtender\Drv\SABI2x64\KStartMem.exe.Manifest ». Assembly dépendant Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé. [ System Events ] Error - 1/31/2014 10:14:28 AM | Computer Name = drinus-PC | Source = Service Control Manager | ID = 7001 Description = Le service Client DNS dépend du service Pilote de prise en charge TDI héritée NetIO qui n’a pas pu démarrer en raison de l’erreur : %%31 Error - 1/31/2014 10:14:28 AM | Computer Name = drinus-PC | Source = Service Control Manager | ID = 7001 Description = Le service Assistance NetBIOS sur TCP/IP dépend du service Ancillary Function Driver for Winsock qui n’a pas pu démarrer en raison de l’erreur : %%31 Error - 1/31/2014 10:14:28 AM | Computer Name = drinus-PC | Source = Service Control Manager | ID = 7001 Description = Le service Service Interface du magasin réseau dépend du service NSI proxy service driver. qui n’a pas pu démarrer en raison de l’erreur : %%31 Error - 1/31/2014 10:14:28 AM | Computer Name = drinus-PC | Source = Service Control Manager | ID = 7001 Description = Le service Station de travail dépend du service Service Interface du magasin réseau qui n’a pas pu démarrer en raison de l’erreur : %%1068 Error - 1/31/2014 10:14:28 AM | Computer Name = drinus-PC | Source = Service Control Manager | ID = 7001 Description = Le service Assistance IP dépend du service Service Interface du magasin réseau qui n’a pas pu démarrer en raison de l’erreur : %%1068 Error - 1/31/2014 10:14:28 AM | Computer Name = drinus-PC | Source = Service Control Manager | ID = 7001 Description = Le service Wrapper et moteur de mini-redirecteur SMB dépend du service Sous-système de mise en mémoire tampon redirigée qui n’a pas pu démarrer en raison de l’erreur : %%31 Error - 1/31/2014 10:14:28 AM | Computer Name = drinus-PC | Source = Service Control Manager | ID = 7001 Description = Le service Mini-redirecteur SMB 1.x dépend du service Wrapper et moteur de mini-redirecteur SMB qui n’a pas pu démarrer en raison de l’erreur : %%1068 Error - 1/31/2014 10:14:28 AM | Computer Name = drinus-PC | Source = Service Control Manager | ID = 7001 Description = Le service Mini-redirecteur SMB 2.0 dépend du service Wrapper et moteur de mini-redirecteur SMB qui n’a pas pu démarrer en raison de l’erreur : %%1068 Error - 1/31/2014 10:14:28 AM | Computer Name = drinus-PC | Source = Service Control Manager | ID = 7001 Description = Le service Connaissance des emplacements réseau dépend du service Service Interface du magasin réseau qui n’a pas pu démarrer en raison de l’erreur : %%1068 Error - 1/31/2014 10:14:33 AM | Computer Name = drinus-PC | Source = Service Control Manager | ID = 7026 Description = Le pilote de démarrage système ou d’amorçage suivant n’a pas pu se charger : AFD aswRdr aswRvrt aswSnx aswSP aswVmm DfsC discache NetBIOS NetBT nsiproxy Psched rdbss SABI spldr tdx vwififlt Wanarpv6 WfpLwf < End of report >