ÿþOTL Extras logfile created on: 20/05/2018 12:29:29 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\user\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.18837) Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy 7,91 Gb Total Physical Memory | 4,37 Gb Available Physical Memory | 55,20% Memory free 15,81 Gb Paging File | 11,99 Gb Available in Paging File | 75,79% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 931,41 Gb Total Space | 622,09 Gb Free Space | 66,79% Space Free | Partition Type: NTFS Computer Name: USER-PC | User Name: user | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (All) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation) .hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" .inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation) .txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .bat [@ = batfile] -- "%1" %* .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cmd [@ = cmdfile] -- "%1" %* .com [@ = ComFile] -- "%1" %* .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .exe [@ = exefile] -- "%1" %* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" .inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .pif [@ = piffile] -- "%1" %* .reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation) .scr [@ = scrfile] -- "%1" /S .txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office15\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office15\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation) htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office15\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office15\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [color=#E56717]========== Firewall Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{13A9929A-D8A4-40D1-83C8-3A83DDE21565}" = lport=1688 | protocol=6 | dir=in | name=kms emulator port | "{158E6670-3702-40EF-9E71-B8D204F6348B}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamnetworkservice.exe | "{172D9F0C-F09D-4CBA-8458-E3AF15F1A2DD}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1B0CB28F-FB87-4690-8DA8-69F4694D6CCE}" = rport=137 | protocol=17 | dir=out | app=system | "{1D671D2A-98E6-4D8D-ACC6-80E30727114B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{27CFED7E-2F44-4D91-BDFF-9F61736C818A}" = lport=10243 | protocol=6 | dir=in | app=system | "{28B39806-ACF5-4D24-93B8-ED9B4A9B930F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{28C0FFA0-3453-4051-91DD-A1818D6BF263}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{2DFBA587-DC3B-42C7-AC65-9703C5D03517}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{32E1D10C-7AB1-4EDF-A3C8-36BAE01038EA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{341E7E35-17BC-4C40-B79A-755C221E21E3}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{3472F449-705A-4958-8F44-542317E61877}" = rport=139 | protocol=6 | dir=out | app=system | "{34C009F7-059F-4FDD-98D5-672CE6F63DCC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{4184CF34-0F14-45AF-8101-26B9087DB5DF}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4611E910-D0C9-434A-9FD1-BB2829CE27D0}" = lport=2869 | protocol=6 | dir=in | app=system | "{475FE955-7894-40A1-AE83-A828D94F2EC5}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{5330D328-D2D4-4C97-A965-652872D32B60}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{54323F00-B12B-4AC6-9658-84DA76ABF522}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5B903075-09C7-4A1E-B757-8E64BA1B67CC}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamnetworkservice.exe | "{75AE45DA-C6B1-4DE2-8583-95C2212B71CA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{7A389623-AE7B-4F32-A413-4B789FA634B2}" = lport=137 | protocol=17 | dir=in | app=system | "{8DE416CD-570E-40A1-BC8E-82D5D3B99A4A}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{8E6CFCBB-DD4E-4333-8EBE-0BF029CC5E11}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{97FDC63C-6C79-4EA9-A835-43E5A16DE928}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{9D82DF5B-ACAC-4227-8FB7-893DEB161F51}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{A68CDFB9-1931-4CBE-B571-F9B5774A0C66}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{A885AF36-89FF-4F6F-93F1-A0FE0B3C7FB2}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe | "{A8B841BA-CEB4-4322-8402-25094DC22603}" = lport=138 | protocol=17 | dir=in | app=system | "{AC5D735B-FD50-4F25-A054-FD19FA499851}" = lport=35043 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{B2300EC0-3FE3-470B-9AFB-F1D3116C1A0F}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\avast software\browser\application\avastbrowser.exe | "{BD15F17D-BAF8-44F4-B189-DA74C480C3E4}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BD9EC0C7-4A28-4242-AAEE-B257016E084E}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{C6B428EF-FE10-4459-BC53-F11E5CE385A9}" = lport=139 | protocol=6 | dir=in | app=system | "{CF63E097-A4DC-4873-8C2B-C02BBBC26D4A}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{D1CEEFE7-463F-43D7-A55E-EFDEB73D5841}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{E04E8A41-BFB7-4CD3-AAAB-6D0C1782C6F2}" = rport=138 | protocol=17 | dir=out | app=system | "{EAC51058-82DA-4A6B-B266-59B467671DE5}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{EB884418-5379-4D0B-A63B-6FD7C37B9F23}" = lport=445 | protocol=6 | dir=in | app=system | "{EC6DF902-8140-4B3F-B91A-91D0E8BF1A09}" = lport=47995 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{ED9272F3-2460-44E0-B9B9-8DD9D9AE3B3F}" = lport=47998 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamuseragent.exe | "{EEB10191-8F21-4920-AAF2-9B262705E156}" = rport=10243 | protocol=6 | dir=out | app=system | "{F96E6E63-D254-4FFF-B613-5A9CBF550084}" = rport=445 | protocol=6 | dir=out | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02D42E30-34F2-4BDF-A384-D3CB21A4F6DB}" = dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer 3 tiberium wars\retailexe\1.9\cnc3game.dat | "{0319FFCE-0988-4DFD-B07B-2D913D352B27}" = protocol=6 | dir=in | app=c:\users\user\appdata\roaming\utorrent\utorrent.exe | "{03BBBE92-4256-44FD-A028-001944DC7CE6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{106250F5-E4AC-47C3-B4CD-6763A54D9ECC}" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "{109280DB-37B4-421C-ACF4-A423D97649C0}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft\skype for desktop\skype.exe | "{11647772-1795-40B5-B784-EA6A7610D985}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amnesia the dark descent\launcher.exe | "{13E1E1AC-4935-413E-BE06-61C8C35E17B2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\theredsolstice\bin\game.exe | "{15BE3946-B503-4F30-91B8-A6E89050AC0B}" = dir=in | app=c:\romstation\netplay\openvpn\bin\openvpn.exe | "{17331882-DFD1-4D67-95D8-F8C8DDB7C9FD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\theredsolstice\bin\game.exe | "{1FA162F9-6E10-4DEC-B686-2ED7F01BC1C5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war for the overworld\wfto.exe | "{23C01F35-7171-4E11-A29B-65B9C726C143}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | "{260F93E6-A59E-4DA0-BE39-BB7F7827BEDB}" = dir=out | app=c:\romstation\emulation\gamecube\dolphin x64\dolphin.exe | "{27477057-70B1-45E6-86E7-4A122B321286}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{2DBEA660-E43A-4826-85E7-9AEBC075D426}" = dir=out | app=c:\romstation\netplay\openvpn\bin\openvpn.exe | "{34EC2225-86D8-4943-87B8-8456D70F0B6D}" = protocol=6 | dir=out | app=system | "{37DAA7FD-540F-42CE-8687-8D4BFC51528C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iii complete\conquests\civ3conquests.exe | "{3941B8F7-3C15-4E2B-920F-928E82CFE145}" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "{3A4C852C-FC7C-43EB-A06D-AB2AD8847147}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\jotun\jotun.exe | "{3B7435A9-31AD-4200-AC7E-5EA20E5ADEBD}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{3C771EE9-4E83-4731-8641-403014202227}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{3DC089E7-9A91-4E09-B2FD-EC6CB539447C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deathtrap\deathtrap.exe | "{3EC782B6-7618-4D9D-8FB0-C7ABC8BBA2A3}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | "{3EDADFA3-970F-4E10-B38C-5A38A2A60631}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\hirezbridge.exe | "{4244CB72-21AC-41F6-BB40-E4A522DF608E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\modlauncher.exe | "{4316F01D-743A-45DF-A337-3C1BE394FCFA}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | "{46E7E818-7C21-4B60-B2CF-1AA1B72F110D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\hirezbridge.exe | "{4F70E620-4F50-4B31-A6AD-24A25E5AD696}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | "{5916DB28-C351-47F4-BF9B-3A630A60DF5D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer 3 tiberium wars\cnc3.exe | "{5AF2BAB1-A9D2-432F-B9DB-0FA45B1F8950}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer 3 - kane's wrath\cnc3ep1.exe | "{5C133160-B6F5-4300-A0E0-B7A5468CF36C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amnesia the dark descent\launcher.exe | "{5FFAE0A8-EFA8-4F8B-827D-098B16B59FE9}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "{66D69E58-84E3-49B2-ADFC-7C0F97B5A3F7}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{6878A71C-88B7-4923-9185-9AC659E83232}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{6AC1456E-ECB5-481A-BD65-07B6C33274D2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{6C6C52E5-6C49-4A06-9B97-ACC68E51ED87}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | "{6D72233D-DAB8-4B1B-BC70-B2760187A17A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{6FA2FC4A-FEE7-45E9-9FC4-ED477B731E7C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{77CF08A4-6F64-4E9E-A970-EC6938BF4B92}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm reactive drop\reactivedrop.exe | "{8184A9FF-6BD5-4308-8FBB-A5C522F93B0E}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | "{84C547A7-0DA9-4297-B773-B7AD0DBB2672}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{861FF0A9-0FE5-4118-8AEB-AAA3325D44C7}" = dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer 3 - kane's wrath\retailexe\1.2\cnc3ep1.dat | "{86ED9CF2-26AF-489E-84D5-7256F0832AE4}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{8705947D-C65E-4CFF-9294-4CC42A27B670}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | "{89F0F2D8-AA17-4B48-B6E5-97C5D7B6990D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8B650861-5A8B-4F63-8680-A3F347BA6DF8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\dashboard\bin\spitfiredashboard.exe | "{8DE77639-4846-48F7-B1D0-27C6CE05DEB7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | "{8E003CA4-FACF-4691-9D09-82C6E1FD1BED}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\super meat boy\supermeatboy.exe | "{8E4BD9FA-0671-4DF2-B396-A93F6D0F377D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\atlas reactor\glyphclient.exe | "{94B70357-888E-4F30-8C7A-D9842DD59C6A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\layers of fear\layers of fear.exe | "{98BFE6FC-BCF2-4E15-ACB7-49A3B599EBED}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer 3 tiberium wars\cnc3.exe | "{99C9070A-593F-46A7-8881-172DF6D6528E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout\falloutlauncher.exe | "{A212E5AF-B5B2-4E6B-ACE4-0D7F6330E154}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\layers of fear\layers of fear.exe | "{A5CD657B-9421-49B3-86E5-2DDCAFFE18DB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war for the overworld\wfto.exe | "{A8288F6A-B517-4BB5-A7DE-406F79D21919}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{AB18C6E7-047F-4347-A00B-1D7490A118FA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amnesia the dark descent\amnesia.exe | "{ABC6D8FF-909D-4BFC-8EB6-AF453E37F668}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dundefeternity\dungeondefenderseternity\binaries\win32\dundefgame.exe | "{AE89FF47-78FC-4F74-9C24-EFF6B20BDFF4}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "{B3A140E1-9409-45AC-B86E-82914AEE33FB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{B601C800-0833-49B8-9E86-7390534F0DDB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer 3 - kane's wrath\cnc3ep1.exe | "{BAB8E29D-A2B1-4B6A-9974-D8C38E642894}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft\skype for desktop\skype.exe | "{BD026639-047D-4F23-A85B-9EE507E5F36A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\dashboard\bin\spitfiredashboard.exe | "{BE9E3B0A-12AC-4ED8-B6F2-0BEF35207EA0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\super meat boy\supermeatboy.exe | "{C26DBAAB-3FA8-435B-B336-5B7FE399DA93}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{C2B45B59-1949-4AA6-9907-3372552AD698}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{C3CEC91B-4855-4425-86D1-EA6396660EAB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\jotun\jotun.exe | "{C80A73CD-2EC6-4991-BE45-3D074398207C}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | "{C83B6A2A-4DA4-4D27-B65D-1E8BEAE47C0E}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | "{CBE2D403-282E-4B0A-BA97-7E2C7DD8221B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe | "{D3BF67AA-2892-49B6-8B9F-41F8DD77C16A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\bin\cef\cef.win7\steamwebhelper.exe | "{D6AD3386-DBEC-481D-A083-D85B6868F19A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amnesia the dark descent\amnesia.exe | "{D99F185C-5596-4E10-B557-8A345F87BC76}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders 2\dundeflauncher.exe | "{DA5AE9D3-8A06-43F9-A738-660807C740B5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dundefeternity\dungeondefenderseternity\binaries\win32\dundefgame.exe | "{DC3C7FEF-426C-47C6-81EF-2BC14B2009E8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders 2\dundeflauncher.exe | "{DEC6C88D-0842-4048-9D52-BADD779AA6ED}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm reactive drop\reactivedrop.exe | "{E7326E7D-00F5-488B-B679-6B65A7693294}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E929B329-9F4F-4166-88BA-B00570A3AB04}" = protocol=17 | dir=in | app=c:\users\user\appdata\roaming\utorrent\utorrent.exe | "{E9626038-63AD-4915-8E7C-56FCDA748FA6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deathtrap\deathtrap.exe | "{E96BE447-D1CF-4E37-A39B-2F6D1EA16075}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout\falloutlauncher.exe | "{EB4CB2D6-2D8B-40A8-9A8D-A29A59DEBBD6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\atlas reactor\glyphclient.exe | "{EDDE26D1-AF7A-4AFD-BFE9-F57718373404}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{F6954B33-E3BE-42A1-B30E-5A2F5B2ADA3A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\modlauncher.exe | "{F6B5103B-0B92-435E-8568-23C6BBEC879E}" = dir=in | app=c:\romstation\emulation\gamecube\dolphin x64\dolphin.exe | "{F6DE04AE-D500-47E9-A32F-D3AA29431848}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{F757E6F2-DBAB-4E3A-8E5D-7EEAD7C38ACF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iii complete\conquests\civ3conquests.exe | "{FBC74C61-9941-4D19-823D-E0C8112DD28E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{FBEFAE62-C464-4115-A60E-E5BAE2E9D898}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{FD2EC78B-2539-4D4C-9F81-6B84887EBC39}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe | "{FF901ED2-CC5C-4478-B0CA-8E4CB5EB4A1C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\bin\cef\cef.win7\steamwebhelper.exe | "TCP Query User{09DAD542-FA8E-45C9-8DA3-8CE58D0986DF}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win64\paladins.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\paladins\binaries\win64\paladins.exe | "TCP Query User{09F65B7F-5B64-4B61-A6D9-D714908D144B}C:\program files (x86)\heroes of the storm\versions\base56705\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base56705\heroesofthestorm_x64.exe | "TCP Query User{0A64B1C3-2ABC-4B8A-98DA-518151B7EC1C}C:\program files (x86)\starcraft ii\versions\base47185\sc2_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base47185\sc2_x64.exe | "TCP Query User{0C5B958E-73E4-492F-8386-86848C6B06F4}C:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe | "TCP Query User{0E2EA925-97D1-4ED5-9034-BFF673E3C05F}C:\program files (x86)\starcraft ii\versions\base55958\sc2_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base55958\sc2_x64.exe | "TCP Query User{11E9BD63-54F2-4FC0-A10D-61FF76E77064}C:\users\user\desktop\ygopro-1.033.7-v2-percy\ygopro_vs_ai_debug.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\ygopro-1.033.7-v2-percy\ygopro_vs_ai_debug.exe | "TCP Query User{11F4494C-3163-4A3A-9CD2-4F1E8BF52982}C:\program files (x86)\heroes of the storm\versions\base64455\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base64455\heroesofthestorm_x64.exe | "TCP Query User{137F9BA4-E529-49DE-B5C4-B0BE59D8FE49}C:\program files (x86)\heroes of the storm\versions\base56361\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base56361\heroesofthestorm_x64.exe | "TCP Query User{1A672F70-3A87-45A7-8DBF-359274ECC5E7}C:\users\user\desktop\ygopro-1.033.7-v2-percy\ygopro_vs.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\ygopro-1.033.7-v2-percy\ygopro_vs.exe | "TCP Query User{1A7D6E53-7F13-40C8-BB94-D0CC63371BD1}C:\users\user\desktop\ygopro\ygopro_vs_links_beta\ygopro_vs_links.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\ygopro\ygopro_vs_links_beta\ygopro_vs_links.exe | "TCP Query User{1F19E150-DCA1-466A-B7BF-4157406AF2A8}C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe | "TCP Query User{2895310C-6CCC-4715-B844-5B1A1DA8415F}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe | "TCP Query User{32097F94-C946-4193-8BF8-BFD00EAE9711}C:\program files (x86)\heroes of the storm\versions\base57286\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base57286\heroesofthestorm_x64.exe | "TCP Query User{347C1B4B-A255-4B9A-8CC3-BC2B44CC2F41}C:\program files (x86)\battle.net\battle.net.exe" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | "TCP Query User{3AEC0710-7775-483E-BEEB-573C7DC5ED2F}C:\program files (x86)\heroes of the storm\versions\base64657\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base64657\heroesofthestorm_x64.exe | "TCP Query User{4BE866BC-C7C3-4F03-87F5-0A6FDF989208}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe | "TCP Query User{51AF49DA-3328-4A4E-9506-C8B914222373}C:\program files (x86)\starcraft ii - legacy of the void beta\versions\base37164\sc2_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii - legacy of the void beta\versions\base37164\sc2_x64.exe | "TCP Query User{742B817D-58D5-400F-A36E-24AA12291A19}C:\program files (x86)\steam\steamapps\common\awesomenauts\awesomenauts.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\awesomenauts\awesomenauts.exe | "TCP Query User{81DE933E-D2FC-49A9-BDC0-39D44A14A972}C:\program files (x86)\heroes of the storm\versions\base55288\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base55288\heroesofthestorm_x64.exe | "TCP Query User{907CC32E-4A52-4F87-A2B9-9B8B1D8CD126}C:\program files (x86)\heroes of the storm\versions\base55844\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base55844\heroesofthestorm_x64.exe | "TCP Query User{9A3A28FC-B580-412C-938B-0F68F9513E0E}C:\program files (x86)\srware iron\chrome.exe" = protocol=6 | dir=in | app=c:\program files (x86)\srware iron\chrome.exe | "TCP Query User{A04513B7-5F21-48DF-A4F0-337F4C13A8A9}C:\program files (x86)\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe | "TCP Query User{A869911F-7B7E-4E99-9872-E4F0608A7063}C:\program files (x86)\heroes of the storm\versions\base59657\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base59657\heroesofthestorm_x64.exe | "TCP Query User{BD193D44-85A7-46D6-91C9-1D5113D894D7}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe | "TCP Query User{BFA039F2-9135-40A3-AF43-7181B4E85FE9}C:\program files (x86)\destiny 2\destiny2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\destiny 2\destiny2.exe | "TCP Query User{C1DFBD4B-A973-4D59-A04F-105E10C38B84}C:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe | "TCP Query User{C56957A3-3541-40F3-AF28-894E19B13BE5}C:\program files (x86)\heroes of the storm\versions\base56175\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base56175\heroesofthestorm_x64.exe | "TCP Query User{D5D567BC-5D99-49EC-8110-A33345759A7B}C:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe | "TCP Query User{E2541172-E9E2-4884-95D9-232927D994CF}C:\program files (x86)\heroes of the storm\versions\base46690\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base46690\heroesofthestorm_x64.exe | "TCP Query User{E5A44959-A14F-4F02-9CDF-C499DA484F0C}C:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe | "TCP Query User{E75E5ABC-51E8-438A-9AEC-B8F59A184908}C:\program files (x86)\hearthstone\hearthstone.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe | "TCP Query User{EEE18220-56E0-46BD-BCE0-16688687E169}C:\program files (x86)\starcraft ii\versions\base56787\sc2_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base56787\sc2_x64.exe | "TCP Query User{F07ADA75-3F1D-41D1-847D-8AA04262E7B0}C:\users\user\desktop\ygopro\ygopro-1.033.7-v2-percy\ygopro_vs.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\ygopro\ygopro-1.033.7-v2-percy\ygopro_vs.exe | "TCP Query User{F18D3E61-81C3-4085-A91C-1D061BD0754F}C:\program files (x86)\heroes of the storm\versions\base57062\heroesofthestorm_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base57062\heroesofthestorm_x64.exe | "TCP Query User{F4139F70-3569-46C8-964D-F59A4654C7AE}C:\program files (x86)\steam\steamapps\common\command and conquer 3 tiberium wars\retailexe\1.9\cnc3game.dat" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer 3 tiberium wars\retailexe\1.9\cnc3game.dat | "TCP Query User{FABCAC2B-8BF2-4875-B9F6-416A405E63B7}C:\program files (x86)\starcraft ii\versions\base55505\sc2_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base55505\sc2_x64.exe | "UDP Query User{0E9D02C5-46DB-4B8A-B04D-1368303FE67B}C:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe | "UDP Query User{10B3996C-16A6-4769-A84C-065F022CB4B9}C:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe | "UDP Query User{15BCAA10-B3BC-4694-AD2B-E3349064EAAA}C:\program files (x86)\heroes of the storm\versions\base46690\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base46690\heroesofthestorm_x64.exe | "UDP Query User{183C3F2D-B95F-4EC8-8F53-B19D95C3B757}C:\program files (x86)\srware iron\chrome.exe" = protocol=17 | dir=in | app=c:\program files (x86)\srware iron\chrome.exe | "UDP Query User{300417A6-E51F-4E3B-A8D9-E3C399646633}C:\users\user\desktop\ygopro\ygopro-1.033.7-v2-percy\ygopro_vs.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\ygopro\ygopro-1.033.7-v2-percy\ygopro_vs.exe | "UDP Query User{332C8865-0D9B-4CC4-8918-0D3A272A9A5D}C:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe | "UDP Query User{343AD59B-6E84-49F0-881D-BA2C9A443131}C:\program files (x86)\heroes of the storm\versions\base57062\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base57062\heroesofthestorm_x64.exe | "UDP Query User{37514B13-B0A0-41DD-8AF4-42C41C8ECDA9}C:\users\user\desktop\ygopro\ygopro_vs_links_beta\ygopro_vs_links.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\ygopro\ygopro_vs_links_beta\ygopro_vs_links.exe | "UDP Query User{46A586CD-72D7-45B3-9D89-48A62794DD30}C:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war for the overworld\wftogame.exe | "UDP Query User{54AC4A70-A2A8-4DB1-BD1F-1450295A86F2}C:\program files (x86)\starcraft ii\versions\base56787\sc2_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base56787\sc2_x64.exe | "UDP Query User{5B540AD6-0CF0-4180-A414-B76595ABE3CE}C:\program files (x86)\starcraft ii - legacy of the void beta\versions\base37164\sc2_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii - legacy of the void beta\versions\base37164\sc2_x64.exe | "UDP Query User{5D44974E-E2B3-4070-AD3F-7043656034D1}C:\program files (x86)\starcraft ii\versions\base47185\sc2_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base47185\sc2_x64.exe | "UDP Query User{6AFFEF1A-3D40-43C7-B9E2-49BB8C836FEF}C:\users\user\desktop\ygopro-1.033.7-v2-percy\ygopro_vs.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\ygopro-1.033.7-v2-percy\ygopro_vs.exe | "UDP Query User{6CC69413-A840-43CB-A15E-A0DF6C6FA5D0}C:\program files (x86)\heroes of the storm\versions\base55288\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base55288\heroesofthestorm_x64.exe | "UDP Query User{6D43874F-E883-4907-8113-CFCB6F1F867F}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win64\paladins.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\paladins\binaries\win64\paladins.exe | "UDP Query User{7F0E502A-6BE3-4623-A58E-B9C6E3C7E681}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe | "UDP Query User{89C36530-B4CC-46F5-A1E0-0F9FD0C43524}C:\program files (x86)\heroes of the storm\versions\base59657\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base59657\heroesofthestorm_x64.exe | "UDP Query User{8A98B5EE-B513-471C-B7BE-52C2B200AD2C}C:\program files (x86)\destiny 2\destiny2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\destiny 2\destiny2.exe | "UDP Query User{9775930D-1911-459B-9CD2-19B53F954F54}C:\users\user\desktop\ygopro-1.033.7-v2-percy\ygopro_vs_ai_debug.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\ygopro-1.033.7-v2-percy\ygopro_vs_ai_debug.exe | "UDP Query User{97F8347A-41E4-4DC4-9F1E-116CA571E1AA}C:\program files (x86)\heroes of the storm\versions\base56705\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base56705\heroesofthestorm_x64.exe | "UDP Query User{9CF8D524-05FE-490C-86EB-F4D078229B0D}C:\program files (x86)\steam\steamapps\common\awesomenauts\awesomenauts.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\awesomenauts\awesomenauts.exe | "UDP Query User{9F89570F-4BC1-4C69-BE52-FD6092348B1C}C:\program files (x86)\heroes of the storm\versions\base56175\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base56175\heroesofthestorm_x64.exe | "UDP Query User{A6F6EA66-476D-464A-8DD1-220F6ADEB0A3}C:\program files (x86)\heroes of the storm\versions\base64657\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base64657\heroesofthestorm_x64.exe | "UDP Query User{A9FF837D-7D91-44C8-8DF5-E63AE5F02B52}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe | "UDP Query User{AC7D3C3C-D239-4C83-B97B-378215E4E235}C:\program files (x86)\steam\steamapps\common\command and conquer 3 tiberium wars\retailexe\1.9\cnc3game.dat" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer 3 tiberium wars\retailexe\1.9\cnc3game.dat | "UDP Query User{B02DE68D-9057-43ED-BB66-56A97CDA6785}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe | "UDP Query User{B9687D70-DC17-4C3D-811F-2A1B9F747527}C:\program files (x86)\heroes of the storm\versions\base56361\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base56361\heroesofthestorm_x64.exe | "UDP Query User{BFE5DF9D-659A-4642-B4DC-4BC301AA6B05}C:\program files (x86)\heroes of the storm\versions\base64455\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base64455\heroesofthestorm_x64.exe | "UDP Query User{C8EC1399-AB2D-4F45-87AA-F4DFCC29A64D}C:\program files (x86)\starcraft ii\versions\base55958\sc2_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base55958\sc2_x64.exe | "UDP Query User{C92E8222-A805-47CF-8F55-772E20E91C27}C:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcsmustdieunchained\binaries\win64\spitfiregame.exe | "UDP Query User{DF95D93F-9FA2-4212-99AE-529EF9C55CE5}C:\program files (x86)\heroes of the storm\versions\base55844\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base55844\heroesofthestorm_x64.exe | "UDP Query User{E721D7C8-9C39-4BF0-BC53-3E6045100856}C:\program files (x86)\battle.net\battle.net.exe" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | "UDP Query User{E860D462-82A7-4DBA-BA0F-A293020773F8}C:\program files (x86)\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe | "UDP Query User{F1C30560-375B-4FF3-AD3B-0C09A40DC070}C:\program files (x86)\heroes of the storm\versions\base57286\heroesofthestorm_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base57286\heroesofthestorm_x64.exe | "UDP Query User{F5003796-B002-41B8-8870-234D90D32EB2}C:\program files (x86)\starcraft ii\versions\base55505\sc2_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base55505\sc2_x64.exe | "UDP Query User{F88FAF8F-27EE-4745-8F09-68A944989814}C:\program files (x86)\hearthstone\hearthstone.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1" = MotioninJoy Gamepad tool 0.7.1001 "{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1" = Malwarebytes version 3.5.1.2522 "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 "{36EAD5CF-44EF-4FCF-8BE1-D96C4835D7A4}" = UE4 Prerequisites (x64) "{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 "{3BFC9CAE-091D-11E4-886A-F04DA23A5C58}" = MSVCRT Redists "{50A2BC33-C9CD-3BF1-A8FF-53C10A0B183C}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.24215 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{8D0A0EC6-9A3C-354F-9BFC-A61E96BE1846}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - FRA "{90150000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2013 "{90150000-0015-040C-1000-0000000FF1CE}" = Microsoft Access MUI (French) 2013 "{90150000-0016-040C-1000-0000000FF1CE}" = Microsoft Excel MUI (French) 2013 "{90150000-0018-040C-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (French) 2013 "{90150000-0019-040C-1000-0000000FF1CE}" = Microsoft Publisher MUI (French) 2013 "{90150000-001A-040C-1000-0000000FF1CE}" = Microsoft Outlook MUI (French) 2013 "{90150000-001B-040C-1000-0000000FF1CE}" = Microsoft Word MUI (French) 2013 "{90150000-001F-0401-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - 'DD:) 'D91(J) "{90150000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Korrekturhilfen 2013 - Deutsch "{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English "{90150000-001F-040C-1000-0000000FF1CE}" = Outils de vérification linguistique 2013 de Microsoft Office - Français "{90150000-001F-0413-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - Nederlands "{90150000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - Español "{90150000-002C-040C-1000-0000000FF1CE}" = Microsoft Office Proofing (French) 2013 "{90150000-0044-040C-1000-0000000FF1CE}" = Microsoft InfoPath MUI (French) 2013 "{90150000-006E-040C-1000-0000000FF1CE}" = Microsoft Office Shared MUI (French) 2013 "{90150000-0090-040C-1000-0000000FF1CE}" = Microsoft DCF MUI (French) 2013 "{90150000-00A1-040C-1000-0000000FF1CE}" = Microsoft OneNote MUI (French) 2013 "{90150000-00BA-040C-1000-0000000FF1CE}" = Microsoft Groove MUI (French) 2013 "{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013 "{90150000-00C1-040C-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (French) 2013 "{90150000-00E1-040C-1000-0000000FF1CE}" = Microsoft Office OSM MUI (French) 2013 "{90150000-00E2-040C-1000-0000000FF1CE}" = Microsoft Office OSM UX MUI (French) 2013 "{90150000-012B-040C-1000-0000000FF1CE}" = Microsoft Lync MUI (French) 2013 "{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.7 "{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) "{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Pilote 3D Vision 347.25 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panneau de configuration NVIDIA 347.25 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Pilote graphique 347.25 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 2.9.1.22 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Pilote du contrôleur 3D Vision 347.09 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Mises à jour NVIDIA 2.9.1.22 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService" = NVIDIA GeForce Experience Service "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Pilote audio HD : 1.3.33.0 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 2.9.1.22 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController" = SHIELD Wireless Controller Driver "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.34 "{B5E06417-A4AC-4225-B36E-7E34C91616E7}" = Intel® Trusted Connect Service Client "{BCF0C1F7-671C-3922-A7EA-8AC11F4FC0EB}" = Microsoft .NET Framework 4.7 "{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 "{D4BD27CF-BFBC-11E3-9B8F-F04DA23A5C58}" = MSVCRT Redists "{D66B7840-6A9B-11E4-8FED-F04DA23A5C58}" = MSVCRT Redists "{EF1EC6A9-17DE-3DA9-B040-686A1E8A8B04}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.24215 "8B3D7924-ED89-486B-8322-E8594065D5CB_is1" = RogueKiller version 12 "CCleaner" = CCleaner "Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64) "Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - FRA" = Module linguistique Microsoft Visual Studio 2010 Tools pour Office Runtime (x64) - FRA "Mozilla Firefox 54.0.1 (x64 fr)" = Mozilla Firefox 54.0.1 (x64 fr) "Office15.PROPLUS" = Microsoft Office Professionnel Plus 2013 "Recuva" = Recuva "Steam App 230190" = War for the Overworld "Steam App 24790" = Command and Conquer 3: Tiberium Wars "Steam App 24810" = Command and Conquer 3: Kane's Wrath "Steam App 265590" = The Red Solstice "Steam App 310510" = Deathtrap "Steam App 323580" = Jotun "Steam App 38400" = Fallout "Steam App 3910" = Sid Meier's Civilization III: Complete "Steam App 391720" = Layers of Fear "Steam App 402570" = Atlas Reactor "Steam App 427270" = Orcs Must Die! Unchained "Steam App 444090" = Paladins "Steam App 563560" = Alien Swarm: Reactive Drop "Steam App 65800" = Dungeon Defenders [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{050d4fc8-5d48-4b8f-8972-47c82c46020f}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 "{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video "{121727D5-FDF3-4723-BA57-EB383440ED72}" = OpenOffice 4.1.1 "{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 "{14B5DDCF-61C4-4F1E-A621-844685D60B5A}" = LibreOffice 5.0.4.2 "{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi "{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main "{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1FF7993C-23B1-4C91-B1F6-09D13C57A06A}_is1" = VirtualDub 1.9.6 Fr "{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin "{223B62A8-F6FF-4BEB-BC17-230D12723CD0}_is1" = RomStation "{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver "{26A24AE4-039D-4CA4-87B4-2F32180101F0}" = Java 8 Update 101 "{2890ae6b-90e9-448d-b3e6-97e43c21e2fd}" = UE4 Prerequisites (x64) "{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 "{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee WebAdvisor "{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF000}" = HiPatch "{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT "{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}" = Microsoft ASP.NET MVC 4 Runtime "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{69BCE4AC-9572-3271-A2FB-9423BDA36A43}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215 "{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{80407BA7-7763-4395-AB98-5233F1B34E65}" = NVIDIA PhysX "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin "{9DF24673-1780-4621-8476-0E44BE708C96}_is1" = YgoLink version 3.5.0.0 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Avast Update Helper "{AC76BA86-0804-1033-1959-001824265200}" = Adobe Refresh Manager "{AC76BA86-7AD7-1036-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Français "{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 "{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6 "{BBF2AC74-720C-3CB3-8291-5E34039232FA}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215 "{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 "{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1" = SRWare Iron version 51.2700.0 "{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}" = ASUS Product Register Program "{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 "{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software "{d992c12e-cab2-426f-bde3-fb8c53950b0d}" = Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 "{e2803110-78b3-4664-a479-3611a381656a}" = Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 "{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 "{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe Flash Player PPAPI" = Adobe Flash Player 29 PPAPI "Audacity_is1" = Audacity 2.0.6 "Avast Antivirus" = Avast Antivirus Gratuit "Avast Secure Browser" = Avast Secure Browser "Battle.net" = Battle.net "DAEMON Tools Lite" = DAEMON Tools Lite "Heroes of the Storm" = Heroes of the Storm "Magic Bullet PhotoLooks" = Magic Bullet PhotoLooks "MozillaMaintenanceService" = Mozilla Maintenance Service "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "Open Broadcaster Software" = Open Broadcaster Software "pcsx2-r4600" = PCSX2 - Playstation 2 Emulator "pcsx2-r5875" = PCSX2 - Playstation 2 Emulator "RGSS de RPG MAKER XP_is1" = RGSS de RMXP version 1.0.1 "RGSS-RTP Standard_is1" = RGSS-RTP Standard "RPG Maker XP_is1" = RPG Maker XP 1.03 "Skype_is1" = Skype version 8.21 "StarCraft II" = StarCraft II "StarCraft II - Legacy of the Void Beta" = StarCraft II - Legacy of the Void Beta "Steam" = Steam "Steam App 200710" = Torchlight II "Steam App 236110" = Dungeon Defenders II "Steam App 302270" = Dungeon Defenders Eternity "Steam App 40800" = Super Meat Boy "Steam App 57300" = Amnesia: The Dark Descent "VLC media player" = VLC media player "Warcraft III" = Warcraft III "WinRAR archiver" = WinRAR 5.31 (32-bit) "ZHPFix_is1" = ZHPFix 2015 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-768028322-443926211-1286405372-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "2744A393-554C-4E35-A24F-DEF0392B4484-2" = Dofus "correctif rpgxp 1.0.0.1 pour vista" = correctif rpgxp 1.0.0.1 pour vista "TeamSpeak 3 Client" = TeamSpeak 3 Client "The Forgotten" = C&C 3: The Forgotten "uTorrent" = µTorrent [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 15/05/2018 13:23:29 | Computer Name = user-PC | Source = Office Software Protection Platform Service | ID = 16385 Description = Failed to schedule Software Protection service for re-start at 2018-05-24T15:01:29Z. Error Code: 0x80041321. Error - 16/05/2018 02:45:46 | Computer Name = user-PC | Source = WinMgmt | ID = 10 Description = Error - 16/05/2018 06:28:09 | Computer Name = user-PC | Source = WinMgmt | ID = 10 Description = Error - 16/05/2018 13:50:17 | Computer Name = user-PC | Source = Office Software Protection Platform Service | ID = 16385 Description = Failed to schedule Software Protection service for re-start at 2018-05-24T15:01:17Z. Error Code: 0x80041321. Error - 17/05/2018 06:09:43 | Computer Name = user-PC | Source = WinMgmt | ID = 10 Description = Error - 18/05/2018 03:55:30 | Computer Name = user-PC | Source = WinMgmt | ID = 10 Description = Error - 18/05/2018 09:50:35 | Computer Name = user-PC | Source = WinMgmt | ID = 10 Description = Error - 18/05/2018 17:23:34 | Computer Name = user-PC | Source = Office Software Protection Platform Service | ID = 16385 Description = Failed to schedule Software Protection service for re-start at 2018-05-24T15:01:34Z. Error Code: 0x80041321. Error - 19/05/2018 03:51:56 | Computer Name = user-PC | Source = WinMgmt | ID = 10 Description = Error - 20/05/2018 03:47:35 | Computer Name = user-PC | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 20/05/2018 03:51:48 | Computer Name = user-PC | Source = Schannel | ID = 36887 Description = L alerte fatale suivante a été reçue : 70. Error - 20/05/2018 03:51:48 | Computer Name = user-PC | Source = Schannel | ID = 36887 Description = L alerte fatale suivante a été reçue : 40. Error - 20/05/2018 04:23:02 | Computer Name = user-PC | Source = Schannel | ID = 36887 Description = L alerte fatale suivante a été reçue : 70. Error - 20/05/2018 04:23:02 | Computer Name = user-PC | Source = Schannel | ID = 36887 Description = L alerte fatale suivante a été reçue : 40. Error - 20/05/2018 04:23:03 | Computer Name = user-PC | Source = Schannel | ID = 36887 Description = L alerte fatale suivante a été reçue : 70. Error - 20/05/2018 04:23:03 | Computer Name = user-PC | Source = Schannel | ID = 36887 Description = L alerte fatale suivante a été reçue : 40. Error - 20/05/2018 05:11:12 | Computer Name = user-PC | Source = Schannel | ID = 36887 Description = L alerte fatale suivante a été reçue : 70. Error - 20/05/2018 05:11:12 | Computer Name = user-PC | Source = Schannel | ID = 36887 Description = L alerte fatale suivante a été reçue : 40. Error - 20/05/2018 05:11:13 | Computer Name = user-PC | Source = Schannel | ID = 36887 Description = L alerte fatale suivante a été reçue : 70. Error - 20/05/2018 05:11:13 | Computer Name = user-PC | Source = Schannel | ID = 36887 Description = L alerte fatale suivante a été reçue : 40. < End of report >