OTL Extras logfile created on: 27/09/2021 23:36:50 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\HP\Downloads 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.19041.0) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 7,90 Gb Total Physical Memory | 1,03 Gb Available Physical Memory | 13,07% Memory free 13,22 Gb Paging File | 2,31 Gb Available in Paging File | 17,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 235,48 Gb Total Space | 172,18 Gb Free Space | 73,12% Space Free | Partition Type: NTFS Drive E: | 453,52 Gb Total Space | 448,84 Gb Free Space | 98,97% Space Free | Partition Type: NTFS Computer Name: LT-5CD7400SPY | User Name: HP | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- Reg Error: Key error. htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- Reg Error: Key error. InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [Powershell] -- powershell.exe -noexit -command Set-Location -literalPath '%V' (Microsoft Corporation) Directory [UpdateEncryptionSettings] -- Reg Error: Key error. Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- Reg Error: Key error. http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- Reg Error: Key error. piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [Powershell] -- powershell.exe -noexit -command Set-Location -literalPath '%V' (Microsoft Corporation) Directory [UpdateEncryptionSettings] -- Reg Error: Key error. Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Feature] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av] "DataMigrated" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}] "GUID" = {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} "DISPLAYNAME" = Windows Defender Antivirus "STATE" = 393472 "PRODUCTEXE" = windowsdefender:// "REPORTINGEXE" = %ProgramFiles%\Windows Defender\MsMpeng.exe -- (Microsoft Corporation) [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{FFDC234A-CE9B-08F9-406B-F876951CE066}] "GUID" = {FFDC234A-CE9B-08F9-406B-F876951CE066} "DISPLAYNAME" = 360 Total Security "STATE" = 331776 "PRODUCTEXE" = C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe -- (Qihoo 360 Technology Co. Ltd.) "REPORTINGEXE" = C:\Program Files (x86)\360\Total Security\safemon\WscReg.exe -- (Qihoo 360 Technology Co. Ltd.) [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\CBP] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\DPA] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Fw] "DataMigrated" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\SecurityApp] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\SecurityApp\WebProtection] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ProvidersMigration] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ProvidersMigration\WicaUpgradableAVs] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 91 42 44 66 AB 99 D7 01 [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Feature] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\CBP] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\DPA] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Fw] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\SecurityApp] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\SecurityApp\WebProtection] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ProvidersMigration] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{24BD1F40-F366-424F-A871-66B423C31B20}" = lport=57621 | protocol=17 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.168.632.0_x86__zpdnekdrzrea0\spotify.exe | "{3775F698-F663-40CE-B211-795D91717A8E}" = lport=5353 | protocol=17 | dir=in | app=c:\users\hp\appdata\local\programs\opera\78.0.4093.231\opera.exe | "{49A9AADD-753D-4DA9-8A21-350A9E3D9F7C}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\google\chrome\application\chrome.exe | "{548FD0D0-EBC9-48FF-AA2A-DAF9E11C8DD9}" = lport=8088 | protocol=6 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.168.632.0_x86__zpdnekdrzrea0\spotify.exe | "{5807DE5C-CA3F-4577-A0C6-5911A721B3E8}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft\edge\application\msedge.exe | "{84D9DC57-ED20-4A47-A5B5-0BCE9D24DEA1}" = lport=8088 | protocol=17 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.168.632.0_x86__zpdnekdrzrea0\spotify.exe | "{AF89E366-B234-4C37-899E-66FE0B06708D}" = lport=5353 | protocol=17 | dir=in | app=c:\users\hp\appdata\local\programs\opera\64.0.3417.73\opera.exe | "{DE3654E5-A847-4DDF-AB00-AAB7A9DA489C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\root\office16\outlook.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{04B9B775-959E-49BF-AB4D-C4D185DD48EF}" = dir=out | name=@{microsoft.windows.search_1.14.2.19041_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.search/resources/packagedisplayname} | "{04DBBFC7-63D8-462C-8714-32C33A4B8B1D}" = protocol=17 | dir=in | app=c:\program files (x86)\360\total security\softmgr\360instantsetup.exe | "{074CC46B-537E-496B-8C76-DAE859EDA836}" = dir=out | name=@{microsoft.mixedreality.portal_2000.21051.1282.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.mixedreality.portal/resources/pkgdisplayname} | "{086E940D-A8F6-4F93-ADCA-474D6E20CF56}" = protocol=6 | dir=out | app=c:\program files\windowsapps\microsoft.skypeapp_15.75.140.0_x86__kzf8qxf38zg5c\skype\skype.exe | "{0BC396E7-03FA-4323-AC1D-9129E0714C3E}" = dir=in | name=@{microsoft.windows.photos_2021.21090.10007.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} | "{0E3864BF-1ADA-4543-95D4-2649BEEFB434}" = dir=out | name=windows_ie_ac_001 | "{0F52741A-FDC8-4AC4-B4E2-27A4F4293C5C}" = protocol=6 | dir=in | app=c:\program files (x86)\360\total security\liveupdate360.exe | "{107AD248-CE72-457D-9DC8-6B6DD0E65582}" = dir=in | app=c:\windows\system32\rundll32.exe | "{16725987-C110-4BB2-8527-35E87D67B20C}" = dir=out | name=@{microsoft.yourphone_1.21084.73.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.yourphone/resources/appname} | "{169CB9F8-B2E9-4A94-9D84-3EAA6633B909}" = dir=in | name=@{microsoft.windows.cortana_1.13.0.18362_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} | "{195F8A57-273B-4897-B93E-0906B2603937}" = dir=in | name=@{microsoft.windows.startmenuexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.startmenuexperiencehost/startmenuexperiencehost/pkgdisplayname} | "{1A696BE8-2E6A-4F92-8969-D08E3D99AA18}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.18362.387.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{1BFD3E86-BCA0-424A-8682-5611F30D57A1}" = dir=out | name=@{microsoft.mspaint_6.2105.4017.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.mspaint/resources/appname} | "{1E6AF031-41A0-43CA-A855-A94F4074E101}" = dir=in | name=@{microsoft.microsoftedge_44.18362.387.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | "{20DA6DDB-163C-4020-B8ED-953587DCBBF9}" = dir=in | name=skype | "{211112FD-C787-4BC4-BECF-7E30B98F9112}" = dir=out | name=@{microsoft.windows.startmenuexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.startmenuexperiencehost/startmenuexperiencehost/pkgdisplayname} | "{24D1EF66-C1A3-4E3C-8DFA-EF13D1645545}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} | "{291A2DD3-A7D7-425A-A38C-96C8C9FB4050}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{2A552BC9-D5CE-4217-B19D-0824B5CC2565}" = dir=out | name=@{microsoft.windows.secureassessmentbrowser_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.secureassessmentbrowser/resources/packagedisplayname} | "{2BEE3B7F-5F41-4682-93C4-AC0DDB5522FE}" = dir=out | name=@{microsoft.storepurchaseapp_12106.1001.33.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.storepurchaseapp/resources/displaytitle} | "{2C0EC958-2CEF-4384-81FC-86E42A84413B}" = dir=in | name=microsoft edge | "{2DBD9901-E11A-4172-870D-D164AEF99F6D}" = dir=out | name=@{microsoft.windowscommunicationsapps_16005.14326.20436.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/appmanifest_outlookdesktop_displayname} | "{2DEDB46B-9117-4D15-B9E4-C4C88C121F69}" = dir=out | name=@{microsoft.people_10.2105.4.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.people/resources/appstorename} | "{2E4B630C-7E78-4D89-B74B-0F654064858B}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.18362.387.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{304A2CFA-3934-4B42-BBBB-DE5CC91C12C8}" = dir=in | name=@{microsoft.messaging_4.1901.10241.1000_x64__8wekyb3d8bbwe?ms-resource://microsoft.messaging/resources/appstorename} | "{30A7F930-AB8F-4DC9-874D-6CD191448076}" = dir=out | name=@{microsoft.windows.oobenetworkcaptiveportal_10.0.19041.1023_neutral__cw5n1h2txyewy?ms-resource://microsoft.windows.oobenetworkcaptiveportal/resources/appdisplayname} | "{34485873-A3BF-4F0F-9A3B-C3E6BF367D51}" = protocol=6 | dir=in | app=c:\program files (x86)\360\total security\360tsliveupd.exe | "{353BE60D-5F69-4F82-9058-10656C035CE4}" = dir=out | name=windows_ie_ac_001 | "{359CF7BE-FB53-4CEB-A3D1-900CED89857F}" = dir=in | name=@{microsoft.desktopappinstaller_1.4.3161.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.desktopappinstaller/resources/appdisplayname} | "{35A42018-12B9-4A6E-8C52-90E1FDE9A605}" = dir=out | name=microsoft edge | "{35CC6DE7-312A-4482-8A11-930F82C73646}" = protocol=17 | dir=out | app=c:\program files\windowsapps\microsoft.skypeapp_15.75.140.0_x86__kzf8qxf38zg5c\skype\skype.exe | "{368CB7A3-53FF-4C28-A018-E5870D321CC6}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} | "{38F782FB-09DA-4F8A-968D-0E982417093C}" = dir=out | name=print 3d | "{3A004D0D-2475-450D-915C-6FAEDAFC737C}" = dir=in | name=@{microsoft.windows.search_1.14.2.19041_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.search/resources/packagedisplayname} | "{3A3DFDAA-83DE-4B11-AE8F-1F7091A38D21}" = dir=out | name=@{microsoft.microsoft3dviewer_7.2107.7012.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoft3dviewer/common.view.uwp/resources/storeappname} | "{3C3C322E-5902-470C-B2D9-4D260BB1A76C}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{3FC490F2-F017-49DA-A6DE-72B73E0BA882}" = dir=out | name=xbox game bar | "{43302743-7FAC-4699-B071-4CE644FCB01F}" = dir=in | name=@{microsoft.windows.shellexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} | "{43C6C8C9-1270-448B-80BC-3C913A3E631D}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} | "{4470858B-A232-430E-B041-7BDBDBF1B38A}" = dir=out | name=office | "{454C5945-D8B7-4F86-BD9E-4A36CA9A9133}" = dir=out | name=@{microsoft.windows.apprep.chxapp_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.apprep.chxapp/resources/displayname} | "{466924FF-19A5-44B6-945B-4D5DB55B1650}" = dir=out | name=@{microsoft.xboxidentityprovider_12.80.11001.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxidentityprovider/resources/displayname} | "{466CB560-0693-4879-B44E-46837DB6EE3E}" = dir=out | name=hp support assistant | "{48A7CB1A-0A2C-40BE-BBCB-7FB6E60BE166}" = protocol=6 | dir=in | app=c:\windows\system32\rundll32.exe | "{498DAA95-AB2F-49F9-84D5-34FCB694AF3A}" = dir=in | name=@{microsoft.windows.startmenuexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.startmenuexperiencehost/startmenuexperiencehost/pkgdisplayname} | "{4ECE1C01-1374-4CFB-9A9E-E5432A5CADA6}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} | "{509FDC53-1CEB-4E4D-AAC4-418BEB297309}" = dir=in | name=cortana | "{54D989DD-F2B1-4FD4-8170-2900FEE1AB46}" = protocol=17 | dir=in | app=c:\program files (x86)\360\total security\360tsliveupd.exe | "{56FC40C2-EF3A-42DB-95AE-A9495D505234}" = dir=in | name=@{microsoft.win32webviewhost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.win32webviewhost/resources/displayname} | "{594F32F6-58EC-459D-9C0A-E799902C6E51}" = dir=out | name=xbox tcui | "{5A07E42B-E040-49F0-836C-7B007642C65C}" = dir=in | name=@{microsoft.windowscommunicationsapps_16005.14326.20436.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/appmanifest_outlookdesktop_displayname} | "{5C8B2D5D-0508-4060-B5D0-F0F11E5D4674}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} | "{6CEF64FF-868A-4832-89F1-FED33D68C851}" = dir=out | name=skype | "{6D9DD8C1-4B11-4536-BB4E-E6D743EC9FB7}" = protocol=6 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.168.632.0_x86__zpdnekdrzrea0\spotify.exe | "{7045A6D8-0C48-4EBF-A665-B88C1E6B66F3}" = dir=out | name=@{microsoft.windows.peopleexperiencehost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.peopleexperiencehost/resources/pkgdisplayname} | "{75040D58-BDAC-4DDE-A340-102D375AEDD5}" = dir=out | name=@{microsoft.lockapp_10.0.19041.1023_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} | "{76D63DEA-C0D3-4D83-9C6B-14D238203001}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{78E66A20-A842-4A07-9ABC-B54B9C8BF6EB}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.18362.387.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{793CA406-964A-4E62-8838-5FEA9EFFABAF}" = dir=out | name=cortana | "{79615BE9-154E-4B5C-BE28-4E556AA13264}" = dir=out | name=@{microsoft.bingweather_4.46.32012.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} | "{79FA1295-1C63-4DDA-9EDF-CD2B6DC5D9F5}" = dir=in | name=@{microsoft.windows.startmenuexperiencehost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.startmenuexperiencehost/startmenuexperiencehost/pkgdisplayname} | "{7A9182D5-E926-470D-A6B7-4E67E7F79F08}" = dir=out | name=@{microsoft.windows.startmenuexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.startmenuexperiencehost/startmenuexperiencehost/pkgdisplayname} | "{7C3B530A-4C82-4EDB-862E-18C2C29FB07E}" = dir=out | name=@{microsoft.windows.sechealthui_10.0.19041.1023_neutral__cw5n1h2txyewy?ms-resource://microsoft.windows.sechealthui/resources/packagedisplayname} | "{7C6C8A00-AC63-4554-80C8-BBC3BB8C4428}" = protocol=6 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.168.632.0_x86__zpdnekdrzrea0\spotify.exe | "{7F6AB953-68BE-4124-BF1D-ED538BD6FAC1}" = dir=in | name=@{microsoft.zunemusic_10.21061.10121.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{8162288A-3F09-4BE3-8BC0-939E8166A9A5}" = dir=in | name=@{microsoft.oneconnect_5.2011.3081.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.oneconnect/oneconnectstrings/oneconnect/appstorename} | "{82880A93-C5C5-4727-A374-E8EDA3FA1D85}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{84D5AC49-9812-428B-9AEF-A959C75D56E7}" = dir=out | name=xbox game bar plugin | "{86D35B1D-E106-4E5A-8BAA-1441F320BD91}" = dir=out | name=@{microsoft.microsoftedge_44.18362.387.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | "{8D3240C6-BCD0-4A53-AC97-D6E9B0139DBD}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{8D5DBBBC-8358-4E66-A22C-EEA798594B5C}" = dir=out | name=@{microsoft.messaging_4.1901.10241.1000_x64__8wekyb3d8bbwe?ms-resource://microsoft.messaging/resources/appstorename} | "{8E78AF32-7E5E-43F8-B1FA-F002D777995F}" = protocol=17 | dir=in | app=c:\program files (x86)\360\total security\liveupdate360.exe | "{90526045-5A89-42E5-8304-FF6A970D2599}" = dir=out | name=@{microsoft.getstarted_10.6.42361.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.getstarted/resources/appstorename} | "{912E1164-8195-455E-A2F9-0EE31319ED10}" = protocol=17 | dir=in | app=c:\program files (x86)\360\total security\safemon\qhsafetray.exe | "{925501AC-C513-4F0A-8A82-173EC20AA4E4}" = dir=in | name=@{microsoft.microsoftstickynotes_4.1.9.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftstickynotes/resources/stickynotesstoreappname} | "{9274F5C8-42A4-4914-94A4-4DEAF17BF4DB}" = protocol=17 | dir=in | app=c:\program files\windowsapps\microsoft.skypeapp_15.75.140.0_x86__kzf8qxf38zg5c\skype\skype.exe | "{93ACFB9E-CCC3-4397-AF4C-77AD9849DC86}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{971C8A8A-EEAE-4E85-A2D0-601AF48E4637}" = dir=in | name=microsoft solitaire collection | "{974C9FD4-86EF-45E7-BA34-7CE9F3312439}" = dir=out | name=@{microsoft.accountscontrol_10.0.19041.1023_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} | "{990EC3B7-4BE9-4C37-925D-6AE22CFCBCD7}" = dir=in | name=@{microsoft.microsoftedge_44.18362.387.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | "{99A917A0-1279-4797-BAC9-B99137727E7E}" = dir=out | name=@{microsoft.windowscalculator_10.2103.8.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscalculator/resources/appstorename} | "{9BB44A39-0D25-4DC4-AB24-24AF8C10AD2A}" = dir=out | name=onenote for windows 10 | "{9C048002-51E9-431D-BFC6-7077E850A86B}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.18362.387.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{9D0CF0E6-2BEC-4A1A-9929-4963AE989096}" = dir=in | name=@{microsoft.windows.startmenuexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.startmenuexperiencehost/startmenuexperiencehost/pkgdisplayname} | "{9E083247-7123-42CE-BFB0-CCD6BD040F21}" = dir=in | name=onenote for windows 10 | "{A0A09F04-E41C-4D42-B98A-007FA476A3E8}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{A44FF196-DA7A-4E86-B36A-11C8BF905BC6}" = dir=out | name=ncsiuwpapp | "{A541149E-165A-4461-94AB-2729FA931E75}" = dir=out | name=@{microsoft.windows.narratorquickstart_10.0.19041.1023_neutral_neutral_8wekyb3d8bbwe?ms-resource://microsoft.windows.narratorquickstart/resources/appdisplayname} | "{A565AF45-F8D2-4D06-9CC7-B4AD1A6F45F7}" = protocol=6 | dir=in | app=c:\program files (x86)\360\total security\softmgr\360instantsetup.exe | "{A5FC7AD5-EF9D-4873-B8BD-C08F30A95CBB}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{A6301C11-9DA1-4A12-8330-F239E5FE5567}" = protocol=6 | dir=in | app=c:\program files (x86)\360\total security\safemon\qhsafetray.exe | "{A698E5C0-A4F7-4C42-9869-AEE86912D753}" = dir=out | name=@{microsoft.windows.startmenuexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.startmenuexperiencehost/startmenuexperiencehost/pkgdisplayname} | "{A798AF12-B436-4C1B-9F7B-6FF53A2976FD}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} | "{A9C7A4DE-1DD4-47DB-B0B9-5030DE188A78}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} | "{AA6C15C0-560E-4876-B216-EA4D79CB7B5D}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.18362.387.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{AB876D8E-0BD8-4D9F-90FD-0ECF8AFA6A30}" = dir=out | name=spotify music | "{ABD863DD-71FE-415F-9BD1-3DE32AE0A168}" = dir=out | name=@{microsoft.windows.photos_2021.21090.10007.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} | "{AF33A42B-F859-42D6-A20D-9CA2073D3FEB}" = dir=in | name=@{microsoft.windows.shellexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} | "{AF34BEB0-D7A6-48F8-B9AE-F8A92DCF3166}" = dir=out | name=microsoft pay | "{B129BB42-819B-4406-A36E-5401D4DC2197}" = protocol=17 | dir=out | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.168.632.0_x86__zpdnekdrzrea0\spotify.exe | "{B3D6A80F-E8CA-42F4-ADCE-4C2D66B1DA6E}" = dir=out | name=@{microsoft.windowsstore_12107.1001.15.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} | "{B515F8AE-E095-4E96-B282-6E50A6C9A6B9}" = protocol=17 | dir=in | app=c:\windows\system32\rundll32.exe | "{B5165D54-89A7-4560-A235-F986FDF9F78B}" = dir=out | name=@{appup.intelgraphicsexperience_1.100.3370.0_x64__8j3eq9eme6ctt?ms-resource://appup.intelgraphicsexperience/resources/system_item_title_intelgraphicscontrolpanel} | "{B6C0B5EE-71E1-47E1-B41C-1A477FE9D258}" = dir=in | name=@{microsoft.xboxapp_48.78.15001.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxapp/xboxapp.resource/resources/app_title} | "{B84A308D-799A-47A6-963A-6EFE6399841C}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} | "{BA0C7D16-041D-49A1-958B-F0B38C1B8362}" = dir=out | name=@{microsoft.microsoftedge_44.18362.387.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | "{BB6A49D3-FD10-4FE2-ACC7-AE3B3C6EA582}" = dir=in | name=@{microsoft.windows.shellexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} | "{C148E51C-8F21-4E9B-B1E5-3DE5D3C2C76D}" = dir=out | name=@{microsoft.zunemusic_10.21061.10121.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{C3F8122C-168C-4BF7-B8E8-BFDD3F2F2373}" = dir=in | name=@{microsoft.zunevideo_10.21061.10121.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{C5CFE396-709D-41EF-AF0F-2F185674C874}" = protocol=6 | dir=out | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.168.632.0_x86__zpdnekdrzrea0\spotify.exe | "{CC4D54F8-1A34-49FC-B4D7-C02EEF056F56}" = dir=out | name=windows feature experience pack | "{CF241920-6395-47EC-8DC9-FFFFCC261790}" = dir=in | app=c:\program files (x86)\driverpack\tools\aria2c.exe | "{CF59444B-7AD6-4FAD-8F26-F7F79E2F1095}" = dir=out | name=microsoft solitaire collection | "{D2280B50-EDB2-4759-81B9-6E6E9BC83F49}" = dir=out | name=@{microsoft.microsoftstickynotes_4.1.9.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftstickynotes/resources/stickynotesstoreappname} | "{D33C74FB-B288-4502-8D61-62EEE80520FC}" = protocol=6 | dir=in | app=c:\program files\windowsapps\spotifyab.spotifymusic_1.168.632.0_x86__zpdnekdrzrea0\spotify.exe | "{D4B9AFE4-F1E3-4615-8DB3-CDC460346CF9}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.18362.387.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{D537341B-A176-4D81-BBF7-EB0FD4EEB692}" = dir=out | name=@{microsoft.zunevideo_10.21061.10121.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{D68D5E38-4BCF-4047-B2FC-FB1058AB08FA}" = dir=out | name=@{microsoft.win32webviewhost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.win32webviewhost/resources/displayname} | "{D87FB837-78F2-4287-9822-242D5B8D0FD2}" = dir=out | name=@{microsoft.windowsfeedbackhub_1.2106.1801.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsfeedbackhub/resources/appstorename} | "{DA1299B4-E759-4581-AF9D-E1139C0C0517}" = protocol=6 | dir=in | app=c:\program files\windowsapps\microsoft.skypeapp_15.75.140.0_x86__kzf8qxf38zg5c\skype\skype.exe | "{DB130004-7162-4B07-9031-88FD22FC7456}" = dir=in | name=print 3d | "{DD7578BA-D7D6-4AD5-A2ED-F3DE6058A6B5}" = dir=out | name=@{microsoft.windows.startmenuexperiencehost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.startmenuexperiencehost/startmenuexperiencehost/pkgdisplayname} | "{E05331D8-6564-4AB9-865F-67DDFA39D728}" = dir=in | name=@{microsoft.windowsstore_12107.1001.15.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} | "{E066BD0D-63B9-40D2-B1EE-FAFA54BE25BA}" = dir=out | name=@{microsoft.xboxapp_48.78.15001.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxapp/xboxapp.resource/resources/app_title} | "{E292EB0B-747A-41F2-BCD3-BE87C8061EAC}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{E3C84F31-7344-4E1E-AA4E-6E5586F7D7C0}" = dir=in | name=@{microsoft.yourphone_1.21084.73.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.yourphone/resources/appname} | "{E7EFFC13-02CC-41EF-98C1-573BCA47D7F9}" = dir=out | name=@{microsoft.desktopappinstaller_1.4.3161.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.desktopappinstaller/resources/appdisplayname} | "{EA421EC4-AC18-4027-A107-0DD94D48E6D6}" = dir=out | name=@{microsoft.oneconnect_5.2011.3081.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.oneconnect/oneconnectstrings/oneconnect/appstorename} | "{EBC4DAC7-D957-48A4-B78F-0C31B978168C}" = dir=out | name=@{microsoft.windowsmaps_10.2104.2.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsmaps/resources/appstorename} | "{ECBF6968-D398-45C1-AA77-E1CD6243CED4}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} | "{F34A53BA-1598-4AC0-8D48-DC9580D185F5}" = dir=out | name=@{microsoft.windows.cortana_1.13.0.18362_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} | "{F3724DD8-9013-4027-B4B1-2E820D716C2E}" = dir=out | name=@{microsoft.windowscamera_2021.105.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscamera/lenssdk/resources/appstorename} | "{F5582D8D-3F74-46FF-A7D9-E3E6D09869F1}" = dir=in | name=xbox game bar | "{F9E30CC7-9907-4EB7-9C06-68EDA2889C2F}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{FAB21492-4E2E-489B-876E-E96BBC773C56}" = dir=out | name=@{microsoft.gethelp_10.2108.42428.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.gethelp/resources/appdisplayname} | "{FAE3769B-1EF5-4B45-AC00-5C71CBB33293}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.18362.387_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} | "TCP Query User{00A5C47D-954C-47B8-875B-88E2DAF71AC3}E:\app\sdi_rus 2019\sdi_x64_r1904.exe" = protocol=6 | dir=in | app=e:\app\sdi_rus 2019\sdi_x64_r1904.exe | "TCP Query User{2DC919BC-59D4-4468-A697-EAA54BE15F5C}C:\chrone\chrome.exe" = protocol=6 | dir=in | app=c:\chrone\chrome.exe | "UDP Query User{2ECA24C9-FEDF-42C5-A3B4-ADD2EFE79BA8}C:\chrone\chrome.exe" = protocol=17 | dir=in | app=c:\chrone\chrome.exe | "UDP Query User{E4ACF769-2D01-4213-8956-5D4C694F70B6}E:\app\sdi_rus 2019\sdi_x64_r1904.exe" = protocol=17 | dir=in | app=e:\app\sdi_rus 2019\sdi_x64_r1904.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0BCD0446-9933-3CF9-B784-9B82FF57B144}" = Google Chrome "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 "{5740BD44-B58D-321A-AFC0-6D3D4556DD6C}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40660 "{7B981965-2FBC-433C-B4B3-E183EE97CD29}" = Microsoft Update Health Tools "{90160000-007E-0000-1000-0000000FF1CE}" = Office 16 Click-to-Run Licensing Component "{90160000-008C-0000-1000-0000000FF1CE}" = Office 16 Click-to-Run Extensibility Component "{90160000-008C-040C-1000-0000000FF1CE}" = Office 16 Click-to-Run Localization Component "{C77195A4-CEB8-38EE-BDD6-C46CB459EF6E}" = Microsoft Visual C++ 2017 x64 Minimum Runtime - 14.15.26706 "{CB0836EC-B072-368D-82B2-D3470BF95707}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40660 "{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 "{F106B700-BFF8-3065-B305-14D36AD40539}" = Microsoft Visual C++ 2017 x64 Additional Runtime - 14.15.26706 "CNXT_AUDIO_HDA" = Conexant ISST Audio "ProPlus2019Retail - fr-fr" = Microsoft Office Professionnel Plus 2019 - fr-fr "SynTPDeinstKey" = Synaptics Pointing Device Driver "VLC media player" = VLC media player "WinRAR archiver" = WinRAR 6.01 (64-bit) "Wondershare Filmora X_is1" = Wondershare Filmora X(Build 10.2.0.32) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{2757496A-3E74-320A-B007-36120A9F126D}" = Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 "{29E20347-C62F-4657-938E-876A182B67F1}" = HP System Event Utility "{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 "{39E15475-23F2-345D-8977-B5DC47A94E26}" = Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 "{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1" = Wondershare Helper Compact 2.6.0 "{61087a79-ac85-455c-934d-1fa22cc64f36}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 "{7DAD0258-515C-3DD4-8964-BD714199E0F7}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660 "{7e9fae12-5bbf-47fb-b944-09c49e75c061}" = Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 "{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}" = Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 "{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 "{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 "{C845414C-903C-4218-9DE7-132AB97FDF62}" = Windows Manager "{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 "{E30D8B21-D82D-3211-82CC-0F0A5D1495E8}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660 "{ef6b00ec-13e1-4c25-9064-b2f383cb8412}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 "360TotalSecurity" = 360 Total Security "411A5457-AC1D-462D-979D-A617B79C6DCB" = VideoAdsBlocker "Chrone Browser" = Chrone Browser "DriverPack" = DriverPack "dsPICFLASH Programmer" = dsPICFLASH Programmer (remove only) "FarLabUninstaller.exe_is1" = FarLabUninstaller v1.53.666 "Firefox Browser" = Firefox Browser "Foxit Reader_is1" = Foxit PDF Reader "LvPICFLASH Programmer" = LvPICFLASH Programmer (remove only) "Microsoft Edge" = Microsoft Edge "Microsoft Edge Update" = Microsoft Edge Update "mikroC dsPIC" = mikroC dsPIC(remove only) "mikroC PRO for PIC" = mikroC PRO for PIC (remove only) "mikroProg Suite For PIC" = mikroProg Suite For PIC (remove only) "PHSP_21_0" = Adobe Photoshop 2020 "SearcherBar" = SearcherBar [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-4073201698-989389081-2523801930-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{497aa788-6cca-433f-905e-0f11f639e18a}" = CODEGRIP Suite "OneDriveSetup.exe" = Microsoft OneDrive [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 26/09/2021 21:16:57 | Computer Name = LT-5CD7400SPY | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante lighteningplayer.exe, version : 3.0.7.0, horodatage : 0x5d1b6392 Nom du module défaillant : libqt_plugin.dll, version : 3.0.5.0, horodatage : 0x00030000 Code d’exception : 0xc0000005 Décalage d’erreur : 0x003af4da ID du processus défaillant : 0x4f50 Heure de début de l’application défaillante : 0x01d7b33be86444dd Chemin d’accès de l’application défaillante : C:\Program Files (x86)\lighteningplayer\lighteningplayer.exe Chemin d’accès du module défaillant: C:\Program Files (x86)\lighteningplayer\plugins\gui\libqt_plugin.dll ID de rapport : ac4f7b33-f0a7-4061-9a06-ca5d47a26c20 Nom complet du package défaillant : ? ID de l’application relative au package défaillant : ? Error - 26/09/2021 21:21:06 | Computer Name = LT-5CD7400SPY | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante uwrtgvr, version : 12.0.0.0, horodatage : 0x6128c117 Nom du module défaillant : unknown, version : 0.0.0.0, horodatage : 0x00000000 Code d’exception : 0xc0000005 Décalage d’erreur : 0x00008250 ID du processus défaillant : 0x4100 Heure de début de l’application défaillante : 0x01d7b33dca8f4f8e Chemin d’accès de l’application défaillante : C:\Users\HP\AppData\Roaming\uwrtgvr Chemin d’accès du module défaillant: unknown ID de rapport : 08e0039b-5f6e-4010-adad-ba7e78339363 Nom complet du package défaillant : ? ID de l’application relative au package défaillant : ? Error - 26/09/2021 21:30:42 | Computer Name = LT-5CD7400SPY | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante uwrtgvr, version : 12.0.0.0, horodatage : 0x6128c117 Nom du module défaillant : unknown, version : 0.0.0.0, horodatage : 0x00000000 Code d’exception : 0xc0000005 Décalage d’erreur : 0x00008250 ID du processus défaillant : 0x5100 Heure de début de l’application défaillante : 0x01d7b33f30400f74 Chemin d’accès de l’application défaillante : C:\Users\HP\AppData\Roaming\uwrtgvr Chemin d’accès du module défaillant: unknown ID de rapport : 3db8c116-c3f1-485c-8c90-c955366b34c3 Nom complet du package défaillant : ? ID de l’application relative au package défaillant : ? Error - 26/09/2021 21:50:25 | Computer Name = LT-5CD7400SPY | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante uwrtgvr, version : 12.0.0.0, horodatage : 0x6128c117 Nom du module défaillant : unknown, version : 0.0.0.0, horodatage : 0x00000000 Code d’exception : 0xc0000005 Décalage d’erreur : 0x00008250 ID du processus défaillant : 0x255c Heure de début de l’application défaillante : 0x01d7b341fb86b34a Chemin d’accès de l’application défaillante : C:\Users\HP\AppData\Roaming\uwrtgvr Chemin d’accès du module défaillant: unknown ID de rapport : c2ded78e-389e-48cc-9cb6-665dc74e0cc9 Nom complet du package défaillant : ? ID de l’application relative au package défaillant : ? Error - 27/09/2021 00:20:46 | Computer Name = LT-5CD7400SPY | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante uwrtgvr, version : 12.0.0.0, horodatage : 0x6128c117 Nom du module défaillant : unknown, version : 0.0.0.0, horodatage : 0x00000000 Code d’exception : 0xc0000005 Décalage d’erreur : 0x00008250 ID du processus défaillant : 0xcd0 Heure de début de l’application défaillante : 0x01d7b356efd3beae Chemin d’accès de l’application défaillante : C:\Users\HP\AppData\Roaming\uwrtgvr Chemin d’accès du module défaillant: unknown ID de rapport : 6ac19d13-81a1-45eb-81d2-e6e3da834f30 Nom complet du package défaillant : ? ID de l’application relative au package défaillant : ? Error - 27/09/2021 01:02:35 | Computer Name = LT-5CD7400SPY | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante uwrtgvr, version : 12.0.0.0, horodatage : 0x6128c117 Nom du module défaillant : unknown, version : 0.0.0.0, horodatage : 0x00000000 Code d’exception : 0xc0000005 Décalage d’erreur : 0x00008250 ID du processus défaillant : 0x46dc Heure de début de l’application défaillante : 0x01d7b35b20c751c5 Chemin d’accès de l’application défaillante : C:\Users\HP\AppData\Roaming\uwrtgvr Chemin d’accès du module défaillant: unknown ID de rapport : dbbc109f-d66d-4755-aa28-9b532fc44169 Nom complet du package défaillant : ? ID de l’application relative au package défaillant : ? Error - 27/09/2021 01:34:18 | Computer Name = LT-5CD7400SPY | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante uwrtgvr, version : 12.0.0.0, horodatage : 0x6128c117 Nom du module défaillant : unknown, version : 0.0.0.0, horodatage : 0x00000000 Code d’exception : 0xc0000005 Décalage d’erreur : 0x00008250 ID du processus défaillant : 0x30e8 Heure de début de l’application défaillante : 0x01d7b360b7678bfe Chemin d’accès de l’application défaillante : C:\Users\HP\AppData\Roaming\uwrtgvr Chemin d’accès du module défaillant: unknown ID de rapport : 656d9672-e145-4db5-aaf4-9c6122b884c0 Nom complet du package défaillant : ? ID de l’application relative au package défaillant : ? Error - 27/09/2021 16:08:39 | Computer Name = LT-5CD7400SPY | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante svchost.exe_FrameServer, version : 10.0.19041.546, horodatage : 0x058e175a Nom du module défaillant : RsProvider.dll, version : 1.30.0.0, horodatage : 0x57ee1a06 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000000000007bd6d ID du processus défaillant : 0x700 Heure de début de l’application défaillante : 0x01d7b3db7571cfec Chemin d’accès de l’application défaillante : C:\WINDOWS\System32\svchost.exe Chemin d’accès du module défaillant: C:\Program Files\Realtek\RsProviders\RsProvider.dll ID de rapport : 8df33a82-2e23-4eca-ab3b-e64f488b3f5e Nom complet du package défaillant : ? ID de l’application relative au package défaillant : ? Error - 27/09/2021 16:09:25 | Computer Name = LT-5CD7400SPY | Source = Application Error | ID = 1000 Description = Nom de l’application défaillante System.exe, version : 0.8.0.6, horodatage : 0x613f71f2 Nom du module défaillant : System.exe, version : 0.8.0.6, horodatage : 0x613f71f2 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000000000001b379 ID du processus défaillant : 0x818 Heure de début de l’application défaillante : 0x01d7b3db91c5a533 Chemin d’accès de l’application défaillante : C:\ProgramData\Microsoft Network\System.exe Chemin d’accès du module défaillant: C:\ProgramData\Microsoft Network\System.exe ID de rapport : 65550248-2601-43c4-80ec-86223e44f6b7 Nom complet du package défaillant : ? ID de l’application relative au package défaillant : ? Error - 27/09/2021 16:10:54 | Computer Name = LT-5CD7400SPY | Source = SecurityCenter | ID = 17 Description = [ Microsoft-Windows-Diagnostics-Performance/Operational Events ] Error - 21/09/2021 14:06:06 | Computer Name = LT-5CD7400SPY | Source = Microsoft-Windows-Diagnostics-Performance | ID = 101 Description = Error - 21/09/2021 14:06:06 | Computer Name = LT-5CD7400SPY | Source = Microsoft-Windows-Diagnostics-Performance | ID = 101 Description = Error - 21/09/2021 17:52:01 | Computer Name = LT-5CD7400SPY | Source = Microsoft-Windows-Diagnostics-Performance | ID = 203 Description = Error - 26/09/2021 08:51:05 | Computer Name = LT-5CD7400SPY | Source = Microsoft-Windows-Diagnostics-Performance | ID = 100 Description = Error - 26/09/2021 08:51:05 | Computer Name = LT-5CD7400SPY | Source = Microsoft-Windows-Diagnostics-Performance | ID = 101 Description = Error - 26/09/2021 08:51:05 | Computer Name = LT-5CD7400SPY | Source = Microsoft-Windows-Diagnostics-Performance | ID = 101 Description = Error - 26/09/2021 08:51:05 | Computer Name = LT-5CD7400SPY | Source = Microsoft-Windows-Diagnostics-Performance | ID = 101 Description = Error - 26/09/2021 12:57:53 | Computer Name = LT-5CD7400SPY | Source = Microsoft-Windows-Diagnostics-Performance | ID = 200 Description = Error - 26/09/2021 13:33:15 | Computer Name = LT-5CD7400SPY | Source = Microsoft-Windows-Diagnostics-Performance | ID = 101 Description = Error - 26/09/2021 13:33:15 | Computer Name = LT-5CD7400SPY | Source = Microsoft-Windows-Diagnostics-Performance | ID = 101 Description = [ Parameters Events ] OTL encountered an error while reading this event log. It may be corrupt. [ State Events ] OTL encountered an error while reading this event log. It may be corrupt. Error - 27/09/2021 16:10:54 | Computer Name = LT-5CD7400SPY | Source = Service Control Manager | ID = 7000 Description = Le service QHProtected n’a pas pu démarrer en raison de l’erreur : %%577 Error - 27/09/2021 16:10:54 | Computer Name = LT-5CD7400SPY | Source = Service Control Manager | ID = 7000 Description = Le service QHProtected n’a pas pu démarrer en raison de l’erreur : %%577 Error - 27/09/2021 16:16:41 | Computer Name = LT-5CD7400SPY | Source = Service Control Manager | ID = 7000 Description = Le service WinRing0_1_2_0 n’a pas pu démarrer en raison de l’erreur : %%2 Error - 27/09/2021 16:25:25 | Computer Name = LT-5CD7400SPY | Source = Service Control Manager | ID = 7000 Description = Le service WinRing0_1_2_0 n’a pas pu démarrer en raison de l’erreur : %%2 Error - 27/09/2021 16:29:23 | Computer Name = LT-5CD7400SPY | Source = Service Control Manager | ID = 7000 Description = Le service WinRing0_1_2_0 n’a pas pu démarrer en raison de l’erreur : %%2 Error - 27/09/2021 16:33:17 | Computer Name = LT-5CD7400SPY | Source = Service Control Manager | ID = 7000 Description = Le service WinRing0_1_2_0 n’a pas pu démarrer en raison de l’erreur : %%2 Error - 27/09/2021 16:33:25 | Computer Name = LT-5CD7400SPY | Source = Service Control Manager | ID = 7000 Description = Le service WinRing0_1_2_0 n’a pas pu démarrer en raison de l’erreur : %%2 Error - 27/09/2021 16:34:45 | Computer Name = LT-5CD7400SPY | Source = Service Control Manager | ID = 7000 Description = Le service WinRing0_1_2_0 n’a pas pu démarrer en raison de l’erreur : %%2 Error - 27/09/2021 16:42:45 | Computer Name = LT-5CD7400SPY | Source = Service Control Manager | ID = 7000 Description = Le service WinRing0_1_2_0 n’a pas pu démarrer en raison de l’erreur : %%2 Error - 27/09/2021 16:53:25 | Computer Name = LT-5CD7400SPY | Source = Service Control Manager | ID = 7000 Description = Le service WinRing0_1_2_0 n’a pas pu démarrer en raison de l’erreur : %%2 < End of report >