Je n'arrive pas a mettre google en page de démarrage !!!

ilnamso Messages postés 253 Statut Membre -  
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   -
Salut

je n'arrive pas a mettre google en page de démarage il ya un autre moteur de recherche qui sort qui s'appelle "search-certified-toolbar"

j'ai essayer dans les paramétre j'aplique les parametre et quand je reouvre sa me met pas google en page de démarrage encore se "search-certified toolbar" que je n'arrive pas a enlever

jai aussi essayer de mettre google en page de démarrage sur son site mais sa ne marche pas !

il ya un site qui dise que c'est un virus ce site la https://lesvirus.fr/search-certified-toolbar-com/

Aider moi SVP
Merci d'avance

10 réponses

Résumé de la discussion

Problème rencontré : Google ne peut pas être défini comme page d'accueil car une barre d'outils nommée search-certified-toolbar s'impose et empêche les réglages, alimentant des inquiétudes sur une potentielle infection. Pour résoudre ce problème, la solution retenue privilégie le téléchargement d’AdwCleaner et l’option suppression pour éliminer les composants indésirables et rétablir Google comme page d'accueil. Des échanges complémentaires évoquent aussi la vérification des emplacements d’apparition et la nécessité d’un nettoyage approfondi côté navigateur, en complément d’un éventuel redémarrage du système. Des éléments techniques incluent des extraits de logs et de scans comme OTL Extras, illustrant des détails de registre et de paramètres système pouvant accompagner ce type d'infection.

Bobot (l'IA à votre service)
  1. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Bonjour,

    --> Télécharge et lance AdwCleaner (d'Xplode), choisis l'option "Suppression" et poste le rapport.
    0
  2. ilnamso Messages postés 253 Statut Membre 44
     
    attent jessai dejas avec Spyhunter apres on verra
    0
    1. ilnamso Messages postés 253 Statut Membre 44
       
      ookmec merci avant de le telecharger
      0
    2. ilnamso Messages postés 253 Statut Membre 44
       
      AdwCleaner
      0
    3. ilnamso Messages postés 253 Statut Membre 44
       
      j'essaie
      0
    4. ilnamso Messages postés 253 Statut Membre 44
       
      apres
      0
  3. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    --> Télécharge ZHPDiag (de Nicolas Coolman).

    --> Double-clique sur le fichier d'installation. Installe ZHPDiag avec les paramètres par défaut (laisse "Créer une icône sur le Bureau" coché).

    --> Lance ZHPDiag en double-cliquant sur le raccourci présent sur ton Bureau.
    (Sous Vista/Win7/Win8, il faut cliquer droit sur le raccourci de ZHPDiag et choisir "Exécuter en tant qu'administrateur")

    --> Clique sur la loupe (Lancer le diagnostic) puis laisse l'outil scanner.

    --> Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier (le rapport de l'analyse) sur ton Bureau.

    --> Utilise le site http://pjjoint.malekal.com/ pour me transmettre le rapport ZHPDiag car il est plutôt long. Copie-colle le lien donné par le site dans ton prochain message.
    0
  4. ilnamso Messages postés 253 Statut Membre 44
     
    salut,
    dit moi des information plus précise je peut pas le telecharger d'autre par
    0
    1. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
       
      0
    2. ilnamso Messages postés 253 Statut Membre 44
       
      ya pa de loupe
      0
    3. ilnamso Messages postés 253 Statut Membre 44
       
      ok
      0
    4. ilnamso Messages postés 253 Statut Membre 44
       
      sa met traitmement en cours et j'attent ??
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. ilnamso Messages postés 253 Statut Membre 44
     
    comment on lance le telechargement !
    0
    1. ilnamso Messages postés 253 Statut Membre 44
       
      ta Facebook ou autre pour discuter parce que laon doit attendre tout les 2o min
      0
    2. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
       
      Non, la discussion doit se poursuivre sur le sujet.

      Tu as réussi à télécharger AdwCleaner, fais pareil pour ZHPDiag.
      0
    3. ilnamso Messages postés 253 Statut Membre 44
       
      ok apres avoir telecharger
      0
  7. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    --> Copie tout le texte présent en gras ci-dessous (Sélectionne-le, clique droit dessus et choisis "Copier").

    SysRestore
    O4 - HKLM\..\Wow6432Node\Run: [Advanced System Protector_startup] C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe (.not file.)
    O39 - APT:Automatic Planified Task - C:\Windows\Tasks\RegClean Pro.job
    [HKCU\Software\Systweak]
    [HKLM\Software\Wow6432Node\Systweak]
    O43 - CFD: 31/12/2012 - 21:07:39 - [12,210] ----D C:\ProgramData\Systweak
    O43 - CFD: 31/12/2012 - 21:07:43 - [0,244] ----D C:\Users\Tunc\AppData\Roaming\Systweak
    O44 - LFC:[MD5.CE251790D21B525FE220CAF49EBDB356] - 31/12/2012 - 21:04:47 ---A- . (.Systweak Inc., (www.systweak.com) - Regclean Pro.) -- C:\Windows\SysNative\roboot64.exe [19896]
    O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Web Search) - http://ww7.certified-toolbar.com
    O69 - SBI: SearchScopes [HKCR] {afdbddaa-5d3f-42ee-b79c-185a7020515b} - (Web Search) - http://ww7.certified-toolbar.com
    O87 - FAEL: "{2CC49C47-7543-480A-B14A-DC38FD45E0DC}" |In - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Protected Search\ProtectedSearch.exe (.not file.)
    O87 - FAEL: "{5F634AB8-EFFA-421C-A4FB-1D77A5094B62}" |Out - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Protected Search\ProtectedSearch.exe (.not file.)
    O87 - FAEL: "{842FF703-EFCA-45DC-BEF9-175B39D75DB7}" |In - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Protected Search\ProtectedSearch.exe (.not file.)
    O87 - FAEL: "{5840DD07-4698-4E64-8B26-B31B69500EB8}" |Out - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Protected Search\ProtectedSearch.exe (.not file.)
    C:\Program Files (x86)\Advanced System Protector
    EmptyCLSID
    EmptyFlash
    EmptyTemp


    --> Puis lance ZHPFix depuis le raccourci situé sur ton Bureau.
    (Sous Vista/Win7/Win8, il faut cliquer droit sur le raccourci de ZHPFix et choisir Exécuter en tant qu'administrateur)

    --> Une fois ZHPFix ouvert, clique sur le bouton "Coller le presse-papier".

    --> Dans l'encadré principal, tu verras donc les lignes que tu as copié précédemment apparaître. Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

    --> Clique sur "GO" pour lancer le nettoyage. Laisse l'outil travailler et ne touche à rien.

    --> Une fois terminé, copie-colle le rapport dans ton prochain message.
    0
    1. ilnamso Messages postés 253 Statut Membre 44
       
      voici le message

      Rapport de ZHPFix 1.3.11 par Nicolas Coolman, Update du 30/12/2012
      Fichier d'export Registre :
      Run by Tunc at 16/01/2013 16:31:47
      Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)



      ========== Clé(s) du Registre ==========
      ABSENT Key: HKCU\Software\Systweak
      ABSENT Key: HKLM\Software\Wow6432Node\Systweak
      ABSENT SearchScopes :{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
      ABSENT SearchScopes :{afdbddaa-5d3f-42ee-b79c-185a7020515b}

      ========== Valeur(s) du Registre ==========
      ABSENT RunValue: Advanced System Protector_startup
      ABSENT {2CC49C47-7543-480A-B14A-DC38FD45E0DC}
      ABSENT {5F634AB8-EFFA-421C-A4FB-1D77A5094B62}
      ABSENT {842FF703-EFCA-45DC-BEF9-175B39D75DB7}
      ABSENT {5840DD07-4698-4E64-8B26-B31B69500EB8}

      ========== Dossier(s) ==========
      SUPPRIME Flash Cookies:
      SUPPRIME Temporaires Windows:

      ========== Fichier(s) ==========
      ABSENT File: c:\program files (x86)\advanced system protector\advancedsystemprotector.exe
      ABSENT File: c:\windows\tasks\regclean pro.job
      ABSENT File: c:\windows\system32\roboot64.exe
      ABSENT Folder/File: c:\program files (x86)\advanced system protector
      SUPPRIME Flash Cookies:
      SUPPRIME Temporaires Windows:

      ========== Restauration Système ==========
      Point de restauration du système créé avec succès


      ========== Récapitulatif ==========
      4 : Clé(s) du Registre
      5 : Valeur(s) du Registre
      2 : Dossier(s)
      6 : Fichier(s)
      1 : Restauration Système


      End of clean in 00mn 09s

      ========== Chemin de fichier rapport ==========
      C:\ZHP\ZHPFix[R1].txt - 16/01/2013 15:08:45 [2072]
      C:\ZHP\ZHPFix[R2].txt - 16/01/2013 15:16:25 [3786]
      C:\ZHP\ZHPFix[R3].txt - 16/01/2013 16:28:23 [1700]
      C:\ZHP\ZHPFix[R4].txt - 16/01/2013 16:30:37 [1719]
      C:\ZHP\ZHPFix[R5].txt - 16/01/2013 16:31:47 [1719]
      0
  8. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Il te reste quel(s) souci(s) ?
    0
    1. ilnamso Messages postés 253 Statut Membre 44
       
      sa me sort encore search-certified-toolbar
      0
    2. ilnamso Messages postés 253 Statut Membre 44
       
      au demarrage
      0
    3. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
       
      Sur Google Chrome ?
      0
    4. ilnamso Messages postés 253 Statut Membre 44
       
      oui c'est ca
      0
    5. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
       
      https://www.commentcamarche.net/faq/16919-comment-changer-la-page-d-accueil-de-son-navigateur-web#sous-google-chrome
      0
  9. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    --> Relance AdwCleaner et choisis "Désinstaller".

    --> Télécharge et enregistre OTL sur ton Bureau.

    --> Double-clique sur OTL pour le lancer.
    (Sous Vista/Win7/Win8, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)

    --> Clique ici pour voir les réglages que tu dois effectuer.

    --> Copie-colle le texte présent en gras ci-dessous dans la partie inférieure d'OTL "Personnalisation" :

    /md5start
    explorer.exe
    winlogon.exe
    wininit.exe
    /md5stop
    netsvcs
    safebootminimal
    safebootnetwork
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\*.ini
    %systemroot%\Tasks\*.*
    %systemroot%\system32\Tasks\*.*
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\config\*.sav
    %systemroot%\system32\config\*.exe /s
    %systemroot%\system32\*.sys
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa /s
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    CREATERESTOREPOINT


    --> Clique sur "Analyse".

    --> A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt). Il y aura aussi un rapport nommé Extras.txt.

    /!\ Ne les poste pas directement sur le forum (ils sont trop longs) /!\

    --> Héberge OTL.txt et Extras.txt sur http://pjjoint.malekal.com et poste les liens qui mènent aux rapports dans ton prochain message.
    0
    1. ilnamso Messages postés 253 Statut Membre 44
       
      nn laise beton sa ne marche pas bon ba il va rester ou sinon plus tard je ferai une restauration du systeme
      merci pour ton aide
      0
    2. yoann090 Messages postés 10597 Statut Contributeur sécurité 1 697
       
      Salut, ce que proposait Destrio servait juste a essayer de trouver où pouvait se «cacher» ce qui maintenait certified search. Sinon essaye de desinstaller reinstaller google chrome, il se peut que ça règle le problème.
      Cordialement
      0
    3. ilnamso Messages postés 253 Statut Membre 44
       
      ouai mais pour internet exploreur
      0
    4. ilnamso Messages postés 253 Statut Membre 44
       
      et si je supprime sa va effacer tout les contee en memoir
      0
  10. ilnamso Messages postés 253 Statut Membre 44
     
    jai envoyer

    0
    1. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
       
      Le rapport n'est pas complet.

      "/!\ Ne les poste pas directement sur le forum (ils sont trop longs) /!\

      --> Héberge OTL.txt et Extras.txt sur http://pjjoint.malekal.com et poste les liens qui mènent aux rapports dans ton prochain message."
      0
    2. ilnamso Messages postés 253 Statut Membre 44
       
      comment on heberge !
      0
    3. ilnamso Messages postés 253 Statut Membre 44
       
      ahh okkk en faite ses un autre ok escuse
      0
    4. ilnamso Messages postés 253 Statut Membre 44
       
      voici le raport :

      OTL Extras logfile created on: 21/01/2013 19:35:13 - Run 1
      OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Tunc\Downloads
      64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
      Internet Explorer (Version = 9.0.8112.16421)
      Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy

      1,93 Gb Total Physical Memory | 1,09 Gb Available Physical Memory | 56,42% Memory free
      3,87 Gb Paging File | 2,73 Gb Available in Paging File | 70,53% Paging File free
      Paging file location(s): ?:\pagefile.sys [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
      Drive C: | 214,47 Gb Total Space | 185,69 Gb Free Space | 86,58% Space Free | Partition Type: NTFS
      Drive D: | 18,11 Gb Total Space | 2,62 Gb Free Space | 14,49% Space Free | Partition Type: NTFS

      Computer Name: TUNC-HP | User Name: Tunc | Logged in as Administrator.
      Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
      Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days

      <FONT COLOR=E56717]>========== Extra Registry (All) ==========</FONT>


      <FONT COLOR=E56717]>========== File Associations ==========</FONT>

      [b]64bit:/b [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\extension]
      .chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
      .cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
      .hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
      .html[@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
      .inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
      .ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
      .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
      .js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
      .jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
      .reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
      .txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
      .vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
      .vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
      .wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
      .wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\extension]
      .bat [@ = batfile] -- %1 %*
      .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
      .cmd [@ = cmdfile] -- %1 %*
      .com [@ = comfile] -- %1 %*
      .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
      .exe [@ = exefile] -- %1 %*
      .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
      .hta [@ = htafile] -- %1 %*
      .html [@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
      .inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
      .ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
      .url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
      .js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
      .jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
      .pif [@ = piffile] -- %1 %*
      .reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
      .scr [@ = scrfile] -- %1 /S
      .txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
      .vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
      .vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
      .wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
      .wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

      [HKEY_USERS\S-1-5-21-142970233-1726851096-1208565108-1001\SOFTWARE\Classes\extension]
      .html [@ = ChromeHTML] -- Reg Error: Key error. File not found

      <FONT COLOR=E56717]>========== Shell Spawning ==========</FONT>

      [b]64bit:/b [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\key\shell\[command]\command]
      batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
      batfile [open] -- %1 %*
      batfile [] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
      chm.file [open] -- %SystemRoot%\hh.exe %1 (Microsoft Corporation)
      cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
      cmdfile [open] -- %1 %*
      cmdfile [] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
      comfile [open] -- %1 %*
      cplfile [cplopen] -- %SystemRoot%\System32\control.exe %1,%* (Microsoft Corporation)
      exefile [open] -- %1 %*
      helpfile [open] -- Reg Error: Key error.
      hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
      htafile [open] -- %1 %*
      htmlfile [edit] -- Reg Error: Key error.
      htmlfile [open] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -nohome (Microsoft Corporation)
      htmlfile [opennew] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe %1 (Microsoft Corporation)
      htmlfile [] -- rundll32.exe %windir%\system32\mshtml.dll,HTML %1
      http [open] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -nohome (Microsoft Corporation)
      https [open] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -nohome (Microsoft Corporation)
      inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe %1 (Microsoft Corporation)
      inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
      inffile [] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
      inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
      inifile [] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
      InternetShortcut [open] -- C:\Windows\System32\rundll32.exe C:\Windows\System32\ieframe.dll,OpenURL %l (Microsoft Corporation)
      InternetShortcut [] -- C:\Windows\System32\rundll32.exe C:\Windows\System32\mshtml.dll,HTML %1 (Microsoft Corporation)
      jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
      jsfile [open] -- C:\Windows\System32\WScript.exe %1 %* (Microsoft Corporation)
      jsfile [] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
      jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
      jsefile [open] -- C:\Windows\System32\WScript.exe %1 %* (Microsoft Corporation)
      jsefile [] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
      piffile [open] -- %1 %*
      regfile [edit] -- %SystemRoot%\system32\notepad.exe %1 (Microsoft Corporation)
      regfile [open] -- regedit.exe %1 (Microsoft Corporation)
      regfile [merge] -- Reg Error: Key error.
      regfile [] -- %SystemRoot%\system32\notepad.exe /p %1 (Microsoft Corporation)
      scrfile [config] -- %1
      scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
      scrfile [open] -- %1 /S
      txtfile [edit] -- Reg Error: Key error.
      txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
      txtfile [] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
      txtfile [to] -- %SystemRoot%\system32\notepad.exe /pt %1 %2 %3 %4 (Microsoft Corporation)
      vbefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
      vbefile [open] -- %SystemRoot%\System32\WScript.exe %1 %* (Microsoft Corporation)
      vbefile [] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
      vbsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
      vbsfile [open] -- %SystemRoot%\System32\WScript.exe %1 %* (Microsoft Corporation)
      vbsfile [] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
      wsffile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
      wsffile [open] -- %SystemRoot%\System32\WScript.exe %1 %* (Microsoft Corporation)
      wsffile [] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
      wshfile [open] -- %SystemRoot%\System32\WScript.exe %1 %* (Microsoft Corporation)
      Unknown [openas] -- C:\Program Files (x86)\Advanced System Protector\filetypehelper.exe -scanunknown %1
      Directory [cmd] -- cmd.exe /s /k pushd %V (Microsoft Corporation)
      Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Folder [explore] -- Reg Error: Value error.
      Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Applications\iexplore.exe [open] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe %1 (Microsoft Corporation)
      CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\key\shell\[command]\command]
      batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
      batfile [open] -- %1 %*
      batfile [] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
      chm.file [open] -- %SystemRoot%\hh.exe %1 (Microsoft Corporation)
      cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
      cmdfile [open] -- %1 %*
      cmdfile [] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
      comfile [open] -- %1 %*
      cplfile [cplopen] -- %SystemRoot%\System32\control.exe %1,%* (Microsoft Corporation)
      exefile [open] -- %1 %*
      helpfile [open] -- Reg Error: Key error.
      hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
      htafile [open] -- %1 %*
      htmlfile [edit] -- Reg Error: Key error.
      htmlfile [open] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -nohome (Microsoft Corporation)
      htmlfile [opennew] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe %1 (Microsoft Corporation)
      htmlfile [] -- rundll32.exe %windir%\system32\mshtml.dll,HTML %1
      http [open] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -nohome (Microsoft Corporation)
      https [open] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -nohome (Microsoft Corporation)
      inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe %1 (Microsoft Corporation)
      inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
      inffile [] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
      inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
      inifile [] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
      InternetShortcut [open] -- C:\Windows\System32\rundll32.exe C:\Windows\System32\ieframe.dll,OpenURL %l (Microsoft Corporation)
      InternetShortcut [] -- C:\Windows\System32\rundll32.exe C:\Windows\System32\mshtml.dll,HTML %1 (Microsoft Corporation)
      jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
      jsfile [open] -- C:\Windows\System32\WScript.exe %1 %* (Microsoft Corporation)
      jsfile [] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
      jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
      jsefile [open] -- C:\Windows\System32\WScript.exe %1 %* (Microsoft Corporation)
      jsefile [] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
      piffile [open] -- %1 %*
      regfile [edit] -- %SystemRoot%\system32\notepad.exe %1 (Microsoft Corporation)
      regfile [open] -- regedit.exe %1 (Microsoft Corporation)
      regfile [merge] -- Reg Error: Key error.
      regfile [] -- %SystemRoot%\system32\notepad.exe /p %1 (Microsoft Corporation)
      scrfile [config] -- %1
      scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
      scrfile [open] -- %1 /S
      txtfile [edit] -- Reg Error: Key error.
      txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
      txtfile [] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
      txtfile [to] -- %SystemRoot%\system32\notepad.exe /pt %1 %2 %3 %4 (Microsoft Corporation)
      vbefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
      vbefile [open] -- %SystemRoot%\System32\WScript.exe %1 %* (Microsoft Corporation)
      vbefile [] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
      vbsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
      vbsfile [open] -- %SystemRoot%\System32\WScript.exe %1 %* (Microsoft Corporation)
      vbsfile [] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
      wsffile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
      wsffile [open] -- %SystemRoot%\System32\WScript.exe %1 %* (Microsoft Corporation)
      wsffile [] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
      wshfile [open] -- %SystemRoot%\System32\WScript.exe %1 %* (Microsoft Corporation)
      Unknown [openas] -- C:\Program Files (x86)\Advanced System Protector\filetypehelper.exe -scanunknown %1
      Directory [cmd] -- cmd.exe /s /k pushd %V (Microsoft Corporation)
      Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Folder [explore] -- Reg Error: Value error.
      Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Applications\iexplore.exe [open] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe %1 (Microsoft Corporation)
      CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)

      <FONT COLOR=E56717]>========== Security Center Settings ==========</FONT>

      [b]64bit:/b [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
      cval = 1

      [b]64bit:/b [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

      [b]64bit:/b [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
      VistaSp1 = 28 4D B2 76 41 04 CA 01 [binary data]
      AntiVirusOverride = 0
      AntiSpywareOverride = 0
      FirewallOverride = 0

      [b]64bit:/b [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

      <FONT COLOR=E56717]>========== Firewall Settings ==========</FONT>

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
      DisableNotifications = 0
      EnableFirewall = 1
      DoNotAllowExceptions = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
      DisableNotifications = 0
      EnableFirewall = 1
      DoNotAllowExceptions = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
      DisableNotifications = 0
      EnableFirewall = 1

      <FONT COLOR=E56717]>========== Authorized Applications List ==========</FONT>


      <FONT COLOR=E56717]>========== Vista Active Open Ports Exception List ==========</FONT>

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
      {208C5883-7E0C-4BF2-887A-A4E4C5761C12} = lport=445 | protocol=6 | dir=in | app=system |
      {25EDBBBE-C352-4B2F-B47C-33A448A679EE} = rport=137 | protocol=17 | dir=out | app=system |
      {2BE58DB4-C91E-4B86-B067-6EFF2E07EA72} = lport=138 | protocol=17 | dir=in | app=system |
      {2E5C0CD6-2496-4932-B3D0-7896A74EF9BD} = lport=10243 | protocol=6 | dir=in | app=system |
      {30BEB165-E265-44DC-B333-99B2CA66758B} = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
      {3FAFF4A2-2725-4B1A-92BD-706DBF833133} = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
      {4232051E-DC45-48C2-9738-A8AFE8E3F86A} = lport=2869 | protocol=6 | dir=in | app=system |
      {45D83B7E-8642-4D10-8DD5-2FE7444434A0} = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
      {558FAAE7-9145-4FB8-A64C-A5AB7C83AF26} = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
      {698B5A99-B8A5-469B-AF68-B33014FAE375} = lport=139 | protocol=6 | dir=in | app=system |
      {6DE792E5-1BCE-4A61-9A48-BB42941B2354} = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
      {7C50EC5E-E3B6-4A19-BBE5-B8D7BE1B3259} = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
      {864DE7F0-C5A3-4AD8-8BC3-8F87EFE8E49C} = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
      {86B4E75B-B3A9-4875-9372-8D069238A88D} = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
      {9143F75D-9AF1-4615-9CDD-3BA5F7A1E45E} = rport=445 | protocol=6 | dir=out | app=system |
      {950201E8-4F7F-4FF2-A817-8BB4FD4096AF} = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
      {BFAE625E-3DAF-41ED-A204-CC28E0101BF9} = rport=139 | protocol=6 | dir=out | app=system |
      {CCA67C51-E9FC-4C04-834E-EDDC022915BC} = rport=138 | protocol=17 | dir=out | app=system |
      {D0E2E22A-85A0-4737-8C86-7C7A05724055} = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
      {DA69AC8C-08C6-4274-BE9E-96197B8E87CC} = lport=137 | protocol=17 | dir=in | app=system |
      {E91C2946-E11C-4651-B5B9-276D469152BF} = rport=10243 | protocol=6 | dir=out | app=system |

      <FONT COLOR=E56717]>========== Vista Active Application Exception List ==========</FONT>

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
      {17CCF45D-A8A5-4894-B110-5AAFFE4F494B} = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
      {1EA162BA-C2B8-4011-A478-FDF2544CD412} = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
      {251973DF-45B4-493A-97E8-EA8A24475FFC} = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
      {2545545B-2152-493D-8662-D9E18BA68979} = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
      {30E0B25A-0826-40D4-8762-DF967B299664} = protocol=58 | dir=in | app=system |
      {3C778EC4-52B0-4544-A27E-EDE17C48AD1B} = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
      {3E0789E4-73AE-413A-BB47-1B91A4299C79} = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
      {4085E3CF-C5DA-4BC1-83B8-57BB579307F4} = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
      {456C8344-19C2-4D91-AAE8-0ADA3048BC54} = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
      {4EF7F411-8021-4A57-8A26-056889F89AE6} = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
      {51C65489-B359-4384-97CE-320F5EF65B7E} = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
      {5A575B44-AFE7-4A78-A08F-E5908CC86E3C} = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
      {6E5C80E0-9A3B-4E2E-92D7-091F1CDC3241} = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
      {6EBB25E3-7C2E-4C0C-87A1-E5929E5D6331} = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
      {74D164A9-96D6-427D-AA25-F388036FDFD1} = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
      {78F0757B-262C-4670-948B-0142BA7DB102} = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe |
      {81B389CD-2CB3-44AC-A5FF-3C931D67CCB8} = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
      {849FFBF3-F4D3-4085-B53A-DD1FC9C1B495} = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
      {89B1EBE0-D0AC-4F5C-B17F-9674BC8C43BF} = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
      {8C39406F-9ED9-47D3-B134-329B5C44904C} = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
      {967B6386-9A89-4022-AD53-CD231C776048} = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
      {ABBE8FE8-AC4B-40FD-B07A-AE5564063048} = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
      {B5725B9F-497E-4E1C-9237-7749CF652FD8} = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
      {B993A395-8DCF-43D1-A094-2A3F4A9DD407} = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
      {BA78CABF-A407-48D5-85E2-D39684843446} = protocol=6 | dir=out | app=system |
      {C235E5CE-9AA9-4133-91E1-939293BEF61E} = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
      {C49055CF-4D05-49E5-85CC-0AD3A6856B94} = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
      {CAAD4AEA-BC33-4193-9242-9B4B43B7A9DB} = protocol=17 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |
      {D5F121DC-3B76-4B1B-98D6-63DA72FFE250} = protocol=6 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |
      TCP Query User{16EFCF32-5F58-451B-99AD-486D3DFC65D7}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
      TCP Query User{51A44F6F-A5F5-4D2F-9345-F22527A0D926}C:\nexon\combat arms eu\engine.exe = protocol=6 | dir=in | app=c:\nexon\combat arms eu\engine.exe |
      TCP Query User{7205D49A-DCE0-48DB-894E-34ACC325B945}C:\nexon\combat arms eu\nmservice.exe = protocol=6 | dir=in | app=c:\nexon\combat arms eu\nmservice.exe |
      TCP Query User{815109BB-09BF-4DE2-A666-58F7FA6AD09A}C:\program files (x86)\ea games\battlefield heroes\bfheroes.exe = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield heroes\bfheroes.exe |
      TCP Query User{969E3150-CD45-4205-83B4-48641C4FF5FD}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
      TCP Query User{FD957569-76F7-4265-9C9E-E0B5EAB49BA2}C:\program files (x86)\ea games\battlefield heroes\bfheroes.exe = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield heroes\bfheroes.exe |
      UDP Query User{49756001-53A5-4D03-9F4A-597E8EDB12EE}C:\nexon\combat arms eu\engine.exe = protocol=17 | dir=in | app=c:\nexon\combat arms eu\engine.exe |
      UDP Query User{7585C5C7-ECAC-466A-BD32-B618767B740D}C:\nexon\combat arms eu\nmservice.exe = protocol=17 | dir=in | app=c:\nexon\combat arms eu\nmservice.exe |
      UDP Query User{81B5CB17-7092-4ABF-A8D2-AC790BF244BB}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
      UDP Query User{8800B17A-E64F-4FF1-A834-92DB3A22738D}C:\program files (x86)\ea games\battlefield heroes\bfheroes.exe = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield heroes\bfheroes.exe |
      UDP Query User{E36BD55B-D9A8-47C9-9F47-9F928F24CEEC}C:\program files (x86)\ea games\battlefield heroes\bfheroes.exe = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield heroes\bfheroes.exe |
      UDP Query User{ECAF19B0-9868-40E2-AFE8-E8726D3DE74E}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |

      <FONT COLOR=E56717]>========== HKEY_LOCAL_MACHINE Uninstall List ==========</FONT>

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      {091A0130-A82F-4A6D-9C61-3BBBB3289030} = RtVOsd
      {48EE0E00-86DE-47A5-8D00-B5D72A70BCCD} = HP Wireless Assistant
      {4B5F58F7-C7D1-3CE3-9B37-B657F0852643} = Microsoft .NET Framework 4 Client Profile FRA Language Pack
      {8220EEFE-38CD-377E-8595-13398D740ACE} = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
      {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} = Microsoft .NET Framework 4 Client Profile
      Microsoft .NET Framework 4 Client Profile = Microsoft .NET Framework 4 Client Profile
      Microsoft .NET Framework 4 Client Profile FRA Language Pack = Module linguistique Microsoft .NET Framework 4 Client Profile FRA
      SynTPDeinstKey = Synaptics Pointing Device Driver

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      {1B9DB1DF-3530-442B-AE07-1F5D08B6BA71} = HP Software Framework
      {254C37AA-6B72-4300-84F6-98A82419187E} = ActiveCheck component for HP Active Support Library
      {3877C901-7B90-4727-A639-B6ED2DD59D43} = ESU for Microsoft Windows 7
      {3E29EE6C-963A-4aae-86C1-DC237C4A49FC} = Intel(R) Rapid Storage Technology
      {44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5} = Recovery Manager
      {669D4A35-146B-4314-89F1-1AC3D7B88367} = HPAsset component for HP Active Support Library
      {705B639E-FAAF-40D7-AD58-C445321C7C3F} = LightScribe System Software
      {7299052b-02a4-4627-81f2-1818da5d550d} = Microsoft Visual C++ 2005 Redistributable
      {8833FFB6-5B0C-4764-81AA-06DFEED9A476} = Realtek Ethernet Controller Driver For Windows 7
      {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} = Microsoft Silverlight
      {8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0} = Ralink RT5390 802.11b/g/n WiFi Adapter
      {B1A4A13D-4665-4ED3-9DFE-F845725FBBD8} = HP Support Assistant
      {EA17F4FC-FDBF-4CF8-A529-2D983132D053} = Skype(TM) 6.0
      {EF682D1C-591D-48B5-9803-628DA622C281} = HP Quick Launch
      {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} = Intel(R) Graphics Media Accelerator Driver
      {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} = Realtek High Definition Audio Driver
      PunkBusterSvc = PunkBuster Services

      <FONT COLOR=E56717]>========== HKEY_USERS Uninstall List ==========</FONT>

      [HKEY_USERS\S-1-5-21-142970233-1726851096-1208565108-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      {8DC910CD-8EE3-4ffc-A4EB-9B02701059C4} = Battlefield Heroes

      <FONT COLOR=E56717]>========== Last 20 Event Log Errors ==========</FONT>

      [ Application Events ]
      Error - 03/01/2013 09:03:39 | Computer Name = Tunc-HP | Source = Application Error | ID = 1000
      Description = Nom de l'application défaillante PnkBstrB.exe, version : 0.0.0.0,
      horodatage : 0x4cf7ed9e Nom du module défaillant : unknown, version : 0.0.0.0, horodatage
      : 0x00000000 Code d'exception : 0xc0000005 Décalage d'erreur : 0x74066a64 ID du processus
      défaillant : 0x624 Heure de début de l'application défaillante : 0x01cde9b25cb50f69
      Chemin
      d'accès de l'application défaillante : C:\Windows\SysWOW64\PnkBstrB.exe Chemin d'accès
      du module défaillant: unknown ID de rapport : fd532d0d-55a5-11e2-ac92-2c27d7df8425

      Error - 03/01/2013 09:03:39 | Computer Name = Tunc-HP | Source = Application Error | ID = 1000
      Description = Nom de l'application défaillante hpqwmiex.exe, version : 4.0.70.1,
      horodatage : 0x4c93defa Nom du module défaillant : unknown, version : 0.0.0.0, horodatage
      : 0x00000000 Code d'exception : 0xc0000005 Décalage d'erreur : 0x74066a64 ID du processus
      défaillant : 0x9f8 Heure de début de l'application défaillante : 0x01cde9b2bf7706a7
      Chemin
      d'accès de l'application défaillante : C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
      Chemin
      d'accès du module défaillant: unknown ID de rapport : fdada157-55a5-11e2-ac92-2c27d7df8425

      Error - 03/01/2013 11:35:49 | Computer Name = Tunc-HP | Source = Google Update | ID = 20
      Description =

      Error - 06/01/2013 09:33:06 | Computer Name = Tunc-HP | Source = Google Update | ID = 20
      Description =

      Error - 07/01/2013 08:34:13 | Computer Name = Tunc-HP | Source = Application Error | ID = 1000
      Description = Nom de l'application défaillante hpasset.exe, version : 3.0.0.3, horodatage
      : 0x4ab90f9f Nom du module défaillant : hpasset.exe, version : 3.0.0.3, horodatage
      : 0x4ab90f9f Code d'exception : 0xc0000005 Décalage d'erreur : 0x00016c6c ID du processus
      défaillant : 0x116c Heure de début de l'application défaillante : 0x01cdecd34a309e7b
      Chemin
      d'accès de l'application défaillante : C:\Program Files (x86)\Hewlett-Packard\HP
      Health Check\HPAsset\hpasset.exe Chemin d'accès du module défaillant: C:\Program
      Files (x86)\Hewlett-Packard\HP Health Check\HPAsset\hpasset.exe ID de rapport :
      8aac691c-58c6-11e2-960c-2c27d7df8425

      Error - 07/01/2013 08:34:32 | Computer Name = Tunc-HP | Source = Application Error | ID = 1000
      Description = Nom de l'application défaillante hpasset.exe, version : 3.0.0.3, horodatage
      : 0x4ab90f9f Nom du module défaillant : hpasset.exe, version : 3.0.0.3, horodatage
      : 0x4ab90f9f Code d'exception : 0xc0000005 Décalage d'erreur : 0x00016c6c ID du processus
      défaillant : 0x13c0 Heure de début de l'application défaillante : 0x01cdecd3580f3cb9
      Chemin
      d'accès de l'application défaillante : C:\Program Files (x86)\Hewlett-Packard\HP
      Health Check\HPAsset\hpasset.exe Chemin d'accès du module défaillant: C:\Program
      Files (x86)\Hewlett-Packard\HP Health Check\HPAsset\hpasset.exe ID de rapport :
      9601e1f8-58c6-11e2-960c-2c27d7df8425

      Error - 09/01/2013 11:35:04 | Computer Name = Tunc-HP | Source = Google Update | ID = 20
      Description =

      Error - 09/01/2013 13:42:54 | Computer Name = Tunc-HP | Source = Application Error | ID = 1000
      Description = Nom de l'application défaillante Skype.exe, version : 6.0.0.126, horodatage
      : 0x509ce778 Nom du module défaillant : unknown, version : 0.0.0.0, horodatage :
      0x00000000 Code d'exception : 0xc0000005 Décalage d'erreur : 0x5c158b00 ID du processus
      défaillant : 0x844 Heure de début de l'application défaillante : 0x01cdee7dc99d3c97
      Chemin
      d'accès de l'application défaillante : C:\Program Files (x86)\Skype\Phone\Skype.exe
      Chemin
      d'accès du module défaillant: unknown ID de rapport : fe7b5140-5a83-11e2-b723-2c27d7df8425

      Error - 12/01/2013 10:05:56 | Computer Name = Tunc-HP | Source = Microsoft-Windows-CAPI2 | ID = 257
      Description = Le service Services de chiffrement n'a pas réussi à initialiser la
      base de données du catalogue. L'erreur ESENT était : -550.

      Error - 14/01/2013 17:42:00 | Computer Name = Tunc-HP | Source = Application Error | ID = 1000
      Description = Nom de l'application défaillante x1nject_downloader.exe, version :
      0.0.0.0, horodatage : 0x4b1ae3c6 Nom du module défaillant : inetc.dll_unloaded,
      version : 0.0.0.0, horodatage : 0x4ea14cb0 Code d'exception : 0xc0000005 Décalage
      d'erreur : 0x02cc36fe ID du processus défaillant : 0x6f4 Heure de début de l'application
      défaillante : 0x01cdf29fdf3811bc Chemin d'accès de l'application défaillante : C:\Users\Tunc\Downloads\x1nject_downloader.exe
      Chemin
      d'accès du module défaillant: inetc.dll ID de rapport : 39c2782a-5e93-11e2-8258-2c27d7df8425

      [ Hewlett-Packard Events ]
      Error - 07/01/2013 08:34:29 | Computer Name = Tunc-HP | Source = Hewlett-Packard | ID = 0
      Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\011307013403.xml
      File not created by asset agent

      [ HP Wireless Assistant Events ]
      Error - 30/12/2012 13:51:24 | Computer Name = Tunc-HP | Source = HP WA Service | ID = 0
      Description = System.Runtime.InteropServices.COMException Le serveur RPC n'est pas
      disponible. (Exception de HRESULT : 0x800706BA) à System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
      errorCode, IntPtr errorInfo) à System.Management.ManagementScope.InitializeGuts(Object
      o) à System.Management.ManagementScope.Initialize() à System.Management.ManagementObject.Initialize(Boolean
      getObject) à System.Management.ManagementBaseObject.get_Properties() à System.Management.ManagementBaseObject.GetPropertyValue(String
      propertyName) à HPPA_Service.CurrentConfiguration.ReloadRadioListb__c()

      Error - 30/12/2012 13:52:32 | Computer Name = Tunc-HP | Source = HP WA Service | ID = 0
      Description = System.Runtime.InteropServices.COMException Le serveur RPC n'est pas
      disponible. (Exception de HRESULT : 0x800706BA) à System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
      errorCode, IntPtr errorInfo) à System.Management.ManagementScope.InitializeGuts(Object
      o) à System.Management.ManagementScope.Initialize() à System.Management.ManagementObject.Initialize(Boolean
      getObject) à System.Management.ManagementBaseObject.get_Properties() à System.Management.ManagementBaseObject.GetPropertyValue(String
      propertyName) à HPPA_Service.CurrentConfiguration.ReloadRadioListb__c()

      Error - 30/12/2012 13:53:40 | Computer Name = Tunc-HP | Source = HP WA Service | ID = 0
      Description = System.Runtime.InteropServices.COMException Le serveur RPC n'est pas
      disponible. (Exception de HRESULT : 0x800706BA) à System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
      errorCode, IntPtr errorInfo) à System.Management.ManagementScope.InitializeGuts(Object
      o) à System.Management.ManagementScope.Initialize() à System.Management.ManagementObject.Initialize(Boolean
      getObject) à System.Management.ManagementBaseObject.get_Properties() à System.Management.ManagementBaseObject.GetPropertyValue(String
      propertyName) à HPPA_Service.CurrentConfiguration.ReloadRadioListb__c()

      Error - 30/12/2012 13:54:48 | Computer Name = Tunc-HP | Source = HP WA Service | ID = 0
      Description = System.Runtime.InteropServices.COMException Le serveur RPC n'est pas
      disponible. (Exception de HRESULT : 0x800706BA) à System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
      errorCode, IntPtr errorInfo) à System.Management.ManagementScope.InitializeGuts(Object
      o) à System.Management.ManagementScope.Initialize() à System.Management.ManagementObject.Initialize(Boolean
      getObject) à System.Management.ManagementBaseObject.get_Properties() à System.Management.ManagementBaseObject.GetPropertyValue(String
      propertyName) à HPPA_Service.CurrentConfiguration.ReloadRadioListb__c()

      Error - 30/12/2012 13:55:55 | Computer Name = Tunc-HP | Source = HP WA Service | ID = 0
      Description = System.Runtime.InteropServices.COMException Le serveur RPC n'est pas
      disponible. (Exception de HRESULT : 0x800706BA) à System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
      errorCode, IntPtr errorInfo) à System.Management.ManagementScope.InitializeGuts(Object
      o) à System.Management.ManagementScope.Initialize() à System.Management.ManagementObject.Initialize(Boolean
      getObject) à System.Management.ManagementBaseObject.get_Properties() à System.Management.ManagementBaseObject.GetPropertyValue(String
      propertyName) à HPPA_Service.CurrentConfiguration.ReloadRadioListb__c()

      Error - 30/12/2012 13:57:03 | Computer Name = Tunc-HP | Source = HP WA Service | ID = 0
      Description = System.Runtime.InteropServices.COMException Le serveur RPC n'est pas
      disponible. (Exception de HRESULT : 0x800706BA) à System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
      errorCode, IntPtr errorInfo) à System.Management.ManagementScope.InitializeGuts(Object
      o) à System.Management.ManagementScope.Initialize() à System.Management.ManagementObject.Initialize(Boolean
      getObject) à System.Management.ManagementBaseObject.get_Properties() à System.Management.ManagementBaseObject.GetPropertyValue(String
      propertyName) à HPPA_Service.CurrentConfiguration.ReloadRadioListb__c()

      Error - 02/01/2013 11:15:26 | Computer Name = Tunc-HP | Source = HP WA Service | ID = 0
      Description = System.Runtime.InteropServices.COMException L'appel a été annulé par
      le filtre de messages. (Exception de HRESULT : 0x80010002 (RPC_E_CALL_CANCELED))

      à System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode,
      IntPtr errorInfo) à System.Management.ManagementScope.InitializeGuts(Object o)

      à System.Management.ManagementScope.Initialize() à System.Management.ManagementObject.Initialize(Boolean
      getObject) à System.Management.ManagementBaseObject.get_Properties() à System.Management.ManagementBaseObject.GetPropertyValue(String
      propertyName) à HPPA_Service.CurrentConfiguration.ReloadRadioListb__c()

      Error - 03/01/2013 11:34:21 | Computer Name = Tunc-HP | Source = HP WA Service | ID = 0
      Description = System.Exception GetDeviceInfo() failed : 597 à HP_Common.CaslWrapper.GetDeviceInfo(List'1&
      radioList) à HPPA_Service.CurrentConfiguration.ReloadRadioList()

      Error - 03/01/2013 11:35:39 | Computer Name = Tunc-HP | Source = HP WA Service | ID = 0
      Description = System.Exception GetDeviceInfo() failed : 597 à HP_Common.CaslWrapper.GetDeviceInfo(List'1&
      radioList) à HPPA_Service.CurrentConfiguration.ReloadRadioList()

      Error - 04/01/2013 15:26:01 | Computer Name = Tunc-HP | Source = HP WA Service | ID = 0
      Description = System.Runtime.InteropServices.COMException à System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
      errorCode, IntPtr errorInfo) à System.Management.ManagementObject.Initialize(Boolean
      getObject) à System.Management.ManagementBaseObject.get_Properties() à System.Management.ManagementBaseObject.GetPropertyValue(String
      propertyName) à HPPA_Service.CurrentConfiguration.ReloadRadioListb__c()

      [ Media Center Events ]
      Error - 09/01/2013 11:30:51 | Computer Name = Tunc-HP | Source = MCUpdate | ID = 0
      Description = 16:30:51 - Erreur de connexion à Internet. 16:30:51 - Impossible
      de contacter le service..

      Error - 09/01/2013 11:31:28 | Computer Name = Tunc-HP | Source = MCUpdate | ID = 0
      Description = 16:31:21 - Erreur de connexion à Internet. 16:31:21 - Impossible
      de contacter le service..

      [ System Events ]
      Error - 17/01/2013 07:39:06 | Computer Name = Tunc-HP | Source = Service Control Manager | ID = 7000
      Description = Le service Service Google Update (gupdate) n'a pas pu démarrer en
      raison de l'erreur : %%2

      Error - 17/01/2013 12:22:06 | Computer Name = Tunc-HP | Source = EventLog | ID = 6008
      Description = L'arrêt système précédant à 13:49:16 le ?17/?01/?2013 n'était pas
      prévu.

      Error - 17/01/2013 12:27:00 | Computer Name = Tunc-HP | Source = Service Control Manager | ID = 7000
      Description = Le service Service Google Update (gupdate) n'a pas pu démarrer en
      raison de l'erreur : %%2

      Error - 17/01/2013 13:50:11 | Computer Name = Tunc-HP | Source = Tcpip | ID = 4199
      Description = Le système a détecté un conflit d'adresses pour l'adresse IP 0.0.0.0
      avec le système d'adresse physique réseau 00-00-00-00-00-00. En conséquence les
      opérations réseau sur se système peuvent être interrompues.

      Error - 18/01/2013 07:52:12 | Computer Name = Tunc-HP | Source = EventLog | ID = 6008
      Description = L'arrêt système précédant à 22:30:58 le ?17/?01/?2013 n'était pas
      prévu.

      Error - 18/01/2013 07:54:53 | Computer Name = Tunc-HP | Source = Service Control Manager | ID = 7000
      Description = Le service Service Google Update (gupdate) n'a pas pu démarrer en
      raison de l'erreur : %%2

      Error - 18/01/2013 11:33:51 | Computer Name = Tunc-HP | Source = Service Control Manager | ID = 7000
      Description = Le service Service Google Update (gupdate) n'a pas pu démarrer en
      raison de l'erreur : %%2

      Error - 18/01/2013 11:37:22 | Computer Name = Tunc-HP | Source = Tcpip | ID = 4199
      Description = Le système a détecté un conflit d'adresses pour l'adresse IP 88.182.180.187
      avec le système d'adresse physique réseau 88-53-95-CC-E0-D8. En conséquence les
      opérations réseau sur se système peuvent être interrompues.

      Error - 18/01/2013 17:58:16 | Computer Name = Tunc-HP | Source = Service Control Manager | ID = 7011
      Description = Le dépassement de délai (30000 millisecondes) a été atteint lors de
      l'attente de la réponse transactionnelle du service HPWMISVC.

      Error - 18/01/2013 17:58:23 | Computer Name = Tunc-HP | Source = Tcpip | ID = 4199
      Description = Le système a détecté un conflit d'adresses pour l'adresse IP 88.182.180.187
      avec le système d'adresse physique réseau 88-9F-FA-A3-EA-A7. En conséquence les
      opérations réseau sur se système peuvent être interrompues.


      < End of report >
      0
    5. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
       
      Pour le rapport Extras.txt, il est complet.

      Pour le rapport OTL.txt, il faut l'héberger sur un site comme http://pjjoint.malekal.com/ ou https://www.cjoint.com/.
      0
  11. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Le problème est-il encore présent ?
    0