1. ========================= SEAF 1.0.1.0 - C_XX 2. 3. Commencé à: 19:01:04 le 29/03/2017 4. 5. Valeur(s) recherchée(s): 6. YAC 7. 8. Légende: TC => Date de création, TM => Date de modification, DA => Dernier accès 9. 10. (!) --- Calcul du Hash "MD5" 11. (!) --- Informations supplémentaires 12. (!) --- Recherche registre 13. 14. ====== Fichier(s) ====== 15. 16. 17. "C:\Program Files (x86)\Steam\tenfoot\resource\layout\library\library_details_playaction.xml" [ ARCHIVE | 1 Ko ] 18. TC: 15/11/2016,01:59:50 | TM: 10/02/2016,23:03:10 | DA: 15/11/2016,02:00:16 19. 20. Hash MD5: BC4687F1154CF01FD8C5E6D6F8E9800B 21. 22. 23. ========================= 24. 25. 26. "C:\Users\ADRI\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\LocalState\Indexed\Settings\fr-FR\AAA_SettingsPagePrivacyAccountInfo.settingcontent-ms" [ ARCHIVE | 1 Ko ] 27. TC: 15/11/2016,00:45:26 | TM: 16/07/2016,13:42:42 | DA: 15/11/2016,00:45:26 28. 29. Hash MD5: 9B43B4462DC2273B2D37D73C28D212F8 30. 31. 32. ========================= 33. 34. 35. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\Elex-tech.DIR\YAC\skin2\bugreport\image\default\res\reset_yac_btn_bg.png" [ ARCHIVE | 3 Ko ] 36. TC: 27/03/2017,22:29:58 | TM: 19/05/2016,08:41:40 | DA: 27/03/2017,22:29:58 37. 38. Hash MD5: DB4E0E6978A5FEB8988F867FB828138B 39. 40. 41. ========================= 42. 43. 44. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\Elex-tech.DIR\YAC\skin2\fbSkin\image\default\fb_yac_icon.png" [ ARCHIVE | 5 Ko ] 45. TC: 27/03/2017,22:29:58 | TM: 19/05/2016,08:41:43 | DA: 27/03/2017,22:29:58 46. 47. Hash MD5: 6A1006F85A4CA8F9B6B8CA46DE58E74E 48. 49. 50. ========================= 51. 52. 53. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\Elex-tech.DIR\YAC\skin2\SafeProtect\image\default\yac_ico.png" [ ARCHIVE | 3 Ko ] 54. TC: 27/03/2017,22:30:00 | TM: 19/05/2016,08:41:35 | DA: 27/03/2017,22:30:00 55. 56. Hash MD5: 1A53EBB049420D45292244B59B23EA0E 57. 58. 59. ========================= 60. 61. 62. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\Elex-tech.DIR\YAC\skin2\trayplugin\Floaty\image\yaclogo.png" [ ARCHIVE | 3 Ko ] 63. TC: 27/03/2017,22:30:00 | TM: 19/05/2016,08:41:55 | DA: 27/03/2017,22:30:00 64. 65. Hash MD5: 16F5CE719FA583DF84DBDB129DD096B4 66. 67. 68. ========================= 69. 70. 71. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\Elex-tech.DIR\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\yac_logo.png" [ ARCHIVE | 12 Ko ] 72. TC: 27/03/2017,22:30:00 | TM: 19/05/2016,08:41:59 | DA: 27/03/2017,22:30:00 73. 74. Hash MD5: B1A24F36F489F7CEF38FEF0ABE5C91E6 75. 76. 77. ========================= 78. 79. 80. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\Elex-tech.DIR\YAC\skin2\trayplugin\StartupAssist\image\sa_yac_logo.png" [ ARCHIVE | 4 Ko ] 81. TC: 27/03/2017,22:30:00 | TM: 19/05/2016,08:41:58 | DA: 27/03/2017,22:30:00 82. 83. Hash MD5: 46C218B449AC770A5701FBDBB5BC3150 84. 85. 86. ========================= 87. 88. 89. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\Elex-tech.DIR\YAC\skin2\uninstall\image\yac_side_ico.png" [ ARCHIVE | 2 Ko ] 90. TC: 27/03/2017,22:30:00 | TM: 19/05/2016,08:42:01 | DA: 27/03/2017,22:30:00 91. 92. Hash MD5: 463C1B916D919CD71DF941A512E6DBBD 93. 94. 95. ========================= 96. 97. 98. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\YAC.DIR\skin2\bugreport\image\default\res\reset_yac_btn_bg.png" [ ARCHIVE | 3 Ko ] 99. TC: 27/03/2017,22:30:14 | TM: 19/05/2016,08:41:40 | DA: 27/03/2017,22:30:14 100. 101. Hash MD5: DB4E0E6978A5FEB8988F867FB828138B 102. 103. 104. ========================= 105. 106. 107. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\YAC.DIR\skin2\fbSkin\image\default\fb_yac_icon.png" [ ARCHIVE | 5 Ko ] 108. TC: 27/03/2017,22:30:15 | TM: 19/05/2016,08:41:43 | DA: 27/03/2017,22:30:15 109. 110. Hash MD5: 6A1006F85A4CA8F9B6B8CA46DE58E74E 111. 112. 113. ========================= 114. 115. 116. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\YAC.DIR\skin2\SafeProtect\image\default\yac_ico.png" [ ARCHIVE | 3 Ko ] 117. TC: 27/03/2017,22:30:15 | TM: 19/05/2016,08:41:35 | DA: 27/03/2017,22:30:15 118. 119. Hash MD5: 1A53EBB049420D45292244B59B23EA0E 120. 121. 122. ========================= 123. 124. 125. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\YAC.DIR\skin2\trayplugin\Floaty\image\yaclogo.png" [ ARCHIVE | 3 Ko ] 126. TC: 27/03/2017,22:30:15 | TM: 19/05/2016,08:41:55 | DA: 27/03/2017,22:30:15 127. 128. Hash MD5: 16F5CE719FA583DF84DBDB129DD096B4 129. 130. 131. ========================= 132. 133. 134. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\YAC.DIR\skin2\trayplugin\iDesk\image\arrangedesktop\yac_logo.png" [ ARCHIVE | 12 Ko ] 135. TC: 27/03/2017,22:30:15 | TM: 19/05/2016,08:41:59 | DA: 27/03/2017,22:30:15 136. 137. Hash MD5: B1A24F36F489F7CEF38FEF0ABE5C91E6 138. 139. 140. ========================= 141. 142. 143. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\YAC.DIR\skin2\trayplugin\StartupAssist\image\sa_yac_logo.png" [ ARCHIVE | 4 Ko ] 144. TC: 27/03/2017,22:30:15 | TM: 19/05/2016,08:41:58 | DA: 27/03/2017,22:30:15 145. 146. Hash MD5: 46C218B449AC770A5701FBDBB5BC3150 147. 148. 149. ========================= 150. 151. 152. "C:\Users\ADRI\AppData\Roaming\ZHP\Quarantine\YAC.DIR\skin2\uninstall\image\yac_side_ico.png" [ ARCHIVE | 2 Ko ] 153. TC: 27/03/2017,22:30:16 | TM: 19/05/2016,08:42:01 | DA: 27/03/2017,22:30:16 154. 155. Hash MD5: 463C1B916D919CD71DF941A512E6DBBD 156. 157. 158. ========================= 159. 160. 161. "C:\Windows\ImmersiveControlPanel\Settings\AAA_SettingsPagePrivacyAccountInfo.settingcontent-ms" [ ARCHIVE | 1 Ko ] 162. TC: 16/07/2016,13:42:42 | TM: 16/07/2016,13:42:42 | DA: 16/07/2016,13:42:42 163. 164. Hash MD5: 9B43B4462DC2273B2D37D73C28D212F8 165. 166. 167. ========================= 168. 169. 170. "C:\Windows\Provisioning\Packages\Power.EnergyEstimationEngine.StandbyActivation.ppkg" [ ARCHIVE | 5 Ko ] 171. TC: 11/01/2017,00:05:02 | TM: 21/12/2016,07:35:32 | DA: 11/01/2017,00:05:02 172. 173. Hash MD5: FB65FA3495157F4DB25F05502B11778F 174. 175. 176. ========================= 177. 178. 179. "C:\Windows\WinSxS\amd64_microsoft-windows-p..ne-client-overrides_31bf3856ad364e35_10.0.14393.0_none_5fe52cac391f412a\Power.EnergyEstimationEngine.StandbyActivation.ppkg" [ ARCHIVE | 1 Ko ] 180. TC: 16/07/2016,13:42:13 | TM: 12/01/2017,19:33:18 | DA: 12/01/2017,19:33:18 181. 182. Hash MD5: E484414582764DA865E8EFAB3CECDD1C 183. 184. 185. ========================= 186. 187. 188. "C:\Windows\WinSxS\amd64_microsoft-windows-p..ne-client-overrides_31bf3856ad364e35_10.0.14393.693_none_6c10b5b1c0815b1e\Power.EnergyEstimationEngine.StandbyActivation.ppkg" [ ARCHIVE | 5 Ko ] 189. TC: 11/01/2017,00:05:02 | TM: 21/12/2016,07:35:32 | DA: 11/01/2017,00:05:02 190. 191. Hash MD5: FB65FA3495157F4DB25F05502B11778F 192. 193. 194. ========================= 195. 196. 197. "C:\Windows\WinSxS\amd64_microsoft-windows-s..settings-searchdata_31bf3856ad364e35_10.0.14393.0_none_bb1fc3c1adc6ecc6\AAA_SettingsPagePrivacyAccountInfo.settingcontent-ms" [ ARCHIVE | 1 Ko ] 198. TC: 16/07/2016,13:42:42 | TM: 16/07/2016,13:42:42 | DA: 16/07/2016,13:42:42 199. 200. Hash MD5: 9B43B4462DC2273B2D37D73C28D212F8 201. 202. 203. ========================= 204. 205. 206. "C:\Windows\WinSxS\Backup\amd64_microsoft-windows-p..ne-client-overrides_31bf3856ad364e35_10.0.14393.693_none_6c10b5b1c0815b1e_power.energyestimationengine.standbyactivation.ppkg_21aafe77" [ ARCHIVE | 3 Ko ] 207. TC: 11/01/2017,17:26:24 | TM: 12/01/2017,19:41:25 | DA: 12/01/2017,19:41:25 208. 209. Hash MD5: D24CE994156D4EF6FC412EEE55597C65 210. 211. 212. ========================= 213. 214. 215. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\com.batteryacid.highwayrider.cfg" [ ARCHIVE | 506 o ] 216. TC: 20/03/2017,18:20:36 | TM: 03/03/2017,03:04:15 | DA: 20/03/2017,18:20:36 217. 218. Hash MD5: 2E4576F530C8B3918D531EABEF90A4AB 219. 220. 221. ========================= 222. 223. 224. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\com.batteryacid.highwayrider.cfg.cfg" [ ARCHIVE | 331 o ] 225. TC: 20/03/2017,18:20:36 | TM: 03/03/2017,10:49:47 | DA: 20/03/2017,18:20:36 226. 227. Hash MD5: 98EF7F8BC7E898BC0F9AAB006AF42AEA 228. 229. 230. ========================= 231. 232. 233. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\com.batteryacidgames.streetballfree.cfg" [ ARCHIVE | 338 o ] 234. TC: 20/03/2017,18:20:36 | TM: 03/03/2017,03:04:15 | DA: 20/03/2017,18:20:36 235. 236. Hash MD5: BE9623B6552B16BEEE73ACB20DCDF47C 237. 238. 239. ========================= 240. 241. 242. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\com.batteryacidgames.streetballfree.cfg.cfg" [ ARCHIVE | 338 o ] 243. TC: 20/03/2017,18:20:36 | TM: 03/03/2017,10:49:47 | DA: 20/03/2017,18:20:36 244. 245. Hash MD5: 83F05D9F9A12925A7F267C15FFCC276A 246. 247. 248. ========================= 249. 250. 251. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\com.moxygames.armyacademy1.cfg" [ ARCHIVE | 622 o ] 252. TC: 20/03/2017,18:20:38 | TM: 03/03/2017,03:12:25 | DA: 20/03/2017,18:20:38 253. 254. Hash MD5: DE5C2DC24461797BFEB06ADADC3D8BD7 255. 256. 257. ========================= 258. 259. 260. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\com.moxygames.armyacademy1.cfg.cfg" [ ARCHIVE | 329 o ] 261. TC: 20/03/2017,18:20:38 | TM: 03/03/2017,10:49:59 | DA: 20/03/2017,18:20:38 262. 263. Hash MD5: F9FC4A6ACFE5526E83740A9917F1B945 264. 265. 266. ========================= 267. 268. 269. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\com.yoyogamesapp.ThiefSpyAce.cfg" [ ARCHIVE | 525 o ] 270. TC: 20/03/2017,18:20:39 | TM: 03/03/2017,03:18:23 | DA: 20/03/2017,18:20:39 271. 272. Hash MD5: 2BDC09BB9B0CA9942CB758E9C912FB12 273. 274. 275. ========================= 276. 277. 278. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\com.yoyogamesapp.ThiefSpyAce.cfg.cfg" [ ARCHIVE | 331 o ] 279. TC: 20/03/2017,18:20:39 | TM: 03/03/2017,10:50:07 | DA: 20/03/2017,18:20:39 280. 281. Hash MD5: 2173DB7FB4B04AD641F6F56592C6334F 282. 283. 284. ========================= 285. 286. 287. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\ru.gamedevteam.skyaces.cfg" [ ARCHIVE | 510 o ] 288. TC: 20/03/2017,18:20:39 | TM: 03/03/2017,03:19:44 | DA: 20/03/2017,18:20:39 289. 290. Hash MD5: BAFBBE50D29E8D267CF8A5C4CFE1DE28 291. 292. 293. ========================= 294. 295. 296. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\ru.gamedevteam.skyaces.cfg.cfg" [ ARCHIVE | 325 o ] 297. TC: 20/03/2017,18:20:39 | TM: 03/03/2017,10:50:09 | DA: 20/03/2017,18:20:39 298. 299. Hash MD5: DBBF91561C2A56C2B58BB1A45A53419A 300. 301. 302. ========================= 303. 304. 305. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\ru.gamedevteam.skyaces.free.cfg" [ ARCHIVE | 515 o ] 306. TC: 20/03/2017,18:20:39 | TM: 03/03/2017,03:19:44 | DA: 20/03/2017,18:20:39 307. 308. Hash MD5: 885A27B038EFE2B2FC0D58F251B9A877 309. 310. 311. ========================= 312. 313. 314. "D:\Program Files (x86)\Bluestacks\Bluestacks\UserData\InputMapper\ru.gamedevteam.skyaces.free.cfg.cfg" [ ARCHIVE | 330 o ] 315. TC: 20/03/2017,18:20:39 | TM: 03/03/2017,10:50:09 | DA: 20/03/2017,18:20:39 316. 317. Hash MD5: FBB2194CDE50166C319875E01D2E6BAA 318. 319. 320. ========================= 321. 322. 323. 324. ====== Entrée(s) du registre ====== 325. 326. 327. [HKLM\Software\Elex-tech\YAC] 328. DA: 27/03/2017 20:05:26 329. 330. [HKLM\Software\Microsoft\Speech_OneCore\Settings] 331. "PrivacyPolicyAcceptance"="2" (REG_DWORD) 332. 333. [HKLM\Software\Microsoft\Windows\CurrentVersion\Setup\PnpResources\Registry\HKLM\System\CurrentControlSet\Services\Lsi_sas\Parameters\Device\EnableQueryAccessAlignment] 334. DA: Impossible à obtenir 335. 336. [HKLM\Software\Microsoft\Windows\CurrentVersion\Setup\PnpResources\Registry\HKLM\System\CurrentControlSet\Services\Lsi_sas2i\Parameters\Device\EnableQueryAccessAlignment] 337. DA: Impossible à obtenir 338. 339. [HKLM\Software\Microsoft\Windows\CurrentVersion\Setup\PnpResources\Registry\HKLM\System\CurrentControlSet\Services\Lsi_sas3i\Parameters\Device\EnableQueryAccessAlignment] 340. DA: Impossible à obtenir 341. 342. [HKLM\Software\Microsoft\Windows\CurrentVersion\Setup\PnpResources\Registry\HKLM\System\CurrentControlSet\Services\Lsi_sss\Parameters\Device\EnableQueryAccessAlignment] 343. DA: Impossible à obtenir 344. 345. [HKLM\Software\WOW6432Node\Elex-tech\YAC] 346. DA: 27/03/2017 20:05:26 347. 348. [HKLM\Software\WOW6432Node\Microsoft\Speech_OneCore\Settings] 349. "PrivacyPolicyAcceptance"="2" (REG_DWORD) 350. 351. [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Setup\PnpResources\Registry\HKLM\System\CurrentControlSet\Services\Lsi_sas\Parameters\Device\EnableQueryAccessAlignment] 352. DA: Impossible à obtenir 353. 354. [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Setup\PnpResources\Registry\HKLM\System\CurrentControlSet\Services\Lsi_sas2i\Parameters\Device\EnableQueryAccessAlignment] 355. DA: Impossible à obtenir 356. 357. [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Setup\PnpResources\Registry\HKLM\System\CurrentControlSet\Services\Lsi_sas3i\Parameters\Device\EnableQueryAccessAlignment] 358. DA: Impossible à obtenir 359. 360. [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Setup\PnpResources\Registry\HKLM\System\CurrentControlSet\Services\Lsi_sss\Parameters\Device\EnableQueryAccessAlignment] 361. DA: Impossible à obtenir 362. 363. [HKLM\Software\WOW6432Node\Classes\CLSID\{91f39027-217f-11da-b2a4-000e7bbb2b09}\ProgID] 364. ""="X509Enrollment.CX509EnrollmentPolicyActiveDirectory.1" (REG_SZ) 365. 366. [HKLM\Software\WOW6432Node\Classes\CLSID\{91f39027-217f-11da-b2a4-000e7bbb2b09}\VersionIndependentProgID] 367. ""="X509Enrollment.CX509EnrollmentPolicyActiveDirectory" (REG_SZ) 368. 369. [HKLM\Software\WOW6432Node\Classes\Interface\{2FE9F084-1511-3052-BE7C-9010B522C10E}] 370. ""="_QueryAccessibilityHelpEventArgs" (REG_SZ) 371. 372. [HKLM\Software\WOW6432Node\Classes\Interface\{3CD63077-A08C-481A-93EB-C5D7568AE886}] 373. ""="__x_Windows_CInternal_CSettingSync_CINotifyAccountChange" (REG_SZ) 374. 375. [HKLM\Software\WOW6432Node\Classes\Interface\{7197B56B-5FA1-31EF-B38B-62FEE737277F}] 376. ""="IContextPropertyActivator" (REG_SZ) 377. 378. [HKLM\Software\WOW6432Node\Classes\Interface\{C84650E2-FCB3-435B-AEE4-13FD49C3BF5D}] 379. ""="__x_Windows_CUI_CCore_CIAcceleratorKeyActivatedEventHandler" (REG_SZ) 380. 381. [HKLM\Software\WOW6432Node\Classes\Record\{BA99AE52-D539-362F-B78C-4E84C14158BF}\2.0.0.0] 382. "Class"="System.Security.Permissions.SecurityAction" (REG_SZ) 383. 384. [HKLM\Software\WOW6432Node\Classes\Record\{BA99AE52-D539-362F-B78C-4E84C14158BF}\4.0.0.0] 385. "Class"="System.Security.Permissions.SecurityAction" (REG_SZ) 386. 387. [HKLM\Software\WOW6432Node\Classes\WOW6432Node\CLSID\{91f39027-217f-11da-b2a4-000e7bbb2b09}\ProgID] 388. ""="X509Enrollment.CX509EnrollmentPolicyActiveDirectory.1" (REG_SZ) 389. 390. [HKLM\Software\WOW6432Node\Classes\WOW6432Node\CLSID\{91f39027-217f-11da-b2a4-000e7bbb2b09}\VersionIndependentProgID] 391. ""="X509Enrollment.CX509EnrollmentPolicyActiveDirectory" (REG_SZ) 392. 393. [HKLM\Software\WOW6432Node\Classes\WOW6432Node\Interface\{2FE9F084-1511-3052-BE7C-9010B522C10E}] 394. ""="_QueryAccessibilityHelpEventArgs" (REG_SZ) 395. 396. [HKLM\Software\WOW6432Node\Classes\WOW6432Node\Interface\{3CD63077-A08C-481A-93EB-C5D7568AE886}] 397. ""="__x_Windows_CInternal_CSettingSync_CINotifyAccountChange" (REG_SZ) 398. 399. [HKLM\Software\WOW6432Node\Classes\WOW6432Node\Interface\{7197B56B-5FA1-31EF-B38B-62FEE737277F}] 400. ""="IContextPropertyActivator" (REG_SZ) 401. 402. [HKLM\Software\WOW6432Node\Classes\WOW6432Node\Interface\{C84650E2-FCB3-435B-AEE4-13FD49C3BF5D}] 403. ""="__x_Windows_CUI_CCore_CIAcceleratorKeyActivatedEventHandler" (REG_SZ) 404. 405. [HKLM\Software\WOW6432Node\Classes\X509Enrollment.CX509EnrollmentPolicyActiveDirectory] 406. DA: 29/03/2017 18:58:45 407. 408. [HKLM\Software\WOW6432Node\Classes\X509Enrollment.CX509EnrollmentPolicyActiveDirectory.1] 409. DA: 29/03/2017 18:58:45 410. 411. [HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\EnhancedStorageDevices] 412. "TCGSecurityActivationDisabled"="0" (REG_DWORD) 413. 414. [HKLM\Software\Classes\CLSID\{91f39027-217f-11da-b2a4-000e7bbb2b09}\ProgID] 415. ""="X509Enrollment.CX509EnrollmentPolicyActiveDirectory.1" (REG_SZ) 416. 417. [HKLM\Software\Classes\CLSID\{91f39027-217f-11da-b2a4-000e7bbb2b09}\VersionIndependentProgID] 418. ""="X509Enrollment.CX509EnrollmentPolicyActiveDirectory" (REG_SZ) 419. 420. [HKLM\Software\Classes\Interface\{2FE9F084-1511-3052-BE7C-9010B522C10E}] 421. ""="_QueryAccessibilityHelpEventArgs" (REG_SZ) 422. 423. [HKLM\Software\Classes\Interface\{3CD63077-A08C-481A-93EB-C5D7568AE886}] 424. ""="__x_Windows_CInternal_CSettingSync_CINotifyAccountChange" (REG_SZ) 425. 426. [HKLM\Software\Classes\Interface\{7197B56B-5FA1-31EF-B38B-62FEE737277F}] 427. ""="IContextPropertyActivator" (REG_SZ) 428. 429. [HKLM\Software\Classes\Interface\{C84650E2-FCB3-435B-AEE4-13FD49C3BF5D}] 430. ""="__x_Windows_CUI_CCore_CIAcceleratorKeyActivatedEventHandler" (REG_SZ) 431. 432. [HKLM\Software\Classes\Record\{BA99AE52-D539-362F-B78C-4E84C14158BF}\2.0.0.0] 433. "Class"="System.Security.Permissions.SecurityAction" (REG_SZ) 434. 435. [HKLM\Software\Classes\Record\{BA99AE52-D539-362F-B78C-4E84C14158BF}\4.0.0.0] 436. "Class"="System.Security.Permissions.SecurityAction" (REG_SZ) 437. 438. [HKLM\Software\Classes\WOW6432Node\CLSID\{91f39027-217f-11da-b2a4-000e7bbb2b09}\ProgID] 439. ""="X509Enrollment.CX509EnrollmentPolicyActiveDirectory.1" (REG_SZ) 440. 441. [HKLM\Software\Classes\WOW6432Node\CLSID\{91f39027-217f-11da-b2a4-000e7bbb2b09}\VersionIndependentProgID] 442. ""="X509Enrollment.CX509EnrollmentPolicyActiveDirectory" (REG_SZ) 443. 444. [HKLM\Software\Classes\WOW6432Node\Interface\{2FE9F084-1511-3052-BE7C-9010B522C10E}] 445. ""="_QueryAccessibilityHelpEventArgs" (REG_SZ) 446. 447. [HKLM\Software\Classes\WOW6432Node\Interface\{3CD63077-A08C-481A-93EB-C5D7568AE886}] 448. ""="__x_Windows_CInternal_CSettingSync_CINotifyAccountChange" (REG_SZ) 449. 450. [HKLM\Software\Classes\WOW6432Node\Interface\{7197B56B-5FA1-31EF-B38B-62FEE737277F}] 451. ""="IContextPropertyActivator" (REG_SZ) 452. 453. [HKLM\Software\Classes\WOW6432Node\Interface\{C84650E2-FCB3-435B-AEE4-13FD49C3BF5D}] 454. ""="__x_Windows_CUI_CCore_CIAcceleratorKeyActivatedEventHandler" (REG_SZ) 455. 456. [HKLM\Software\Classes\X509Enrollment.CX509EnrollmentPolicyActiveDirectory] 457. DA: 29/03/2017 18:58:45 458. 459. [HKLM\Software\Classes\X509Enrollment.CX509EnrollmentPolicyActiveDirectory.1] 460. DA: 29/03/2017 18:58:45 461. 462. [HKLM\Software\Policies\Microsoft\Windows\EnhancedStorageDevices] 463. "TCGSecurityActivationDisabled"="0" (REG_DWORD) 464. 465. [HKLM\System\ControlSet001\Control\iSafeKrnlBoot] 466. "ProgramPath"="C:\Program Files (x86)\Elex-tech\YAC" (REG_SZ) 467. 468. [HKLM\System\ControlSet001\Control\Power\EnergyEstimation\StandbyActivationEnergy] 469. DA: 14/11/2016 23:42:15 470. 471. [HKLM\System\ControlSet001\Services\amdsata\Parameters\Device] 472. "EnableQueryAccessAlignment"="1" (REG_DWORD) 473. 474. [HKLM\System\ControlSet001\Services\LSI_SAS\Parameters\Device] 475. "EnableQueryAccessAlignment"="1" (REG_DWORD) 476. 477. [HKLM\System\ControlSet001\Services\LSI_SAS2i\Parameters\Device] 478. "EnableQueryAccessAlignment"="1" (REG_DWORD) 479. 480. [HKLM\System\ControlSet001\Services\LSI_SAS3i\Parameters\Device] 481. "EnableQueryAccessAlignment"="1" (REG_DWORD) 482. 483. [HKLM\System\ControlSet001\Services\LSI_SSS\Parameters\Device] 484. "EnableQueryAccessAlignment"="1" (REG_DWORD) 485. 486. [HKLM\System\ControlSet001\Services\megasas\Parameters\Device] 487. "EnableQueryAccessAlignment"="1" (REG_DWORD) 488. 489. [HKLM\System\ControlSet001\Services\megasas2i\Parameters\Device] 490. "EnableQueryAccessAlignment"="1" (REG_DWORD) 491. 492. [HKLM\System\ControlSet001\Services\nvraid\Parameters\Device] 493. "EnableQueryAccessAlignment"="1" (REG_DWORD) 494. 495. [HKLM\System\ControlSet001\Services\nvstor\Parameters\Device] 496. "EnableQueryAccessAlignment"="1" (REG_DWORD) 497. 498. [HKLM\System\ControlSet001\Services\percsas2i\Parameters\Device] 499. "EnableQueryAccessAlignment"="1" (REG_DWORD) 500. 501. [HKLM\System\ControlSet001\Services\percsas3i\Parameters\Device] 502. "EnableQueryAccessAlignment"="1" (REG_DWORD) 503. 504. [HKLM\System\ControlSet001\Services\storvsc\Parameters\Device] 505. "EnableQueryAccessAlignment"="1" (REG_DWORD) 506. 507. [HKLM\System\DriverDatabase\DriverPackages\amdsata.inf_amd64_ea60132f1a9a7a62\Configurations\amdsata_inst\Services\amdsata\Parameters\Device] 508. "EnableQueryAccessAlignment"="1" (REG_DWORD) 509. 510. [HKLM\System\DriverDatabase\DriverPackages\megasas.inf_amd64_a6884b17a7bddfd4\Configurations\Install_INT.NT\Services\megasas\Parameters\Device] 511. "EnableQueryAccessAlignment"="1" (REG_DWORD) 512. 513. [HKLM\System\DriverDatabase\DriverPackages\megasas.inf_amd64_a6884b17a7bddfd4\Configurations\Install_MSI.NT\Services\megasas\Parameters\Device] 514. "EnableQueryAccessAlignment"="1" (REG_DWORD) 515. 516. [HKLM\System\DriverDatabase\DriverPackages\megasas2i.inf_amd64_8453eea48984e122\Configurations\Install_MSI.NT\Services\megasas2i\Parameters\Device] 517. "EnableQueryAccessAlignment"="1" (REG_DWORD) 518. 519. [HKLM\System\DriverDatabase\DriverPackages\nvraid.inf_amd64_3ee6d81b22b3ea66\Configurations\Crush11_IDE_Inst\Services\nvstor\Parameters\Device] 520. "EnableQueryAccessAlignment"="1" (REG_DWORD) 521. 522. [HKLM\System\DriverDatabase\DriverPackages\nvraid.inf_amd64_3ee6d81b22b3ea66\Configurations\Crush11_Inst\Services\nvstor\Parameters\Device] 523. "EnableQueryAccessAlignment"="1" (REG_DWORD) 524. 525. [HKLM\System\DriverDatabase\DriverPackages\nvraid.inf_amd64_3ee6d81b22b3ea66\Configurations\nvraid\Services\nvraid\Parameters\Device] 526. "EnableQueryAccessAlignment"="1" (REG_DWORD) 527. 528. [HKLM\System\DriverDatabase\DriverPackages\nvraid.inf_amd64_3ee6d81b22b3ea66\Configurations\nvraidbus\Services\nvraid\Parameters\Device] 529. "EnableQueryAccessAlignment"="1" (REG_DWORD) 530. 531. [HKLM\System\DriverDatabase\DriverPackages\percsas2i.inf_amd64_a7f5d94e6751c911\Configurations\Install_MSI.NT\Services\percsas2i\Parameters\Device] 532. "EnableQueryAccessAlignment"="1" (REG_DWORD) 533. 534. [HKLM\System\DriverDatabase\DriverPackages\percsas3i.inf_amd64_8635c202e10bcf51\Configurations\Install_MSI.NT\Services\percsas3i\Parameters\Device] 535. "EnableQueryAccessAlignment"="1" (REG_DWORD) 536. 537. [HKLM\System\DriverDatabase\DriverPackages\wstorvsc.inf_amd64_dcd20fdead9eb74b\Configurations\storvscDriveInstall\Services\storvsc\Parameters\Device] 538. "EnableQueryAccessAlignment"="1" (REG_DWORD) 539. 540. [HKLM\System\CurrentControlSet\Control\iSafeKrnlBoot] 541. "ProgramPath"="C:\Program Files (x86)\Elex-tech\YAC" (REG_SZ) 542. 543. [HKLM\System\CurrentControlSet\Control\Power\EnergyEstimation\StandbyActivationEnergy] 544. DA: 14/11/2016 23:42:15 545. 546. [HKLM\System\CurrentControlSet\Services\amdsata\Parameters\Device] 547. "EnableQueryAccessAlignment"="1" (REG_DWORD) 548. 549. [HKLM\System\CurrentControlSet\Services\LSI_SAS\Parameters\Device] 550. "EnableQueryAccessAlignment"="1" (REG_DWORD) 551. 552. [HKLM\System\CurrentControlSet\Services\LSI_SAS2i\Parameters\Device] 553. "EnableQueryAccessAlignment"="1" (REG_DWORD) 554. 555. [HKLM\System\CurrentControlSet\Services\LSI_SAS3i\Parameters\Device] 556. "EnableQueryAccessAlignment"="1" (REG_DWORD) 557. 558. [HKLM\System\CurrentControlSet\Services\LSI_SSS\Parameters\Device] 559. "EnableQueryAccessAlignment"="1" (REG_DWORD) 560. 561. [HKLM\System\CurrentControlSet\Services\megasas\Parameters\Device] 562. "EnableQueryAccessAlignment"="1" (REG_DWORD) 563. 564. [HKLM\System\CurrentControlSet\Services\megasas2i\Parameters\Device] 565. "EnableQueryAccessAlignment"="1" (REG_DWORD) 566. 567. [HKLM\System\CurrentControlSet\Services\nvraid\Parameters\Device] 568. "EnableQueryAccessAlignment"="1" (REG_DWORD) 569. 570. [HKLM\System\CurrentControlSet\Services\nvstor\Parameters\Device] 571. "EnableQueryAccessAlignment"="1" (REG_DWORD) 572. 573. [HKLM\System\CurrentControlSet\Services\percsas2i\Parameters\Device] 574. "EnableQueryAccessAlignment"="1" (REG_DWORD) 575. 576. [HKLM\System\CurrentControlSet\Services\percsas3i\Parameters\Device] 577. "EnableQueryAccessAlignment"="1" (REG_DWORD) 578. 579. [HKLM\System\CurrentControlSet\Services\storvsc\Parameters\Device] 580. "EnableQueryAccessAlignment"="1" (REG_DWORD) 581. 582. [HKU\S-1-5-20\SOFTWARE\Microsoft\Windows Defender] 583. "CachedProxyAccessType "="1" (REG_DWORD) 584. 585. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000\SOFTWARE\Microsoft\Office\Common\WhatsNew] 586. "Microsoft Word_Content"="CwoACgUFCgABAAAAEhQANE8AcAB0AGkAbQBpAHMAZQB6ACAAbABhACAAbABlAGMAdAB1AHIAZQAgAGEAdgBlAGMAIABsAGUAcwAgAG8AdQB0AGkAbABzACAAZAAZIGEAcABwAHIAZQBuAHQAaQBzAHMAYQBnAGUAEh4A5gFEAGUAIABuAG8AdQB2AGUAbABsAGUAcwAgAGMAbwBtAG0AYQBuAGQAZQBzACAAZAB1ACAAbQBvAGQAZQAgAEwAZQBjAHQAdQByAGUAIABzAGkAbQBwAGwAaQBmAGkAZQBuAHQAIABsABkgZQB4AHAA6QByAGkAZQBuAGMAZQAgAGQAZQAgAGwAZQBjAHQAdQByAGUAIABlAG4AIABhAGoAdQBzAHQAYQBuAHQAIABsABkgZQBzAHAAYQBjAGUAbQBlAG4AdAAgAGQAdQAgAHQAZQB4AHQAZQAsACAAZQBuACAAYQBmAGYAaQBjAGgAYQBuAHQAIABsAGUAIABkAOkAYwBvAHUAcABhAGcAZQAgAGQAZQBzACAAcwB5AGwAbABhAGIAZQBzACAAZQB0ACAAZQBuACAAbQBlAHQAdABhAG4AdAAgAGMAaABhAHEAdQBlACAAbQBvAHQAIABlAG4AIADpAHYAaQBkAGUAbgBjAGUAIABwAGUAbgBkAGEAbgB0ACAAbABhACAAbABlAGMAdAB1AHIAZQAgAOAAIABoAGEAdQB0AGUAIAB2AG8AaQB4ACAAZAB1ACAAZABvAGMAdQBtAGUAbgB0AC4AEkYACVIAZQBhAGQAQQBsAG8AdQBkABJuAA5BAHUAZABpAGUAbgBjAGUAOgA6AE4AbwBuAGUABXgADwAAABKCABQxADYAMAAxAC0AMAAxAC0AMAAxAFQAMAAwADoAMAAwADoAMAAwAFoAEowAFDEANgAwADEALQAwADEALQAwADEAVAAwADAAOgAwADAAOgAwADAAWgAABQoAAgAAABIUABZBAGMAYwBlAHMAcwBpAGIAaQBsAGkAdADpACAAaQBuAHQA6QBnAHIA6QBlABIeAOYBUAByAGkAcwBlACAAZQBuACAAYwBoAGEAcgBnAGUAIABhAG0A6QBsAGkAbwByAOkAZQAgAGQAZQAgAGwAGSB1AHQAaQBsAGkAcwBhAHQAaQBvAG4AIABkAHUAIABjAGwAYQB2AGkAZQByACwAIABkAHUAIABOAGEAcgByAGEAdABlAHUAcgAgAGUAdAAgAGQAZQBzACAAYQB1AHQAcgBlAHMAIAB0AGUAYwBoAG4AbwBsAG8AZwBpAGUAcwAgAGQAGSBhAHMAcwBpAHMAdABhAG4AYwBlACAAcABvAHUAcgAgAHQAcgBhAHYAYQBpAGwAbABlAHIAIABzAHUAcgAgAGQAdQAgAHQAZQB4AHQAZQAsACAAYQBwAHAAbwByAHQAZQByACAAZABlAHMAIABtAG8AZABpAGYAaQBjAGEAdABpAG8AbgBzACAAYQB2AGUAYwAgAGQAGSBhAHUAdAByAGUAcwAgAHUAdABpAGwAaQBzAGEAdABlAHUAcgBzACwAIABjAHIA6QBlAHIAIABkAGUAcwAgAGQAbwBjAHUAbQBlAG4AdABzACAAYQBjAGMAZQBzAHMAaQBiAGwAZQBzACwAIABlAHQAYwAuABJGAA1BAGMAYwBlAHMAcwBpAGIAaQBsAGkAdAB5ABJuAA5BAHUAZABpAGUAbgBjAGUAOgA6AE4AbwBuAGUABXgADwAAABKCABQxADYAMAAxAC0AMAAxAC0AMAAxAFQAMAAwADoAMAAwADoAMAAwAFoAEowAFDEANgAwADEALQAwADEALQAwADEAVAAwADAAOgAwADAAOgAwADAAWgAABQoAAwAAABIUAB5JAG4AcwDpAHIAZQB6ACAAZQB0ACAAbQBvAGQAaQBmAGkAZQB6ACAAZABlAHMAIABpAGMA9ABuAGUAcwASHgBeUgBlAG4AZgBvAHIAYwBlAHoAIABsABkgaQBtAHAAYQBjAHQAIAB2AGkAcwB1AGUAbAAgAGQAZQAgAHYAbwB0AHIAZQAgAGQAbwBjAHUAbQBlAG4AdAAgAGUAbgAgAGkAbgBzAOkAcgBhAG4AdAAgAG8AdQAgAGUAbgAgAG0AbwBkAGkAZgBpAGEAbgB0ACAAdQBuAGUAIABkAGUAIABuAG8AcwAgADUAMAAwAKAAaQBjAPQAbgBlAHMALgASRgASSQBjAG8AbgBJAG4AcwBlAHIAdABGAHIAbwBtAEYAaQBsAGUAEmQAJU0AaQBjAHIAbwBzAG8AZgB0AC4ATwBmAGYAaQBjAGUALgBHAHIAYQBwAGgAaQBjAHMALgBPAG4AbABpAG4AZQBJAGMAbwBuAHMAEm4ADkEAdQBkAGkAZQBuAGMAZQA6ADoATgBvAG4AZQAFeAAPAAAAEoIAFDEANgAwADEALQAwADEALQAwADEAVAAwADAAOgAwADAAOgAwADAAWgASjAAUMQA2ADAAMQAtADAAMQAtADAAMQBUADAAMAA6ADAAMAA6ADAAMABaAAAFCgAEAAAAEhQAIVUAdABpAGwAaQBzAGUAegAgAGQAZQBzACAAaQBtAGEAZwBlAHMAIABTAFYARwAgAGQAYQBuAHMAIABXAG8AcgBkABIeAIUBSQBuAHMA6QByAGUAegAgAGUAdAAgAG0AbwBkAGkAZgBpAGUAegAgAGQAZQBzACAAaQBtAGEAZwBlAHMAIABTAFYARwAgAGQAYQBuAHMAIAB2AG8AdAByAGUAIABkAG8AYwB1AG0AZQBuAHQAIABwAG8AdQByACAAYwByAOkAZQByACAAZAB1ACAAYwBvAG4AdABlAG4AdQAgAGIAaQBlAG4AIABkAOkAZgBpAG4AaQAuACAAQQB1AGMAdQBuACAAbABvAGcAaQBjAGkAZQBsACAAcwBwAOkAYwBpAGEAbABpAHMA6QAgAG4AGSBlAHMAdAAgAG4A6QBjAGUAcwBzAGEAaQByAGUALgASRgASSQBuAHMAZQByAHQASQBtAGEAZwBlAEgAdABtAGwAVABhAGcAEmQAHU0AaQBjAHIAbwBzAG8AZgB0AC4ATwBmAGYAaQBjAGUALgBHAHIAYQBwAGgAaQBjAHMALgBTAFYARwASbgAOQQB1AGQAaQBlAG4AYwBlADoAOgBOAG8AbgBlAAV4AA8AAAASggAUMQA2ADAAMQAtADAAMQAtADAAMQBUADAAMAA6ADAAMAA6ADAAMABaABKMABQxADYAMAAxAC0AMAAxAC0AMAAxAFQAMAAwADoAMAAwADoAMAAwAFoAAAUKAAUAAAASFAA9RQBuAHIAZQBnAGkAcwB0AHIAZQB6ACAAZABlAHMAIABmAGkAYwBoAGkAZQByAHMAIAByAGEAcABpAGQAZQBtAGUAbgB0ACAAZABhAG4AcwAgAGwAZQBzACAAZABvAHMAcwBpAGUAcgBzACAAcgDpAGMAZQBuAHQAcwASHgCEAUUAbgByAGUAZwBpAHMAdAByAGUAegAgAGQAZQBzACAAZABvAGMAdQBtAGUAbgB0AHMAIABkAGEAbgBzACAAbABlAHMAIABkAG8AcwBzAGkAZQByAHMAIAByAOkAYwBlAG0AbQBlAG4AdAAgAHUAdABpAGwAaQBzAOkAcwAgAOAAIABsABkgYQBpAGQAZQAgAGQAZQAgAGwAGSBvAG4AZwBsAGUAdAAgAFIA6QBjAGUAbgB0ACAAYQBjAGMAZQBzAHMAaQBiAGwAZQAgAHYAaQBhACAAbAAZIG8AcAB0AGkAbwBuACAARQBuAHIAZQBnAGkAcwB0AHIAZQByACAAcwBvAHUAcwAuABJGAB1TAGUAYwB0AGkAbwBuAEwAaQBuAGsAVAByAGEAbgBzAGkAdABpAG8AbgBEAHUAcgBhAHQAaQBvAG4AEmQAK00AaQBjAHIAbwBzAG8AZgB0AC4ATwBmAGYAaQBjAGUALgBEAG8AYwBzAC4AUwBhAHYAZQBBAHMAUgBlAGMAZQBuAHQATABvAGMAYQB0AGkAbwBuAHMAEm4ADkEAdQBkAGkAZQBuAGMAZQA6ADoATgBvAG4AZQAFeAAPAAAAEoIAFDEANgAwADEALQAwADEALQAwADEAVAAwADAAOgAwADAAOgAwADAAWgASjAAUMQA2ADAAMQAtADAAMQAtADAAMQBUADAAMAA6ADAAMAA6ADAAMABaAAAA" (REG_SZ) 587. 588. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000\SOFTWARE\Microsoft\Office\Common\WhatsNew] 589. "Microsoft PowerPoint_Content"="CwoACgcFCgABAAAAEhQAQEEAcABwAG8AcgB0AGUAegAgAGQAZQBzACAAbQBvAGQAaQBmAGkAYwBhAHQAaQBvAG4AcwAgAGUAbgAgAHQAZQBtAHAAcwAgAHIA6QBlAGwAIABhAHYAZQBjACAAZAAZIGEAdQB0AHIAZQBzACAAcABlAHIAcwBvAG4AbgBlAHMAEh4AdkkAZABlAG4AdABpAGYAaQBlAHoAIABsAGUAcwAgAHMAZQBjAHQAaQBvAG4AcwAgAGQAYQBuAHMAIABsAGUAcwBxAHUAZQBsAGwAZQBzACAAZAAZIGEAdQB0AHIAZQBzACAAcABlAHIAcwBvAG4AbgBlAHMAIAB0AHIAYQB2AGEAaQBsAGwAZQBuAHQAIABlAHQAIABjAG8AbgBzAHUAbAB0AGUAegAgAGwAZQB1AHIAcwAgAG0AbwBkAGkAZgBpAGMAYQB0AGkAbwBuAHMAIABlAG4AIAB0AGUAbQBwAHMAIAByAOkAZQBsAC4AEkYADkQAZQBsAGUAZwBhAHQAZQBBAGMAYwBlAHMAcwASZAApTQBpAGMAcgBvAHMAbwBmAHQALgBPAGYAZgBpAGMAZQAuAFAAbwB3AGUAcgBQAG8AaQBuAHQALgBBAHUAdABvAFMAYQB2AGUATQBlAHIAZwBlABJuAA5BAHUAZABpAGUAbgBjAGUAOgA6AE4AbwBuAGUABXgADwAAABKCABQxADYAMAAxAC0AMAAxAC0AMAAxAFQAMAAwADoAMAAwADoAMAAwAFoAEowAFDEANgAwADEALQAwADEALQAwADEAVAAwADAAOgAwADAAOgAwADAAWgAABQoAAgAAABIUABZBAGMAYwBlAHMAcwBpAGIAaQBsAGkAdADpACAAaQBuAHQA6QBnAHIA6QBlABIeAJQBUAByAGkAcwBlACAAZQBuACAAYwBoAGEAcgBnAGUAIABhAG0A6QBsAGkAbwByAOkAZQAgAGQAZQAgAGwAGSB1AHQAaQBsAGkAcwBhAHQAaQBvAG4AIABkAHUAIABjAGwAYQB2AGkAZQByACwAIABkAHUAIABOAGEAcgByAGEAdABlAHUAcgAgAGUAdAAgAGQAZQBzACAAYQB1AHQAcgBlAHMAIAB0AGUAYwBoAG4AbwBsAG8AZwBpAGUAcwAgAGQAGSBhAHMAcwBpAHMAdABhAG4AYwBlACAAcABvAHUAcgAgAGwAaQByAGUAIABlAHQAIABtAG8AZABpAGYAaQBlAHIAIABkAGUAcwAgAHAAcgDpAHMAZQBuAHQAYQB0AGkAbwBuAHMALgASRgANQQBjAGMAZQBzAHMAaQBiAGkAbABpAHQAeQASbgAOQQB1AGQAaQBlAG4AYwBlADoAOgBOAG8AbgBlAAV4AA8AAAASggAUMQA2ADAAMQAtADAAMQAtADAAMQBUADAAMAA6ADAAMAA6ADAAMABaABKMABQxADYAMAAxAC0AMAAxAC0AMAAxAFQAMAAwADoAMAAwADoAMAAwAFoAAAUKAAMAAAASFAAeSQBuAHMA6QByAGUAegAgAGUAdAAgAG0AbwBkAGkAZgBpAGUAegAgAGQAZQBzACAAaQBjAPQAbgBlAHMAEh4AYlIAZQBuAGYAbwByAGMAZQB6ACAAbAAZIGkAbQBwAGEAYwB0ACAAdgBpAHMAdQBlAGwAIABkAGUAIAB2AG8AdAByAGUAIABwAHIA6QBzAGUAbgB0AGEAdABpAG8AbgAgAGUAbgAgAGkAbgBzAOkAcgBhAG4AdAAgAGUAdAAgAGUAbgAgAG0AbwBkAGkAZgBpAGEAbgB0ACAAdQBuAGUAIABkAGUAIABuAG8AcwAgADUAMAAwAKAAaQBjAPQAbgBlAHMALgASRgASSQBjAG8AbgBJAG4AcwBlAHIAdABGAHIAbwBtAEYAaQBsAGUAEmQAJU0AaQBjAHIAbwBzAG8AZgB0AC4ATwBmAGYAaQBjAGUALgBHAHIAYQBwAGgAaQBjAHMALgBPAG4AbABpAG4AZQBJAGMAbwBuAHMAEm4ADkEAdQBkAGkAZQBuAGMAZQA6ADoATgBvAG4AZQAFeAAPAAAAEoIAFDEANgAwADEALQAwADEALQAwADEAVAAwADAAOgAwADAAOgAwADAAWgASjAAUMQA2ADAAMQAtADAAMQAtADAAMQBUADAAMAA6ADAAMAA6ADAAMABaAAAFCgAEAAAAEhQAJ1UAdABpAGwAaQBzAGUAegAgAGQAZQBzACAAaQBtAGEAZwBlAHMAIABTAFYARwAgAGQAYQBuAHMAIABQAG8AdwBlAHIAUABvAGkAbgB0ABIeAIkBSQBuAHMA6QByAGUAegAgAGUAdAAgAG0AbwBkAGkAZgBpAGUAegAgAGQAZQBzACAAaQBtAGEAZwBlAHMAIABTAFYARwAgAGQAYQBuAHMAIAB2AG8AdAByAGUAIABwAHIA6QBzAGUAbgB0AGEAdABpAG8AbgAgAHAAbwB1AHIAIABjAHIA6QBlAHIAIABkAHUAIABjAG8AbgB0AGUAbgB1ACAAYgBpAGUAbgAgAGQA6QBmAGkAbgBpAC4AIABBAHUAYwB1AG4AIABsAG8AZwBpAGMAaQBlAGwAIABzAHAA6QBjAGkAYQBsAGkAcwDpACAAbgAZIGUAcwB0ACAAbgDpAGMAZQBzAHMAYQBpAHIAZQAuABJGABJJAG4AcwBlAHIAdABJAG0AYQBnAGUASAB0AG0AbABUAGEAZwASZAAdTQBpAGMAcgBvAHMAbwBmAHQALgBPAGYAZgBpAGMAZQAuAEcAcgBhAHAAaABpAGMAcwAuAFMAVgBHABJuAA5BAHUAZABpAGUAbgBjAGUAOgA6AE4AbwBuAGUABXgADwAAABKCABQxADYAMAAxAC0AMAAxAC0AMAAxAFQAMAAwADoAMAAwADoAMAAwAFoAEowAFDEANgAwADEALQAwADEALQAwADEAVAAwADAAOgAwADAAOgAwADAAWgAABQoABQAAABIUAD1FAG4AcgBlAGcAaQBzAHQAcgBlAHoAIABkAGUAcwAgAGYAaQBjAGgAaQBlAHIAcwAgAHIAYQBwAGkAZABlAG0AZQBuAHQAIABkAGEAbgBzACAAbABlAHMAIABkAG8AcwBzAGkAZQByAHMAIAByAOkAYwBlAG4AdABzABIeAIgBRQBuAHIAZQBnAGkAcwB0AHIAZQB6ACAAZABlAHMAIABwAHIA6QBzAGUAbgB0AGEAdABpAG8AbgBzACAAZABhAG4AcwAgAGwAZQBzACAAZABvAHMAcwBpAGUAcgBzACAAcgDpAGMAZQBtAG0AZQBuAHQAIAB1AHQAaQBsAGkAcwDpAHMAIADgACAAbAAZIGEAaQBkAGUAIABkAGUAIABsABkgbwBuAGcAbABlAHQAIABSAOkAYwBlAG4AdAAgAGEAYwBjAGUAcwBzAGkAYgBsAGUAIAB2AGkAYQAgAGwAGSBvAHAAdABpAG8AbgAgAEUAbgByAGUAZwBpAHMAdAByAGUAcgAgAHMAbwB1AHMALgASRgAdUwBlAGMAdABpAG8AbgBMAGkAbgBrAFQAcgBhAG4AcwBpAHQAaQBvAG4ARAB1AHIAYQB0AGkAbwBuABJkACtNAGkAYwByAG8AcwBvAGYAdAAuAE8AZgBmAGkAYwBlAC4ARABvAGMAcwAuAFMAYQB2AGUAQQBzAFIAZQBjAGUAbgB0AEwAbwBjAGEAdABpAG8AbgBzABJuAA5BAHUAZABpAGUAbgBjAGUAOgA6AE4AbwBuAGUABXgADwAAABKCABQxADYAMAAxAC0AMAAxAC0AMAAxAFQAMAAwADoAMAAwADoAMAAwAFoAEowAFDEANgAwADEALQAwADEALQAwADEAVAAwADAAOgAwADAAOgAwADAAWgAABQoABgAAABIUACVDAHIA6QBlAHoAIABkAGUAcwAgAGYAbwByAG0AZQBzACAAbQBhAG4AdQBzAGMAcgBpAHQAZQBzACAAcAByAOkAYwBpAHMAZQBzABIeAH5GAGEAaQB0AGUAcwAgAGcAbABpAHMAcwBlAHIAIABsAGEAIABnAG8AbQBtAGUAIADgACAAcwBlAGcAbQBlAG4AdABzACAAcABvAHUAcgAgAHMAdQBwAHAAcgBpAG0AZQByACAAYwBlAHIAdABhAGkAbgBlAHMAIABwAG8AcgB0AGkAbwBuAHMAIABkAGUAcwAgAGUAbgB0AHIA6QBlAHMAIABtAGEAbgB1AHMAYwByAGkAdABlAHMALAAgAGoAdQBzAHEAdQAZIOAAIABsAGEAIABsAGkAZwBuAGUAIABsAGEAIABwAGwAdQBzACAAcAByAG8AYwBoAGUALgASRgANUwBlAGcAbQBlAG4AdABFAHIAYQBzAGUAcgASZAAwTQBpAGMAcgBvAHMAbwBmAHQALgBPAGYAZgBpAGMAZQAuAFAAbwB3AGUAcgBQAG8AaQBuAHQALgBPAGEAcgB0AEkAbgBrAFMAZQBnAG0AZQBuAHQARQByAGEAcwBlAHIAEm4ADkEAdQBkAGkAZQBuAGMAZQA6ADoATgBvAG4AZQAFeAAPAAAAEoIAFDEANgAwADEALQAwADEALQAwADEAVAAwADAAOgAwADAAOgAwADAAWgASjAAUMQA2ADAAMQAtADAAMQAtADAAMQBUADAAMAA6ADAAMAA6ADAAMABaAAAFCgAHAAAAEhQAPlUAdABpAGwAaQBzAGUAegAgAHYAbwB0AHIAZQAgAHMAdAB5AGwAZQB0ACAAcABvAHUAcgAgAHMA6QBsAGUAYwB0AGkAbwBuAG4AZQByACAAZQB0ACAAbQBvAGQAaQBmAGkAZQByACAAZABlAHMAIABvAGIAagBlAHQAcwASHgC/AUwAZQAgAHMAdAB5AGwAZQB0ACAAUwB1AHIAZgBhAGMAZQAgAHYAbwB1AHMAIABwAGUAcgBtAGUAdAAgAGQAZQAgAHIAZQBkAGkAbQBlAG4AcwBpAG8AbgBuAGUAcgAgAGUAdAAgAGQAZQAgAGYAYQBpAHIAZQAgAHAAaQB2AG8AdABlAHIAIABkAGUAcwAgAG8AYgBqAGUAdABzACwAIABkAGUAIABkAOkAcABsAGEAYwBlAHIAIABsAGUAcwAgAHAAbwBpAGcAbgDpAGUAcwAgAGQAZQBzACAAbwBiAGoAZQB0AHMAIABlAHQAIABkAGUAIABzAOkAbABlAGMAdABpAG8AbgBuAGUAcgAgAGQAZQBzACAAZQBuAHQAcgDpAGUAcwAgAG0AYQBuAHUAcwBjAHIAaQB0AGUAcwAgAHAAYQByACAAbABhAHMAcwBvACAAcwBhAG4AcwAgAGEAYwBjAOkAZABlAHIAIABhAHUAIAByAHUAYgBhAG4ALgASRgAPVABhAGIAbABlAE0AbwB2AGUASABhAG4AZABsAGUAEmQAOk0AaQBjAHIAbwBzAG8AZgB0AC4ATwBmAGYAaQBjAGUALgBQAG8AdwBlAHIAUABvAGkAbgB0AC4ATwBhAHIAdABTAGgAYQBwAGUASQBuAHQAZQByAGEAYwB0AGkAbwBuAFcAaQB0AGgAUwB0AHkAbAB1AHMAEm4ADkEAdQBkAGkAZQBuAGMAZQA6ADoATgBvAG4AZQAFeAAPAAAAEoIAFDEANgAwADEALQAwADEALQAwADEAVAAwADAAOgAwADAAOgAwADAAWgASjAAUMQA2ADAAMQAtADAAMQAtADAAMQBUADAAMAA6ADAAMAA6ADAAMABaAAAA" (REG_SZ) 590. 591. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] 592. "C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe"="SACP" (REG_BINARY) 593. 594. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] 595. "C:\Program Files (x86)\Elex-tech\YAC\uninstall.exe"="SACP" (REG_BINARY) 596. 597. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000\SOFTWARE\Classes\AppXv3w8be6gretzpzjq0s27982mxr4acyac] 598. DA: 29/03/2017 18:59:12 599. 600. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWINDOWS%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d23ec7f15ae24c\5404146] 601. "@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAccountInfo/Description}"="Paramètres de confidentialité des informations sur le compte" (REG_SZ) 602. 603. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWINDOWS%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d23ec7f15ae24c\5404146] 604. "@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAccountInfo/HighKeywords}"="informations utilisateur;user information" (REG_SZ) 605. 606. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWINDOWS%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d23ec7f15ae24c\5404146] 607. "@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAccountInfo/Keywords}"="" (REG_SZ) 608. 609. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWINDOWS%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d23ec7f15ae24c\5404146] 610. "@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAccountInfo/LowKeywords}"="Contrôles contrôle;restreindre restreint restriction;nom;image;Controls control;restrict restricts restricted restricting; name; picture" (REG_SZ) 611. 612. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\App\Capabilities\URLAssociations] 613. "skypesettings"="AppXv3w8be6gretzpzjq0s27982mxr4acyac" (REG_SZ) 614. 615. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000_Classes\AppXv3w8be6gretzpzjq0s27982mxr4acyac] 616. DA: 29/03/2017 18:59:12 617. 618. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000_Classes\Local Settings\MrtCache\C:%5CWINDOWS%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d23ec7f15ae24c\5404146] 619. "@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAccountInfo/Description}"="Paramètres de confidentialité des informations sur le compte" (REG_SZ) 620. 621. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000_Classes\Local Settings\MrtCache\C:%5CWINDOWS%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d23ec7f15ae24c\5404146] 622. "@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAccountInfo/HighKeywords}"="informations utilisateur;user information" (REG_SZ) 623. 624. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000_Classes\Local Settings\MrtCache\C:%5CWINDOWS%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d23ec7f15ae24c\5404146] 625. "@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAccountInfo/Keywords}"="" (REG_SZ) 626. 627. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000_Classes\Local Settings\MrtCache\C:%5CWINDOWS%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d23ec7f15ae24c\5404146] 628. "@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAccountInfo/LowKeywords}"="Contrôles contrôle;restreindre restreint restriction;nom;image;Controls control;restrict restricts restricted restricting; name; picture" (REG_SZ) 629. 630. [HKU\S-1-5-21-962331595-1246707547-2241510325-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\App\Capabilities\URLAssociations] 631. "skypesettings"="AppXv3w8be6gretzpzjq0s27982mxr4acyac" (REG_SZ) 632. 633. ========================= 634. 635. Fin à: 19:04:59 le 29/03/2017 636. 698789 Éléments analysés 637. 638. ========================= 639. E.O.F