ÿþOTL Extras logfile created on: 30/11/2017 23:05:05 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\fauquant\Desktop 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.18838) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 3,44 Gb Total Physical Memory | 2,04 Gb Available Physical Memory | 59,35% Memory free 4,75 Gb Paging File | 3,21 Gb Available in Paging File | 67,69% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 456,15 Gb Total Space | 423,74 Gb Free Space | 92,89% Space Free | Partition Type: NTFS Drive D: | 457,11 Gb Total Space | 456,96 Gb Free Space | 99,97% Space Free | Partition Type: NTFS Computer Name: PC-SALON | User Name: fauquant | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{17460C50-390D-4567-A503-44F34B75C2E6}" = rport=10243 | protocol=6 | dir=out | app=system | "{293E6338-5E58-4FE4-A8BB-7758623A9B0C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{540DAFA5-3E5A-485D-92B0-7E3CDE968F6B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{62C240E7-5A43-41EC-B1EB-29B7F999737A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{C4A7022D-C2D7-48DD-9D6E-F8373D93DCBD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{DB6E4553-CEAE-4FC3-96A5-C3CA2D4C3F29}" = lport=10243 | protocol=6 | dir=in | app=system | "{E0E60FA0-0911-4D73-9F69-BC441B9A60C4}" = lport=2869 | protocol=6 | dir=in | app=system | "{F2D5D1C1-136A-464C-AD10-63404E314DCB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{FC7005A9-5212-472E-9B11-93A3EA2A2C55}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00A3BC5D-6592-4397-8DBC-227D0232148E}" = dir=in | name=@{microsoft.skypeapp_1.3.0.112_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{03B4C39D-0159-45E0-9A20-AF51B648BF32}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\powerdvd12.exe | "{043F2CB8-02BB-40DC-B984-6A115F0F2E8D}" = dir=in | name=microsoft minesweeper | "{074132DC-BE2A-410D-BF1A-0B584A267ACB}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.21234_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{0AB6D91D-BE56-4550-AA58-DF1EB79DC158}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | "{0D479832-A895-47C8-ABD9-2508ECF306C0}" = dir=out | name=@{microsoft.bingweather_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{12AD822F-251A-4F85-8EC9-BC59139F03A3}" = dir=out | name=packard bell explorer | "{16F33761-3249-46DF-97CE-A7D82B5CB6EE}" = dir=out | name=@{microsoft.bingmaps_1.6.1821.2624_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{1D1C8596-9490-4445-9CE5-B4B13A406485}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{1DB655AC-FFE4-4A4C-860D-E2461224F362}" = protocol=6 | dir=out | app=system | "{2158A903-EEC7-40E6-8DBC-819AFAFD4BBE}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{26CAA09D-183C-4FF5-A8DB-ECD6D14DF9B6}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\kernel\dms\clmsserverpdvd12.exe | "{2728C1D6-75F6-4629-ADA8-30B2F8211E55}" = protocol=6 | dir=in | app=c:\program files (x86)\spotify\spotify.exe | "{2909F116-B923-4E9E-ABFE-3D3DFC0FE98C}" = dir=out | name=7digital music store | "{29CD97DF-264B-4551-9266-E3E3F3839EF9}" = dir=out | name=shark dash | "{2E1FEBE6-B1BB-4290-8DE8-56294C153044}" = dir=out | name=microsoft mahjong | "{2F2CC1FA-861B-40B6-A3BC-E571EDB4AB24}" = dir=out | name=@{microsoft.xboxlivegames_1.3.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{32B4CF48-B0CC-47E6-96AA-17964B2C4C9A}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\kernel\dmr\powerdvd12dmrengine.exe | "{3318431C-E695-4297-A382-9D224FA99ED3}" = dir=out | name=newsxpresso | "{33A29CC3-A54A-41C4-9D69-C9FDBB83F517}" = dir=out | name=microsoft solitaire collection | "{33A8672A-569D-486B-A569-301CDE7E5386}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{3B09842B-C7C3-493A-A7D6-AC4DE37317C2}" = dir=in | name=microsoft solitaire collection | "{3C1DDE86-B746-46A8-B2B0-A99D53377184}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{3F489027-5846-48B5-95A0-F2E46300DF00}" = dir=out | name=tunein radio | "{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | "{42F400A9-58FE-40E2-9A8D-E13BB631429A}" = dir=out | name=@{microsoft.reader_6.2.9200.22277_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{49E18620-38A0-4385-8CFD-8FE9E3DBD63C}" = dir=out | name=juniper networks junos pulse | "{4AB2C7F2-A8CE-4BB6-87E9-A32E1FF78852}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe | "{4E016F9B-436A-46E4-95EA-1CEA250501FB}" = dir=in | name=taptiles | "{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{556876B4-3E08-4A7F-845A-C7F678788B7A}" = dir=in | name=microsoft mahjong | "{55F5E3FF-13C3-4CDC-8EF5-6799A4EB2553}" = dir=out | name=windows_ie_ac_001 | "{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | "{58E83607-AE8E-43E5-BF81-44A485C45ABB}" = dir=out | name=- games app - | "{5916CC3A-AAE7-4B8C-A909-F408F4038A53}" = dir=out | name=@{microsoft.bingsports_3.0.4.345_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} | "{5C61F69F-AF33-47D8-8638-A10F8817ECF3}" = dir=out | name=@{microsoft.bingfinance_3.0.4.344_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} | "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | "{5F73DB46-A0CB-49E1-B028-938F62882546}" = protocol=17 | dir=in | app=c:\program files (x86)\spotify\data\spotifywebhelper.exe | "{5FD72B52-D239-4406-8EEA-E816865E7E1A}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | "{678AB335-017D-4EE6-BE5C-5A5A96CF7365}" = dir=out | name=@{microsoft.bingnews_3.0.4.344_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | "{69262661-E817-4416-8D4A-A082FAD56A83}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{6A1A583A-3C62-4493-8770-53025511B41F}" = dir=out | name=check point vpn | "{6AFB4E32-1C54-46C1-8054-473422D1063B}" = dir=in | name=check point vpn | "{6CD20600-AC9C-4273-A8B0-9ACE32B4D68C}" = dir=out | name=f5 vpn | "{6DDB278B-55BC-4426-B864-6008BF976064}" = dir=out | name=wordament | "{6F313BA4-3F6C-4223-A4F6-F1F713C8BB9D}" = dir=out | name=@{microsoft.skypeapp_1.3.0.112_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} | "{6F467C67-16E9-4755-BE08-04A49C9D5A5F}" = dir=out | name=cut the rope | "{6F6ABAB6-3C1D-4138-9227-FBA384661F6B}" = dir=out | name=windows_ie_ac_001 | "{6FB0B629-C74C-48EA-858B-9C68E1570362}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{718C0D71-4477-4EB3-8F52-B44E41DCE38B}" = dir=in | name=sonicwall mobile connect | "{7745A2B8-3261-4316-A540-CD1B63092E19}" = dir=in | name=onenote | "{79017D94-8207-4A84-B565-5D733CCA2E89}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe | "{7CB857A3-59A3-4C08-A951-5630C5F9B149}" = dir=out | name=weatherbug.a | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{809DDEE8-6475-42E8-85C5-3AF0B538AF54}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{831604A4-2FA5-4C5B-ACDE-283DDB0C2A71}" = dir=out | name=@{microsoft.bingnews_2.0.0.320_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{84CFB2A4-F915-4ECE-A197-600F6BA2DB3F}" = dir=out | name=windows_ie_ac_001 | "{8A147640-DF4F-4170-8CBD-AF34033F7C95}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\movie\powerdvd.exe | "{8C7A72AA-5F00-4FE8-9112-6A603E031DF1}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{8E7D6856-9525-47CE-9D27-744DE0AAE7DA}" = dir=in | name=@{microsoft.reader_6.2.9200.22277_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{96266C0E-C57F-4D2A-9A61-079E2B3B322F}" = dir=out | name=@{microsoft.bingtravel_2.0.0.326_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{97635835-4746-4920-B8B8-6FEC543FD739}" = protocol=6 | dir=in | app=c:\program files (x86)\nero\nero 12\nero backitup\backitup.exe | "{98B959AF-2EFC-4605-9489-4B712E20083E}" = dir=out | name=onenote | "{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{9FDE8D7F-CDB5-4BF0-A8B1-FC1B3968704E}" = dir=in | name=packard bell explorer | "{A5AB38E3-5BBE-4220-9AFD-A52A9BB76CCC}" = dir=out | name=the treasures of montezuma 3 | "{A66486B1-4DCA-453E-AFBA-14B64461711E}" = dir=out | name=@{microsoft.bingweather_3.0.4.350_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} | "{A6E5E419-4965-4F45-84D1-32DC50C6626B}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.21234_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | "{AA12F8FE-A238-4F4E-B0CF-901EC4A6A507}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{AA1C6314-64A5-48DF-9D7D-4CAB884645E3}" = protocol=17 | dir=in | app=c:\program files (x86)\spotify\spotify.exe | "{AF3CC1F7-9A75-4232-8ACB-E8C9073CD014}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\powerdvd12ml.exe | "{AF967717-AF8E-4768-BEE9-30952501B37E}" = dir=out | name=taptiles | "{B41BF8B2-6F9A-4AB3-B744-3211B40DE1D5}" = dir=out | name=@{microsoft.zunemusic_1.5.216.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{B550CEA5-AA8E-4F8F-BBD5-DC6EA164D647}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{BB269361-769A-4821-BDC5-DFB2559F4836}" = dir=out | name=@{microsoft.bingfinance_2.0.0.320_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{C3329F2B-4F2E-4944-9CE2-75991CF8AC06}" = dir=out | name=sonicwall mobile connect | "{C6272FAC-4A32-49FA-A066-7839C143DC2A}" = dir=out | name=pinball fx2 | "{CBF073EF-B1FB-4B55-AACB-CAE920822136}" = dir=out | name=@{microsoft.zunevideo_1.5.909.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{CE0E4179-9DB7-4D3C-85FE-31F8540F09C9}" = dir=in | name=juniper networks junos pulse | "{D0904174-6386-49BE-9145-E87E82960D0D}" = dir=in | name=f5 vpn | "{D185184F-2AC7-43AF-9CF8-47330536CBA7}" = dir=out | name=@{microsoft.bingsports_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{D35E1FB4-3506-4C26-A52E-A7F20A4BF29C}" = dir=out | name=skype | "{D5AD3DA4-87C8-44D9-B51D-B2D5C2AAF7E5}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | "{D8656F1C-9650-40B0-9E4B-4F8DAFAADD8C}" = dir=out | name=txtr ebooks | "{D9888808-5DA9-4986-B8C2-8B2C214D6E96}" = dir=out | name=@{microsoft.zunevideo_2.6.446.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{DA8D5FBD-3D6B-4D5D-9BC7-BB31A7CAF603}" = dir=out | name=@{microsoft.zunemusic_2.6.672.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | "{DD74C3C3-F54E-4F8E-9B65-F7DF6B2C16D1}" = dir=out | name=ebay | "{DE80D01E-CF7A-40D1-8ABF-8F72DCCE30A4}" = dir=out | name=@{microsoft.bingtravel_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | "{E0673995-5F6D-437E-AC18-7347AE90EE8F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{E62E30CD-0087-4689-B684-36A41E8707D7}" = dir=in | name=skype | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{EC459E61-A2D9-4494-8766-92510F9E5D41}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd12\powerdvd12agent.exe | "{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | "{EC978F73-682F-4061-8328-678E34F64756}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{F457E89B-B8B9-44A6-BEA6-158560160B21}" = dir=out | name=microsoft minesweeper | "{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | "{F77711A2-4023-4DF1-B5D8-94CF879DF082}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | "{FBB35032-8A15-4A4C-A851-93EE1BDC1B50}" = protocol=6 | dir=in | app=c:\program files (x86)\spotify\data\spotifywebhelper.exe | "{FCE55D30-29F7-4C71-A842-ACF31F03A1F5}" = dir=in | name=pinball fx2 | "{FD2E20EF-9EBE-4418-9096-50E2D787287C}" = protocol=17 | dir=in | app=c:\program files (x86)\nero\nero 12\nero backitup\backitup.exe | "{FDFB0CF4-245A-4959-94E5-ECDDFBE75EFA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "TCP Query User{2CD22875-CBD6-4081-B60B-96DB6CD83012}C:\program files (x86)\acer remote\arcserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\acer remote\arcserver.exe | "TCP Query User{373A8CDB-AD0A-4CEE-8D96-EEF610751159}C:\program files (x86)\acer remote\arcserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\acer remote\arcserver.exe | "TCP Query User{73AB3F12-5CA3-44F8-B25B-80D6846EA5EE}C:\program files (x86)\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files (x86)\emule\emule.exe | "TCP Query User{A545399D-6CBE-423A-B905-57A77CA58607}C:\program files (x86)\dap\dap.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dap\dap.exe | "UDP Query User{09291050-5AA4-4C6A-97F2-79C5B392F91D}C:\program files (x86)\acer remote\arcserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\acer remote\arcserver.exe | "UDP Query User{557BB3F0-9744-4F2D-A64B-4577433DEDA3}C:\program files (x86)\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files (x86)\emule\emule.exe | "UDP Query User{AAD6BCF5-CD96-4194-B00D-0547D5520541}C:\program files (x86)\acer remote\arcserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\acer remote\arcserver.exe | "UDP Query User{D78BA753-EA30-49EB-81B7-526CC87285BB}C:\program files (x86)\dap\dap.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dap\dap.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}" = Packard Bell Recovery Management "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{4B3EF5E6-9A2C-0A1B-C61C-B1FD444B84BC}" = ccc-utility64 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{710655AE-52FC-174A-912A-9B70D7507A2C}" = ccc-utility64 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{91F52DE4-B789-42B0-9311-A349F10E5479}" = Packard Bell Power Management "{9C82656B-D8D4-9BAB-B932-B6AC8B2B70E3}" = AMD Accelerated Video Transcoding "{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 "{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 "{E3AB2F4D-B540-437B-4E4F-3A3C344C3B2A}" = AMD Catalyst Install Manager "{E7ACB435-E0B4-4770-77DE-ED38887CD133}" = AMD Fuel "8461-7759-5462-8226" = Vuze [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{070232F8-068B-1FF6-B5C4-F8F38E09C7E1}" = CCC Help Turkish "{0B311221-05A5-4766-8D03-7A6446794156}" = Nero RescueAgent Help (CHM) "{0C87DBFD-50CF-81A0-FFD7-12B5FEDDD030}" = CCC Help Swedish "{0E4630AF-0AB7-440E-A978-1A78FC4F43B9}" = Nero Launcher "{104DE091-6C4F-C5A9-F619-5D6C965A0296}" = CCC Help Chinese Traditional "{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 "{1A3E16DF-113C-D0F2-2602-D38E93AA9749}" = CCC Help Spanish "{1CCF73DE-3780-778F-F9BB-7A085C7C3C30}" = CCC Help Hungarian "{1D41A492-FB42-7C86-4EB1-28905978B4EB}" = Catalyst Control Center InstallProxy "{1E496A68-4943-424E-829D-5C3C85B7B8F2}" = Realtek USB Card Reader "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FFDB327-2DD7-5F59-6C09-F96277E0DD0F}" = CCC Help Norwegian "{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 "{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype"! 7.3 "{25A3B953-1423-3F15-640E-B620DD0F419A}" = Catalyst Control Center - Branding "{285C9F30-3BF8-697B-BD1D-353435E94B78}" = CCC Help Hungarian "{29967A7C-6E18-91CD-BBE4-9C09F401E950}" = CCC Help Italian "{2F204D9B-A610-92E8-8AE3-3775897AFCAD}" = CCC Help English "{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 "{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App "{3063FD40-0D1A-9149-5856-72B8157573C5}" = CCC Help Czech "{39061334-CFFE-4795-B11F-2823257A555B}" = CCC Help Danish "{3AAB08A3-F129-4BD5-B409-AE674F93759D}" = Prerequisite installer "{3D9CB654-99AD-4301-89C6-0D12A790767C}" = Identity Card "{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup "{4CA8F973-6377-4ABF-9ED5-CC2323B3C000}" = Nero BackItUp 12 Essentials OEM.a01 "{4CCD823D-B71B-F369-F16A-6FE643087C55}" = CCC Help Chinese Traditional "{54D05374-2428-7BE0-58CD-CE8031163DE6}" = CCC Help Russian "{5974B773-C39A-6F89-032F-14DEB2A4BA2B}" = AMD VISION Engine Control Center "{5B461DCA-A55C-63C0-B3E6-B213B03E66D7}" = CCC Help Thai "{5C6AFE98-08BF-086A-300D-18F77D284966}" = CCC Help Swedish "{5C757800-27E8-2AE3-889A-8B959AE689F8}" = CCC Help Japanese "{5D2B5E19-C333-4519-3D32-AAB8EEE9ACA4}" = AMD Catalyst Control Center "{5D3EC645-B957-36A1-068A-FE8450963669}" = CCC Help Spanish "{61B90A4D-8CC9-2FED-2495-AC8C9467C984}" = CCC Help Norwegian "{641E05BB-5A07-8543-3B2F-E99BE787BB1F}" = CCC Help Italian "{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update "{6A9540AF-3E24-D7D8-7702-2E106509CF9C}" = CCC Help Portuguese "{6EE98A5B-1C7D-479B-D126-2275971BA0B0}" = CCC Help Turkish "{6F640E9F-785B-4AD2-991F-C52F4EC321AF}" = Catalyst Control Center - Branding "{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-packardbell" = WildTangent Games App "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{748E2B7C-5B7C-884D-9E03-EA01BA54EC78}" = CCC Help Korean "{7C5B13DA-6A68-86C7-ED29-610CA0F49555}" = CCC Help French "{7E021F53-7DB6-2E6D-BC30-9DD10898ED9E}" = CCC Help Japanese "{80680785-2EE1-053F-9CD3-4B2C904596EE}" = Catalyst Control Center InstallProxy "{81523678-E998-C377-C4CA-EEB5DFA842D8}" = CCC Help Chinese Standard "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{90150000-0138-0409-0000-0000000FF1CE}" = Microsoft Office "{91589413-6675-4C27-8AFC-EFB9103B90A5}" = eBay Worldwide "{95B8F519-8C35-9010-A63C-51B3E0EE8D4E}" = CCC Help Dutch "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A2D43081-CF7B-4637-A9F3-E2651AA5C4A8}" = Nero RescueAgent "{A3806AB7-AB46-7672-A825-F9AE0DE6910A}" = CCC Help Finnish "{A6DC88AD-501A-44BC-884D-57435F972E2C}" = Hotkey Utility "{ABC88553-8770-4B97-B43E-5A90647A5B63}" = Nero ControlCenter "{AC76BA86-7AD7-1036-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Français "{B079957C-3276-4B9F-DB08-D1CA8C090D9E}" = CCC Help Greek "{B12BE177-DC00-5746-3AB9-91CD090AF555}" = Catalyst Control Center Localization All "{B352ECA3-943B-D7C2-C1E9-760F365DBA78}" = CCC Help Polish "{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" = CyberLink PowerDVD 12 "{BEB0EE39-1081-FBB2-916E-B8675DAD62D4}" = CCC Help Dutch "{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components "{BF5509A0-250A-25EA-0C19-61505E9EBA13}" = CCC Help Chinese Standard "{C4EE2BA3-EEA5-9650-86E0-0405ECA5C22C}" = CCC Help Thai "{C69EA753-0D3F-E48B-8C98-7F6310DC29B8}" = CCC Help German "{C994C746-C6D0-4EBA-B09E-DF7B18381B69}" = Nero ControlCenter Help (CHM) "{CA2B81C9-7954-CA01-8765-4C68C6F63E87}" = CCC Help French "{CB95FCB7-4FDF-6FFF-A118-9726353E1C28}" = CCC Help Finnish "{CD285FFA-58DA-81C5-95E8-47C2FF0DE879}" = Catalyst Control Center Profiles Mobile "{DA2D3078-A58C-45E8-8EE0-18B8BE6B34F7}" = Nero BackItUp "{DF296B54-EDB4-FD6C-4877-91E1784EC097}" = CCC Help German "{DF63A8EF-FDA6-BA5E-AF46-08A6E0DECA3B}" = CCC Help Russian "{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso 6.5 "{EB766D4A-C56C-946D-F74D-43C78FE4521E}" = CCC Help Korean "{ED0D7699-1943-0C29-7465-6530F8DE2DA2}" = CCC Help Polish "{EDA5BB56-AAF4-6889-AD8E-E25A17BD140B}" = CCC Help Czech "{EE26E302-876A-48D9-9058-3129E5B99999}" = Live Updater "{EEF14371-2D24-5A2D-0EF2-22010DB4CFA6}" = CCC Help Danish "{EF0D1292-8FC1-41BE-9740-DBC134F66415}" = Nero BackItUp Help (CHM) "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 "{FDD69799-37B2-9ACE-F70C-ABD1F96FD04C}" = CCC Help Portuguese "{FDE96D85-2B23-0FB0-A497-30E62596C60A}" = Catalyst Control Center Localization All "{FDF2FE33-426D-45C2-4E70-76C162F1B790}" = CCC Help English "{FE1B0B92-6744-8A7D-804E-4759F2E06615}" = CCC Help Greek "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" = CyberLink PowerDVD 12 "InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso 6.5 "NARA" = Norton Online Backup ARA "NIS" = Norton Internet Security "Spotify" = Spotify "WildTangent wildgames Master Uninstall" = WildTangent Games "WTA-42bcad72-1d61-45ad-bbb9-df4ad08574d2" = John Deere Drive Green "WTA-43674f13-a90c-42cf-9990-bc120ccaead4" = Governor of Poker 2 Premium Edition "WTA-471562d6-75a2-4cf5-8923-5299ce4b3689" = Magic Academy "WTA-5b2e68c5-2e43-4b38-84f0-16fda12864b8" = Bejeweled 3 "WTA-910dfdea-5881-4033-a303-196af7a0bb40" = Plants vs. Zombies - Game of the Year "WTA-b81e33f3-3502-4f78-8610-a9afc4a17582" = Jewel Match 3 "WTA-c442dc76-1163-446c-b2ce-985fdfb4af85" = Delicious: Emily's Childhood Memories Premium Edition "WTA-d71419f3-e0ee-491c-8f8e-7cd23fc85cbf" = Tales of Lagoona "WUCCCApp" = Catalyst Control Center [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 25/11/2017 22:14:18 | Computer Name = pc-salon | Source = Application Error | ID = 1000 Description = Nom de l application défaillante atieclxx.exe, version : 6.14.11.1143, horodatage : 0x51488c11 Nom du module défaillant : atieclxx.exe, version : 6.14.11.1143, horodatage : 0x51488c11 Code d exception : 0xc0000005 Décalage d erreur : 0x000000000002ea19 ID du processus défaillant : 0xcec Heure de début de l application défaillante : 0x01d3665c3f670ba7 Chemin d accès de l application défaillante : C:\WINDOWS\system32\atieclxx.exe Chemin d accès du module défaillant: C:\WINDOWS\system32\atieclxx.exe ID de rapport : 81a1fb77-d24f-11e7-be73-f80f41aeb600 Nom complet du package défaillant : ID de l application relative au package défaillant : Error - 27/11/2017 15:42:23 | Computer Name = pc-salon | Source = VSS | ID = 13 Description = Error - 27/11/2017 15:42:23 | Computer Name = pc-salon | Source = VSS | ID = 8193 Description = Error - 27/11/2017 15:42:23 | Computer Name = pc-salon | Source = VSS | ID = 13 Description = Error - 27/11/2017 15:42:23 | Computer Name = pc-salon | Source = VSS | ID = 8193 Description = Error - 27/11/2017 15:42:23 | Computer Name = pc-salon | Source = System Restore | ID = 8193 Description = Error - 27/11/2017 15:42:37 | Computer Name = pc-salon | Source = VSS | ID = 13 Description = Error - 27/11/2017 15:42:37 | Computer Name = pc-salon | Source = VSS | ID = 8193 Description = Error - 27/11/2017 15:42:37 | Computer Name = pc-salon | Source = System Restore | ID = 8193 Description = Error - 27/11/2017 16:25:19 | Computer Name = pc-salon | Source = Microsoft-Windows-Immersive-Shell | ID = 5973 Description = Échec de l activation de l application winstore_cw5n1h2txyewy!Windows.Store avec l erreur : -2144927142 Pour plus d informations, voir le journal Microsoft-Windows-TWinUI/Opérationnel. [ System Events ] Error - 27/11/2017 16:31:09 | Computer Name = pc-salon | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000 Description = Le module d extensibilité WLAN n a pas pu démarrer. Chemin d accès du module : C:\WINDOWS\system32\Rtlihvs.dll Code d erreur : 126 Error - 27/11/2017 17:38:42 | Computer Name = pc-salon | Source = EventLog | ID = 6008 Description = L arrêt système précédant à 22:37:15 le ?27/?11/?2017 n était pas prévu. Error - 27/11/2017 17:38:52 | Computer Name = pc-salon | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000 Description = Le module d extensibilité WLAN n a pas pu démarrer. Chemin d accès du module : C:\WINDOWS\system32\Rtlihvs.dll Code d erreur : 126 Error - 27/11/2017 18:26:10 | Computer Name = pc-salon | Source = EventLog | ID = 6008 Description = L arrêt système précédant à 23:24:43 le ?27/?11/?2017 n était pas prévu. Error - 27/11/2017 18:26:16 | Computer Name = pc-salon | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000 Description = Le module d extensibilité WLAN n a pas pu démarrer. Chemin d accès du module : C:\WINDOWS\system32\Rtlihvs.dll Code d erreur : 126 Error - 27/11/2017 19:33:56 | Computer Name = pc-salon | Source = Schannel | ID = 36887 Description = Une alerte irrécupérable a été reçue du point de terminaison distant. Le code d alerte irrécupérable défini par protocole de TLS est 20. Error - 28/11/2017 16:42:41 | Computer Name = pc-salon | Source = DCOM | ID = 10010 Description = Error - 28/11/2017 18:20:29 | Computer Name = pc-salon | Source = Schannel | ID = 36887 Description = Une alerte irrécupérable a été reçue du point de terminaison distant. Le code d alerte irrécupérable défini par protocole de TLS est 20. Error - 28/11/2017 18:30:50 | Computer Name = pc-salon | Source = EventLog | ID = 6008 Description = L arrêt système précédant à 23:29:44 le ?28/?11/?2017 n était pas prévu. Error - 28/11/2017 18:30:51 | Computer Name = pc-salon | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000 Description = Le module d extensibilité WLAN n a pas pu démarrer. Chemin d accès du module : C:\WINDOWS\system32\Rtlihvs.dll Code d erreur : 126 < End of report >