OTL Extras logfile created on: 22/01/2014 15:18:09 - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jacques\Downloads 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16750) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 5,95 Gb Total Physical Memory | 4,41 Gb Available Physical Memory | 74,06% Memory free 6,89 Gb Paging File | 4,51 Gb Available in Paging File | 65,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 455,95 Gb Total Space | 400,10 Gb Free Space | 87,75% Space Free | Partition Type: NTFS Drive D: | 456,76 Gb Total Space | 150,65 Gb Free Space | 32,98% Space Free | Partition Type: NTFS Drive F: | 1863,01 Gb Total Space | 1556,45 Gb Free Space | 83,54% Space Free | Partition Type: NTFS Drive G: | 14,90 Gb Total Space | 2,05 Gb Free Space | 13,76% Space Free | Partition Type: FAT32 Computer Name: DESCOUT | User Name: Jacques | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (All) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation) .hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation) .txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .bat [@ = batfile] -- "%1" %* .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cmd [@ = cmdfile] -- "%1" %* .com [@ = comfile] -- "%1" %* .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .exe [@ = exefile] -- "%1" %* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- "%1" %* .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .pif [@ = piffile] -- "%1" %* .reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation) .scr [@ = scrfile] -- "%1" /S .txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-4014571762-1555873058-2083660991-1001\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [Digital Photo Professional] -- C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [Digital Photo Professional] -- C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07DE5286-0999-497E-9289-6F76557C2681}" = lport=138 | protocol=17 | dir=in | app=system | "{19B1B087-E8DB-4E98-9111-95F94E615EEF}" = rport=139 | protocol=6 | dir=out | app=system | "{2501D5A8-3A97-4E75-B6F7-3A91FCE3D68E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{2BB47BD2-35C1-4944-B731-11959CB63B68}" = rport=138 | protocol=17 | dir=out | app=system | "{653C4F24-0513-4792-8384-CD0573B087D8}" = rport=137 | protocol=17 | dir=out | app=system | "{688664B4-D49C-4359-97E0-0CFD3A060D9A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{7A8FFADE-B455-4677-B573-F3167F01AB14}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{7FE2FB88-BBD1-4B13-A2EF-4A57E9D11899}" = rport=445 | protocol=6 | dir=out | app=system | "{84BCB79B-4426-4F9A-BAF2-462F2DC5CB6C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{89C3DE41-DDB7-424F-A108-E32CF8E035E9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{9ABAA41A-5021-4D1E-A64A-F009B0E9C9D5}" = lport=139 | protocol=6 | dir=in | app=system | "{9F1870BE-EB97-4E84-8E91-D9A0A6C21C60}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A36208A4-473C-4B8D-955D-F8C1615FAC3E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B0648CA1-AC95-4B54-B197-DA2B0B397E91}" = lport=10243 | protocol=6 | dir=in | app=system | "{BE6F129A-628E-48D2-93DD-9EDA4B247474}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{BEF4D8EF-3B82-4B24-8913-02C053D1F521}" = lport=137 | protocol=17 | dir=in | app=system | "{CBD10BA0-B7BE-44F4-80E3-F80E4BB2B6E5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E44FBBF3-A828-4585-A778-CDA68ED6C93A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{E6534095-2311-42D9-95BA-940B91094C94}" = lport=445 | protocol=6 | dir=in | app=system | "{F629ACC7-B46B-4479-8FB7-0ACB1E2B3F33}" = lport=2869 | protocol=6 | dir=in | app=system | "{F9D56395-1F97-48C5-B762-EF6563E3B257}" = rport=10243 | protocol=6 | dir=out | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{008063D6-AFEE-4DC3-9977-CA29C8DF8941}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe | "{00B1CE50-83FC-4ACC-BBA1-7611186C14B2}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{0176737D-36B7-4B74-B422-810F3B9F931B}" = dir=out | name=kindle | "{0178D9D4-84CA-4ABE-B416-C7AF44E9132F}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe | "{0265E315-D602-45FF-BE5B-528CC861DAC0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{06826894-385F-4C78-910F-D34C1B237111}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{0D924137-13FB-4729-9B41-F89C3EEBCA75}" = dir=out | name=@{microsoft.bingfinance_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{152711D2-9E38-487F-8D3D-A26FB2914949}" = dir=out | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{16EB537E-3CE6-471B-8E6D-CC6427A44AA4}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1CCDD747-FE8E-4F72-B6DB-B50177131755}" = dir=out | name=windows_ie_ac_001 | "{1CEBB0F8-1019-4218-B610-E2EA651586FB}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{1E85770A-C53C-434F-81B7-396505272EA3}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe | "{1F037CF9-1E3C-4F5F-9F81-C57A77C8EE3E}" = dir=out | name=@{microsoft.zunevideo_1.5.299.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{1F81CE6A-3038-40E2-8769-3F8B3B5DEDE4}" = dir=out | name=microsoft minesweeper | "{2105AC8B-6BCE-4A2A-ACC0-4530F35BCDD8}" = protocol=17 | dir=in | app=c:\program files (x86)\windows searchqu toolbar\datamngr\toolbar\dtuser.exe | "{2241B542-415D-4AF4-ADDC-881B97E0C809}" = dir=out | name=newsxpresso | "{26C6A797-F82B-4C35-B34F-1795A13B4B6B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{2C1AF343-493B-409F-AFE8-A49D4B08D585}" = dir=out | name=@{microsoft.bingsports_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{2D833F7C-E542-407C-A0A2-DD06552BE4B5}" = dir=out | name=cut the rope | "{3049448D-BC45-4AB7-858D-47CC7B721102}" = dir=out | name=@{microsoft.zunemusic_1.5.214.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{304ECEBA-E776-4B65-B968-5FA1D053B758}" = dir=out | name=@{microsoft.xboxlivegames_1.3.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{345C96C9-2C6B-4121-94E8-9D8B62E73DA5}" = dir=out | name=evernote touch | "{3526F3E1-9586-485F-A0CE-4EF5FF94A548}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\video\videoplayer.exe | "{36C6E06D-7BA9-44BC-9D04-93747189AC2C}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe | "{3784D2B0-D625-4DF8-BA96-9076FC956AE9}" = protocol=17 | dir=in | app=c:\program files (x86)\spotify\data\spotifywebhelper.exe | "{3E296C38-978E-41D3-8D5C-7AE324596C7C}" = protocol=6 | dir=in | app=c:\program files (x86)\windows searchqu toolbar\datamngr\toolbar\dtuser.exe | "{3F2A2E7D-498C-46B1-B0A5-89AB9554BFC9}" = dir=out | name=taptiles | "{418F3CC8-EC91-4F7B-A953-BA9592E16230}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{43EDDEEA-9167-48FC-BD53-04068365BBA4}" = dir=in | name=microsoft mahjong | "{46B2EAE5-0315-4F55-90BF-064854E768BE}" = dir=out | name=microsoft solitaire collection | "{4912F9AA-D51D-4271-BEDC-98F9752635DA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{4E8DD07B-31CF-440E-84F9-11CA85ED3998}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{51426E2C-B220-4B07-83C1-CC49F25B59D1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{54B3E3FA-AC0E-4BB5-990E-6ED269A32768}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe | "{57094769-71A3-4F63-ADF5-BCB03928EDB7}" = protocol=6 | dir=in | app=c:\program files (x86)\spotify\spotify.exe | "{57692CAB-0E16-44F1-A418-DB4FAC2D0942}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{59DFE29A-CD8D-4236-A49F-A9D6B8AFD10F}" = dir=out | name=pinball fx2 | "{5CD5807A-2B68-4405-B3EC-F9823503E894}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{5D940A74-AF2A-48D2-9274-4AC34C69880F}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{5E8F1DE8-F886-4D8A-9B09-38E6C7A174D9}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe | "{6112C3BF-E204-417A-AAA7-22C4EE8BB41C}" = dir=out | name=acer explorer | "{65568B90-7174-4DAB-A4F1-28C1D4CB1487}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe | "{679D8DD9-ECA5-46BE-B586-7791F7F07F5E}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{6CA280DF-B911-4102-A54F-5F31DC96D290}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{73CF38A4-DFCC-4A18-9A05-D41883D77425}" = protocol=6 | dir=out | app=system | "{7706C8F6-A3E5-4348-8E48-77570DB304FA}" = dir=out | name=ebay | "{78FFA0D4-AD9B-459A-9B8E-3E6C3E4C6E84}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\movie\playmovie.exe | "{7A119770-DB85-4027-8954-BB6D290F791F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{7AB5E106-42FE-4263-B223-6B8F360FFDC8}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe | "{7C27A398-1504-4004-B5C8-802AD4D5AF8F}" = protocol=17 | dir=in | app=c:\program files (x86)\spotify\spotify.exe | "{7DAEE777-D9CC-4D33-A009-EB8021FF48E4}" = dir=out | name=weatherbug | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{82D1AF1A-44F8-4467-93E4-7CDD18BE2683}" = protocol=6 | dir=in | app=c:\program files (x86)\spotify\data\spotifywebhelper.exe | "{8334C0C9-3058-4D07-B4FA-58806ECFA6FB}" = dir=in | name=skype | "{870222BD-078E-423B-ADA6-91B83E91BD81}" = dir=in | name=acer explorer | "{8854756F-8A2F-4B0A-84A4-36ADFEF26FD6}" = dir=out | name=adera | "{91C361C6-07C6-4A3D-A9FE-50BD8A9AE94F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{99A00C64-9BE6-46B4-A40C-E28ECBD42002}" = dir=out | name=tunein radio | "{A020BF3F-9C3C-4CBE-B03B-5164A40E80CD}" = dir=in | name=pinball fx2 | "{A587D61F-72A0-4E9D-B840-5A5FDA39FF13}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe | "{AA09D4BE-23D2-4566-9D8D-56422A663C21}" = dir=out | name=the treasures of montezuma 3 | "{AA4F4C4B-916E-4FF9-9812-DB84C2D21EE5}" = dir=in | name=evernote touch | "{AA655B94-8CB6-4956-A61D-3E5B57C90670}" = dir=out | name=@{microsoft.bingweather_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{AF717CA5-FF40-4F6E-BA7B-686F202FBCFF}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{B5BE08B6-397A-46B7-87B6-9E7806C985C5}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{C0E47374-CDED-43CB-B9D0-1B91A129A6DF}" = dir=out | name=shark dash | "{C2E192CE-13AC-4AA8-BFAD-C35501596C91}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{C3B9A21A-6CF8-4A72-BE30-E28F0514A8B7}" = dir=out | name=microsoft mahjong | "{C54D5B8C-9790-4090-8F2E-0A40C6CA1EBA}" = dir=out | name=@{microsoft.bingmaps_1.6.1821.2624_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{C91C8FFC-063D-423C-B4D5-19503AD478DC}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{CB5A72D6-26FA-493E-9C28-DCB10C63BF56}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{CD267F07-1D91-43E5-83B6-B13486301799}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{CDEB2A6D-AF69-44B2-BC0A-6985BD6CF227}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{CF8B2D63-30D6-451E-8995-B68BBF3A84E9}" = dir=in | name=newsxpresso | "{CFBF56AD-6F16-42CD-8CFF-7D7C81E52EA8}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\video\musicplayer.exe | "{D050434C-6D73-474F-94F8-A347D93D7EFF}" = dir=out | name=@{microsoft.bingnews_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{D0BB5F5F-3193-45E2-9A12-213A432E40CA}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{D7C22141-5D79-44F2-AA34-CC10F5E9DB4C}" = dir=in | name=microsoft minesweeper | "{DA9B29EB-78E6-446C-A5BB-64EFFFC0B155}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe | "{DAA394A2-F7E0-40E8-977A-E461DA9EF6B6}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{DF287487-5B93-4FAF-8EE5-17FB063870B0}" = dir=out | name=7digital music store | "{DF5C7F6D-8930-4B00-A583-676DFA1AE55A}" = dir=in | name=taptiles | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{EADFDFEB-6E3A-4298-930A-AD5A502C133B}" = dir=in | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{EBB703A5-6C85-4ECB-BFD1-1D365423066F}" = dir=out | name=skype | "{F373F23E-ABAF-4A3A-B35E-0939AE97DA8D}" = dir=in | name=microsoft solitaire collection | "{F3E501E0-DC1D-4ABF-8063-1B10F9301633}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{F64BC0B3-19C6-4667-8FC4-DE0BB4A529B5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FC6D7CBD-5AD6-4863-8D50-1B8F8E43B26D}" = dir=out | name=@{microsoft.bingtravel_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{FE2EF257-1C10-4928-93CA-1969A8B6BB62}" = dir=out | name=skitch touch | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}" = Acer Recovery Management "{0B78ECB0-1A6B-4E6D-89D7-0E7CE77F0427}" = MyWinLocker "{19CB64EB-ACFE-681D-B571-A8A3398F1943}" = AMD Catalyst Install Manager "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder "{4016464A-0C3E-4070-8293-5D7F0D8EAE3A}" = Adobe Premiere Elements 12 "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{559815B1-A489-9A58-6B5F-632E27CCAD54}" = AMD AVIVO64 Codecs "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{86A8BF23-E1A0-C52F-17A3-E3014C86152E}" = ccc-utility64 "{91F52DE4-B789-42B0-9311-A349F10E5479}" = Acer Power Management "{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64 "{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client "Bitdefender" = Bitdefender Internet Security 2013 "CCleaner" = CCleaner "EPSON Printer and Utilities" = EPSON Logiciel imprimante "Pen Tablet Driver" = Bamboo "PremElem120" = Adobe Premiere Elements 12 "PROSet" = Intel(R) Network Connections Drivers "VueScan x64" = VueScan x64 "Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin 64 bit [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0F08C4AC-C143-4D56-2467-8F227C3B3174}" = Catalyst Control Center "{148C8BF9-E1B4-445D-AC67-2CABAE63949A}" = Epson Event Manager "{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite "{182728B1-8727-4AB3-A1AE-F1ED2C8B1BAC}" = Catalyst Control Center - Branding "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F2984E4-B954-8D3D-270A-C56DCA17C127}" = CCC Help Danish "{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email "{2470F852-5FFF-EDCA-0AD1-BE0667470F48}" = CCC Help Norwegian "{2502CD92-F99E-4246-85ED-A48BA943B3A1}_is1" = DxO Optics Pro import plugin "{26345ECA-A514-0E5F-88CA-79F1D8508F26}" = CCC Help Chinese Traditional "{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant "{2D6FA081-495F-9B0F-DBA1-8501943F1116}" = CCC Help Turkish "{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager "{2F90A789-DD1E-41CE-BFCA-BD78213BABC7}" = OpenOffice.org 3.4 "{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App "{35DA427D-BB23-49B8-9AFD-CFFCFE3B708D}" = clear.fi SDK- Movie 2 "{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime "{39F15B50-A977-4CA6-B1C3-6A8724CDA025}" = MyWinLocker 4 "{3B8F29EB-703C-4723-8CDE-4B2E5D695972}" = DxO Optics Pro 6 "{3D78F2A2-C893-4ABD-B5FE-AD7011837755}" = EPSON Easy Photo Print "{3D7F8D64-01E9-3974-E4FE-E65AEECADC8C}" = CCC Help German "{3D9CB654-99AD-4301-89C6-0D12A790767C}" = Identity Card "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{42EDF895-158C-484E-A7F2-42B90759F281}" = Camera RAW Plug-In for EPSON Creativity Suite "{43C423D9-E6D6-4607-ADC9-EBB54F690C57}" = Seagate Dashboard 2.0 "{49F225AD-969D-5B88-C8D0-7D78EB0044ED}" = CCC Help Russian "{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}" = Google Earth Plug-in "{5587ED78-9E1B-7606-EF39-70031DFA86F4}" = CCC Help Greek "{5AC083E1-47DD-7C36-705F-17970A9FB566}" = CCC Help Hungarian "{5B81F6D8-AFA6-BBD4-0B74-342EE195C4FF}" = Catalyst Control Center InstallProxy "{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 "{61D2FA89-5AC0-BBD2-5552-36E9FC0D40F2}" = CCC Help Italian "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{6ABCA9B3-DB26-8099-0B2C-8CD13E7709E0}" = CCC Help English "{6D2BBE1D-E600-4695-BA37-0B0E605542CC}" = Office Addin "{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer" = WildTangent Games App "{72318469-1238-30FB-6069-ADF6CC9998AC}" = CCC Help Swedish "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{73A56EB0-9633-6864-E012-C026A3ADEEEC}" = CCC Help Japanese "{777B751F-C904-4BD7-8DFF-81F97A3C0BC5}" = Adobe Photoshop Elements 12 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{841AFCE1-383C-A89F-366D-83620CD0F4CA}" = CCC Help French "{86CE88A4-EF02-2EAB-328F-2E17D856B323}" = CCC Help Czech "{89D34078-8AB9-9FA7-55D4-4B502F716AEB}" = CCC Help Thai "{8ACCD8E0-BF86-8A47-C651-D37F4F5B2ACC}" = CCC Help Dutch "{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime "{92C1D2D7-8AD5-48A0-970E-A8AC006FF299}" = Epson Print Plug-In for Photoshop "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9C9446C7-26A8-AE84-B712-E2B16147D693}" = CCC Help Finnish "{9D80A7B7-DC01-485D-AE93-710D559B5C56}" = Elements 12 Organizer "{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}" = AcerCloud "{A694AF57-9891-4D62-824C-7E55A1361A14}" = eBay Worldwide "{A6DC88AD-501A-44BC-884D-57435F972E2C}" = Hotkey Utility "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}" = Epson Copy Utility 3.5 "{AC76BA86-7AD7-1036-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) - Français "{B2670B9D-A2D7-425B-83ED-728767906D04}" = DxO Optics Pro 6 "{B4A3C072-87AF-4937-880D-3D7997111C0D}" = Document Capture Pro "{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder "{C33F7349-6E7A-4319-2F44-D0E78AB4CD5B}" = CCC Help Portuguese "{C5988CB0-8E2C-08F6-5C34-7689C9C5A696}" = CCC Help Polish "{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}" = AcerCloud Docs "{D16A31F9-276D-4968-A753-FFEAC56995D0}" = Epson Print CD "{E0364441-5551-5DD2-0833-43EA612986A9}" = Catalyst Control Center Localization All "{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso 6.5 "{EBA33CAD-E071-48d5-A168-FBA4EEB42E93}" = clear.fi SDK - Video 2 "{EE26E302-876A-48D9-9058-3129E5B99999}" = Live Updater "{EE50081C-89B1-700E-D60E-B66453635250}" = CCC Help Chinese Standard "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F3E11D62-47E6-8E81-CCFC-3BEFB14243EC}" = CCC Help Spanish "{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint "{FB46F473-333E-4A06-A777-31C54188593E}" = ArcSoft MediaImpression 2 "{FC23B1B6-9916-E256-7397-896706B53C49}" = CCC Help Korean "{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD "7-Zip" = 7-Zip 9.22beta "ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint "Adobe Photoshop Elements 12" = Adobe Photoshop Elements 12 "Audacity_is1" = Audacity 2.0.2 "CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX "Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX "Canon MOV Decoder" = Canon MOV Decoder "Canon MOV Encoder" = Canon MOV Encoder "CDex" = CDex - Open Source Digital Audio CD Extractor "DPP" = Canon Utilities Digital Photo Professional 3.9 "EOS Utility" = Canon Utilities EOS Utility "Epson Perfection V370 Photo Useg" = Epson Guide d'utilisation Epson Perfection V370 Photo "EPSON Scanner" = EPSON Scan "EPSON Stylus Photo R1900 Guide d'utilisation" = EPSON Stylus Photo R1900 Manuel "fileopenerpro" = File Opener Pro "Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 2.2 "Google Chrome" = Google Chrome "InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite "InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email "InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso 6.5 "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300 "Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools pour Office Second Edition Runtime "MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX "MyCamera Download Plugin" = CANON iMAGE GATEWAY MyCamera Download Plugin "PhotoStitch" = Canon Utilities PhotoStitch "Picture Style Editor" = Canon Utilities Picture Style Editor "PortraitProfessional10_is1" = Portrait Professional 10.8 "ProShow Producer" = ProShow Producer "Rainlendar2" = Rainlendar2 (remove only) "Spotify" = Spotify "VLC media player" = VLC media player 2.0.6 "Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin 32 bit "WFTK" = Canon Utilities WFT Utility "WildTangent wildgames Master Uninstall" = WildTangent Games "ZoomBrowser EX" = Canon Utilities ZoomBrowser EX "ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 22/01/2014 10:26:23 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:26:38 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:26:53 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:27:08 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:27:23 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:27:38 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:27:53 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:28:08 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:28:23 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:28:38 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error [ System Events ] Error - 21/09/2013 16:24:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:25:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:26:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:27:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:28:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:29:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:30:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:31:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:32:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:33:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 < End of report > OTL Extras logfile created on: 22/01/2014 15:18:09 - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jacques\Downloads 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16750) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 5,95 Gb Total Physical Memory | 4,41 Gb Available Physical Memory | 74,06% Memory free 6,89 Gb Paging File | 4,51 Gb Available in Paging File | 65,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 455,95 Gb Total Space | 400,10 Gb Free Space | 87,75% Space Free | Partition Type: NTFS Drive D: | 456,76 Gb Total Space | 150,65 Gb Free Space | 32,98% Space Free | Partition Type: NTFS Drive F: | 1863,01 Gb Total Space | 1556,45 Gb Free Space | 83,54% Space Free | Partition Type: NTFS Drive G: | 14,90 Gb Total Space | 2,05 Gb Free Space | 13,76% Space Free | Partition Type: FAT32 Computer Name: DESCOUT | User Name: Jacques | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (All) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation) .hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation) .txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation) .vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) .wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .bat [@ = batfile] -- "%1" %* .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation) .cmd [@ = cmdfile] -- "%1" %* .com [@ = comfile] -- "%1" %* .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .exe [@ = exefile] -- "%1" %* .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .hta [@ = htafile] -- "%1" %* .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .pif [@ = piffile] -- "%1" %* .reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation) .scr [@ = scrfile] -- "%1" /S .txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation) .vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) .wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-4014571762-1555873058-2083660991-1001\SOFTWARE\Classes\] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [Digital Photo Professional] -- C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation) cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation) comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htafile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation) jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation) jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation) regfile [open] -- regedit.exe "%1" (Microsoft Corporation) regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation) scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation) vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation) wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation) wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation) Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [Digital Photo Professional] -- C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{07DE5286-0999-497E-9289-6F76557C2681}" = lport=138 | protocol=17 | dir=in | app=system | "{19B1B087-E8DB-4E98-9111-95F94E615EEF}" = rport=139 | protocol=6 | dir=out | app=system | "{2501D5A8-3A97-4E75-B6F7-3A91FCE3D68E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{2BB47BD2-35C1-4944-B731-11959CB63B68}" = rport=138 | protocol=17 | dir=out | app=system | "{653C4F24-0513-4792-8384-CD0573B087D8}" = rport=137 | protocol=17 | dir=out | app=system | "{688664B4-D49C-4359-97E0-0CFD3A060D9A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{7A8FFADE-B455-4677-B573-F3167F01AB14}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{7FE2FB88-BBD1-4B13-A2EF-4A57E9D11899}" = rport=445 | protocol=6 | dir=out | app=system | "{84BCB79B-4426-4F9A-BAF2-462F2DC5CB6C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{89C3DE41-DDB7-424F-A108-E32CF8E035E9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{9ABAA41A-5021-4D1E-A64A-F009B0E9C9D5}" = lport=139 | protocol=6 | dir=in | app=system | "{9F1870BE-EB97-4E84-8E91-D9A0A6C21C60}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A36208A4-473C-4B8D-955D-F8C1615FAC3E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B0648CA1-AC95-4B54-B197-DA2B0B397E91}" = lport=10243 | protocol=6 | dir=in | app=system | "{BE6F129A-628E-48D2-93DD-9EDA4B247474}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{BEF4D8EF-3B82-4B24-8913-02C053D1F521}" = lport=137 | protocol=17 | dir=in | app=system | "{CBD10BA0-B7BE-44F4-80E3-F80E4BB2B6E5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E44FBBF3-A828-4585-A778-CDA68ED6C93A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{E6534095-2311-42D9-95BA-940B91094C94}" = lport=445 | protocol=6 | dir=in | app=system | "{F629ACC7-B46B-4479-8FB7-0ACB1E2B3F33}" = lport=2869 | protocol=6 | dir=in | app=system | "{F9D56395-1F97-48C5-B762-EF6563E3B257}" = rport=10243 | protocol=6 | dir=out | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{008063D6-AFEE-4DC3-9977-CA29C8DF8941}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe | "{00B1CE50-83FC-4ACC-BBA1-7611186C14B2}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{0176737D-36B7-4B74-B422-810F3B9F931B}" = dir=out | name=kindle | "{0178D9D4-84CA-4ABE-B416-C7AF44E9132F}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe | "{0265E315-D602-45FF-BE5B-528CC861DAC0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{06826894-385F-4C78-910F-D34C1B237111}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{0D924137-13FB-4729-9B41-F89C3EEBCA75}" = dir=out | name=@{microsoft.bingfinance_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{152711D2-9E38-487F-8D3D-A26FB2914949}" = dir=out | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{16EB537E-3CE6-471B-8E6D-CC6427A44AA4}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1CCDD747-FE8E-4F72-B6DB-B50177131755}" = dir=out | name=windows_ie_ac_001 | "{1CEBB0F8-1019-4218-B610-E2EA651586FB}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{1E85770A-C53C-434F-81B7-396505272EA3}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe | "{1F037CF9-1E3C-4F5F-9F81-C57A77C8EE3E}" = dir=out | name=@{microsoft.zunevideo_1.5.299.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{1F81CE6A-3038-40E2-8769-3F8B3B5DEDE4}" = dir=out | name=microsoft minesweeper | "{2105AC8B-6BCE-4A2A-ACC0-4530F35BCDD8}" = protocol=17 | dir=in | app=c:\program files (x86)\windows searchqu toolbar\datamngr\toolbar\dtuser.exe | "{2241B542-415D-4AF4-ADDC-881B97E0C809}" = dir=out | name=newsxpresso | "{26C6A797-F82B-4C35-B34F-1795A13B4B6B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{2C1AF343-493B-409F-AFE8-A49D4B08D585}" = dir=out | name=@{microsoft.bingsports_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{2D833F7C-E542-407C-A0A2-DD06552BE4B5}" = dir=out | name=cut the rope | "{3049448D-BC45-4AB7-858D-47CC7B721102}" = dir=out | name=@{microsoft.zunemusic_1.5.214.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{304ECEBA-E776-4B65-B968-5FA1D053B758}" = dir=out | name=@{microsoft.xboxlivegames_1.3.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{345C96C9-2C6B-4121-94E8-9D8B62E73DA5}" = dir=out | name=evernote touch | "{3526F3E1-9586-485F-A0CE-4EF5FF94A548}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\video\videoplayer.exe | "{36C6E06D-7BA9-44BC-9D04-93747189AC2C}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe | "{3784D2B0-D625-4DF8-BA96-9076FC956AE9}" = protocol=17 | dir=in | app=c:\program files (x86)\spotify\data\spotifywebhelper.exe | "{3E296C38-978E-41D3-8D5C-7AE324596C7C}" = protocol=6 | dir=in | app=c:\program files (x86)\windows searchqu toolbar\datamngr\toolbar\dtuser.exe | "{3F2A2E7D-498C-46B1-B0A5-89AB9554BFC9}" = dir=out | name=taptiles | "{418F3CC8-EC91-4F7B-A953-BA9592E16230}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{43EDDEEA-9167-48FC-BD53-04068365BBA4}" = dir=in | name=microsoft mahjong | "{46B2EAE5-0315-4F55-90BF-064854E768BE}" = dir=out | name=microsoft solitaire collection | "{4912F9AA-D51D-4271-BEDC-98F9752635DA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{4E8DD07B-31CF-440E-84F9-11CA85ED3998}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{51426E2C-B220-4B07-83C1-CC49F25B59D1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{54B3E3FA-AC0E-4BB5-990E-6ED269A32768}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe | "{57094769-71A3-4F63-ADF5-BCB03928EDB7}" = protocol=6 | dir=in | app=c:\program files (x86)\spotify\spotify.exe | "{57692CAB-0E16-44F1-A418-DB4FAC2D0942}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{59DFE29A-CD8D-4236-A49F-A9D6B8AFD10F}" = dir=out | name=pinball fx2 | "{5CD5807A-2B68-4405-B3EC-F9823503E894}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{5D940A74-AF2A-48D2-9274-4AC34C69880F}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{5E8F1DE8-F886-4D8A-9B09-38E6C7A174D9}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe | "{6112C3BF-E204-417A-AAA7-22C4EE8BB41C}" = dir=out | name=acer explorer | "{65568B90-7174-4DAB-A4F1-28C1D4CB1487}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe | "{679D8DD9-ECA5-46BE-B586-7791F7F07F5E}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{6CA280DF-B911-4102-A54F-5F31DC96D290}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{73CF38A4-DFCC-4A18-9A05-D41883D77425}" = protocol=6 | dir=out | app=system | "{7706C8F6-A3E5-4348-8E48-77570DB304FA}" = dir=out | name=ebay | "{78FFA0D4-AD9B-459A-9B8E-3E6C3E4C6E84}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\movie\playmovie.exe | "{7A119770-DB85-4027-8954-BB6D290F791F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{7AB5E106-42FE-4263-B223-6B8F360FFDC8}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe | "{7C27A398-1504-4004-B5C8-802AD4D5AF8F}" = protocol=17 | dir=in | app=c:\program files (x86)\spotify\spotify.exe | "{7DAEE777-D9CC-4D33-A009-EB8021FF48E4}" = dir=out | name=weatherbug | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{82D1AF1A-44F8-4467-93E4-7CDD18BE2683}" = protocol=6 | dir=in | app=c:\program files (x86)\spotify\data\spotifywebhelper.exe | "{8334C0C9-3058-4D07-B4FA-58806ECFA6FB}" = dir=in | name=skype | "{870222BD-078E-423B-ADA6-91B83E91BD81}" = dir=in | name=acer explorer | "{8854756F-8A2F-4B0A-84A4-36ADFEF26FD6}" = dir=out | name=adera | "{91C361C6-07C6-4A3D-A9FE-50BD8A9AE94F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{99A00C64-9BE6-46B4-A40C-E28ECBD42002}" = dir=out | name=tunein radio | "{A020BF3F-9C3C-4CBE-B03B-5164A40E80CD}" = dir=in | name=pinball fx2 | "{A587D61F-72A0-4E9D-B840-5A5FDA39FF13}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe | "{AA09D4BE-23D2-4566-9D8D-56422A663C21}" = dir=out | name=the treasures of montezuma 3 | "{AA4F4C4B-916E-4FF9-9812-DB84C2D21EE5}" = dir=in | name=evernote touch | "{AA655B94-8CB6-4956-A61D-3E5B57C90670}" = dir=out | name=@{microsoft.bingweather_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | "{AF717CA5-FF40-4F6E-BA7B-686F202FBCFF}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{B5BE08B6-397A-46B7-87B6-9E7806C985C5}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{C0E47374-CDED-43CB-B9D0-1B91A129A6DF}" = dir=out | name=shark dash | "{C2E192CE-13AC-4AA8-BFAD-C35501596C91}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{C3B9A21A-6CF8-4A72-BE30-E28F0514A8B7}" = dir=out | name=microsoft mahjong | "{C54D5B8C-9790-4090-8F2E-0A40C6CA1EBA}" = dir=out | name=@{microsoft.bingmaps_1.6.1821.2624_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{C91C8FFC-063D-423C-B4D5-19503AD478DC}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{CB5A72D6-26FA-493E-9C28-DCB10C63BF56}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{CD267F07-1D91-43E5-83B6-B13486301799}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{CDEB2A6D-AF69-44B2-BC0A-6985BD6CF227}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{CF8B2D63-30D6-451E-8995-B68BBF3A84E9}" = dir=in | name=newsxpresso | "{CFBF56AD-6F16-42CD-8CFF-7D7C81E52EA8}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\video\musicplayer.exe | "{D050434C-6D73-474F-94F8-A347D93D7EFF}" = dir=out | name=@{microsoft.bingnews_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{D0BB5F5F-3193-45E2-9A12-213A432E40CA}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | "{D7C22141-5D79-44F2-AA34-CC10F5E9DB4C}" = dir=in | name=microsoft minesweeper | "{DA9B29EB-78E6-446C-A5BB-64EFFFC0B155}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe | "{DAA394A2-F7E0-40E8-977A-E461DA9EF6B6}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{DF287487-5B93-4FAF-8EE5-17FB063870B0}" = dir=out | name=7digital music store | "{DF5C7F6D-8930-4B00-A583-676DFA1AE55A}" = dir=in | name=taptiles | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{EADFDFEB-6E3A-4298-930A-AD5A502C133B}" = dir=in | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{EBB703A5-6C85-4ECB-BFD1-1D365423066F}" = dir=out | name=skype | "{F373F23E-ABAF-4A3A-B35E-0939AE97DA8D}" = dir=in | name=microsoft solitaire collection | "{F3E501E0-DC1D-4ABF-8063-1B10F9301633}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{F64BC0B3-19C6-4667-8FC4-DE0BB4A529B5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{FC6D7CBD-5AD6-4863-8D50-1B8F8E43B26D}" = dir=out | name=@{microsoft.bingtravel_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{FE2EF257-1C10-4928-93CA-1969A8B6BB62}" = dir=out | name=skitch touch | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}" = Acer Recovery Management "{0B78ECB0-1A6B-4E6D-89D7-0E7CE77F0427}" = MyWinLocker "{19CB64EB-ACFE-681D-B571-A8A3398F1943}" = AMD Catalyst Install Manager "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder "{4016464A-0C3E-4070-8293-5D7F0D8EAE3A}" = Adobe Premiere Elements 12 "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime "{559815B1-A489-9A58-6B5F-632E27CCAD54}" = AMD AVIVO64 Codecs "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{86A8BF23-E1A0-C52F-17A3-E3014C86152E}" = ccc-utility64 "{91F52DE4-B789-42B0-9311-A349F10E5479}" = Acer Power Management "{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64 "{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client "Bitdefender" = Bitdefender Internet Security 2013 "CCleaner" = CCleaner "EPSON Printer and Utilities" = EPSON Logiciel imprimante "Pen Tablet Driver" = Bamboo "PremElem120" = Adobe Premiere Elements 12 "PROSet" = Intel(R) Network Connections Drivers "VueScan x64" = VueScan x64 "Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin 64 bit [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0F08C4AC-C143-4D56-2467-8F227C3B3174}" = Catalyst Control Center "{148C8BF9-E1B4-445D-AC67-2CABAE63949A}" = Epson Event Manager "{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite "{182728B1-8727-4AB3-A1AE-F1ED2C8B1BAC}" = Catalyst Control Center - Branding "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F2984E4-B954-8D3D-270A-C56DCA17C127}" = CCC Help Danish "{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email "{2470F852-5FFF-EDCA-0AD1-BE0667470F48}" = CCC Help Norwegian "{2502CD92-F99E-4246-85ED-A48BA943B3A1}_is1" = DxO Optics Pro import plugin "{26345ECA-A514-0E5F-88CA-79F1D8508F26}" = CCC Help Chinese Traditional "{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant "{2D6FA081-495F-9B0F-DBA1-8501943F1116}" = CCC Help Turkish "{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager "{2F90A789-DD1E-41CE-BFCA-BD78213BABC7}" = OpenOffice.org 3.4 "{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App "{35DA427D-BB23-49B8-9AFD-CFFCFE3B708D}" = clear.fi SDK- Movie 2 "{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime "{39F15B50-A977-4CA6-B1C3-6A8724CDA025}" = MyWinLocker 4 "{3B8F29EB-703C-4723-8CDE-4B2E5D695972}" = DxO Optics Pro 6 "{3D78F2A2-C893-4ABD-B5FE-AD7011837755}" = EPSON Easy Photo Print "{3D7F8D64-01E9-3974-E4FE-E65AEECADC8C}" = CCC Help German "{3D9CB654-99AD-4301-89C6-0D12A790767C}" = Identity Card "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{42EDF895-158C-484E-A7F2-42B90759F281}" = Camera RAW Plug-In for EPSON Creativity Suite "{43C423D9-E6D6-4607-ADC9-EBB54F690C57}" = Seagate Dashboard 2.0 "{49F225AD-969D-5B88-C8D0-7D78EB0044ED}" = CCC Help Russian "{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}" = Google Earth Plug-in "{5587ED78-9E1B-7606-EF39-70031DFA86F4}" = CCC Help Greek "{5AC083E1-47DD-7C36-705F-17970A9FB566}" = CCC Help Hungarian "{5B81F6D8-AFA6-BBD4-0B74-342EE195C4FF}" = Catalyst Control Center InstallProxy "{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 "{61D2FA89-5AC0-BBD2-5552-36E9FC0D40F2}" = CCC Help Italian "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{6ABCA9B3-DB26-8099-0B2C-8CD13E7709E0}" = CCC Help English "{6D2BBE1D-E600-4695-BA37-0B0E605542CC}" = Office Addin "{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer" = WildTangent Games App "{72318469-1238-30FB-6069-ADF6CC9998AC}" = CCC Help Swedish "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{73A56EB0-9633-6864-E012-C026A3ADEEEC}" = CCC Help Japanese "{777B751F-C904-4BD7-8DFF-81F97A3C0BC5}" = Adobe Photoshop Elements 12 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{841AFCE1-383C-A89F-366D-83620CD0F4CA}" = CCC Help French "{86CE88A4-EF02-2EAB-328F-2E17D856B323}" = CCC Help Czech "{89D34078-8AB9-9FA7-55D4-4B502F716AEB}" = CCC Help Thai "{8ACCD8E0-BF86-8A47-C651-D37F4F5B2ACC}" = CCC Help Dutch "{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime "{92C1D2D7-8AD5-48A0-970E-A8AC006FF299}" = Epson Print Plug-In for Photoshop "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9C9446C7-26A8-AE84-B712-E2B16147D693}" = CCC Help Finnish "{9D80A7B7-DC01-485D-AE93-710D559B5C56}" = Elements 12 Organizer "{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}" = AcerCloud "{A694AF57-9891-4D62-824C-7E55A1361A14}" = eBay Worldwide "{A6DC88AD-501A-44BC-884D-57435F972E2C}" = Hotkey Utility "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}" = Epson Copy Utility 3.5 "{AC76BA86-7AD7-1036-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) - Français "{B2670B9D-A2D7-425B-83ED-728767906D04}" = DxO Optics Pro 6 "{B4A3C072-87AF-4937-880D-3D7997111C0D}" = Document Capture Pro "{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder "{C33F7349-6E7A-4319-2F44-D0E78AB4CD5B}" = CCC Help Portuguese "{C5988CB0-8E2C-08F6-5C34-7689C9C5A696}" = CCC Help Polish "{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}" = AcerCloud Docs "{D16A31F9-276D-4968-A753-FFEAC56995D0}" = Epson Print CD "{E0364441-5551-5DD2-0833-43EA612986A9}" = Catalyst Control Center Localization All "{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso 6.5 "{EBA33CAD-E071-48d5-A168-FBA4EEB42E93}" = clear.fi SDK - Video 2 "{EE26E302-876A-48D9-9058-3129E5B99999}" = Live Updater "{EE50081C-89B1-700E-D60E-B66453635250}" = CCC Help Chinese Standard "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F3E11D62-47E6-8E81-CCFC-3BEFB14243EC}" = CCC Help Spanish "{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint "{FB46F473-333E-4A06-A777-31C54188593E}" = ArcSoft MediaImpression 2 "{FC23B1B6-9916-E256-7397-896706B53C49}" = CCC Help Korean "{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD "7-Zip" = 7-Zip 9.22beta "ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint "Adobe Photoshop Elements 12" = Adobe Photoshop Elements 12 "Audacity_is1" = Audacity 2.0.2 "CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX "Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX "Canon MOV Decoder" = Canon MOV Decoder "Canon MOV Encoder" = Canon MOV Encoder "CDex" = CDex - Open Source Digital Audio CD Extractor "DPP" = Canon Utilities Digital Photo Professional 3.9 "EOS Utility" = Canon Utilities EOS Utility "Epson Perfection V370 Photo Useg" = Epson Guide d'utilisation Epson Perfection V370 Photo "EPSON Scanner" = EPSON Scan "EPSON Stylus Photo R1900 Guide d'utilisation" = EPSON Stylus Photo R1900 Manuel "fileopenerpro" = File Opener Pro "Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 2.2 "Google Chrome" = Google Chrome "InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite "InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email "InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso 6.5 "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300 "Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools pour Office Second Edition Runtime "MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX "MyCamera Download Plugin" = CANON iMAGE GATEWAY MyCamera Download Plugin "PhotoStitch" = Canon Utilities PhotoStitch "Picture Style Editor" = Canon Utilities Picture Style Editor "PortraitProfessional10_is1" = Portrait Professional 10.8 "ProShow Producer" = ProShow Producer "Rainlendar2" = Rainlendar2 (remove only) "Spotify" = Spotify "VLC media player" = VLC media player 2.0.6 "Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin 32 bit "WFTK" = Canon Utilities WFT Utility "WildTangent wildgames Master Uninstall" = WildTangent Games "ZoomBrowser EX" = Canon Utilities ZoomBrowser EX "ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 22/01/2014 10:26:23 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:26:38 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:26:53 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:27:08 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:27:23 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:27:38 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:27:53 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:28:08 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:28:23 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error Error - 22/01/2014 10:28:38 | Computer Name = DESCOUT | Source = ATIeRecord | ID = 16388 Description = ATI EEU Client event error [ System Events ] Error - 21/09/2013 16:24:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:25:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:26:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:27:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:28:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:29:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:30:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:31:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:32:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 Error - 21/09/2013 16:33:02 | Computer Name = DESCOUT | Source = Service Control Manager | ID = 7000 Description = Le service BitGuard n’a pas pu démarrer en raison de l’erreur : %%2 < End of report >