--------------- QuickDiag | g3n-h@ckm@n | V3_19.10.17.1 --------------- ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 19/10/2017 18:44:41 Updated 19/10/2017 | 18.05 (GMT) by g3n-h@ckm@n Contact : http://www.sosvirus.net/ Time Zone : (UTC+01:00) Bruxelles, Copenhague, Madrid, Paris [Thomas (Administrator)] - [PC-THOMAS] (S-1-5-21-1200667838-2990588833-2439126145-1001) System: Microsoft Windows 8.1 Professionnel - - (6.3.9600) - BuildType: Multiprocessor Free - OSLanguage: 1036 (040c) -> () System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True Boot : Microsoft Windows 8.1 Professionnel|C:\WINDOWS|\Device\Harddisk0\Partition2 Boot : Normal boot PC: To Be Filled By O.E.M. - To Be Filled By O.E.M. - IdNumber: To Be Filled By O.E.M. - UUID: 03000200-0400-0500-0006-000700080009 Processor : X64 - 3394 Mhz - AMD Athlon(tm) X4 750K Quad Core Processor BIOS Date: 01/17/14 18:49:19 Ver: 04.06.05 - - American Megatrends Inc. - S/N: To Be Filled By O.E.M. - P2.10 - ALASKA - 1072009 CoreTemp : ? Celsius ----------| Quick ---------- | SoundDevice Périphérique High Definition Audio - Status: OK - Manufacturer: Microsoft - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10EC&DEV_0892&SUBSYS_1849C892&REV_1003\4&22D0AEA8&0&0001 NVIDIA High Definition Audio - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: HDAUDIO\FUNC_01&VEN_10DE&DEV_0084&SUBSYS_14583724&REV_1001\5&79E213E&0&0001 NVIDIA Virtual Audio Device (Wave Extensible) (WDM) - Status: OK - Manufacturer: NVIDIA - PNPDeviceID: ROOT\UNNAMED_DEVICE\0000 Virtual Audio Cable - Status: OK - Manufacturer: EuMus Design - PNPDeviceID: ROOT\MEDIA\0000 ---------- | Video NVIDIA GeForce GTX 1060 3GB - Resolution: 1920x1080 - Colors: 4294967296 - RefreshRate: 60 - 32 Bits Per Pixel - DeviceID: VideoController1 - Drivers: nvd3dumx.dll,nvwgf2umx.dll,nvwgf2umx.dll,nvd3dum,nvwgf2um,nvwgf2um - PNPDeviceID: PCI\VEN_10DE&DEV_1C02&SUBSYS_37241458&REV_A1\4&B1EEDFB&0&0010 - AdapterCompatibility: NVIDIA - RAM: -1073741824 Inegrated Video Chipset DeviceName: NVIDIA GeForce GTX 1060 3GB - DriverVersion: 21.21.13.7866 - SpecificationVersion: 1025 ---------- | Codecs c:\windows\system32\l3codeca.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 82432 - Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK c:\windows\system32\msg711.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 25312 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msrle32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 16896 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\tsbyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 15872 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 34088 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 26624 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msvidc32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 37888 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\iyuv_32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 52736 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\frapsv64.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 71680 - Manufacturer: Beepa P/L - Status: OK c:\windows\system32\imaadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 35664 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\msgsm32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 41880 - Manufacturer: Microsoft Corporation - Status: OK c:\windows\system32\ficvdec_x64.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 652288 - Manufacturer: - Status: OK ---------- | CPU ---------- | Network Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20) - Ethernet 802.3 - Qualcomm Atheros - Status: - PnPID : PCI\VEN_1969&DEV_10A1&SUBSYS_10A11849&REV_10\4&70251AE&0&00AB Carte réseau de débogage du noyau Microsoft - - Microsoft - Status: - PnPID : ROOT\KDNIC\0000 SAMSUNG Mobile USB Remote NDIS Network Device - - - Status: - PnPID : LogMeIn Hamachi Virtual Ethernet Adapter - Ethernet 802.3 - LogMeIn Inc. - Status: - PnPID : ROOT\NET\0000 Remote NDIS based Internet Sharing Device - - - Status: - PnPID : ---------- | Memory RAM = Total (MB) : 8305 | Free (MB) : 4196 Pagefile = Total (MB) : 9616 | Free (MB) : 4140 Virtual = Total (MB) : 4194 | Free (MB) : 3952 Physical Memory 0 : Capacity: 8589934592 - DIMM 0 - Posit.: 0 - Manufacturer: Kingston - PartNumber: KHX1600C10D3/8G - S/N: 69162F99 ---------- | SID Users Administrateur : [S-1-5-21-1200667838-2990588833-2439126145-500] Invité : [S-1-5-21-1200667838-2990588833-2439126145-501] Thomas : [S-1-5-21-1200667838-2990588833-2439126145-1001] Administrateurs : [S-1-5-32-544] Administrateurs Hyper-V : [S-1-5-32-578] Duplicateurs : [S-1-5-32-552] IIS_IUSRS : [S-1-5-32-568] Invités : [S-1-5-32-546] Lecteurs des journaux d’événements : [S-1-5-32-573] Opérateurs d'assistance de contrôle d'accès : [S-1-5-32-579] Opérateurs de chiffrement : [S-1-5-32-569] Opérateurs de configuration réseau : [S-1-5-32-556] Opérateurs de sauvegarde : [S-1-5-32-551] Utilisateurs : [S-1-5-32-545] Utilisateurs avec pouvoir : [S-1-5-32-547] Utilisateurs de gestion à distance : [S-1-5-32-580] Utilisateurs de l’Analyseur de performances : [S-1-5-32-558] Utilisateurs du Bureau à distance : [S-1-5-32-555] Utilisateurs du journal de performances : [S-1-5-32-559] Utilisateurs du modèle COM distribué : [S-1-5-32-562] WinRMRemoteWMIUsers__ : [S-1-5-21-1200667838-2990588833-2439126145-1000] ---------- | SystemAccounts Name: Tout le monde - SID: S-1-1-0 - SIDType: 5 - Status: OK Name: LOCAL - SID: S-1-2-0 - SIDType: 5 - Status: OK Name: CREATEUR PROPRIETAIRE - SID: S-1-3-0 - SIDType: 5 - Status: OK Name: GROUPE CREATEUR - SID: S-1-3-1 - SIDType: 5 - Status: OK Name: CREATOR OWNER SERVER - SID: S-1-3-2 - SIDType: 5 - Status: OK Name: CREATOR GROUP SERVER - SID: S-1-3-3 - SIDType: 5 - Status: OK Name: DROITS DU PROPRIÉTAIRE - SID: S-1-3-4 - SIDType: 5 - Status: OK Name: LIGNE - SID: S-1-5-1 - SIDType: 5 - Status: OK Name: RESEAU - SID: S-1-5-2 - SIDType: 5 - Status: OK Name: TACHE - SID: S-1-5-3 - SIDType: 5 - Status: OK Name: INTERACTIF - SID: S-1-5-4 - SIDType: 5 - Status: OK Name: SERVICE - SID: S-1-5-6 - SIDType: 5 - Status: OK Name: ANONYMOUS LOGON - SID: S-1-5-7 - SIDType: 5 - Status: OK Name: Proxy - SID: S-1-5-8 - SIDType: 5 - Status: OK Name: Système - SID: S-1-5-18 - SIDType: 5 - Status: OK Name: ENTERPRISE DOMAIN CONTROLLERS - SID: S-1-5-9 - SIDType: 5 - Status: OK Name: SELF - SID: S-1-5-10 - SIDType: 5 - Status: OK Name: Utilisateurs authentifiés - SID: S-1-5-11 - SIDType: 5 - Status: OK Name: RESTRICTED - SID: S-1-5-12 - SIDType: 5 - Status: OK Name: UTILISATEUR TERMINAL SERVER - SID: S-1-5-13 - SIDType: 5 - Status: OK Name: REMOTE INTERACTIVE LOGON - SID: S-1-5-14 - SIDType: 5 - Status: OK Name: IUSR - SID: S-1-5-17 - SIDType: 5 - Status: OK Name: SERVICE LOCAL - SID: S-1-5-19 - SIDType: 5 - Status: OK Name: SERVICE RÉSEAU - SID: S-1-5-20 - SIDType: 5 - Status: OK Name: BUILTIN - SID: S-1-5-32 - SIDType: 3 - Status: OK ---------- | Drives C:\ -> [Fixed] | [] | Total : 49.66 Go | Free : 0.19 Go -> NTFS [SATA] D:\ -> [Fixed] | [Data] | Total : 881.51 Go | Free : 219.68 Go -> NTFS [SATA] DeviceID: \\.\PHYSICALDRIVE0 - Status: OK - IDE - Fixed hard disk media - 3 Part. - PnPID : SCSI\DISK&VEN_&PROD_ST1000DM003-1ER1\4&1DFD9489&0&010000 ---------- | Windows updates Last detection : 2017-10-18 19:57:51 Downloaded last ones : 2017-10-17 17:56:33 Installed last ones : 2017-09-02 17:50:21 Next search : 2017-10-19 17:37:12 Test 1 : Windows Is Activated ---------- | Browsers IE : 11.0.9600.18124 (© Microsoft Corporation. Tous droits réservés.) GC : 61.0.3163.100 (Copyright 2016 Google Inc.) Default : "C:\Program Files\Internet Explorer\iexplore.exe" ---------- | FlashPlayer FlashPlayer ActiveX : 26.0.0.137 FlashPlayer Plugin : 27.0.0.159 ---------- | Security AV : Windows Defender Disabled AS : Avast Antivirus Enabled FW : Avast Antivirus Enabled WMI : OK WU: Windows Update Service [Manual(3)] = stopped AS: Windows Defender [Manual(3)] = stopped WMI: Windows Management Instrumentation [Auto(2)] = Running ---------- | Running processes 344 | [Owner : Système | Parent : 4(System) | ?????] - (.Microsoft Corporation - Gestionnaire de sessions Windows.) - (6.3.9600.17031) = C:\Windows\System32\smss.exe [21/11/2014 00:55:29] --> Command Line : 476 | [Owner : Système | Parent : 464() | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (6.3.9600.16384) = C:\Windows\System32\csrss.exe [22/08/2013 15:25:40] --> Command Line : 528 | [Owner : Système | Parent : 464() | 3.85 Mo] - (.Microsoft Corporation - Application de démarrage de Windows.) - (6.3.9600.18577) = C:\Windows\System32\wininit.exe [15/03/2017 18:25:06] --> Command Line : 544 | [Owner : Système | Parent : 536() | ?????] - (.Microsoft Corporation - Processus d’exécution client-serveur.) - (6.3.9600.16384) = C:\Windows\System32\csrss.exe [22/08/2013 15:25:40] --> Command Line : 584 | [Owner : Système | Parent : 528(wininit.exe) | ?????] - (.Microsoft Corporation - Applications Services et Contrôleur.) - (6.3.9600.17793) = C:\Windows\System32\services.exe [13/05/2015 14:22:38] --> Command Line : 592 | [Owner : Système | Parent : 528(wininit.exe) | ?????] - (.Microsoft Corporation - Local Security Authority Process.) - (6.3.9600.17415) = C:\Windows\System32\lsass.exe [21/11/2014 01:19:13] --> Command Line : 636 | [Owner : Système | Parent : 536() | 7.77 Mo] - (.Microsoft Corporation - Application d’ouverture de session Windows.) - (6.3.9600.18188) = C:\Windows\System32\winlogon.exe [09/03/2016 10:50:04] --> Command Line : 716 | [Owner : Système | Parent : 584(services.exe) | 12.09 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 748 | [Owner : SERVICE RÉSEAU | Parent : 584(services.exe) | 8.15 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 864 | [Owner : DWM-1 | Parent : 636(winlogon.exe) | 30.58 Mo] - (.Microsoft Corporation - Gestionnaire de fenêtres du Bureau.) - (6.3.9600.17415) = C:\Windows\System32\dwm.exe [21/11/2014 01:20:39] --> Command Line : 896 | [Owner : Système | Parent : 584(services.exe) | 9.86 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.2.0.0) = C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [08/03/2017 20:28:17] --> Command Line : 972 | [Owner : SERVICE LOCAL | Parent : 584(services.exe) | 24.6 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 1004 | [Owner : Système | Parent : 896(NVDisplay.Container.exe) | 21.47 Mo] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) - (8.17.13.7866) = C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [08/03/2017 20:28:38] --> Command Line : 1012 | [Owner : Système | Parent : 584(services.exe) | 96.34 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 268 | [Owner : Système | Parent : 584(services.exe) | 37.94 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 372 | [Owner : SERVICE LOCAL | Parent : 584(services.exe) | 19.37 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 1096 | [Owner : SERVICE RÉSEAU | Parent : 584(services.exe) | 20.09 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 1184 | [Owner : Système | Parent : 584(services.exe) | ?????] - (.AVAST Software - Avast Service.) - (17.7.3660.0) = D:\Program Files\AVAST Software\Avast\AvastSvc.exe [10/10/2017 20:19:24] --> Command Line : 1444 | [Owner : Système | Parent : 584(services.exe) | 14.58 Mo] - (.Microsoft Corporation - Application sous-système spouleur.) - (6.3.9600.17415) = C:\Windows\System32\spoolsv.exe [21/11/2014 01:20:20] --> Command Line : 1472 | [Owner : SERVICE LOCAL | Parent : 584(services.exe) | 20.94 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 1540 | [Owner : Système | Parent : 584(services.exe) | ?????] - (.AVAST Software - Avast firewall service.) - (17.7.3660.0) = D:\Program Files\AVAST Software\Avast\afwServ.exe [10/10/2017 20:19:12] --> Command Line : 1668 | [Owner : Système | Parent : 584(services.exe) | 6.3 Mo] - (.Adobe Systems Incorporated - Adobe Update Service.) - (4.2.0.211) = C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [13/07/2017 09:50:22] --> Command Line : 1768 | [Owner : Système | Parent : 584(services.exe) | 8.28 Mo] - (.Adobe Systems, Incorporated - Adobe Genuine Software Integrity Service.) - (4.4.0.652) = C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [26/09/2016 12:55:26] --> Command Line : 1800 | [Owner : Système | Parent : 584(services.exe) | 13.2 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 1844 | [Owner : SERVICE LOCAL | Parent : 1012(svchost.exe) | 14.67 Mo] - (.Microsoft Corporation - Device Association Framework Provider Host.) - (6.3.9600.17415) = C:\Windows\System32\dasHost.exe [21/11/2014 01:19:49] --> Command Line : 1868 | [Owner : Système | Parent : 584(services.exe) | 7.92 Mo] - (.IObit - Product Updater.) - (2.1.6.1447) = C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [13/05/2016 21:30:02] --> Command Line : 1928 | [Owner : Système | Parent : 584(services.exe) | 9.57 Mo] - (.Malwarebytes - Malwarebytes Anti-Malware.) - (3.1.6.0) = D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [19/10/2015 19:24:39] --> Command Line : 2072 | [Owner : Système | Parent : 584(services.exe) | 21.31 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.6.2264.7232) = C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [08/03/2017 20:29:39] --> Command Line : 2128 | [Owner : SERVICE RÉSEAU | Parent : 584(services.exe) | 10.6 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.4.2250.7081) = C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [14/04/2017 18:44:44] --> Command Line : 2888 | [Owner : Thomas | Parent : 268(svchost.exe) | 10.71 Mo] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) - (6.3.9600.17415) = C:\Windows\System32\taskhostex.exe [21/11/2014 01:19:37] --> Command Line : 2964 | [Owner : Thomas | Parent : 2936() | 112.84 Mo] - (.Microsoft Corporation - Explorateur Windows.) - (6.3.9600.18460) = C:\Windows\explorer.exe [17/10/2016 11:32:34] --> Command Line : 2104 | [Owner : Thomas | Parent : 2072(nvcontainer.exe) | 26.25 Mo] - (.NVIDIA Corporation - NVIDIA Container.) - (1.6.2264.7232) = C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [08/03/2017 20:29:39] --> Command Line : 2724 | [Owner : SERVICE LOCAL | Parent : 584(services.exe) | 6.54 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 3120 | [Owner : Système | Parent : 584(services.exe) | 10.43 Mo] - (.LogMeIn Inc. - Hamachi Client Tunneling Engine.) - (2.2.0.579) = D:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [29/06/2017 12:31:56] --> Command Line : 3180 | [Owner : Système | Parent : 3120(hamachi-2.exe) | 5.3 Mo] - (.LogMeIn, Inc. - LMIGuardianSvc.) - (10.1.0.1742) = D:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [27/05/2016 14:04:16] --> Command Line : 3296 | [Owner : SERVICE RÉSEAU | Parent : 716(svchost.exe) | 11.15 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (6.3.9600.18264) = C:\Windows\System32\wbem\WmiPrvSE.exe [11/05/2016 10:57:37] --> Command Line : 4084 | [Owner : SERVICE LOCAL | Parent : 584(services.exe) | 12.08 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 3788 | [Owner : Système | Parent : 584(services.exe) | ?????] - (.AVAST Software s.r.o. - Avast Behavior Shield.) - (17.7.3.15075) = D:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [10/10/2017 20:19:17] --> Command Line : 3544 | [Owner : SERVICE RÉSEAU | Parent : 584(services.exe) | 4.66 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 3552 | [Owner : Système | Parent : 584(services.exe) | 23.86 Mo] - (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - (7.0.9600.18722) = C:\Windows\System32\SearchIndexer.exe [18/07/2017 12:00:40] --> Command Line : 3220 | [Owner : Thomas | Parent : 716(svchost.exe) | 14.12 Mo] - (.Microsoft Corporation - OneDrive Sync Engine.) - (6.3.9600.17416) = C:\Windows\System32\SkyDrive.exe [21/11/2014 05:48:43] --> Command Line : 5132 | [Owner : Thomas | Parent : 4056() | 44.1 Mo] - (.AVAST Software - Avast Antivirus.) - (17.7.3660.226) = D:\Program Files\AVAST Software\Avast\AvastUI.exe [10/10/2017 20:20:11] --> Command Line : 5164 | [Owner : Thomas | Parent : 716(svchost.exe) | 26.95 Mo] - (.NVIDIA Corporation - NVIDIA Capture Server.) - (3.9.0.61) = C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe [08/03/2017 20:30:15] --> Command Line : 5432 | [Owner : Thomas | Parent : 2964(explorer.exe) | 5.92 Mo] - (.Nota Inc. - Gyazo Station.) - (2.2.0.0) = C:\Program Files (x86)\Gyazo\GyStation.exe [20/06/2017 19:04:36] --> Command Line : 5596 | [Owner : Thomas | Parent : 2964(explorer.exe) | 44.63 Mo] - (.SteelSeries ApS - SteelSeries Engine 3 Core.) - (3.10.9.0) = C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe [30/06/2017 21:40:46] --> Command Line : 5656 | [Owner : Thomas | Parent : 5580() | 8.68 Mo] - (.Oracle Corporation - Java Update Scheduler.) - (2.8.131.11) = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [15/03/2017 02:37:52] --> Command Line : 5668 | [Owner : Thomas | Parent : 5640() | 11.28 Mo] - (.Skillbrains - Lightshot.) - (5.3.0.0) = C:\Program Files (x86)\Skillbrains\lightshot\5.3.0.0\Lightshot.exe [02/10/2015 21:46:49] --> Command Line : 5788 | [Owner : Thomas | Parent : 5580() | 67.18 Mo] - (.Adobe Systems Incorporated - Adobe Creative Cloud.) - (4.2.0.211) = C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [13/07/2017 09:50:22] --> Command Line : 5804 | [Owner : Thomas | Parent : 2072(nvcontainer.exe) | 9.68 Mo] - (.NVIDIA Corporation - NVIDIA ShadowPlay Helper.) - (3.9.0.61) = C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe [08/03/2017 20:30:16] --> Command Line : 5820 | [Owner : Thomas | Parent : 5164(nvspcaps64.exe) | 43.72 Mo] - (.NVIDIA Corporation - NVIDIA Share.) - (59.3071.1634.2) = C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe [08/03/2017 20:30:09] --> Command Line : 5948 | [Owner : Thomas | Parent : 5788(Creative Cloud.exe) | 8.38 Mo] - (.Adobe Systems Incorporated - Adobe IPC Broker.) - (5.4.0.12) = C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe [14/02/2017 11:41:16] --> Command Line : 5972 | [Owner : SERVICE LOCAL | Parent : 972(svchost.exe) | ?????] - (.Microsoft Corporation - Isolation graphique de périphérique audio Windows.) - (6.3.9600.17415) = C:\Windows\System32\audiodg.exe [21/11/2014 01:19:39] --> Command Line : 1780 | [Owner : Thomas | Parent : 5156() | 44.13 Mo] - (.Node.js - NVIDIA Web Helper Service.) - (6.9.5.0) = C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe [08/03/2017 20:30:06] --> Command Line : 1752 | [Owner : Thomas | Parent : 1780(NVIDIA Web Helper.exe) | 3.64 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (6.3.9600.17415) = C:\Windows\System32\conhost.exe [21/11/2014 01:20:37] --> Command Line : 5284 | [Owner : Thomas | Parent : 5788(Creative Cloud.exe) | 63.55 Mo] - (.Adobe Systems Incorporated - Creative Cloud.) - (4.2.0.211) = C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe [13/07/2017 09:50:22] --> Command Line : 5480 | [Owner : Thomas | Parent : 5788(Creative Cloud.exe) | 57.09 Mo] - (.Adobe Systems Incorporated - Adobe CEF Helper.) - (4.2.0.211) = C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe [13/07/2017 09:50:22] --> Command Line : 4704 | [Owner : Thomas | Parent : 4284() | 112.15 Mo] - (.Valve Corporation - Steam Client Bootstrapper.) - (4.18.55.94) = D:\Program Files (x86)\Steam\Steam.exe [19/10/2017 18:18:21] --> Command Line : 3140 | [Owner : Thomas | Parent : 5284(Adobe Desktop Service.exe) | 23.88 Mo] - (.- Core Sync.) - (2.4.2.61) = C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe [14/08/2017 03:48:42] --> Command Line : 4640 | [Owner : Système | Parent : 5204() | 0.1 Mo] - (.Google Inc. - Programme d'installation de Google.) - (1.3.29.5) = C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [10/06/2016 15:18:56] --> Command Line : 6128 | [Owner : Système | Parent : 4640(GoogleUpdate.exe) | 0.15 Mo] - (.Google Inc. - Google Crash Handler.) - (1.3.33.5) = C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe [10/05/2017 12:57:36] --> Command Line : 5984 | [Owner : Thomas | Parent : 5284(Adobe Desktop Service.exe) | 2.49 Mo] - (.Adobe Systems Incorporated - CCXProcess.) - (2.0.1.406) = C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe [13/07/2017 10:12:36] --> Command Line : 6184 | [Owner : Thomas | Parent : 5984(CCXProcess.exe) | 57.58 Mo] - (.Node.js - Node.js: Server-side JavaScript.) - (6.9.2.0) = C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe [19/12/2016 17:35:00] --> Command Line : 6192 | [Owner : SERVICE RÉSEAU | Parent : 584(services.exe) | 7.12 Mo] - (.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) - (12.0.9600.17415) = C:\Program Files\Windows Media Player\wmpnetwk.exe [21/11/2014 01:21:25] --> Command Line : 6244 | [Owner : Thomas | Parent : 6184(node.exe) | 3.61 Mo] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (6.3.9600.17415) = C:\Windows\System32\conhost.exe [21/11/2014 01:20:37] --> Command Line : 6528 | [Owner : Thomas | Parent : 5788(Creative Cloud.exe) | 48.96 Mo] - (.Adobe Systems Incorporated - Adobe CEF Helper.) - (4.2.0.211) = C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe [13/07/2017 09:50:22] --> Command Line : 7116 | [Owner : Système | Parent : 4640(GoogleUpdate.exe) | 0.06 Mo] - (.Google Inc. - Google Crash Handler.) - (1.3.33.5) = C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe [10/05/2017 12:57:36] --> Command Line : 2364 | [Owner : Thomas | Parent : 716(svchost.exe) | 2.82 Mo] - (.Microsoft Corporation - Host Process for Setting Synchronization.) - (6.3.9600.18231) = C:\Windows\System32\SettingSyncHost.exe [13/04/2016 11:40:01] --> Command Line : 3692 | [Owner : Thomas | Parent : 4704(Steam.exe) | 32.29 Mo] - (.Valve Corporation - Steam Client WebHelper.) - (4.18.55.94) = D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe [19/10/2017 18:18:21] --> Command Line : 7144 | [Owner : Thomas | Parent : 3692(steamwebhelper.exe) | 15.04 Mo] - (.Valve Corporation - Steam Client WebHelper.) - (4.18.55.94) = D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe [19/10/2017 18:18:21] --> Command Line : 3216 | [Owner : Système | Parent : 584(services.exe) | 13 Mo] - (.Valve Corporation - Steam Client Service.) - (4.18.55.94) = C:\Program Files (x86)\Common Files\Steam\SteamService.exe [25/12/2014 14:53:40] --> Command Line : 2864 | [Owner : Thomas | Parent : 5820(NVIDIA Share.exe) | 52.16 Mo] - (.NVIDIA Corporation - NVIDIA Share.) - (59.3071.1634.2) = C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe [08/03/2017 20:30:09] --> Command Line : 6288 | [Owner : Thomas | Parent : 5656(jusched.exe) | 11.97 Mo] - (.Oracle Corporation - Java Update Checker.) - (2.8.131.11) = C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe [15/03/2017 02:37:40] --> Command Line : 196 | [Owner : Système | Parent : 3552(SearchIndexer.exe) | 4.42 Mo] - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) - (7.0.9600.18722) = C:\Windows\System32\SearchProtocolHost.exe [18/07/2017 12:00:40] --> Command Line : 2628 | [Owner : Système | Parent : 3552(SearchIndexer.exe) | 4.52 Mo] - (.Microsoft Corporation - Microsoft Windows Search Filter Host.) - (7.0.9600.17415) = C:\Windows\System32\SearchFilterHost.exe [21/11/2014 01:21:19] --> Command Line : 2760 | [Owner : Thomas | Parent : 2964(explorer.exe) | 311.33 Mo] - (.Mozilla Corporation - Firefox.) - (56.0.1.6484) = D:\Program Files (x86)\Mozilla Firefox\firefox.exe [15/10/2017 17:47:33] --> Command Line : 968 | [Owner : Thomas | Parent : 2760(firefox.exe) | 80.58 Mo] - (.Mozilla Corporation - Firefox.) - (56.0.1.6484) = D:\Program Files (x86)\Mozilla Firefox\firefox.exe [15/10/2017 17:47:33] --> Command Line : 5908 | [Owner : Thomas | Parent : 2760(firefox.exe) | 214.57 Mo] - (.Mozilla Corporation - Firefox.) - (56.0.1.6484) = D:\Program Files (x86)\Mozilla Firefox\firefox.exe [15/10/2017 17:47:33] --> Command Line : 6020 | [Owner : Thomas | Parent : 2760(firefox.exe) | 204.24 Mo] - (.Mozilla Corporation - Firefox.) - (56.0.1.6484) = D:\Program Files (x86)\Mozilla Firefox\firefox.exe [15/10/2017 17:47:33] --> Command Line : 4456 | [Owner : Thomas | Parent : 2760(firefox.exe) | 267.55 Mo] - (.Mozilla Corporation - Firefox.) - (56.0.1.6484) = D:\Program Files (x86)\Mozilla Firefox\firefox.exe [15/10/2017 17:47:33] --> Command Line : 7216 | [Owner : Système | Parent : 584(services.exe) | 3.06 Mo] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.3.9600.17415) = C:\Windows\System32\svchost.exe [21/11/2014 01:19:13] --> Command Line : 7292 | [Owner : Système | Parent : 7216(svchost.exe) | ?????] - (.Microsoft Corporation - Rapport d’erreurs Windows.) - (6.3.9600.17550) = C:\Windows\SysWOW64\WerFaultSecure.exe [06/04/2015 17:01:38] --> Command Line : 7400 | [Owner : Système | Parent : 7216(svchost.exe) | ?????] - (.Microsoft Corporation - Rapport d’erreurs Windows.) - (6.3.9600.17550) = C:\Windows\SysWOW64\WerFaultSecure.exe [06/04/2015 17:01:38] --> Command Line : 7996 | [Owner : Thomas | Parent : 2964(explorer.exe) | 34.18 Mo] - (.SosVirus - QuickDiag.) - (19.10.17.1) = C:\Users\Thomas\Desktop\QuickDiag.exe [19/10/2017 18:41:51] --> Command Line : 5572 | [Owner : Thomas | Parent : 2760(firefox.exe) | 128.5 Mo] - (.Mozilla Corporation - Firefox.) - (56.0.1.6484) = D:\Program Files (x86)\Mozilla Firefox\firefox.exe [15/10/2017 17:47:33] --> Command Line : 7608 | [Owner : Thomas | Parent : 2760(firefox.exe) | 210.94 Mo] - (.Mozilla Corporation - Firefox.) - (56.0.1.6484) = D:\Program Files (x86)\Mozilla Firefox\firefox.exe [15/10/2017 17:47:33] --> Command Line : 4540 | [Owner : Système | Parent : 716(svchost.exe) | 6.16 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (6.3.9600.18264) = C:\Windows\System32\wbem\WmiPrvSE.exe [11/05/2016 10:57:37] --> Command Line : 7548 | [Owner : SERVICE RÉSEAU | Parent : 716(svchost.exe) | 7.8 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (6.3.9600.18264) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe [11/05/2016 10:57:37] --> Command Line : ---------- | MD5 [MD5.ED6B4C95E2A6D67480B9DBB8A8E7D9B4] - [17/10/2016 11:32:34] - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [2690.92 Ko] - (6.3.9600.18460) : C:\WINDOWS\Explorer.exe [MD5.F5AE03DE0AD60F5B17B82F2CD68402FE] - [21/11/2014 01:19:43] - (.© Microsoft Corporation. Tous droits réservés. - Interpréteur de commandes Windows.) - [349 Ko] - (6.3.9600.17415) : C:\WINDOWS\System32\cmd.exe [MD5.B2D3F07F5E8A13AF988A8B3C0A800880] - [22/08/2013 15:25:40] - (.© Microsoft Corporation. Tous droits réservés. - Processus d’exécution client-serveur.) - [16.72 Ko] - (6.3.9600.16384) : C:\WINDOWS\System32\csrss.exe [MD5.9361355721F51E3A25DF53702D10E9DE] - [21/11/2014 01:19:13] - (.© Microsoft Corporation. - COM Surrogate.) - [18.81 Ko] - (6.3.9600.17415) : C:\WINDOWS\System32\dllhost.exe [MD5.4F455778B6CDA2FD61D4F8B0A3E0543C] - [21/11/2014 01:19:48] - (.© Microsoft Corporation. Tous droits réservés. - DLL du client API BASE Windows NT.) - [1279.05 Ko] - (6.3.9600.17415) : C:\WINDOWS\System32\Kernel32.dll [MD5.382100E75B6F4668AEAEF228C6CEFFAD] - [21/11/2014 01:19:13] - (.© Microsoft Corporation. - Local Security Authority Process.) - [45.92 Ko] - (6.3.9600.17415) : C:\WINDOWS\System32\lsass.exe [MD5.20CC6E9FE25ACD34BE4FCDDB7B08364D] - [12/05/2017 13:57:54] - (.© Microsoft Corporation. - Distributed COM Services.) - [798.5 Ko] - (6.3.9600.18666) : C:\WINDOWS\System32\rpcss.dll [MD5.6C308D32AFA41D26CE2A0EA8F7B79565] - [21/11/2014 01:20:22] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte Windows (Rundll32).) - [53.5 Ko] - (6.3.9600.17415) : C:\WINDOWS\System32\rundll32.exe [MD5.E0C7813A97CA7947FF5C18A8F3B61A45] - [13/05/2015 14:22:38] - (.© Microsoft Corporation. Tous droits réservés. - Applications Services et Contrôleur.) - [400.52 Ko] - (6.3.9600.17793) : C:\WINDOWS\System32\services.exe [MD5.E3A2AD05E24105B35E986CF9CB38EC47] - [21/11/2014 01:19:13] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte pour les services Windows.) - [37.88 Ko] - (6.3.9600.17415) : C:\WINDOWS\System32\svchost.exe [MD5.421B695412FE0D5B0C0DB00C51EABA1B] - [14/12/2016 16:07:56] - (.© Microsoft Corporation. Tous droits réservés. - DLL client de l’API uilisateur de Windows multi-utilisateurs.) - [1505.12 Ko] - (6.3.9600.18535) : C:\WINDOWS\System32\user32.dll [MD5.5C131534A3EA4A461A793FB507A8004F] - [21/11/2014 01:19:14] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Userinit.) - [25.5 Ko] - (6.3.9600.17415) : C:\WINDOWS\System32\userinit.exe [MD5.D9516405E05F24EDCD90B1988FAF3948] - [15/03/2017 18:25:06] - (.© Microsoft Corporation. Tous droits réservés. - Application de démarrage de Windows.) - [143.5 Ko] - (6.3.9600.18577) : C:\WINDOWS\System32\Wininit.exe [MD5.B1102BBDDD9C87B3D609D6C08F7A3DBD] - [09/03/2016 10:50:04] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Windows.) - [557.5 Ko] - (6.3.9600.18188) : C:\WINDOWS\System32\Winlogon.exe [MD5.A460C3AF3755A2A79A3C8EFE72E147B5] - [11/11/2015 13:11:36] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de fonction connexe pour WinSock.) - [546.5 Ko] - (6.3.9600.18089) : C:\WINDOWS\System32\Drivers\afd.sys [MD5.74B14192CF79A72F7536B27CB8814FBD] - [22/08/2013 14:22:57] - (.© Microsoft Corporation. - ATAPI IDE Miniport Driver.) - [25.84 Ko] - (6.3.9600.16384) : C:\WINDOWS\System32\Drivers\atapi.sys [MD5.38E1F4E0148A24C65D215F14D57B0711] - [22/08/2013 14:22:57] - (.© Microsoft Corporation. - ATAPI Driver Extension.) - [194.84 Ko] - (6.3.9600.16384) : C:\WINDOWS\System32\Drivers\ataport.sys [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - [22/08/2013 13:40:20] - (.© Microsoft Corporation. - CD-ROM File System Driver.) - [86.5 Ko] - (6.3.9600.16384) : C:\WINDOWS\System32\Drivers\cdfs.sys [MD5.C6796EA22B513E3457514D92DCDB1A3D] - [22/08/2013 10:46:35] - (.© Microsoft Corporation. - SCSI CD-ROM Driver.) - [160.5 Ko] - (6.3.9600.16384) : C:\WINDOWS\System32\Drivers\cdrom.sys [MD5.4FED6AD69C9EE1EE7FD3C88437138855] - [12/05/2017 13:58:02] - (.© Microsoft Corporation. - DFS Namespace Client Driver.) - [135.5 Ko] - (6.3.9600.18573) : C:\WINDOWS\System32\Drivers\dfsc.sys [MD5.D4B7ED39C7900384D9E5C1283F1E7926] - [21/11/2014 01:19:10] - (.© Microsoft Corporation. - High Definition Audio Bus Driver.) - [75 Ko] - (6.3.9600.17238) : C:\WINDOWS\System32\Drivers\hdaudbus.sys [MD5.49EE0AE9E5B64FFBBD06D55C4984B598] - [15/07/2015 10:38:26] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port i8042.) - [106 Ko] - (6.3.9600.17480) : C:\WINDOWS\System32\Drivers\i8042prt.sys [MD5.B7342B3C58E91107F6E946A93D9D4EFD] - [21/11/2014 00:55:49] - (.© Microsoft Corporation. - IP Network Address Translator.) - [139.5 Ko] - (6.3.9600.16477) : C:\WINDOWS\System32\Drivers\ipnat.sys [MD5.E2FC654EC895E92A022794329BFC53EC] - [18/07/2017 11:59:47] - (.© Microsoft Corporation. Tous droits réservés. - Minirdr SMB Windows NT.) - [392 Ko] - (6.3.9600.18586) : C:\WINDOWS\System32\Drivers\mrxsmb.sys [MD5.FFAA6C6E798FBA448FA7628A1B277F5C] - [12/05/2017 13:58:32] - (.© Microsoft Corporation. Tous droits réservés. - NDIS (Network Driver Interface Specification).) - [1087.84 Ko] - (6.3.9600.18577) : C:\WINDOWS\System32\Drivers\ndis.sys [MD5.9DC17B7D9D84C37C102D379FCC7D4942] - [15/06/2016 11:16:20] - (.© Microsoft Corporation. - MBT Transport driver.) - [274.5 Ko] - (6.3.9600.18340) : C:\WINDOWS\System32\Drivers\netbt.sys [MD5.275CF7F20338B2B1F5264C665033073F] - [18/07/2017 12:01:20] - (.© Microsoft Corporation. Tous droits réservés. - Pilote du système de fichiers NT.) - [1966.34 Ko] - (6.3.9600.18727) : C:\WINDOWS\System32\Drivers\ntfs.sys [MD5.57DCE4FB0467986AE78E1C6FC5240D32] - [15/10/2016 12:32:15] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port parallèle.) - [94 Ko] - (6.3.9600.18437) : C:\WINDOWS\System32\Drivers\parport.sys [MD5.235624C147E3CB4C288D5D3D8E8D64A2] - [13/04/2016 11:42:02] - (.© Microsoft Corporation. - RAS L2TP mini-port/call-manager driver.) - [110 Ko] - (6.3.9600.18226) : C:\WINDOWS\System32\Drivers\rasl2tp.sys [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - [21/11/2014 00:27:19] - (.© Microsoft Corporation. Tous droits réservés. - Redirecteur de périphérique de Microsoft RDP.) - [191 Ko] - (6.3.9600.16384) : C:\WINDOWS\System32\Drivers\rdpdr.sys [MD5.2F10C145F517419E17203632FCDA0A13] - [14/12/2016 16:08:00] - (.© Microsoft Corporation. Tous droits réservés. - Pilote TCP/IP.) - [2404.34 Ko] - (6.3.9600.18478) : C:\WINDOWS\System32\Drivers\tcpip.sys [MD5.23DF7EBD9B782E1436CEC700565A4366] - [18/07/2017 12:00:11] - (.© Microsoft Corporation. - TDI Translation Driver.) - [105 Ko] - (6.3.9600.18698) : C:\WINDOWS\System32\Drivers\tdx.sys [MD5.17F7B0F2298D97F4B6C7A69511033D3D] - [11/05/2016 10:57:06] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de cliché instantané du volume.) - [309.34 Ko] - (6.3.9600.18265) : C:\WINDOWS\System32\Drivers\volsnap.sys ---------- | Locked Applications ---------- | Explorer.exe component call (Microsoft Files Whitelisted) (.NVIDIA Corporation.-.NVIDIA D3D10 Driver, Version 378.66.) - (21.21.13.7866) -- C:\WINDOWS\SYSTEM32\nvwgf2umx.dll (.NVIDIA Corporation.-.NVIDIA Capture Server Proxy.) - (3.9.0.61) -- C:\WINDOWS\system32\nvspcap64.dll (..-.Core Sync.) - (2.4.2.61) -- C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncExtension\CoreSync_x64.dll (..-..) - (0.0.0.0) -- :\Program Files\AVAST Software\Avast\ashShA64.dll (..-..) - (0.0.0.0) -- :\Program Files (x86)\WinCDEmu\x64\WinCDEmuContextMenu.dll (.NVIDIA Corporation.-.NVIDIA NVAPI Library, Version 378.66.) - (21.21.13.7866) -- C:\WINDOWS\system32\nvapi64.dll (.Alexander Roshal.-.WinRAR shell extension.) - (5.40.0.0) -- C:\Program Files\WinRAR\rarext.dll (.IObit.-.IObitUnlockerExtension.) - (1.2.0.2) -- C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll (..-..) - (0.0.0.0) -- :\Program Files (x86)\Notepad++\NppShell_06.dll (.NVIDIA Corporation.-.NVIDIA Shell Extensions.) - (8.17.13.7866) -- C:\WINDOWS\system32\nv3dappshext.dll (..-..) - (0.0.0.0) -- :\windows\SysWOW64\cmdlineext_x64.dll (.IObit.-.Uninstall for explorer.) - (1.0.7.16) -- C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll (..-..) - (0.0.0.0) -- :\Program Files\Recuva\RecuvaShell64.dll ---------- | Svchost.exe component call (Microsoft Files Whitelisted) (..-..) - (0.0.0.0) -- C:\Program Files\AVAST Software\Avast\x64\aswhooka.dll ---------- | ZeroAccess Check [HKLM\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll [HKLM\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll ---------- | Startings up uTorrent - ("C:\Users\Thomas\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\...\Run]) - User: PC-THOMAS\Thomas CCleaner Monitoring - ("C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\...\Run]) - User: PC-THOMAS\Thomas AdobeBridge - ( [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\...\Run]) - User: PC-THOMAS\Thomas EADM - ("D:\Program Files (x86)\Origin\Origin.exe" -AutoStart [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\...\Run]) - User: PC-THOMAS\Thomas Chromatic - (C:\Users\Thomas\AppData\Local\Chromatic\application\chromatic.exe --restore-last-session [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\...\Run]) - User: PC-THOMAS\Thomas Updater - (C:\Users\Thomas\AppData\Local\Chromatic\Utils\Updater.exe [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\...\Run]) - User: PC-THOMAS\Thomas Steam - ("D:\Program Files (x86)\Steam\steam.exe" -silent [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\...\Run]) - User: PC-THOMAS\Thomas Skype - ("C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\...\Run]) - User: PC-THOMAS\Thomas Gyazo - (C:\Program Files (x86)\Gyazo\GyStation.exe [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\...\Run]) - User: PC-THOMAS\Thomas SteelSeries Engine 3 - (C:\PROGRA~1\STEELS~1\STEELS~1\STEELS~1.EXE -dataPath="C:\ProgramData\SteelSeries\SteelSeries Engine 3" -dbEnv=production -auto=true [Common Startup]) - User: Public MouseDriver - (TiltWheelMouse.exe [HKLM\SOFTWARE\...\Run]) - User: Public ShadowPlay - ("C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart [HKLM\SOFTWARE\...\Run]) - User: Public AvastUI.exe - ("D:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui [HKLM\SOFTWARE\...\Run]) - User: Public AdobeAAMUpdater-1.0 - ("C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [HKLM\SOFTWARE\...\Run]) - User: Public [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Command Processor] "PathCompletionChar"=9 "EnableExtensions"=1 "CompletionChar"=9 "DefaultColor"=0 [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Run] "uTorrent"="C:\Users\Thomas\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR "AdobeBridge"= "EADM"="D:\Program Files (x86)\Origin\Origin.exe" -AutoStart "Chromatic"=C:\Users\Thomas\AppData\Local\Chromatic\application\chromatic.exe --restore-last-session "Updater"=C:\Users\Thomas\AppData\Local\Chromatic\Utils\Updater.exe "Steam"="D:\Program Files (x86)\Steam\steam.exe" -silent "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun "Gyazo"=C:\Program Files (x86)\Gyazo\GyStation.exe [20/06/2017 19:04:36] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "uTorrent"=0x03000000671204D3B78DD001 "DAEMON Tools Lite"=0x03000000BF77970AE3BED001 "{BD9F320B-EDDC-42BA-80E3-3332A8A5F11D}"=0x020000000000000000000000 "Skype"=0x0300000020E8357D67A0D101 "WindApp"=0x020000000000000000000000 "CyberGhost"=0x020000000000000000000000 "CCleaner Monitoring"=0x0300000010C449527C7CD101 "Steam"=0x020000000000000000000000 "EADM"=0x03000000A0DDB5507C7CD101 "AdobeBridge"=0x03000000E016F9527C7CD101 "Chromatic"=0x020000000000000000000000 "Updater"=0x020000000000000000000000 "WatchDog"=0x020000000000000000000000 [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "UserSelectedDefault"=1 "Device"=HP Officejet Pro 6230 (Copie 1),winspool,Ne03: [HKLM\Software\Microsoft\Command Processor] "PathCompletionChar"=64 "EnableExtensions"=1 "CompletionChar"=64 "DefaultColor"=0 [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "MouseDriver"=TiltWheelMouse.exe "ShadowPlay"="C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart "AvastUI.exe"="D:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui "AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "ShadowPlay"=0x020000000000000000000000 "NvBackend"=0x020000000000000000000000 "MouseDriver"=0x03000000B6C04F0EE3BED001 "cpuminer"=0x03000000015167D4B78DD001 "Andy"=0x0300000017F3380CE3BED001 "gpuminer"=0x03000000F412CB76B9ECD001 "AdobeAAMUpdater-1.0"=0x020000000000000000000000 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32] "BlueStacks Agent"=0x03000000AE7F1FD7B78DD001 "gmsd_fr_373"=0x0300000017FC262F7E7FD001 "Lightshot"=0x020000000000000000000000 "AvastUI.exe"=0x020000000000000000000000 "SunJavaUpdateSched"=0x020000000000000000000000 "AdobeCS6ServiceManager"=0x020000000000000000000000 "SwitchBoard"=0x020000000000000000000000 "InstallShieldSetup"=0x03000000101B68557C7CD101 [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "Spooler"=yes "DeviceNotSelectedTimeout"=15 "TransmissionRetryTimeout"=90 "EnableDwmInputProcessing"=7 "ShutdownWarningDialogTimeout"=4294967295 "USERProcessHandleQuota"=10000 "LoadAppInit_DLLs"=0 "IconServiceLib"=IconCodecService.dll "DesktopHeapLogging"=1 "DdeSendTimeout"=0 "DwmInputUsesIoCompletionPort"=1 "USERPostMessageLimit"=10000 "USERNestedWindowLimit"=50 "AppInit_DLLs"= "NaturalInputHandler"=Ninput.dll "ThreadUnresponsiveLogTimeout"=500 "GDIProcessHandleQuota"=10000 "Win32kLastWriteTime"=1D2EB62FDEA7E06 [HKLM\Software\WOW6432Node\Microsoft\Command Processor] "PathCompletionChar"=64 "EnableExtensions"=1 "CompletionChar"=64 "DefaultColor"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] "BlueStacks Agent"=C:\Program Files (x86)\BlueStacks\HD-Agent.exe [16/09/2017 16:12:39] "Lightshot"=C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [16/06/2016 22:06:13] "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "LogMeIn Hamachi Ui"="D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start "Adobe Creative Cloud"="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows] ""=mnmsrvc "Spooler"=yes "DeviceNotSelectedTimeout"=15 "TransmissionRetryTimeout"=90 "EnableDwmInputProcessing"=7 "ShutdownWarningDialogTimeout"=4294967295 "USERProcessHandleQuota"=10000 "LoadAppInit_DLLs"=1 "IconServiceLib"=IconCodecService.dll "DesktopHeapLogging"=1 "DdeSendTimeout"=0 "DwmInputUsesIoCompletionPort"=1 "USERPostMessageLimit"=10000 "USERNestedWindowLimit"=50 "AppInit_DLLs"= "NaturalInputHandler"=Ninput.dll "ThreadUnresponsiveLogTimeout"=500 "GDIProcessHandleQuota"=10000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED} ---------- | Win.ini : ---------- | System.ini : ---------- | Tasks List Adobe Flash Player Updater AdobeAAMUpdater-1.0-MicrosoftAccount-tom_62210@hotmail.fr Avast Emergency Update CCleanerSkipUAC GoogleUpdateTaskMachineCore GoogleUpdateTaskMachineUA GyazoUpdateTaskMachine GyazoUpdateTaskMachineDaily NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} Optimize Start Menu Cache Files-S-1-5-21-1200667838-2990588833-2439126145-1001 SafeZone scheduled Autoupdate 1490634679 Uninstaller_SkipUac_Thomas update-S-1-5-21-1200667838-2990588833-2439126145-1001 update-sys User_Feed_Synchronization-{59FD181C-8EAA-41A7-84E8-0B36D93CBB0D} {28866037-A235-4610-8926-98A8DFAB7A61} ---------- | Startings up registry ? Folder ---------- | Control - lsa - SecurityProviders - Session Manager - Terminal Server [HKLM\System\CurrentControlSet\Control] "PreshutdownOrder"=wuauserv gpsvc trustedinstaller "EarlyStartServices"=RpcSs Power BrokerInfrastructure SystemEventsBroker DcomLaunch RpcEpMapper LSM "BootDriverFlags"=28 "CurrentUser"=USERNAME "WaitToKillServiceTimeout"=200 "ServiceControlManagerExtension"=%systemroot%\system32\scext.dll "SystemStartOptions"= NODEBUG "SystemBootDevice"=multi(0)disk(0)rdisk(0)partition(2) "FirmwareBootDevice"=multi(0)disk(0)rdisk(0)partition(1) "LastBootSucceeded"=1 "LastBootShutdown"=1 "DirtyShutdownCount"=220 [HKLM\System\CurrentControlSet\Control\lsa] "Bounds"=0x0030000000200000 "auditbasedirectories"=0 "fullprivilegeauditing"=0x00 "crashonauditfail"=0 "auditbaseobjects"=0 "LimitBlankPasswordUse"=1 "NoLmHash"=1 "Notification Packages"=scecli "Authentication Packages"=msv1_0 "SecureBoot"=1 "ProductType"=6 "disabledomaincreds"=0 "everyoneincludesanonymous"=0 "forceguest"=0 "restrictanonymous"=0 "restrictanonymoussam"=1 "LsaPid"=592 "Security Packages"=kerberos msv1_0 schannel wdigest tspkg pku2u livessp "SamConnectedAccountsExist"=1 [HKLM\System\CurrentControlSet\Control\SecurityProviders] "SecurityProviders"=credssp.dll [HKLM\System\CurrentControlSet\Control\Session Manager] "GlobalFlag"=0 "HeapDeCommitTotalFreeThreshold"=0 "HeapSegmentCommit"=0 "HeapDeCommitFreeBlockThreshold"=0 "ResourceTimeoutCount"=648000 "ObjectDirectories"=\Windows \RPC Control "ProtectionMode"=1 "CriticalSectionTimeout"=2592000 "ProcessorControl"=2 "HeapSegmentReserve"=0 "ExcludeFromKnownDlls"= "BootExecute"=autocheck autochk * "BootShell"=%SystemRoot%\system32\bootim.exe "NumberOfInitialSessions"=2 "RunLevelExecute"=WinInit ServiceControlManager "AutoChkTimeout"=1 "RunLevelValidate"=ServiceControlManager "SETUPEXECUTE"= [HKLM\System\CurrentControlSet\Control\Terminal Server] "StartRCM"=0 "DeleteTempDirsOnExit"=1 "fSingleSessionPerUser"=1 "TSUserEnabled"=0 "RCDependentServices"=CertPropSvc SessionEnv "SnapshotMonitors"=1 "DelayConMgrTimeout"=0 "NotificationTimeOut"=0 "PerSessionTempDir"=0 "AllowRemoteRPC"=0 "ProductVersion"=5.1 "fDenyTSConnections"=1 "InstanceID"=eaed8b15-703e-47c4-9770-f0cb9dc "GlassSessionId"=1 "fDenyChildConnections"=0 ---------- | .LNK with Arguments ---------- | AppCertDlls ---------- | Dnsapi.dll C:\WINDOWS\System32\dnsapi.dll -> OK : \drivers\etc\hosts C:\WINDOWS\SysWOW64\dnsapi.dll -> OK : \drivers\etc\hosts ---------- | Policies | Registry [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Control Panel\Desktop] "DragHeight"=4 "CoolSwitchColumns"=7 "ActiveWndTrackTimeout"=0 "MouseCornerClipLength"=6 "MouseMonitorEscapeSpeed"=0 "DragWidth"=4 "WallpaperStyle"=10 "ScreenSaveActive"=1 "TileWallpaper"=0 "WheelScrollLines"=3 "Pattern"=0 "FontSmoothingType"=2 "WindowArrangementActive"=1 "BlockSendInputResets"=0 "MenuShowDelay"=400 "ClickLockTime"=1200 "CaretWidth"=1 "FocusBorderWidth"=1 "WallpaperOriginX"=0 "WallpaperOriginY"=0 "DragFullWindows"=1 "CoolSwitchRows"=3 "ForegroundFlashCount"=7 "LeftOverlapChars"=3 "ForegroundLockTimeout"=200000 "FontSmoothingGamma"=0 "DragFromMaximize"=1 "FontSmoothing"=2 "FocusBorderHeight"=1 "WheelScrollChars"=3 "DockMoving"=1 "SnapSizing"=1 "CursorBlinkRate"=530 "MouseWheelRouting"=1 "RightOverlapChars"=3 "FontSmoothingOrientation"=1 "PaintDesktopVersion"=0 "UserPreferencesMask"=0x9E1E078012000000 "AutoColorization"=0 "MaxVirtualDesktopDimension"=1920 "MaxMonitorDimension"=1920 "TranscodedImageCount"=1 "LastUpdated"=4294967295 "TranscodedImageCache"=0x7AC30100CA2E22008007000038040000F6E5B3B55D34D30144003A005C00500072006F006700720061006D002000460069006C00650073002000280078003800360029005C004300340044005C00630072006F0070007000650064002D0031003900320030002D0031003000380030002D003500350036003900330036002E006A0070006700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "ImageColor"=3305111551 "PreferredUILanguages"=fr-FR "ScreenSaverIsSecure"=1 "ScreenSaveTimeOut"=21600 "Wallpaper"=D:\Program Files (x86)\C4D\cropped-1920-1080-556936.jpg [23/09/2017 13:18:40] "Win8DpiScaling"=0 "ActiveWndTrkTimeout"=500 "WaitToKillAppTimeout"=200 "HungAppTimeout"=0 "DesktopDPIOverride"=0 "SCRNSAVE.EXE"=C:\WINDOWS\system32\scrnsave.scr [21/11/2014 01:20:22] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDriveTypeAutoRun"=145 [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer] "ShellState"=0x240000003E28000000000000000000000000000001000000130000000000000062000000 "ExplorerStartupTraceRecorded"=1 "UserSignedIn"=1 "SIDUpdatedOnLibraries"=1 "LastClockSize"=0x270000000F000000460000000F000000410000000F000000 "GlobalAssocChangedCounter"=391 "AppReadinessLogonComplete"=1 "link"=0x1E000000 "Browse For Folder Width"=725 "Browse For Folder Height"=634 [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 "ServerAdminUI"=0 "Hidden"=2 "ShowCompColor"=1 "HideFileExt"=0 "DontPrettyPath"=0 "ShowInfoTip"=1 "HideIcons"=0 "MapNetDrvBtn"=0 "WebView"=1 "Filter"=0 "ShowSuperHidden"=0 "SeparateProcess"=0 "AutoCheckSelect"=0 "IconsOnly"=0 "ShowTypeOverlay"=1 "ShowStatusBar"=1 "ListviewAlphaSelect"=1 "ListviewShadow"=1 "TaskbarAnimations"=1 "StartMenuInit"=6 "ReindexedProfile"=1 "Start_TrackSearchContract"=1 "ApplicationSearchHistory"=1 "TaskbarSizeMove"=1 "StoreAppsOnTaskbar"=0 "DisablePreviewDesktop"=1 "TaskbarGlomLevel"=0 "RTStartMenuNotificationDisplayCount"=0 "NavPaneShowAllFolders"=1 "TaskbarSmallIcons"=0 "DontUsePowerShellOnWinX"=1 "Start_JumpListItems"=10 [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery] "MRUListEx"=0xFFFFFFFF [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "EnableVirtualization"=1 "EnableInstallerDetection"=1 "PromptOnSecureDesktop"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "ConsentPromptBehaviorAdmin"=5 "ValidateAdminCodeSignatures"=0 "EnableUIADesktopToggle"=0 "EnableCursorSuppression"=1 "ConsentPromptBehaviorUser"=3 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "FilterAdministratorToken"=0 "SoftwareSASGeneration"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktopChanges"=1 "NoActiveDesktop"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoComponents"=1 "NoAddingComponents"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{8E74D236-7F35-4720-B138-1FED0B85EA75}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "HKeyRoot"=2147483649 "DefaultValue"=2 "ValueName"=Hidden "Text"=@shell32.dll,-30500 "Type"=radio [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer] "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "AccessDeniedDialog"={100B4FC8-74C1-470F-B1B7-DD7B6BAE79BD} "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "GlobalAssocChangedCounter"=112 "SmartScreenEnabled"=RequireAdmin [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "TaskbarSizeMove"=0 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System] "EnableVirtualization"=1 "EnableInstallerDetection"=1 "PromptOnSecureDesktop"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "ConsentPromptBehaviorAdmin"=5 "ValidateAdminCodeSignatures"=0 "EnableUIADesktopToggle"=0 "EnableCursorSuppression"=1 "ConsentPromptBehaviorUser"=3 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "FilterAdministratorToken"=0 "SoftwareSASGeneration"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=0 "NoActiveDesktopChanges"=1 "NoActiveDesktop"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoComponents"=1 "NoAddingComponents"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 "{8E74D236-7F35-4720-B138-1FED0B85EA75}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=1 "Id"=2 "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "HKeyRoot"=2147483649 "DefaultValue"=2 "ValueName"=Hidden "Text"=@shell32.dll,-30500 "Type"=radio [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer] "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "IconUnderline"=2 "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "AccessDeniedDialog"={100B4FC8-74C1-470F-B1B7-DD7B6BAE79BD} "TaskScheduler"={0f87369f-a4e5-4cfc-bd3e-73e6154572dd} "GlobalAssocChangedCounter"=110 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "TaskbarSizeMove"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s ---------- | Winlogon [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin;SkyDrive;Work Folders "BuildNumber"=9600 "FirstLogon"=0 "ParseAutoexec"=1 [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"=C:\Windows\system32\userinit.exe, "LegalNoticeText"= "Shell"=explorer.exe "LegalNoticeCaption"= "DebugServerCommand"=no "ForceUnlockLogon"=0 "ReportBootOk"=1 "VMApplet"=SystemPropertiesPerformance.exe /pagefile "AutoRestartShell"=1 "PowerdownAfterShutdown"=0 "ShutdownWithoutLogon"=0 "Background"=0 0 0 "PasswordExpiryWarning"=5 "CachedLogonsCount"=10 "WinStationsDisabled"=0 "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "scremoveoption"=0 "ShutdownFlags"=2147484203 "EnableFirstLogonAnimation"=1 "AutoLogonSID"=S-1-5-32 "LastUsedUsername"= "DisableCad"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"=userinit.exe, "Shell"=explorer.exe "VMApplet"=SystemPropertiesPerformance.exe /pagefile "DefaultDomainName"= "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "DefaultUserName"= ---------- | Associations [HKLM\Software\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\Classes\.com] ""=comfile [HKLM\Software\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.reg] ""=regfile [HKLM\Software\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\Classes\.scr] ""=scrfile [HKLM\Software\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\Classes\.bat] ""=batfile [HKLM\Software\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.cmd] ""=cmdfile [HKLM\Software\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.pif] ""=piffile [HKLM\Software\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.inf] ""=inffile [HKLM\Software\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\Classes\.url] ""=InternetShortcut [HKLM\Software\Classes\.lnk] ""=lnkfile [HKLM\Software\Classes\.hta] ""=htafile "PerceivedType"=text "Content Type"=application/hta [HKLM\Software\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\Classes\InternetShortcut] "NeverShowExt"= "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "EditFlags"=2 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\Classes\Application.Manifest] ""=Application Manifest "EditFlags"=4259840 "BrowserFlags"=4096 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\Classes\Application.Reference] ""=Application Reference "NeverShowExt"= "EditFlags"=131072 "IsShortcut"= "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 [HKLM\Software\Classes\Folder] "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeLayoutPatternForBrowse"=delta ""=Folder "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "ThumbnailCutoff"=0 "NoRecentDocs"= "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKLM\Software\WOW6432Node\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\WOW6432Node\Classes\.com] ""=comfile [HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.reg] ""=regfile [HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\WOW6432Node\Classes\.scr] ""=scrfile [HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\WOW6432Node\Classes\.bat] ""=batfile [HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.cmd] ""=cmdfile [HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.pif] ""=piffile [HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.inf] ""=inffile [HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\WOW6432Node\Classes\.url] ""=InternetShortcut [HKLM\Software\WOW6432Node\Classes\.lnk] ""=lnkfile [HKLM\Software\WOW6432Node\Classes\.hta] ""=htafile "PerceivedType"=text "Content Type"=application/hta [HKLM\Software\WOW6432Node\Classes\htafile\Shell\Open\Command] ""=C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* [HKLM\Software\WOW6432Node\Classes\InternetShortcut] "NeverShowExt"= "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "EditFlags"=2 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "FriendlyTypeName"=@C:\WINDOWS\system32\ieframe.dll,-10046 "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\WOW6432Node\Classes\Application.Manifest] ""=Application Manifest "EditFlags"=4259840 "BrowserFlags"=4096 "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-200 [HKLM\Software\WOW6432Node\Classes\Application.Reference] ""=Application Reference "NeverShowExt"= "EditFlags"=131072 "IsShortcut"= "FriendlyTypeName"=@C:\Windows\System32\dfshim.dll,-201 [HKLM\Software\WOW6432Node\Classes\Folder] "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeLayoutPatternForBrowse"=delta ""=Folder "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay "ContentViewModeLayoutPatternForSearch"=alpha "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size;System.HomeGroupSharingStatus "ThumbnailCutoff"=0 "NoRecentDocs"= "TileInfo"=prop:System.Title;System.HomeGroupSharingStatus [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="D:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="D:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Clients\StartMenuInternet\Google Chrome.AS6LRBBV5MF4JS7RAFUSFK4UKA\Shell\open\Command] ""="D:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Clients\StartMenuInternet\Google Chrome.AS6LRBBV5MF4JS7RAFUSFK4UKA\InstallInfo] "ReinstallCommand"="D:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="D:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKLM\Software\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="D:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=C:\Program Files\Internet Explorer\iexplore.exe [10/12/2015 18:58:27] [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\Clients\StartMenuInternet\SafeZoneStable\Shell\open\Command] ""="D:\Program Files\AVAST Software\SZBrowser\Launcher.exe" [HKLM\Software\Clients\StartMenuInternet\SafeZoneStable\InstallInfo] "ReinstallCommand"="D:\Program Files\AVAST Software\SZBrowser\Launcher.exe" --makedefaultbrowser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\Shell\open\Command] ""="D:\Program Files (x86)\Mozilla Firefox\firefox.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\FIREFOX.EXE\InstallInfo] "ReinstallCommand"="D:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=C:\Program Files\Internet Explorer\iexplore.exe [10/12/2015 18:58:27] [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\SafeZoneStable\Shell\open\Command] ""="D:\Program Files\AVAST Software\SZBrowser\Launcher.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\SafeZoneStable\InstallInfo] "ReinstallCommand"="D:\Program Files\AVAST Software\SZBrowser\Launcher.exe" --makedefaultbrowser ---------- | AppcompatFlags [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted] "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe"=32 "C:\Users\Thomas\AppData\Local\Temp\HiSuiteDownLoader\Setup.exe"=1 "D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe"=32 [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "SIGN.MEDIA=1A98E12 Drivers\LAN\Atheros\(v2.1.0.21)\setup.exe"=0x5341435001000000000000000700000028000000C8CE050045A00600010000000000000000000006710200002EF6C8A3A56ACD010000000000000000 "C:\Program Files (x86)\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\setup.exe"=0x5341435001000000000000000700000028000000C8CE050045A00600030000000000000000000006710200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000001000000000000000000000000000000000F4600000000000000100000001000000 "SIGN.MEDIA=16DBB0CA CdAutoRun.exe"=0x534143500100000000000000070000002800000060D7000038A80100010000000000000000000006712000002EF6C8A3A56ACD01000000000000000002000000280000000000000080000000000000000000000000000000000000005FA80400000000000100000001000000 "C:\Users\Thomas\Downloads\347.09-desktop-win8-win7-winvista-64bit-international-whql.exe"=0x534143500100000000000000070000002800000038B35512DA935612010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000300C0300000000000100000001000000 "C:\Users\Thomas\Downloads\ChromeSetup.exe"=0x534143500100000000000000070000002800000090700D005D4B0E00010000000000000000000206002100002EF6C8A3A56ACD010000000100000000 "C:\Users\Thomas\AppData\Local\Temp\GUMC6F7.tmp\GoogleUpdateSetup.exe"=0x534143500100000000000000070000002800000090700D005D4B0E00010000000000000000000206002100002EF6C8A3A56ACD01000000800000000002000000280000000000000000000040000000000000000000000000000000004FC30200000000000100000001000000 "C:\Program Files (x86)\TmUnitedForever\TmForeverLauncher.exe"=0x534143500100000000000000070000002800000000502300B1212200010000000000000000000106712000002EF6C8A3A56ACD010000000000000000020000002800000000000000800000000000000000000000000000000000000012072E00000000000900000009000000 "C:\Users\Thomas\Downloads\chromeinstall-8u25.exe"=0x5341435001000000000000000700000028000000A8BF0900C5AE0A00010000000000000000000206712200002EF6C8A3A56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000002A820500000000000100000001000000 "C:\Users\Thomas\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe"=0x534143500100000000000000070000002800000098650200DA2B0300010000000000000000000206712200002EF6C8A3A56ACD010000000000000000 "C:\Users\Thomas\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr_x64.exe"=0x534143500100000000000000070000002800000098810200DFFD020001000000000000000000020673220000647CA60EA56ACD010000000000000000 "C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaw.exe"=0x5341435001000000000000000700000028000000A8B1020062520300010000000000000000000206002100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000009BCD0C00000000001600000016000000 "C:\Users\Thomas\Downloads\JAVA-7u51-64bits-ASCENTIA.exe"=0x5341435001000000000000000700000028000000A8EBD501D5CCD60101000000000000000000010600010000647CA60EA56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000E85D0000000000000100000001000000 "C:\Users\Thomas\Downloads\Minecraft.exe"=0x534143500100000000000000070000002800000008B51300C9611400010000000000000000000206712000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000100000000000000000000000000000A0E70200000000000100000001000000 "C:\Users\Thomas\Downloads\Launcher Ascentia 3.3.exe"=0x5341435001000000000000000700000028000000916F0400FBD50400010000000000000000000206712000002EF6C8A3A56ACD0100000000000000000200000028000000000000008000000000100000000000000000000000000000A8670100000000000100000001000000 "C:\Users\Thomas\Desktop\Ascentia.exe"=0x5341435001000000000000000700000028000000916F0400FBD5040001000000000000000000020671200000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000A00000000000000000000000001000000000000000000000000000003270600200000000800500000E0000000000020600000020000200000000000000000000000000006B1D00000000000001000000000000000000020600000060001000000000000000000000000000003DC87400000000000D0000000000000000000000000000400000000000000000000000000000000022199800000000003200000000000000 "C:\Users\Thomas\Documents\ManiaPlanet\ManiaPlanetLauncher.exe"=0x534143500100000000000000070000002800000000C0460000000000010000000000000000000206712200002EF6C8A3A56ACD010000000000000000020000002800000000000000800000000000000000000000000000000000000034090000000000000200000002000000 "C:\Users\Thomas\Documents\ManiaPlanet\ManiaPlanet.exe"=0x5341435001000000000000000700000028000000A85C4301B51F4401010000000000000000000206712200002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000001C030000000000000100000001000000 "C:\Users\Thomas\Downloads\daemon-tools-lite_v-4-49_fr_10729.exe"=0x5341435001000000000000000700000028000000202E0B00DE9D0491010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000507C0000000000000100000001000000 "C:\Users\Thomas\Downloads\DTLite4491-0356.exe"=0x534143500100000000000000070000002800000060BF0A009D169052010000000000000000000206002100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000004EB20100000000000100000001000000 "C:\Users\Thomas\Downloads\TeamSpeak3-Client-win64-3.0.16.exe"=0x534143500100000000000000070000002800000010FCC9010EE4CA01010000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000400000000000000000000000000000000031330400000000000100000001000000 "C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe"=0x5341435001000000000000000700000028000000C8A7A300CD1EA40001000000000000000000020673220000647CA60EA56ACD0100000000000000000200000028000000000000000000004004000000000000000000000000000000244B4A00000000000500000005000000 "D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe"=0x5341435001000000000000000700000028000000009401000000000001000000000000000000020600210000975FD891C99ECE0100000000000000000200000078000000000000000000009000000000000000000000000000000000E0700C0000000000020000000200000000000000000000D010000000000000000000000000000000B68F4000000000002700000000000000000000000000000000000000000000000000000000000000FADE3300000000000600000000000000 "C:\Users\Thomas\Desktop\cs go\csgo.exe"=0x53414350010000000000000007000000280000000094010000000000010000000000000000000206002100002EF6C8A3A56ACD01000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000000000000000000000000000000000000009A3600000000000002000000020000000000000000000040000000000000000000000000000000007E5A0000000000000100000000000000 "C:\Program Files (x86)\Faster Light\FasterLightUninstall.exe"=0x5341435001000000000000000700000028000000D0F50300040F0400030000000000000000000006710000002EF6C8A3A56ACD01000000000000000002000000280000000000000000080000000000000000000000000000000000001B560000000000000100000001000000 "D:\Program Files (x86)\TmUnitedForever\TmForeverLauncher.exe"=0x534143500100000000000000070000002800000000502300B121220001000000000000000000010671200000975FD891C99ECE0100000000000000000500000010000000000000000000000000000206A000000002000000A0000000000002068000002000000000000000000000000000000000FAD19000000000003B0000003B00000000000206A00000600000000000000000000000000000000069424800000000003700000000000000000000008000004000000000000000000000000000000000CB564F00000000001B000000000000000000000080000000000000000000000000000000000000004BEBF00000000000AB00000000000000 "C:\Users\Thomas\Documents\Spintires v1.0 (2014)(2-click run) sim\Spintires v1.0 (2014)(2-click run)(Registered).exe"=0x53414350010000000000000007000000280000006A5475149EB80100010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000CE240100000000000100000001000000 "D:\Program Files (x86)\SpinTires.exe"=0x534143500100000000000000070000002800000010F0840000000000010000000000000000000006710200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000099030000000000000100000001000000 "C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win64.exe"=0x5341435001000000000000000700000028000000C8A7A300CD1EA40001000000000000000000020673220000647CA60EA56ACD0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004004000000000000000000000000000000D7140000000000000100000001000000 "D:\Program Files (x86)\uninstall.exe"=0x53414350010000000000000007000000280000000084140000000000030000000000000000000206002100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000053300000000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\downloading\233450\Prison Architect.exe"=0x534143500100000000000000070000002800000010B6560027CC5000010000000000000000000206712200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000032020000000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\Garry's Mod\hl2.exe"=0x5341435001000000000000000700000028000000004A0100BD6A0100010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000EC1D0000000000000100000001000000 "C:\Users\Thomas\Downloads\dxwebsetup.exe"=0x5341435001000000000000000700000028000000587504004CBE040001000000000000000000010571000000975FD891C99ECE0100000080000000000200000028000000000000000008004000000000000000000000000000000000998E0400000000000200000002000000 "C:\Users\Thomas\Downloads\daemon-tools-lite_4-49-1_fr_10729.exe"=0x534143500100000000000000070000002800000000EBCC000DE7CD00010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000010C0200000000000100000001000000 "D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe"=0x534143500100000000000000070000002800000010693800E305390001000000000000000000020671220000975FD891C99ECE0100000000000000000200000050000000000000000000000000000000000000000000000000000000FC64120000000000A70000001A0000000000000000000040000000000000000000000000000000009C230F00000000001F00000000000000 "SIGN.MEDIA=A8537ABF Setup.exe"=0x53414350010000000000000007000000280000003FBB100000000000010000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000800000000000000000000000000000000000000062410100000000000100000001000000 "SIGN.MEDIA=4A8E390 SKIDROW\LIFELESSPLANET.EXE"=0x53414350010000000000000007000000280000000050940000000000010000000000000000000106710000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000A7080000000000000100000001000000 "D:\Program Files (x86)\KISS ltd\Lifeless Planet\LifelessPlanet.exe"=0x53414350010000000000000007000000280000000050940000000000010000000000000000000106710000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000CF830700000000000100000001000000 "SIGN.MEDIA=5F95238F Setup.exe"=0x5341435001000000000000000700000028000000F723955F00000000010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000C0AA0700000000000100000001000000 "D:\Program Files (x86)\Manhunter\MH.exe"=0x534143500100000000000000070000002800000000002300B32A230001000000000000000000010671000000975FD891C99ECE01000000000000000002000000500000000000000000000040000000000000000000000000000000000A0E0000000000000100000001000000000000000000000000000000000000000000000000000000E4C90800000000000100000000000000 "C:\Program Files (x86)\Wajam\uninstall.exe"=0x53414350010000000000000007000000280000002B110C0000000000030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000F6400000000000000100000001000000 "C:\Users\Thomas\Downloads\ManiaplanetMinimalSetup.exe"=0x5341435001000000000000000700000028000000A84B9A079FC89A07010000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000003BB52600000000000100000001000000 "D:\Program Files (x86)\ManiaPlanet\TM2Unlimiter.exe"=0x534143500100000000000000070000002800000000FA040049740500010000000000000000000206712200002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000200000000000000000000000000000E950500000000000100000001000000 "C:\Users\Thomas\Downloads\winrar_5-10_fr_9632_64.exe"=0x534143500100000000000000070000002800000098B51E006AA61F0001000000000000000000020600210000647CA60EA56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000FD500000000000000100000001000000 "C:\Users\Thomas\Downloads\Turbo.Dismount.Early.Access.Cracked-P2PGAMES\p2pgames-td.ea.cracked\TurboDismount\TurboDismount.exe"=0x5341435001000000000000000700000028000000002EAC0000000000010000000000000000000206712000002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000000AD50400000000000100000001000000 "SIGN.MEDIA=488A09CE Setup.exe"=0x5341435001000000000000000700000028000000D0942312B67A2412010000000000000000000106002100002EF6C8A3A56ACD0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000272D0500000000000200000002000000 "D:\Program Files (x86)\Demolition Company\DemolitionCompany.exe"=0x5341435001000000000000000700000028000000D0BA07003C490800010000000000000000000106712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000121D0000000000000400000004000000 "D:\Program Files (x86)\Demolition Company\game.exe"=0x5341435001000000000000000700000028000000D0FA26001F262700010000000000000000000106712200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000002020000000000000000000000000009060000000000000200000002000000 "SIGN.MEDIA=488A09CE cdstart.exe"=0x5341435001000000000000000700000028000000D05A040070580500010000000000000000000106712200002EF6C8A3A56ACD01000000000000000002000000280000000000000080000000000000000000000000000000000000007E220100000000000200000002000000 "SIGN.MEDIA=445E1E3 sdk\GIANTS_EDITOR_4.1.6_WIN32.EXE"=0x5341435001000000000000000700000028000000F88F8900D98D8A00010000000000000000000106002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000DE240000000000000100000001000000 "C:\Users\Thomas\Documents\Ship Simulator 2008\Shipsim2008.exe"=0x5341435001000000000000000700000028000000D1E5762800000000010000000000000000000006710200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000169B0000000000000100000001000000 "C:\Program Files (x86)\Vstep\ShipSim2008\ShipSim2008.exe"=0x53414350010000000000000007000000280000003DA4030000000000010000000000000000000006712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000008000000000000000000000000000000413A0000000000000100000001000000 "C:\Program Files (x86)\Vstep\ShipSim2008\uninstall.exe"=0x5341435001000000000000000700000028000000BEDF030000000000010000000000000000000006710200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000E5230000000000000100000001000000 "D:\Program Files (x86)\Demolition Company\unins000.exe"=0x5341435001000000000000000700000028000000D0021200D6331200010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000020000000000000000000000000000B72F0000000000000100000001000000 "SIGN.MEDIA=31A46B89 Setup.exe"=0x534143500100000000000000070000002800000048B72C0019042D00010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000ABB70C00000000000300000003000000 "SIGN.MEDIA=F150F Crack\keygen.exe"=0x53414350010000000000000007000000280000000F150F003D500F00010000000000000000000206712000002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000060CA0800000000000600000006000000 "D:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\Autorun\Exe\Autorun.exe"=0x534143500100000000000000070000002800000070D90000CBBF0100010000000000000000000106F1000000975FD891C99ECE0100000000000000000200000050000000000000008000000000000000000000000000000000000000741244000000000020000000100000000000000080000040000000000000000000000000000000009F180000000000000200000000000000 "D:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\PCM-Protection.exe"=0x5341435001000000000000000700000028000000301F0E00A9C00E00010000000000000000000206712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000870D0000000000000100000001000000 "SIGN.MEDIA=2B0F3FF0 Update\Setup-Patch-1.3.0.0-From-1.0.0.0.exe"=0x5341435001000000000000000700000028000000F03F0F2B6431102B010000000000000000000106000100002EF6C8A3A56ACD0100000080000000000200000028000000000000000000000000000000000000000000000000000000358A0100000000000200000002000000 "D:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\CrashReport.exe"=0x534143500100000000000000070000002800000000E8000000000000010000000000000000000206F5220000647CA60EA56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000B8ED0000000000000100000001000000 "D:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\unins000.exe"=0x534143500100000000000000070000002800000070FB150063FB160003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000100000000000000000000000000000BFC00000000000000200000002000000 "D:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\PCM.exe"=0x53414350010000000000000007000000280000007005A500FD64A500010000000000000000000206712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000C1040000000000000200000002000000 "D:\ManiaPlanet\ManiaPlanetLauncher.exe"=0x534143500100000000000000070000002800000000C0460000000000010000000000000000000206712200002EF6C8A3A56ACD0100000000000000000200000028000000000000008000000000000000000000000000000000000000DA6E5400000000000300000003000000 "C:\Users\Thomas\Downloads\SKILL_GameforgeLiveSetup.exe"=0x5341435001000000000000000700000028000000E4BE1600E4F93401010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000500C0000000000000100000001000000 "C:\Users\Thomas\Downloads\SKILL_GameforgeLiveSetup (1).exe"=0x534143500100000000000000070000002800000050A23401E4F93401010000000000000000000206002100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000092AB6F07000000000100000001000000 "D:\Program Files (x86)\GameforgeLive\gfl_client.exe"=0x5341435001000000000000000700000028000000804D2E0041EC2E00010000000000000000000206712200002EF6C8A3A56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000003A2F0000000000000100000001000000 "C:\Users\Thomas\Downloads\AdvancedMouseAutoClickerSetup.exe"=0x5341435001000000000000000700000028000000A85B080000000000010000000000000000000206002100002EF6C8A3A56ACD010000000000000000 "C:\Users\Thomas\Downloads\star_wars.exe"=0x5341435001000000000000000700000028000000F8C60C00DF6FE963010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000D65B0600000000000200000002000000 "C:\Program Files (x86)\Solution Real\SolutionRealUninstall.exe"=0x5341435001000000000000000700000028000000E0F1030022990400030000000000000000000006710000002EF6C8A3A56ACD010000000000000000020000002800000000000000000800000000000000000000000000000000000096280000000000000100000001000000 "C:\Program Files (x86)\PC Speed Maximizer\unins000.exe"=0x5341435001000000000000000700000028000000D9F50A0000000000030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000A3100000000000000100000001000000 "C:\Users\Thomas\AppData\Roaming\vi-view\UninstallManager.exe"=0x534143500100000000000000070000002800000000DE1C0000000000030000000000000000000206712200002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000007A5D0100000000000100000001000000 "C:\Program Files (x86)\GIANTS Software\GIANTS_Editor_4.1.6\unins000.exe"=0x5341435001000000000000000700000028000000D0C8110059941200030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000390D0000000000000100000001000000 "C:\Program Files (x86)\Advanced Mouse Auto Clicker\unins000.exe"=0x5341435001000000000000000700000028000000A1EA0A0000000000030000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000A40B0000000000000100000001000000 "SIGN.MEDIA=161236 Setup.exe"=0x5341435001000000000000000700000028000000A01216007B9E1400010000000000000000000206002100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000002FAD0200000000000100000001000000 "SIGN.MEDIA=1AEDF3E7 Files\Support\DirectX\DXSETUP.exe"=0x534143500100000000000000070000002800000058E7070074330800010000000000000000000106710200002EF6C8A3A56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000009CB70000000000000100000001000000 "SIGN.MEDIA=EACC1EA2 Setup.exe"=0x53414350010000000000000007000000280000002A3D150000000000010000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000006410A00000000000100000001000000 "SIGN.MEDIA=DB9000 SKIDROW\NFS13.exe"=0x53414350010000000000000007000000280000000090DB004FC6CE00010000000000000000000106710200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000CF1F0200000000000100000001000000 "D:\Program Files (x86)\EA Games\Need for Speed Most Wanted\NFS13.exe"=0x53414350010000000000000005000000100000000000000000000000000000000000000007000000280000000090DB004FC6CE0001000000000000000000010671020000975FD891C99ECE01000000000000000002000000780000000000020620000060000000000000000000000000000000002DEE13000000000004000000040000000000000000000040000000000000000000000000000000003C784200000000000300000000000000000000000000000000000000000000000000000000000000948F5600000000003600000000000000 "D:\Program Files (x86)\SimCity\SimCity\SimCity.exe"=0x53414350010000000000000007000000280000000080C600D3F9A70001000000000000000000020671220000975FD891C99ECE010000000000000000020000005000000000000000000000400000000000000000000000000000000096450300000000000100000001000000000000000000000000000000000000000000000000000000118B4000000000000D00000000000000 "C:\Users\Thomas\AppData\Local\Temp\jre-8u31-windows-au.exe"=0x5341435001000000000000000700000028000000A8C9090066AB0A00010000000000000000000206712200002EF6C8A3A56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000003E110100000000000100000001000000 "SIGN.MEDIA=6EB60D55 install.exe"=0x534143500100000000000000070000002800000000E0030000000000010000000000000000000105712000002EF6C8A3A56ACD01000000000000000002000000280000000000000000080040000000000000000000000000000000009E5A0300000000000100000001000000 "SIGN.MEDIA=47149D2A CDCheck.exe"=0x534143500100000000000000070000002800000000C00000DBA30100010000000000000000000105712000002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000000000000000000000200000002000000 "SIGN.MEDIA=3F09B71A CDCheck.exe"=0x534143500100000000000000070000002800000000C00000DBA30100010000000000000000000105712000002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000000000000000000000100000001000000 "D:\Program Files (x86)\Far Cry 4\Euro Truck Simulator 2 v1.14.0.4s (18 DLC)(2014)(2-click run).exe"=0x53414350010000000000000007000000280000007D0773489EB80100010000000000000000000206002100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000004CFE0900000000000200000002000000 "D:\Program Files (x86)\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe"=0x534143500100000000000000070000002800000000B01D010000000001000000000000000000020673220000B395E7CF049FCE01000000000000000002000000A000000000000000000400200000000000000000000000000000000096C56F0000000000090000000100000000000000000400600002020000000000000000000000000039E12E00000000000300000000000000000000000000000000000002000000000000000000000000926D3500000000000C0000000000000000000000000000400000000000000000000000000000000019542000000000000100000000000000 "C:\Users\Thomas\Desktop\IGG-The.Escapists.v0.86\TheEscapists.exe"=0x5341435001000000000000000700000028000000C6A8240000000000010000000000000000000206712200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000080020F00000000000100000001000000 "D:\Program Files (x86)\Goat Simulator\Binaries\Win32\GoatGame-Win32-Shipping.exe"=0x534143500100000000000000070000002800000000EC9702AAF19702010000000000000000000206F1220000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000001CDA9200000000000600000006000000 "C:\Program Files (x86)\Java\jre1.8.0_31\bin\javaw.exe"=0x5341435001000000000000000700000028000000A8B10200C7E70200010000000000000000000206002100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000004350000000000000500000005000000 "C:\Users\Thomas\AppData\Roaming\.minecraft\saves\Portal HoS - Automatique\Setup.exe"=0x5341435001000000000000000700000028000000F66F880100000000010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000D9420000000000000100000001000000 "D:\Program Files (x86)\Microsoft Games\Age of Empires III\age3.exe"=0x534143500100000000000000050000001000000000000000000000000000000010000000070000002800000038BBAA000ADAAA0001000000000000000000000671020000975FD891C99ECE0100000000000000000200000050000000000000001000001000000000000000000000000000000000F4A85500000000002300000002000000000000001000005000000000000000000000000000000000F2579700000000000700000000000000 "SIGN.MEDIA=28052 swgbg.exe"=0x53414350010000000000000007000000280000000080020000000000010000000000000000000105712000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000001000000000000000000000000000000000A7F70200000000000100000001000000 "D:\Program Files (x86)\Far Cry 4\StrandedDeep.exe"=0x53414350010000000000000007000000280000003C61520B5C7D0300010000000000000000000206612200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000400000000000000000000000000000000096C90000000000000100000001000000 "D:\Program Files (x86)\StrandedDeep\Stranded_Deep_x64.exe"=0x53414350010000000000000007000000280000000000E3000000000001000000000000000000020673200000647CA60EA56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000BA845100000000000600000006000000 "D:\Program Files (x86)\Far Cry 4\Star Wars - Force Commander Setup.exe"=0x53414350010000000000000007000000280000000020642A00000000010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000F32D0000000000000100000001000000 "SIGN.MEDIA=F31C99D7 setup.exe"=0x53414350010000000000000007000000280000000584470000000000010000000000000000000105712000002EF6C8A3A56ACD010000000000000000020000002800000000000000000800400000000000000000000000000000000076C90000000000000100000001000000 "C:\Users\Thomas\Downloads\Download Coldplay - A Sky Full of Stars.mp3 Torrent - KickassTorrents.exe"=0x5341435001000000000000000700000028000000787B1000F7771100010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000AD810000000000000100000001000000 "SIGN.MEDIA=28076 CloneCampaigns.exe"=0x5341435001000000000000000700000028000000008002000000000001000000000000000000010571200000975FD891C99ECE0100000000000000000200000050000000000000000000004020000040000000000000000000000000F552D200000000001100000011000000000000000000000000000000000000000000000000000000EC660500000000000100000000000000 "D:\Program Files (x86)\LucasArts\Star Wars Galactic Battlegrounds\Game\run.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "SIGN.MEDIA=21B5A71 Setup.exe"=0x5341435001000000000000000700000028000000B3F3070000000000010000000000000000000106412200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000F6400800000000000200000002000000 "D:\Program Files (x86)\Darkest of Days\darkestofdays.exe"=0x534143500100000000000000070000002800000000B0410000000000010000000000000000000006710000002EF6C8A3A56ACD0100000000000000000200000050000000000000000000000000000000000000000000000000000000E4170000000000000500000003000000000000000000004000000000000000000000000000000000E50D0000000000000100000000000000 "D:\Program Files (x86)\Darkest of Days\unins000.exe"=0x5341435001000000000000000700000028000000F0D50B000000000003000000000000000000020641220000975FD891C99ECE01000000000000000002000000280000000000000000000000000200000000000000000000000000001C140000000000000200000002000000 "C:\Program Files\Maxis\SimCity 2000\SIMCITY.EXE"=0x5341435001000000000000000700000028000000003E150000000000010000000000000000000105510000002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000000F050000000000000100000001000000 "D:\Program Files (x86)\Coop-Land\SpeedRunners\unins000.exe"=0x534143500100000000000000070000002800000000F90A0000000000010000000000000000000206002100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000048120000000000000100000001000000 "D:\Program Files (x86)\Far Cry 4\setup.exe"=0x5341435001000000000000000700000028000000BD4C130000000000010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000F6510200000000000100000001000000 "D:\Program Files (x86)\SpeedRunners\SpeedRunners.exe"=0x534143500100000000000000070000002800000000BE0C0000000000010000000000000000000206F12200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000085540300000000000100000001000000 "C:\Users\Thomas\Desktop\AutoClick by Armax2001.exe"=0x53414350010000000000000007000000280000000036070000000000010000000000000000000206F1200000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000024294700000000002600000026000000 "C:\Users\Thomas\Downloads\jre-8u31-windows-x64.exe"=0x5341435001000000000000000700000028000000A89591058CEE910501000000000000000000020673220000647CA60EA56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000AD330200000000000100000001000000 "C:\Users\Thomas\Downloads\download.exe"=0x534143500100000000000000070000002800000068150B00C3CCEF83010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000D2370000000000000100000001000000 "C:\Windows\unins000.exe"=0x5341435001000000000000000700000028000000C95B12000000000003000000000000000000020600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A60D0000000000000200000002000000 "C:\Program Files (x86)\SmileFilesUpdater\Uninstall.exe"=0x534143500100000000000000070000002800000058A3390048923900030000000000000000000206002100002EF6C8A3A56ACD01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000006D2C0000000000000200000002000000 "C:\Users\Thomas\AppData\Roaming\Nosibay\Bubble Dock\LBubble Dock.exe"=0x5341435001000000000000000700000028000000102B0A00CDC40A00010000000000000000000206712000002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000000DFE0300000000000100000001000000 "C:\Program Files (x86)\SmileFiles\Uninstall.exe"=0x534143500100000000000000070000002800000058A3390048923900030000000000000000000206002100002EF6C8A3A56ACD0100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000000000000000000000000000000000000000532B0000000000000200000001000000000000000000004000000000000000000000000000000000442B0000000000000100000000000000 "C:\Users\Thomas\AppData\Roaming\WTools\Selection Tools\Selection Tools.exe"=0x5341435001000000000000000700000028000000100B1700DB651700010000000000000000000206712000002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000014F80400000000000100000001000000 "C:\Users\Thomas\AppData\Roaming\Nosibay\Bubble Dock\Uninstall Bubble Dock.exe"=0x534143500100000000000000070000002800000058E80A005B8E0B00030000000000000000000006710000002EF6C8A3A56ACD01000000000000000002000000280000000000000000080000000000000000000000000000000000003D580100000000000100000001000000 "C:\Program Files (x86)\Common Files\ClaraUpdater\ClaraUpdater.exe"=0x534143500100000000000000070000002800000070020500FBFD0500030000000000000000000206712200002EF6C8A3A56ACD010000008000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000038280000000000000300000003000000 "C:\Users\Thomas\AppData\Roaming\WTools\Selection Tools\Selection Tools Uninstall.exe"=0x534143500100000000000000070000002800000088BD0900C3560A00030000000000000000000006710000002EF6C8A3A56ACD01000000000000000005000000100000000000000000000000000000000008000002000000280000000000000000080000000080000000000000008000000000009A5D0000000000000100000001000000010000000400000001000000 "C:\ProgramData\PicColor Utility\uninstall.exe"=0x534143500100000000000000070000002800000083C2000000000000030000000000000000000106000100002EF6C8A3A56ACD010000000000000000010000000400000001000000020000007800000000000106000000200002800000000000000080000000000023720000000000000400000004000000000001060000006000028000000000000000800000000000C60D000000000000010000000000000000000000000000000000800000000000000080000000000098190000000000000200000000000000 "C:\Users\Thomas\AppData\Roaming\Store\WindApp\WindApp Uninstall.exe"=0x5341435001000000000000000700000028000000B02F090047300900030000000000000000000006710000002EF6C8A3A56ACD0100000000000000000500000010000000000000000000000000000000000800000200000028000000000000000008000000008000000000000000800000000000D26F0000000000000100000001000000010000000400000001000000 "D:\Program Files (x86)\SpeedRunners\unins000.exe"=0x5341435001000000000000000700000028000000B7EC0B0000000000030000000000000000000206002100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000007A140000000000000100000001000000 "C:\Program Files (x86)\MyPC Backup\uninst.exe"=0x53414350010000000000000007000000280000004C460100D9630500030000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000066540900000000000200000002000000 "C:\Users\Thomas\AppData\Local\ConvertAd\Uninstall.exe"=0x5341435001000000000000000700000028000000052D010000000000030000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000022180000000000000100000001000000 "C:\Program Files (x86)\Optimizer Pro 3.38\unins000.exe"=0x534143500100000000000000070000002800000090F1110083321200030000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000E0410000000000000100000001000000 "C:\Users\Thomas\AppData\Local\wincheck\Uninstall.exe"=0x53414350010000000000000007000000280000003065010000000000030000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000001B190000000000000100000001000000 "C:\Program Files\Java\jre1.8.0_31\bin\javaw.exe"=0x5341435001000000000000000700000028000000A8EB02006CD3030001000000000000000000020600210000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000DB94E401000000002F0000002F000000 "C:\Users\Thomas\Downloads\SkypeSetup.exe"=0x534143500100000000000000070000002800000060A0170079701800010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000004000000000000000000000000000000000A5760200000000000100000001000000 "C:\Users\Thomas\Downloads\BlueStacks-SplitInstaller_native.exe"=0x534143500100000000000000070000002800000000D7CE00AEA3CF00010000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000000F421200000000000100000001000000 "C:\Program Files (x86)\BlueStacks\HD-StartLauncher.exe"=0x5341435001000000000000000700000028000000D81E0A00161A0B0001000000000000000000010680010000975FD891C99ECE0100000000000000000200000050000000000000008000004000000000000000000000000000000000EC960B0000000000010000000100000000000000800000000010000000000000000000000000000038C90F00000000000300000000000000 "C:\Users\Thomas\Downloads\minecraftdl_1619.exe"=0x5341435001000000000000000700000028000000C8F010005D181100010000000000000000000206002100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000005F810000000000000100000001000000 "C:\Program Files (x86)\CoUpExttension\CoUpExttension.exe"=0x534143500100000000000000070000002800000000F80B0001D20C00030000000000000000000206002100002EF6C8A3A56ACD0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000BB000000000000000100000001000000 "C:\Program Files (x86)\ReaunnDomPrice\L6e4AptUYzVNMH.exe"=0x534143500100000000000000070000002800000000F80B0001D20C00030000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000360B0000000000000100000001000000 "C:\ProgramData\Block The Ads\Block The Ads.exe"=0x534143500100000000000000070000002800000067D3050000000000030000000000000000000106710000002EF6C8A3A56ACD0100000000000000000500000010000000000000000000000000000000000800000200000028000000000000000008000000020000000000000000000000000000D3060000000000000300000003000000 "C:\Users\Thomas\Downloads\Launcher-IYC-5.1.exe"=0x5341435001000000000000000700000028000000FA87010038AB0100010000000000000000000206712000002EF6C8A3A56ACD010000000000000000020000002800000000000000800000000010000000000000000000000000000073410500000000000100000001000000 "C:\Users\Thomas\Downloads\super-macro_super_macro_31_01_2006_francais_10859.exe"=0x5341435001000000000000000700000028000000DC51150000000000010000000000000000000105710000002EF6C8A3A56ACD01000000000000000002000000280000000000000000080040000000000000000000000000000000006E0C0400000000000100000001000000 "C:\Program Files (x86)\HD-Quality-3.1V19.02\Uninstall.exe"=0x5341435001000000000000000700000028000000D0DB01002D990200010000000000000000000206002100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000003F110000000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\War Thunder\redist\dxwebsetup.exe"=0x5341435001000000000000000700000028000000587504004CBE0400010000000000000000000105710000002EF6C8A3A56ACD010000008000000000020000002800000000000000000800400000000000000000000000000000000036370000000000000100000001000000 "C:\Program Files (x86)\Search Extensions\uninstall.exe"=0x534143500100000000000000070000002800000000605B0000000000030000000000000000000206802100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000061240000000000000100000001000000 "C:\Program Files (x86)\ver8BlockAndSurf\Uninstall.exe"=0x5341435001000000000000000700000028000000768F040000000000030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000DC440000000000000100000001000000 "C:\Users\Thomas\Desktop\Besiege.exe"=0x534143500100000000000000070000002800000000EEAF0000000000010000000000000000000206712000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000A5120000000000000100000001000000 "C:\Users\Thomas\Desktop\Besiege_Alpha_Win_v0_02\Besiege.exe"=0x534143500100000000000000070000002800000000EEAF0000000000010000000000000000000206712000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000DCAD2600000000000200000002000000 "C:\Users\Thomas\Downloads\Geometry Dash Free Download PC Game.exe"=0x5341435001000000000000000700000028000000C87001000E900100010000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000003D310000000000000100000001000000 "C:\Users\Thomas\Downloads\liteloader-installer-1.7.10-04.exe"=0x5341435001000000000000000700000028000000B1C62C008BE30000010000000000000000000106000100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000010000000000000000000000000000051290000000000000100000001000000 "C:\Users\Thomas\Downloads\SuperMacro_install.exe"=0x534143500100000000000000070000002800000059904D000000000001000000000000000000000671000000975FD891C99ECE01000000000000000002000000280000000000000000080040000000000000000000000000000000001E7F0600000000000200000002000000 "C:\Program Files (x86)\Super macro\super_macro.exe"=0x53414350010000000000000007000000280000000090220000000000010000000000000000000106612000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000FE721300000000000600000006000000 "C:\Users\Thomas\Desktop\SkinConvertingSheep.exe"=0x5341435001000000000000000700000028000000009C000000000000010000000000000000000206F12200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000027480400000000000100000001000000 "D:\Program Files (x86)\Far Cry 4\gimp-2.8.14-setup-1.exe"=0x534143500100000000000000070000002800000050C47A05B5CF7A05010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000A8ED0000000000000100000001000000 "C:\Program Files\GIMP 2\bin\gimp-2.8.exe"=0x5341435001000000000000000700000028000000709A5200E90A530001000000000000000000020600210000B395E7CF049FCE0100000000000000000200000050000000000000000000005000000000000000000000000000000000F14722000000000004000000040000000000000000000000000000000000000000000000000000003F9C0D00000000000300000000000000 "C:\Users\Thomas\Desktop\MGS Shadow Moses Launcher v1.2.exe"=0x5341435001000000000000000700000028000000002C06000000000001000000000000000000010673000000647CA60EA56ACD0100000000000000000200000028000000000000000000000010100000000000000000000000000000C80F0000000000000100000001000000 "C:\Users\Thomas\Desktop\Minecraft MGS Shadow Moses Island v1.2 (thejamerson.com)\Minecraft MGS Shadow Moses Island v1.2\MGS Shadow Moses Island for Minecraft\MGS Shadow Moses Launcher v1.2.exe"=0x5341435001000000000000000700000028000000002C06000000000001000000000000000000010673000000647CA60EA56ACD0100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004010000000000000000000000000000000CA050000000000000100000001000000000000000000000010100000000000000000000000000000CD07000000000000020000000000000006000000080000001010000000000000 "C:\Users\Thomas\Desktop\Minecraft MGS Shadow Moses Island v1.2 (thejamerson.com)\Minecraft MGS Shadow Moses Island v1.2\MGS Shadow Moses Island for Minecraft\minecraft_server.exe"=0x5341435001000000000000000700000028000000E5979800738C0600010000000000000000000206712000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000100000000000000000000000000000EE350400000000000100000001000000 "C:\Users\Thomas\Desktop\Shiginima Launcher SE v1.406.exe"=0x5341435001000000000000000700000028000000B5F810005D760100010000000000000000000206712000002EF6C8A3A56ACD0100000000000000000500000010000000000000000000000000000000800000000200000050000000000000008000000000100000000000000000000000000000B6E60100000000000100000001000000000000008000004000000000000000000000000000000000EF8F0100000000000100000000000000 "C:\Users\Thomas\Desktop\Unturned Give Editor.exe"=0x534143500100000000000000070000002800000000A67F0000000000010000000000000000000206F5220000B395E7CF049FCE01000000000000000002000000500000000000000000000000000000000000000000000000000000005A081500000000000600000006000000000000000000004000000000000000000000000000000000870D0300000000000100000000000000 "SIGN.MEDIA=884646B setup.exe"=0x5341435001000000000000000700000028000000A781150000000000010000000000000000000206002100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000020750B00000000000100000001000000 "D:\Program Files (x86)\Need for Speed Most Wanted 2005\speed.exe"=0x534143500100000000000000070000002800000000005C000000000001000000000000000000010571000000975FD891C99ECE01000000000000000002000000500000000000000000000000000000000000000000000000000000008E6A53000000000059000000150000000000000000000040000000000000000000000000000000000C9C1800000000000800000000000000 "C:\Users\Thomas\Desktop\vac414\x64\vcctlpan.exe"=0x5341435001000000000000000700000028000000A00101001AF8010001000000000000000000020673200000647CA60EA56ACD010000000000000000020000002800000000000000000000000002020000000000000000000000000092040000000000000100000001000000 "C:\Users\Thomas\Desktop\vac414\setup64.exe"=0x5341435001000000000000000700000028000000A87901008A1D020001000000000000000000020673220000647CA60EA56ACD0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000200000000000000000000000000198C0000000000000200000002000000 "C:\Users\Thomas\Desktop\vac414\setup.exe"=0x5341435001000000000000000700000028000000A84B0100C37E0100010000000000000000000206712200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000400000000000000000000000000000000066540000000000000100000001000000 "C:\Program Files\Java\jre1.8.0_31\bin\javacpl.exe"=0x5341435001000000000000000700000028000000A82D0100B4E0010001000000000000000000010600010000B395E7CF049FCE01000000000000000002000000280000000000000000000000001000000000000000000000000000000A390200000000000600000006000000 "C:\Users\Thomas\Downloads\qbittorrent_3.1.12_setup.exe"=0x5341435001000000000000000700000028000000CEA3A30000000000010000000000000000000206002100002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000092570000000000000100000001000000 "D:\Program Files (x86)\qBittorrent\qbittorrent.exe"=0x534143500100000000000000070000002800000000EEF1000000000001000000000000000000020671200000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000068D50500000000000500000005000000 "C:\Users\Thomas\Downloads\Terramining_Launcher_v1.3.exe"=0x534143500100000000000000070000002800000021BF120095E30200010000000000000000000206612200002EF6C8A3A56ACD0100000000000000000200000028000000000000008000004000000000000000000000000000000000121D0300000000000100000001000000 "C:\Users\Thomas\AppData\Roaming\.minecraft\minecraft.exe"=0x5341435001000000000000000700000028000000C65F1000D69F0000010000000000000000000206712000002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000010000000000000000000000000000091A50000000000000100000001000000 "C:\Users\Thomas\Downloads\Lifecraft.exe"=0x5341435001000000000000000700000028000000A54E040024CE0000010000000000000000000206712000002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000010000000000000000000000000000001F60300000000000100000001000000 "C:\Users\Thomas\Desktop\Lifecraft.exe"=0x5341435001000000000000000700000028000000A54E040024CE000001000000000000000000020671200000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000078000000000002060000002000100000000000000000000000000000E41C0C00000000000F000000080000000000000000000000001000000000000000000000000000000E198700000000001B00000000000000000000000000004000000000000000000000000000000000BA870100000000000300000000000000 "C:\Users\Thomas\Downloads\_MagicLauncher_1.2.5.exe"=0x53414350010000000000000007000000280000004FE5050039350100010000000000000000000206712000002EF6C8A3A56ACD010000000000000000020000002800000000000000800000000010000000000000000000000000000009060400000000000100000001000000 "C:\Users\Thomas\Downloads\HyperCraft.exe"=0x53414350010000000000000007000000280000009B35030099630200010000000000000000000206712000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000100000000000000000000000000000AAD20900000000000300000003000000 "C:\Users\Thomas\Downloads\Scrolls-Installer.msi"=0x534143500100000000000000070000002800000000F6000039910100010000000000000000000105001000002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000001D360000000000000100000001000000 "D:\Program Files (x86)\Scrolls\ScrollsLauncher.exe"=0x534143500100000000000000070000002800000008BF13008C63140001000000000000000000020671200000975FD891C99ECE0100000000000000000200000028000000000000008000000000000000000000000000000000000000F0140000000000000300000003000000 "D:\Program Files (x86)\Steam\steamapps\common\TheForest\TheForest.exe"=0x5341435001000000000000000700000028000000003EAC0000000000010000000000000000000206712000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000BC2AC000000000000B0000000B000000 "C:\Users\Thomas\Downloads\Lifecraft (1).exe"=0x5341435001000000000000000700000028000000A54E040024CE0000010000000000000000000206712000002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000001000000000000000000000000000003CED0500000000000100000001000000 "C:\Users\Thomas\Desktop\MagicLauncher_1.2.5.exe"=0x53414350010000000000000007000000280000004FE5050039350100010000000000000000000206712000002EF6C8A3A56ACD0100000000000000000200000028000000000000008000000000100000000000000000000000000000EAC30100000000000100000001000000 "C:\ProgramData\AdBlocker Manger\AdBlocker Manger.exe"=0x534143500100000000000000070000002800000067D305000000000003000000000000000000010671000000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000800000200000028000000000000000008000000020000000000000000000000000000D6080000000000000500000005000000 "D:\Program Files (x86)\StrandedDeep\Uninstall.exe"=0x53414350010000000000000007000000280000003AC801007AD70100030000000000000000000206612200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000911A0000000000000100000001000000 "C:\Users\Thomas\AppData\Local\gmsd_fr_349\upgmsd_fr_349.exe"=0x5341435001000000000000000700000028000000A87E3200377C3300010000000000000000000206712200002EF6C8A3A56ACD010000000000000000020000002800000000000000000000000000000000000000000000000000000057010000000000001100000011000000 "C:\Users\Thomas\AppData\Local\Temp\mtmp49021005\QQBrowser.exe"=0x53414350010000000000000007000000280000003802020000E10200010000000000000000000206712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000B41C0D00000000000200000002000000 "C:\Program Files (x86)\IGS\uninstall.exe"=0x534143500100000000000000070000002800000063F0000000000000030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000008000000000000000800000000000A5170000000000000200000002000000010000000400000001000000 "C:\Users\Thomas\AppData\Roaming\mystartsearch\UninstallManager.exe"=0x5341435001000000000000000700000028000000002C1D0000000000030000000000000000000206712200002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000009C110100000000000100000001000000 "C:\Users\Thomas\AppData\Local\03000200-1427536388-0500-0006-000700080009\Uninstall.exe"=0x534143500100000000000000070000002800000003E1000000000000030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000751C0000000000000100000001000000 "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\39.4.2171.95\Installer\setup.exe"=0x534143500100000000000000070000002800000000F00D0000000000030000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000B2520000000000000100000001000000 "C:\Program Files (x86)\QuickRef_1.10.0.9\Uninstall.exe"=0x534143500100000000000000070000002800000070D30400AD6F0500030000000000000000000106000100002EF6C8A3A56ACD0100000000000000000100000004000000010000000200000028000000000000000000000000008000000000000000800000000000F76E0000000000000300000003000000 "C:\Users\Thomas\AppData\Local\03000200-1427536213-0500-0006-000700080009\Uninstall.exe"=0x5341435001000000000000000700000028000000C534010000000000030000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000004A400000000000000100000001000000 "C:\Program Files (x86)\gmsd_fr_349\unins000.exe"=0x534143500100000000000000070000002800000008D60A00DF6F0B00030000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000DAB20000000000000200000002000000 "C:\Users\Thomas\AppData\Local\SmartWeb\__u.exe"=0x534143500100000000000000070000002800000081A2020091140C0003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B9360000000000000500000005000000 "C:\Users\Thomas\AppData\Local\03000200-1427538376-0500-0006-000700080009\Uninstall.exe"=0x53414350010000000000000007000000280000008991010000000000030000000000000000000106000100002EF6C8A3A56ACD010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000800000000000000080000000000028170000000000000100000001000000010000000400000001000000 "C:\Users\Thomas\AppData\Local\03000200-1427536367-0500-0006-000700080009\Uninstall.exe"=0x5341435001000000000000000700000028000000B14B010000000000030000000000000000000106000100002EF6C8A3A56ACD01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000080000000000000008000000000003C360000000000000100000001000000010000000400000001000000 "C:\Program Files (x86)\RCP\RCPUninstall.exe"=0x5341435001000000000000000700000028000000184B0800020A0900010000000000000000000206002100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000040000000000000000000000000000000000F000000000000000200000002000000 "C:\Program Files (x86)\XTab\uninstall.exe"=0x5341435001000000000000000700000028000000E5E8010016EF2700010000000000000000000106000100002EF6C8A3A56ACD010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000036960000000000000100000001000000 "C:\Program Files (x86)\Steel Cut\SteelCutUninstall.exe"=0x534143500100000000000000070000002800000050F60300E10D0400010000000000000000000006710000002EF6C8A3A56ACD01000000000000000002000000280000000000000000080040000000000000000000000000000000008E330000000000000100000001000000 "C:\Program Files (x86)\GoHDV28.03\Uninstall.exe"=0x534143500100000000000000070000002800000000CC010000000000010000000000000000000206002100002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000B5120000000000000200000002000000 "C:\Program Files (x86)\AnyProtectEx\Uninstall.exe"=0x5341435001000000000000000700000028000000906B010000000000010000000000000000000106000100002EF6C8A3A56ACD0100000000000000000200000050000000000000000000000000000000000000000000000000000000121D00000000000001000000010000000000000000000040000000000000000000000000000000007A250000000000000100000000000000 "C:\Users\Thomas\Downloads\mcedit2-2.0.0-alpha1-win-amd64.exe"=0x53414350010000000000000007000000280000001F44330200000000010000000000000000000106710000002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000590D0000000000000100000001000000 "C:\Users\Thomas\Downloads\mcedit2-2.0.0-alpha1-win-amd64\mcedit2.exe"=0x534143500100000000000000070000002800000051C730020000000001000000000000000000020673200000647CA60EA56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000E3106200000000000300000003000000 "C:\ProgramData\HealthAlert\Uninstall.exe"=0x5341435001000000000000000700000028000000F03108005A8B0800030000000000000000000206712200002EF6C8A3A56ACD0100000000000000000200000028000000000000000000000000000000000000000000000000000000473E0000000000000100000001000000 "C:\Users\Thomas\AppData\Local\03000200-1427577762-0500-0006-000700080009\Uninstall.exe"=0x53414350010000000000000007000000280000005495010000000000030000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000002B140000000000000100000001000000 "C:\Users\Thomas\AppData\Local\03000200-1427583030-0500-0006-000700080009\Uninstall.exe"=0x53414350010000000000000007000000280000005495010000000000030000000000000000000106000100002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000004C250000000000000100000001000000 "C:\Program Files\shopperz\unins000.exe"=0x5341435001000000000000000700000028000000C94A12000000000003000000000000000000020600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000CC440000000000000200000002000000 "C:\Users\Thomas\AppData\Local\gmsd_fr_373\upgmsd_fr_373.exe"=0x5341435001000000000000000700000028000000907E3200AF303300010000000000000000000206712200002EF6C8A3A56ACD01000000000000000002000000280000000000000000000000000000000000000000000000000000004E000000000000000800000008000000 "D:\Program Files (x86)\DAEMON Tools Lite\DTHelper.exe"=0x534143500100000000000000070000002800000010250500544E050001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000B1140000000000000100000001000000 "C:\Program Files (x86)\Infonaut_1.10.0.13\Uninstall.exe"=0x534143500100000000000000070000002800000018DA0400DF2D050003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000CA510000000000000100000001000000 "C:\Program Files (x86)\gmsd_fr_373\unins000.exe"=0x53414350010000000000000007000000280000002DF40A000000000003000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000040330100000000000100000001000000 "C:\Program Files (x86)\ClearNiceBrOwse\ItxSNJ8hP0CrSM.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000272B0000000000000100000001000000 "C:\Program Files (x86)\EnoormoouSSaleesi\IVHsbXhgfIylXI.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000BF240000000000000100000001000000 "C:\Program Files (x86)\DiscountSmasher\DiscountSmasher.exe"=0x534143500100000000000000070000002800000067D305000000000003000000000000000000010671000000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000800000200000028000000000000000008000000020000000000000000000000000000BA1D0000000000000300000003000000 "C:\Users\Thomas\Downloads\uTorrent.exe"=0x5341435001000000000000000700000028000000509C1A0023351B0001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000000000010000000000000000000000000000000007E251402000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\GarrysMod\bin\hammer.exe"=0x534143500100000000000000070000002800000000180200D08B020001000000000000000000020600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000C6051500000000000200000002000000 "D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Source\bin\hammer.exe"=0x5341435001000000000000000700000028000000006602000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A2F90000000000000800000008000000 "D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Source\bin\Hammer.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "C:\Users\Thomas\Downloads\archimedes-ships-1-7-10 (1).exe"=0x5341435001000000000000000700000028000000009604004509050001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002AB20000000000000100000001000000 "C:\Program Files (x86)\Bundle This\Bundle This.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000601F0000000000000100000001000000 "C:\Program Files (x86)\CoupExtEnsIon\CoupExtEnsIon.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000005F1F0000000000000100000001000000 "C:\Program Files (x86)\FiNaeDEaLSoft\xxjySknGXAny0o.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000613E0000000000000100000001000000 "C:\Program Files (x86)\tPerfecttcoupon\tPerfecttcoupon.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B1210000000000000100000001000000 "C:\Program Files (x86)\WebProtector\webprotector_uninstaller.exe"=0x5341435001000000000000000700000028000000D80201000000000003000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000000008000000000000000000000000000000000000B80B0000000000000100000001000000 "C:\Program Files (x86)\SaverExtenosion\rNDrB9UHDbJcQG.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000008B370000000000000100000001000000 "C:\Program Files (x86)\saverabox\G0t2AJc5KL4jz9.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D9370000000000000100000001000000 "C:\Program Files (x86)\Recycle Bin\Recycle Bin.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000088200000000000000100000001000000 "SIGN.MEDIA=10844504 setup.exe"=0x534143500100000000000000070000002800000088C2050064EF050001000000000000000000000671020000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000006D890800000000000100000001000000 "D:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\delegate_execute.exe"=0x534143500100000000000000070000002800000048651F00C7E81F0001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000011510001000000000100000001000000 "D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe"=0x5341435001000000000000000700000028000000A00300017464000101000000000000000000010671200000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000000000000000000000000000000000000001D100000000000000300000002000000000000000000004000000000000000000000000000000000771B0000000000000100000000000000 "C:\Users\Thomas\Desktop\Minecraft MGS Shadow Moses Island v1.2\MGS Shadow Moses Island for Minecraft\MGS Shadow Moses Launcher v1.2.exe"=0x5341435001000000000000000700000028000000002C06000000000001000000000000000000010673000000B395E7CF049FCE01000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000040100000000000000000000000000000001B0600000000000001000000010000000000000000000000101000000000000000000000000000000507000000000000020000000000000006000000080000001010000000000000 "C:\Users\Thomas\Desktop\Minecraft MGS Shadow Moses Island v1.2\MGS Shadow Moses Island for Minecraft\minecraft_server.exe"=0x5341435001000000000000000700000028000000E5979800738C060001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B7130000000000000100000001000000 "C:\Users\Thomas\AppData\Roaming\03000200-1427532258-0500-0006-000700080009\Uninstall.exe"=0x5341435001000000000000000700000028000000483D01000000000001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000018090000000000000100000001000000 "C:\Program Files\paint.net\PaintDotNet.exe"=0x534143500100000000000000070000002800000048F21A00A9031B0001000000000000000000030680210000B395E7CF049FCE0100000000000000000200000050000000000000000000000000000000000000000000000000000000E66D3600000000007C0000006E000000000000000000004000000000000000000000000000000000728C3B00000000002900000000000000 "C:\Users\Thomas\Downloads\Just.Cause.2.Multi6-RU.Repack\setup.exe"=0x5341435001000000000000000700000028000000C5629F000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B3A60600000000000100000001000000 "D:\Program Files (x86)\Just Cause 2\JustCause2.exe"=0x534143500100000000000000070000002800000020EDDD002892DE0001000000000000000000010671220000975FD891C99ECE01000000000000000002000000C800000000020006200400601010000200000000000000000000000091FD68000000000024000000240000000000020620040060101000020000000000000000000000006085C201000000007A0000000000000000000206200000601010000200000000000000000000000012C1090000000000020000000000000000000206000000600000000000000000000000000000000047860D0000000000010000000000000000000000000000000000000000000000000000000000000010D63400000000001400000000000000 "C:\Users\Thomas\Downloads\CheatEngine64.exe"=0x534143500100000000000000070000002800000010328A005C0C8B0001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000108B0200000000000200000002000000 "D:\Program Files (x86)\Cheat Engine 6.4\Cheat Engine.exe"=0x534143500100000000000000070000002800000018090500DD7B050001000000000000000000030661220000975FD891C99ECE01000000000000000002000000280000000000000000000040020000000000000000000000000000005B410400000000000300000003000000 "SIGN.MEDIA=1C50D12 autorun.exe"=0x534143500100000000000000070000002800000010450500A95A050001000000000000000000000671020000975FD891C99ECE010000000000000000 "SIGN.MEDIA=3776E8E crack\JUSTCAUSE2.EXE"=0x534143500100000000000000070000002800000020E1DD009650DE0001000000000000000000010671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000290E0000000000000200000002000000 "SIGN.MEDIA=1C50D12 steambackup.EXE"=0x5341435001000000000000000700000028000000000604000000000001000000000000000000010641200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000009DE60200000000000600000006000000 "SIGN.MEDIA=1C50D12 STEAMSERVICE.EXE"=0x5341435001000000000000000700000028000000F8D40400A901050001000000000000000000000671020000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000002F000000000000000100000001000000 "D:\Program Files (x86)\Nouveau dossier\Just Cause 2\JustCause2.exe"=0x534143500100000000000000070000002800000020E1DD009650DE0001000000000000000000010671220000975FD891C99ECE010000000000000000020000002800000000000000000000000000020000000000000000000000000020CB0000000000000100000001000000 "C:\Users\Thomas\Downloads\pfsx-setup-fr-10.9.2.exe"=0x5341435001000000000000000700000028000000F6B2A9000000000001000000000000000000000671000000975FD891C99ECE010000000000000000020000002800000000000000000800400000000000000000000000000000000040AC0600000000000100000001000000 "D:\Program Files (x86)\Far Cry 4\scc_\Tom Clancy's Splinter Cell Conviction PC game + DLC ^^nosTEAM^^\Tom Clancy's Splinter Cell Conviction nosTEAM.part1.exe"=0x5341435001000000000000000700000028000000000050FF0000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000008000000000000000000000000000000000000000C8350600000000000100000001000000 "D:\Program Files (x86)\Splinter Cell Conviction\Tom Clancy's Splinter Cell Conviction\play-TCSCC.exe"=0x5341435001000000000000000700000028000000442007000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000206A0000000020000007800000000000206A000006000000000000000000000000000000000BD561A000000000006000000060000000000020680000020000000000000000000000000000000000F1C01000000000002000000000000000000000080000000000000000000000000000000000000008C985B00000000000300000000000000 "D:\Program Files (x86)\Splinter Cell Conviction\Tom Clancy's Splinter Cell Conviction\src\system\Conviction_game.exe"=0x5341435001000000000000000700000028000000A00300017464000101000000000000000000010671200000975FD891C99ECE010000000000000000020000007800000000000106000000200000000000000000000000000000000085835300000000002300000023000000000001060000006000000000000000000000000000000000C8236F00000000000C000000000000000000020600000020000000000000000000000000000000009C000000000000000100000000000000 "C:\Users\Thomas\Downloads\splinter_cell_conviction_1.04.exe"=0x534143500100000000000000070000002800000030FB77019725780101000000000000000000000671020000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000009FAE0000000000000100000001000000 "D:\Program Files (x86)\Splinter Cell Conviction\update-Conviction.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "SIGN.MEDIA=3F3F2CE2 Setup.exe"=0x5341435001000000000000000700000028000000BF2312000000000001000000000000000000010600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000050210400000000000100000001000000 "D:\Program Files (x86)\Rebellion\SniperEliteV2\bin\SniperEliteV2.exe"=0x534143500100000000000000070000002800000000046600EC54660001000000000000000000010671220000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000024253300000000000900000009000000 "C:\Users\Thomas\Downloads\forge-1.8-11.14.1.1334-installer-win.exe"=0x53414350010000000000000007000000280000008E5234002545010001000000000000000000030671200000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000008000002000000280000000000000000080040000020000000000000002000000000006D270000000000000100000001000000010000000400000001000000 "C:\Users\Thomas\Desktop\minecraft_server.1.8.4.exe"=0x5341435001000000000000000700000028000000923C9B00F239060001000000000000000000030671200000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004000000000000000000000000000000000480E00000000000001000000010000000000000000000000000000000000000000000000000000007E120000000000000200000000000000 "C:\Program Files (x86)\DiGiCeOupon\PUT1SDwBy4tHby.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002C250000000000000100000001000000 "C:\Program Files (x86)\DiscuoUntExtenSi\0UWC8M1BQ3KkLR.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000E3230000000000000100000001000000 "C:\Program Files (x86)\Plurk Smile\Plurk Smile.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000FB1A0000000000000100000001000000 "C:\Program Files (x86)\InstallShield Installation Information\{6D8DDB4A-C263-40DE-BA16-AFDAD159D59A}\setup.exe"=0x534143500100000000000000070000002800000088C2050064EF050003000000000000000000000671020000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000C99A0000000000000100000001000000 "C:\Users\Thomas\Downloads\flstudio_11.0.4.exe"=0x5341435001000000000000000700000028000000F09EC3120B22C41201000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000667E0700000000000100000001000000 "D:\Program Files (x86)\Image-Line\FL Studio 11\FL.exe"=0x5341435001000000000000000700000028000000903E05005187050001000000000000000000020671000000975FD891C99ECE01000000000000000002000000500000000000000000000040100000000000000000000000000000007A4E08010000000001000000010000000000000000000000000000000000000000000000000000004A4C0700000000000700000000000000 "C:\Users\Thomas\Downloads\GeForce_Experience_v2.4.5.28.exe"=0x5341435001000000000000000700000028000000883C3102EED7310201000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000018660100000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"=0x534143500100000000000000070000002800000090082A00F49D2A0001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000070F11201000000000100000001000000 "C:\Users\Thomas\Downloads\PlaylistCreator3_Setup.exe"=0x5341435001000000000000000700000028000000409818000000000001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000098100700000000000100000001000000 "D:\Program Files (x86)\Playlist Creator 3.6.2\pc3.exe"=0x5341435001000000000000000700000028000000007A1700BF18180001000000000000000000010671220000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000001F000000000000000100000001000000 "C:\Users\Thomas\Desktop\virtual-audio-cable_4-14_fr_69178\setup64.exe"=0x5341435001000000000000000700000028000000A87901008A1D020001000000000000000000020673220000B395E7CF049FCE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000200000000000000000000000000EE2C0300000000000800000008000000 "C:\Program Files\Virtual Audio Cable\setup64.exe"=0x5341435001000000000000000700000028000000A87901008A1D020003000000000000000000020673020000B395E7CF049FCE010000000000000000020000002800000000000000000000000000000000000000000000000000000075110000000000000100000001000000 "C:\ProgramData\VideoDimmer\Uninstall.exe"=0x5341435001000000000000000700000028000000F0310800796C080003000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000BB490000000000000100000001000000 "C:\Users\Thomas\Desktop\virtual-audio-cable_4-14_fr_69178\setup.exe"=0x5341435001000000000000000700000028000000A84B0100C37E010001000000000000000000020671220000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000002000000000000000000000000003C250000000000000100000001000000 "C:\Program Files (x86)\Image-Line\Shared\Uninstall.exe"=0x534143500100000000000000070000002800000036A70500D967970003000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002A130000000000000100000001000000 "C:\Users\Thomas\Downloads\ccleaner_5-06-5219_fr_14492.exe"=0x5341435001000000000000000700000028000000C0EE6300013B640001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000D4844100000000000100000001000000 "D:\Program Files (x86)\virtual-audio-cable_4-14_fr_69178\setup64.exe"=0x5341435001000000000000000700000028000000A87901008A1D020001000000000000000000020673220000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000200000000000000000000000000DC4E0000000000000400000004000000 "D:\Program Files (x86)\virtual-audio-cable_4-14_fr_69178\x86\vcctlpan.exe"=0x5341435001000000000000000700000028000000A0E100005D81010001000000000000000000030671200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002C030000000000000100000001000000 "D:\Program Files (x86)\virtual-audio-cable_4-14_fr_69178\x86\audiorepeater_ks.exe"=0x5341435001000000000000000700000028000000B0C90000B0A1010001000000000000000000020671200000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000DC050000000000000100000001000000 "D:\Program Files (x86)\virtual-audio-cable_4-14_fr_69178\x86\audiorepeater.exe"=0x5341435001000000000000000700000028000000B08B0000CC86010001000000000000000000020671200000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A12E0000000000000100000001000000 "C:\Program Files\CCleaner\CCleaner64.exe"=0x534143500100000000000000070000002800000018FD7E00BA1C7F0001000000000000000000030600210000B395E7CF049FCE010000000000000000020000005000000000000000000000000000000000000000000000000000000051E17A04000000002B000000260000000000000000000040000000000000000000000000000000007C696D02000000000900000000000000 "C:\Users\Thomas\Downloads\revouninstaller_1-95_fr_39528.exe"=0x5341435001000000000000000700000028000000A8082800A0C6280001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000A87E2700000000000100000001000000 "C:\Users\Thomas\Downloads\CG_5.0.15.14.exe"=0x534143500100000000000000070000002800000040A69400909C950001000000000000000000030600210000975FD891C99ECE0100000000000000000200000050000000000000000000004000000000000000000000000000000000BC41000000000000010000000100000000000000000000000000000000000000000000000000000003E01300000000000100000000000000 "C:\Program Files\CyberGhost 5\CyberGhost.exe"=0x5341435001000000000000000700000028000000E08F0600F13D0700010000000000000000000306F1220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000C3562600000000000D0000000D000000 "C:\Users\Thomas\Downloads\Andy_Android_Emulator_v44_8.exe"=0x534143500100000000000000070000002800000000641300AE14140001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000800000000000000000000000000000000000000036522100000000000100000001000000 "C:\Program Files\Andy\HandyAndy.exe"=0x5341435001000000000000000700000028000000103A0E008B820E0001000000000000000000030600210000975FD891C99ECE01000000000000000002000000500000000000000000000040000000000000000000000000000000009BFD4C01000000000100000001000000000000000000000000000000000000000000000000000000533B0000000000000100000000000000 "C:\Program Files\CyberGhost 5\unins000.exe"=0x5341435001000000000000000700000028000000E0711200015F130001000000000000000000030600210000975FD891C99ECE010000000000000000020000005000000000000000000000400000000000000000000000000000000061DC0100000000000100000001000000000000000000000000000000000000000000000000000000983A0000000000000200000000000000 "C:\Users\Thomas\AppData\Local\Temp\RarSFX0\Binaries\FirefoxInstaller.exe"=0x5341435001000000000000000700000028000000A8BA0C0033010D0001000000000000000000010600010000975FD891C99ECE01000000000000000005000000100000000000000000000000000000008000000002000000280000000000000080000000000000000000000000000000000000003E000000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Temp\RarSFX0\Binaries\ChromeInstaller.exe"=0x5341435001000000000000000700000028000000A8281000BE96100001000000000000000000010600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000800000000200000028000000000000008000000000000000000000000000000000000000652B0000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Temp\RarSFX1\Binaries\IExploreInstaller.exe"=0x5341435001000000000000000700000028000000B01A1A00F6BA1A0001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000800000000000000000000000000000000000000081020000000000000100000001000000 "C:\Users\Thomas\Downloads\AdobeDownloadAssistant-CC.exe"=0x5341435001000000000000000700000028000000387F2700C9AC270001000000000000000000020671020000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000464D0300000000000100000001000000 "D:\Program Files (x86)\Photoshop\Adobe Download Assistant\Adobe Download Assistant.exe"=0x5341435001000000000000000700000028000000002C0200C719010001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002A350000000000000200000002000000 "C:\Users\Thomas\Desktop\Castle Story v0.1.0.6f02_ENG.exe"=0x53414350010000000000000007000000280000007E7E58085C7D030001000000000000000000030661220000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000001E850000000000000100000001000000 "C:\Games\Castle Story v0.1.0.6f02\Castle Story Prototype.exe"=0x53414350010000000000000007000000280000000070A0000000000001000000000000000000020671000000975FD891C99ECE0100000000000000000200000050000000000000000000004000000000000000000000000000000000B76900000000000001000000010000000000000000000000000000000000000000000000000000001D6C2000000000000600000000000000 "C:\Users\Thomas\Downloads\Pipix_Setup.exe"=0x5341435001000000000000000700000028000000E54AD5000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000AF330400000000000100000001000000 "SIGN.MEDIA=B8D93B60 setup.exe"=0x5341435001000000000000000700000028000000E98509000000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000003D9D0600000000000100000001000000 "D:\Program Files (x86)\Project CARS\pCARS64.exe"=0x534143500100000000000000070000002800000050A2900122908A0101000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000AC800600000000000100000001000000 "C:\Program Files (x86)\Browser QuickLinks\Browser QuickLinks.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002D1D0000000000000100000001000000 "C:\Program Files (x86)\CircleCountcom\CircleCountcom.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A91D0000000000000100000001000000 "C:\Program Files (x86)\DDiiggiSaveeR\fwKuac5rg0XAMt.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000009A1D0000000000000100000001000000 "C:\ProgramData\FinanceAlert\uninstall.exe"=0x534143500100000000000000070000002800000000FD0900FE320A0003000000000000000000030680210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000E6200000000000000100000001000000 "C:\Program Files (x86)\Fun2SaVuee\Fun2SaVuee.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000811C0000000000000100000001000000 "C:\Program Files (x86)\Iminent\inst\Bootstrapper\IminentUninstall.exe"=0x5341435001000000000000000700000028000000984A13009129140003000000000000000000030600210000975FD891C99ECE010000000000000000 "C:\Program Files (x86)\Pricescout for Chrome\Pricescout for Chrome.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000B01C0000000000000100000001000000 "C:\Program Files (x86)\SipAceCouPonApp\oElxzzBi278ONa.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000DE1C0000000000000100000001000000 "C:\Program Files (x86)\RRandoomPrice\hSmwChxYquMmfY.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000002C1D0000000000000100000001000000 "C:\Program Files\TAP-Windows\Uninstall.exe"=0x53414350010000000000000007000000280000006F470100E702040003000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000008E390000000000000300000003000000 "C:\Program Files (x86)\Unblock The Pirate Bay tpb\Unblock The Pirate Bay tpb.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000003C1D0000000000000100000001000000 "C:\Program Files (x86)\WPSNIFFER\WPSNIFFER.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000901C0000000000000100000001000000 "C:\Program Files (x86)\WordShark_1.10.0.17\Uninstall.exe"=0x534143500100000000000000070000002800000018D80400F1FC040003000000000000000000010600010000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000080000000000000008000000000003C440000000000000100000001000000010000000400000001000000 "D:\Program Files (x86)\VS Revo Group\Revo Uninstaller\uninst.exe"=0x5341435001000000000000000700000028000000FE550100A0C6280003000000000000000000010600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000020000000000000000000000000000B80B0000000000000100000001000000 "C:\Program Files (x86)\eye perform\eyeperformUninstall.exe"=0x534143500100000000000000070000002800000020CB03005FE7030003000000000000000000000671000000975FD891C99ECE0100000000000000000200000028000000000000000008000000000000000000000000000000000000C46C0000000000000100000001000000 "C:\Program Files (x86)\rEaldealo\htI6wTIvHpmboV.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000016260000000000000100000001000000 "C:\Program Files (x86)\Sidekick by HubSpot\Sidekick by HubSpot.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000063210000000000000100000001000000 "C:\Users\Thomas\Downloads\CubeSetup3.exe"=0x5341435001000000000000000700000028000000DAB918000000000001000000000000000000020600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000004D220000000000000100000001000000 "C:\Program Files (x86)\Cube World\CubeLauncher.exe"=0x5341435001000000000000000700000028000000008002000000000001000000000000000000020671220000975FD891C99ECE01000000000000000002000000280000000000000080000000000000000000000000000000000000008A7A0B00000000000100000001000000 "C:\Program Files (x86)\AllDealAupp\BqtsmAuj8FJWh2.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A5230000000000000300000003000000 "D:\Program Files (x86)\ManiaPlanet\ManiaPlanet.exe"=0x5341435001000000000000000700000028000000A8B6430190B8430101000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000CA9F0000000000000200000002000000 "D:\Program Files (x86)\Rebellion\SniperEliteV2\unins000.exe"=0x5341435001000000000000000700000028000000D9F50A000000000003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000320F0000000000000100000001000000 "C:\Program Files (x86)\AutuoDealsApp\18XD89AvEFwN6J.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000681B0000000000000100000001000000 "D:\Program Files (x86)\Photoshop\Adobe Download Assistant\7z.exe"=0x5341435001000000000000000700000028000000008002000000000001000000000000000000010671000000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000001F000000000000000100000001000000 "C:\Program Files\paint.net\PdnRepair.exe"=0x5341435001000000000000000700000028000000483C00007601010001000000000000000000030680210000B395E7CF049FCE010000000000000000020000002800000000000000000000400000000000000000000000000000000003650000000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\ManiaPlanet_TMStadium\ManiaPlanetLauncher.exe"=0x534143500100000000000000070000002800000000C046000000000001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000080000000000000000000000000000000000000001C180000000000000200000002000000 "C:\Program Files (x86)\XKit\XKit.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000035190000000000000100000001000000 "C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.132\delegate_execute.exe"=0x5341435001000000000000000700000028000000488F0A003E2F0B0001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000E1220500000000000100000001000000 "C:\Program Files\CCleaner\CCleaner.exe"=0x5341435001000000000000000700000028000000182F61005FB2610001000000000000000000030600210000975FD891C99ECE0100000000000000000200000050000000000000000000000000000000000000000000000000000000065E16010000000016000000150000000000000000000040000000000000000000000000000000009F310000000000000400000000000000 "C:\Users\Thomas\Downloads\cf25freeSetup.exe"=0x534143500100000000000000070000002800000070967D02533E7E0201000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000B7690000000000000100000001000000 "D:\Program Files (x86)\Clickteam Fusion 2.5 Free Edition\mmf2u.exe"=0x534143500100000000000000070000002800000010809E0000649F0001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000054A0100000000000200000002000000 "C:\Program Files (x86)\Gravity Space\Uninstaller.exe"=0x5341435001000000000000000700000028000000A8C80400C5E7040003000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000007C780000000000000100000001000000 "C:\Program Files (x86)\Its Results Hub\Uninstaller.exe"=0x5341435001000000000000000700000028000000E0C604002960050003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000FF840000000000000100000001000000 "C:\Users\Thomas\Downloads\TeamSpeak3-Client-win32-3.0.17.exe"=0x5341435001000000000000000700000028000000F05ABC0199D4BC0101000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000006E8F0000000000000100000001000000 "SIGN.MEDIA=894BD8 MAXON-Start.exe"=0x5341435001000000000000000700000028000000B8FD2100E6D0220001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000005D0C1200000000000300000003000000 "D:\Program Files (x86)\C4D\Maxon Cinema 4D R16 [MUMBAI-TPB]\Crack\xf-c4dr16.exe"=0x5341435001000000000000000700000028000000005801000000000001000000000000000000030671200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000004A9E0200000000000200000002000000 "D:\Program Files (x86)\MAXON Cinema4D\CINEMA 4D TeamRender Client.exe"=0x5341435001000000000000000700000028000000288D4800A796480001000000000000000000030673200000B395E7CF049FCE010000000000000000020000002800000000000000000000001000000000000000000000000000000060D00000000000000600000006000000 "D:\Program Files (x86)\MAXON Cinema4D\CINEMA 4D.exe"=0x5341435001000000000000000700000028000000288D4800D650490001000000000000000000030673200000B395E7CF049FCE01000000000000000002000000500000000000000000000000000000000000000000000000000000004CEA7E0000000000120000000C0000000000000000000040000000000000000000000000000000004E3C3B00000000000300000000000000 "C:\Users\Thomas\Desktop\Mineways.exe"=0x5341435001000000000000000700000028000000006E0900CF74090001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000E7E80700000000000200000002000000 "C:\Program Files (x86)\AllSaavEr\IbkDeL5XDAh7ys.exe"=0x5341435001000000000000000700000028000000006803009D26040003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000BC270000000000000100000001000000 "C:\Users\Thomas\Desktop\GeometryDash.exe"=0x534143500100000000000000070000002800000000943A00E1343B0001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000000000000100000000000000000000000000000005C150000000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\Geometry Dash v1.0 Steam\GeometryDash.exe"=0x534143500100000000000000070000002800000000943A00E1343B0001000000000000000000030671220000975FD891C99ECE01000000000000000002000000500000000000000000000040000000000000000000000000000000001E999200000000004E0000004E00000000000000000000000000000000000000000000000000000075849A00000000003B00000000000000 "C:\Program Files\Andy\AndyAPK.exe"=0x5341435001000000000000000700000028000000103A0D00D1100E0001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000700A0000000000000100000001000000 "C:\Users\Thomas\Downloads\setup-lightshot.exe"=0x534143500100000000000000070000002800000000522600E7C9260001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000DB3B0100000000000100000001000000 "C:\Users\Thomas\AppData\Local\03000200-1440948825-0500-0006-000700080009\Uninstall.exe"=0x534143500100000000000000070000002800000021CA00000000000003000000000000000000000671000000975FD891C99ECE0100000000000000000200000028000000000000000008000000000000000000000000000000000000EC1F0000000000000100000001000000 "C:\Program Files (x86)\Giant Galaxy\GiantGalaxyUninstall.exe"=0x534143500100000000000000070000002800000030CA0300E359040003000000000000000000000671000000975FD891C99ECE010000000000000000020000002800000000000000000800000000000000000000000000000000000055400000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Temp\Zzoooomit_uninstall.exe"=0x5341435001000000000000000700000028000000DB8A00000000000003000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000000008000000000000000000000000000000000000CB000000000000000100000001000000 "C:\Program Files (x86)\03000200-1440941581-0500-0006-000700080009\Uninstall.exe"=0x53414350010000000000000007000000280000006E0901000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000D28F0200000000000100000001000000 "C:\Program Files\shopperz250820151344\unins000.exe"=0x5341435001000000000000000700000028000000A1120B000000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000009D410000000000000100000001000000 "C:\Program Files (x86)\DriverRestore\uninst.exe"=0x53414350010000000000000007000000280000000BF203005BFE7A0003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000001B3A0000000000000200000002000000 "C:\Users\Thomas\AppData\Roaming\ASPackage\Uninstall.exe"=0x5341435001000000000000000700000028000000A40101000000000003000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000088060000000000000100000001000000 "C:\Users\Thomas\AppData\Roaming\cpuminer\cpuminer-uninst.exe"=0x534143500100000000000000070000002800000074DE000082C2400003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002B0B0000000000000100000001000000 "C:\Program Files (x86)\WordSurfer_1.10.0.19\Uninstall.exe"=0x534143500100000000000000070000002800000000CA0400BD06050003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A6420000000000000100000001000000 "C:\Program Files (x86)\03000200-1441017224-0500-0006-000700080009\Uninstall.exe"=0x5341435001000000000000000700000028000000A40101000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000A4040000000000000100000001000000 "SIGN.IE=0E2E50 ChromeSetup.exe"=0x5341435001000000000000000700000028000000502E0E008E1A0E0001000000000000000000030600210000975FD891C99ECE010000000100000000 "C:\Users\Thomas\AppData\Local\Temp\GUM4281.tmp\GoogleUpdateSetup.exe"=0x5341435001000000000000000700000028000000502E0E008E1A0E0001000000000000000000030600210000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000DFB40200000000000100000001000000 "C:\Program Files (x86)\PathMaxx\PathMaxxUninstall.exe"=0x534143500100000000000000070000002800000008CE0300BED5030003000000000000000000000671000000975FD891C99ECE0100000000000000000200000028000000000000000008000000000000000000000000000000000000356F0000000000000100000001000000 "C:\Program Files (x86)\PlayGem\uninst.exe"=0x5341435001000000000000000700000028000000F74602000000000003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D92A0000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Temp\09da6d07\LineInst.exe"=0x5341435001000000000000000700000028000000C860AB019F84AB0101000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000B8340100000000000100000001000000 "C:\Users\Thomas\Downloads\avast_premier_antivirus_setup_online.exe"=0x5341435001000000000000000700000028000000C07B53000000000001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000057741000000000000100000001000000 "D:\Program Files (x86)\qBittorrent\uninst.exe"=0x534143500100000000000000070000002800000080E101000000000003000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000068130000000000000100000001000000 "D:\Program Files\AVAST Software\Avast\VisthAux.exe"=0x534143500100000000000000070000002800000020900400998D050001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000C00000000000000000000000000000000042020000000000000200000002000000 "C:\Users\Thomas\AppData\Local\Temp\AIR9B5D.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000B87C0500D874060001000000000000000000030671220000975FD891C99ECE010000008000000000020000002800000000000000000000400000000000000000000000000000000048160000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Temp\Camtasia_Setup\Setup_CamtasiaStudio8_x86_ENU.msi"=0x534143500100000000000000070000002800000000EA0000AA51010001000000000000000000010500100000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000065C40100000000000100000001000000 "D:\Program Files (x86)\TechSmith\Camtasia Studio 8\CamtasiaStudio.exe"=0x534143500100000000000000070000002800000050AFA900300CAA00010000000000000000000306F1220000975FD891C99ECE0100000000000000000200000028000000000000000000004004000000000000000000000000000000035F0B00000000000100000001000000 "D:\Program Files (x86)\C4D\Turbo Dismount v1.8-ALiAS\setup.exe"=0x5341435001000000000000000700000028000000F5A914000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000395C0000000000000100000001000000 "D:\Program Files (x86)\Turbo Dismount\TurboDismount.exe"=0x5341435001000000000000000700000028000000003EB0000000000001000000000000000000030671200000975FD891C99ECE0100000000000000000200000050000000000002062000006000000000000000000000000000000000D9E10900000000000100000001000000000000000000004000000000000000000000000000000000E9170E00000000000200000000000000 "C:\Program Files (x86)\BlueStacks\HD-Service.exe"=0x5341435001000000000000000700000028000000D83E06004CA50600010000000000000000000306F1200000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000039010000000000000100000001000000 "C:\Users\Thomas\Downloads\LineInst.exe"=0x53414350010000000000000007000000280000001846AE01BEB2AE0101000000000000000000010671020000975FD891C99ECE010000000000000000 "D:\Program Files (x86)\TmUnitedForever\TmForever.exe"=0x53414350010000000000000007000000280000000020A0005C5C9F0001000000000000000000010671200000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000FC170000000000000300000003000000 "C:\Users\Thomas\Downloads\McEdit\mcedit2.exe"=0x534143500100000000000000070000002800000051C730020000000001000000000000000000020673000000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000CB960800000000000300000003000000 "D:\Pylo\MCreator158\MCreator.exe"=0x534143500100000000000000070000002800000000F606006236070001000000000000000000000671000000975FD891C99ECE01000000000000000002000000280000000000000000000040001000000000000000000000000000007FE84100000000000100000001000000 "C:\Program Files\Java\jre1.8.0_60\bin\javaw.exe"=0x5341435001000000000000000700000028000000602803009F49030001000000000000000000030600210000B395E7CF049FCE010000000000000000020000002800000000000000000000400000000000000000000000000000000081110400000000001C0000001C000000 "D:\Program Files\WorldPainter\worldpainter.exe"=0x5341435001000000000000000700000028000000705A09000000000001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000E6E50B00000000000100000001000000 "C:\Users\Thomas\Documents\Trucs\Pour C4D\Mineways.exe"=0x5341435001000000000000000700000028000000006E0900CF74090001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000BC702400000000000300000003000000 "C:\Users\Thomas\AppData\Local\Temp\30a8cff8\LineInst.exe"=0x5341435001000000000000000700000028000000C860AB019F84AB0101000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000AD750000000000000100000001000000 "C:\Users\Thomas\Downloads\Nouveau dossier\GeForce_Experience_v2.4.5.28.exe"=0x5341435001000000000000000700000028000000883C3102EED7310201000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000022950200000000000100000001000000 "D:\Program Files (x86)\GlassWire\GlassWire.exe"=0x534143500100000000000000070000002800000020E2C200901BC30001000000000000000000030671220000975FD891C99ECE01000000000000000002000000500000000000000000000000000000000000000000000000000000000E57BA05000000000C0000000C0000000000000000000040000000000000000000000000000000000A888D04000000002400000000000000 "C:\Users\Thomas\AppData\Local\Temp\AIRC7E8.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000B87C0500ACE5050001000000000000000000030671220000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000C54A0000000000000100000001000000 "D:\Program Files (x86)\Splinter Cell Conviction\Tom Clancy's Splinter Cell Conviction\play-Docks of San Francisco.exe"=0x5341435001000000000000000700000028000000482007000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000078000000000001068000006000000000000000000000000000000000A73500000000000001000000010000000000020680000060000000000000000000000000000000006A2500000000000001000000000000000000000080000040000000000000000000000000000000004B890200000000000200000000000000 "D:\Program Files (x86)\Steam\steamapps\common\APB Reloaded\Binaries\APB.exe"=0x5341435001000000000000000700000028000000F87CDD02547FDD0201000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000E3C20000000000000100000001000000 "SIGN.MEDIA=C0EB9AEC raf-cs_de.exe"=0x5341435001000000000000000700000028000000DE5515000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000BE900500000000000200000002000000 "D:\Cities Skyline\Cities Skyline\Cities.exe"=0x534143500100000000000000070000002800000020AD1C01FF631D0101000000000000000000030673200000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000227C1B00000000000500000005000000 "C:\Program Files\GIMP 2\bin\gimp-console-2.8.exe"=0x534143500100000000000000070000002800000080CB2600D183270001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000005000000000000000000000000000000000E2040000000000000100000001000000 "C:\Users\Thomas\Downloads\StarMade\StarMade-dedicated-server-windows.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "C:\Users\Thomas\Downloads\StarMade-starter.exe"=0x5341435001000000000000000700000028000000D0BB21000DED210001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000BA7C9900000000001600000016000000 "SIGN.MEDIA=1FC0CC2 autorun.exe"=0x534143500100000000000000070000002800000088450300F0C2030001000000000000000000000671020000975FD891C99ECE0100000000000000000200000028000000000000008000004000000000000000000000000000000000B0471C00000000000100000001000000 "D:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2010\settings.exe"=0x534143500100000000000000070000002800000088B515004075160001000000000000000000000671020000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000DD400100000000000100000001000000 "C:\ProgramData\Andy\Setup.exe"=0x534143500100000000000000070000002800000010AC0E00A18B0F0003000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000097220100000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\APB Reloaded\Binaries\pbsvc_apb.exe"=0x5341435001000000000000000700000028000000989328008795280003000000000000000000010671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000C2190000000000000100000001000000 "C:\Program Files (x86)\BlueStacks\HD-RuntimeUninstaller.exe"=0x5341435001000000000000000700000028000000D81E0A00FC2F0A00030000000000000000000306F1200000975FD891C99ECE0100000000000000000200000028000000000000000008004000000000000000000000000000000000BA2A0000000000000100000001000000 "D:\Program Files (x86)\Cheat Engine 6.4\unins000.exe"=0x534143500100000000000000070000002800000018D50A00F2530B0003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000F0210000000000000100000001000000 "C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.101\Installer\setup.exe"=0x534143500100000000000000070000002800000048390F008D2D100003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000E1470100000000000100000001000000 "C:\Windows\SysWOW64\FlashPlayerApp.exe"=0x5341435001000000000000000700000028000000F85D0C002C710C0001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000CC4E0000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Apps\2.0\DLY8XA4W.D81\YGG88MDO.5JJ\prog...app_86fd5b6b43e66935_0001.0003_5cb14937c086ca58\clickonce_bootstrap.exe"=0x5341435001000000000000000700000028000000482B00002B56000001000000000000000000030680210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000F28F0200000000000100000001000000 "SIGN.MEDIA=906C01E launcheawg.exe"=0x5341435001000000000000000700000028000000B8D524012958250101000000000000000000000671200000975FD891C99ECE0100000000000000000200000028000000000000008000004000000000000000000000000000000000F05E0500000000000300000003000000 "D:\Program Files (x86)\LucasArts\Star Wars Empire at War\LaunchEAW.exe"=0x534143500100000000000000070000002800000088D524017F7F250101000000000000000000000671200000975FD891C99ECE01000000000000000002000000780000000000020680000060000000000000000000000000000000006419000000000000010000000100000000000004800000600000000000000000000000000000000095300000000000000100000000000000000000008000004000000000000000000000000000000000744D0000000000000200000000000000 "D:\Program Files (x86)\LucasArts\Star Wars Empire at War Forces of Corruption\LaunchEAWX.exe"=0x5341435001000000000000000700000028000000B8D52401FFB8250101000000000000000000000671200000975FD891C99ECE010000000000000000020000002800000000000000800000400000000000000000000000000000000086300000000000000100000001000000 "C:\Program Files (x86)\InstallShield Installation Information\{6592FDEC-2C1A-413A-9985-25FEC2F0848D}\setup.exe"=0x5341435001000000000000000700000028000000E0F6060089BC070003000000000000000000000671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000C4230000000000000100000001000000 "C:\Program Files (x86)\InstallShield Installation Information\{99AE7207-8612-4DBA-A8F8-BAE5C633390D}\setup.exe"=0x5341435001000000000000000700000028000000E0F6060089BC070003000000000000000000000671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000851E0000000000000100000001000000 "C:\Users\Thomas\Downloads\DarkRP.exe"=0x53414350010000000000000007000000280000009FAD1F00D313060001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000DF771700000000000100000001000000 "D:\Program Files (x86)\C4D\Camtasia Studio v7.0.0_Full Version-fAiPaSSa\camtasia.msi"=0x534143500100000000000000070000002800000000FE0000B780010001000000000000000000010500100000B395E7CF049FCE0100000000000000000200000050000000000000000000000000000000000000000000000000000000BF8F06000000000001000000010000000000000000000040000000000000000000000000000000008E840400000000000100000000000000 "D:\Program Files (x86)\Camtasia Studio 7\CamtasiaStudio.exe"=0x534143500100000000000000070000002800000058575C004C995C0001000000000000000000010671220000975FD891C99ECE010000000000000000020000002800000000000000000000500000000000000000000000000000000046790A00000000000100000001000000 "D:\Program Files (x86)\virtual-audio-cable_4-14_fr_69178\setup.exe"=0x5341435001000000000000000700000028000000A84B0100C37E010001000000000000000000020671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000E2BB0900000000000100000001000000 "D:\Program Files (x86)\virtual-audio-cable_4-14_fr_69178\x64\vcctlpan.exe"=0x5341435001000000000000000700000028000000A00101001AF8010001000000000000000000030673200000B395E7CF049FCE01000000000000000002000000280000000000000000000040000000000000000000000000000000009D8F0000000000000100000001000000 "D:\Program Files\Virtual Audio Cable\setup64.exe"=0x5341435001000000000000000700000028000000A87901008A1D020003000000000000000000020673020000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000AF8C0000000000000100000001000000 "C:\Users\Thomas\Desktop\Virtual Audio Cable 4.10\setup64.exe"=0x5341435001000000000000000700000028000000A85A0100340B020001000000000000000000010673200000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000200000000000000000000000000375F0000000000000300000003000000 "C:\Users\Thomas\Desktop\Virtual Audio Cable 4.10\setup.exe"=0x5341435001000000000000000700000028000000A8EC00000565010001000000000000000000010671200000975FD891C99ECE0100000000000000000200000028000000000000000008004000000000000000000000000000000000C0A60000000000000200000002000000 "D:\Program Files\Virtual Audio Cable\vcctlpan.exe"=0x5341435001000000000000000700000028000000A892000077D7000001000000000000000000010673000000B395E7CF049FCE010000000000000000020000005000000000000000000000000000000000000000000000000000000035A90900000000000200000002000000000000000000004000000000000000000000000000000000E5E00B00000000000100000000000000 "D:\Program Files (x86)\C4D\Door.Kickers.2.1.0.6-GOG\setup_door_kickers_2.1.0.6.exe"=0x534143500100000000000000070000002800000010AE6C254F946D2501000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000574F0A00000000000100000001000000 "D:\Program Files (x86)\Door Kickers\DoorKickers.exe"=0x534143500100000000000000070000002800000000AC30000000000001000000000000000000030671220000975FD891C99ECE0100000000000000000200000050000000000002063000006000000000000000000000000000000000739C0900000000000300000003000000000000001000006000000000000000000000000000000000B22D6700000000002400000000000000 "C:\Users\Thomas\AppData\Local\Temp\jre-8u65-windows-au.exe"=0x534143500100000000000000070000002800000060F008008151090001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000C2200100000000000100000001000000 "C:\Users\Thomas\Desktop\Planetbase.v1.0.1\Planetbase.exe"=0x5341435001000000000000000700000028000000D83DF1009A88F10001000000000000000000030671200000975FD891C99ECE0100000000000000000200000078000000000002062080006000000000000000000000000000000000D01B01000000000001000000010000000000000000800060000000000000000000000000000000002E462800000000000C0000000000000000000000000000400000004000000000000000000000000035260000000000000100000000000000 "C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe"=0x5341435001000000000000000700000028000000E8DF97008DC0980001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000008762B903000000003F0000003F000000 "D:\Program Files (x86)\Image-Line\FL Studio 11\FL (compatible memory).exe"=0x5341435001000000000000000700000028000000903E0500760A060001000000000000000000020671000000975FD891C99ECE010000000000000000 "D:\Program Files (x86)\Image-Line\FL Studio 11\uninstall.exe"=0x5341435001000000000000000700000028000000F0DB3400CFE2340003000000000000000000010600010000975FD891C99ECE01000000000000000002000000500000000000000000000000000000000000000000000000000000000F850000000000000100000001000000000000000000004000000000000000000000000000000000CF0F0000000000000100000000000000 "D:\Program Files (x86)\FPS\Medal OF Honor Allied Assault\MOHDA\MOHAA.exe"=0x5341435001000000000000000700000028000000008017000000000001000000000000000000010571000000975FD891C99ECE0100000000000000000200000028000000000000000000005000040040000000000000000000000000B5E10000000000000100000001000000 "SIGN.MEDIA=374B162 setup.exe"=0x534143500100000000000000070000002800000019509C010000000001000000000000000000010571200000975FD891C99ECE01000000000000000002000000280000000000000080080040000000000000000000000000000000009D350200000000000100000001000000 "D:\Program Files (x86)\Nightfire\Bond.exe"=0x534143500100000000000000070000002800000000B001000000000001000000000000000000010571200000975FD891C99ECE010000000000000000020000002800000000000000000000402004000000000000000000000000000041870D00000000000200000002000000 "SIGN.MEDIA=D6A41DAB setup.exe"=0x5341435001000000000000000700000028000000A75D13000000000001000000000000000000020600010000975FD891C99ECE0100000000000000000200000028000000000000008000004000000000000000000000000000000000B93D0900000000000100000001000000 "G:\jeux FPS\F1-2013\F1-2013-PatchFRv2.exe"=0x5341435001000000000000000700000028000000FB60781B0000000001000000000000000000010600010000975FD891C99ECE01000000800000000002000000280000000000000000000040000000000000000000000000000000009C1D0300000000000100000001000000 "D:\Program Files (x86)\F1 2013\F1_2013.exe"=0x5341435001000000000000000700000028000000004809010000000001000000000000000000020671020000975FD891C99ECE0100000000000000000200000050000000000002062000006000000000000000000000000000000000D0B7080000000000010000000100000000000000000000400000000000000000000000000000000085D91E00000000000600000000000000 "D:\Program Files (x86)\Steam\steamerrorreporter.exe"=0x534143500100000000000000070000002800000050D60700214B080001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000029280000000000000100000001000000 "C:\Users\Thomas\Downloads\SteamSetup.exe"=0x534143500100000000000000070000002800000070881600A657170001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000036FE0000000000000100000001000000 "D:\Program Files (x86)\Steam\GameOverlayUI.exe"=0x534143500100000000000000070000002800000050DC0500A3E3050001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000E4010000000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Source\hl2.exe"=0x534143500100000000000000070000002800000020E10100BBD9020001000000000000000000030600210000975FD891C99ECE0100000000000000000200000050000000000000000000009000000000000000000000000000000000BA37000000000000030000000300000000000000000000D000000000000000000000000000000000F43D0000000000000100000000000000 "C:\Users\Thomas\AppData\Local\Temp\jre-8u66-windows-au.exe"=0x534143500100000000000000070000002800000060F008007969090001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000072640100000000000100000001000000 "D:\Program Files (x86)\C4D\Universe_Sandbox_2_setup.exe"=0x5341435001000000000000000700000028000000BC673C1B0000000001000000000000000000000671000000975FD891C99ECE0100000000000000000200000028000000000000000008004000000000000000000000000000000000D5C60100000000000300000003000000 "D:\Program Files (x86)\Universe Sandbox 2\Universe Sandbox.exe"=0x53414350010000000000000007000000280000000062F6000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000E0070000000000000100000001000000 "D:\Program Files (x86)\Universe Sandbox 2\Universe Sandbox x64.exe"=0x5341435001000000000000000700000028000000009427010000000001000000000000000000030600210000B395E7CF049FCE010000000000000000050000001000000000000000000000000000020620000000020000005000000000000206200000600000000000000000000000000000000037CD5800000000000E0000000E00000000000000000000400000000000000000000000000000000021863600000000001100000000000000 "D:\Program Files (x86)\C4D\Universe.Sandbox.2.Alpha17\Universe Sandbox x64.exe"=0x534143500100000000000000070000002800000000FE27010000000001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000BA510000000000000200000002000000 "D:\Program Files (x86)\C4D\Universe.Sandbox.2.Alpha17\LAUNCHER.exe"=0x534143500100000000000000070000002800000000F801004240020001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000080000040000000000000000000000000000000008E120000000000000200000002000000 "C:\Windows\System32\hpinkins7312.exe"=0x534143500100000000000000070000002800000008C22700BABB280001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000CB1A0000000000000100000001000000 "D:\Program Files (x86)\C4D\Trucs\Unturned Give Editor.exe"=0x534143500100000000000000070000002800000000A67F0000000000010000000000000000000306F5220000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000375F0000000000000100000001000000 "D:\Program Files (x86)\C4D\[www.Cpasbien.pe] Photoshop Cs6 Extended Version Finale Pc Fr\Adobe CS6\Set-up.exe"=0x5341435001000000000000000700000028000000A0C821004D60220001000000000000000000010671020000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000077B00600000000000300000003000000 "C:\Program Files (x86)\Adobe\Adobe Photoshop CS6\Photoshop.exe"=0x5341435001000000000000000700000028000000A0E88F02DE13900201000000000000000000010671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000B91F0E00000000000300000003000000 "C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe"=0x5341435001000000000000000700000028000000A092B5039091B60301000000000000000000010673220000B395E7CF049FCE01000000000000000002000000280000000000000000000040000000000000000000000000000000004D110500000000000100000001000000 "D:\Program Files (x86)\Adobe\Adobe Photoshop CS6\Photoshop.exe"=0x5341435001000000000000000700000028000000A0E88F02DE13900201000000000000000000010671220000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000040000002000000000000000000000000004CAB1200000000001000000001000000000000000000000000000000000000000000000000000000F82A0000000000000100000000000000 "D:\Program Files (x86)\FPS\Soldier OF Fortune 2\CD 1\AUTORUN.EXE"=0x5341435001000000000000000700000028000000007000000000000001000000000000000000010571200000975FD891C99ECE010000000000000000050000001000000000000000000000000000000080080000020000002800000000000000800800400000200000000000000020000000000057010000000000000100000001000000010000000400000001000000 "D:\Program Files (x86)\FPS\Soldier OF Fortune 2\CD 1\Setup.exe"=0x5341435001000000000000000700000028000000003001000000000001000000000000000000010571200000975FD891C99ECE010000000000000000 "C:\Users\Thomas\Downloads\gu5setup.exe"=0x5341435001000000000000000700000028000000E836E80062E9E80001000000000000000000010600010000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000057230000000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"=0x534143500100000000000000070000002800000090E21C0038091D0001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000048010000000000000400000004000000 "C:\Users\Thomas\Downloads\GeForce_Experience_v2.7.4.10.exe"=0x5341435001000000000000000700000028000000F8574F024D8F4F0201000000000000000000020600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000AC5B0000000000000300000003000000 "D:\Program Files (x86)\Steam\steamapps\common\WARMODE\warmode.exe"=0x534143500100000000000000070000002800000000A8F6000000000001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000206200000600000000000000000000000000000000007331700000000000100000001000000 "SIGN.MEDIA=6FF154F9 autorun.exe"=0x534143500100000000000000070000002800000088C22E00DFC02F0001000000000000000000000671220000975FD891C99ECE01000000000000000002000000280000000000000080000040000000000000000000000000000000009A030000000000000100000001000000 "SIGN.MEDIA=6FF154F9 setup.exe"=0x534143500100000000000000070000002800000088C2050044E3050001000000000000000000000671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000542D1500000000000100000001000000 "D:\Program Files (x86)\Ubisoft\Far Cry 2\bin\FC2Editor.exe"=0x534143500100000000000000070000002800000000F01100BCEA1200010000000000000000000006F1220000975FD891C99ECE0100000000000000000200000050000000000002062000006000000000000000000000000000000000CD9A090000000000010000000100000000000000000000400000000000000000000000000000000054D90100000000000100000000000000 "C:\Windows\SysWOW64\pbsvc.exe"=0x5341435001000000000000000700000028000000285522002070220003000000000000000000000671020000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000030F0000000000000100000001000000 "SIGN.MEDIA=F92CE282 Setup.exe"=0x53414350010000000000000007000000280000000B0306000000000001000000000000000000010600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000008F6F0E00000000000100000001000000 "D:\Program Files (x86)\THQ\Saints Row The Third\game_launcher.exe"=0x534143500100000000000000070000002800000000D22100B158220001000000000000000000010671220000975FD891C99ECE010000000000000000020000002800000000000206A0000060000000000000000000000000000000005E700000000000000500000005000000 "D:\Program Files (x86)\THQ\Saints Row The Third\saintsrowthethird.exe"=0x53414350010000000000000007000000280000004886F50033F8F50001000000000000000000010671220000975FD891C99ECE0100000000000000000200000050000000000002062000006000000000000000000000000000000000DE0200000000000001000000010000000000000000000040000000000000000000000000000000000D030000000000000100000000000000 "D:\Program Files (x86)\THQ\Saints Row The Third\saintsrowthethird_dx11.exe"=0x534143500100000000000000070000002800000048F63504E1B8360401000000000000000000010671220000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000000D030000000000000100000001000000 "D:\Program Files (x86)\Ubisoft\Far Cry 2\bin\FarCry2.exe"=0x534143500100000000000000070000002800000048BBD50058FBD50001000000000000000000000671000000975FD891C99ECE0100000000000000000200000028000000000002062000007000100000000000000000000000000000684A0300000000000500000005000000 "SIGN.MEDIA=35973006 autorun.exe"=0x5341435001000000000000000700000028000000009000000000000001000000000000000000010571200000975FD891C99ECE010000000000000000020000002800000000000000800000400010000000000000000000000000000043430000000000000100000001000000 "SIGN.MEDIA=2A24D755 MGSI.exe"=0x53414350010000000000000007000000280000006E002C000000000001000000000000000000010571200000975FD891C99ECE010000000000000000020000002800000000000000000000401004020000000000000000000000000092210000000000000200000002000000 "SIGN.MEDIA=2A24D755 MGSVR.exe"=0x53414350010000000000000007000000280000006DE02C000000000001000000000000000000010571200000975FD891C99ECE01000000000000000002000000280000000000000000000040001602000000000000000000000000000F150000000000000100000001000000 "SIGN.MEDIA=3B09597D AutoRun.exe"=0x53414350010000000000000007000000280000001085060085EA060001000000000000000000000671200000975FD891C99ECE01000000000000000002000000280000000000000080000040000000000000000000000000000000009B590300000000000100000001000000 "SIGN.MEDIA=829D9D0 Crack\BurnoutParadise.exe"=0x5341435001000000000000000700000028000000101FA002DFAFC30001000000000000000000000671200000975FD891C99ECE01000000C000000000020000002800000000000000000000500000000000000000000000000000000072010100000000000100000001000000 "SIGN.MEDIA=6000 Test Drive Unlimited\Crack\YASU.exe"=0x5341435001000000000000000700000028000000006000000000000001000000000000000000000661220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000013424D00000000000100000001000000 "SIGN.MEDIA=14D18C setup.exe"=0x534143500100000000000000070000002800000000E003000000000001000000000000000000010571000000975FD891C99ECE0100000000000000000200000028000000000000000008004000000000000000000000000000000000B05F0100000000000100000001000000 "D:\Program Files (x86)\THQ\Saints Row The Third\unins000.exe"=0x5341435001000000000000000700000028000000D9F50A000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000020000000000000000000000000000951E0000000000000100000001000000 "C:\Program Files\GIMP 2\uninst\unins000.exe"=0x534143500100000000000000070000002800000070FE11008EBE120001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000091210000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Apps\2.0\DLY8XA4W.D81\YGG88MDO.5JJ\idle..tion_86367c4a3014b007_0001.0004_0282557b99ab4040\IdleMaster.exe"=0x534143500100000000000000070000002800000058451C00A7251D00010000000000000000000306F1220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000074690400000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\Aftermath\AMLauncher.exe"=0x534143500100000000000000070000002800000098C6A1006B78A20001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000206A00000600000000000000000000000000000000032D70E00000000000200000002000000 "D:\Program Files (x86)\GameforgeLive\GameforgeLive.exe"=0x5341435001000000000000000700000028000000301A0D0031370D0001000000000000000000030671220000975FD891C99ECE01000000000000000002000000500000000000020620000060000000000000000000000000000000000B3D2700000000000200000001000000000000000000004000000000000000000000000000000000422AB700000000000200000000000000 "G:\jeux FPS\FIFA.14.Multi13\setup.exe"=0x5341435001000000000000000700000028000000EDE249000000000001000000000000000000020600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000008A6D0100000000000200000002000000 "C:\Users\Thomas\Desktop\eclipse.exe"=0x5341435001000000000000000700000028000000F0E104000D09050001000000000000000000030673200000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000D6130000000000000200000002000000 "D:\Program Files (x86)\Eclipse\eclipse\eclipse.exe"=0x5341435001000000000000000700000028000000F0E104000D09050001000000000000000000030673200000B395E7CF049FCE0100000000000000000200000050000000000000000000000000000000000000000000000000000000C66F4400000000000C0000000C0000000000000000000040000000000000000000000000000000007F7E1200000000000600000000000000 "SIGN.MEDIA=76631B88 setup.exe"=0x5341435001000000000000000700000028000000B5AF34000000000001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000089C50F00000000000100000001000000 "D:\Program Files (x86)\Pro Cycling Manager 2015\PCM.exe"=0x53414350010000000000000007000000280000007051A1004104A20001000000000000000000030671220000975FD891C99ECE01000000000000000002000000500000000000020620000060000000000000000000000000000000005BA92F000000000003000000030000000000000020000060000000000000000000000000000000001B550200000000000100000000000000 "D:\Program Files (x86)\Steam\steamapps\common\Tom Clancy's Ghost Recon Phantoms - EU\Launcher.exe"=0x534143500100000000000000070000002800000028E64800D2254900010000000000000000000306F1220000975FD891C99ECE010000000000000000020000002800000000000206A000006000000000000000000000000000000000A1910000000000000100000001000000 "D:\Program Files (x86)\C4D\FIFA 16 Super Deluxe Edition -SKIDROWCRACK\fifa16.exe"=0x5341435001000000000000000700000028000000183DCA06CFF8CA0601000000000000000000030673220000B395E7CF049FCE0100000000000000000200000050000000000000000000000000000000000000000000000000000000DF500000000000000100000001000000000000000000004000000000000000000000000000000000732E0000000000000300000000000000 "D:\Program Files (x86)\C4D\FIFA 16 Super Deluxe Edition -SKIDROWCRACK\Core\ActivationUI.exe"=0x53414350010000000000000007000000280000001879190065321A0001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000001F000000000000000100000001000000 "SIGN.MEDIA=DBB8CF8F AutoRun.exe"=0x5341435001000000000000000700000028000000004A36000000000001000000000000000000020600010000975FD891C99ECE0100000000000000000200000050000000000000008000000000000000000000000000000000000000990B000000000000010000000100000000000000800000400000000000000000000000000000000059420000000000000100000000000000 "D:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe"=0x534143500100000000000000070000002800000000B8F5000000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000500000000000000000000000000000000000000000000000000000007E122100000000000A0000000A0000000000000000000040000000000000000000000000000000007B723900000000000400000000000000 "D:\Program Files (x86)\Paint.the.Town.Red.v0.1.3\PaintTheTownRed.exe"=0x5341435001000000000000000700000028000000E0EF2E010000000001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000DA3C0000000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\Paint.the.Town.Red.v0.1.3\Paint The Town Red.exe"=0x5341435001000000000000000700000028000000E0EF2E010000000001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000CD120000000000000300000003000000 "D:\Program Files (x86)\Steam\steamapps\common\Paint.the.Town.Red.v0.1.3\PaintTheTownRed.exe"=0x5341435001000000000000000700000028000000E0EF2E010000000001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000050000000000002062000006000000000000000000000000000000000E10A4100000000001B0000001B00000000000000000000400000000000000000000000000000000099590000000000000100000000000000 "D:\Program Files (x86)\Expériences Minecraft\HEROBRINEMAP\mcedit\mcedit.exe"=0x5341435001000000000000000700000028000000BA4D49000000000001000000000000000000020673000000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000AC000000000000000800000008000000 "D:\Program Files (x86)\RomStation\RomStation.exe"=0x534143500100000000000000070000002800000000801D000000000001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000FC920600000000000100000001000000 "C:\Users\Thomas\Desktop\Armax2001 - AutoClick v1.0\AutoClick by Armax2001.exe"=0x53414350010000000000000007000000280000000036070000000000010000000000000000000206F1200000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000E0C02400000000000900000009000000 "C:\Users\Thomas\Downloads\HunterZ.exe"=0x5341435001000000000000000700000028000000380901000A34010001000000000000000000020671000000975FD891C99ECE010000000000000000020000002800000000000000000000400010000000000000000000000000000011050000000000000600000006000000 "D:\Program Files (x86)\Cheat Engine 6.4\cheatengine-x86_64.exe"=0x534143500100000000000000070000002800000018179900943D990001000000000000000000030663220000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000B7902100000000000700000007000000 "C:\Users\Thomas\AppData\Local\Temp\jre-8u71-windows-au.exe"=0x534143500100000000000000070000002800000060D609002C970A0001000000000000000000030671220000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000001E150000000000000100000001000000 "D:\Program Files (x86)\LucasArts\Star Wars Galactic Battlegrounds\Game\battlegrounds_x1.exe"=0x534143500100000000000000070000002800000000002B000000000001000000000000000000010571200000975FD891C99ECE01000000000000000002000000A00000000000020600800020004602000000000000000000000000001D25630100000000210000002100000000000206008000600000000000000000000000000000000042F17400000000000400000000000000000201050080006020000040000000000000000000000000D0C7AC000000000013000000000000000000000000800060000000000000000000000000000000006D430100000000000100000000000000 "C:\ProgramData\Origin\SelfUpdate\StagedUpdate\UpdateTool.exe"=0x5341435001000000000000000700000028000000F8DB0300398D040001000000000000000000030671220000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000D5350000000000000100000001000000 "D:\Program Files (x86)\TeamSpeak 3 Client\update.exe"=0x5341435001000000000000000700000028000000E8CB130043F4130001000000000000000000030671220000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000A9100000000000000200000002000000 "C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.97\delegate_execute.exe"=0x5341435001000000000000000700000028000000483B0B00CA480B0001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000002D030000000000000200000002000000 "D:\Program Files (x86)\Google\Update\GoogleUpdate.exe"=0x534143500100000000000000070000002800000088A5010008CB010001000000000000000000030600210000975FD891C99ECE010000008000000000020000002800000000000000000000400000000000000000000000000000000029010000000000000100000001000000 "D:\Program Files (x86)\VirtualDJ\virtualdj8.exe"=0x5341435001000000000000000700000028000000F8804E02D75B4F0201000000000000000000030600210000975FD891C99ECE010000000000000000020000007800000000000206000000200000000000000000000000000000000022B56700000000005A0000005A000000000000000000000000000000000000000000000000000000420B1C000000000003000000000000000000000000000040000000000000000000000000000000004B412500000000000700000000000000 "D:\Program Files (x86)\Steam\steamapps\common\PAYDAY The Heist\payday_win32_release.exe"=0x534143500100000000000000070000002800000000CC6A000000000001000000000000000000010671020000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000DC050000000000000300000003000000 "C:\Users\Thomas\Desktop\Clustertruck.exe"=0x534143500100000000000000070000002800000000B203010000000001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000206000000600000000000000000000000000000000021050000000000000200000002000000 "C:\Users\Thomas\Downloads\KoduSetup.exe"=0x53414350010000000000000007000000280000006C582E0A1F707D0F01000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000000A0E0000000000000200000002000000 "D:\Program Files (x86)\Steam\steamapps\common\Blockstorm\Blockstorm.exe"=0x5341435001000000000000000700000028000000002EB0000000000001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000002062000006000000000000000000000000000000000510A0000000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\aceofspades\aos.exe"=0x534143500100000000000000070000002800000000CC0E000000000001000000000000000000010671000000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000006F620400000000000100000001000000 "D:\Program Files (x86)\Unity Web Player\Editor\Unity.exe"=0x5341435001000000000000000700000028000000D82501039B68010301000000000000000000030600210000B395E7CF049FCE0100000000000000000200000050000000000000000000000000000000000000000000000000000000A68B00000000000002000000020000000000000000000040000000000000000000000000000000004EAD7500000000000600000000000000 "D:\Program Files (x86)\Goat Simulator\unins000.exe"=0x53414350010000000000000007000000280000005AA50A000000000001000000000000000000030641220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000D8100000000000000100000001000000 "SIGN.MEDIA=34949F6D AutoRun.exe"=0x534143500100000000000000070000002800000010450600CDDA060001000000000000000000000671200000975FD891C99ECE01000000000000000002000000280000000000000080000040000000000000000000000000000000006B630700000000000400000004000000 "SIGN.MEDIA=58E0BA0 Crack\nfs.exe"=0x5341435001000000000000000700000028000000D015C702DEB9A20001000000000000000000000671200000975FD891C99ECE01000000C00000000002000000280000000000000000000050000000000000000000000000000000008B100000000000000100000001000000 "D:\Program Files (x86)\Ubisoft\Far Cry 2\bin\FC2Launcher.exe"=0x534143500100000000000000070000002800000088720900DFD2090001000000000000000000000671220000975FD891C99ECE0100000000000000000200000028000000000000008000005000100000000000000000000000000000A08C0000000000000100000001000000 "SIGN.MEDIA=83F73A62 setup.exe"=0x5341435001000000000000000700000028000000B06247000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000C92D0300000000000200000002000000 "D:\Games\American Truck Simulator\bin\win_x64\amtrucks.exe"=0x534143500100000000000000070000002800000000A03C0140CB370101000000000000000000030600210000B395E7CF049FCE010000000000000000020000002800000000000000200000600000000000000000000000000000000010A86100000000000900000009000000 "SIGN.MEDIA=18C8B4 BlacklistAutoRun.exe"=0x534143500100000000000000070000002800000010226300CAB8630001000000000000000000020600210000975FD891C99ECE0100000000000000000200000050000000000000008000004000000000000000000000000000000000CCA400000000000001000000010000000000000000000040000000000000000000000000000000007EB60000000000000500000000000000 "SIGN.MEDIA=18C8B4 setup.exe"=0x5341435001000000000000000700000028000000106A0C0090D20C0001000000000000000000020600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000073440F00000000000200000002000000 "SIGN.MEDIA=34949F6D EASetup.exe"=0x534143500100000000000000070000002800000010550600A090060001000000000000000000000671200000975FD891C99ECE0100000000000000000200000028000000000000008008004000000000000000000000000000000000CD350500000000000100000001000000 "SIGN.MEDIA=34949F6D nfs.exe"=0x534143500100000000000000070000002800000010A5F6001372F70001000000000000000000000671200000975FD891C99ECE01000000C0000000000200000028000000000000000000005000000000000000000000000000000000BD050000000000000100000001000000 "SIGN.MEDIA=34949F6D setup.exe"=0x5341435001000000000000000700000028000000005600000000000001000000000000000000010571000000975FD891C99ECE010000000000000000010000000400000001000000050000001000000000000000000000000000000000080000020000002800000000000000000800400000200000000000000020000000000092070000000000000200000002000000 "D:\Program Files (x86)\EA Games\Need for Speed Undercover\nfs.exe"=0x5341435001000000000000000700000028000000D015C702DEB9A20001000000000000000000000671200000975FD891C99ECE01000000C0000000000200000028000000000000000000005000000000000000000000000000000000D48D1800000000000200000002000000 "D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_DX11_game.exe"=0x53414350010000000000000007000000280000001046EF021325F00201000000000000000000020671200000975FD891C99ECE0100000000000000000200000050000000000001060000006000000000000000000000000000000000A48E000000000000030000000300000000000000000000400000000000000000000000000000000026CA0000000000000100000000000000 "D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_game.exe"=0x534143500100000000000000070000002800000010F0E902ABB9EA0201000000000000000000020671200000975FD891C99ECE0100000000000000000200000078000000000001060000006000000000000000000000000000000000A7D90000000000000900000002000000000301050000006000000000000000000000000000000000DC750000000000000200000000000000000000000000004000000000000000000000000000000000B6A50000000000000200000000000000 "D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\Blacklist_Launcher.exe"=0x53414350010000000000000007000000280000001044010082F0010001000000000000000000020671220000975FD891C99ECE0100000000000000000200000028000000000000008000004000000000000000000000000000000000788B0000000000000100000001000000 "D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\blacklist_patch_v1_01.exe"=0x5341435001000000000000000700000028000000183E796D7B297A6D01000000000000000000020600210000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000E6660700000000000100000001000000 "C:\Users\Thomas\AppData\Local\Temp\jre-8u73-windows-au.exe"=0x5341435001000000000000000700000028000000603C0B003D120C0001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000AD140400000000000200000002000000 "SIGN.MEDIA=18ADE037 Crack\BLACKLIST_GAME.EXE"=0x534143500100000000000000070000002800000010F0E902ABB9EA0201000000000000000000020671200000975FD891C99ECE0100000000000000000200000028000000000000000000004010000000000000000000000000000000395C0000000000000100000001000000 "D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\gu.exe"=0x534143500100000000000000070000002800000010760900EAAE090001000000000000000000000671020000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000006DA40000000000000100000001000000 "D:\Program Files (x86)\C4D\Age Of Empires 2 & The Conquerors Expansion - Full Game - [HUSSEY]\setup.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500300000B395E7CF049FCE010000000000000000 "D:\Program Files (x86)\C4D\Age Of Empires 2 & The Conquerors Expansion - Full Game - [HUSSEY]\SETUPREG.EXE"=0x534143500100000000000000070000002800000000B000000000000001000000000000000000010571200000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000080000020000002800000000000000000800400000200000000000000020000000000046040000000000000100000001000000010000000400000001000000 "D:\Program Files (x86)\C4D\Age Of Empires 2 & The Conquerors Expansion - Full Game - [HUSSEY]\age2_x1.exe"=0x53414350010000000000000007000000280000002D2029000000000001000000000000000000010571200000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000E70B0000000000000100000001000000 "D:\Program Files (x86)\C4D\Age Of Empires 2 & The Conquerors Expansion - Full Game - [HUSSEY]\empires2.exe"=0x5341435001000000000000000700000028000000001027000000000001000000000000000000010571200000975FD891C99ECE0100000000000000000200000028000000000000000000005000000040000000000000000000000000C2C20A00000000000100000001000000 "C:\Users\Thomas\Desktop\Minecraft.exe"=0x534143500100000000000000070000002800000088071300D238130001000000000000000000030671200000975FD891C99ECE01000000000000000002000000A0000000000002060000002000000000000000000000000000000000CB72CA01000000006802000007000000000002060000006000000000000000000000000000000000200000000000000001000000000000000000020620000060000000000000000000000000000000007D7BEC000000000036000000000000000000010620000060000000000000000000000000000000003A9A8801000000006B00000000000000 "SIGN.MEDIA=53DFCAAE setup.exe"=0x534143500100000000000000070000002800000076394F000000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000001EC00100000000000300000003000000 "D:\Program Files (x86)\ALONE IN SPACE\ALONE IN SPACE.exe"=0x534143500100000000000000070000002800000000B23D010000000001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000050000000000002060000006000000000000000000000000000000000E1070300000000000400000003000000000000000000004000000000000000000000000000000000610F0000000000000200000000000000 "D:\Program Files (x86)\ALONE IN SPACE\unins000.exe"=0x5341435001000000000000000700000028000000D1D41A000000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000009A100000000000000100000001000000 "D:\Program Files (x86)\KISS ltd\Lifeless Planet\unins000.exe"=0x5341435001000000000000000700000028000000D9F50A000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000020000000000000000000000000000B74F0000000000000100000001000000 "D:\Program Files (x86)\Nightfire\EA Support\James Bond Nightfire_uninst.exe"=0x5341435001000000000000000700000028000000005001000000000001000000000000000000010571200000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000800000200000028000000000000000008004000000000000000000000000000000000CB000000000000000300000003000000 "SIGN.MEDIA=FC45492B setup.exe"=0x53414350010000000000000007000000280000008F6247000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000619B0100000000000200000002000000 "D:\Program Files (x86)\Firewatch\Firewatch.exe"=0x5341435001000000000000000700000028000000003228010000000001000000000000000000030600210000B395E7CF049FCE010000000000000000020000005000000000000206200000600000000000000000000000000000000084700F00000000000100000001000000000000002000006000000000000000000000000000000000E15A0000000000000100000000000000 "SIGN.MEDIA=1B4AD56E setup.exe"=0x5341435001000000000000000700000028000000B9FC30000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000962F0B00000000000200000002000000 "D:\Program Files (x86)\Assassins Creed\AssassinsCreed_Game.exe"=0x534143500100000000000000070000002800000088A2060017C2060001000000000000000000000671220000975FD891C99ECE0100000000000000000200000028000000000000000000004010100000000000000000000000000000D51B0000000000000200000002000000 "D:\Program Files (x86)\Assassins Creed\AssassinsCreed_Dx9.exe"=0x53414350010000000000000007000000280000008862780189F2780101000000000000000000000671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000100000000000000000000000000000CF1C0000000000000100000001000000 "D:\Program Files (x86)\Assassins Creed\AssassinsCreed_Dx10.exe"=0x53414350010000000000000007000000280000008802710113F4710101000000000000000000000671220000975FD891C99ECE01000000000000000002000000280000000000000000000040101000000000000000000000000000006D150000000000000100000001000000 "SIGN.MEDIA=F7966097 setup.exe"=0x5341435001000000000000000700000028000000F1F22F000000000001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000080000040000000000000000000000000000000004C9F0A00000000000100000001000000 "D:\Program Files (x86)\Assassins Creed Black Flag\AC4BFSP.exe"=0x5341435001000000000000000700000028000000A08BB0023997B00201000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000009E1F0000000000000100000001000000 "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe"=0x5341435001000000000000000700000028000000B87C050088A2050003000000000000000000030671220000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000CE6D0000000000000100000001000000 "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDapp.exe"=0x5341435001000000000000000700000028000000A0422000E215210003000000000000000000010600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000BA160200000000000100000001000000 "C:\Program Files (x86)\InstallShield Installation Information\{A6356F2F-D3E1-4D83-9AA2-72871DD0C298}\setup.exe"=0x5341435001000000000000000700000028000000106A0C0090D20C0003000000000000000000020600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000CA1D0300000000000100000001000000 "D:\Program Files (x86)\Clickteam Fusion 2.5 Free Edition\UninstallFusion25.exe"=0x534143500100000000000000070000002800000088FC02000000000003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000930C0000000000000100000001000000 "SIGN.MEDIA=2EE3022A Setup.exe"=0x5341435001000000000000000700000028000000102E190067E6190001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000003BFB1000000000000100000001000000 "D:\Program Files (x86)\Ubisoft\Assassin's Creed Rogue\ACC.exe"=0x5341435001000000000000000700000028000000D85A0B042D9B0B0401000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000CF6A2100000000000200000002000000 "C:\Users\Thomas\Downloads\beatpad_installer.exe"=0x5341435001000000000000000700000028000000BF360203BBB0120001000000000000000000020600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000002B6E0000000000000100000001000000 "D:\Program Files (x86)\Beatpad\Beatpad.exe"=0x5341435001000000000000000700000028000000005E320000000000010000000000000000000306F1220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000024300100000000000100000001000000 "SIGN.MEDIA=C401FB5 setup.exe"=0x53414350010000000000000007000000280000008C6247000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000008000004000000000000000000000000000000000A55F0300000000000100000001000000 "D:\Program Files (x86)\Microsoft Games\Age of Empires II HD The African Kingdoms\Launcher.exe"=0x534143500100000000000000070000002800000000401C000000000001000000000000000000030671220000975FD891C99ECE010000000000000000020000005000000000020105A0000060000000000000000000000000000000005CFC150000000000040000000400000000000000A000006000000000000000000000000000000000EE500000000000000200000000000000 "D:\Program Files (x86)\Microsoft Games\Age of Empires II HD The African Kingdoms\AoK HD.exe"=0x534143500100000000000000070000002800000018057700FC33770001000000000000000000030671220000975FD891C99ECE010000000000000000050000001000000000000000000000000003010500000000020000002800000000030105000000600000000000000000000000000000000010F73500000000000500000005000000 "D:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe"=0x534143500100000000000000070000002800000038099600CD0E960001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000028941301000000000200000002000000 "D:\Program Files (x86)\JCC Pokémon\PokemonTradingCardGameOnline\Pokemon Trading Card Game Online.exe"=0x53414350010000000000000007000000280000007895B1007116B20001000000000000000000030671200000975FD891C99ECE010000000000000000020000002800000000000206000000200000000000000000000000000000000064380700000000000600000006000000 "D:\Program Files\AVAST Software\Avast\setup\instup.exe"=0x534143500100000000000000070000002800000008DF0B000000000003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000C43F0100000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\America's Army\AAPG\Binaries\Win32\pbsvc_pg.exe"=0x5341435001000000000000000700000028000000680D29000885290003000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D6130000000000000100000001000000 "C:\Program Files (x86)\OpenAL\oalinst.exe"=0x5341435001000000000000000700000028000000185A0C00D09C0C0003000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000014290000000000000100000001000000 "D:\Program Files (x86)\Turbo Dismount\unins000.exe"=0x534143500100000000000000070000002800000069BC1A000000000003000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000041240000000000000100000001000000 "D:\Program Files (x86)\C4D\Star.Wars.Battlefront.II-GOG\setup_sw_battlefront2_2.0.0.5.exe"=0x534143500100000000000000070000002800000018A6D001ECE5D00101000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000016FC0600000000000100000001000000 "D:\Program Files (x86)\Star Wars - Battlefront 2\GameData\BattlefrontII.exe"=0x534143500100000000000000070000002800000000504600F761460001000000000000000000010571000000975FD891C99ECE0100000000000000000200000028000000000000001000002000440000000000000000000000000000BCFD5500000000000600000006000000 "SIGN.MEDIA=60D6DD setup.exe"=0x534143500100000000000000070000002800000000052D0047AC2D0001000000000000000000000671020000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000005A050100000000000100000001000000 "SIGN.MEDIA=60D6DD Launcher.exe"=0x534143500100000000000000070000002800000028150400E7EC040001000000000000000000000671220000975FD891C99ECE010000000000000000020000002800000000000000800000000000000000000000000000000000000072350B00000000000200000002000000 "D:\Program Files (x86)\LucasArts\LEGO Star Wars La Saga Complète\LEGOStarWarsSaga.exe"=0x5341435001000000000000000700000028000000000052000000000001000000000000000000000671020000975FD891C99ECE010000000000000000020000002800000000000000000000000010000000000000000000000000000083C68C00000000000600000006000000 "D:\Program Files (x86)\TeamSpeak 3 Client\error_report.exe"=0x5341435001000000000000000700000028000000E89F0600F07F070001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000020000000000000000100000001000000 "C:\Users\Thomas\Downloads\jre-8u73-windows-i586-iftw.exe"=0x534143500100000000000000070000002800000060360B00D0F30B0001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000D2B10200000000000100000001000000 "C:\Users\Thomas\Downloads\JAVA-8u45-64bits-ASCENTIA.exe"=0x5341435001000000000000000700000028000000600493026F0A930201000000000000000000030673220000B395E7CF049FCE010000000000000000020000002800000000000000000000400000000000000000000000000000000003A80100000000000200000002000000 "D:\Program Files (x86)\C4D\Mini.Metro-GOG\setup_mini_metro_2.0.0.3.exe"=0x5341435001000000000000000700000028000000D0596B0BD1856B0B01000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000009E410D00000000000100000001000000 "D:\Program Files (x86)\Mini Metro\MiniMetro.exe"=0x53414350010000000000000007000000280000000076B1000000000001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000002061000002000000000000000000000000000000000CDD20400000000000100000001000000 "D:\Program Files (x86)\WorldPainter\worldpainter.exe"=0x5341435001000000000000000700000028000000905809000000000001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A7E74700000000000400000004000000 "C:\Users\Thomas\Downloads\vlc-2.2.2-win64.exe"=0x5341435001000000000000000700000028000000C59FDE014ACB010001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000009EE0000000000000100000001000000 "D:\Program Files (x86)\C4D\Cities.XL.Platinum.2013.MULTI7.CRACKED-P2P\setup.exe"=0x534143500100000000000000070000002800000048120D000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000FB190B00000000000200000002000000 "D:\Program Files (x86)\Steam\steamapps\common\Cities XL Platinum\CitiesXL_Platinum.exe"=0x534143500100000000000000070000002800000000167B018D27840101000000000000000000010671020000975FD891C99ECE0100000000000000000200000028000000000002060000002000000000000000000000000000000000B1350B00000000000100000001000000 "SIGN.MEDIA=558DD50B setup.exe"=0x5341435001000000000000000700000028000000D6C406000000000001000000000000000000020600210000975FD891C99ECE0100000000000000000200000050000000000000000000000000000000000000000000000000000000DD44130000000000010000000100000000000000800000000000000000000000000000000000000081B40200000000000100000000000000 "D:\Program Files (x86)\Steam\steamapps\common\Cities XL Platinum\unins000.exe"=0x5341435001000000000000000700000028000000DFB219000000000003000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002D2A0000000000000100000001000000 "D:\Program Files (x86)\Ubisoft\Driver San Francisco\Driver.exe"=0x534143500100000000000000070000002800000038E9C2000F6BC30001000000000000000000010671020000975FD891C99ECE0100000000000000000200000028000000000000000000000000020000000000000000000000000000CE0F0000000000000400000004000000 "D:\Program Files (x86)\Ubisoft\Driver San Francisco\fwecmd.exe"=0x534143500100000000000000070000002800000038010200BCF9020001000000000000000000010671020000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D8030000000000000100000001000000 "D:\Program Files (x86)\Ubisoft\Driver San Francisco\gdfcmd.exe"=0x534143500100000000000000070000002800000038A30200DCA7020001000000000000000000010671020000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000004E000000000000000100000001000000 "SIGN.MEDIA=C057BF92 setup.exe"=0x5341435001000000000000000700000028000000936247000000000001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000097CD0200000000000200000002000000 "D:\Program Files (x86)\Cities Skylines Snowfall\Cities.exe"=0x534143500100000000000000070000002800000000F826010000000001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000050000000000002062000006000000000000000000000000000000000203D1200000000000500000003000000000000002000006000000000000000000000000000000000CED50000000000000100000000000000 "D:\Program Files (x86)\Cities Skylines Snowfall\unins000.exe"=0x5341435001000000000000000700000028000000712518000000000003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000C1210000000000000200000002000000 "D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher64.exe"=0x534143500100000000000000070000002800000038BF2B001FCA2B0001000000000000000000030673220000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000005E000000000000000200000002000000 "D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"=0x5341435001000000000000000700000028000000388B23009869240001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000008000000000000000000000000000000000000000DC050000000000000200000002000000 "D:\Program Files (x86)\Ubisoft\Driver San Francisco\unins001.exe"=0x53414350010000000000000007000000280000002CFD0A000000000003000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000045110000000000000100000001000000 "D:\Program Files (x86)\F1 2013\unins000.exe"=0x5341435001000000000000000700000028000000A12611000000000003000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000014360000000000000100000001000000 "D:\Program Files (x86)\Firewatch\unins000.exe"=0x5341435001000000000000000700000028000000712518000000000003000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000060120000000000000100000001000000 "D:\Program Files (x86)\Manhunter\unins000.exe"=0x53414350010000000000000007000000280000001E050B000000000003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D6200000000000000100000001000000 "D:\Games\American Truck Simulator\unins000.exe"=0x5341435001000000000000000700000028000000712518000000000003000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000049130000000000000100000001000000 "C:\Program Files (x86)\InstallShield Installation Information\{F2835483-37F2-4123-B4FE-0E77D58447F2}\setup.exe"=0x534143500100000000000000070000002800000088C2050044E3050003000000000000000000000671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000469B0000000000000100000001000000 "D:\Program Files (x86)\Euro Truck Simulator 2\uninstall.exe"=0x5341435001000000000000000700000028000000008414000000000001000000000000000000020600010000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400002020000000000000000000000000014140000000000000200000002000000 "D:\Program Files (x86)\Project CARS\unins000.exe"=0x5341435001000000000000000700000028000000C96012000000000003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000006A180000000000000100000001000000 "C:\Users\Thomas\Documents\Armax2001 - AutoClick v1.0\AutoClick by Armax2001.exe"=0x53414350010000000000000007000000280000000036070000000000010000000000000000000206F1200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000006CDB0000000000000100000001000000 "D:\Program Files (x86)\Super macro\Super_macro.exe"=0x5341435001000000000000000700000028000000009022000000000001000000000000000000010661200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000006BD50B00000000000100000001000000 "D:\Program Files (x86)\C4D\Just Cause 3\JustCause3.exe"=0x534143500100000000000000070000002800000000D62C070000000001000000000000000000030673200000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000F0260000000000000100000001000000 "D:\Program Files (x86)\C4D\Watch_Dogs.Multi-RU.Repack.by.z10yded\setup.exe"=0x5341435001000000000000000700000028000000B67233000000000001000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000009261D00000000000200000002000000 "C:\Users\Thomas\Downloads\FunCraft Premium Setup.exe"=0x5341435001000000000000000700000028000000789B08004127090001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000063480000000000000100000001000000 "D:\Program Files (x86)\FunCraft Premium\FunCraft (Launcher Minecraft Premium).exe"=0x534143500100000000000000070000002800000030C905006EB0060001000000000000000000030671200000975FD891C99ECE01000000000000000002000000A0000000000002068000002000000000000000000000000000000000A4140600000000000A000000090000000000020680000060000000000000000000000000000000005C100000000000000100000000000000000000008000000000000000000000000000000000000000740C000000000000030000000000000000000000800000400000000000000000000000000000000061020000000000000100000000000000 "C:\Users\Thomas\Downloads\JAVA-8u45-64bits-ASCENTIA (1).exe"=0x5341435001000000000000000700000028000000600493026F0A930201000000000000000000030673220000B395E7CF049FCE010000000000000000020000002800000000000000000000400000000000000000000000000000000085CF0000000000000100000001000000 "C:\Users\Thomas\Downloads\jre-8u73-windows-x64.exe"=0x534143500100000000000000070000002800000060446703BBC2670301000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000A0D50000000000000100000001000000 "C:\Users\Thomas\Desktop\KeiNett Launcher.exe"=0x5341435001000000000000000700000028000000D1B11000F67E010001000000000000000000030671200000975FD891C99ECE010000000000000000020000002800000000000000800000000000000000000000000000000000000074050200000000000300000003000000 "D:\Program Files (x86)\C4D\Watch Dogs.(v.1.06.329).(2014) [Decepticon] RePack\Setup.exe"=0x5341435001000000000000000700000028000000BEF233000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000FDEF0000000000000100000001000000 "D:\Program Files (x86)\Watch_Dogs\Launcher.exe"=0x534143500100000000000000070000002800000000A60E000000000001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000002068000002000000000000000000000000000000000F3010A00000000000100000001000000 "D:\Program Files (x86)\Watch_Dogs\Uninstall\unins000.exe"=0x53414350010000000000000007000000280000005F2112000000000001000000000000000000020600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000020000000000000000000000000000DD240000000000000100000001000000 "D:\Program Files (x86)\Paint.the.Town.Red.v0.1.5\PaintTheTownRed.exe"=0x5341435001000000000000000700000028000000E0EF2E010000000001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000050000000000002060000002000000000000000000000000000000000F792110000000000010000000100000000000000000000000000000000000000000000000000000014430000000000000100000000000000 "C:\Users\Thomas\Desktop\FunCraft (Launcher Minecraft).exe"=0x534143500100000000000000070000002800000028C90500040E060001000000000000000000030671200000975FD891C99ECE0100000000000000000200000050000000000002068000002000000000000000000000000000000000A15A280000000000100000001000000000000000800000000000000000000000000000000000000020A00500000000000200000000000000 "D:\Program Files (x86)\Steam\steamapps\common\Life.is.Feudal.Your.Own.v1.0.0.6\Life.is.Feudal.Your.Own.v1.0.0.6\yo_cm_client.exe"=0x5341435001000000000000000700000028000000002038010000000001000000000000000000030671220000975FD891C99ECE0100000000000000000500000010000000000000000000000000000206200000000200000050000000000002062000006000000000000000000000000000000000D71F01000000000002000000020000000000000000000000000000000000000000000000000000007C100300000000000100000000000000 "D:\Program Files (x86)\SAVES ETC\Armax2001 - AutoClick v1.0\AutoClick by Armax2001.exe"=0x53414350010000000000000007000000280000000036070000000000010000000000000000000206F1200000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000020680000000000000100000001000000 "C:\Program Files\Java\jre1.8.0_73\bin\javaw.exe"=0x5341435001000000000000000700000028000000602803003C5F030001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000050000000000000000000000000000000000000000000000000000000E8B04700000000002F00000004000000000002060000000000000000000000000000000000000000EEC00000000000000300000000000000 "C:\Users\Thomas\Desktop\Spigot\start.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "D:\Program Files (x86)\TeamSpeak 3 Client\package_inst.exe"=0x5341435001000000000000000700000028000000E801070096BC070001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000075A0000000000000200000002000000 "C:\Users\Thomas\Downloads\Droid4XInstaller.exe"=0x5341435001000000000000000700000028000000A84A8500D0C9850001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000018E00800000000000100000001000000 "C:\Users\Thomas\Downloads\MEGAsyncSetup.exe"=0x5341435001000000000000000700000028000000F09F9F00A29EA00001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000030390000000000000100000001000000 "C:\ProgramData\MEGAsync\MEGAsync.exe"=0x5341435001000000000000000700000028000000C884490058654A0001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000030270000000000000300000003000000 "D:\Program Files (x86)\Factorio by Nicomouk9\bin\Win32\Factorio.exe"=0x534143500100000000000000070000002800000000C688000000000001000000000000000000030671220000975FD891C99ECE01000000000000000002000000500000000000020600000020000000000000000000000000000000009A77080000000000010000000100000000000000000000000000000000000000000000000000000063210000000000000100000000000000 "D:\Program Files (x86)\Castle Crashers by Nicomouk9\castle.exe"=0x534143500100000000000000070000002800000000EA16000000000001000000000000000000020671220000975FD891C99ECE010000000000000000020000005000000000000206000000200000000000000000000000000000000060A41A00000000000100000001000000000000000000000000000000000000000000000000000000DD7B0200000000000100000000000000 "D:\Program Files (x86)\Droid4X\Droid4X\uninst.exe"=0x5341435001000000000000000700000028000000937E0600B66F6C0D01000000000000000000000671000000975FD891C99ECE0100000000000000000200000028000000000000000008004000000000000000000000000000000000FD4B0000000000000200000002000000 "D:\Program Files (x86)\Steam\steamapps\common\Trackmania Turbo\Config.exe"=0x5341435001000000000000000700000028000000A06447005F14480001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000AD0C0100000000000100000001000000 "C:\Users\Thomas\Desktop\Spigot 1.8\start.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "D:\Program Files (x86)\Serveurs\Spigot 1.8\start.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "D:\Serveurs\Spigot 1.8\start.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "D:\Serveurs\Spigot\start.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "D:\Program Files (x86)\TubeTycoon B1.2.3\TubeTycoon.exe"=0x534143500100000000000000070000002800000000B009000000000001000000000000000000030671220000975FD891C99ECE01000000000000000002000000500000000000020600000020000000000000000000000000000000009E400B00000000000100000001000000000000000000000000000000000000000000000000000000DD390000000000000100000000000000 "C:\Users\Thomas\Downloads\project64_2-2_fr_10645.exe"=0x5341435001000000000000000700000028000000FCCD2F000000000001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000005B8D3800000000000100000001000000 "C:\Users\Thomas\AppData\Roaming\News\news.exe"=0x534143500100000000000000070000002800000000B4050093BC050001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000F8572A00000000000100000001000000 "D:\Program Files (x86)\Project64 2.2\Project64.exe"=0x534143500100000000000000070000002800000000D213000000000001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000C42A4300000000005F0000005F000000 "C:\Users\Thomas\AppData\Roaming\News\uninstall.exe"=0x53414350010000000000000007000000280000009EE002000000000003000000000000000000030600210000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000BD050000000000000100000001000000 "C:\Program Files (x86)\More Results Hub\Uninstaller.exe"=0x534143500100000000000000070000002800000020B00500707A060003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A48E0000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Chromatic\Utils\ChromaticUninstall.exe"=0x534143500100000000000000070000002800000060EE01000000000003000000000000000000010600010000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000800000000000000080000000000060530000000000000100000001000000010000000400000001000000 "D:\Program Files (x86)\ServerMania\TrackmaniaServer_2011-02-21\TrackmaniaServer.exe"=0x534143500100000000000000070000002800000000F06A0058EC690001000000000000000000010671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D6340100000000000300000003000000 "C:\Users\Thomas\Downloads\pcsx2-1.4.0-setup.exe"=0x5341435001000000000000000700000028000000602C10010000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000F0EC0000000000000100000001000000 "D:\Program Files (x86)\PCSX2 1.4.0\pcsx2.exe"=0x534143500100000000000000070000002800000000AA8B000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000050000000000002060000002000000000000000000000000000000000192B2700000000000200000002000000000000000000000000000000000000000000000000000000455A8700000000000C00000000000000 "C:\Users\Thomas\Documents\PCSX2\bios\PCSX2_0.9.8_8198.exe"=0x5341435001000000000000000700000028000000BF03C3000000000001000000000000000000010600010000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000007E970000000000000200000002000000 "D:\Program Files (x86)\PCSX2 0.9.8\pcsx2-r4600.exe"=0x534143500100000000000000070000002800000000944300D606440001000000000000000000010671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000BAA61500000000000600000006000000 "C:\Users\Thomas\Downloads\dolphin-emulator_4-0-2_fr_430789.exe"=0x534143500100000000000000070000002800000099E39A000000000001000000000000000000000671000000975FD891C99ECE0100000000000000000200000028000000000000000008004000000000000000000000000000000000850B0100000000000100000001000000 "D:\Program Files\Dolphin\Dolphin.exe"=0x534143500100000000000000070000002800000000B0CD0018C8CD0001000000000000000000020673020000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000002BB10E00000000000200000002000000 "D:\Program Files (x86)\C4D\RomStation_Setup_fr.exe"=0x53414350010000000000000007000000280000004F5C090A0000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000DC8B0500000000000100000001000000 "C:\Users\Thomas\AppData\Local\Apps\2.0\DLY8XA4W.D81\YGG88MDO.5JJ\prog...app_f09d422d3b6d863a_0001.0003_de9f895a8577734e\clickonce_bootstrap.exe"=0x5341435001000000000000000700000028000000484500008DE6000001000000000000000000030680210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B0840000000000000100000001000000 "D:\Program Files\Virtual Audio Cable\audiorepeater.exe"=0x5341435001000000000000000700000028000000B88A00002810010001000000000000000000010673000000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A61B0000000000000300000003000000 "D:\Program Files\Virtual Audio Cable\audiorepeater_ks.exe"=0x5341435001000000000000000700000028000000B8BA0000EB45010001000000000000000000010673000000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000AC270000000000000300000003000000 "D:\Program Files (x86)\C4D\rcsetup152.exe"=0x534143500100000000000000070000002800000088894300F21A440001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000034A21200000000000100000001000000 "D:\Program Files (x86)\EA Games\Need for Speed Most Wanted\unins000.exe"=0x53414350010000000000000007000000280000001EE90A000000000003000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000017110000000000000100000001000000 "D:\Program Files (x86)\GameforgeLive\Games\FRA_fra\S.K.I.L.L\unins000.exe"=0x5341435001000000000000000700000028000000C3CB13000000000003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A60E0000000000000100000001000000 "D:\Program Files (x86)\Super macro\uninst.exe"=0x53414350010000000000000007000000280000004DC100000000000003000000000000000000000671000000975FD891C99ECE010000000000000000020000002800000000000000000800000000000000000000000000000000000018090000000000000100000001000000 "D:\Program Files (x86)\Mini Metro\unins000.exe"=0x53414350010000000000000007000000280000005040140086E7140003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000008A1D0000000000000100000001000000 "D:\Program Files (x86)\GlassWire\uninstall.exe"=0x5341435001000000000000000700000028000000B06C38007FE4380003000000000000000000010600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000008000000000000000800000000000C73A0000000000000100000001000000010000000400000001000000 "C:\ProgramData\MEGAsync\uninst.exe"=0x5341435001000000000000000700000028000000088405006C72060003000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000052360000000000000100000001000000 "D:\Program Files (x86)\Bordel\Unturned Give Editor.exe"=0x534143500100000000000000070000002800000000A67F0000000000010000000000000000000306F5220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000AE460000000000000100000001000000 "D:\Program Files\Recuva\recuva64.exe"=0x5341435001000000000000000700000028000000185B4B0084C34B0001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000287A1900000000000900000009000000 "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe"=0x5341435001000000000000000700000028000000C8AAD400A5CED40003000000000000000000030671220000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000080000000000000008000000000005C080000000000000100000001000000010000000400000001000000 "D:\Program Files (x86)\C4D\GeForce_Experience_v2.11.2.65.exe"=0x5341435001000000000000000700000028000000680BAE0216D8AE0201000000000000000000020600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000000A251E00000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe"=0x5341435001000000000000000700000028000000C09F48001CE14800010000000000000000000306F1220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000EC050000000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe"=0x5341435001000000000000000700000028000000C04110005B6B100001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000008000000000000000000000000000000000000000DDA20C00000000000100000001000000 "D:\Program Files (x86)\C4D\SkypeSetup.exe"=0x534143500100000000000000070000002800000080F216003960170001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000001D80000000000000100000001000000 "C:\Program Files (x86)\Skype\Phone\Skype.exe"=0x5341435001000000000000000700000028000000802C05033BAD050301000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000003CE5B301000000009E0100009E010000 "C:\Users\Thomas\AppData\Local\Temp\Rar$EXa0.494\paint.net.4.0.9.install.exe"=0x5341435001000000000000000700000028000000B0E46A00578F6B0001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000001C530100000000000100000001000000 "D:\Program Files\paint.net\PaintDotNet.exe"=0x534143500100000000000000070000002800000048BC1A00CBAB1B0001000000000000000000030680210000B395E7CF049FCE0100000000000000000200000050000000000000000000000000000000000000000000000000000000975F1A0000000000830000006800000000000206000000000000000000000000000000000000000002B60000000000000100000000000000 "D:\Program Files (x86)\C4D\pcsx2-1.2.1-r5875-setup.exe"=0x5341435001000000000000000700000028000000E0D2E6005645E70001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000001E9F0000000000000100000001000000 "D:\Program Files (x86)\PCSX2 1.2.1\pcsx2-r5875.exe"=0x53414350010000000000000007000000280000008001520038FD520001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000BF432100000000001200000012000000 "D:\Program Files (x86)\C4D\geeditsetupeditorinstaller3.exe"=0x53414350010000000000000007000000280000007B7A9D090000000001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000064E80500000000000100000001000000 "D:\GEEdit3\gzip.exe"=0x5341435001000000000000000700000028000000000A0100674D010001000000000000000000000671200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000000F000000000000000100000001000000 "D:\GEEdit3\PerfectGold.exe"=0x534143500100000000000000070000002800000000C24B02DE0D4C0201000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000003E370300000000000400000004000000 "C:\Users\Thomas\AppData\Local\Temp\Rar$EXa0.452\Fraps 3.5.99 .exe"=0x534143500100000000000000070000002800000070742A000000000001000000000000000000010600010000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000086950400000000000100000001000000 "D:\Fraps\fraps.exe"=0x5341435001000000000000000700000028000000B8DE2600A404270001000000000000000000020671220000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040001000000000000000000000000000009FAB0400000000000300000003000000 "D:\Fraps\uninstall.exe"=0x5341435001000000000000000700000028000000FE9D00000000000003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000E5130000000000000100000001000000 "D:\Program Files (x86)\C4D\action_1_30_3_setup.exe"=0x5341435001000000000000000700000028000000E0C04A0154724B0101000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000105B0000000000000100000001000000 "C:\Program Files (x86)\Mirillis\Action!\Action.exe"=0x5341435001000000000000000700000028000000D0221201C89D120101000000000000000000030671220000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000034472C00000000000700000007000000 "C:\Users\Thomas\AppData\Local\Temp\7zS8E86.tmp\setup-stub.exe"=0x5341435001000000000000000700000028000000188E0F00C1DC0F0001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000C00000000000000000000000000000000036C20000000000000100000001000000 "D:\Program Files (x86)\TechSmith\Camtasia Studio 7\CamtasiaStudio.exe"=0x534143500100000000000000070000002800000058575C004C995C0001000000000000000000010671220000975FD891C99ECE010000000000000000020000002800000000000000000000100000000000000000000000000000000006C70400000000000200000002000000 "C:\Users\Thomas\AppData\Local\Temp\Rar$EXa0.352\Mirillis Action! 1.18.0 BY LastxGamer\action_1_18_0_setup.exe"=0x534143500100000000000000070000002800000020573A011DCE3A0101000000000000000000010600010000975FD891C99ECE010000000000000000 "D:\Program Files (x86)\Mirillis\Action!\Action.exe"=0x534143500100000000000000070000002800000000701301B035140101000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000F74B0B00000000000300000003000000 "D:\Program Files (x86)\Mirillis\Action!\Uninstall.exe"=0x5341435001000000000000000700000028000000F11407001DCE3A0103000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D2330000000000000100000001000000 "D:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe"=0x534143500100000000000000070000002800000080E20400F504050001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000BE870000000000000100000001000000 "D:\Program Files (x86)\PCSX2 1.2.1\Uninst-pcsx2-r5875.exe"=0x5341435001000000000000000700000028000000850301005645E70003000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000064330000000000000100000001000000 "D:\Program Files\MotioninJoy\unins000.exe"=0x5341435001000000000000000700000028000000C3E711000000000003000000000000000000010600010000975FD891C99ECE010000000000000000 "D:\Program Files (x86)\C4D\PCSX2_0.9.8_8198.exe"=0x5341435001000000000000000700000028000000BF03C3000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000F89A0000000000000100000001000000 "D:\Program Files (x86)\PCSX2 0.9.8\Uninst-pcsx2-r4600.exe"=0x53414350010000000000000007000000280000004B0301000000000003000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000079130000000000000100000001000000 "D:\Program Files (x86)\C4D\pcsx2-1.2.1-r5875-websetup.exe"=0x534143500100000000000000070000002800000048A23D00525F3E0001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000C4520000000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\SourceSDK\bin\SDKLauncher.exe"=0x5341435001000000000000000700000028000000800B0D0076580D0001000000000000000000010600010000975FD891C99ECE0100000000000000000200000050000000000002068000002000000000000000000000000000000000A30C0000000000000200000002000000000000008000000000000000000000000000000000000000D20C0000000000000100000000000000 "C:\Users\Thomas\AppData\Local\Apps\2.0\DLY8XA4W.D81\YGG88MDO.5JJ\pcmf..tion_c1e7c94c1be0ad92_0002.0001_506a9e03f002d25d\PCM Fast Editor.exe"=0x534143500100000000000000070000002800000000480B0000000000010000000000000000000106F5020000B395E7CF049FCE010000000000000000020000002800000000000000000000000000000000000000000000000000000074410200000000000100000001000000 "D:\Program Files (x86)\Pro Cycling Manager 2015\CTStageEditor.exe"=0x534143500100000000000000070000002800000070FDC1000944C20001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000092090400000000000100000001000000 "D:\Program Files (x86)\Mirillis\Action!\actionc.exe"=0x534143500100000000000000070000002800000000701301B035140101000000000000000000030671220000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000D7E73300000000000900000009000000 "D:\Program Files (x86)\C4D\gimp-2.8.16-setup-2.exe"=0x5341435001000000000000000700000028000000586BC505BE27C60501000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000004DD50100000000000100000001000000 "D:\Program Files (x86)\GIMP 2\bin\gimp-2.8.exe"=0x534143500100000000000000070000002800000088CB53002C54540001000000000000000000030600210000B395E7CF049FCE010000000000000000020000002800000000000000000000100000000000000000000000000000000016863F00000000000800000008000000 "D:\Program Files (x86)\Door Kickers\unins000.exe"=0x5341435001000000000000000700000028000000504014006335150003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000FC460000000000000100000001000000 "C:\Program Files (x86)\InstallShield Installation Information\{D596980D-17BE-4425-B8F0-5640719AADE9}\setup.exe"=0x534143500100000000000000070000002800000040D504003500050003000000000000000000000671020000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000B3330000000000000100000001000000 "C:\Program Files (x86)\LINE\LINE.exe"=0x5341435001000000000000000700000028000000E82D0F01A53A0F0101000000000000000000030671200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000007D22A801000000001000000010000000 "D:\Serveurs\Vanilla 1.8\start.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "D:\Program Files (x86)\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe"=0x5341435001000000000000000700000028000000003A0200E63C010001000000000000000000030600210000975FD891C99ECE0100000000000000000500000010000000000000000000000000000106200000000200000028000000000001062000006000000000000000000000000000000000AEA91700000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\ManiaPlanet_TMCanyon\ManiaPlanet.exe"=0x5341435001000000000000000700000028000000A8B6430190B8430101000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000711C0000000000000100000001000000 "D:\Program Files (x86)\C4D\iobituninstaller.exe"=0x5341435001000000000000000700000028000000208FC8006C6DC90001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000BC550100000000000100000001000000 "D:\Program Files (x86)\C4D\IGG-BeamNG.drive.v0.5.1\BeamNG.drive.exe"=0x5341435001000000000000000700000028000000003E0B008A150C0001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000510A0000000000000400000004000000 "D:\Program Files (x86)\C4D\IGG-BeamNG.drive.v0.5.1\IGG-BeamNG.drive.v0.5.1\BeamNG.drive.exe"=0x5341435001000000000000000700000028000000003E0B008A150C0001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000053C60200000000000100000001000000 "D:\Program Files (x86)\C4D\IGG-BeamNG.drive.v0.5.1\IGG-BeamNG.drive.v0.5.1\BeamNG.drive.x64.exe"=0x53414350010000000000000007000000280000000088630155CE630101000000000000000000030600210000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000003A690000000000000100000001000000 "D:\Program Files (x86)\C4D\IGG-BeamNG.drive.v0.5.1\Bin64\BeamNG.drive.x64.exe"=0x53414350010000000000000007000000280000000088630155CE630101000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000FC0A0000000000000100000001000000 "D:\Program Files (x86)\C4D\IGG-BeamNG.drive.v0.5.1\Bin32\BeamNG.drive.x86.exe"=0x5341435001000000000000000700000028000000002E1901414D190101000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B91D0000000000000100000001000000 "SIGN.MEDIA=91F9D8FC setup.exe"=0x5341435001000000000000000700000028000000920951000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A7E20F00000000000200000002000000 "D:\Program Files (x86)\Assetto Corsa\AssettoCorsa.exe"=0x534143500100000000000000070000002800000000FE4F0000000000010000000000000000000306F1220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B1BB0300000000000100000001000000 "D:\Program Files (x86)\Assetto Corsa\unins000.exe"=0x5341435001000000000000000700000028000000D1C212000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B9730000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Temp\GUM6F53.tmp\GoogleUpdateSetup.exe"=0x534143500100000000000000070000002800000050120F00AD530F0001000000000000000000030600210000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000750B0100000000000100000001000000 "D:\Program Files (x86)\Google\Chrome\Application\chrome.exe"=0x534143500100000000000000070000002800000098720D00E59A0D0001000000000000000000030600210000975FD891C99ECE010000000100000000 "C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe"=0x534143500100000000000000070000002800000020815000D422510001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000009BE80000000000000300000003000000 "D:\Serveurs\Vanilla 1.10\start.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "C:\Users\Thomas\Downloads\flashplayer21_xa_install.exe"=0x5341435001000000000000000700000028000000D036120039F8120001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000089950000000000000100000001000000 "D:\Serveurs\Spigot 1.9.2\start.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "D:\Program Files (x86)\Playlist Bot\Playlist Bot\NBTExplorer-2.7.6.msi"=0x534143500100000000000000070000002800000000EA0000AA51010001000000000000000000010500100000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000ECE40100000000000100000001000000 "D:\Program Files (x86)\C4D\GoogleEarthSetup.exe"=0x534143500100000000000000070000002800000050120F00AD530F0001000000000000000000030600210000975FD891C99ECE01000000800000000002000000280000000000000000000000000000000000000000000000000000009CA40000000000000100000001000000 "D:\RomStation\RomStation.exe"=0x534143500100000000000000070000002800000000AC1D000000000001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000090992100000000000200000002000000 "D:\Program Files (x86)\C4D\ZHPDiag3.exe"=0x534143500100000000000000070000002800000000C821002960220001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000ACD30000000000000400000004000000 "D:\Program Files (x86)\C4D\ZHPCleaner.exe"=0x534143500100000000000000070000002800000000A42200DCFB220001000000000000000000030600210000975FD891C99ECE010000000000000000 "D:\Program Files (x86)\C4D\ZHPFix.exe"=0x534143500100000000000000070000002800000051BC35000000000001000000000000000000030641220000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000056450000000000000100000001000000 "D:\Program Files (x86)\ZHPFix\ZHPhep.exe"=0x534143500100000000000000070000002800000000421D000000000001000000000000000000020671220000975FD891C99ECE010000000000000000 "D:\Program Files (x86)\C4D\AZ_Minecraft_Launcher.exe"=0x53414350010000000000000007000000280000004FE30700DA8E040001000000000000000000030671200000975FD891C99ECE010000000000000000020000002800000000000206800000000000000000000000000000000000000010850300000000000100000001000000 "D:\Program Files (x86)\C4D\Gyazo-3.2.3.exe"=0x5341435001000000000000000700000028000000200EEF00531EEF0001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000002060000000000000000000000000000000000000000B86C7C00000000000100000001000000 "C:\Program Files (x86)\Gyazo\Gyazowin.exe"=0x5341435001000000000000000700000028000000209D08002549090001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000CB2F0000000000000400000004000000 "D:\Program Files (x86)\C4D\setup-lightshot.exe"=0x5341435001000000000000000700000028000000689C26001435270001000000000000000000030600210000975FD891C99ECE010000000000000000 "D:\Program Files (x86)\Splinter Cell Conviction\Tom Clancy's Splinter Cell Conviction\play-Prison in Portland.exe"=0x5341435001000000000000000700000028000000482007000000000001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000080000000000000000000000000000000000000000D591700000000000600000006000000 "D:\Program Files (x86)\Splinter Cell Conviction\Tom Clancy's Splinter Cell Conviction\play-New Orleans cemetery.exe"=0x53414350010000000000000007000000280000004A2007000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000008000000000000000000000000000000000000000B2CA1700000000000200000002000000 "D:\Program Files (x86)\Splinter Cell Conviction\Tom Clancy's Splinter Cell Conviction\play-Salt Lake City.exe"=0x53414350010000000000000007000000280000004D2007000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000008000000000000000000000000000000000000000CA111900000000000200000002000000 "D:\Program Files (x86)\Playlist Bot\Playlist Bot\flashplayer22au_ga_install.exe"=0x5341435001000000000000000700000028000000D036120018B8120001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000002060000000000000000000000000000000000000000F3483400000000000100000001000000 "SIGN.MEDIA=36D9F8 setup.exe"=0x5341435001000000000000000700000028000000B0270F00713A0F0001000000000000000000010600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000BB370300000000000100000001000000 "SIGN.MEDIA=9C43FB08 Setup.exe"=0x5341435001000000000000000700000028000000D72A63000000000001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000086B73F00000000000200000002000000 "D:\Program Files (x86)\Focus Home Interactive\Pro Cycling Manager 2016\PCM.exe"=0x5341435001000000000000000700000028000000309DAD00643CAE0001000000000000000000030671220000975FD891C99ECE01000000000000000002000000500000000000020600000020100000000000000000000000000000007CCE0D00000000000500000005000000000000000000000000000000000000000000000000000000B4E60700000000000200000000000000 "D:\Program Files (x86)\Steam\steamapps\common\Survarium\downloads\torrent\survarium-web-installer-042b6.exe"=0x5341435001000000000000000700000028000000484726001B14270001000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000800000400000000000000000000000000000000062371900000000000100000001000000 "D:\Serveurs\Spigot 1.10\start.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "C:\Program Files\McAfee Security Scan\uninstall.exe"=0x5341435001000000000000000700000028000000F0CF0500C455060003000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000007F460000000000000100000001000000 "D:\Program Files (x86)\Pro Cycling Manager 2015\unins000.exe"=0x5341435001000000000000000700000028000000712518000000000003000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000043500000000000000100000001000000 "D:\Program Files (x86)\Survarium\unins000.exe"=0x5341435001000000000000000700000028000000587A14009FB2140003000000000000000000020600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000C3A80000000000000100000001000000 "C:\Users\Thomas\Desktop\tools\NativeUpdater.exe"=0x5341435001000000000000000700000028000000881304004E12050001000000000000000000030671220000975FD891C99ECE010000008000000000020000002800000000000000000000000000000000000000000000000000000000000000000000000200000002000000 "D:\Program Files (x86)\Minecraft\MinecraftLauncher.exe"=0x534143500100000000000000070000002800000088091300F7AC130001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000002068000002000000000000000000000000000000000E06A5601000000002C0100002C010000 "D:\Serveurs\Spigot 1.10\start2.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "D:\Serveurs\CS GO\steamcmd.exe"=0x5341435001000000000000000700000028000000A8BF190028E8190001000000000000000000020671020000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000063AA1F00000000000100000001000000 "D:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe"=0x5341435001000000000000000700000028000000F8D621062580220601000000000000000000030673220000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000001EF13D00000000000800000008000000 "D:\Program Files (x86)\C4D\3DMGAME-Planetbase.v1.0.5.Cracked-3DM\Planetbase\Planetbase.exe"=0x5341435001000000000000000700000028000000D83DF1009A88F10001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000000000000000000040000000000000000000000000F2841D00000000000100000001000000 "D:\Program Files (x86)\C4D\ARK.Survival.Evolved.build.238.3\Setup.exe"=0x53414350010000000000000007000000280000000FC539000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000D0F70600000000000200000002000000 "D:\Program Files (x86)\Planetbase v.1.2.0 CTGG\Planetbase.exe"=0x5341435001000000000000000700000028000000D83DF1009A88F10001000000000000000000030671200000975FD891C99ECE010000000000000000020000007800000000000206008000200000000000000000000000000000000009D8330000000000030000000300000000000000008000200000000000000000000000000000000044DE360000000000020000000000000000000000000000000000004000000000000000000000000055B50000000000000100000000000000 "D:\Program Files (x86)\Ravenfield\ravenfield.exe"=0x5341435001000000000000000700000028000000009400010000000001000000000000000000030600210000975FD891C99ECE010000000000000000020000005000000000000206000000200000000000000000000000000000000020C110000000000009000000090000000000000000000000000000000000000000000000000000003B610000000000000200000000000000 "D:\Program Files (x86)\Castle Crashers\castle.exe"=0x534143500100000000000000070000002800000000EA16000000000001000000000000000000020671220000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000095786400000000001700000017000000 "D:\Program Files (x86)\Origin Games\Need for Speed\NFS16.exe"=0x534143500100000000000000070000002800000020AB5806887F590601000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000863D0000000000000200000002000000 "D:\Program Files (x86)\Steam\steamapps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe"=0x5341435001000000000000000700000028000000E0AA33010E86340101000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000C8610000000000000200000002000000 "D:\Program Files (x86)\F1 2013\Uninstall.exe"=0x53414350010000000000000007000000280000008E4701000000000001000000000000000000010600010000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400002000000000000000000000000000044140000000000000100000001000000 "SIGN.MEDIA=30DE95D OriginSetup.exe"=0x534143500100000000000000070000002800000000B661000000000001000000000000000000030661200000975FD891C99ECE010000000000000000020000002800000000000000000800400000000000000000000000000000000034A70500000000000100000001000000 "D:\Program Files (x86)\FIFA 15\fifa15.exe"=0x5341435001000000000000000700000028000000D09D3305C677340501000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000002060000002000000000000000000000000000000000ADBF4700000000001F0000001F000000 "D:\Program Files (x86)\FIFA 15\fifasetup\fifaconfig.exe"=0x534143500100000000000000070000002800000018D30500094B060001000000000000000000010680010000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A1DA0000000000000100000001000000 "C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe"=0x5341435001000000000000000700000028000000007503004177030001000000000000000000000671020000975FD891C99ECE010000000000000000 "D:\Program Files (x86)\C4D\SimCity_RePack by SEYTER\setup.exe"=0x5341435001000000000000000700000028000000FB8B22000000000001000000000000000000010600010000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000400000000000000000000000000000000075680200000000000200000002000000 "SIGN.MEDIA=68AB864 WIN95\MAXIS.EXE"=0x5341435001000000000000000700000028000000001E0D000000000001000000000000000000010551200000975FD891C99ECE01000000000000000002000000280000000000000000000000000002000000000000000000000000006A250000000000000200000002000000 "SIGN.MEDIA=2B051F2 WIN95\SC2K\SIMCITY.EXE"=0x5341435001000000000000000700000028000000000214000000000001000000000000000000010551200000975FD891C99ECE0100000000000000000500000010000000000000000000000000020105010000000200000050000000000201050100006000040000000000000000000000000000B43000000000000001000000010000000000000000000000000002000000000000000000000000005C440000000000000200000000000000 "D:\Program Files (x86)\C4D\songbird_2-2-0-2453_fr_18790.exe"=0x5341435001000000000000000700000028000000A8D4F000B3B1F10001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000029CF0300000000000100000001000000 "C:\Program Files\NVIDIA Corporation\Control Panel Client\nvcplui.exe"=0x534143500100000000000000070000002800000040CF680035C4690001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000ED170000000000000200000002000000 "D:\Program Files (x86)\Songbird\songbird.exe"=0x53414350010000000000000007000000280000000002120096F4120001000000000000000000010671000000975FD891C99ECE010000000000000000020000002800000000000206000000200000000000000000000000000000000003757402000000008400000084000000 "C:\Users\Thomas\AppData\Local\Temp\Rar$EXa0.410\Songr_1_9_2398_Setup.exe"=0x53414350010000000000000007000000280000003B035D000000000001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000097830000000000000100000001000000 "D:\Program Files (x86)\Serveur CSGO\steamcmd.exe"=0x5341435001000000000000000700000028000000A8BF190028E8190001000000000000000000020671020000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000006F0D6900000000000100000001000000 "D:\Program Files (x86)\Serveur CSGO\SteamCMD GUI.exe"=0x53414350010000000000000007000000280000000028070000000000010000000000000000000306F1220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D60C1600000000000200000002000000 "D:\Program Files (x86)\C4D\Universe_Sandbox_2_Alpha_19_setup.exe"=0x5341435001000000000000000700000028000000E13544360000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000280A0200000000000100000001000000 "D:\Program Files (x86)\Universe Sandbox 2\LAUNCHER.exe"=0x5341435001000000000000000700000028000000008C0300F40A040001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000206800000200000000000000000000000000000000055AE0900000000000600000006000000 "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayService.exe"=0x5341435001000000000000000700000028000000C80424003E94240001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000080000000000000000000000000000000000000002E510000000000000100000001000000 "D:\Program Files (x86)\C4D\GoldenEye_Source_v5.0_full.exe"=0x534143500100000000000000070000002800000051EA8481FB8B040001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000CA220000000000000100000001000000 "D:\Program Files (x86)\GoldenEye\GoldenEye_Source_v5.0_full.exe"=0x534143500100000000000000070000002800000051EA8481FB8B040001000000000000000000010600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000B27C0D00000000000700000007000000 "D:\Program Files (x86)\GoldenEye\GoldenEye_Source_full.exe"=0x53414350010000000000000007000000280000004A9E67000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000A3FC0600000000000200000002000000 "D:\Program Files (x86)\Steam\steamapps\sourcemods\gesource_run.exe"=0x5341435001000000000000000700000028000000B9A700000000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000009C000000000000000800000008000000 "D:\Program Files (x86)\BeamNG Drive\BeamNG.drive v0.6.0.0.2707\BeamNG.drive.exe"=0x534143500100000000000000070000002800000000200E00324A0E0001000000000000000000030600210000975FD891C99ECE01000000000000000002000000500000000000020600000020000000000000000000000000000000005E4D08000000000001000000010000000000000000000000000000000000000000000000000000003A130000000000000100000000000000 "C:\Users\Thomas\Desktop\Windows Shortcut Arrow Editor by Les Deux Blogueurs\Windows 8\x64\WindowsShortcutArrowEditor By Les Deux Blogueurs.exe"=0x534143500100000000000000070000002800000000EA030000000000010000000000000000000206F3020000B395E7CF049FCE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000355A0000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Songr\Songr.exe"=0x534143500100000000000000070000002800000000C8080000000000010000000000000000000306F1220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000298C0200000000002000000020000000 "D:\Program Files (x86)\Songbird\Songbird-Uninstall.exe"=0x53414350010000000000000007000000280000003B370700B3B1F10001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000F1400000000000000400000004000000 "D:\Program Files (x86)\ZHPFix\ZHPFix.exe"=0x534143500100000000000000070000002800000000B82E000000000001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D61A0100000000000100000001000000 "D:\Playlist Bot\Playlist Bot\Songbird_2.2.0-2453_windows-i686-msvc8.exe"=0x5341435001000000000000000700000028000000A8D4F000B3B1F10001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000026C40100000000000100000001000000 "D:\Playlist Bot\Playlist Bot\Synthesia-10.3-installer.exe"=0x53414350010000000000000007000000280000005845320019AE320001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000005F1F0000000000000100000001000000 "D:\Playlist Bot\Playlist Bot\synthesia-9.0-installer.exe"=0x5341435001000000000000000700000028000000D80E2B00541D2B0001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000088900000000000000100000001000000 "C:\Program Files (x86)\Synthesia\Synthesia.9.x-patch.exe"=0x534143500100000000000000070000002800000000320500DDEC000001000000000000000000010671020000975FD891C99ECE0100000080000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000B64F0000000000000300000003000000 "C:\Program Files (x86)\Synthesia\Synthesia.exe"=0x534143500100000000000000070000002800000010848600540B870001000000000000000000020671000000975FD891C99ECE0100000000000000000200000028000000000002060000002000000000000000000000000000000000A3630200000000000800000008000000 "D:\Program Files (x86)\Steam\steamapps\common\Prison Architect\Prison Architect.exe"=0x5341435001000000000000000700000028000000905856000000000001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000FC050000000000000300000003000000 "SIGN.MEDIA=3CCC29D6 setup.exe"=0x5341435001000000000000000700000028000000EA6E0A000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B5B70700000000000100000001000000 "D:\Program Files (x86)\Outlast\OutlastLauncher.exe"=0x534143500100000000000000070000002800000000CC0000E353010001000000000000000000030671220000975FD891C99ECE01000000000000000002000000500000000000020680000020000000000000000000000000000000004B441400000000000400000004000000000000008000000000000000000000000000000000000000E66E0000000000000100000000000000 "D:\Program Files (x86)\Outlast\Binaries\Win64\OLGame.exe"=0x534143500100000000000000070000002800000000320A02500C0B0201000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000E4482A00000000001100000011000000 "C:\Program Files (x86)\Gyazo\unins000.exe"=0x5341435001000000000000000700000028000000305F12009925130001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B4380000000000000100000001000000 "SIGN.MEDIA=D6C23559 setup.exe"=0x5341435001000000000000000700000028000000287712000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000E50D4D00000000000500000005000000 "D:\Program Files (x86)\Need for Speed World\nfssetup.exe"=0x5341435001000000000000000700000028000000F00C5A003E1F5A0001000000000000000000010600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000F6120100000000000100000001000000 "D:\Program Files (x86)\Need for Speed World\data\nfsw.exe"=0x53414350010000000000000007000000280000001025A3005CB3A30001000000000000000000010671200000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000038230000000000000100000001000000 "D:\Program Files (x86)\Electronic Arts\Need For Speed World\GameLauncher.exe"=0x53414350010000000000000007000000280000001085190073BA1900010000000000000000000106F1220000975FD891C99ECE01000000000000000002000000280000000000000080000000000000000000000000000000000000006E6F0100000000000100000001000000 "D:\Program Files (x86)\SEGA\Alien - Isolation\AI.exe"=0x534143500100000000000000070000002800000000FC4C012F4B4D0101000000000000000000030671220000975FD891C99ECE0100000000000000000200000078000000000002060000002000000000000000000000000000000000ADE67F000000000002000000020000000000000000000000000000000000000000000000000000005F05000000000000030000000000000000000000000000400000000000000000000000000000000071020000000000000100000000000000 "D:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe"=0x5341435001000000000000000700000028000000003602002D61020001000000000000000000020600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000AA852B00000000000200000002000000 "C:\Users\Thomas\AppData\Local\Temp\jre-8u111-windows-au.exe"=0x534143500100000000000000070000002800000040420B0047080C0001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000062FC0000000000000100000001000000 "D:\Program Files (x86)\ARK - Survival Evolved\unins000.exe"=0x5341435001000000000000000700000028000000C51C18000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D4030100000000000100000001000000 "D:\Playlist Bot\Playlist Bot\audacity_2-1-0_fr_10372.exe"=0x53414350010000000000000007000000280000005F5080010000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000007C280900000000000100000001000000 "D:\Playlist Bot\Playlist Bot\SWTOR_setup.exe"=0x5341435001000000000000000700000028000000807DC5018352C60101000000000000000000000671000000975FD891C99ECE01000000000000000002000000280000000000000000080040000000000000000000000000000000004C240100000000000100000001000000 "D:\Program Files (x86)\Electronic Arts\Star Wars TOR\launcher.exe"=0x5341435001000000000000000700000028000000B0C13C00FFB03D0001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000800000000000000000000000000000000000000022420800000000000200000002000000 "D:\Program Files (x86)\Origin Games\STAR WARS Battlefront\__Installer\Cleanup.exe"=0x5341435001000000000000000700000028000000E0470E00A49B0E0001000000000000000000020600010000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000000F000000000000000100000001000000 "C:\Program Files (x86)\Common Files\EAInstaller\STAR WARS Battlefront\Cleanup.exe"=0x5341435001000000000000000700000028000000E0470E00A49B0E0003000000000000000000020600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B61B0000000000000100000001000000 "SIGN.MEDIA=DBB8CF8F Setup.exe"=0x5341435001000000000000000700000028000000004A36000000000001000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000046DF1401000000000200000002000000 "D:\Program Files (x86)\C4D\neighbor\HelloNeighbor\HelloNeighbour.exe"=0x534143500100000000000000070000002800000000B60500EE21020001000000000000000000030673200000B395E7CF049FCE0100000000000000000200000050000000000002060000002000000000000000000000000000000000CE28080000000000010000000100000000000000000000000000000000000000000000000000000029FB0000000000000600000000000000 "SIGN.MEDIA=1D1304 HiSuiteDownLoader.exe"=0x5341435001000000000000000700000028000000C8DA1D009C1D1E0001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000605B0300000000000300000003000000 "D:\Program Files (x86)\C4D\minecraft_test_launcher\Minecraft_staging.exe"=0x534143500100000000000000070000002800000080B75002BF91510201000000000000000000030671200000975FD891C99ECE010000000000000000020000005000000000000206000000200000000000000000000000000000000077547A00000000000D0000000D0000000000000000000000000000000000000000000000000000007CF90800000000000200000000000000 "D:\Program Files (x86)\C&C Alerte Rouge\RA1MPLauncher.exe"=0x534143500100000000000000070000002800000000F2040000000000010000000000000000000306F5220000B395E7CF049FCE010000000000000000020000002800000000000206000000200000000000000000000000000000000002732000000000000A0000000A000000 "C:\Users\Thomas\AppData\Local\Temp\Rar$EXa0.958\shexview.exe"=0x534143500100000000000000070000002800000060D60000238F010001000000000000000000030600210000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000E68C0500000000000100000001000000 "C:\ProgramData\BitRaider\common\brwc.exe"=0x534143500100000000000000070000002800000000037D00AB337D0003000000000000000000030600210000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000000000000000000000000000000000000004A0B0000000000000100000001000000 "D:\Program Files (x86)\Steam\uninstall.exe"=0x5341435001000000000000000700000028000000082B0300F483030001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000066D00200000000000200000002000000 "D:\Playlist Bot\Playlist Bot\FRST64.exe"=0x534143500100000000000000070000002800000000C22400D4F7240001000000000000000000030600210000B395E7CF049FCE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000D5D40000000000000200000002000000 "C:\Users\Thomas\Desktop\FRST64.exe"=0x534143500100000000000000070000002800000000C22400D4F7240001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000C84B5101000000000100000001000000 "D:\Program Files (x86)\New Launcher\Minecraft_staging.exe"=0x534143500100000000000000070000002800000080B75002BF91510201000000000000000000030671200000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000034DE0800000000000300000003000000 "SIGN.MEDIA=6998313B setup.exe"=0x534143500100000000000000070000002800000012B32F000000000001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000004D820700000000000100000001000000 "D:\Program Files (x86)\City Car Driving\bin\win32\Starter.exe"=0x53414350010000000000000007000000280000000080070053FF070001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000200000600000000000000000000000000000000065380A00000000000100000001000000 "D:\Program Files (x86)\City Car Driving\unins000.exe"=0x5341435001000000000000000700000028000000712518000000000003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B0500000000000000100000001000000 "D:\Playlist Bot\Playlist Bot\SteamSetup.exe"=0x534143500100000000000000070000002800000088131600052B160001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000033500000000000000100000001000000 "D:\Playlist Bot\Playlist Bot\CitraSetup.exe"=0x534143500100000000000000070000002800000000E885010000000001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000091210000000000000100000001000000 "C:\Program Files\Java\jre1.8.0_111\bin\javaw.exe"=0x53414350010000000000000007000000280000004028030022C8030001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000AE812200000000000300000003000000 "C:\Users\Thomas\AppData\Local\LINE\bin\LineLauncher.exe"=0x5341435001000000000000000700000028000000D05109009E390A0001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000800000000000000000000000000000000000000062CE4B01000000000800000008000000 "D:\Program Files (x86)\SEGA\Alien - Isolation\unins000.exe"=0x5341435001000000000000000700000028000000C96112000000000003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000009FF70000000000000100000001000000 "C:\Program Files (x86)\Common Files\EAInstaller\Need for Speed\Cleanup.exe"=0x5341435001000000000000000700000028000000E0470E0015B80E0003000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000044210000000000000100000001000000 "D:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe"=0x534143500100000000000000070000002800000018FB9600F0F5970001000000000000000000030671220000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000004000002000000280000000000000000040060000000000000000000000000000000006A9F2602000000005D0000005D000000 "D:\Program Files (x86)\American Truck Simulator\American Truck Simulator\bin\win_x64\amtrucks.exe"=0x534143500100000000000000070000002800000000BC2C0141D42F0101000000000000000000030600210000B395E7CF049FCE0100000000000000000500000010000000000000000000000000000206000000000200000050000000000002060000006000000000000000000000000000000000ED3A1C00000000000100000001000000000000000000000000000000000000000000000000000000EB770100000000000100000000000000 "D:\Program Files (x86)\Steam\steamapps\common\Geometry Dash\GeometryDash.exe"=0x5341435001000000000000000700000028000000007C66000000000001000000000000000000030671220000975FD891C99ECE0100000000000000000500000010000000000000000000000000000206200000000200000028000000000002062000006000000000000000000000000000000000E9C23000000000000A0000000A000000 "D:\Program Files (x86)\Origin\legacyPM\OriginLegacyCLI.exe"=0x534143500100000000000000070000002800000070AD0C00F9F30C0001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002F000000000000000400000004000000 "D:\Program Files (x86)\Origin Games\Star Wars Battlefront\STAR WARS Battlefront\starwarsbattlefront.exe"=0x5341435001000000000000000700000028000000F828C10654A8C10601000000000000000000030673220000B395E7CF049FCE010000000000000000020000002800000000000000000000001000000000000000000000000000000034E21000000000000700000007000000 "D:\Playlist Bot\Playlist bot\Apache_OpenOffice_4.1.3_Win_x86_install_fr.exe"=0x534143500100000000000000070000002800000066CAE3070000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000006DC10300000000000100000001000000 "D:\Program Files (x86)\OpenOffice 4\program\soffice.exe"=0x5341435001000000000000000700000028000000001A9600A653960001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000001000000000000000000000000000000000426F0700000000000500000005000000 "D:\Playlist Bot\Playlist bot\UplayInstaller.exe"=0x5341435001000000000000000700000028000000E89DC50394EAC50301000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000A234C801000000000100000001000000 "D:\Playlist Bot\Playlist bot\EF_INSTALLER.exe"=0x53414350010000000000000007000000280000000030D40A0000000001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000036A30300000000000100000001000000 "D:\Playlist Bot\Playlist bot\EFPatch1.1.1.exe"=0x534143500100000000000000070000002800000000187902C77B790201000000000000000000030671220000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000D8D70200000000000100000001000000 "D:\Program Files (x86)\LucasArts\Star Wars Galactic Battlegrounds\Game\battlegrounds_x2.exe"=0x534143500100000000000000070000002800000000702B000000000001000000000000000000010571000000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000A00000000000020600800020004400000000000000000000000000005E6205010000000026000000260000000000020600000020006402400000000000000000000000001F204E00000000000200000000000000000000000000000000000000000000000000000000000000A6710000000000000A0000000000000000000000000000400000000000000000000000000000000095090000000000000100000000000000 "D:\Program Files (x86)\LucasArts\Star Wars Galactic Battlegrounds\Game\configurator.exe"=0x5341435001000000000000000700000028000000000C0000378D000001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000BC0D0000000000000200000002000000 "D:\Program Files (x86)\Steam\steamapps\common\Tom Clancy's Rainbow Six Siege\rainbowsix.exe"=0x5341435001000000000000000700000028000000087A0D002BC10D0001000000000000000000030671200000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000023020000000000000100000001000000 "D:\Program Files (x86)\TmUnitedForever\TMUnlimiterConfigurator.exe"=0x534143500100000000000000070000002800000000FC040000000000010000000000000000000306F1220000975FD891C99ECE0100000000000000000200000050000000000000000000004000000000000000000000000000000000FE1C0000000000000100000001000000000000000000000000000000000000000000000000000000FB680000000000000700000000000000 "D:\Program Files (x86)\TmUnitedForever\TMUnlimiter.exe"=0x5341435001000000000000000700000028000000007A01009F15020001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000072C88000000000001400000014000000 "C:\Program Files (x86)\Synthesia\uninstall.exe"=0x5341435001000000000000000700000028000000D9CB0000541D2B0003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000510A0000000000000100000001000000 "D:\Program Files (x86)\C4D\The Sims 4 [FitGirl Repack]\setup.exe"=0x534143500100000000000000070000002800000087726A000000000001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000059474F00000000000100000001000000 "D:\Program Files (x86)\C4D\The Sims 4 [FitGirl Repack]\Verify BIN files before installation.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "D:\Games\The Sims 4\Game\Bin\TS4.exe"=0x534143500100000000000000070000002800000000D63E010000000001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000200000600000000000000000000000000000000024E82300000000000200000002000000 "D:\Games\The Sims 4\Game\Bin\TS4_x64.exe"=0x534143500100000000000000070000002800000000149C010000000001000000000000000000030600210000B395E7CF049FCE010000000000000000020000002800000000000000200000600000000000000000000000000000000014A10A01000000000C0000000C000000 "SIGN.MEDIA=B90B5085 setup.exe"=0x53414350010000000000000007000000280000005E750B000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000020200000000000000000000000000AE750D00000000000400000004000000 "D:\Program Files (x86)\Sniper Elite 3\bin\SniperElite3.exe"=0x534143500100000000000000070000002800000018539A007E2A9B0001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000020600000020000000000000000000000000000000008ACA4700000000000600000006000000 "D:\Program Files (x86)\Sniper Elite 3\bin\SniperElite3_Mantle.exe"=0x5341435001000000000000000700000028000000187B9F002624A00001000000000000000000030671200000975FD891C99ECE010000000000000000 "D:\Playlist Bot\Playlist bot\mumble-1.2.19_plus_MumbleComSkin.exe"=0x5341435001000000000000000700000028000000A0DCEA008F65EB0001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000B9D44100000000000100000001000000 "D:\Program Files (x86)\Mumble\mumble.exe"=0x5341435001000000000000000700000028000000903F57007FDF570001000000000000000000010600010000975FD891C99ECE010000000000000000 "D:\Program Files (x86)\C4D\02.Sniper.Elite.V2.v.1.14.Ru.En.Multi7.Steam.Rip.by.R.G.Origins\setup.exe"=0x534143500100000000000000070000002800000067560D000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D7F50700000000000100000001000000 "D:\Program Files (x86)\Rebellion\Sniper Elite V2\bin\SniperEliteV2.exe"=0x5341435001000000000000000700000028000000001A6C0074CA6C0001000000000000000000020671020000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000040000000000000000000000000000000008B00140000000000010000000100000000000000000000000000000000000000000000000000000086E62B00000000000500000000000000 "D:\Program Files (x86)\Cyanide - PCM 2016\Pro Cycling Manager 2016\PCM.exe"=0x5341435001000000000000000700000028000000309DAD00643CAE0001000000000000000000030671220000975FD891C99ECE0100000000000000000200000050000000000002060000002000000000000000000000000000000000F0C9120000000000010000000100000000000000000000000000000000000000000000000000000001760200000000000100000000000000 "D:\Playlist Bot\Playlist bot\378.66-desktop-win8-win7-64bit-international-whql.exe"=0x534143500100000000000000070000002800000040086717A6D5671701000000000000000000020600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000431C0000000000000100000001000000 "D:\NVIDIA\DisplayDriver\378.66\Win8_Win7_64\International\setup.exe"=0x5341435001000000000000000700000028000000387806001026070001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000B0740400000000000100000001000000 "C:\Program Files\NVIDIA Corporation\Display\nvtray.exe"=0x5341435001000000000000000700000028000000387C25006167260001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000ED982301000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe"=0x5341435001000000000000000700000028000000C003ED00F320ED0001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000BB000000000000000100000001000000 "D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe"=0x5341435001000000000000000700000028000000C8CA0600BBBE070001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000000A2E2E07000000000400000004000000 "C:\Users\Thomas\AppData\Local\Temp\Rar$EXa0.434\RatioMaster-1.9.1\RM.exe"=0x53414350010000000000000007000000280000000040040000000000010000000000000000000106F5220000B395E7CF049FCE010000000000000000 "C:\Users\Thomas\Desktop\RatioMaster-1.9.1\RM.exe"=0x53414350010000000000000007000000280000000040040000000000010000000000000000000106F5220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B1CCBA07000000000D0000000D000000 "D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\bin\hammer.exe"=0x534143500100000000000000070000002800000000C802000000000001000000000000000000020600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000086010000000000000C0000000C000000 "D:\Program Files (x86)\C4D\Dragon Ball Xenoverse 2\Setup.exe"=0x53414350010000000000000007000000280000004CED15000000000001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000003B4E6700000000000200000002000000 "D:\Program Files (x86)\Dragon Ball Xenoverse 2\Game\bin\DX2.exe"=0x534143500100000000000000070000002800000000440700F98A070001000000000000000000030671220000975FD891C99ECE010000000000000000020000005000000000000000200000600000000200000000000000000000000084162B000000000005000000040000000000020620000060000000020000000000000000000000008D374800000000000300000000000000 "D:\Program Files (x86)\Dragon Ball Xenoverse 2\Game\bin\DBXV2.exe"=0x5341435001000000000000000700000028000000D0FA1B010000000001000000000000000000030673220000B395E7CF049FCE01000000000000000005000000100000000000000000000000000002062004000002000000280000000000020620040060000000000000000000000000000000001F270000000000000100000001000000 "D:\Program Files (x86)\Dragon Ball Xenoverse 2\unins000.exe"=0x53414350010000000000000007000000280000006FF01F000000000003000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000CD2C0000000000000200000002000000 "C:\Program Files (x86)\Common Files\EAInstaller\FIFA 15\Cleanup.exe"=0x5341435001000000000000000700000028000000200B0D00619B0D0003000000000000000000020600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000892D0000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Molotov\Update.exe"=0x5341435001000000000000000700000028000000002A17000000000003000000000000000000030680210000975FD891C99ECE0100000080000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000375F0000000000000100000001000000 "SIGN.MEDIA=AA8EF4D9 setup.exe"=0x5341435001000000000000000700000028000000B2060B000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000229E1100000000000100000001000000 "D:\Program Files (x86)\Pro Evolution Soccer 2017\Settings.exe"=0x5341435001000000000000000700000028000000B0530F00FF530F0001000000000000000000030680210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000E0B80000000000000100000001000000 "D:\Program Files (x86)\Pro Evolution Soccer 2017\PES2017.exe"=0x5341435001000000000000000700000028000000003891060000000001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000002060000002000000000000000000000000000000000AA9C0400000000000100000001000000 "C:\Users\Thomas\Desktop\cemu_1.7.3d\Cemu.exe"=0x534143500100000000000000070000002800000000C45B000000000001000000000000000000030673220000B395E7CF049FCE01000000000000000002000000280000000000000000000000100000000000000000000000000000005F8F5C00000000004500000045000000 "C:\Users\Thomas\Desktop\avast_free_antivirus_setup_online_a1c.exe"=0x534143500100000000000000070000002800000038926500B945660001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000005A700400000000000100000001000000 "C:\Users\Public\Desktop\avast_free_antivirus_setup_online_a1c.exe"=0x534143500100000000000000070000002800000038926500B945660001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000004B470300000000000100000001000000 "D:\Program Files\AVAST Software\Avast\wsc_proxy.exe"=0x5341435001000000000000000700000028000000D0F0000041B4010001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000331D0200000000000200000002000000 "D:\Program Files (x86)\Cyanide - PCM 2016\Pro Cycling Manager 2016\unins000.exe"=0x534143500100000000000000070000002800000021100F000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000EC120000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Temp\AIR7985.tmp\Adobe AIR Installer.exe"=0x5341435001000000000000000700000028000000488C05007B37060001000000000000000000030600210000975FD891C99ECE01000000800000000002000000280000000000000000000000000000000000000000000000000000000D1D0000000000000100000001000000 "C:\Windows\SysWOW64\Macromed\Temp\{433B3AF9-BA39-462E-BB87-904473995852}\InstallFlashPlayer.exe"=0x534143500100000000000000070000002800000058609E007EA49E0001000000000000000000030600210000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000009F0A0000000000000100000001000000 "C:\Program Files\WinRAR\Uninstall.exe"=0x5341435001000000000000000700000028000000909D03002F23040001000000000000000000030600210000B395E7CF049FCE010000000000000000020000002800000000000000000000000000000000000000000000000000000048010000000000000100000001000000 "C:\Program Files\WinRAR\WinRAR.exe"=0x534143500100000000000000070000002800000090AB170059E6170001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000050000000000000000000001000000000000000000000000000000000B50B110000000000410000000400000000000206000000100000000000000000000000000000000093DA4800000000000D00000000000000 "C:\Users\Thomas\Downloads\flashplayer25_xa_install.exe"=0x534143500100000000000000070000002800000068541200103E130001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B0A90600000000000100000001000000 "D:\Program Files\VideoLAN\VLC\vlc.exe"=0x5341435001000000000000000700000028000000C02502004B47020001000000000000000000030663220000B395E7CF049FCE010000000000000000020000005000000000000000000000000000000000000000000000000000000098ACC60000000000300500001B000000000002060000000000000000000000000000000000000000B3180100000000000400000000000000 "D:\Program Files\Dolphin\uninst.exe"=0x5341435001000000000000000700000028000000BCD601000000000003000000000000000000000671000000975FD891C99ECE01000000000000000002000000280000000000000000080000000000000000000000000000000000000B200000000000000100000001000000 "C:\Users\Thomas\Downloads\dolphin-4.0-win64.exe"=0x5341435001000000000000000700000028000000501D44000000000001000000000000000000010671000000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000078690000000000000100000001000000 "D:\Program Files (x86)\Pro Evolution Soccer 2017\unins000.exe"=0x5341435001000000000000000700000028000000A5360E000000000003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002C100000000000000100000001000000 "C:\Users\Thomas\Desktop\dolphin-x64-5.0.exe"=0x534143500100000000000000070000002800000058E82601DA99270101000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000062E80200000000000100000001000000 "D:\Program Files (x86)\Dolphin\Dolphin.exe"=0x5341435001000000000000000700000028000000A8CBED002A17EE0001000000000000000000030673220000B395E7CF049FCE01000000000000000002000000280000000000020600200020000000000000000000000000000000002A453E00000000000600000006000000 "C:\Users\Thomas\Desktop\pcsx2-1.4.0-setup.exe"=0x5341435001000000000000000700000028000000602C10010000000001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000009FDC0100000000000100000001000000 "C:\Program Files (x86)\Common Files\BioWare\Uninstall Star Wars - The Old Republic.exe"=0x5341435001000000000000000700000028000000D0D407000C54080003000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000050600000000000000100000001000000 "D:\Program Files (x86)\Universe Sandbox 2\unins000.exe"=0x5341435001000000000000000700000028000000437816000000000003000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000E10C0000000000000100000001000000 "D:\Program Files (x86)\Electronic Arts\Star Wars TOR\bitraider\bin\brwc.exe"=0x534143500100000000000000070000002800000000037D00AB337D0003000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000007E1A0000000000000100000001000000 "D:\Program Files (x86)\Emulateurs\PSX\ePSXe.exe"=0x5341435001000000000000000700000028000000008213000000000001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000CA740500000000000700000007000000 "D:\Program Files (x86)\Emulateurs\PCSX\pcsx.exe"=0x5341435001000000000000000700000028000000006002000000000001000000000000000000010571200000975FD891C99ECE0100000000000000000200000028000000000000000000000010000000000000000000000000000000D3A90200000000000E0000000E000000 "D:\Program Files (x86)\Emulateurs\SNES\zsnesw.exe"=0x5341435001000000000000000700000028000000001209000000000001000000000000000000000671200000975FD891C99ECE010000000000000000020000005000000000000000008000200000000000000000000000000000000012614101000000000500000002000000000000000000000000000040000000000000000000000000D3254A01000000000100000000000000 "D:\Program Files (x86)\Steam\steamapps\common\Fallout Shelter\FalloutShelter.exe"=0x5341435001000000000000000700000028000000009647010000000001000000000000000000030600210000B395E7CF049FCE010000000000000000020000002800000000000206000000200000000000000000000000000000000062360000000000000300000003000000 "D:\Program Files (x86)\Emulateurs\Dolphin\Dolphin.exe"=0x5341435001000000000000000700000028000000A8CBED002A17EE0001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000DAFF4C00000000002200000022000000 "D:\Program Files (x86)\Emulateurs\PCSX2 1.4.0\pcsx2.exe"=0x534143500100000000000000070000002800000000AA8B000000000001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000002631000000000000A0000000A000000 "C:\Users\Thomas\Documents\PCSX2\memcards\pc-asterix-obelix-xxl-by-pizzadox.exe"=0x534143500100000000000000070000002800000080B81500DB3EDBB601000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000087150100000000000100000001000000 "D:\Program Files (x86)\H1Z1\H1Z1\LaunchPad.exe"=0x5341435001000000000000000700000028000000589B0F007393100001000000000000000000020671000000975FD891C99ECE0100000000000000000200000028000000000000008000000000000000000000000000000000000000067C0000000000000100000001000000 "D:\Program Files (x86)\C4D\QuickPar-0.9.1.0-FRA.exe"=0x5341435001000000000000000700000028000000509F07000000000001000000000000000000010571000000975FD891C99ECE010000000000000000 "D:\Program Files (x86)\QuickPar\QuickPar.exe"=0x534143500100000000000000070000002800000000700A000000000001000000000000000000010571200000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D0210000000000000100000001000000 "D:\Program Files (x86)\C4D\pc-asterix-obelix-xxl-by-pizzadox.exe"=0x534143500100000000000000070000002800000080B815004AB46E0101000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000B8260200000000000100000001000000 "C:\Users\Thomas\AppData\Roaming\.minecraft\Uninstall.exe"=0x534143500100000000000000070000002800000074A10100C11D020003000000000000000000030661220000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000008000000000000000800000000000F22B0000000000000100000001000000010000000400000001000000 "D:\Program Files (x86)\QuickPar\uninst.exe"=0x5341435001000000000000000700000028000000CBDF00000000000003000000000000000000010571000000975FD891C99ECE0100000000000000000200000028000000000000000008000000000000000000000000000000000000420F0000000000000100000001000000 "C:\Users\Thomas\AppData\Local\Songr\Uninstall.exe"=0x5341435001000000000000000700000028000000C43001000000000003000000000000000000010600010000975FD891C99ECE0100000080000000000500000010000000000000000000000000000000000000000200000028000000000000000000000000000000000000000000000000000000F0620000000000000100000001000000 "D:\Program Files (x86)\Universe.Sandbox.2.Alpha.19.5\Universe Sandbox x64.exe"=0x534143500100000000000000070000002800000000E644010000000001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000002060000002000000000000000000000000000000000221C0A00000000000300000003000000 "D:\Program Files (x86)\Steam\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix_BE.exe"=0x534143500100000000000000070000002800000008B60D00D5220E0001000000000000000000030671200000975FD891C99ECE0100000000000000000200000028000000000000008000004000000000000000000000000000000000FA000000000000000100000001000000 "D:\Program Files (x86)\Ultimate Epic Battle Simulator\UEBS-Beta.exe"=0x5341435001000000000000000700000028000000D0A25401C75B550101000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000002060000002000000000000000000000000000000000B3711100000000000200000002000000 "D:\Program Files (x86)\Steam\steamapps\common\Outlast 2 Demo\Binaries\Win64\OL2Demo.exe"=0x5341435001000000000000000700000028000000002E22024F3B220201000000000000000000030673220000B395E7CF049FCE010000000000000000020000002800000000000000000000000000000000000000000000000000000038140900000000000100000001000000 "C:\Users\Thomas\Desktop\cemu_1.7.4d\Cemu.exe"=0x5341435001000000000000000700000028000000001A60000000000001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000050000000000002060000002000000000000000000000000000000000386308000000000012000000120000000000000000000000000000000000000000000000000000004D0B1000000000000700000000000000 "D:\Program Files (x86)\Steam\steamapps\common\Tom Clancy's Ghost Recon Phantoms - EU\Uninstaller.exe"=0x534143500100000000000000070000002800000028E21200F5C8130001000000000000000000010680010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000A54A0000000000000100000001000000 "D:\Program Files (x86)\RealWorld Cursor Editor\RWCursorEditor.exe"=0x5341435001000000000000000700000028000000B0711F000541200001000000000000000000020671020000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000CC480100000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\Outlast 2\Binaries\Win64\Outlast2.exe"=0x5341435001000000000000000700000028000000001828028BCC280201000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000002060000002000000000000000000000000000000000A30C0000000000000100000001000000 "D:\Program Files (x86)\C4D\BRAWL\flashplayer25_xa_install.exe"=0x53414350010000000000000007000000280000006856120020B7120001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000002060000000000000000000000000000000000000000EA970000000000000100000001000000 "C:\Program Files\Java\jre1.8.0_121\bin\javaw.exe"=0x53414350010000000000000007000000280000004028030043CE030001000000000000000000030600210000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000005C6B0000000000000400000004000000 "C:\Users\Thomas\Desktop\Citra\citra.exe"=0x5341435001000000000000000700000028000000006634000000000001000000000000000000030673220000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000005D080000000000001300000013000000 "C:\Users\Thomas\Desktop\Citra\citra-qt.exe"=0x534143500100000000000000070000002800000000063F000000000001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000AA180300000000000100000001000000 "C:\Windows\SysWOW64\Macromed\Temp\{E5A82A02-06A1-4012-8B18-5E1563D32649}\InstallFlashPlayer.exe"=0x5341435001000000000000000700000028000000F8C39B0083889C0001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B00F0000000000000100000001000000 "D:\Program Files (x86)\Outlast\Binaries\StatsComparison.exe"=0x534143500100000000000000070000002800000040C90000F9AA0100010000000000000000000206F5020000B395E7CF049FCE010000000000000000020000002800000000000000000000000000000000000000000000000000000027040000000000000100000001000000 "D:\Program Files (x86)\ManiaPlanet\ManiaPlanetLauncher.exe"=0x534143500100000000000000070000002800000000C64B000000000001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000206A00000601000000000000000000000000000000051B01F01000000006300000063000000 "D:\Program Files (x86)\Steam\steamapps\common\ManiaPlanet_TMStadium\ManiaPlanet.exe"=0x534143500100000000000000070000002800000058E09001602B910101000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000000E150000000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe"=0x534143500100000000000000070000002800000008E01200E507130001000000000000000000030671200000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000040000000000000000000000000000000006D4D29000000000002000000010000000000000000000000100000000000000000000000000000003FBE0000000000000400000000000000 "D:\Program Files (x86)\Steam\steamapps\common\Unturned\BattlEye\BEService_x64.exe"=0x5341435001000000000000000700000028000000085A1700B392170001000000000000000000030673200000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000006D000000000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\Unturned\BattlEye\Install_BattlEye.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe"=0x5341435001000000000000000700000028000000F84503000911040001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000002060000003000000000000000000000000000000000397F0F00000000000700000007000000 "D:\Program Files (x86)\C4D\DiscordSetup.exe"=0x534143500100000000000000070000002800000000E821039A22220301000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000002A90000000000000100000001000000 "D:\Program Files (x86)\C4D\MCreator 1.7.1 [1.10.2] Windows 64bit.exe"=0x534143500100000000000000070000002800000000226F040000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000BFA60000000000000100000001000000 "D:\Pylo\MCreator171\MCreator.exe"=0x534143500100000000000000070000002800000000AA10006236070001000000000000000000000671000000975FD891C99ECE010000000000000000020000002800000000000000000000000010000000000000000000000000000069060000000000000500000005000000 "D:\Pylo\MCreator171\uninstall.exe"=0x53414350010000000000000007000000280000009E5202000000000003000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000020120000000000000100000001000000 "D:\Program Files (x86)\C4D\MCreator 1.7.1 [1.10.2] Windows 64bit (1).exe"=0x534143500100000000000000070000002800000000226F040000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000002A000100000000000100000001000000 "C:\Users\Thomas\MCreator171\MCreator.exe"=0x534143500100000000000000070000002800000000AA10006236070001000000000000000000000671000000975FD891C99ECE0100000000000000000200000050000000000000000000000000100000000000000000000000000000BB08000000000000040000000200000000000000000000400000000000000000000000000000000069060000000000000100000000000000 "C:\Users\Thomas\MCreator171\external\mcskin3d\MCSkin3D.exe"=0x5341435001000000000000000700000028000000000C5F0000000000010000000000000000000306F1200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000007B8E0200000000000100000001000000 "D:\Program Files (x86)\C4D\MCreator 1.7.5 [1.11.2] Windows 64bit.exe"=0x5341435001000000000000000700000028000000C5DA42040000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000002D6B0000000000000200000002000000 "C:\Users\Thomas\MCreator171\uninstall.exe"=0x53414350010000000000000007000000280000009E5202000000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000006D0D0000000000000100000001000000 "D:\Pylo\MCreator175\MCreator.exe"=0x534143500100000000000000070000002800000000A010006236070001000000000000000000000671000000975FD891C99ECE010000000000000000020000002800000000000000000000000010000000000000000000000000000043070000000000000100000001000000 "D:\Pylo\MCreator175\uninstall.exe"=0x53414350010000000000000007000000280000009E5202000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000D70B0000000000000100000001000000 "D:\Pylo\MCreator.exe"=0x534143500100000000000000070000002800000000AA10006236070001000000000000000000000671000000975FD891C99ECE01000000000000000005000000100000000000000000000000000001060000000002000000C8000000000001060000006000100000000000000000000000000000D0070000000000000300000001000000000001060000002000100000000000000000000000000000EE0F0000000000000200000000000000000002060000006000100000000000000000000000000000C00700000000000001000000000000000000000000000040001000000000000000000000000000001E0800000000000002000000000000000000000000000000000000000000000000000000000000002A060000000000000100000000000000 "C:\Pylo\MCreator175\MCreator.exe"=0x534143500100000000000000070000002800000000A010006236070001000000000000000000000671000000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000050000000000000000000004000000000000000000000000000000000460400000000000001000000010000000000000000000000000200000000000000000000000000006B320000000000000100000000000000 "D:\Pylo\jdk64\bin\javac.exe"=0x5341435001000000000000000700000028000000203E00004390000001000000000000000000030600210000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000005E0D0000000000000100000001000000 "D:\Pylo\jdk64\bin\java.exe"=0x534143500100000000000000070000002800000020280300B379030001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000E2040000000000000100000001000000 "D:\Program Files (x86)\Pylo\MCreator.exe"=0x534143500100000000000000070000002800000000A010006236070001000000000000000000000671000000975FD891C99ECE01000000000000000005000000100000000000000000000000000002062000000002000000C8000000000002062000006000100000000000000000000000000000040700000000000002000000020000000000020600000060001000000000000000000000000000006906000000000000040000000000000000000206000000200010000000000000000000000000000059060000000000000100000000000000000000000000000000000000000000000000000000000000620700000000000004000000000000000000000000000040001000000000000000000000000000008E4E0000000000000400000000000000 "C:\Program Files\Java\jre1.8.0_131\bin\javaw.exe"=0x53414350010000000000000007000000280000004028030062EF030001000000000000000000030600210000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000002C320000000000000100000001000000 "D:\Program Files (x86)\Clash Royale\MCreator 1.7.1 [1.10.2] Windows 64bit.exe"=0x534143500100000000000000070000002800000000226F040000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000002060000004000000000000000000000000000000000ECF20000000000000100000001000000 "D:\Program Files (x86)\MCreator171\MCreator.exe"=0x534143500100000000000000070000002800000000AA10006236070001000000000000000000000671000000975FD891C99ECE0100000000000000000200000050000000000000000000004000100000000000000000000000000000041C0000000000001200000001000000000000000000000000000000000000000000000000000000B80B0000000000000200000000000000 "D:\Program Files (x86)\Java\jdk64\bin\javac.exe"=0x5341435001000000000000000700000028000000203E00004390000001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000B0070000000000000100000001000000 "D:\Program Files (x86)\Java\jdk64\bin\java.exe"=0x534143500100000000000000070000002800000020280300B379030001000000000000000000030600210000B395E7CF049FCE010000000000000000020000002800000000000000000000000000000000000000000000000000000058010000000000000900000009000000 "D:\Program Files (x86)\Launcher\Minecraft_staging.exe"=0x534143500100000000000000070000002800000080555302D5F1530201000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000020600000020000000000000000000000000000000004CC2B700000000001B0000001B000000 "D:\Program Files (x86)\Clash Royale\Gyazo-3.3.2.exe"=0x5341435001000000000000000700000028000000C8EBD3006424D40001000000000000000000030600210000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000028A98C00000000000100000001000000 "D:\Program Files (x86)\DAEMON Tools Lite\uninst.exe"=0x5341435001000000000000000700000028000000301E24001E5A240003000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000002D720100000000000100000001000000 "D:\Program Files (x86)\C4D\DTLiteInstaller.exe"=0x5341435001000000000000000700000028000000D80E0C00CFE30C0001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000021000300000000000400000004000000 "D:\Program Files (x86)\C4D\DTLiteInstaller (1).exe"=0x5341435001000000000000000700000028000000D80E0C00CFE30C0001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000EEFC0000000000000100000001000000 "D:\Program Files (x86)\C4D\SetupVirtualCloneDrive5500.exe"=0x5341435001000000000000000700000028000000581A1A00463D1A0001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000009E9C0000000000000100000001000000 "D:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe"=0x5341435001000000000000000700000028000000985B0100445C010001000000000000000000020671200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000001F000000000000000200000002000000 "D:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDMount.exe"=0x534143500100000000000000070000002800000000E000000000000001000000000000000000030671200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000003A060000000000000100000001000000 "D:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\vcd-uninst.exe"=0x534143500100000000000000070000002800000051390100463D1A0003000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000051170000000000000100000001000000 "D:\Program Files (x86)\Clash Royale\WinCDEmu-4.1.exe"=0x534143500100000000000000070000002800000010E8190049BC1A0001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000002060000004000000000000000000000000000000000E44A0000000000000100000001000000 "D:\Program Files (x86)\WinCDEmu\vmnt64.exe"=0x5341435001000000000000000700000028000000583306005554060001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000BBAC0000000000000400000004000000 "C:\Users\Thomas\AppData\Local\Temp\Rar$EXa0.354\shexview.exe"=0x534143500100000000000000070000002800000060D60000238F010001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000025350E00000000000100000001000000 "SIGN.MEDIA=5AC4A8BB Setup.exe"=0x5341435001000000000000000700000028000000A98FA8000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D45E0100000000000100000001000000 "D:\Program Files (x86)\American Truck Simulator\bin\win_x64\amtrucks.exe"=0x5341435001000000000000000700000028000000A87F2F01F437300101000000000000000000030600210000B395E7CF049FCE0100000000000000000200000050000000000000000000000000000000000000000000000000000000F33F3C000000000006000000060000000000000000000040000000000000000000000000000000004B087700000000000100000000000000 "D:\Program Files (x86)\C4D\gta5\Verify BIN files before installation.bat"=0x53414350010000000000000007000000280000000074050047AE050001000000000000000000010500100000B395E7CF049FCE010000000000000000 "D:\Program Files (x86)\C4D\gta5\setup-ultra-repack-2.1x.exe"=0x5341435001000000000000000700000028000000BF33BC000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000020200000000000000000000000000D11EC900000000000200000002000000 "C:\Users\Thomas\AppData\Local\Temp\Rar$EXa0.044\Pursuit Heat Levels till Level 10.exe"=0x53414350010000000000000007000000280000009DD201000000000001000000000000000000010571000000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000800000200000028000000000000000008004000000000000000000000000000000000CB000000000000000100000001000000 "D:\Program Files (x86)\Focus Home Interactive\Pro Cycling Manager 2016\unins000.exe"=0x534143500100000000000000070000002800000021100F000000000001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000007A460100000000000100000001000000 "D:\Games\Grand Theft Auto V\GTAVLauncher.exe"=0x534143500100000000000000070000002800000000E83D019D493E0101000000000000000000030673220000B395E7CF049FCE01000000000000000002000000A00000000000000000000000000000000000000000000000000000001A574800000000000A0000000900000000000106000000200000000000000000000000000000000031E0A4000000000003000000000000000000020600000020000000000000000000000000000000000F3FB100000000001500000000000000000000002000006000000000000000000000000000000000166A0300000000000100000000000000 "D:\Games\Grand Theft Auto V\GTA5.exe"=0x5341435001000000000000000700000028000000000A40031D8C400301000000000000000000030673200000B395E7CF049FCE0100000000000000000200000050000000000000000000000000000000000000000000000000000000822E0000000000000300000001000000000000000000004000000000000000000000000000000000160C0000000000000100000000000000 "SIGN.MEDIA=20F0D3F2 setup.exe"=0x53414350010000000000000007000000280000006D8221000000000001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000049B70A00000000000100000001000000 "D:\Program Files (x86)\Electronic Arts\Need For Speed - Hot Pursuit\NFS11.exe"=0x53414350010000000000000007000000280000000066100130F0100101000000000000000000010671020000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000EE9B2500000000000100000001000000 "D:\Program Files (x86)\C4D\SteelSeriesEngine3.10.9Setup.exe"=0x5341435001000000000000000700000028000000A8CA17053DBB180501000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000005710100000000000300000003000000 "C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe"=0x5341435001000000000000000700000028000000E8F2C500C0ADC60001000000000000000000030673200000B395E7CF049FCE010000000000000000020000002800000000000000000000000000000000000000000000000000000063E26900000000000500000005000000 "C:\Users\Thomas\Desktop\cemu_1.8.1b\Cemu.exe"=0x534143500100000000000000070000002800000000946D000000000001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000DAB81500000000000100000001000000 "D:\Program Files (x86)\C&C Alerte Rouge\RedAlertEditorLauncher.exe"=0x5341435001000000000000000700000028000000005A050000000000010000000000000000000306F1220000975FD891C99ECE01000000000000000002000000280000000000000080000000000000000000000000000000000000002E3E0100000000000100000001000000 "D:\Program Files (x86)\C&C Alerte Rouge\raed.exe"=0x534143500100000000000000070000002800000000F60A000000000001000000000000000000030641200000975FD891C99ECE01000000000000000002000000280000000000020600000020000000000000000000000000000000003A540000000000000100000001000000 "D:\Program Files (x86)\Clash Royale\ZHPDiag3.exe"=0x5341435001000000000000000700000028000000806F2A008B112B0001000000000000000000030600210000975FD891C99ECE010000000000000000050000001000000000000000000000000000020600000000020000002800000000000206000000400000000000000000000000000000000007291D00000000000100000001000000 "D:\Program Files (x86)\Clash Royale\ZHPFix.exe"=0x534143500100000000000000070000002800000000B82E000000000001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000002060000000000000000000000000000000000000000EF090E00000000000100000001000000 "D:\Program Files (x86)\Clash Royale\ZHPCleaner.exe"=0x534143500100000000000000070000002800000080152B008E7A2B0001000000000000000000030600210000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000040000000000000000000000000000000002B5F09000000000002000000020000000000020600000040000000000000000000000000000000000A960900000000000100000000000000 "D:\Program Files (x86)\Clash Royale\lmms-1.1.3-win64.exe"=0x5341435001000000000000000700000028000000F7E1E7016AB0010001000000000000000000010671000000975FD891C99ECE0100000000000000000200000028000000000002060008004000000000000000000000000000000000CA450200000000000100000001000000 "D:\Program Files (x86)\LMMS\lmms.exe"=0x5341435001000000000000000700000028000000009E24008263250001000000000000000000030673200000B395E7CF049FCE01000000000000000002000000280000000000020600000020000000000000000000000000000000004B7D0400000000000100000001000000 "D:\Program Files (x86)\LMMS\Uninstall.exe"=0x534143500100000000000000070000002800000022FF03006AB0010001000000000000000000010671000000975FD891C99ECE010000000000000000020000002800000000000000000800400000000000000000000000000000000008CF0000000000000100000001000000 "D:\Program Files (x86)\Clash Royale\Hydrogen-0.9.7-win32.exe"=0x5341435001000000000000000700000028000000B9565001253E010001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000020600000040000000000000000000000000000000006D3C0000000000000100000001000000 "D:\Program Files (x86)\Hydrogen\hydrogen.exe"=0x5341435001000000000000000700000028000000B0322D00FD322D0001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000206000000200000000000000000000000000000000020C60300000000000100000001000000 "D:\Program Files (x86)\Subtitle WS XE\SWXE.exe"=0x5341435001000000000000000700000028000000771852020000000001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000008D020400000000000300000003000000 "SIGN.MEDIA=36D54F7 setup.exe"=0x5341435001000000000000000700000028000000F47741000000000001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000003F880900000000000100000001000000 "D:\Program Files (x86)\Pro Cycling Manager 2017\PCM64.exe"=0x534143500100000000000000070000002800000078B4FC005F19FD0001000000000000000000030673220000B395E7CF049FCE010000000000000000050000001000000000000000000000000000000020000000020000005000000000000000200000600000000000000000000000000000000024AF0500000000000200000002000000000002062000006000000000000000000000000000000000B1041E00000000000200000000000000 "D:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe"=0x534143500100000000000000070000002800000000EA79000000000001000000000000000000030671200000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000053210000000000000100000001000000 "D:\Games\Grand Theft Auto V\Language Selector.exe"=0x5341435001000000000000000700000028000000009000000000000001000000000000000000030671200000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000080B65F00000000000200000002000000 "D:\Program Files (x86)\Emulateurs\Project64 2.2\Project64.exe"=0x534143500100000000000000070000002800000000D213000000000001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000BFEB0F00000000000600000006000000 "D:\Program Files (x86)\Emulateurs\ePSXe\ePSXe.exe"=0x534143500100000000000000070000002800000000DC05000000000001000000000000000000020671000000975FD891C99ECE0100000000000000000200000050000000000002060000002000000000000000000000000000000000145E960000000000190000001600000000000000000000000000000000000000000000000000000073FB8B00000000000D00000000000000 "D:\Program Files (x86)\Pro Cycling Manager 2017\unins000.exe"=0x5341435001000000000000000700000028000000712518000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D99A0000000000000100000001000000 "D:\Program Files (x86)\Electronic Arts\Need For Speed - Hot Pursuit\unins000.exe"=0x5341435001000000000000000700000028000000C97312000000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000E93E0100000000000100000001000000 "SIGN.MEDIA=5BF3FEB4 setup.exe"=0x5341435001000000000000000700000028000000EE7741000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000F4DE0700000000000100000001000000 "D:\Program Files (x86)\Cities Skylines Mass Transit\Cities.exe"=0x5341435001000000000000000700000028000000009A54010000000001000000000000000000030600210000B395E7CF049FCE0100000000000000000500000010000000000000000000000000000000200000000200000050000000000002062000006000000000000000000000000000000000C5292300000000000100000001000000000000002000006000000000000000000000000000000000F5000100000000000100000000000000 "D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayService.exe"=0x5341435001000000000000000700000028000000586936008833370001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000008000000000000000000000000000000000000000F40E0000000000000200000002000000 "D:\Program Files (x86)\Cities Skylines Mass Transit\unins000.exe"=0x5341435001000000000000000700000028000000712518000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000D4300000000000000100000001000000 "D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe"=0x5341435001000000000000000700000028000000A8CD5900F7EB590001000000000000000000030671220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000EF0F0000000000000100000001000000 "D:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe"=0x5341435001000000000000000700000028000000B065060062F0060001000000000000000000030673220000B395E7CF049FCE01000000000000000002000000280000000000000000000000000000000000000000000000000000000F000000000000000100000001000000 "C:\ProgramData\NVIDIA Corporation\Downloader\latest\setup.exe"=0x5341435001000000000000000700000028000000C0710600DE2C070001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000001B570300000000000200000002000000 "D:\Program Files (x86)\Clash Royale\UserBenchMark.exe"=0x5341435001000000000000000700000028000000C96555000000000001000000000000000000010600010000975FD891C99ECE0100000000000000000500000010000000000000000000000000000206000000000200000028000000000002060000004000000000000000000000000000000000B33B0300000000000100000001000000 "D:\Program Files (x86)\C4D\pcsx2-1.4.0-setup.exe"=0x5341435001000000000000000700000028000000602C10010000000001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000004B620200000000000100000001000000 "D:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe"=0x5341435001000000000000000700000028000000B8B454018C44550101000000000000000000030600210000B395E7CF049FCE010000000000000000020000002800000000000206000000200000000000000000000000000000000097C01900000000000200000002000000 "C:\ProgramData\NVIDIA Corporation\Downloader\d20b0c765978b18fcd06bf8de3657f6c\GeForce_Experience_Update_v3.9.0.61.exe"=0x53414350010000000000000007000000280000005072FF04EB09000501000000000000000000020600010000975FD891C99ECE0100000080000000000200000028000000000000000000004000000000000000000000000000000000E04A0100000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe"=0x5341435001000000000000000700000028000000C06F0E00B0A40E0001000000000000000000030671200000975FD891C99ECE01000000000000000002000000280000000000000080000000000000000000000000000000000000009C000000000000000100000001000000 "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe"=0x5341435001000000000000000700000028000000C08117009CE5170001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000039525500000000000100000001000000 "D:\Program Files (x86)\Clash Royale\mse-win32-2011-02-05-full.exe"=0x5341435001000000000000000700000028000000F16769020000000001000000000000000000030641220000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000CF391A00000000000100000001000000 "D:\Program Files (x86)\Magic Set Editor 2\mse.exe"=0x5341435001000000000000000700000028000000001038000000000001000000000000000000010671200000975FD891C99ECE0100000000000000000200000028000000000000000000001000000000000000000000000000000000A95A3000000000002500000025000000 "D:\Program Files (x86)\Clash Royale\easy-card-creator-free_8-20-36_fr_181768.exe"=0x5341435001000000000000000700000028000000EDF762020000000001000000000000000000030641220000975FD891C99ECE0100000000000000000200000028000000000002060000004000000000000000000000000000000000D72C0100000000000100000001000000 "D:\Program Files (x86)\Krita\bin\krita.exe"=0x534143500100000000000000070000002800000013904700F266480001000000000000000000030663200000B395E7CF049FCE010000000000000000020000002800000000000206000000200000000000000000000000000000000084640700000000000200000002000000 "D:\Program Files (x86)\C4D\Photoshop\Set-up.exe"=0x5341435001000000000000000700000028000000B8AE39007F383A0001000000000000000000030600210000975FD891C99ECE010000000000000000020000005000000000000000000000000000000000000000000000000000000066436200000000000B000000070000000000000000000040000000000000000000000000000000009A450200000000000100000000000000 "C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe"=0x5341435001000000000000000700000028000000D0581E0AC36F1E0A01000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000F1EE4301000000002700000027000000 "SIGN.MEDIA=94F84716 setup.exe"=0x5341435001000000000000000700000028000000CF3C3D000000000001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000082650300000000000200000002000000 "D:\Games\Grand Theft Auto V\unins000.exe"=0x5341435001000000000000000700000028000000712117000000000001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000098C40000000000000100000001000000 "D:\Program Files (x86)\C4D\BlueStacks-Installer_BS3_native_a5964c7c2826a73f317428dc87f340cf.exe"=0x5341435001000000000000000700000028000000E0F84A0FB50E4B0F01000000000000000000010600010000975FD891C99ECE010000000000000000020000005000000000000000000000400000000000000000000000000000000002450B00000000000100000001000000000002060000000000000000000000000000000000000000B4C40400000000000100000000000000 "D:\Program Files (x86)\BlueStacks\BlueStacks\Client\Bluestacks.exe"=0x5341435001000000000000000700000028000000381A120036E01200010000000000000000000306F1220000975FD891C99ECE0100000000000000000200000050000000000000000000000010000000000000000000000000000000A5C30F00000000000600000001000000000000000000004000000000000000000000000000000000D5280000000000000100000000000000 "D:\Program Files (x86)\BlueStacks\BlueStacks\Client\BlueStacksClientUninstaller.exe"=0x534143500100000000000000070000002800000038AC0E0060270F0001000000000000000000030680210000975FD891C99ECE0100000000000000000200000028000000000000000000004000000000000000000000000000000000188D0100000000000100000001000000 "C:\Program Files (x86)\BlueStacks\HD-RunApp.exe"=0x534143500100000000000000070000002800000038C20500B89B0600010000000000000000000306F1220000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000068B14300000000000100000001000000 "D:\Program Files (x86)\Steam\bin\steamservice.exe"=0x5341435001000000000000000700000028000000209118007034190001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000097010000000000000100000001000000 "D:\Program Files (x86)\C4D\Detective Conan\EpicInstaller-6.3.0-fortnite-ab6fbd758419498fa61b679e226b0444.msi"=0x534143500100000000000000070000002800000000EA0000FD42010001000000000000000000010500100000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000004BB60100000000000100000001000000 "D:\Program Files (x86)\Epic Games\Launcher\Portal\SelfUpdateStaging\Install\Portal\Extras\Redist\LauncherPrereqSetup_x64.exe"=0x5341435001000000000000000700000028000000509AB200EA66B30001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000800000000000000000000000000000000000000032040100000000000100000001000000 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"=0x53414350010000000000000007000000280000005825160072B5160001000000000000000000030600210000B395E7CF049FCE010000000100000000 "D:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.exe"=0x5341435001000000000000000700000028000000C0772E0099D32E0001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000206800000200000000000000000000000000000000051660200000000000200000002000000 "D:\Program Files (x86)\Fortnite\Fortnite\FortniteGame\Binaries\Win64\FortniteClient-Win64-Shipping.exe"=0x5341435001000000000000000700000028000000C08136059492360501000000000000000000030673200000B395E7CF049FCE010000000000000000020000002800000000000206000000200000000000000000000000000000000007040000000000000100000001000000 "D:\Program Files (x86)\Mozilla Firefox\minidump-analyzer.exe"=0x5341435001000000000000000700000028000000D0110800CA36080001000000000000000000030671200000975FD891C99ECE010000000000000000020000002800000000000206000000000000000000000000000000000000000065040000000000000300000003000000 "D:\Program Files (x86)\C4D\Detective Conan\TeamSpeak3-Client-win64-3.1.6.exe"=0x53414350010000000000000007000000280000001045A7046813A80401000000000000000000010600010000975FD891C99ECE0100000000000000000200000050000000000000000000004000000000000000000000000000000000F49F43000000000001000000010000000000020600000040000000000000000000000000000000005E0E0200000000000100000000000000 "D:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win64.exe"=0x5341435001000000000000000700000028000000189DE300D379E40001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000004000000000000000000000000000000000F380AC00000000000400000004000000 "D:\Program Files (x86)\Origin\OriginCrashReporter.exe"=0x5341435001000000000000000700000028000000605922006A66220001000000000000000000030671220000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000093040000000000000100000001000000 "D:\Program Files (x86)\Origin\OriginClientService.exe"=0x53414350010000000000000007000000280000006059200038B4200001000000000000000000010600010000975FD891C99ECE010000000000000000050000001000000000000000000000000000000000000000020000002800000000000000000000000000000000000000000000000000000043070000000000000100000001000000 "D:\Program Files (x86)\Origin\OriginWebHelperService.exe"=0x534143500100000000000000070000002800000068C72D00AF292E0001000000000000000000010600010000975FD891C99ECE010000000000000000020000002800000000000000000000000000000000000000000000000000000050120000000000000100000001000000 "C:\Users\Thomas\AppData\Roaming\uTorrent\uTorrent.exe"=0x5341435001000000000000000700000028000000C03E1E009D951E0001000000000000000000030600210000975FD891C99ECE0100000000000000000200000050000000000002060000001000000000000000000000000000000000CF113601000000000C00000001000000000000000000001000000000000000000000000000000000AB080000000000000200000000000000 "D:\Program Files (x86)\Origin\Origin.exe"=0x534143500100000000000000070000002800000048492F00947A2F0001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000007CEC4701000000000200000002000000 "D:\Program Files (x86)\C4D\setup_cuphead_20170929_(15295).exe"=0x534143500100000000000000070000002800000018630B00D9790B0001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000004F943500000000000100000001000000 "D:\Program Files (x86)\Cuphead\Cuphead.exe"=0x5341435001000000000000000700000028000000006215010000000001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000002061000002000000000000000000000000000000000504B1400000000000100000001000000 "D:\Program Files\AVAST Software\Avast\AvastUI.exe"=0x534143500100000000000000070000002800000078DF8F00AC96900001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000EE020000000000000600000006000000 "D:\Program Files (x86)\Steam\Steam.exe"=0x534143500100000000000000070000002800000020552F00BDDA2F0001000000000000000000030600210000975FD891C99ECE0100000000000000000200000028000000000000000000000000000000000000000000000000000000FA000000000000001900000019000000 "D:\Program Files (x86)\C4D\DBX2\setup.exe"=0x5341435001000000000000000700000028000000E5F238000000000001000000000000000000010600010000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000004CD82602000000000200000002000000 "D:\Program Files (x86)\Dragon Ball Xenoverse 2\bin\Language Selector.exe"=0x5341435001000000000000000700000028000000009000000000000001000000000000000000030671200000975FD891C99ECE01000000000000000002000000280000000000000000000000000000000000000000000000000000005C582F00000000000200000002000000 "D:\Program Files (x86)\Dragon Ball Xenoverse 2\bin\DBXV2.exe"=0x5341435001000000000000000700000028000000D0AC1D010000000001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000002000006000000000000000000000000000000000C8C94500000000000200000002000000 "D:\Program Files (x86)\Mozilla Firefox\firefox.exe"=0x5341435001000000000000000700000028000000D0C707008E6A080001000000000000000000030600210000B395E7CF049FCE010000000100000000 "C:\Windows\SysWOW64\Macromed\Temp\{E23CBCA3-D8D2-4271-BB29-0705DC20E06A}\InstallFlashPlayer.exe"=0x534143500100000000000000070000002800000000EC9E004C019F0001000000000000000000030600210000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000521C0000000000000100000001000000 "C:\Users\Thomas\Documents\TrackMania\Tracks\Challenges\My Challenges\ZHPFix.exe"=0x534143500100000000000000070000002800000000B82E000000000001000000000000000000030671220000975FD891C99ECE01000000000000000002000000280000000000020600000000000000000000000000000000000000008EFA0300000000000100000001000000 "C:\Users\Thomas\Desktop\ZHPFix.exe"=0x534143500100000000000000070000002800000000B82E000000000001000000000000000000030671220000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000500000000000000000000000000000000000000000000000000000005C0C05000000000001000000010000000000000000000040000000000000000000000000000000000D0A0100000000000100000000000000 "C:\Users\Thomas\Desktop\ZHPDiag3.exe"=0x534143500100000000000000070000002800000080612C0053DB2C0001000000000000000000030600210000975FD891C99ECE01000000000000000002000000280000000000000000000040000000000000000000000000000000008CDA0100000000000400000004000000 "C:\Users\Thomas\AppData\Roaming\ZHP\ZHPDiag3.exe"=0x534143500100000000000000070000002800000080612C0053DB2C0001000000000000000000030600210000975FD891C99ECE0100000000000000000500000010000000000000000000000000000000000000000200000028000000000000000000004000000000000000000000000000000000A3BA0700000000000200000002000000 "D:\Games\Dragon Ball Xenoverse 2\bin\DBXV2.exe"=0x5341435001000000000000000700000028000000D0AC1D010000000001000000000000000000030673220000B395E7CF049FCE0100000000000000000200000028000000000000000000000000000000000000000000000000000000C98F1B00000000000100000001000000 "C:\Users\Thomas\ZHPDiag3.exe"=0x534143500100000000000000070000002800000080772C00F45E2D0001000000000000000000030600210000975FD891C99ECE01000000000000000005000000100000000000000000000000000000000000000002000000280000000000000000000040000000000000000000000000000000006DF74900000000000200000002000000 "D:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe"=0x5341435001000000000000000700000028000000C03FE7011FD3E70101000000000000000000030600210000B395E7CF049FCE01000000000000000002000000280000000000020600000020000000000000000000000000000000003B566000000000000100000001000000 "C:\Users\Thomas\Desktop\QuickDiag.exe"=0x534143500100000000000000070000002800000000B23C0083113D0001000000000000000000030600210000975FD891C99ECE010000000000000000020000002800000000000000000000400000000000000000000000000000000032040100000000000100000001000000 [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted] "D:\Program Files\AVAST Software\SZBrowser\Launcher.exe"=32 ---------- | IFEO ---------- | Mountpoints2 [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{14398807-6e0e-11e7-8072-d0509926b2f8}] : "T:\setup.exe" (AutoRun) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{1b612911-8ef2-11e7-80aa-d0509926b2f8}] : "T:\setup.exe" (AutoRun) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{21f6870e-9a43-11e7-80bd-d0509926b2f8}] : "T:\setup.exe" (AutoRun) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{27fa20bf-9c22-11e6-bf47-d0509926b2f8}] : "F:\HiSuiteDownLoader.exe" (AutoRun) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{27fa210c-9c22-11e6-bf47-d0509926b2f8}] : "F:\HiSuiteDownLoader.exe" (AutoRun) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{44e00a19-f947-11e6-bf91-d0509926b2f8}] : "H:\HiSuiteDownLoader.exe" (AutoRun) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{7794d630-6195-11e7-805a-d0509926b2f8}] : "T:\setup.exe" (AutoRun) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{9327833c-5d68-11e7-8054-d0509926b2f8}] : "T:\Setup.exe" (AutoRun) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{9a22d202-7142-11e7-8077-d0509926b2f8}] : "T:\setup.exe" (AutoRun) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{b9fe96fc-5843-11e7-8046-d0509926b2f8}] : "T:\Setup.exe" (AutoRun) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{cbaeff1b-b9e1-11e4-be88-d0509926b2f8}] : "G:\setup.exe" (AutoRun) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{f89ccbbe-8cd3-11e4-be6c-7a946c4a4b04}] : "F:\OriginSetup.exe" (AutoRun) ---------- | Windows [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] "DoubleClickSpeed"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "DragFullWindows"=USR:Control Panel\Desktop ""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows "Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "DoubleClickHeight"=#USR:Control Panel\Mouse "MouseSpeed"=#USR:Control Panel\Mouse "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "MouseThreshold2"=#USR:Control Panel\Mouse "SwapMouseButtons"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "CoolSwitch"=USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DoubleClickWidth"=#USR:Control Panel\Mouse "SnapToDefaultButton"=#USR:Control Panel\Mouse "Beep"=#USR:Control Panel\Sound "ScreenSaveActive"=#USR:Control Panel\Desktop "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "PowerOffTimeOut"=#USR:Control Panel\Desktop "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon "SCRNSAVE.EXE"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "ScreenSaverActive"=USR:Control Panel\Desktop [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] "DoubleClickSpeed"=#USR:Control Panel\Mouse "PowerOffActive"=#USR:Control Panel\Desktop "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "DoubleClickHeight"=#USR:Control Panel\Mouse "MouseSpeed"=#USR:Control Panel\Mouse "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "MouseThreshold2"=#USR:Control Panel\Mouse "SwapMouseButtons"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "CoolSwitch"=USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "DoubleClickWidth"=#USR:Control Panel\Mouse "SnapToDefaultButton"=#USR:Control Panel\Mouse "Beep"=#USR:Control Panel\Sound "ScreenSaveActive"=#USR:Control Panel\Desktop "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "PowerOffTimeOut"=#USR:Control Panel\Desktop "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon "SCRNSAVE.EXE"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "ScreenSaverActive"=USR:Control Panel\Desktop [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] "windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 ---------- | Security center [HKLM\SOFTWARE\Microsoft\Security Center] "cval"=1 [HKLM\SOFTWARE\Microsoft\Security Center\svc] "VistaSp1"=130216565553372332 "AntiVirusOverride"=0 "AntiSpywareOverride"=0 "FirewallOverride"=0 [HKLM\SOFTWARE\Microsoft\Windows Defender] "ProductIcon"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-100 "RemediationExe"=%ProgramFiles%\Windows Defender\MSASCui.exe "ProductLocalizedName"=@%ProgramFiles%\Windows Defender\EppManifest.dll,-1000 "DisableAntiSpyware"=1 "ProductType"=2 "ProductStatus"=0 "InstallTime"=0x5981034A231ED001 "OneTimeSqmDataSent"=1 "DisableAntiVirus"=1 "ProductAppDataPath"=C:\ProgramData\Microsoft\Windows Defender [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications"=1 ---------- | Safeboot [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicDisplay.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicRender.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BrokerInfrastructure] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DeviceInstall] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dxgkrnl.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\FsDepends.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LSM] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SmartcardSimulator] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SystemEventsBroker] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VirtualSmartcardReader] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wcmsvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] ---------- | Winsock (Whitelist) ---------- | Hosts ---------- | Ping Envoi d'une requ?te 'ping' sur google.com [2a00:1450:4009:805::200e] avec 32 octets de donn?es?: D?lai d'attente de la demande d?pass?. D?lai d'attente de la demande d?pass?. D?lai d'attente de la demande d?pass?. D?lai d'attente de la demande d?pass?. Statistiques Ping pour 2a00:1450:4009:805::200e: Paquets?: envoy?s = 4, re?us = 0, perdus = 4 (perte 100%), ---------- | @ [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Internet Explorer\Main] "Anchor Underline"=yes "Cache_Update_Frequency"=Once_Per_Session "Display Inline Images"=yes "Do404Search"=0x01000000 "Local Page"=C:\WINDOWS\system32\blank.htm "Save_Session_History_On_Exit"=no "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "Search Page"=https://www.google.com/search?trackid=sp-006&q={searchTerms} "XMLHTTP"=1 "NoUpdateCheck"=1 "Disable Script Debugger"=yes "DisableScriptDebuggerIE"=yes "UseClearType"=no "Enable Browser Extensions"=yes "Play_Background_Sounds"=yes "Play_Animations"=yes "Start Page"=http://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRghBdFgNUVpGRxgWdwwJTA1FF1EOeAwMBxQSElQSJgkNBA1EQlYFIk0FA1ADB0VXfVBdFElXTwhuL0tdM1wCVFlXM3FNAw== "OperationalData"=13 "CompatibilityFlags"=0 "FullScreen"=no "Window_Placement"=0x2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000090060000F2030000 "Start Page Redirect Cache_TIMESTAMP"=0x0D991521251ED001 "Start Page Redirect Cache AcceptLangs"=fr-FR "IE10RunOncePerInstallCompleted"=1 "IE10RunOnceCompletionTime"=0x23A183C2552ED301 "IconCache"=2snbh8m "DownloadWindowPlacement"=0x2C0000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0D010000F50000008D030000D5020000 "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "IE10TourShown"=1 "IE10TourShownTime"=0x09C73DC0CD60D001 "PrivacyPolicyShown"=1 "ImageStoreRandomFolder"=xa8duyf "Isolation"=PMIL "IE10TourNoShow"=1 "Search Bar"=https://www.google.com/?trackid=sp-006 "AutoHide"=yes "Check_Associations"=no "Start Page_TIMESTAMP"=0x842187C2552ED301 "SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy"=0x010000009B000000E1CDB1A0488D17B2591CA841FF31128F9DFD52B681818EEA7627D58D50A0FF4924B32E268CA56BC57FB49F03C7C8B28AED3CC9F86ABF40497DA716F161151D16F7D80128E61372A4CB544613DDF88D938426B11F45EEAFBE261B265EF6E4B73D75670F3C1FCBF5FF1AACBE2FDEAB5678C63EC7848D27D461BF0CAB4240C96303C4B91B87370AE147330C26238B750A93D3926A503771A26EC03436020000000E000000647657476C2F326B716151253364 [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings] "IE5_UA_Backup_Flag"=5.0 "EnableNegotiate"=1 "MigrateProxy"=1 "PrivacyAdvanced"=0 "ProxyEnable"=0 "ProxyOverride"=*.local "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "ZonesSecurityUpgrade"=0x75A34AB2CF6FD001 "EmailName"=User@ "AutoConfigProxy"=wininet.dll "MimeExclusionListForCache"=multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "WarnOnPost"=0x01000000 "UseSchannelDirectly"=0x01000000 "EnableHttp1_1"=1 "UrlEncoding"=0 "SecureProtocols"=2688 "DisableCachingOfSSLPages"=0 "WarnonZoneCrossing"=0 "CertificateRevocation"=1 "GlobalUserOffline"=0 [HKLM\Software\Microsoft\Internet Explorer\Main] "AutoHide"=yes "Security Risk Page"=about:SecurityRisk "Extensions Off Page"=about:NoAdd-ons "Anchor_Visitation_Horizon"=0x01000000 "Cache_Percent_of_Disk"=0x0A000000 "Placeholder_Width"=0x1A000000 "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE "Placeholder_Height"=0x1A000000 "Default_Secondary_Page_URL"= "Use_Async_DNS"=yes "Local Page"=C:\Windows\System32\blank.htm "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "Default_Search_URL"=www.google.com "Default_Page_URL"=www.google.com "Start Page"=http://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRghBdFgNUVpGRxgWdwwJTA1FF1EOeAwMBxQSElQSJgkNBA1EQlYFIk0FA1ADB0VXfVBdFElXTwhuL0tdM1wCVFlXM3FNAw== "Search Page"=www.google.com "DoNotTrack"=1 [HKLM\Software\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "Home"=270 "PostNotCached"=res://ieframe.dll/repost.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm "Compat"=res://mshtml.dll/compat.htm [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes] "mosaic"=http:// "www"=http:// "home"=http:// "ftp"=ftp:// [HKLM\Software\Microsoft\Windows\CurrentVersion\Internet settings] "CodeBaseSearchPath"=CODEBASE "EnablePunycode"=1 "WarnOnIntranet"=1 "MinorVersion"=0 "ActiveXCache"=C:\Windows\Downloaded Program Files [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main] "AutoHide"=yes "Security Risk Page"=about:SecurityRisk "Extensions Off Page"=about:NoAdd-ons "Anchor_Visitation_Horizon"=0x01000000 "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "Cache_Percent_of_Disk"=0x0A000000 "Placeholder_Width"=0x1A000000 "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE "Placeholder_Height"=0x1A000000 "Default_Secondary_Page_URL"= "Use_Async_DNS"=yes "Start Page"=https://www.google.com/?trackid=sp-006 "Local Page"=C:\Windows\SysWOW64\blank.htm "Search Page"=https://www.google.com/search?trackid=sp-006&q={searchTerms} "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "DoNotTrack"=1 "Search Bar"=https://www.google.com/?trackid=sp-006 [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "InPrivate"=res://ieframe.dll/inprivate.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "Home"=270 "PostNotCached"=res://ieframe.dll/repost.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm "Tabs"=about:newtab "Compat"=res://mshtml.dll/compat.htm [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes] "mosaic"=http:// "www"=http:// "home"=http:// "ftp"=ftp:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings] "CodeBaseSearchPath"=CODEBASE "WarnOnIntranet"=1 "EnablePunycode"=1 "MinorVersion"=0 "ActiveXCache"=C:\Windows\Downloaded Program Files ---------- | Proxy ---------- | reparsepoint ---------- | Detection of offsets ---------- | Notify ---------- | Execution FileExts [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ccd] "Application"=vmnt64.exe [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cue] "Application"=vmnt64.exe [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dvd] "Application"=VCDMount.exe [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.egb] "Application"=SimCity [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gb] "Application"=SimCity [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.img] "Application"=vmnt64.exe [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iso] "Application"=vmnt64.exe [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mds] "Application"=vmnt64.exe [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrg] "Application"=vmnt64.exe [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.world] "Progid"=worldpainter 1 ---------- | SIOI | SEH | URLSH [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ AccExtIco1] - {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} -- C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncExtension\CoreSync_x64.dll [14/08/2017 03:48:44] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ AccExtIco2] - {853B7E05-C47D-4985-909A-D0DC5C6D7303} -- C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncExtension\CoreSync_x64.dll [14/08/2017 03:48:44] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ AccExtIco3] - {42D38F2E-98E9-4382-B546-E24E4D6D04BB} -- C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncExtension\CoreSync_x64.dll [14/08/2017 03:48:44] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending] - {056D528D-CE28-4194-9BA3-BA2E9197FF8C} -- C:\ProgramData\MEGAsync\ShellExtX64.dll [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced] - {05B38830-F4E9-4329-978B-1DD28605D202} -- C:\ProgramData\MEGAsync\ShellExtX64.dll [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing] - {0596C850-7BDD-4C9D-AFDF-873BE6890637} -- C:\ProgramData\MEGAsync\ShellExtX64.dll [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw] - {472083B0-C522-11CF-8763-00608CC02F24} -- D:\Program Files\AVAST Software\Avast\ashShA64.dll [10/10/2017 20:19:39] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast] - {472083B0-C522-11CF-8763-00608CC02F24} -- D:\Program Files\AVAST Software\Avast\ashShA64.dll [10/10/2017 20:19:39] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} -- C:\Windows\System32\EhStorShell.dll [21/11/2014 01:19:54] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81} -- %SystemRoot%\System32\cscui.dll [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending] - {056D528D-CE28-4194-9BA3-BA2E9197FF8C} -- C:\ProgramData\MEGAsync\ShellExtX32.dll [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced] - {05B38830-F4E9-4329-978B-1DD28605D202} -- C:\ProgramData\MEGAsync\ShellExtX32.dll [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing] - {0596C850-7BDD-4C9D-AFDF-873BE6890637} -- C:\ProgramData\MEGAsync\ShellExtX32.dll [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"= [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\URLSearchHooks] ""={CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} ---------- | Toolbar [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "Locked"=1 [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser] "ITBar7Layout"=0x13000000000000000000000020000000100001000000000001000000000700005E01000006000000010100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000051B1C7CC8C1DE311B2ADF3EF3D58318D0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} "KnownProvidersUpgradeTime"=0x1971A8701B8FD101 "Version"=4 "UpgradeTime"=0x5020EE701B8FD101 "DefaultPackCorrection"=1 "DoNotAskAgain"=searchinterneat-a.akamaihd.net "DefaultPackNTCorrection"=1 "DownloadRetries"=2 [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A} "DoNotAskAgain"=searchinterneat-a.akamaihd.net [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={E9410C70-B6AE-41FF-AB71-32F4B279EA5F} "DoNotAskAgain"=google.com ---------- | Extensions ---------- | SearchScopes [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch] - (Google) - https://www.google.com/search?trackid=sp-006&q={searchTerms} : [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (Bing) - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 : [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}] - (Google) - https://www.google.com/search?trackid=sp-006&q={searchTerms} : ---------- | Browser Helper Objects [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}] -> () : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] -> (Java(tm) Plug-In SSV Helper) : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] -> (avast! Online Security) : D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [10/10/2017 20:19:22] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] -> (Java(tm) Plug-In 2 SSV Helper) : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] -> (avast! Online Security) : D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [10/10/2017 20:19:22] ---------- | Chrome C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\apdfllckaahabafndbhieahigkjlhalf = : Google & co - https://drive.google.com/?usp=chrome_app - Google & co - [http://docs.google.com/http://drive.google.com/https://docs.google.com/https://drive.google.com/] - https://clients2.google.com/service/update2/crx C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\bigefpfhnfcobdlfbedofhhaibnlghod = : Secure Cloud Storage - MEGA - https://clients2.google.com/service/update2/crx C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo = : Google & co - http://www.youtube.com - http://www.youtube.com - Google & co - http://clients2.google.com/service/update2/crx C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo = : The world's most popular userscript manager - short_name: Tampermonkey - permissions:[notificationsunlimitedStoragetabsidlemanagementwebNavigationwebRequestwebRequestBlockingstoragecontextMenuschrome://favicon/clipboardWritecookies\u003Call_urls>] - https://clients2.google.com/service/update2/crx C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\gfffnbhinkdleedlodeeodpaipoeonoa = : This extension automatically loads the Radiant Community Script when loading plug.dj. - short_name: RCE - https://clients2.google.com/service/update2/crx C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\gighmmpiobklfepjocnamgkkbiglidom = : __MSG_description__ - short_name: __MSG_name__ - permissions:[tabs\u003Call_urls>contextMenuswebRequestwebRequestBlockingwebNavigationstorageunlimitedStoragenotificationsidlealarms] - https://clients2.google.com/service/update2/crx C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\ldhcdlnondjolfdmlagafpjnhglkfefl = : __MSG_liloDesc__ - Lilo Search - https://clients2.google.com/service/update2/crx C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\nmmhkkegccagdldgiimedpiccmgmieda = : Google & co - Google & co - 203784468217.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\ogkcjmbhnfmlnielkjhedpcjomeaghda = : Debug diagnose and explore WebGL scenes. - WebGL Inspector - http://clients2.google.com/service/update2/crx C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\okadibdjfemgnhjiembecghcbfknbfhg = : Enhances the Steam Experience - Enhanced Steam - https://clients2.google.com/service/update2/crx C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\pjkljhegncpnkpknbcohdijeoejaedia = : Google & co - https://mail.google.com/mail/ca - Google & co - [*://mail.google.com/mail/ca] - http://clients2.google.com/service/update2/crx C:\Users\Thomas\AppData\Local\Google\Chrome\User Data\Default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm = : Provider for discovery and services for mirroring of Chrome Media Router - Chrome Media Router - 919648714761-55j965o0km033psv3i9qls5mo3qtdrb0.apps.googleusercontent.com - https://clients2.google.com/service/update2/crx [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki] ---------- | Opera ---------- | Firefox C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ii7m9bkr.default\Extensions\cacaoweb@cacaoweb.org : : cacaoweb - : http://www.cacaoweb.org/ C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ii7m9bkr.default\Extensions\adblockultimate@adblockultimate.net.xpi [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\MozillaPlugins\@nsroblox.roblox.com/launcher] - (Roblox Launcher) : C:\Users\Thomas\AppData\Local\Roblox\Versions\version-d31f23e3f760404e\\NPRobloxProxy.dll [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\MozillaPlugins\@nsroblox.roblox.com/launcher64] - (Roblox Launcher) : C:\Users\Thomas\AppData\Local\Roblox\Versions\version-d31f23e3f760404e\\NPRobloxProxy64.dll [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0] - (Unity Player 5.3.2f1) : C:\Users\Thomas\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\MozillaPlugins\ubisoft.com/uplaypc] - () : C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 27.0.0.159 Plugin) : C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_159.dll [HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.131.2] - (Java™ Deployment Toolkit) : C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.131.2] - (Oracle® Next Generation Java™ Plug-In) : C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.2] - (VLC Multimedia Plugin) : D:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.4] - (VLC Multimedia Plugin) : D:\Program Files\VideoLAN\VLC\npvlc.dll [HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect] - () : C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 27.0.0.159 Plugin) : C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_159.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@nvidia.com/3DVision] - (NVIDIA stereo images plugin for Mozilla browsers) : C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming] - (NVIDIA 3D Vision Streaming plugin for Mozilla browsers) : C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect] - () : C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ii7m9bkr.default\Prefs.js user_pref("browser.startup.homepage_override.buildID", "20171002220106"); user_pref("browser.startup.homepage_override.mstone", "56.0.1"); user_pref("e10s.rollout.cohort", "webextensions-multiBucket4"); user_pref("extensions.adblockultimate@adblockultimate.net.app-version", "2.26"); user_pref("extensions.adblockultimate@adblockultimate.net.block-list-domains", "[]"); user_pref("extensions.adblockultimate@adblockultimate.net.client-id", "ukLvo43I729098"); user_pref("extensions.adblockultimate@adblockultimate.net.filters-state", "{\"2\":{\"loaded\":true,\"enabled\":true,\"installed\":true},\"113\":{\"loaded\":true,\"enabled\":true,\"installed\":true}}"); user_pref("extensions.adblockultimate@adblockultimate.net.filters-version", "{\"2\":{\"version\":\"1.1.28.23\",\"lastCheckTime\":1502989809588,\"lastUpdateTime\":1502982033910},\"113\":{\"version\":\"1.0.85.85\",\"lastCheckTime\":1502989810229,\"lastUpdateTime\":1502976709096}}"); user_pref("extensions.adblockultimate@adblockultimate.net.page-statistic", "{\"totalBlocked\":78966}"); user_pref("extensions.adblockultimate@adblockultimate.net.sb-cache", "{}"); user_pref("extensions.adblockultimate@adblockultimate.net.user-rank", 2); user_pref("extensions.adblockultimate@adblockultimate.net.white-list-domains", "[\"get-skins.com\",\"www.s0urce.io\",\"www.dragon-ball-super-streaming.com\"]"); user_pref("extensions.blocklist.pingCountTotal", 226); user_pref("extensions.blocklist.pingCountVersion", 5); user_pref("extensions.databaseSchema", 22); user_pref("extensions.e10s.rollout.blocklist", ""); user_pref("extensions.e10s.rollout.hasAddon", true); user_pref("extensions.e10s.rollout.policy", "50allmpc"); user_pref("extensions.e10sBlockedByAddons", false); user_pref("extensions.e10sMultiBlockedByAddons", false); user_pref("extensions.followonsearch.cohortSample", "0.035691"); user_pref("extensions.getAddons.cache.lastUpdate", 1508354022); user_pref("extensions.getAddons.databaseSchema", 5); user_pref("extensions.hotfix.lastVersion", "20170302.01"); user_pref("extensions.lastAppBuildId", "20171002220106"); user_pref("extensions.lastAppVersion", "56.0.1"); user_pref("extensions.lastPlatformVersion", "56.0.1"); user_pref("extensions.pendingOperations", false); user_pref("extensions.pocket.settings.test.panelSignUp", "v1"); user_pref("extensions.shield-recipe-client.first_run", false); user_pref("extensions.shield-recipe-client.startupExperimentMigrated", true); user_pref("extensions.shield-recipe-client.startupExperimentPrefs.extensions.screenshots.system-disabled", false); user_pref("extensions.shield-recipe-client.user_id", "60a971ca-f231-437d-9cb4-956d80d66d83"); user_pref("extensions.shownSelectionUI", true); user_pref("extensions.systemAddonSet", "{\"schema\":1,\"directory\":\"{380fa774-9ee8-4978-b8f4-f77dc25342fa}\",\"addons\":{\"shield-recipe-client@mozilla.org\":{\"version\":\"65.1\"}}}"); user_pref("extensions.ui.dictionary.hidden", true); user_pref("extensions.ui.experiment.hidden", true); user_pref("extensions.ui.lastCategory", "addons://list/plugin"); user_pref("extensions.ui.locale.hidden", true); user_pref("extensions.webextensions.uuids", "{\"adblockultimate@adblockultimate.net\":\"4199a5e7-3f60-4830-8eff-7f1d211d9a2f\",\"screenshots@mozilla.org\":\"3bbe864a-0cc4-43f3-8dea-87dd7ae20a12\"}"); C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\ii7m9bkr.default [Profile0] - Name=default -> Profiles/ii7m9bkr.default ---------- | DNS [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{1421502C-E9AC-4692-98E4-A0552883C06F}] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{2406EF40-9B85-4602-B239-16C4F889CC60}] "DhcpNameServer"=192.168.42.129 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{97131384-BEEB-46E4-BCBF-29F04B983EB7}] "DhcpNameServer"=192.168.42.129 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1421502C-E9AC-4692-98E4-A0552883C06F}] "DhcpNameServer"=192.168.1.1 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{2406EF40-9B85-4602-B239-16C4F889CC60}] "DhcpNameServer"=192.168.42.129 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{97131384-BEEB-46E4-BCBF-29F04B983EB7}] "DhcpNameServer"=192.168.42.129 ---------- | Applications [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Classes\Applications\csgo.exe] : "d:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe" "%1" [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Classes\Applications\FL.exe] : "D:\Program Files (x86)\Image-Line\FL Studio 11\FL.exe" "%1" [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Classes\Applications\package_inst.exe] : "D:\Program Files (x86)\TeamSpeak 3 Client\package_inst.exe" "%1" [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Classes\Applications\pc3.exe] : "D:\Program Files (x86)\Playlist Creator 3.6.2\pc3.exe" "%1" [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Classes\Applications\uTorrent.exe] : "C:\Users\Thomas\AppData\Roaming\uTorrent\uTorrent.exe" "%1" [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Classes\Applications\virtualdj8.exe] : "D:\Program Files (x86)\VirtualDJ\virtualdj8.exe" "%1" [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Classes\Applications\WinRAR.exe] : "C:\Program Files\WinRAR\WinRAR.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\chrome.exe] : "D:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" [HKLM\SOFTWARE\Classes\Applications\firefox.exe] : "D:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" [HKLM\SOFTWARE\Classes\Applications\hl2.exe] : "d:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\Classes\Applications\Photoshop.exe] : "C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\Classes\Applications\SimCity] : D:\Program Files (x86)\SimCity\SimCity\SimCity.exe "%1" -dataDir:D:\Program Files (x86)\SimCity\SimCityData\ [HKLM\SOFTWARE\Classes\Applications\SZBrowser.exe] : "D:\Program Files\AVAST Software\SZBrowser\Launcher.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\vlc.exe] : "D:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "%1" [HKLM\SOFTWARE\Classes\Applications\vmnt64.exe] : "D:\Program Files (x86)\WinCDEmu\vmnt64.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\chrome.exe] : "D:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\firefox.exe] : "D:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\hl2.exe] : "d:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\Photoshop.exe] : "C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\SimCity] : D:\Program Files (x86)\SimCity\SimCity\SimCity.exe "%1" -dataDir:D:\Program Files (x86)\SimCity\SimCityData\ [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\SZBrowser.exe] : "D:\Program Files\AVAST Software\SZBrowser\Launcher.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\vlc.exe] : "D:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\vmnt64.exe] : "D:\Program Files (x86)\WinCDEmu\vmnt64.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" ---------- | SvcHost (Whitelist) [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "DcomLaunch"=Power LSM BrokerInfrastructure PlugPlay DcomLaunch DeviceInstall SystemEventsBroker "regsvc"=RemoteRegistry "PeerDist"=PeerDistSvc [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost] "DcomLaunch"=PlugPlay DcomLaunch DeviceInstall ---------- | SvcHost - Netsvcs (Whitelist) ---------- | Software [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\2015] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Adobe] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Andy] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\antiufo] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\ApathyWorks] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\AppDataLow] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\AVAST Software] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\awac] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\BEAM Team Games] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Bethesda] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\BitTorrent] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\BlueStacks] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Bugsplat] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Butterflyware] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\cacaoweb] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\CampoSanto] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Cheat Engine] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Chromium] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Clickteam] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Clients] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Colossal Order] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\CoolROM] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Cyanide] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\DefaultCompany] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Dinosaur Polo Club] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Disc Soft] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Drivers] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\ej-technologies] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Elaborate Bytes] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Electronic Arts] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Enterbrain] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Epic Games] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\epsxe] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Eric Haines] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\FredaikisAB] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Freejam] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\FreeReign] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\g3n-h@ckm@n] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Gaijin] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Game Maker] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Gameforge4d] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Gearbox Software] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\GfaceGmbh] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Giant Army] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\GlassWire] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\gmstudio_steam] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\GOG.com] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\GoldenEye Setup Editor] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Google] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Gyazo] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\HngSync] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\IM Providers] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Image-Line] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Imagination Technologies] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\IndieGala] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\InstallPath] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Intel] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\JavaSoft] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\JustCause2] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Landfall Games] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Leadertech] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Licenses] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\LINE Corporation] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\LucasArts Entertainment Company LLC] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Macromedia] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Madruga Works] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\MainConcept] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\MainConcept (Consumer)] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Maxis] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Maxis AiTemp] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\MC4D] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Metal Gear Solid] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Mine] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Minecraft Projects] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Mirillis] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Mojang] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\MountAndBladeWarbandKeys] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Mozilla] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\MozillaPlugins] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Mumble] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Naver] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\NBTExplorer] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\NewZ] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Nexon] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\NHN Corporation] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\NLDT] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\nobodyshot] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\NVIDIA Corporation] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\oddgravity] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\OpenAutomate] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\OpenOffice] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\paint.net] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Pcsx] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\PCSX2] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\PhotoFiltre Studio X] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Piriform] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Pixart] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Pixelife] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Policies] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\QtProject] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\QuickPar] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\RatioMaster.NET] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Reg] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\RegisteredApplications] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\ROBLOX Corporation] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\RobloxReg] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Sauropod Studio] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Scirra] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Secret Exit Ltd.] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\SecuredDownload] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\SecuROM] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\SkillBrains] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\SKS] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Skype] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\SmallGamesInfo] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Smartly Dressed Games] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\SoftVoice] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Software] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\South East Games] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Spiderling Games] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Stage 2 Studios] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\SteamPopCap] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\SteelRaven7] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Studio MDHR] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\StudioQTRobloxReg] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\sysinternals] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\SysProgs] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\System32] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\TeamSpeak 3 Client] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\TechSmith] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\tfdfu] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\The Pokémon Company International] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\THQ] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Trolltech] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Ubisoft] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Unity] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Unity Technologies] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\US Army] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Valve] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\VirtualDJ] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Vision Thing] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Volition] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\WARTEAM] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Win] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\WinRAR] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\WinRAR SFX] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Wow6432Node] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\ZebHelpProcess Helper] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\ZHP] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\AppDataLow\Software\JavaSoft] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\AppDataLow\Software\Microsoft] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\AppDataLow\Software\Unity] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\DWM] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\Roaming] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\Shell] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\Adobe] [HKLM\Software\AGEIA Technologies] [HKLM\Software\Apple Inc.] [HKLM\Software\ATI Technologies] [HKLM\Software\BlueStacks] [HKLM\Software\Clients] [HKLM\Software\CyberGhost] [HKLM\Software\Disc Soft] [HKLM\Software\ej-technologies] [HKLM\Software\EuMus Design] [HKLM\Software\g3n-h@ckm@n] [HKLM\Software\Huawei technologies] [HKLM\Software\IM Providers] [HKLM\Software\Image-Line] [HKLM\Software\Intel] [HKLM\Software\JavaSoft] [HKLM\Software\JreMetrics] [HKLM\Software\Khronos] [HKLM\Software\LogMeIn, Inc.] [HKLM\Software\Macromedia] [HKLM\Software\Maxis] [HKLM\Software\MAXON Installer] [HKLM\Software\mcafeeupdater] [HKLM\Software\Microsoft] [HKLM\Software\Mozilla] [HKLM\Software\MozillaPlugins] [HKLM\Software\NVIDIA Corporation] [HKLM\Software\ODBC] [HKLM\Software\Oracle] [HKLM\Software\paint.net] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\RegisteredApplications] [HKLM\Software\SteelSeries] [HKLM\Software\sysinternals] [HKLM\Software\TeamSpeak 3 Client] [HKLM\Software\VideoLAN] [HKLM\Software\WinRAR] [HKLM\Software\Wow6432Node] [HKLM\Software\{E91885F1-84E4-11d5-898D-0008C725AC74}] [HKLM\Software\Microsoft\Windows\CurrentVersion] [HKLM\Software\Microsoft\Windows\HTML Help] [HKLM\Software\Microsoft\Windows\ITStorage] [HKLM\Software\Microsoft\Windows\ScheduledDiagnostics] [HKLM\Software\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\Microsoft\Windows\Shell] [HKLM\Software\Microsoft\Windows\Tablet PC] [HKLM\Software\Microsoft\Windows\TabletPC] [HKLM\Software\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\Microsoft\Windows\Windows Search] [HKLM\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\defragsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ICService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\print] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\swprv] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\utcsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wcssvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\WepHostSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wercplsupport] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wsappx] [HKLM\Software\WOW6432Node\"alpha_installer"/n] [HKLM\Software\WOW6432Node\"echo_installer"/n] [HKLM\Software\WOW6432Node\Adobe] [HKLM\Software\WOW6432Node\AGEIA Technologies] [HKLM\Software\WOW6432Node\AMD] [HKLM\Software\WOW6432Node\AppDataLow] [HKLM\Software\WOW6432Node\ARTDINK] [HKLM\Software\WOW6432Node\AVAST Software] [HKLM\Software\WOW6432Node\BioWare] [HKLM\Software\WOW6432Node\BlueStacks] [HKLM\Software\WOW6432Node\BlueStacksGP] [HKLM\Software\WOW6432Node\Clickteam] [HKLM\Software\WOW6432Node\Cyanide] [HKLM\Software\WOW6432Node\CyberGhost] [HKLM\Software\WOW6432Node\Disc Soft] [HKLM\Software\WOW6432Node\DSPRobotics] [HKLM\Software\WOW6432Node\EA Games] [HKLM\Software\WOW6432Node\EasyAntiCheat] [HKLM\Software\WOW6432Node\echo_list] [HKLM\Software\WOW6432Node\echo_update] [HKLM\Software\WOW6432Node\Electronic Arts] [HKLM\Software\WOW6432Node\Epic Games] [HKLM\Software\WOW6432Node\EpicGames] [HKLM\Software\WOW6432Node\Fraps] [HKLM\Software\WOW6432Node\Gameforge] [HKLM\Software\WOW6432Node\Gameforge4d] [HKLM\Software\WOW6432Node\gamersfirst] [HKLM\Software\WOW6432Node\GEARBOX] [HKLM\Software\WOW6432Node\GOG.com] [HKLM\Software\WOW6432Node\Google] [HKLM\Software\WOW6432Node\Hydrogen Developers] [HKLM\Software\WOW6432Node\IM Providers] [HKLM\Software\WOW6432Node\Image-Line] [HKLM\Software\WOW6432Node\InstallShield] [HKLM\Software\WOW6432Node\Intel] [HKLM\Software\WOW6432Node\IObit] [HKLM\Software\WOW6432Node\JavaSoft] [HKLM\Software\WOW6432Node\JreMetrics] [HKLM\Software\WOW6432Node\Khronos] [HKLM\Software\WOW6432Node\LMMS Developers] [HKLM\Software\WOW6432Node\LogMeIn Hamachi] [HKLM\Software\WOW6432Node\LucasArts] [HKLM\Software\WOW6432Node\LucasArts Entertainment Company LLC] [HKLM\Software\WOW6432Node\Macromedia] [HKLM\Software\WOW6432Node\Malwarebytes' Anti-Malware] [HKLM\Software\WOW6432Node\Maxis] [HKLM\Software\WOW6432Node\McAfee.com] [HKLM\Software\WOW6432Node\mcafeeupdater] [HKLM\Software\WOW6432Node\Metin2_FR] [HKLM\Software\WOW6432Node\Microsoft] [HKLM\Software\WOW6432Node\Mojang] [HKLM\Software\WOW6432Node\Mozilla] [HKLM\Software\WOW6432Node\mozilla.org] [HKLM\Software\WOW6432Node\MozillaPlugins] [HKLM\Software\WOW6432Node\Naver] [HKLM\Software\WOW6432Node\NHN Corporation] [HKLM\Software\WOW6432Node\Nostale_FR] [HKLM\Software\WOW6432Node\Notepad++] [HKLM\Software\WOW6432Node\NVIDIA Corporation] [HKLM\Software\WOW6432Node\ODBC] [HKLM\Software\WOW6432Node\OpenOffice] [HKLM\Software\WOW6432Node\Origin] [HKLM\Software\WOW6432Node\Origin Games] [HKLM\Software\WOW6432Node\Overwolf] [HKLM\Software\WOW6432Node\Paradox Interactive] [HKLM\Software\WOW6432Node\PCSX2] [HKLM\Software\WOW6432Node\Piriform] [HKLM\Software\WOW6432Node\PocketSoft] [HKLM\Software\WOW6432Node\Propellerhead Software] [HKLM\Software\WOW6432Node\Reg] [HKLM\Software\WOW6432Node\Runes of Magic] [HKLM\Software\WOW6432Node\Skillbrains] [HKLM\Software\WOW6432Node\Skype] [HKLM\Software\WOW6432Node\SoftVoice] [HKLM\Software\WOW6432Node\Software] [HKLM\Software\WOW6432Node\Songbird] [HKLM\Software\WOW6432Node\Synthesia] [HKLM\Software\WOW6432Node\TeamSpeak 3 Client] [HKLM\Software\WOW6432Node\TechSmith] [HKLM\Software\WOW6432Node\THQ] [HKLM\Software\WOW6432Node\trex] [HKLM\Software\WOW6432Node\Ubi Soft Entertainment] [HKLM\Software\WOW6432Node\Ubisoft] [HKLM\Software\WOW6432Node\updated_list] [HKLM\Software\WOW6432Node\US Army] [HKLM\Software\WOW6432Node\Valve] [HKLM\Software\WOW6432Node\VirtualDJ] [HKLM\Software\WOW6432Node\Vstep] [HKLM\Software\WOW6432Node\Wow6432Node] [HKLM\Software\WOW6432Node\Zemi Interactive] [HKLM\Software\WOW6432Node\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}] [HKLM\Software\WOW6432Node\Clients] [HKLM\Software\WOW6432Node\Policies] [HKLM\Software\WOW6432Node\RegisteredApplications] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows\HTML Help] [HKLM\Software\WOW6432Node\Microsoft\Windows\ITStorage] [HKLM\Software\WOW6432Node\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Search] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\wcssvc] ---------- | Drives D: [01/12/2006 23:37:14] - |A| - (.© Microsoft Corporation. - Microsoft® Debug Information Accessor.) - [904704] - (8.0.50727.762) - D:\msdia80.dll ---------- | C: [21/04/2017 17:00:19] - |HDC| - [225280] - C:\$AV_ASW [22/08/2013 17:36:31] - |SHD| - [23235] - C:\$Recycle.Bin [16/08/2015 14:14:22] - |HD| - [148795302] - C:\$Windows.~BT [MD5.21BF183C15AFE62A8D1137BB9007B2A3] - [26/07/2012 10:18:43] - |RASH| - (.-.) - [398156] - (0.0.0.0) - C:\bootmgr [MD5.93B885ADFE0DA089CDF634904FD59F71] - [26/07/2012 10:18:43] - |ASHC| - (.-.) - [1] - (0.0.0.0) - C:\BOOTNXT [22/08/2013 16:45:52] - |SHD| - [0] - C:\Documents and Settings [22/08/2013 15:36:15] - |RD| - [4806264669] - C:\Program Files [22/08/2013 15:36:15] - |RD| - [2834908082] - C:\Program Files (x86) [22/08/2013 15:36:15] - |HD| - [12389079941] - C:\ProgramData [19/10/2017 18:42:52] - |DC| - [68684] - C:\QuickDiag [MD5.E114FB5613FF3F8AD60943DA875E7176] - [19/10/2017 18:44:41] - |AC| - (.-.) - [444008] - (0.0.0.0) - C:\QuickDiag.txt [MD5.D41D8CD98F00B204E9800998ECF8427E] - [05/04/2015 15:41:19] - |ASH| - (.-.) - [268435456] - (0.0.0.0) - C:\swapfile.sys [22/12/2014 22:09:40] - |SHD| - [2614676] - C:\System Volume Information [22/08/2013 15:36:15] - |RD| - [26041522777] - C:\Users [22/08/2013 15:36:15] - |D| - [27884639807] - C:\Windows ---------- | C:\WINDOWS [22/08/2013 17:36:30] - |D| - [802] - C:\WINDOWS\addins [22/08/2013 17:36:31] - |D| - [1175552] - C:\WINDOWS\ADFS [22/08/2013 17:36:30] - |D| - [34945224] - C:\WINDOWS\AppCompat [22/08/2013 17:36:31] - |D| - [12004256] - C:\WINDOWS\apppatch [22/08/2013 17:36:30] - |D| - [0] - C:\WINDOWS\AppReadiness [22/08/2013 17:36:30] - |RSD| - [955621627] - C:\WINDOWS\assembly [MD5.FA78F9739F8F0239A539A06B10D354C7] - [22/08/2013 13:21:53] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Utilitaire de service de fichier de démarrage.) - [56832] - (6.3.9600.16384) - C:\WINDOWS\bfsvc.exe [21/11/2014 00:27:34] - |SHD| - [586747] - C:\WINDOWS\BitLockerDiscoveryVolumeContents [22/08/2013 17:36:31] - |D| - [36950400] - C:\WINDOWS\Boot [MD5.EB7375282B3B7421975B6CC38F5C519E] - [22/08/2013 16:46:23] - |AS| - (.-.) - [67584] - (0.0.0.0) - C:\WINDOWS\bootstat.dat [22/08/2013 17:36:31] - |D| - [2295864] - C:\WINDOWS\Branding [22/08/2013 17:36:30] - |D| - [7211564] - C:\WINDOWS\Camera [26/07/2012 09:59:48] - |D| - [10773] - C:\WINDOWS\CbsTemp [22/12/2014 22:13:58] - |D| - [0] - C:\WINDOWS\CSC [22/08/2013 17:36:30] - |D| - [4503720] - C:\WINDOWS\Cursors [22/08/2013 17:36:31] - |D| - [25873] - C:\WINDOWS\debug [22/08/2013 17:36:30] - |RD| - [22590] - C:\WINDOWS\DesktopTileResources [MD5.81DD33EC695AB90466031CF430CFA1BD] - [05/04/2015 15:47:46] - |A| - (.-.) - [20958] - (0.0.0.0) - C:\WINDOWS\diagerr.xml [22/08/2013 17:36:30] - |D| - [3539068] - C:\WINDOWS\diagnostics [MD5.81DD33EC695AB90466031CF430CFA1BD] - [05/04/2015 15:47:46] - |A| - (.-.) - [20958] - (0.0.0.0) - C:\WINDOWS\diagwrn.xml [22/08/2013 17:43:29] - |D| - [0] - C:\WINDOWS\DigitalLocker [22/08/2013 17:36:31] - |SD| - [65] - C:\WINDOWS\Downloaded Program Files [04/05/2015 11:41:12] - |SHD| - [0] - C:\WINDOWS\ei_temp [26/07/2012 10:12:59] - |HD| - [0] - C:\WINDOWS\ELAMBKUP [22/08/2013 17:43:29] - |D| - [0] - C:\WINDOWS\en-US [MD5.7CEFCABDEDDDA428B2658D6C501F0DC7] - [11/11/2015 17:21:35] - |A| - (.-.) - [571] - (0.0.0.0) - C:\WINDOWS\eReg.dat [MD5.ED6B4C95E2A6D67480B9DBB8A8E7D9B4] - [17/10/2016 11:32:34] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [2755504] - (6.3.9600.18460) - C:\WINDOWS\explorer.exe [22/08/2013 17:36:30] - |D| - [14519113] - C:\WINDOWS\FileManager [22/08/2013 15:36:15] - |RSD| - [724642465] - C:\WINDOWS\Fonts [21/11/2014 00:02:54] - |D| - [111616] - C:\WINDOWS\fr-FR [22/08/2013 17:36:30] - |D| - [93330981] - C:\WINDOWS\Globalization [22/08/2013 17:36:31] - |D| - [72009265] - C:\WINDOWS\Help [MD5.95DBA7370490F85BD8A48B913A3D8541] - [18/07/2017 12:00:04] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Aide et support Microsoft.) - [1001984] - (6.3.9600.18722) - C:\WINDOWS\HelpPane.exe [MD5.B934411DFE7DEACFA95A1255A48133C9] - [21/11/2014 01:20:03] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Exécutable de l’aide HTML Microsoft®.) - [17408] - (6.3.9600.17415) - C:\WINDOWS\hh.exe [22/08/2013 17:36:30] - |D| - [152844180] - C:\WINDOWS\IME [22/08/2013 17:36:31] - |RD| - [7288116] - C:\WINDOWS\ImmersiveControlPanel [22/08/2013 15:36:15] - |D| - [51068777] - C:\WINDOWS\Inf [22/08/2013 17:36:31] - |D| - [119175822] - C:\WINDOWS\InputMethod [22/08/2013 17:36:31] - |SHD| - [814261565] - C:\WINDOWS\Installer [22/08/2013 17:36:31] - |D| - [61417] - C:\WINDOWS\L2Schemas [22/08/2013 17:36:31] - |D| - [2325923] - C:\WINDOWS\LiveKernelReports [22/08/2013 15:36:15] - |D| - [167464587] - C:\WINDOWS\Logs [22/08/2013 17:36:30] - |RSD| - [19944453] - C:\WINDOWS\Media [22/08/2013 17:36:31] - |D| - [18917376] - C:\WINDOWS\MediaViewer [MD5.23AF90D2355D8C83AA4567EF1763B467] - [22/08/2013 09:01:23] - |A| - (.-.) - [43131] - (0.0.0.0) - C:\WINDOWS\mib.bin [22/08/2013 17:36:30] - |D| - [820404710] - C:\WINDOWS\Microsoft.NET [22/05/2015 17:51:13] - |D| - [1263] - C:\WINDOWS\Migration [06/06/2015 21:19:50] - |D| - [0] - C:\WINDOWS\Minidump [26/07/2012 10:12:59] - |D| - [0] - C:\WINDOWS\ModemLogs [MD5.FC2EA5BD5307D2CFA5AAA38E0C0DDCE9] - [12/08/2015 11:44:23] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Bloc-notes.) - [221184] - (6.3.9600.17930) - C:\WINDOWS\notepad.exe [MD5.74F28574BB8F61FFC7DD419FE6B6E0D5] - [08/03/2017 20:28:17] - |A| - (.-.) - [1951] - (0.0.0.0) - C:\WINDOWS\NvContainerRecovery.bat [MD5.74F28574BB8F61FFC7DD419FE6B6E0D5] - [14/04/2017 18:44:44] - |A| - (.-.) - [1951] - (0.0.0.0) - C:\WINDOWS\NvTelemetryContainerRecovery.bat [22/08/2013 17:36:30] - |RD| - [65] - C:\WINDOWS\Offline Web Pages [05/04/2015 16:40:05] - |DC| - [69526746] - C:\WINDOWS\Panther [22/08/2013 17:36:30] - |D| - [45532809] - C:\WINDOWS\Performance [22/08/2013 17:36:30] - |D| - [1136441] - C:\WINDOWS\PLA [22/08/2013 17:36:30] - |D| - [6105281] - C:\WINDOWS\PolicyDefinitions [05/04/2015 15:42:06] - |D| - [42078713] - C:\WINDOWS\Prefetch [MD5.ACBB258BD003F4986AFD0197C5F018B6] - [21/11/2014 00:27:50] - |A| - (.-.) - [36235] - (0.0.0.0) - C:\WINDOWS\Professional.xml [MD5.B67DB709F5FDAA89CA6C2CB6C1E39B3B] - [21/11/2014 01:19:47] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Éditeur du Registre.) - [154624] - (6.3.9600.17415) - C:\WINDOWS\regedit.exe [22/08/2013 17:36:30] - |D| - [1095144] - C:\WINDOWS\Registration [22/08/2013 17:36:30] - |D| - [2444584] - C:\WINDOWS\rescache [22/08/2013 17:36:31] - |D| - [2716159] - C:\WINDOWS\Resources [26/07/2012 10:12:59] - |D| - [0] - C:\WINDOWS\SchCache [22/08/2013 17:36:30] - |D| - [118561] - C:\WINDOWS\schemas [22/08/2013 17:36:31] - |D| - [1071810] - C:\WINDOWS\security [22/08/2013 16:45:15] - |D| - [67147469] - C:\WINDOWS\ServiceProfiles [22/08/2013 15:36:15] - |D| - [266190420] - C:\WINDOWS\servicing [22/08/2013 16:45:23] - |D| - [42] - C:\WINDOWS\Setup [MD5.7BB8C6F58C74DFF69BFFB0571D30F58E] - [12/10/2017 18:16:52] - |A| - (.-.) - [1617] - (0.0.0.0) - C:\WINDOWS\setupact.log [MD5.D41D8CD98F00B204E9800998ECF8427E] - [12/10/2017 18:16:52] - |A| - (.-.) - [0] - (0.0.0.0) - C:\WINDOWS\setuperr.log [21/11/2014 00:27:34] - |D| - [31373168] - C:\WINDOWS\SKB [MD5.7F2F0AC82583EA36913B9C21DEE306CD] - [06/12/2015 18:17:07] - |A| - (.-.) - [137] - (0.0.0.0) - C:\WINDOWS\Sof2.INI [22/12/2014 22:13:54] - |D| - [1121942638] - C:\WINDOWS\SoftwareDistribution [22/08/2013 17:36:30] - |D| - [103543351] - C:\WINDOWS\Speech [MD5.4D9DA155B7B449964E14FC32124CC601] - [21/11/2014 01:20:20] - |A| - (.© Microsoft Corporation. - Print driver host for applications.) - [128512] - (6.3.9600.17415) - C:\WINDOWS\splwow64.exe [MD5.A77E65831A152C8FCA5B822749E2624D] - [22/08/2013 17:19:59] - |A| - (.-.) - [35891] - (0.0.0.0) - C:\WINDOWS\Starter.xml [25/12/2014 16:07:00] - |D| - [0] - C:\WINDOWS\Sun [22/08/2013 17:36:30] - |D| - [31039] - C:\WINDOWS\System [MD5.286A9EDB379DC3423A528B0864A0F111] - [22/08/2013 15:25:43] - |A| - (.-.) - [219] - (0.0.0.0) - C:\WINDOWS\system.ini [22/08/2013 15:36:16] - |D| - [4692607764] - C:\WINDOWS\System32 [22/08/2013 17:36:30] - |D| - [8554944] - C:\WINDOWS\SystemResources [22/08/2013 15:36:16] - |D| - [1544330786] - C:\WINDOWS\SysWOW64 [22/08/2013 17:36:30] - |D| - [1126] - C:\WINDOWS\Tasks [22/08/2013 15:36:16] - |D| - [69519977] - C:\WINDOWS\Temp [22/08/2013 17:36:30] - |RD| - [22151] - C:\WINDOWS\ToastData [22/08/2013 17:36:31] - |D| - [0] - C:\WINDOWS\tracing [22/08/2013 17:36:31] - |D| - [7680] - C:\WINDOWS\twain_32 [MD5.727B4519FE9919447108CBEC4768F34A] - [21/11/2014 01:21:24] - |A| - (.- Gestionnaire de sources Twain_32 (Image Acquisition Interface).) - [54272] - (1.7.1.3) - C:\WINDOWS\twain_32.dll [22/08/2013 17:36:30] - |D| - [15612486] - C:\WINDOWS\vpnplugins [22/08/2013 17:36:30] - |D| - [12420] - C:\WINDOWS\Vss [22/08/2013 17:36:31] - |D| - [8817972] - C:\WINDOWS\Web [MD5.9E5B73218ACD44EB6D292F17CAEE52BD] - [26/07/2012 07:26:52] - |A| - (.-.) - [194] - (0.0.0.0) - C:\WINDOWS\win.ini [MD5.C844CA459F3B209329984772269B6E56] - [22/08/2013 08:53:50] - |RAH| - (.-.) - [670] - (0.0.0.0) - C:\WINDOWS\WindowsShell.Manifest [MD5.85D830C32B1605E65CBD82D9BA4E5C63] - [11/10/2017 16:11:46] - |A| - (.-.) - [782531] - (0.0.0.0) - C:\WINDOWS\WindowsUpdate.log [MD5.335C38783B3F1B383ECAC17DB3705895] - [21/11/2014 01:19:16] - |A| - (.© Microsoft Corporation. Tous droits réservés. - Relais Windows Winhlp32.) - [9728] - (6.3.9600.17415) - C:\WINDOWS\winhlp32.exe [22/08/2013 17:36:31] - |D| - [1793538] - C:\WINDOWS\WinStore [22/08/2013 15:36:16] - |D| - [15638295461] - C:\WINDOWS\WinSxS [MD5.E7E4D8D7340DA6934B9EA81CBB21374C] - [22/08/2013 08:52:18] - |A| - (.-.) - [316640] - (0.0.0.0) - C:\WINDOWS\WMSysPr9.prx [MD5.73E19BE0E0ECD88616B5762F621B0226] - [21/11/2014 01:20:23] - |A| - (.© Microsoft Corporation. - Windows Write.) - [11264] - (6.3.9600.17415) - C:\WINDOWS\write.exe ---------- | C:\WINDOWS\System32\GroupPolicy [MD5.E12324ACF507ACE937B7FEC19E97D9AE] - [11/07/2015 11:32:43] - |A| - (.-.) - [127] - (0.0.0.0) - C:\WINDOWS\System32\GroupPolicy\gpt.ini [11/07/2015 11:32:43] - |D| - [626] - C:\WINDOWS\System32\GroupPolicy\machine ---------- | Systemroot\System ---------- | Systemroot\Installer (Microsoft Files Whitelisted) [20/06/2015 20:29:36] - C:\WINDOWS\Installer\1193c060.msi : (Adobe Download Assistant - Adobe Systems Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [12/02/2015 22:20:34] - C:\WINDOWS\Installer\150cb398.msi : (BlueStacks - BlueStack Systems, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [07/05/2017 10:50:09] - C:\WINDOWS\Installer\163f54.msi : (Java SE Runtime Environment 8 Update 131 - Oracle Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [07/05/2017 10:51:32] - C:\WINDOWS\Installer\163f5f.msi : (Java Auto Updater - Oracle Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [27/06/2016 13:56:42] - C:\WINDOWS\Installer\1e7bc6cc.msi : (Minecraft - Mojang) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [09/02/2017 19:50:27] - C:\WINDOWS\Installer\22c8cd.msi : (TrackMania Unlimiter - TrackMania Unlimiter) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [23/04/2017 20:53:20] - C:\WINDOWS\Installer\258023d.msi : ( - RealWorld Graphics) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [08/06/2016 21:18:14] - C:\WINDOWS\Installer\263c7c2e.msi : (NBTExplorer - Justin Aquadro) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [03/04/2017 22:14:15] - C:\WINDOWS\Installer\2e8812.msi : (Adobe AIR Installer - Adobe Systems Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [03/04/2017 22:15:36] - C:\WINDOWS\Installer\2e8825.msi : (Java SE Runtime Environment 8 Update 121 - Oracle Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [11/07/2017 10:20:11] - C:\WINDOWS\Installer\31e61.msi : (LogMeIn Hamachi Installer - LogMeIn, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [14/06/2013 13:30:16] - C:\WINDOWS\Installer\32b663e5.msi : (Intel(R) C++ Redistributables on Intel(R) 64 - Intel Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [16/09/2017 13:43:15] - C:\WINDOWS\Installer\35695.msi : (Google Earth Pro - Google) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [18/03/2015 12:25:27] - C:\WINDOWS\Installer\41c777fa.msi : (Scrolls - Mojang) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [24/03/2016 21:53:27] - C:\WINDOWS\Installer\4258ce22.msi : (Oracle VM VirtualBox 4.3.12_ZZZZ installation package - Oracle Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [29/09/2016 19:11:18] - C:\WINDOWS\Installer\61dcbf8.msi : (OpenOffice 4.1.3 - OpenOffice) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [05/12/2015 03:31:24] - C:\WINDOWS\Installer\8be8a15.msi : (Blank Project Template - Adobe) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [05/12/2015 03:31:24] - C:\WINDOWS\Installer\8be8a1c.msi : (Blank Project Template - Adobe) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/05/2017 12:57:35] - C:\WINDOWS\Installer\8da72.msi : (Google Update Helper - Google Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [28/01/2017 01:32:16] - C:\WINDOWS\Installer\8e3a149.msi : (Mumble 1.2.19 - Thorvald Natvig) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [10/08/2009 18:12:02] - C:\WINDOWS\Installer\9b9de33.msi : (LEGO® Star Wars™: The Complete Saga - LucasArts) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [01/10/2017 10:33:56] - C:\WINDOWS\Installer\9da39.msi : (Epic Games Launcher - Epic Games, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [19/11/2015 10:56:58] - C:\WINDOWS\Installer\9da3e.msi : (Epic Games Launcher Prerequisites (x64) - Epic Games, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [05/01/2016 18:56:12] - C:\WINDOWS\Installer\ad9f67.msi : ( - dotPDN LLC) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [12/09/2017 11:01:41] - C:\WINDOWS\Installer\b7686.msi : (Skype - Skype Technologies S.A.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [26/09/2005 23:18:51] - C:\WINDOWS\Installer\f99655f.msi : (Blank Project Template - InstallShield Software Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] [27/12/2015 23:27:18] - C:\WINDOWS\Installer\fe5c6fb.msi : (VirtualDJ 8 Installer - Atomix Productions) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000] ---------- | %System%\*.in* [30/08/2015 15:37:45] - [2424] - C:\WINDOWS\System32\ConjimaaniOff.ini [22/08/2013 17:36:48] - [75] - C:\WINDOWS\System32\desktop.ini [15/04/2015 12:40:52] - [16303] - C:\WINDOWS\System32\ieuinit.inf [21/11/2014 00:46:25] - [5430] - C:\WINDOWS\System32\PerfStringBackup.INI [22/08/2013 08:56:03] - [60124] - C:\WINDOWS\System32\tcpmon.ini [21/11/2014 00:55:42] - [2255] - C:\WINDOWS\System32\WimBootCompress.ini [15/04/2015 12:40:52] - [16303] - C:\WINDOWS\Syswow64\ieuinit.inf [07/09/2015 17:20:23] - [0] - C:\WINDOWS\Syswow64\Nadeo.ini [21/11/2014 00:55:58] - [2255] - C:\WINDOWS\Syswow64\WimBootCompress.ini ---------- | Listing no Microsoft signed files (Not necessary Malwares) | system32 | Syswow64 | General scan [MD5.00000000000000000000000000000000] - |D| - [26/07/2012 10:12:59] - [0 Ko] - C:\WINDOWS\AppPatch\Custom\Custom64 [MD5.BE452D7BF880125D2832F99BFDBFD1AE] - |A| - [22/08/2013 08:57:05] - (.-.) - [6.83 Ko] - (0.0.0.0) - C:\WINDOWS\AppPatch\AppPatch64\pcamain.sdb [MD5.3F668EB300F67E3BFA6ED02B0E04C720] - |A| - [13/04/2016 11:42:01] - (.-.) - [423.33 Ko] - (0.0.0.0) - C:\WINDOWS\AppPatch\AppPatch64\sysmain.sdb [MD5.5AF33065FFEA218BBE7F667BF2B1E31D] - |A| - [11/09/2017 19:52:16] - (.-.) - [1129.6 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\adobegc.log [MD5.00000000000000000000000000000000] - |D| - [11/10/2017 18:24:37] - [62651.57 Ko] - C:\WINDOWS\Temp\avast_ash2 [MD5.00000000000000000000000000000000] - |D| - [11/09/2017 19:52:18] - [3940.18 Ko] - C:\WINDOWS\Temp\CreativeCloud [MD5.70A9961232B30966C6BBD0D7C9431CC7] - |A| - [12/10/2017 18:18:23] - (.-.) - [8.64 Ko] - (0.0.0.0) - C:\WINDOWS\Temp\HamachiSetup.log [MD5.00000000000000000000000000000000] - |D| - [12/10/2017 18:18:45] - [3.94 Ko] - C:\WINDOWS\Temp\HP [MD5.00000000000000000000000000000000] - |D| - [27/03/2017 19:11:08] - [156.67 Ko] - C:\WINDOWS\Temp\SafeZone Installer [MD5.00000000000000000000000000000000] - |D| - [27/03/2017 19:09:40] - [0 Ko] - C:\WINDOWS\Temp\_avast_ [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:52] - [0 Ko] - C:\WINDOWS\System32\0409 [MD5.00000000000000000000000000000000] - |D| - [26/07/2012 12:08:57] - [0 Ko] - C:\WINDOWS\System32\040C [MD5.00000000000000000000000000000000] - |D| - [30/08/2015 15:37:19] - [0 Ko] - C:\WINDOWS\System32\abis [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [3882.5 Ko] - C:\WINDOWS\System32\AdvancedInstallers [MD5.4AA372F0DF476DDCC0C858582BE789CB] - |A| - [18/07/2017 11:59:46] - (.-.) - [438.06 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ApnDatabase.xml [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\System32\AppLocker [MD5.00000000000000000000000000000000] - |D| - [26/12/2014 10:25:01] - [0 Ko] - C:\WINDOWS\System32\appmgmt [MD5.00000000000000000000000000000000] - |D| - [07/04/2015 20:40:24] - [2485.91 Ko] - C:\WINDOWS\System32\appraiser [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [544.17 Ko] - C:\WINDOWS\System32\ar-SA [MD5.E5555B741B28425992E8CC2AE6DFCB37] - |A| - [10/10/2017 20:19:50] - (.Copyright (c) 2014 AVAST Software - Avast start-up scanner.) - [392.08 Ko] - (17.7.3660.0) - C:\WINDOWS\System32\aswBoot.exe [MD5.D8632E54B9D4BA45916B0E0D4DD73535] - |A| - [28/03/2015 23:27:44] - (.-.) - [10.84 Ko] - (0.0.0.0) - C:\WINDOWS\System32\AutoconfigV2.cab [MD5.00000000000000000000000000000000] - |D| - [29/03/2015 03:00:50] - [0 Ko] - C:\WINDOWS\System32\AutoUpdateLicense [MD5.D638E3AD81E149A75EEF59E9C743E27C] - |A| - [22/08/2013 17:36:38] - (.-.) - [0.38 Ko] - (0.0.0.0) - C:\WINDOWS\System32\AutoWorkplace.exe.config [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [543.6 Ko] - C:\WINDOWS\System32\bg-BG [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [5993.31 Ko] - C:\WINDOWS\System32\Boot [MD5.A5F320FFE96F6939D2FF39360ADA9B5A] - |A| - [21/11/2014 01:20:11] - (.Copyright (C) 2008 - Gestionnaire de contexte pour réseau personnel Bluetooth.) - [94 Ko] - (1.0.0.1) - C:\WINDOWS\System32\BthpanContextHandler.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [0.93 Ko] - C:\WINDOWS\System32\Bthprops [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [180607.54 Ko] - C:\WINDOWS\System32\catroot [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [73632.44 Ko] - C:\WINDOWS\System32\catroot2 [MD5.9748774B45331802F3C9B4958DBFF57B] - |A| - [30/08/2011 07:06:14] - (.Copyright CANON INC. 2008 All Rights Reserved - Canon Inkjet Printer Driver.) - [261.5 Ko] - (0.3.1536.1) - C:\WINDOWS\System32\CNBLM4.DLL [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [1109.56 Ko] - C:\WINDOWS\System32\CodeIntegrity [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [362.5 Ko] - C:\WINDOWS\System32\Com [MD5.00000000000000000000000000000000] - |SD| - [21/11/2014 08:20:07] - [1440.19 Ko] - C:\WINDOWS\System32\CompatTel [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [353257.24 Ko] - C:\WINDOWS\System32\config [MD5.00000000000000000000000000000000] - |SD| - [22/08/2013 17:36:31] - [20.49 Ko] - C:\WINDOWS\System32\Configuration [MD5.5FD9FDF809513E3C3E9F7ED01D414069] - |A| - [30/08/2015 15:37:45] - (.-.) - [2.37 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ConjimaaniOff.ini [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [402.18 Ko] - C:\WINDOWS\System32\cs-CZ [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [368.79 Ko] - C:\WINDOWS\System32\da-DK [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [420.63 Ko] - C:\WINDOWS\System32\de-DE [MD5.08750A50CF027F93070C8BB78E27C3B7] - |ASH| - [22/08/2013 17:36:48] - (.-.) - [0.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\desktop.ini [MD5.DCF2510E0745720E543E84F5E921FCC0] - |A| - [21/11/2014 00:56:29] - (.-.) - [256.19 Ko] - (0.0.0.0) - C:\WINDOWS\System32\dfpinc.dat [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [6173.17 Ko] - C:\WINDOWS\System32\Dism [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [328 Ko] - C:\WINDOWS\System32\downlevel [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [81956.47 Ko] - C:\WINDOWS\System32\drivers [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:31:28] - [1252956.89 Ko] - C:\WINDOWS\System32\DriverStore [MD5.00000000000000000000000000000000] - |DC| - [10/06/2015 17:22:01] - [260 Ko] - C:\WINDOWS\System32\DRVSTORE [MD5.00000000000000000000000000000000] - |SD| - [22/08/2013 17:36:30] - [88.5 Ko] - C:\WINDOWS\System32\dsc [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [648.92 Ko] - C:\WINDOWS\System32\el-GR [MD5.96106D8A73B5567A7FE51D31115C8212] - |A| - [05/04/2015 16:01:20] - (.-.) - [22.57 Ko] - (0.0.0.0) - C:\WINDOWS\System32\emptyregdb.dat [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:52] - [3 Ko] - C:\WINDOWS\System32\en [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [304.1 Ko] - C:\WINDOWS\System32\en-GB [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [1287.41 Ko] - C:\WINDOWS\System32\en-US [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [400.01 Ko] - C:\WINDOWS\System32\es-ES [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [308.87 Ko] - C:\WINDOWS\System32\et-EE [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [390.69 Ko] - C:\WINDOWS\System32\fi-FI [MD5.FEFF27B893E73212A95E7321222273A4] - |A| - [28/05/2013 22:23:14] - (.-.) - [637 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ficvdec_x64.dll [MD5.944C1D4E9539C077BD9B1192D3B81DAE] - |A| - [22/08/2013 16:44:50] - (.-.) - [4868.63 Ko] - (0.0.0.0) - C:\WINDOWS\System32\FNTCACHE.DAT [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:52] - [1711 Ko] - C:\WINDOWS\System32\fr [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [41815.76 Ko] - C:\WINDOWS\System32\fr-FR [MD5.D8201D1939FC118D90BB464243AF50F4] - |A| - [26/02/2013 08:31:28] - (.Copyright © Beepa P/L 2013 - Fraps.) - [70 Ko] - (3.5.99.15618) - C:\WINDOWS\System32\frapsv64.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\System32\FxsTmp [MD5.55158C8F4CFAB021134137B68BBFD01F] - |A| - [22/08/2013 08:58:31] - (.-.) - [72.53 Ko] - (0.0.0.0) - C:\WINDOWS\System32\gatherNetworkInfo.vbs [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0.74 Ko] - C:\WINDOWS\System32\GroupPolicy [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\System32\GroupPolicyUsers [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [501.56 Ko] - C:\WINDOWS\System32\he-IL [MD5.E299CA629E98F6492E16D2356D8BCD51] - |A| - [23/01/2016 22:49:20] - (.-.) - [37.67 Ko] - (0.0.0.0) - C:\WINDOWS\System32\icons.png [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [36.27 Ko] - C:\WINDOWS\System32\icsxml [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [23350.17 Ko] - C:\WINDOWS\System32\IME [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\System32\inetsrv [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [4637.5 Ko] - C:\WINDOWS\System32\InputMethod [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\System32\Ipmi [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [423.46 Ko] - C:\WINDOWS\System32\it-IT [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [574.94 Ko] - C:\WINDOWS\System32\ja-JP [MD5.AA2F3D9F789F071F90B398CC7D40330E] - |A| - [25/12/2014 20:43:19] - (.Copyright © 2013 - Java(TM) Platform SE binary.) - [184.91 Ko] - (7.0.510.13) - C:\WINDOWS\System32\java.exe [MD5.83EEFE83438AEF9FBB7613A106C5E5BB] - |A| - [25/12/2014 20:43:19] - (.Copyright © 2013 - Java(TM) Platform SE binary.) - [184.91 Ko] - (7.0.510.13) - C:\WINDOWS\System32\javaw.exe [MD5.111011F4D527CE443544F7574E599BD9] - |A| - [21/11/2014 01:19:32] - (.-.) - [2.36 Ko] - (0.0.0.0) - C:\WINDOWS\System32\KeyboardFilterShim.sdb [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [684.01 Ko] - C:\WINDOWS\System32\ko-KR [MD5.FAFA8B2317AABF4EBDC94D74CDB73394] - |A| - [22/08/2013 08:59:51] - (.-.) - [11741.31 Ko] - (0.0.0.0) - C:\WINDOWS\System32\korwbrkr.lex [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [90.07 Ko] - C:\WINDOWS\System32\Licenses [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [22042.56 Ko] - C:\WINDOWS\System32\LogFiles [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [345.5 Ko] - C:\WINDOWS\System32\lt-LT [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [361.77 Ko] - C:\WINDOWS\System32\lv-LV [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [58739.57 Ko] - C:\WINDOWS\System32\Macromed [MD5.7A495CA1402C2F9F5D035092AD808669] - |A| - [22/08/2013 08:52:45] - (.-.) - [0.85 Ko] - (0.0.0.0) - C:\WINDOWS\System32\manage-bde.wsf [MD5.00000000000000000000000000000000] - |SD| - [22/08/2013 16:45:10] - [1125.12 Ko] - C:\WINDOWS\System32\Microsoft [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [4611 Ko] - C:\WINDOWS\System32\migration [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [44102.56 Ko] - C:\WINDOWS\System32\migwiz [MD5.3774B5C0E0BBA8C8EE54DF3606AB815C] - |A| - [22/08/2013 08:53:23] - (.-.) - [1.14 Ko] - (0.0.0.0) - C:\WINDOWS\System32\migwiz.lnk [MD5.3214D6B1B7D9AA2C1C958705A9EEE990] - |A| - [09/04/2013 11:42:06] - (.Copyright (c) 2009 Pixart Imaging Inc. - pximouse.) - [154 Ko] - (1.0.0.1) - C:\WINDOWS\System32\mousecpl.dll [MD5.00000000000000000000000000000000] - |D| - [25/12/2014 16:32:34] - [9.29 Ko] - C:\WINDOWS\System32\MRT [MD5.D41D8CD98F00B204E9800998ECF8427E] - |AC| - [25/12/2014 16:32:32] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\System32\MRT.exe [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [45.5 Ko] - C:\WINDOWS\System32\MSDRM [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [4196.28 Ko] - C:\WINDOWS\System32\MsDtc [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [18.65 Ko] - C:\WINDOWS\System32\MUI [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [371.41 Ko] - C:\WINDOWS\System32\nb-NO [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [640 Ko] - C:\WINDOWS\System32\NDF [MD5.779FDEFF50AF3C6D1581EA17990E6453] - |A| - [22/12/2014 22:21:53] - (.-.) - [1.22 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-176733.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [22/12/2014 22:21:55] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-178683.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [22/12/2014 22:22:03] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-187388.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [22/12/2014 22:22:03] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-187419.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [22/12/2014 22:22:09] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-193082.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [22/12/2014 22:22:14] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-198058.txt [MD5.A14A9B5B1E35235B225953A8AF11E124] - |A| - [22/12/2014 22:22:14] - (.-.) - [1.07 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-198448.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [25/12/2014 20:37:04] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-20410453.txt [MD5.3FBD575F59DB4CAE217018F24BFBCFAF] - |A| - [22/12/2014 22:23:05] - (.-.) - [1.22 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-249617.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [22/12/2014 22:23:07] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-251333.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [25/12/2014 14:11:28] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-255786306.txt [MD5.B568E1AE5DC5E06D833B8A4B0456E6F4] - |A| - [25/12/2014 14:20:30] - (.-.) - [1.09 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-256327910.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [25/12/2014 14:20:39] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-256337551.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [22/12/2014 22:23:14] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-257838.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [22/12/2014 22:23:14] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-257869.txt [MD5.363AB3B147EC26DE764E2FB32EA2041C] - |A| - [22/12/2014 22:10:13] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-39062.txt [MD5.0A742EBDEC323A1C158125EDDCD0ECB9] - |A| - [22/12/2014 22:10:13] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-39577.txt [MD5.EC3F2258DC5247436CF829AA405523A7] - |A| - [22/12/2014 22:10:14] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-39858.txt [MD5.E39F5B5F2F8E17B44BC73BFD6F5EEFE8] - |A| - [22/12/2014 22:10:14] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-40154.txt [MD5.670571AEA7547824368AAFF1210E5219] - |A| - [22/12/2014 22:10:14] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-40341.txt [MD5.876860348EF677B24E4070B6F0D0434B] - |A| - [22/12/2014 22:10:14] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-40466.txt [MD5.D9DF4A50BBA7175DDD31647FDD2E1C1E] - |A| - [22/12/2014 22:10:14] - (.-.) - [0.15 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-40685.txt [MD5.6B60C5E72A98FFD8AA3C3E79EB9EBC37] - |A| - [22/12/2014 22:10:15] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-40965.txt [MD5.FC2AE0A6CD9E5604723A4D73E3485D1B] - |A| - [22/12/2014 22:10:15] - (.-.) - [0.16 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-41277.txt [MD5.8CC3614DB50EB8B061D80657A5E43793] - |A| - [22/12/2014 22:10:16] - (.-.) - [0.18 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-41948.txt [MD5.82A13232C05598BFABA48278F810D7C0] - |A| - [25/12/2014 16:13:32] - (.-.) - [0.11 Ko] - (0.0.0.0) - C:\WINDOWS\System32\netcfg-4597879.txt [MD5.CD48AD912839B9FB6CCA5D4AA9B37500] - |A| - [22/08/2013 08:58:31] - (.-.) - [21.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NetTrace.PLA.Diagnostics.xml [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [51 Ko] - C:\WINDOWS\System32\networklist [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [397.67 Ko] - C:\WINDOWS\System32\nl-NL [MD5.2BF0CEEDCF4C5581E199FC4A265B3F71] - |A| - [08/03/2017 20:26:33] - (.-.) - [0.65 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nv-vk64.json [MD5.B118600075AA8BD0596510F44D9F4274] - |A| - [08/03/2017 20:28:38] - (.-.) - [7608.61 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nvcoproc.bin [MD5.476EB8125090F7B12E32A34FC664CF96] - |A| - [08/03/2017 20:26:34] - (.-.) - [41.61 Ko] - (0.0.0.0) - C:\WINDOWS\System32\nvinfo.pb [MD5.D4149157897615A16FD8C515DD9F7285] - |A| - [08/03/2017 20:30:16] - (.-.) - [118.44 Ko] - (0.0.0.0) - C:\WINDOWS\System32\NvRtmpStreamer64.dll [MD5.F746E5DDC489931AD269ECFFA4A39815] - |A| - [22/08/2013 17:36:38] - (.-.) - [8.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\OEMDefaultAssociations.xml [MD5.2901049544FDF863362FABA2363EB647] - |A| - [22/08/2013 08:52:33] - (.-.) - [0.82 Ko] - (0.0.0.0) - C:\WINDOWS\System32\onlinesetup.cmd [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [12936.7 Ko] - C:\WINDOWS\System32\oobe [MD5.49ADD535655C66C5A71FB06D18567054] - |A| - [22/08/2013 17:39:08] - (.-.) - [348.55 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc009.dat [MD5.D3578695311AF8039E75EBE169026C1D] - |A| - [21/11/2014 00:03:03] - (.-.) - [401.77 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfc00C.dat [MD5.32BC2E0CC95E2DCEE25B15BFB82D07B8] - |A| - [22/08/2013 17:39:08] - (.-.) - [32.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd009.dat [MD5.AA180E09E4990FF71FBEAC8C4455CF47] - |A| - [21/11/2014 00:03:03] - (.-.) - [39.58 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfd00C.dat [MD5.1787F172DCE3837BB1859BFE5BF5975A] - |A| - [22/08/2013 17:39:08] - (.-.) - [931.99 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh009.dat [MD5.2E048FAF550EA4B91B90C002D0C6A09E] - |A| - [21/11/2014 00:03:03] - (.-.) - [1551.12 Ko] - (0.0.0.0) - C:\WINDOWS\System32\perfh00C.dat [MD5.528F32ADD498298E49812A30757A2475] - |A| - [21/11/2014 00:46:25] - (.-.) - [5.3 Ko] - (0.0.0.0) - C:\WINDOWS\System32\PerfStringBackup.INI [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [420.05 Ko] - C:\WINDOWS\System32\pl-PL [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:52] - [420.42 Ko] - C:\WINDOWS\System32\Printing_Admin_Scripts [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\System32\ProximityToast [MD5.007893E8374C766471239EB291BA8C17] - |A| - [22/08/2013 11:17:09] - (.-.) - [4.05 Ko] - (0.0.0.0) - C:\WINDOWS\System32\psmodulediscoveryprovider.mof [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [400.27 Ko] - C:\WINDOWS\System32\pt-BR [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [398.69 Ko] - C:\WINDOWS\System32\pt-PT [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [23.75 Ko] - C:\WINDOWS\System32\ras [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\System32\RasToast [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [1.98 Ko] - C:\WINDOWS\System32\Recovery [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0.07 Ko] - C:\WINDOWS\System32\restore [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [371.29 Ko] - C:\WINDOWS\System32\ro-RO [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [621.43 Ko] - C:\WINDOWS\System32\ru-RU [MD5.5C18CD22BE4628865FCB63337A6E5EF6] - |A| - [22/08/2013 12:54:19] - (.-.) - [10.18 Ko] - (0.0.0.0) - C:\WINDOWS\System32\ScavengeSpace.xml [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [6.92 Ko] - C:\WINDOWS\System32\SecureBootUpdates [MD5.A8308D2F3DDE0745E8B678BF69A2ECD0] - |A| - [22/08/2013 08:55:37] - (.-.) - [8 Ko] - (0.0.0.0) - C:\WINDOWS\System32\settings.dat [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [353.03 Ko] - C:\WINDOWS\System32\sk-SK [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [337.64 Ko] - C:\WINDOWS\System32\sl-SI [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:52] - [52.16 Ko] - C:\WINDOWS\System32\slmgr [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [28841.02 Ko] - C:\WINDOWS\System32\SMI [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [7735.31 Ko] - C:\WINDOWS\System32\Speech [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [116173.29 Ko] - C:\WINDOWS\System32\spool [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [6666.6 Ko] - C:\WINDOWS\System32\spp [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [23.63 Ko] - C:\WINDOWS\System32\sppui [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [224.5 Ko] - C:\WINDOWS\System32\sr-Latn-CS [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [345.43 Ko] - C:\WINDOWS\System32\sr-Latn-RS [MD5.B7CC32E00C5C5152D221DF182827F58E] - |A| - [21/11/2014 01:19:42] - (.-.) - [49.56 Ko] - (0.0.0.0) - C:\WINDOWS\System32\srms.dat [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [18768 Ko] - C:\WINDOWS\System32\sru [MD5.B59958CD06C9F89C39281FB12F1BB233] - |A| - [22/08/2013 08:57:09] - (.-.) - [513.74 Ko] - (0.0.0.0) - C:\WINDOWS\System32\staticurllist.bin [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [377.28 Ko] - C:\WINDOWS\System32\sv-SE [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [1536.63 Ko] - C:\WINDOWS\System32\Sysprep [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [1074.99 Ko] - C:\WINDOWS\System32\SystemResetPlatform [MD5.FFFCC3C3ED6886A95D3C0E1B49C652BA] - |A| - [21/11/2014 00:55:39] - (.-.) - [136.33 Ko] - (0.0.0.0) - C:\WINDOWS\System32\systemsf.ebd [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [505.64 Ko] - C:\WINDOWS\System32\Tasks [MD5.D602CA245CC6774A0981B607F0675609] - |A| - [22/08/2013 08:56:03] - (.-.) - [58.71 Ko] - (0.0.0.0) - C:\WINDOWS\System32\tcpmon.ini [MD5.60CE51972E0A06217C52202F7208EB9A] - |A| - [22/08/2013 12:18:00] - (.-.) - [0.43 Ko] - (0.0.0.0) - C:\WINDOWS\System32\TelemetrySampleManifest.xml [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [567.21 Ko] - C:\WINDOWS\System32\th-TH [MD5.DB367E8C8F46C26A05BA982715CC0DB5] - |A| - [09/04/2013 11:42:06] - (.Copyright (c) 2009 Pixart Imaging Inc. - pximouse.) - [235.5 Ko] - (1.0.0.2) - C:\WINDOWS\System32\TiltWheelMouse.exe [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [398.61 Ko] - C:\WINDOWS\System32\tr-TR [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [552.26 Ko] - C:\WINDOWS\System32\uk-UA [MD5.00000000000000000000000000000000] - |D| - [04/09/2015 20:14:00] - [12222.69 Ko] - C:\WINDOWS\System32\vbox [MD5.F5AA1CD090726ED32C0026FBD023FCF7] - |A| - [26/01/2017 02:09:16] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [315 Ko] - (1.0.39.1) - C:\WINDOWS\System32\vulkan-1-1-0-39-1.dll [MD5.F5AA1CD090726ED32C0026FBD023FCF7] - |A| - [08/03/2017 20:28:59] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [315 Ko] - (1.0.39.1) - C:\WINDOWS\System32\vulkan-1.dll [MD5.6D2AD21CD6674F1B66CCB8C4C433A4E1] - |A| - [26/01/2017 02:09:50] - (.-.) - [115.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vulkaninfo-1-1-0-39-1.exe [MD5.6D2AD21CD6674F1B66CCB8C4C433A4E1] - |A| - [08/03/2017 20:28:59] - (.-.) - [115.5 Ko] - (0.0.0.0) - C:\WINDOWS\System32\vulkaninfo.exe [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [81609.23 Ko] - C:\WINDOWS\System32\wbem [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:52] - [0 Ko] - C:\WINDOWS\System32\WCN [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [54571.01 Ko] - C:\WINDOWS\System32\wdi [MD5.6EDD021A8B6457DDE09DE7B7FA4E8C8B] - |A| - [22/08/2013 10:29:44] - (.-.) - [0.6 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WdsUnattendTemplate.xml [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [128 Ko] - C:\WINDOWS\System32\wfp [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [0 Ko] - C:\WINDOWS\System32\WinBioDatabase [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [46 Ko] - C:\WINDOWS\System32\WinBioPlugIns [MD5.7F185FE9545048D836D7F992628CE67D] - |A| - [14/03/2016 19:09:37] - (.Copyright © 2017 - Java(TM) Platform SE binary.) - [107.56 Ko] - (8.0.1310.11) - C:\WINDOWS\System32\WindowsAccessBridge-64.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [14.53 Ko] - C:\WINDOWS\System32\WindowsInternal.Inbox.Media.Shared [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [27.59 Ko] - C:\WINDOWS\System32\WindowsInternal.Inbox.Shared [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [7441.32 Ko] - C:\WINDOWS\System32\WindowsPowerShell [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [142076 Ko] - C:\WINDOWS\System32\winevt [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [1928.5 Ko] - C:\WINDOWS\System32\WinMetadata [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:53] - [107.53 Ko] - C:\WINDOWS\System32\winrm [MD5.F1DF7849450DBC5D5C3A464E8A791C8C] - |A| - [22/08/2013 08:57:09] - (.-.) - [1485.18 Ko] - (0.0.0.0) - C:\WINDOWS\System32\WpcNBModel.bin [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [399.43 Ko] - C:\WINDOWS\System32\zh-CN [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:30] - [416.02 Ko] - C:\WINDOWS\System32\zh-HK [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [415.72 Ko] - C:\WINDOWS\System32\zh-TW [MD5.E16386EA30B042CD5AC5EFC488B47A68] - |A| - [10/02/2015 19:36:51] - (.-.) - [1.6 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\${LOGFILE} [MD5.BAA43E5AC909E79AEA13BF469C605B43] - |A| - [28/11/2015 18:06:57] - (.-.) - [1 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\.rnd [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:53] - [0 Ko] - C:\WINDOWS\SysWOW64\0409 [MD5.00000000000000000000000000000000] - |D| - [26/07/2012 12:08:58] - [0 Ko] - C:\WINDOWS\SysWOW64\040C [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [2228.5 Ko] - C:\WINDOWS\SysWOW64\AdvancedInstallers [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\AppLocker [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [528.17 Ko] - C:\WINDOWS\SysWOW64\ar-SA [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [524.6 Ko] - C:\WINDOWS\SysWOW64\bg-BG [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0.93 Ko] - C:\WINDOWS\SysWOW64\Bthprops [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\catroot [MD5.38718C4E864DC8F8E1DB0EF3B5566FA7] - |A| - [09/12/2015 16:05:43] - (.Copyright (C) 2004/05 Sony DADC Austria AG - SecuROM Context-Menu for Explorer..) - [174.61 Ko] - (1.1.221.0) - C:\WINDOWS\SysWOW64\CmdLineExt_x64.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [316 Ko] - C:\WINDOWS\SysWOW64\Com [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [5076.23 Ko] - C:\WINDOWS\SysWOW64\config [MD5.8C53C0A7CBED650500FC634DC8CA132B] - |A| - [11/01/2012 05:34:58] - (.Copyright ? 2009 - CP210xUSB_B.) - [92 Ko] - (1.1.0.710) - C:\WINDOWS\SysWOW64\CP210xUSB_B.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [383.68 Ko] - C:\WINDOWS\SysWOW64\cs-CZ [MD5.BEF94E1A08E1FE00CF12F1DFD9505408] - |A| - [06/04/2010 02:05:16] - (.-.) - [2037 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\cv210.dll [MD5.9E4DA93286E2D5D0674A0A692EB4F627] - |A| - [06/04/2010 02:04:06] - (.-.) - [2149.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\cxcore210.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [351.29 Ko] - C:\WINDOWS\SysWOW64\da-DK [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [400.63 Ko] - C:\WINDOWS\SysWOW64\de-DE [MD5.00000000000000000000000000000000] - |D| - [06/05/2015 16:47:16] - [0.11 Ko] - C:\WINDOWS\SysWOW64\directx [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [4739.17 Ko] - C:\WINDOWS\SysWOW64\Dism [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [327.5 Ko] - C:\WINDOWS\SysWOW64\downlevel [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [3420.12 Ko] - C:\WINDOWS\SysWOW64\drivers [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\DriverStore [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [627.92 Ko] - C:\WINDOWS\SysWOW64\el-GR [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:53] - [0 Ko] - C:\WINDOWS\SysWOW64\en [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [286.6 Ko] - C:\WINDOWS\SysWOW64\en-GB [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [1022.07 Ko] - C:\WINDOWS\SysWOW64\en-US [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [380.51 Ko] - C:\WINDOWS\SysWOW64\es-ES [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [291.87 Ko] - C:\WINDOWS\SysWOW64\et-EE [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [372.19 Ko] - C:\WINDOWS\SysWOW64\fi-FI [MD5.C9EB6CFE2A92A4F89993BE6A6F8A21BA] - |A| - [28/05/2013 22:22:48] - (.-.) - [626 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\ficvdec_x86.dll [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:53] - [1686 Ko] - C:\WINDOWS\SysWOW64\fr [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [35929.93 Ko] - C:\WINDOWS\SysWOW64\fr-FR [MD5.2A4552B5BACB8F7A6AD00E9AD8B804DA] - |A| - [26/02/2013 08:31:26] - (.Copyright © Beepa P/L 2013 - Fraps.) - [64 Ko] - (3.5.99.15618) - C:\WINDOWS\SysWOW64\frapsvid.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\FxsTmp [MD5.F0A1BD19DD198FA7F4FC39C8189A89FF] - |A| - [16/09/2016 20:53:32] - (.Copyright © 2000-2006 GEAR Software Inc. - GEARAspi.) - [106.8 Ko] - (2.0.6.2) - C:\WINDOWS\SysWOW64\GEARAspi.dll [MD5.E9868218BF0205F0085CF8863EE228D5] - |A| - [26/01/2016 15:37:53] - (.-.) - [75.19 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\generic_uninstaller.log [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\GroupPolicy [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\GroupPolicyUsers [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [486.06 Ko] - C:\WINDOWS\SysWOW64\he-IL [MD5.D5A6CF1CA694A8D0C8D14F1193A644F9] - |A| - [06/04/2010 02:05:48] - (.-.) - [763 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\highgui210.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [317.45 Ko] - C:\WINDOWS\SysWOW64\hr-HR [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [398.37 Ko] - C:\WINDOWS\SysWOW64\hu-HU [MD5.94A8EBD816A366041F8CCF5AFD3AB7DE] - |A| - [28/01/2015 16:59:35] - (.-.) - [55 Ko] - (1.20.15.1) - C:\WINDOWS\SysWOW64\iyvu9_32.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [562.94 Ko] - C:\WINDOWS\SysWOW64\ja-JP [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [672.51 Ko] - C:\WINDOWS\SysWOW64\ko-KR [MD5.3456A0F50781DD83A8BC7778984C112A] - |A| - [27/08/2010 01:34:22] - (.-.) - [86 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libaccess_http_plugin.dll [MD5.F54D94FA87A75E52824024A4B8D89C26] - |A| - [27/08/2010 01:34:22] - (.-.) - [31.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libau_plugin.dll [MD5.B99FE1C59BF34B961D118471045A0B16] - |A| - [27/08/2010 01:34:22] - (.-.) - [6958 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libavcodec_plugin.dll [MD5.42AE4EE7EE676B2D19CF23026EAF54EA] - |A| - [27/08/2010 01:34:28] - (.-.) - [38.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libfilesystem_plugin.dll [MD5.AD989EB563B8D7DE94203EFBB9090109] - |A| - [27/08/2010 01:34:28] - (.-.) - [32.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libmemcpymmx_plugin.dll [MD5.37859C94E00DE67DDFA46CB80AD88323] - |A| - [27/08/2010 01:34:28] - (.-.) - [34.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libmjpeg_plugin.dll [MD5.68C797622E122C7A597C6B3F72763C58] - |A| - [27/08/2010 01:34:30] - (.-.) - [37 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libmpeg_audio_plugin.dll [MD5.221E950B1A09E10D5B2EF88C2C39B86E] - |A| - [27/08/2010 01:34:30] - (.-.) - [30.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libmpgv_plugin.dll [MD5.36852AB29A0D13BD1B7BE7D62F43435F] - |A| - [27/08/2010 01:34:30] - (.-.) - [32.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libmux_wav_plugin.dll [MD5.D9282B9272E80BC4FD73E081602004AF] - |A| - [27/08/2010 01:34:30] - (.-.) - [39.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libpacketizer_mpegvideo_plugin.dll [MD5.49EE2AC41363D2B0EE8F6284BA569CCD] - |A| - [27/08/2010 01:34:30] - (.-.) - [50 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libps_plugin.dll [MD5.E622592A0CAA83BA34A303E014FBFBC5] - |A| - [27/08/2010 01:34:32] - (.-.) - [35 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libstream_out_smem_plugin.dll [MD5.D88F22CCD103A0D9F4123D46430F1276] - |A| - [27/08/2010 01:34:32] - (.-.) - [64 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libstream_out_transcode_plugin.dll [MD5.239C1C709B87A5DF7301612245D638CA] - |A| - [27/08/2010 01:34:34] - (.-.) - [237.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libswscale_plugin.dll [MD5.767E5715FA8B80CC5CFFB95DEE5FC66D] - |A| - [27/08/2010 01:34:22] - (.-.) - [99 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libvlc.dll [MD5.78732F1770082FAFC6EDCC29BBB21AD8] - |A| - [27/08/2010 01:34:22] - (.-.) - [2210.5 Ko] - (1.1.0.0) - C:\WINDOWS\SysWOW64\libvlccore.dll [MD5.E7CF957AF17D8A863150EC456D44E3F3] - |A| - [27/08/2010 01:34:36] - (.-.) - [34 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libvmem_plugin.dll [MD5.AE5BB353535718872BEB576A530BB1C3] - |A| - [27/08/2010 01:34:36] - (.-.) - [38 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\libvout_wrapper_plugin.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [90.07 Ko] - C:\WINDOWS\SysWOW64\Licenses [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\LogFiles [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [327.5 Ko] - C:\WINDOWS\SysWOW64\lt-LT [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [343.77 Ko] - C:\WINDOWS\SysWOW64\lv-LV [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [49939.55 Ko] - C:\WINDOWS\SysWOW64\Macromed [MD5.00000000000000000000000000000000] - |SD| - [02/01/2016 12:43:36] - [0 Ko] - C:\WINDOWS\SysWOW64\Microsoft [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [3031 Ko] - C:\WINDOWS\SysWOW64\migration [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [789 Ko] - C:\WINDOWS\SysWOW64\migwiz [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [45.5 Ko] - C:\WINDOWS\SysWOW64\MSDRM [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [52.28 Ko] - C:\WINDOWS\SysWOW64\MsDtc [MD5.70EC95FC7732CA1428DD4C9B7595CF00] - |A| - [30/04/2012 18:53:58] - (.Copyright (C) 1993-2011 Yukihiro Matsumoto - Ruby interpreter (DLL) 1.9.3p0 [i386-mswin32_90].) - [1220.5 Ko] - (1.9.3.0) - C:\WINDOWS\SysWOW64\msvcr90-ruby191.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [18.65 Ko] - C:\WINDOWS\SysWOW64\MUI [MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [07/09/2015 17:20:23] - (.-.) - [0 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\Nadeo.ini [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [354.41 Ko] - C:\WINDOWS\SysWOW64\nb-NO [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\NDF [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [51 Ko] - C:\WINDOWS\SysWOW64\networklist [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [378.67 Ko] - C:\WINDOWS\SysWOW64\nl-NL [MD5.E256CF02FDF09732C42AF1C7AB9521DD] - |A| - [08/03/2017 20:26:33] - (.-.) - [0.65 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\nv-vk32.json [MD5.C970315D37DD9C3BBCE8712A4C2BAF86] - |A| - [15/06/2011 13:37:00] - (.-.) - [1083 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\phidget21.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [400.05 Ko] - C:\WINDOWS\SysWOW64\pl-PL [MD5.A535901BA810084E1D888F1251E22C1B] - |A| - [04/10/2015 11:12:43] - (.-.) - [284.68 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\PnkBstrB.ex0 [MD5.A535901BA810084E1D888F1251E22C1B] - |A| - [04/10/2015 11:39:57] - (.-.) - [284.68 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\PnkBstrB.xtr [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:53] - [420.42 Ko] - C:\WINDOWS\SysWOW64\Printing_Admin_Scripts [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [381.27 Ko] - C:\WINDOWS\SysWOW64\pt-BR [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [379.69 Ko] - C:\WINDOWS\SysWOW64\pt-PT [MD5.00000000000000000000000000000000] - |D| - [18/10/2015 18:18:35] - [179 Ko] - C:\WINDOWS\SysWOW64\QuickTime [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [23.75 Ko] - C:\WINDOWS\SysWOW64\ras [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\RasToast [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0.76 Ko] - C:\WINDOWS\SysWOW64\Recovery [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\restore [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [352.79 Ko] - C:\WINDOWS\SysWOW64\ro-RO [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [602.93 Ko] - C:\WINDOWS\SysWOW64\ru-RU [MD5.A07E24C9E657D9E304483D4CDE471450] - |A| - [10/06/2011 05:43:56] - (.Copyright ? 2010 - SerialPort.) - [72 Ko] - (1.0.0.539) - C:\WINDOWS\SysWOW64\SerialPort.dll [MD5.75355D591FFED68A6FEABCC3592380A4] - |A| - [27/04/2010 09:30:28] - (.Copyright © 2006 - SiUSBXp.) - [88 Ko] - (3.1.0.0) - C:\WINDOWS\SysWOW64\SiUSBXp.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [333.53 Ko] - C:\WINDOWS\SysWOW64\sk-SK [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [319.14 Ko] - C:\WINDOWS\SysWOW64\sl-SI [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:53] - [52.16 Ko] - C:\WINDOWS\SysWOW64\slmgr [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [0 Ko] - C:\WINDOWS\SysWOW64\SMI [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [4216.31 Ko] - C:\WINDOWS\SysWOW64\Speech [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [1024.22 Ko] - C:\WINDOWS\SysWOW64\spp [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [23.63 Ko] - C:\WINDOWS\SysWOW64\sppui [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [206.5 Ko] - C:\WINDOWS\SysWOW64\sr-Latn-CS [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [327.43 Ko] - C:\WINDOWS\SysWOW64\sr-Latn-RS [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\sru [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [359.78 Ko] - C:\WINDOWS\SysWOW64\sv-SE [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:53] - [0 Ko] - C:\WINDOWS\SysWOW64\sysprep [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [0 Ko] - C:\WINDOWS\SysWOW64\Tasks [MD5.DC94C711667C9A9F91019548D9FA1E9E] - |A| - [03/02/2012 05:00:58] - (.???? (C) 2008 - TCPClient DLL.) - [136 Ko] - (1.0.0.708) - C:\WINDOWS\SysWOW64\TCPClient.dll [MD5.EA3D5E81BB5B321FD7A3B0381F86A648] - |A| - [01/03/2012 04:32:16] - (.???? (C) 2008 - TcpComm DLL.) - [160 Ko] - (1.0.0.743) - C:\WINDOWS\SysWOW64\TcpComm.dll [MD5.6866AB0E7291F101F2C7F80ADE7D363F] - |A| - [09/04/2009 12:52:02] - (.Copyright ? 2009 - TenxHidDll.) - [36 Ko] - (2.0.2.9) - C:\WINDOWS\SysWOW64\tenxhid.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [550.21 Ko] - C:\WINDOWS\SysWOW64\th-TH [MD5.BB02E40FB9DE6BB6AB5A00D4D5F42074] - |A| - [02/07/2012 22:11:02] - (.Copyright © 2012 - theowl.) - [16 Ko] - (1.0.0.0) - C:\WINDOWS\SysWOW64\theowl.dll [MD5.36328B560CB821EEE5FE84E16A1EAD44] - |A| - [12/09/2011 14:02:32] - (.-.) - [1379 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\theowl_api.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [381.11 Ko] - C:\WINDOWS\SysWOW64\tr-TR [MD5.B4E5A90D7E30DA8F2953D9F3723D7F75] - |A| - [20/12/2011 03:47:44] - (.Copyright ? 2009 - UserCom.) - [48 Ko] - (1.1.0.669) - C:\WINDOWS\SysWOW64\UserCom.dll [MD5.00000000000000000000000000000000] - |D| - [04/09/2015 20:14:00] - [9044.38 Ko] - C:\WINDOWS\SysWOW64\vbox [MD5.9033DAF3277F0498BC86C8D4566C25CE] - |A| - [15/09/2009 11:14:18] - (.Copyright (C)2001 H.Mutsuki - Ogg Vorbis CODEC for MSACM.) - [1518.5 Ko] - (0.0.3.6) - C:\WINDOWS\SysWOW64\vorbis.acm [MD5.4287C9D06A1086CDF75C697A494BE4B7] - |A| - [26/01/2017 02:12:46] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [319 Ko] - (1.0.39.1) - C:\WINDOWS\SysWOW64\vulkan-1-1-0-39-1.dll [MD5.4287C9D06A1086CDF75C697A494BE4B7] - |A| - [08/03/2017 20:28:59] - (.Copyright (C) 2015-2017 - Vulkan Loader.) - [319 Ko] - (1.0.39.1) - C:\WINDOWS\SysWOW64\vulkan-1.dll [MD5.BB0B3644D206847B9E39745E7A25BC64] - |A| - [26/01/2017 02:13:16] - (.-.) - [101.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vulkaninfo-1-1-0-39-1.exe [MD5.BB0B3644D206847B9E39745E7A25BC64] - |A| - [08/03/2017 20:28:59] - (.-.) - [101.5 Ko] - (0.0.0.0) - C:\WINDOWS\SysWOW64\vulkaninfo.exe [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 15:36:16] - [13601.24 Ko] - C:\WINDOWS\SysWOW64\wbem [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:53] - [0 Ko] - C:\WINDOWS\SysWOW64\WCN [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [158.1 Ko] - C:\WINDOWS\SysWOW64\wdi [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [6153.77 Ko] - C:\WINDOWS\SysWOW64\WindowsPowerShell [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [1928.5 Ko] - C:\WINDOWS\SysWOW64\WinMetadata [MD5.00000000000000000000000000000000] - |D| - [21/11/2014 00:02:54] - [107.53 Ko] - C:\WINDOWS\SysWOW64\winrm [MD5.00000000000000000000000000000000] - |D| - [05/04/2015 16:38:30] - [10.16 Ko] - C:\WINDOWS\SysWOW64\XPSViewer [MD5.65459280D4D4E06B3E7C2879AAEE2A94] - |A| - [08/12/2011 09:03:10] - (.Copyright ? 2009 - Z101B.) - [48 Ko] - (1.1.0.669) - C:\WINDOWS\SysWOW64\Z101B.dll [MD5.8D4FB6D48CA097BA8E2CB656D4D84EA9] - |A| - [01/03/2012 04:31:40] - (.Copyright ? 2009 - Z101BAPI.) - [72 Ko] - (1.1.0.743) - C:\WINDOWS\SysWOW64\Z101B2A.dll [MD5.C9C5EB182D887C6429D4081CF2E2C3C2] - |A| - [19/03/2012 10:36:50] - (.???? (C) 2009 - ZBDevice DLL.) - [1128 Ko] - (1.0.0.741) - C:\WINDOWS\SysWOW64\ZBDevice.dll [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [389.93 Ko] - C:\WINDOWS\SysWOW64\zh-CN [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [406.02 Ko] - C:\WINDOWS\SysWOW64\zh-HK [MD5.00000000000000000000000000000000] - |D| - [22/08/2013 17:36:31] - [405.72 Ko] - C:\WINDOWS\SysWOW64\zh-TW ---------- | Shell Folders [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] "!Do not use this registry key"=Use the SHGetFolderPath or SHGetKnownFolderPath function instead "AppData"=C:\Users\Thomas\AppData\Roaming [05/04/2015 15:47:26] "Local AppData"=C:\Users\Thomas\AppData\Local [05/04/2015 15:47:26] "My Video"=C:\Users\Thomas\Videos [22/12/2014 22:13:59] "{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"=C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Libraries [22/12/2014 22:14:56] "My Pictures"=C:\Users\Thomas\Pictures [22/12/2014 22:13:59] "Desktop"=C:\Users\Thomas\Desktop [05/04/2015 15:47:26] "History"=C:\Users\Thomas\AppData\Local\Microsoft\Windows\History [22/12/2014 22:13:59] "NetHood"=C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Network Shortcuts "{56784854-C6CB-462B-8169-88E350ACB882}"=C:\Users\Thomas\Contacts [22/12/2014 22:14:56] "{00BCFC5A-ED94-4E48-96A1-3F6217F21990}"=C:\Users\Thomas\AppData\Local\Microsoft\Windows\RoamingTiles [22/12/2014 22:14:56] "Cookies"=C:\Users\Thomas\AppData\Local\Microsoft\Windows\INetCookies [22/12/2014 22:13:59] "Favorites"=C:\Users\Thomas\Favorites [05/04/2015 15:47:26] "SendTo"=C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\SendTo [05/04/2015 15:47:26] "Start Menu"=C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu [05/04/2015 15:47:26] "My Music"=C:\Users\Thomas\Music [22/12/2014 22:13:59] "Programs"=C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [05/04/2015 15:47:26] "Recent"=C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Recent [22/12/2014 22:13:59] "CD Burning"=C:\Users\Thomas\AppData\Local\Microsoft\Windows\Burn\Burn [05/04/2015 20:39:11] "PrintHood"=C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Printer Shortcuts "{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}"=C:\Users\Thomas\Searches [22/12/2014 22:14:57] "{374DE290-123F-4565-9164-39C4925E467B}"=C:\Users\Thomas\Downloads [22/12/2014 22:13:59] "{A520A1A4-1780-4FF6-BD18-167343C5AF16}"=C:\Users\Thomas\AppData\LocalLow [22/12/2014 22:14:00] "Startup"=C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [22/12/2014 22:14:57] "Administrative Tools"=C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [22/12/2014 22:14:57] "Personal"=C:\Users\Thomas\Documents [05/04/2015 15:47:26] "{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}"=C:\Users\Thomas\Links [22/12/2014 22:13:59] "Cache"=C:\Users\Thomas\AppData\Local\Microsoft\Windows\INetCache [05/04/2015 15:47:26] "Templates"=C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Templates [19/09/2015 21:26:26] "{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}"=C:\Users\Thomas\Saved Games [22/12/2014 22:13:59] "Fonts"=C:\WINDOWS\Fonts [22/08/2013 15:36:15] [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] "Desktop"=%USERPROFILE%\Desktop "Local AppData"=%USERPROFILE%\AppData\Local "Startup"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup "Cookies"=%USERPROFILE%\AppData\Local\Microsoft\Windows\INetCookies "SendTo"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo "Personal"=%USERPROFILE%\Documents "Recent"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent "Favorites"=%USERPROFILE%\Favorites "My Pictures"=%USERPROFILE%\Pictures "Start Menu"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu "NetHood"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts "My Music"=%USERPROFILE%\Music "My Video"=%USERPROFILE%\Videos "Cache"=%USERPROFILE%\AppData\Local\Microsoft\Windows\INetCache "Programs"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs "History"=%USERPROFILE%\AppData\Local\Microsoft\Windows\History "{374DE290-123F-4565-9164-39C4925E467B}"=%USERPROFILE%\Downloads "Templates"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates "AppData"=%USERPROFILE%\AppData\Roaming "PrintHood"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts "{339719B5-8C47-4894-94C2-D8F77ADD44A6}"=%USERPROFILE%\OneDrive\Images "{767E6811-49CB-4273-87C2-20F355E1085B}"=%USERPROFILE%\OneDrive\Images\Pellicule [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] "OEM Links"=C:\ProgramData\OEM\Links "CommonVideo"=C:\Users\Public\Videos [22/08/2013 17:36:30] "Common Documents"=C:\Users\Public\Documents [22/08/2013 17:36:30] "Common Startup"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [22/08/2013 17:36:30] "Common AppData"=C:\ProgramData [22/08/2013 15:36:15] "CommonPictures"=C:\Users\Public\Pictures [22/08/2013 17:36:30] "Common Desktop"=C:\Users\Public\Desktop [22/08/2013 17:36:30] "CommonMusic"=C:\Users\Public\Music [22/08/2013 17:36:30] "Common Start Menu"=C:\ProgramData\Microsoft\Windows\Start Menu [22/08/2013 17:36:30] "Common Programs"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs [22/08/2013 17:36:30] "Common Templates"=C:\ProgramData\Microsoft\Windows\Templates [26/07/2012 10:12:59] "Common Administrative Tools"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [22/08/2013 17:36:30] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] "CommonVideo"=%PUBLIC%\Videos "{3D644C9B-1FB8-4f30-9B45-F670235F79C0}"=%PUBLIC%\Downloads "Common Documents"=%PUBLIC%\Documents "Common Startup"=%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup "Common AppData"=%ProgramData% "CommonPictures"=%PUBLIC%\Pictures "Common Desktop"=%PUBLIC%\Desktop "CommonMusic"=%PUBLIC%\Music "Common Start Menu"=%ProgramData%\Microsoft\Windows\Start Menu "Common Programs"=%ProgramData%\Microsoft\Windows\Start Menu\Programs "Common Templates"=%ProgramData%\Microsoft\Windows\Templates [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] "OEM Links"=C:\ProgramData\OEM\Links "CommonVideo"=C:\Users\Public\Videos [22/08/2013 17:36:30] "Common Administrative Tools"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [22/08/2013 17:36:30] "Common Documents"=C:\Users\Public\Documents [22/08/2013 17:36:30] "Common Startup"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [22/08/2013 17:36:30] "Common AppData"=C:\ProgramData [22/08/2013 15:36:15] "CommonPictures"=C:\Users\Public\Pictures [22/08/2013 17:36:30] "Common Desktop"=C:\Users\Public\Desktop [22/08/2013 17:36:30] "CommonMusic"=C:\Users\Public\Music [22/08/2013 17:36:30] "Common Start Menu"=C:\ProgramData\Microsoft\Windows\Start Menu [22/08/2013 17:36:30] "Common Programs"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs [22/08/2013 17:36:30] "Common Templates"=C:\ProgramData\Microsoft\Windows\Templates [26/07/2012 10:12:59] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] "CommonVideo"=%PUBLIC%\Videos "{3D644C9B-1FB8-4f30-9B45-F670235F79C0}"=%PUBLIC%\Downloads "Common Documents"=%PUBLIC%\Documents "Common Startup"=%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup "Common AppData"=%ProgramData% "CommonPictures"=%PUBLIC%\Pictures "Common Desktop"=%PUBLIC%\Desktop "CommonMusic"=%PUBLIC%\Music "Common Start Menu"=%ProgramData%\Microsoft\Windows\Start Menu "Common Programs"=%ProgramData%\Microsoft\Windows\Start Menu\Programs "Common Templates"=%ProgramData%\Microsoft\Windows\Templates ---------- | [Public] ---------- | [Thomas] [19/03/2016 23:34:33] - |A| - [24] - C:\Users\Thomas\AppData\AdobeACBCache.dat [13/05/2016 21:30:04] - |D| - [0] - C:\Users\Thomas\AppData\IObit [05/04/2015 15:47:26] - |D| - [4774587753] - C:\Users\Thomas\AppData\Local [22/12/2014 22:14:00] - |D| - [899676191] - C:\Users\Thomas\AppData\LocalLow [05/04/2015 15:47:26] - |D| - [2846488546] - C:\Users\Thomas\AppData\Roaming [20/06/2015 20:29:36] - |D| - [8834484] - C:\Users\Thomas\AppData\Local\Adobe [05/04/2015 15:47:26] - |SHD| - [0] - C:\Users\Thomas\AppData\Local\Application Data [16/10/2015 18:33:22] - |D| - [5341142] - C:\Users\Thomas\AppData\Local\Apps [25/03/2017 20:03:54] - |D| - [26084293] - C:\Users\Thomas\AppData\Local\Arktos Entertainment [13/05/2017 12:13:40] - |D| - [24576] - C:\Users\Thomas\AppData\Local\AVAST Software [15/10/2017 10:27:17] - |D| - [2319] - C:\Users\Thomas\AppData\Local\BANDAI NAMCO Entertainment [27/02/2016 23:31:15] - |D| - [8289] - C:\Users\Thomas\AppData\Local\Beatpad [12/02/2015 22:20:04] - |D| - [1735673] - C:\Users\Thomas\AppData\Local\Bluestacks [28/06/2015 14:43:45] - |D| - [195929] - C:\Users\Thomas\AppData\Local\Castle Story Prototype [06/07/2015 10:37:22] - |D| - [10677387] - C:\Users\Thomas\AppData\Local\CEF [15/11/2016 19:09:40] - |D| - [1048616] - C:\Users\Thomas\AppData\Local\Chromium [11/12/2016 00:46:46] - |D| - [1515008] - C:\Users\Thomas\AppData\Local\citra [04/10/2015 20:25:10] - |D| - [1464] - C:\Users\Thomas\AppData\Local\Colossal Order [11/04/2016 21:14:05] - |D| - [74368027] - C:\Users\Thomas\AppData\Local\CrashDumps [01/10/2017 15:41:48] - |D| - [15909] - C:\Users\Thomas\AppData\Local\CrashReportClient [25/03/2017 19:49:25] - |D| - [0] - C:\Users\Thomas\AppData\Local\CrashRpt [09/12/2015 17:42:09] - |D| - [0] - C:\Users\Thomas\AppData\Local\Criterion Games [25/04/2016 19:05:20] - |A| - [3584] - C:\Users\Thomas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [12/09/2017 22:46:29] - |D| - [10380973] - C:\Users\Thomas\AppData\Local\DeadByDaylight [16/10/2015 18:33:21] - |D| - [0] - C:\Users\Thomas\AppData\Local\Deployment [25/12/2014 20:36:34] - |D| - [383215] - C:\Users\Thomas\AppData\Local\Diagnostics [11/06/2017 12:47:53] - |D| - [70688631] - C:\Users\Thomas\AppData\Local\Discord [27/02/2016 23:30:43] - |D| - [67296768] - C:\Users\Thomas\AppData\Local\Downloaded Installations [31/08/2017 00:19:11] - |D| - [7791616] - C:\Users\Thomas\AppData\Local\drmingw [16/12/2015 18:45:50] - |D| - [2300] - C:\Users\Thomas\AppData\Local\Eclipse [19/10/2016 16:41:59] - |D| - [1185] - C:\Users\Thomas\AppData\Local\Electronic_Arts_Inc [31/08/2017 00:09:45] - |A| - [63] - C:\Users\Thomas\AppData\Local\emaildefaults [10/04/2015 19:40:31] - |SHD| - [0] - C:\Users\Thomas\AppData\Local\EmieBrowserModeList [10/04/2015 19:40:31] - |SHD| - [0] - C:\Users\Thomas\AppData\Local\EmieSiteList [10/04/2015 19:40:31] - |SHD| - [0] - C:\Users\Thomas\AppData\Local\EmieUserList [01/10/2017 10:35:54] - |D| - [34255069] - C:\Users\Thomas\AppData\Local\EpicGamesLauncher [14/04/2017 20:32:16] - |D| - [168620] - C:\Users\Thomas\AppData\Local\FalloutShelter [11/03/2016 20:35:51] - |D| - [31607006] - C:\Users\Thomas\AppData\Local\Focus Home Interactive [27/02/2015 10:55:54] - |D| - [5219228] - C:\Users\Thomas\AppData\Local\fontconfig [01/10/2017 11:22:05] - |D| - [57115852] - C:\Users\Thomas\AppData\Local\FortniteGame [25/03/2017 19:49:29] - |D| - [0] - C:\Users\Thomas\AppData\Local\FredaikisAB [13/12/2015 12:02:29] - |D| - [114755222] - C:\Users\Thomas\AppData\Local\FreeReign [09/01/2015 21:05:34] - |D| - [12015] - C:\Users\Thomas\AppData\Local\Gameforge4d [11/04/2016 20:30:45] - |D| - [71264] - C:\Users\Thomas\AppData\Local\gamemaker_studio [11/11/2015 17:23:11] - |D| - [1497710] - C:\Users\Thomas\AppData\Local\Gearbox Software [27/02/2015 10:55:53] - |D| - [660] - C:\Users\Thomas\AppData\Local\gegl-0.2 [13/08/2015 23:23:13] - |D| - [1381514214] - C:\Users\Thomas\AppData\Local\GeometryDash [25/12/2014 14:44:02] - |D| - [494012446] - C:\Users\Thomas\AppData\Local\Google [27/02/2015 11:10:37] - |D| - [202] - C:\Users\Thomas\AppData\Local\gtk-2.0 [01/06/2015 20:29:28] - |D| - [71] - C:\Users\Thomas\AppData\Local\GWX [24/10/2016 18:07:43] - |D| - [66051] - C:\Users\Thomas\AppData\Local\HelloNeighbour [05/04/2015 15:47:26] - |SHD| - [0] - C:\Users\Thomas\AppData\Local\Historique [27/10/2016 14:38:57] - |D| - [5647] - C:\Users\Thomas\AppData\Local\Hisuite [05/04/2015 23:45:24] - |AH| - [130677] - C:\Users\Thomas\AppData\Local\IconCache.db [10/01/2015 22:12:02] - |D| - [154918344] - C:\Users\Thomas\AppData\Local\Introversion [31/08/2017 00:19:08] - |A| - [10080] - C:\Users\Thomas\AppData\Local\kritacrash.log [11/09/2017 18:12:02] - |A| - [39] - C:\Users\Thomas\AppData\Local\kritadisplayrc [30/08/2017 23:58:00] - |A| - [15682] - C:\Users\Thomas\AppData\Local\kritarc [02/09/2015 16:55:54] - |D| - [364309237] - C:\Users\Thomas\AppData\Local\LINE [28/06/2016 20:18:11] - |D| - [0] - C:\Users\Thomas\AppData\Local\LogMeIn [25/06/2016 23:13:59] - |D| - [277] - C:\Users\Thomas\AppData\Local\LogMeIn Hamachi [01/03/2016 14:17:08] - |D| - [41314] - C:\Users\Thomas\AppData\Local\LucasArts [24/01/2015 11:34:38] - |ASH| - [0] - C:\Users\Thomas\AppData\Local\LumaEmu [21/05/2016 22:16:52] - |D| - [0] - C:\Users\Thomas\AppData\Local\Macromedia [25/03/2016 22:22:47] - |D| - [32768] - C:\Users\Thomas\AppData\Local\Mega Limited [05/04/2015 15:47:26] - |D| - [316941311] - C:\Users\Thomas\AppData\Local\Microsoft [20/04/2016 18:47:41] - |D| - [21676296] - C:\Users\Thomas\AppData\Local\Mirillis [01/03/2017 18:26:17] - |D| - [129966709] - C:\Users\Thomas\AppData\Local\Molotov [18/02/2016 13:03:30] - |D| - [398993] - C:\Users\Thomas\AppData\Local\MonoDevelop-Unity-5.0 [20/04/2016 21:52:47] - |D| - [150913128] - C:\Users\Thomas\AppData\Local\Mozilla [02/05/2015 00:29:32] - |D| - [8758] - C:\Users\Thomas\AppData\Local\NBTExplorer [08/03/2017 20:30:24] - |D| - [159543025] - C:\Users\Thomas\AppData\Local\NVIDIA [25/12/2014 14:46:30] - |D| - [111215189] - C:\Users\Thomas\AppData\Local\NVIDIA Corporation [15/04/2015 12:21:47] - |D| - [193] - C:\Users\Thomas\AppData\Local\openvr [23/12/2015 23:21:29] - |D| - [108167709] - C:\Users\Thomas\AppData\Local\Origin [15/12/2015 21:28:51] - |D| - [649146] - C:\Users\Thomas\AppData\Local\Overwolf [22/12/2014 22:14:13] - |D| - [116065148] - C:\Users\Thomas\AppData\Local\Packages [02/05/2015 18:23:22] - |D| - [107104] - C:\Users\Thomas\AppData\Local\paint.net [18/03/2015 12:22:35] - |D| - [3893] - C:\Users\Thomas\AppData\Local\PAYDAY [31/12/2014 12:56:23] - |D| - [464436] - C:\Users\Thomas\AppData\Local\PAYDAY 2 [28/06/2015 15:08:05] - |D| - [468713] - C:\Users\Thomas\AppData\Local\Pipix-3 [09/01/2015 21:05:04] - |D| - [0] - C:\Users\Thomas\AppData\Local\Programs [04/10/2015 11:39:53] - |D| - [9495454] - C:\Users\Thomas\AppData\Local\PunkBuster [15/03/2015 00:39:18] - |D| - [781467] - C:\Users\Thomas\AppData\Local\qBittorrent [22/04/2017 21:17:55] - |D| - [58372] - C:\Users\Thomas\AppData\Local\QuickPar [11/09/2017 19:46:17] - |A| - [4432] - C:\Users\Thomas\AppData\Local\recently-used.xbel [06/12/2015 18:27:00] - |A| - [17] - C:\Users\Thomas\AppData\Local\resmon.resmoncfg [20/02/2017 14:34:18] - |D| - [61919964] - C:\Users\Thomas\AppData\Local\Roblox [04/07/2017 11:48:51] - |D| - [0] - C:\Users\Thomas\AppData\Local\Rockstar Games [21/04/2017 20:34:14] - |D| - [0] - C:\Users\Thomas\AppData\Local\SCE [13/03/2016 13:57:36] - |D| - [32] - C:\Users\Thomas\AppData\Local\Setup Integrity Check [04/05/2015 11:48:38] - |D| - [4930716] - C:\Users\Thomas\AppData\Local\SKIDROW [12/02/2015 20:15:42] - |D| - [0] - C:\Users\Thomas\AppData\Local\Skype [23/02/2017 01:37:53] - |D| - [787532] - C:\Users\Thomas\AppData\Local\Sniper3 [10/05/2015 11:28:18] - |D| - [9320] - C:\Users\Thomas\AppData\Local\SniperV2 [02/08/2016 13:05:57] - |D| - [4791614] - C:\Users\Thomas\AppData\Local\Songbird2 [07/08/2016 19:36:26] - |D| - [15713] - C:\Users\Thomas\AppData\Local\Songr [10/12/2016 22:04:53] - |D| - [19835] - C:\Users\Thomas\AppData\Local\SquirrelTemp [20/02/2015 18:10:09] - |D| - [453194868] - C:\Users\Thomas\AppData\Local\Steam [07/05/2015 10:24:00] - |D| - [7300] - C:\Users\Thomas\AppData\Local\storage [21/10/2016 17:52:43] - |D| - [65] - C:\Users\Thomas\AppData\Local\SWTORPerf [22/10/2015 10:36:03] - |D| - [0] - C:\Users\Thomas\AppData\Local\Targem [05/09/2015 13:23:37] - |D| - [15824] - C:\Users\Thomas\AppData\Local\TechSmith [05/04/2015 15:47:26] - |D| - [192254901] - C:\Users\Thomas\AppData\Local\Temp [12/04/2015 12:11:51] - |A| - [802] - C:\Users\Thomas\AppData\Local\Temp-log.txt [05/04/2015 15:47:26] - |SHD| - [0] - C:\Users\Thomas\AppData\Local\Temporary Internet Files [24/09/2017 16:44:49] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign017e6d1ed37355a5 [02/10/2017 22:13:49] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign04b574bf56a51a61 [11/09/2017 20:58:12] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign07a4ed62509d65d7 [19/09/2017 19:57:04] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign07b55ac4c6a55c00 [10/10/2017 00:15:50] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign0947a3ee7445ef4f [26/09/2017 17:55:42] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign0a0388896c3b0f25 [18/09/2017 19:23:35] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign10ce77ac968f6d7c [11/10/2017 15:04:32] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign132b5a3905fdf6c4 [22/09/2017 19:27:29] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign145dbf1574fee6fe [12/09/2017 13:40:09] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign1646699903f9119e [24/09/2017 16:44:35] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign16e52e2dc2266f0c [12/09/2017 11:12:28] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign18625ffa82b7e996 [11/10/2017 18:08:20] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign1a7c0c232221227b [26/09/2017 17:55:37] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign1b4576c4c837f4f7 [10/10/2017 00:16:10] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign1c42e319c5947713 [12/09/2017 16:13:00] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign1e75cb2d0959163b [24/09/2017 19:43:19] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign20314ee2e3d858d6 [19/09/2017 19:57:04] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign21335f0aaa947cf2 [24/09/2017 16:14:12] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign2179d060892adc35 [20/09/2017 21:04:53] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign23f309e9c16266a2 [24/09/2017 17:07:40] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign253295912751e3e9 [13/09/2017 15:38:30] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign256e6ba25d3bfcde [23/09/2017 18:16:53] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign26165d2370981dd2 [12/09/2017 20:59:11] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign2d54559fd8c9c864 [11/10/2017 15:04:32] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign3164d26474ca1378 [20/09/2017 18:07:56] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign3479db3eebe5d070 [24/09/2017 17:08:12] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign34dded60ba447da6 [12/09/2017 11:12:44] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign34ef6726ef9ae1b6 [12/09/2017 13:40:37] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign35918f718fa081a9 [10/10/2017 12:25:19] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign3798f729f4a6109c [20/09/2017 21:46:40] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign3838b27e3f66211c [11/09/2017 22:44:11] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign38f9162741214282 [20/09/2017 21:04:50] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign39909b4a115b6f86 [12/09/2017 18:07:42] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign3c6aa8df246d406c [08/10/2017 11:40:30] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign3e2ca7205a7de354 [20/09/2017 21:09:27] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign41c55ec42ac012f2 [11/10/2017 18:08:20] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign41d4414c74900f33 [08/10/2017 11:42:14] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign4387579961a30851 [20/09/2017 14:21:07] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign4550b108a51f7dc1 [12/09/2017 16:13:02] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign483a83cbfa904149 [09/10/2017 23:43:17] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign496880c2cd9d8ee3 [21/09/2017 19:17:49] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign4a2d570acbe4b716 [11/10/2017 15:05:23] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign4e2f57908ce75e26 [13/09/2017 15:38:30] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign501748adddc14687 [20/09/2017 21:11:47] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign528c3a70c36c765c [12/10/2017 22:40:12] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign52a5dd53d4a05df2 [20/09/2017 21:04:50] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign55e74b3d7321fd47 [09/10/2017 23:43:17] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign5c94573b6b4d18dd [19/09/2017 19:26:15] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign5ce9ec0938ae187f [24/09/2017 17:08:12] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign5d285acbb62b3826 [20/09/2017 21:09:26] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign5d79c3565e0788a9 [24/09/2017 17:07:42] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign5f8e52f9db67fd61 [21/09/2017 19:16:23] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign64123a551f198a47 [11/09/2017 20:58:42] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign64d5bd8c095b0357 [23/09/2017 18:16:53] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign6798391b44d54f64 [24/09/2017 17:27:34] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign6a353419c059af76 [21/09/2017 19:16:24] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign6c941d8dab44da2b [24/09/2017 19:41:48] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign6eeed14d47e46ab9 [23/09/2017 18:31:53] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign70ea855600f1f072 [11/09/2017 22:44:02] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign7540ca5624e58e7a [12/09/2017 20:59:11] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign76a30e86a03847a4 [21/09/2017 19:28:44] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign76c8a4c7241078bd [22/09/2017 19:24:43] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign7781c24af2fec373 [11/09/2017 20:59:21] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign79acbb6c01601da7 [20/09/2017 21:42:35] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign7b9758c0c7a2b21e [10/10/2017 12:25:35] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign7c49c492cae63a8c [01/10/2017 16:24:12] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign7c9be84773c9357f [16/09/2017 15:34:59] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign83971a9bc6fbb250 [11/09/2017 22:44:02] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign84ae9cdbff0aee2a [11/09/2017 22:44:08] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign84c905ccb794081e [09/10/2017 23:43:47] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign8607fb034c43e5a5 [24/09/2017 19:41:48] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign876275ae8e54aad5 [12/09/2017 18:07:42] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign88db3f011bedaa81 [13/09/2017 15:38:45] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign896079fba9ce60b1 [22/09/2017 19:24:44] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign8b5b93338fe60e59 [20/09/2017 14:21:06] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign8d0adb1998e080a7 [24/09/2017 16:46:23] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign8da01d4c2d7a70fb [09/10/2017 23:44:52] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign8f4f30412066519a [20/09/2017 18:07:52] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign8f7ce2cfa94afde9 [12/09/2017 16:12:59] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign99399565a900f0ff [24/09/2017 17:07:40] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign9a9812b17e740cc7 [12/09/2017 13:41:29] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsign9c10449efe189cad [20/09/2017 14:47:33] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigna02cb687f1e84b18 [18/09/2017 19:23:35] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigna06d6ea8e0c933fc [20/09/2017 21:43:25] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigna38e87302257effd [04/10/2017 13:50:45] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigna5604be98ae38f52 [24/09/2017 20:21:31] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigna933f90ad52114c0 [20/09/2017 14:47:11] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigna9d23dc1dd6d9551 [19/09/2017 19:57:13] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignaada64cae27c64fe [20/09/2017 21:43:15] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignac6cd6a20345eea7 [18/09/2017 19:25:14] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignb1a5ff39a2476ce7 [20/09/2017 14:47:12] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignb2843a5297e6e1b5 [12/10/2017 22:40:12] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignb6ea9cf6575f7e99 [23/09/2017 18:36:50] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignb98276b6e85b3765 [12/09/2017 13:40:09] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignbe7151a7f1361310 [12/09/2017 11:12:28] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignc154f1b04e27bd2d [15/09/2017 21:47:21] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignc2e2cb2354151404 [24/09/2017 20:21:31] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignc4949d90667c4681 [24/09/2017 16:44:35] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignc9029b00dc3421e9 [20/09/2017 21:10:37] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigncc23347726d79f06 [15/09/2017 21:47:12] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigncc23486535955f10 [19/09/2017 19:26:15] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignd2d5c84fd01b5881 [12/09/2017 11:12:53] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignd3b22df29ad0b097 [20/09/2017 21:09:28] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignd6f7e6070363b77a [21/09/2017 19:21:37] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignd9bb489bd5197742 [24/09/2017 20:21:39] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigndcff315f51bd4e50 [20/09/2017 18:07:52] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigndd5190e501f029ae [04/10/2017 13:50:45] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignde15d5201d74dec0 [12/09/2017 20:59:13] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigndf5818819dbf6897 [10/10/2017 12:25:19] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigne17346d21a90e19d [20/09/2017 21:10:38] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigne384a45a8a165fea [11/09/2017 20:58:12] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigne40abd475926cdce [12/09/2017 18:07:55] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigne4604dc9c50d7c9a [16/09/2017 15:34:48] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigne9999600210ee2c0 [20/09/2017 14:21:11] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigne99db9e6ef6a5f5c [20/09/2017 21:42:30] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigne9afdc59686229bd [24/09/2017 20:24:54] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsigned3b806dced73057 [08/10/2017 11:40:30] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignee77a5c574c04fd1 [12/10/2017 22:41:39] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignf0687b4a6f48d5d9 [04/10/2017 13:51:20] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignf129fa61b97df15c [24/09/2017 16:14:11] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignf1a1bed6320651a5 [16/09/2017 15:34:48] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignf4e330b51df5ed8b [19/09/2017 19:28:25] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignf646a3f03a7c4cfb [23/09/2017 18:17:39] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignf723c7c028aef02b [02/10/2017 22:13:49] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignfaabb625e46675c8 [11/10/2017 18:21:15] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignfb60d92e6f8dc032 [20/09/2017 21:43:30] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignfc0400afba14a01a [02/10/2017 22:13:49] - |D| - [0] - C:\Users\Thomas\AppData\Local\Tempzxpsignfebee034b166ff55 [05/09/2015 16:18:18] - |D| - [0] - C:\Users\Thomas\AppData\Local\TurboDismount [15/02/2015 12:11:43] - |D| - [3465] - C:\Users\Thomas\AppData\Local\Ubisoft [01/05/2015 19:39:38] - |D| - [4211] - C:\Users\Thomas\AppData\Local\Ubisoft Game Launcher [18/02/2016 00:49:23] - |D| - [662700] - C:\Users\Thomas\AppData\Local\Unity [24/10/2016 18:07:42] - |D| - [187] - C:\Users\Thomas\AppData\Local\UnrealEngine [01/10/2017 10:35:56] - |D| - [0] - C:\Users\Thomas\AppData\Local\UnrealEngineLauncher [14/08/2015 21:44:02] - |A| - [3] - C:\Users\Thomas\AppData\Local\updater.log [14/08/2015 21:44:02] - |A| - [424] - C:\Users\Thomas\AppData\Local\UserProducts.xml [22/12/2014 22:14:29] - |D| - [1138359] - C:\Users\Thomas\AppData\Local\VirtualStore [17/10/2015 11:15:48] - |D| - [350] - C:\Users\Thomas\AppData\Local\war [30/04/2016 17:47:47] - |D| - [1820886] - C:\Users\Thomas\AppData\Local\wf-launcher [12/07/2017 11:33:37] - |D| - [549377] - C:\Users\Thomas\AppData\Local\ZHP [16/06/2016 11:44:40] - |A| - [758] - C:\Users\Thomas\AppData\Local\ZHPFixReport.txt [05/12/2015 12:57:30] - |D| - [0] - C:\Users\Thomas\AppData\LocalLow\Adobe [10/01/2016 12:46:51] - |D| - [1869242] - C:\Users\Thomas\AppData\LocalLow\ApathyWorks [26/02/2016 23:25:52] - |D| - [647] - C:\Users\Thomas\AppData\LocalLow\Butterflyware [26/02/2016 23:54:43] - |D| - [947584] - C:\Users\Thomas\AppData\LocalLow\CampoSanto [30/03/2015 21:32:48] - |D| - [0] - C:\Users\Thomas\AppData\LocalLow\Company [18/02/2016 11:32:41] - |D| - [565] - C:\Users\Thomas\AppData\LocalLow\DefaultCompany [04/03/2016 23:14:35] - |D| - [663] - C:\Users\Thomas\AppData\LocalLow\Dinosaur Polo Club [10/04/2015 20:04:34] - |SHD| - [0] - C:\Users\Thomas\AppData\LocalLow\EmieBrowserModeList [10/04/2015 19:40:16] - |SHD| - [0] - C:\Users\Thomas\AppData\LocalLow\EmieSiteList [10/04/2015 20:04:34] - |SHD| - [0] - C:\Users\Thomas\AppData\LocalLow\EmieUserList [28/11/2015 02:40:53] - |D| - [964] - C:\Users\Thomas\AppData\LocalLow\Giant Army [22/11/2015 13:45:48] - |D| - [1599132] - C:\Users\Thomas\AppData\LocalLow\Google [25/04/2015 10:47:30] - |D| - [201681] - C:\Users\Thomas\AppData\LocalLow\Heroes and Generals [30/12/2014 11:48:45] - |D| - [215383] - C:\Users\Thomas\AppData\LocalLow\IndieGala [13/05/2016 21:30:03] - |D| - [216] - C:\Users\Thomas\AppData\LocalLow\IObit [22/12/2014 22:23:17] - |D| - [11131261] - C:\Users\Thomas\AppData\LocalLow\Microsoft [22/01/2017 17:34:16] - |D| - [0] - C:\Users\Thomas\AppData\LocalLow\Mozilla [16/11/2016 22:49:16] - |D| - [1690] - C:\Users\Thomas\AppData\LocalLow\nobodyshot [08/02/2015 12:13:20] - |D| - [261380096] - C:\Users\Thomas\AppData\LocalLow\Oracle [20/02/2017 14:35:25] - |A| - [47] - C:\Users\Thomas\AppData\LocalLow\rbxcsettings.rbx [18/03/2015 17:02:20] - |D| - [3588177] - C:\Users\Thomas\AppData\LocalLow\SKS [09/04/2016 23:36:03] - |D| - [1646] - C:\Users\Thomas\AppData\LocalLow\Smartly Dressed Games [21/04/2017 20:34:14] - |D| - [765] - C:\Users\Thomas\AppData\LocalLow\Sony Online Entertainment [30/12/2015 20:12:05] - |D| - [14851888] - C:\Users\Thomas\AppData\LocalLow\South East Games [26/12/2014 17:33:59] - |D| - [661] - C:\Users\Thomas\AppData\LocalLow\Stage 2 Studios [25/12/2014 16:02:33] - |D| - [160159223] - C:\Users\Thomas\AppData\LocalLow\Sun [31/03/2016 18:44:05] - |D| - [0] - C:\Users\Thomas\AppData\LocalLow\Temp [29/02/2016 18:24:25] - |D| - [18788088] - C:\Users\Thomas\AppData\LocalLow\The Pok__mon Company International [30/12/2014 11:44:45] - |D| - [424083594] - C:\Users\Thomas\AppData\LocalLow\Unity [01/07/2017 20:35:11] - |D| - [851968] - C:\Users\Thomas\AppData\LocalLow\uTorrent [23/11/2015 16:27:36] - |D| - [1010] - C:\Users\Thomas\AppData\LocalLow\WARTEAM [19/03/2016 23:33:14] - |D| - [741351] - C:\Users\Thomas\AppData\Roaming\.funcraft [14/03/2016 19:09:51] - |D| - [683817] - C:\Users\Thomas\AppData\Roaming\.funcraft-premium [25/11/2014 11:14:15] - |AD| - [1352081981] - C:\Users\Thomas\AppData\Roaming\.minecraft [01/05/2016 18:49:24] - |D| - [0] - C:\Users\Thomas\AppData\Roaming\Acid Software [22/12/2014 22:14:54] - |D| - [231796488] - C:\Users\Thomas\AppData\Roaming\Adobe [19/12/2016 23:42:15] - |A| - [891] - C:\Users\Thomas\AppData\Roaming\AdobeWLCMR2Cache.dat [10/07/2015 11:16:48] - |A| - [20] - C:\Users\Thomas\AppData\Roaming\appdataFr2.bin [10/07/2015 13:10:12] - |A| - [24] - C:\Users\Thomas\AppData\Roaming\appdataFr25.bin [28/03/2015 11:46:13] - |D| - [0] - C:\Users\Thomas\AppData\Roaming\ASP [21/10/2016 13:43:26] - |D| - [1819] - C:\Users\Thomas\AppData\Roaming\Audacity [27/03/2017 19:09:46] - |D| - [12654773] - C:\Users\Thomas\AppData\Roaming\AVAST Software [27/02/2016 19:47:49] - |D| - [1338] - C:\Users\Thomas\AppData\Roaming\BrawlhallaAir [04/05/2017 19:23:36] - |D| - [43447] - C:\Users\Thomas\AppData\Roaming\Citra [31/07/2015 22:07:48] - |D| - [57974] - C:\Users\Thomas\AppData\Roaming\Clickteam [04/10/2015 20:25:10] - |D| - [0] - C:\Users\Thomas\AppData\Roaming\Colossal Order [20/06/2015 20:31:27] - |D| - [6362] - C:\Users\Thomas\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [28/06/2015 18:17:43] - |D| - [13217] - C:\Users\Thomas\AppData\Roaming\com.playsaurus.heroclicker [16/07/2015 10:52:07] - |D| - [0] - C:\Users\Thomas\AppData\Roaming\Construct2 [07/10/2017 14:47:05] - |D| - [49586] - C:\Users\Thomas\AppData\Roaming\Cuphead [24/03/2016 21:52:47] - |A| - [2731] - C:\Users\Thomas\AppData\Roaming\droid4xinstaller.log [17/09/2017 14:35:09] - |D| - [1912371] - C:\Users\Thomas\AppData\Roaming\EasyAntiCheat [16/05/2015 22:11:40] - |D| - [4459472] - C:\Users\Thomas\AppData\Roaming\FlowStone [16/06/2016 21:48:28] - |D| - [32] - C:\Users\Thomas\AppData\Roaming\Gyazo [24/03/2016 21:52:51] - |D| - [256256116] - C:\Users\Thomas\AppData\Roaming\HaiYuInst [25/04/2015 10:40:51] - |D| - [31323] - C:\Users\Thomas\AppData\Roaming\HeroesAndGeneralsDesktop [28/03/2015 23:19:31] - |D| - [45] - C:\Users\Thomas\AppData\Roaming\Identities [16/05/2015 22:11:55] - |D| - [2447392] - C:\Users\Thomas\AppData\Roaming\Image-Line [13/05/2016 21:29:48] - |D| - [885214] - C:\Users\Thomas\AppData\Roaming\IObit [25/12/2014 20:56:53] - |D| - [3096] - C:\Users\Thomas\AppData\Roaming\java [21/02/2016 13:55:15] - |D| - [442] - C:\Users\Thomas\AppData\Roaming\Leadertech [06/12/2015 15:45:38] - |D| - [69] - C:\Users\Thomas\AppData\Roaming\Lilly and Sasha [22/12/2014 22:23:29] - |D| - [313841] - C:\Users\Thomas\AppData\Roaming\Macromedia [31/08/2017 11:27:48] - |D| - [66630] - C:\Users\Thomas\AppData\Roaming\Magic Set Editor [05/08/2015 09:58:04] - |D| - [1907918] - C:\Users\Thomas\AppData\Roaming\MAXON [05/04/2015 15:47:26] - |SD| - [7998284] - C:\Users\Thomas\AppData\Roaming\Microsoft [20/04/2016 18:47:46] - |D| - [20] - C:\Users\Thomas\AppData\Roaming\Mirillis [24/01/2015 21:19:13] - |D| - [0] - C:\Users\Thomas\AppData\Roaming\MMFApplications [18/02/2016 13:03:36] - |D| - [56805] - C:\Users\Thomas\AppData\Roaming\MonoDevelop-Unity-5.0 [14/04/2015 21:32:43] - |D| - [79034156] - C:\Users\Thomas\AppData\Roaming\Mozilla [24/02/2017 17:05:51] - |D| - [314882] - C:\Users\Thomas\AppData\Roaming\Mumble [17/02/2016 23:05:14] - |D| - [2576903] - C:\Users\Thomas\AppData\Roaming\Notepad++ [08/03/2017 20:43:24] - |D| - [203618696] - C:\Users\Thomas\AppData\Roaming\NVIDIA [03/02/2017 19:20:32] - |D| - [0] - C:\Users\Thomas\AppData\Roaming\OBS [20/01/2017 16:58:13] - |D| - [12421077] - C:\Users\Thomas\AppData\Roaming\OpenOffice [23/12/2015 23:21:32] - |D| - [11148] - C:\Users\Thomas\AppData\Roaming\Origin [19/09/2017 19:26:26] - |D| - [0] - C:\Users\Thomas\AppData\Roaming\PDAppFlex [05/05/2015 13:04:11] - |D| - [1787] - C:\Users\Thomas\AppData\Roaming\PhotoFiltre Studio X [09/01/2015 21:13:47] - |D| - [1578237] - C:\Users\Thomas\AppData\Roaming\Pro Cycling Manager 2014 [20/12/2015 12:32:46] - |D| - [786463] - C:\Users\Thomas\AppData\Roaming\Pro Cycling Manager 2015 [23/06/2016 13:14:05] - |D| - [914374] - C:\Users\Thomas\AppData\Roaming\Pro Cycling Manager 2016 [21/07/2017 17:15:23] - |D| - [913377] - C:\Users\Thomas\AppData\Roaming\Pro Cycling Manager 2017 [13/05/2016 21:39:58] - |D| - [27334] - C:\Users\Thomas\AppData\Roaming\ProductData [28/03/2015 19:04:40] - |D| - [485376] - C:\Users\Thomas\AppData\Roaming\Python-Eggs [15/03/2015 00:39:14] - |D| - [3943] - C:\Users\Thomas\AppData\Roaming\qBittorrent [23/04/2017 20:55:29] - |D| - [1645240] - C:\Users\Thomas\AppData\Roaming\RealWorld [07/07/2015 10:11:29] - |D| - [1793] - C:\Users\Thomas\AppData\Roaming\Shooter [12/02/2015 20:15:40] - |D| - [94140140] - C:\Users\Thomas\AppData\Roaming\Skype [29/04/2015 16:23:39] - |D| - [28073694] - C:\Users\Thomas\AppData\Roaming\skyz [28/11/2015 02:44:42] - |D| - [34] - C:\Users\Thomas\AppData\Roaming\SmartSteamEmu [02/08/2016 13:05:57] - |D| - [3061025] - C:\Users\Thomas\AppData\Roaming\Songbird2 [24/01/2015 21:18:34] - |D| - [1215] - C:\Users\Thomas\AppData\Roaming\Steam [06/07/2017 11:01:58] - |D| - [7080173] - C:\Users\Thomas\AppData\Roaming\steelseries-engine-3-client [18/02/2016 13:03:44] - |D| - [20547] - C:\Users\Thomas\AppData\Roaming\Subversion [05/09/2015 18:57:54] - |D| - [0] - C:\Users\Thomas\AppData\Roaming\Sun [06/05/2016 19:14:02] - |A| - [36] - C:\Users\Thomas\AppData\Roaming\SuYZkvrV.tmp [19/09/2016 17:58:55] - |D| - [205403] - C:\Users\Thomas\AppData\Roaming\Synthesia [26/02/2016 22:33:20] - |D| - [162007369] - C:\Users\Thomas\AppData\Roaming\System [05/09/2015 13:24:02] - |D| - [71] - C:\Users\Thomas\AppData\Roaming\TechSmith [13/07/2015 10:42:52] - |D| - [465324] - C:\Users\Thomas\AppData\Roaming\Trove [25/12/2014 21:54:27] - |D| - [110587721] - C:\Users\Thomas\AppData\Roaming\TS3Client [31/03/2016 16:23:13] - |D| - [15] - C:\Users\Thomas\AppData\Roaming\TubeTycoon [27/02/2016 11:33:07] - |D| - [155] - C:\Users\Thomas\AppData\Roaming\Ubisoft [18/02/2016 01:24:10] - |D| - [170723433] - C:\Users\Thomas\AppData\Roaming\Unity [27/02/2016 18:57:27] - |D| - [88309] - C:\Users\Thomas\AppData\Roaming\uplay [26/12/2014 17:15:13] - |D| - [78617729] - C:\Users\Thomas\AppData\Roaming\uTorrent [07/03/2016 17:49:29] - |D| - [301219] - C:\Users\Thomas\AppData\Roaming\vlc [28/12/2014 17:04:48] - |D| - [12] - C:\Users\Thomas\AppData\Roaming\WinRAR [19/09/2015 21:27:05] - |D| - [40542] - C:\Users\Thomas\AppData\Roaming\WorldPainter [15/06/2016 11:26:02] - |D| - [12264705] - C:\Users\Thomas\AppData\Roaming\ZHP [05/04/2015 15:47:26] - |RD| - [0] - C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [05/04/2015 15:47:26] - |RD| - [0] - C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [05/04/2015 15:47:26] - |RD| - [0] - C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [22/12/2014 22:14:57] - |RD| - [0] - C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [22/12/2014 22:14:57] - |RD| - [0] - C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [05/04/2015 15:47:26] - |RD| - [0] - C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools ---------- | C:\ProgramData [04/10/2015 20:25:10] - |D| - [0] - C:\ProgramData\.mono [20/06/2015 20:31:26] - |D| - [615357133] - C:\ProgramData\Adobe [27/01/2015 21:16:05] - |D| - [0] - C:\ProgramData\Age of Empires 3 [10/06/2015 16:54:57] - |D| - [1144834] - C:\ProgramData\Andy [10/06/2015 17:21:33] - |D| - [0] - C:\ProgramData\Apple [22/08/2013 16:45:52] - |SHD| - [0] - C:\ProgramData\Application Data [04/09/2015 19:59:31] - |D| - [273173848] - C:\ProgramData\AVAST Software [21/10/2016 17:53:21] - |D| - [11144456] - C:\ProgramData\BitRaider [12/02/2015 22:20:04] - |D| - [0] - C:\ProgramData\BlueStacksSetup [27/05/2015 17:12:56] - |D| - [0] - C:\ProgramData\boost_interprocess [22/12/2014 22:12:13] - |SHD| - [0] - C:\ProgramData\Bureau [23/04/2015 17:19:13] - |HD| - [173927] - C:\ProgramData\CanonBJ [19/01/2015 08:19:03] - |D| - [0] - C:\ProgramData\Caphyon [11/11/2015 17:53:11] - |D| - [323] - C:\ProgramData\Codemasters [26/12/2014 17:28:29] - |D| - [3388] - C:\ProgramData\DAEMON Tools Lite [22/08/2013 16:45:52] - |SHD| - [0] - C:\ProgramData\Desktop [22/08/2013 16:45:52] - |SHD| - [0] - C:\ProgramData\Documents [12/12/2015 21:32:53] - |D| - [3714] - C:\ProgramData\Electronic Arts [01/10/2017 10:34:59] - |D| - [74716434] - C:\ProgramData\Epic [10/02/2017 18:42:38] - |D| - [5075638] - C:\ProgramData\For Honor [11/04/2016 20:30:43] - |D| - [3873] - C:\ProgramData\gamemaker_studio [30/04/2016 17:47:49] - |D| - [370755] - C:\ProgramData\GFACE [23/09/2015 16:36:52] - |D| - [468495775] - C:\ProgramData\GlassWire [06/10/2017 22:47:33] - |D| - [707684] - C:\ProgramData\GOG.com [13/05/2016 21:30:03] - |D| - [42334810] - C:\ProgramData\IObit [26/03/2017 14:04:59] - |D| - [0] - C:\ProgramData\KONAMI [28/06/2016 20:18:11] - |D| - [0] - C:\ProgramData\LogMeIn [28/02/2017 20:08:48] - |D| - [3146968] - C:\ProgramData\LumaEmu_SteamCloud [05/09/2015 21:58:06] - |D| - [35330939] - C:\ProgramData\Malwarebytes [28/12/2014 11:21:55] - |D| - [6454271311] - C:\ProgramData\ManiaPlanet [22/06/2016 10:19:22] - |D| - [0] - C:\ProgramData\McAfee [22/12/2014 22:12:13] - |SHD| - [0] - C:\ProgramData\Menu Démarrer [22/08/2013 15:36:15] - |SD| - [1490306249] - C:\ProgramData\Microsoft [20/04/2016 18:47:46] - |D| - [20] - C:\ProgramData\Mirillis [22/12/2014 22:12:13] - |SHD| - [0] - C:\ProgramData\Modèles [17/07/2015 10:14:28] - |RASH| - [496] - C:\ProgramData\ntuser.pol [05/04/2015 15:42:39] - |D| - [2022915] - C:\ProgramData\NVIDIA [05/04/2015 15:42:21] - |D| - [1016944729] - C:\ProgramData\NVIDIA Corporation [25/12/2014 16:05:04] - |D| - [70997815] - C:\ProgramData\Oracle [23/02/2016 12:22:48] - |D| - [0] - C:\ProgramData\Orbit [12/12/2015 21:32:55] - |D| - [358193199] - C:\ProgramData\Origin [24/01/2015 20:46:47] - |D| - [378388648] - C:\ProgramData\Package Cache [13/07/2015 10:41:44] - |D| - [0] - C:\ProgramData\Picroma [13/12/2015 14:11:04] - |D| - [25] - C:\ProgramData\PopCap Games [22/12/2014 22:14:13] - |D| - [24520] - C:\ProgramData\PRICache [13/05/2016 21:30:02] - |D| - [207] - C:\ProgramData\ProductData [05/12/2015 12:43:29] - |D| - [3418] - C:\ProgramData\regid.1986-12.com.adobe [22/08/2013 17:36:30] - |D| - [2070] - C:\ProgramData\regid.1991-06.com.microsoft [27/08/2016 10:35:01] - |D| - [19535] - C:\ProgramData\ShellIcons [12/02/2015 20:15:13] - |D| - [167135432] - C:\ProgramData\Skype [04/07/2017 11:48:47] - |D| - [2384769] - C:\ProgramData\Socialclub [22/08/2013 16:45:52] - |SHD| - [0] - C:\ProgramData\Start Menu [28/06/2015 17:59:45] - |D| - [59171688] - C:\ProgramData\Steam [06/07/2017 11:00:37] - |D| - [240473709] - C:\ProgramData\SteelSeries [19/10/2017 18:42:01] - |D| - [0] - C:\ProgramData\SWCUTemp [22/08/2013 16:45:52] - |SHD| - [0] - C:\ProgramData\Templates [10/12/2016 22:04:54] - |D| - [0] - C:\ProgramData\Thomas [24/03/2016 21:52:53] - |D| - [123] - C:\ProgramData\Thunder Network [07/09/2015 17:20:23] - |D| - [0] - C:\ProgramData\TmForever [25/12/2014 14:22:46] - |D| - [572938981] - C:\ProgramData\TrackMania [24/03/2016 12:01:42] - |D| - [44576116] - C:\ProgramData\TrackmaniaTurbo [01/05/2015 19:35:33] - |D| - [1453] - C:\ProgramData\Ubisoft [18/02/2016 01:24:08] - |D| - [6573] - C:\ProgramData\Unity [11/02/2015 19:40:06] - |D| - [502] - C:\ProgramData\{1d11ea33-3762-5007-1d11-1ea33376a8cc} [19/06/2015 16:17:04] - |D| - [2572] - C:\ProgramData\{3c74fce1-e05a-de5f-3c74-4fce1e05f387} [12/04/2015 12:11:32] - |D| - [0] - C:\ProgramData\{411f5e18-8e9a-978d-411f-f5e188e97862} [03/07/2015 16:17:05] - |D| - [2600] - C:\ProgramData\{47f76586-25fd-080d-47f7-7658625f9618} [10/07/2015 10:17:04] - |D| - [2598] - C:\ProgramData\{69579552-0457-8f64-6957-795520455548} [31/01/2015 11:16:19] - |D| - [952] - C:\ProgramData\{76e39241-b1b2-c0d7-76e3-39241b1b4906} [29/04/2015 16:17:05] - |D| - [1500] - C:\ProgramData\{76fba9b6-b0c6-3d7d-76fb-ba9b6b0ca6da} [23/06/2015 16:17:06] - |D| - [2574] - C:\ProgramData\{7c9b8d21-2bc9-3fb6-7c9b-b8d212bc3484} [11/06/2015 16:17:43] - |D| - [2650] - C:\ProgramData\{97677f6d-e07c-ea14-9767-77f6de07fdb7} [06/07/2015 22:17:03] - |D| - [2646] - C:\ProgramData\{98a91c35-18fe-ca4d-98a9-91c3518f70d4} [01/08/2015 16:17:12] - |D| - [2534] - C:\ProgramData\{99612a3a-dee0-d4b5-9961-12a3adeea8eb} [12/02/2015 22:55:00] - |D| - [948] - C:\ProgramData\{b320a2c0-270d-1064-b320-0a2c02708b00} [01/08/2015 22:17:13] - |D| - [2534] - C:\ProgramData\{bd81746f-3c94-d3c1-bd81-1746f3c9d1bc} [17/06/2015 16:17:05] - |D| - [2600] - C:\ProgramData\{d67e945b-6362-8ebd-d67e-e945b636516d} [24/06/2015 16:17:05] - |D| - [2574] - C:\ProgramData\{dc60c375-807f-e433-dc60-0c3758070dd6} [02/08/2015 22:17:16] - |D| - [2548] - C:\ProgramData\{f39111a0-03b9-81eb-f391-111a003b4680} ---------- | C:\ProgramData\Microsoft\Windows\Start Menu [16/09/2017 16:21:05] - |A| - [823] - C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk [22/08/2013 17:36:33] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini [22/12/2014 22:12:13] - |SHD| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programmes [22/08/2013 17:36:30] - |RD| - [273554] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs [22/08/2013 17:36:30] - |RD| - [1686] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility [22/08/2013 17:36:30] - |RD| - [18062] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories [22/08/2013 17:36:30] - |RD| - [30058] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [12/09/2017 13:41:02] - |A| - [1169] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk [20/06/2015 20:31:26] - |A| - [904] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk [11/09/2017 20:52:42] - |A| - [1056] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk [28/02/2016 12:12:25] - |D| - [2203] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Age of Empires II HD The African Kingdoms [23/06/2017 21:08:43] - |D| - [2911] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\American Truck Simulator - Heavy Cargo Pack [21/10/2016 13:43:16] - |A| - [738] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk [27/03/2017 19:11:20] - |A| - [1033] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk [21/09/2017 18:31:21] - |D| - [1012] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software [12/02/2015 22:20:53] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks [22/08/2013 08:57:22] - |RAS| - [2131] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Camera.lnk [30/05/2015 21:51:35] - |D| - [966] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [19/12/2015 17:27:48] - |D| - [7311] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4 [06/02/2015 19:30:45] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coop-Land [13/07/2015 10:41:44] - |D| - [1063] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cube World [06/10/2017 22:47:32] - |D| - [1711] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cuphead [GOG.com] [22/08/2013 17:36:33] - |SH| - [1216] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini [22/08/2013 08:57:05] - |RAS| - [853] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop.lnk [13/04/2017 19:03:44] - |D| - [1286] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolphin [19/01/2015 19:19:31] - |D| - [5768] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games [01/10/2017 10:35:09] - |A| - [991] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk [21/11/2014 00:56:07] - |RAS| - [2440] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileManager.lnk [14/03/2016 19:02:55] - |A| - [901] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FunCraft (Launcher Minecraft Premium).lnk [09/01/2015 21:05:21] - |D| - [1666] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live [07/01/2015 22:23:47] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games [03/05/2016 18:59:33] - |A| - [796] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk [19/03/2017 16:39:33] - |A| - [927] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GoldenEye Source.lnk [16/10/2015 18:36:44] - |A| - [2213] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [16/09/2017 13:43:41] - |A| - [2230] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk [20/06/2017 19:04:37] - |D| - [3069] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo [15/07/2017 21:21:52] - |D| - [1496] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hydrogen - 0.9.7 [22/08/2013 08:54:10] - |RAS| - [2349] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk [13/05/2016 21:30:01] - |D| - [2651] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller [13/05/2016 21:30:01] - |A| - [1386] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk [14/03/2016 19:09:36] - |D| - [6805] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java [04/05/2015 11:47:04] - |D| - [1502] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Just Cause 2 [16/06/2016 22:06:14] - |D| - [2588] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot [11/07/2017 10:20:53] - |D| - [2385] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi [28/01/2015 16:59:35] - |D| - [4082] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LucasArts [31/08/2017 11:27:29] - |A| - [777] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Set Editor.lnk [22/08/2013 17:36:30] - |D| - [170] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance [05/09/2015 21:58:09] - |D| - [3702] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware [28/12/2014 11:22:05] - |D| - [786] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManiaPlanet [05/08/2015 10:07:32] - |D| - [3260] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAXON [23/01/2015 17:38:45] - |D| - [10110] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games [27/06/2016 13:57:40] - |D| - [752] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft [20/04/2016 18:47:34] - |D| - [1955] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mirillis [20/04/2016 21:52:36] - |A| - [844] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [24/02/2017 17:04:20] - |D| - [797] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble [08/06/2016 21:20:17] - |D| - [1892] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NBTExplorer [07/03/2015 12:09:08] - |D| - [1872] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need for Speed Most Wanted 2005 [17/02/2016 23:05:15] - |D| - [746] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ [08/03/2017 20:29:38] - |D| - [6482] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [20/01/2017 16:57:27] - |SD| - [5845] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.3 [12/12/2015 21:32:54] - |D| - [1255] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin [02/05/2015 18:23:27] - |A| - [1051] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk [04/10/2015 20:24:36] - |D| - [1772] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paradox Interactive [03/04/2016 18:38:08] - |D| - [5454] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2 [05/05/2015 13:04:10] - |D| - [4555] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X [22/08/2013 08:57:08] - |RAS| - [2365] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotosApp.lnk [28/06/2015 15:08:02] - |D| - [2046] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pipix [01/04/2016 15:52:04] - |D| - [1598] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project 64 2.2 [22/04/2017 21:15:52] - |D| - [2034] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickPar [28/02/2017 20:01:09] - |D| - [1926] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rebellion [09/04/2016 14:12:38] - |D| - [1432] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva [09/10/2016 11:46:28] - |D| - [1506] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Barrels [01/01/2016 19:47:52] - |D| - [1144] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RomStation [18/03/2015 12:25:39] - |D| - [720] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scrolls [22/08/2013 08:45:50] - |RAS| - [1588] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk [01/09/2017 12:05:39] - |D| - [1564] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA [27/03/2017 19:41:15] - |D| - [2153] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [23/02/2017 01:33:43] - |D| - [2570] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sniper Elite 3 [16/09/2016 20:53:32] - |D| - [3551] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Songbird [29/02/2016 23:14:59] - |D| - [3636] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Star Wars - Battlefront 2 [GOG.com] [19/01/2017 13:25:30] - |D| - [3972] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STAR WARS Battlefront [22/08/2013 17:36:30] - |RD| - [2418] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp [08/12/2016 17:05:21] - |D| - [764] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam [06/07/2017 11:01:52] - |D| - [2240] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteelSeries [20/02/2015 14:22:47] - |D| - [4772] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super macro [22/08/2013 17:36:30] - |RD| - [6681] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools [25/12/2014 21:54:24] - |D| - [2065] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client [04/10/2017 16:23:55] - |A| - [825] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk [25/12/2014 14:17:14] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmUnitedForever [09/02/2017 19:52:20] - |D| - [10263] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrackMania Unlimiter [27/02/2016 11:32:49] - |D| - [3497] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft [18/02/2016 00:37:05] - |D| - [2931] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unity 5.3.2f1 (64-bit) [07/03/2016 17:49:08] - |D| - [4812] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [18/10/2015 23:27:45] - |D| - [5598] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual Audio Cable [05/12/2015 12:46:53] - |D| - [1333] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTFEdit [23/06/2017 20:52:14] - |D| - [722] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinCDEmu [05/04/2015 15:51:22] - |A| - [1511] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk [04/05/2016 17:10:28] - |A| - [2523] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2.6.lnk [22/08/2013 08:48:43] - |RAS| - [2191] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Store.lnk [28/12/2014 17:03:30] - |D| - [4093] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [19/09/2015 21:27:00] - |D| - [2019] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WorldPainter [16/06/2016 11:43:57] - |D| - [800] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP ---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [22/08/2013 17:36:33] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini [06/07/2017 11:01:51] - |A| - [2244] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk ---------- | C:\Program Files (x86) [03/04/2017 22:14:21] - |D| - [301285644] - C:\Program Files (x86)\Adobe [16/09/2017 16:12:39] - |D| - [63797692] - C:\Program Files (x86)\BlueStacks [22/08/2013 15:36:15] - |D| - [839388385] - C:\Program Files (x86)\Common Files [22/08/2013 17:36:33] - |N| - [174] - C:\Program Files (x86)\desktop.ini [10/06/2016 15:18:55] - |D| - [612267040] - C:\Program Files (x86)\Google [20/06/2017 19:04:36] - |D| - [21417548] - C:\Program Files (x86)\Gyazo [16/05/2015 22:08:04] - |D| - [2048] - C:\Program Files (x86)\Image-Line [23/01/2015 17:38:50] - |D| - [25983285] - C:\Program Files (x86)\InstallShield Installation Information [22/08/2013 17:36:30] - |D| - [6876611] - C:\Program Files (x86)\Internet Explorer [13/05/2016 21:29:48] - |D| - [67185721] - C:\Program Files (x86)\IObit [02/09/2015 16:55:26] - |D| - [12335894] - C:\Program Files (x86)\LINE [18/02/2016 01:12:26] - |D| - [16513331] - C:\Program Files (x86)\Microsoft SDKs [06/02/2015 19:38:38] - |D| - [6076507] - C:\Program Files (x86)\Microsoft XNA [22/08/2013 17:36:30] - |D| - [23935] - C:\Program Files (x86)\Microsoft.NET [20/04/2016 18:47:18] - |D| - [63264061] - C:\Program Files (x86)\Mirillis [04/05/2016 17:10:27] - |D| - [9336778] - C:\Program Files (x86)\Movie Maker 2.6 [20/04/2016 21:52:35] - |D| - [262927] - C:\Program Files (x86)\Mozilla Maintenance Service [05/04/2015 16:38:30] - |D| - [68448446] - C:\Program Files (x86)\MSBuild [24/02/2017 17:03:33] - |D| - [143455] - C:\Program Files (x86)\Mumble [05/04/2015 15:42:17] - |D| - [433188814] - C:\Program Files (x86)\NVIDIA Corporation [05/04/2015 16:38:30] - |D| - [157368635] - C:\Program Files (x86)\Reference Assemblies [14/08/2015 21:43:53] - |D| - [4822888] - C:\Program Files (x86)\Skillbrains [27/03/2017 19:41:14] - |RD| - [92426541] - C:\Program Files (x86)\Skype [05/12/2015 12:46:53] - |D| - [2787982] - C:\Program Files (x86)\VTFEdit [08/03/2017 20:28:57] - |D| - [833354] - C:\Program Files (x86)\VulkanRT [22/08/2013 17:36:30] - |D| - [1712408] - C:\Program Files (x86)\Windows Defender [18/02/2016 01:12:26] - |D| - [4259062] - C:\Program Files (x86)\Windows Kits [22/08/2013 17:36:30] - |D| - [6017536] - C:\Program Files (x86)\Windows Mail [22/08/2013 17:36:30] - |D| - [3326490] - C:\Program Files (x86)\Windows Media Player [22/08/2013 17:36:30] - |D| - [230912] - C:\Program Files (x86)\Windows Multimedia Platform [22/08/2013 17:36:30] - |D| - [7590970] - C:\Program Files (x86)\Windows NT [22/08/2013 17:36:30] - |D| - [5502096] - C:\Program Files (x86)\Windows Photo Viewer [22/08/2013 17:36:30] - |D| - [230912] - C:\Program Files (x86)\Windows Portable Devices [22/08/2013 17:36:30] - |D| - [0] - C:\Program Files (x86)\Windows Sidebar [22/08/2013 17:36:30] - |D| - [0] - C:\Program Files (x86)\WindowsPowerShell ---------- | C:\Program Files [11/09/2017 20:42:37] - |D| - [1849287934] - C:\Program Files\Adobe [30/05/2015 21:51:25] - |D| - [17751848] - C:\Program Files\CCleaner [22/08/2013 15:36:15] - |D| - [200756008] - C:\Program Files\Common Files [22/08/2013 17:36:45] - |ASH| - [174] - C:\Program Files\desktop.ini [01/10/2017 10:39:08] - |D| - [0] - C:\Program Files\Epic Games [22/12/2014 22:12:13] - |SHD| - [0] - C:\Program Files\Fichiers communs [16/05/2015 22:11:52] - |D| - [6588473] - C:\Program Files\Image-Line [22/08/2013 17:36:31] - |D| - [26337180] - C:\Program Files\Internet Explorer [14/03/2016 19:09:13] - |D| - [371157747] - C:\Program Files\Java [05/04/2015 16:38:30] - |D| - [25757] - C:\Program Files\MSBuild [05/04/2015 15:42:17] - |D| - [1225572437] - C:\Program Files\NVIDIA Corporation [24/03/2016 21:55:39] - |D| - [58866682] - C:\Program Files\Oracle [05/04/2015 16:38:30] - |D| - [36850857] - C:\Program Files\Reference Assemblies [06/07/2017 11:00:33] - |D| - [189894213] - C:\Program Files\SteelSeries [26/07/2012 09:22:18] - |HD| - [0] - C:\Program Files\Uninstall Information [22/08/2013 17:36:31] - |D| - [14361858] - C:\Program Files\Windows Defender [22/08/2013 17:36:31] - |D| - [6376448] - C:\Program Files\Windows Mail [22/08/2013 17:36:31] - |D| - [5386302] - C:\Program Files\Windows Media Player [22/08/2013 17:36:31] - |D| - [286208] - C:\Program Files\Windows Multimedia Platform [22/08/2013 17:36:31] - |D| - [7943738] - C:\Program Files\Windows NT [22/08/2013 17:36:31] - |D| - [6433424] - C:\Program Files\Windows Photo Viewer [22/08/2013 17:36:31] - |D| - [286208] - C:\Program Files\Windows Portable Devices [22/08/2013 17:36:31] - |SHD| - [0] - C:\Program Files\Windows Sidebar [22/08/2013 17:36:31] - |HD| - [775800818] - C:\Program Files\WindowsApps [22/08/2013 17:36:31] - |D| - [0] - C:\Program Files\WindowsPowerShell [28/12/2014 17:03:21] - |D| - [6300355] - C:\Program Files\WinRAR ---------- | C:\Program Files (x86)\Common Files [05/12/2015 12:29:14] - |D| - [666842994] - C:\Program Files (x86)\Common Files\Adobe [20/06/2015 20:31:24] - |D| - [28758980] - C:\Program Files (x86)\Common Files\Adobe AIR [27/03/2017 19:09:23] - |D| - [1793] - C:\Program Files (x86)\Common Files\AV [01/10/2016 11:19:04] - |D| - [7547288] - C:\Program Files (x86)\Common Files\BattlEye [21/10/2016 13:54:27] - |D| - [392688] - C:\Program Files (x86)\Common Files\BioWare [25/12/2015 01:07:53] - |HD| - [2828284] - C:\Program Files (x86)\Common Files\EAInstaller [23/01/2015 17:35:17] - |D| - [9370390] - C:\Program Files (x86)\Common Files\InstallShield [05/08/2015 10:00:58] - |D| - [17698048] - C:\Program Files (x86)\Common Files\Intel [07/05/2017 10:51:35] - |D| - [1942088] - C:\Program Files (x86)\Common Files\Java [22/08/2013 17:36:30] - |D| - [52010359] - C:\Program Files (x86)\Common Files\Microsoft Shared [22/08/2013 17:36:30] - |D| - [2702] - C:\Program Files (x86)\Common Files\Services [12/09/2017 11:01:47] - |D| - [2574296] - C:\Program Files (x86)\Common Files\Skype [25/12/2014 14:53:40] - |D| - [5492064] - C:\Program Files (x86)\Common Files\Steam [28/01/2015 16:59:43] - |D| - [0] - C:\Program Files (x86)\Common Files\SWF Studio [22/08/2013 17:36:30] - |D| - [9749899] - C:\Program Files (x86)\Common Files\System [31/01/2015 23:26:41] - |D| - [34176512] - C:\Program Files (x86)\Common Files\Wise Installation Wizard ---------- | C:\Program Files\Common files [11/09/2017 20:42:47] - |DC| - [108737748] - C:\Program Files\Common files\Adobe [27/03/2017 19:09:23] - |D| - [1793] - C:\Program Files\Common files\AV [22/08/2013 17:36:31] - |D| - [81282362] - C:\Program Files\Common files\microsoft shared [22/08/2013 17:36:31] - |D| - [2702] - C:\Program Files\Common files\Services [22/08/2013 17:36:31] - |D| - [10731403] - C:\Program Files\Common files\System ---------- | Tasks [MD5.F1A6CD5ADAAB953A6764EA364E17BFB8] - [22/08/2013 16:45:54] - |AH| - [6] - C:\WINDOWS\Tasks\SA.DAT [MD5.6EC21A571B528FDEDF5F32AF769D065B] - [13/05/2016 21:30:03] - |A| - [300] - C:\WINDOWS\Tasks\Uninstaller_SkipUac_Thomas.job [MD5.A63C049ABC145EE3D0FF4AE19B853BC6] - [16/06/2016 22:06:17] - |A| - [410] - C:\WINDOWS\Tasks\update-S-1-5-21-1200667838-2990588833-2439126145-1001.job [MD5.6DCB73A1AB4FF8F69B6FAF8068D831B3] - [16/06/2016 22:06:16] - |A| - [410] - C:\WINDOWS\Tasks\update-sys.job [MD5.E974F4F2F53304C64974C77C4868C820] - [22/06/2016 10:19:19] - |A| - [4462] - C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater : C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [MD5.A8E98CF5CA80566FD7FEF3D7243CD49D] - [11/09/2017 20:54:50] - |A| - [3508] - C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-tom_62210@hotmail.fr : C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [MD5.3810C373C590705F75FF9B934A0A3896] - [27/03/2017 19:09:20] - |A| - [3914] - C:\WINDOWS\System32\Tasks\Avast Emergency Update : D:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [MD5.00000000000000000000000000000000] - [03/12/2015 19:52:46] - |D| - [7108] - C:\WINDOWS\System32\Tasks\AVAST Software [MD5.60ADA7E961528A28D636EA6876E9CEB5] - [30/05/2015 21:51:40] - |A| - [2796] - C:\WINDOWS\System32\Tasks\CCleanerSkipUAC : "C:\Program Files\CCleaner\CCleaner.exe" [MD5.82A3DFDE8633971468F6309E1C503B59] - [16/10/2015 18:34:08] - |A| - [3374] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.E57161235E5DA512E9F12EA03DACE8AF] - [16/10/2015 18:34:09] - |A| - [3502] - C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.A7CCD77F38AB8FBD560E3B5FA426B9CF] - [20/06/2017 19:04:39] - |A| - [3290] - C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachine : "C:\Program Files (x86)\Gyazo\GyazoUpdate.exe" [MD5.023D3B83543C0953ACF0176AEA64416B] - [20/06/2017 19:04:39] - |A| - [3416] - C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachineDaily : "C:\Program Files (x86)\Gyazo\GyazoUpdate.exe" [MD5.00000000000000000000000000000000] - [22/08/2013 17:36:30] - |D| - [424340] - C:\WINDOWS\System32\Tasks\Microsoft [MD5.09BEF374DBCE47ECF8CA0575891207CF] - [14/04/2017 18:44:58] - |A| - [4148] - C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [MD5.C8AF6111EFEC0ADECDBD807F1C82CB1E] - [27/07/2017 18:38:40] - |A| - [3816] - C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe" [MD5.F442745959CC46308439F253C223ADF5] - [08/03/2017 20:30:13] - |A| - [3854] - C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [MD5.3046684F202E7D598E9C7269277D4377] - [08/03/2017 20:29:42] - |A| - [3740] - C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [MD5.91018BC97436AE2DB1E864037F370BFC] - [08/03/2017 20:29:42] - |A| - [3496] - C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [MD5.20A17C1F913F69CCDF8D85D32C123191] - [08/03/2017 20:29:42] - |A| - [3732] - C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [MD5.C61B9095A9B4359FDFD9166671E56D0A] - [08/03/2017 20:29:43] - |A| - [3556] - C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [MD5.77509C6C7A3A6ADAA96E2DEC4CE4147F] - [08/03/2017 20:29:43] - |A| - [3740] - C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} : C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [MD5.A2DB9D83315CB9BFAB7271628CD5ADC1] - [30/05/2015 23:22:06] - |A| - [3600] - C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1200667838-2990588833-2439126145-1001 : C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [MD5.449ABE5BDEA8622CC5576BC819CBCB4E] - [27/03/2017 19:11:23] - |A| - [3922] - C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1490634679 : D:\Program Files\AVAST Software\SZBrowser\launcher.exe [MD5.8713A784DCD72C0FC1474DE1282474B8] - [13/05/2016 21:30:05] - |A| - [2404] - C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_Thomas : C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [MD5.00000000000000000000000000000000] - [17/01/2016 20:28:23] - |D| - [0] - C:\WINDOWS\System32\Tasks\Update [MD5.3E6A11659EC94773A3F8B257F4C4FB8F] - [16/06/2016 22:06:17] - |A| - [3262] - C:\WINDOWS\System32\Tasks\update-S-1-5-21-1200667838-2990588833-2439126145-1001 : C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [MD5.B3155225636BE29452730F176AF6C5C7] - [16/06/2016 22:06:16] - |A| - [3282] - C:\WINDOWS\System32\Tasks\update-sys : C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [MD5.BA8141228B8D81E70A2F08120EE9FE56] - [10/04/2015 19:40:17] - |A| - [3946] - C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{59FD181C-8EAA-41A7-84E8-0B36D93CBB0D} : C:\WINDOWS\system32\msfeedssync.exe [MD5.00000000000000000000000000000000] - [05/04/2015 20:39:14] - |D| - [4482] - C:\WINDOWS\System32\Tasks\WPD [MD5.31437F1E878B36C19B667B5D5FCC7428] - [16/06/2016 20:55:43] - |A| - [3090] - C:\WINDOWS\System32\Tasks\{28866037-A235-4610-8926-98A8DFAB7A61} : "d:\program files (x86)\mozilla firefox\firefox.exe" [MD5.00000000000000000000000000000000] - [22/08/2013 17:36:31] - |D| - [0] - C:\WINDOWS\Syswow64\Tasks\Microsoft ---------- | Firewall [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules] "Netlogon-NamedPipe-In"=v2.22|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=445|App=System|Name=@netlogon.dll,-1003|Desc=@netlogon.dll,-1006|EmbedCtxt=@netlogon.dll,-1010| "Netlogon-TCP-RPC-In"=v2.22|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=RPC|App=%SystemRoot%\System32\lsass.exe|Name=@netlogon.dll,-1008|Desc=@netlogon.dll,-1009|EmbedCtxt=@netlogon.dll,-1010| "WirelessDisplay-In-TCP"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10200|Desc=@wifidisplay.dll,-10201|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-TCP"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10202|Desc=@wifidisplay.dll,-10203|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "WirelessDisplay-Out-UDP"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|Profile=Private|Profile=Public|App=%systemroot%\system32\WUDFHost.exe|Name=@wifidisplay.dll,-10204|Desc=@wifidisplay.dll,-10205|LUAuth=O:LSD:(A;;CC;;;S-1-5-84-0-0-0-0-0)|EmbedCtxt=@wifidisplay.dll,-100|TTK2_22=WFDDisplay| "{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=SonicWALL.MobileConnect|Desc=SonicWALL.MobileConnect|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-1141404472-3582312691-3771565717-2155153689-4284170330-1053580937-782359393|EmbedCtxt=SonicWALL.MobileConnect|Platform=2:6:2|Platform2=GTEQ| "{560448D6-095C-4907-B046-AC7F710701A7}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=SonicWALL.MobileConnect|Desc=SonicWALL.MobileConnect|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-1141404472-3582312691-3771565717-2155153689-4284170330-1053580937-782359393|EmbedCtxt=SonicWALL.MobileConnect|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{D6980480-941A-4DF6-AB81-3734ECD3D779}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=JuniperNetworks.JunosPulseVpn|Desc=JuniperNetworks.JunosPulseVpn|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-413786399-3497379642-531169432-1175633435-3083429259-2317590812-1892764672|EmbedCtxt=JuniperNetworks.JunosPulseVpn|Platform=2:6:2|Platform2=GTEQ| "{EC799E33-72BA-42D7-9127-DEFE68F9799D}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=JuniperNetworks.JunosPulseVpn|Desc=JuniperNetworks.JunosPulseVpn|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-413786399-3497379642-531169432-1175633435-3083429259-2317590812-1892764672|EmbedCtxt=JuniperNetworks.JunosPulseVpn|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{F64300AD-D559-4000-BD45-0997BCC8E70A}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=f5.vpn.client|Desc=f5.vpn.client|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-3873129616-3864902477-3117653462-838095904-2337665935-1018217662-2152729480|EmbedCtxt=f5.vpn.client|Platform=2:6:2|Platform2=GTEQ| "{F77E5446-4378-4E99-8B7A-7061AAAEA193}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=f5.vpn.client|Desc=f5.vpn.client|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-3873129616-3864902477-3117653462-838095904-2337665935-1018217662-2152729480|EmbedCtxt=f5.vpn.client|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{9E3D57FC-7C37-4424-9352-4831E97D029D}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Desc=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/Description}|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-2608634532-1453884237-1118350049-1925931850-670756941-1603938316-3764965493|EmbedCtxt=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Desc=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/Description}|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-2608634532-1453884237-1118350049-1925931850-670756941-1603938316-3764965493|EmbedCtxt=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=CheckPoint.VPN|Desc=CheckPoint.VPN|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-3676279713-3632409675-756843784-3388909659-2454753834-4233625902-1413163418|EmbedCtxt=CheckPoint.VPN|Platform=2:6:2|Platform2=GTEQ| "{4282FE99-8560-4BC7-9576-5F3ED84E263F}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=CheckPoint.VPN|Desc=CheckPoint.VPN|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-3676279713-3632409675-756843784-3388909659-2454753834-4233625902-1413163418|EmbedCtxt=CheckPoint.VPN|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{A35872E0-7D3D-4C59-8211-067A252F7C67}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=windows_ie_ac_001|Desc=Created by IE|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-500|AppPkgId=S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394|EmbedCtxt=windows_ie_ac_001|Platform=2:6:2|Platform2=GTEQ| "{C5C0BDB1-3776-452C-BEF4-4BDB835EDC78}"=v2.20|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Program Files (x86)\qBittorrent\qbittorrent.exe|Name=qBittorrent| "{26C4F225-004C-4BD1-93D4-F0814CFC2367}"=v2.20|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Program Files (x86)\qBittorrent\qbittorrent.exe|Name=qBittorrent| "UDP Query User{B97F1E6F-97BF-43B2-81C8-DF5F3978A9A6}C:\program files\java\jre1.8.0_31\bin\javaw.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files\java\jre1.8.0_31\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary|Defer=User| "TCP Query User{A1FFD709-40B6-4C58-8CE1-3F0577D232E9}C:\program files\java\jre1.8.0_31\bin\javaw.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files\java\jre1.8.0_31\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary|Defer=User| "{84A3E3F2-FE97-44F6-82F6-2A90767D41E6}"=v2.20|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Users\Thomas\AppData\Local\Temp\Rar$EXa0.547\Madeon_In_The_City_Download_downloader.exe|Name=SmileFiles| "{E5C1D94E-A6D2-499E-BFA0-5EB457308604}"=v2.20|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Users\Thomas\AppData\Local\Temp\Rar$EXa0.547\Madeon_In_The_City_Download_downloader.exe|Name=SmileFiles| "UDP Query User{EB4A204B-9ECB-4876-8589-20D8D622D763}C:\program files\java\jre1.8.0_31\bin\javaw.exe"=v2.10|Action=Block|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\program files\java\jre1.8.0_31\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary| "TCP Query User{AA098068-EDF7-45D2-8774-09241591BEA9}C:\program files\java\jre1.8.0_31\bin\javaw.exe"=v2.10|Action=Block|Active=FALSE|Dir=In|Protocol=6|Profile=Private|App=C:\program files\java\jre1.8.0_31\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary| "UDP Query User{C7FB67BB-0EE2-483E-9EDC-9C8D2822D7CF}D:\program files (x86)\lucasarts\star wars galactic battlegrounds\game\battlegrounds_x1.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\program files (x86)\lucasarts\star wars galactic battlegrounds\game\battlegrounds_x1.exe|Name=Star Wars Galactic Battlegrounds: Clone Campaigns|Desc=Star Wars Galactic Battlegrounds: Clone Campaigns|Defer=User| "TCP Query User{FE275E74-B448-4819-AD25-3C3019140577}D:\program files (x86)\lucasarts\star wars galactic battlegrounds\game\battlegrounds_x1.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\program files (x86)\lucasarts\star wars galactic battlegrounds\game\battlegrounds_x1.exe|Name=Star Wars Galactic Battlegrounds: Clone Campaigns|Desc=Star Wars Galactic Battlegrounds: Clone Campaigns|Defer=User| "UDP Query User{85CE868A-6A72-40D1-A30C-1AED5CCC4B3F}D:\program files (x86)\goat simulator\binaries\win32\goatgame-win32-shipping.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\program files (x86)\goat simulator\binaries\win32\goatgame-win32-shipping.exe|Name=goatgame-win32-shipping|Desc=goatgame-win32-shipping|Defer=User| "TCP Query User{65A78F92-E60E-458C-A9B9-698420077C26}D:\program files (x86)\goat simulator\binaries\win32\goatgame-win32-shipping.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\program files (x86)\goat simulator\binaries\win32\goatgame-win32-shipping.exe|Name=goatgame-win32-shipping|Desc=goatgame-win32-shipping|Defer=User| "{F3E06691-8B5C-43DB-8AD7-F44C4A144232}"=v2.20|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Program Files (x86)\Microsoft Games\Age of Empires III\age3.exe|Name=Age of Empires 3| "{2A33F8FB-CDCB-44F9-B2E7-BA9699860B14}"=v2.20|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Program Files (x86)\Microsoft Games\Age of Empires III\age3.exe|Name=Age of Empires 3| "UDP Query User{EF000E47-8D4B-4661-8476-3C4030B333AF}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary|Defer=User| "TCP Query User{DADA378A-AB57-4FA8-8A19-DF02A56C3B52}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary|Defer=User| "UDP Query User{C74C4D48-8A32-4EEF-9834-FEF1BA8F7BD0}D:\program files (x86)\ea games\need for speed most wanted\nfs13.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\program files (x86)\ea games\need for speed most wanted\nfs13.exe|Name=Need for Speed™ Most Wanted|Desc=Need for Speed™ Most Wanted|Defer=User| "TCP Query User{161F5655-A316-4912-87D2-9D9E541C5CF8}D:\program files (x86)\ea games\need for speed most wanted\nfs13.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\program files (x86)\ea games\need for speed most wanted\nfs13.exe|Name=Need for Speed™ Most Wanted|Desc=Need for Speed™ Most Wanted|Defer=User| "UDP Query User{8B8BE4E1-CEA3-42DC-A091-F51588DA2B03}C:\users\thomas\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\users\thomas\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe|Name=javaw|Desc=javaw| "TCP Query User{27D651D0-3ABF-4240-A48B-C3D98D5F4404}C:\users\thomas\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Private|App=C:\users\thomas\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe|Name=javaw|Desc=javaw| "UDP Query User{5B45F4B8-F96D-4B82-9E25-B140EB70C033}D:\maniaplanet\maniaplanet.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\maniaplanet\maniaplanet.exe|Name=ManiaPlanet|Desc=ManiaPlanet|Defer=User| "TCP Query User{840599C0-FAAA-45FB-8DEC-437BC387AF87}D:\maniaplanet\maniaplanet.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\maniaplanet\maniaplanet.exe|Name=ManiaPlanet|Desc=ManiaPlanet|Defer=User| "{4218F287-4DA6-4E1A-BFDE-ED037FF1FE0C}"=v2.20|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\Autorun\Exe\Autorun.exe|Name=Pro Cycling Manager - Saison 2014 - Autorun| "{7B0D18B7-3293-4C19-8F0F-1E50DB98DF85}"=v2.20|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\Autorun\Exe\Autorun.exe|Name=Pro Cycling Manager - Saison 2014 - Autorun| "{6485FA08-FE1B-4A30-B1A0-B499DD43334A}"=v2.20|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\PCM.exe|Name=Pro Cycling Manager - Saison 2014| "{BAC8BC45-9700-4446-B8F7-558C938683D5}"=v2.20|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Program Files (x86)\Cyanide\Pro Cycling Manager - Saison 2014\PCM.exe|Name=Pro Cycling Manager - Saison 2014| "UDP Query User{36DF25CA-CC2C-40D3-B758-699D355006BF}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary| "TCP Query User{AB741DDC-8E66-40F6-A86E-2629EADDEF04}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary| "UDP Query User{612E3072-75C7-4B8F-A799-7FEB9124A965}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe"=v2.10|Action=Block|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary| "TCP Query User{3094CC3B-8CEF-4EE9-B17C-532D42CDBFE2}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe"=v2.10|Action=Block|Active=FALSE|Dir=In|Protocol=6|Profile=Private|App=C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary| "UDP Query User{0AB79252-6473-4A1D-BBF0-8AA7B1E33775}D:\program files (x86)\maniaplanet\maniaplanet.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\program files (x86)\maniaplanet\maniaplanet.exe|Name=ManiaPlanet|Desc=ManiaPlanet|Defer=User| "TCP Query User{490E002C-5FC9-4D07-BAEF-12F4AA6E95D3}D:\program files (x86)\maniaplanet\maniaplanet.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\program files (x86)\maniaplanet\maniaplanet.exe|Name=ManiaPlanet|Desc=ManiaPlanet|Defer=User| "UDP Query User{15A16AA8-D97D-4E2D-81E0-4FE201D4F1BD}D:\program files (x86)\maniaplanet\maniaplanet.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\program files (x86)\maniaplanet\maniaplanet.exe|Name=ManiaPlanet|Desc=ManiaPlanet|Defer=User| "TCP Query User{8BFC97C5-53F4-4A82-B07C-764DF7A3555B}D:\program files (x86)\maniaplanet\maniaplanet.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\program files (x86)\maniaplanet\maniaplanet.exe|Name=ManiaPlanet|Desc=ManiaPlanet|Defer=User| "UDP Query User{52693C37-D517-47F8-B2F7-4D561ACE5257}D:\program files (x86)\tmunitedforever\tmforever.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\program files (x86)\tmunitedforever\tmforever.exe|Name=tmforever|Desc=tmforever| "TCP Query User{65053642-489A-4F48-BE6C-084171673CFE}D:\program files (x86)\tmunitedforever\tmforever.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\program files (x86)\tmunitedforever\tmforever.exe|Name=tmforever|Desc=tmforever| "UDP Query User{A4D8D26D-4551-4390-A3C2-7AB20CFF8527}D:\program files (x86)\tmunitedforever\tmforever.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\program files (x86)\tmunitedforever\tmforever.exe|Name=tmforever|Desc=tmforever|Defer=User| "TCP Query User{0A1DCD3A-190F-41D7-ACD3-532D89BCCF86}D:\program files (x86)\tmunitedforever\tmforever.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\program files (x86)\tmunitedforever\tmforever.exe|Name=tmforever|Desc=tmforever|Defer=User| "UDP Query User{294EEFB2-758E-428E-BB93-542FE91C6ACF}C:\program files (x86)\tmunitedforever\tmforever.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|Profile=Public|App=C:\program files (x86)\tmunitedforever\tmforever.exe|Name=tmforever|Desc=tmforever|Defer=User| "TCP Query User{D01ABC0B-8666-4037-A311-44D55F253246}C:\program files (x86)\tmunitedforever\tmforever.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=C:\program files (x86)\tmunitedforever\tmforever.exe|Name=tmforever|Desc=tmforever|Defer=User| "{E7985E1D-C36F-4787-80A8-6350D07E9266}"=v2.20|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Name=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Desc=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/Description}|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-2608634532-1453884237-1118350049-1925931850-670756941-1603938316-3764965493|EmbedCtxt=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{808F1451-4108-46FD-ADBB-F17324B5F0BD}"=v2.20|Action=Allow|Active=TRUE|Dir=Out|Name=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Desc=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/Description}|LUOwn=S-1-1-0|AppPkgId=S-1-15-2-2608634532-1453884237-1118350049-1925931850-670756941-1603938316-3764965493|EmbedCtxt=@{C:\Windows\WinStore\resources.pri?ms-resource://WinStore/resources/DisplayName}|Platform=2:6:2|Platform2=GTEQ| "{F2B2370E-5071-4361-B2FD-3BC0C37AE6ED}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=windows_ie_ac_001|Desc=Created by IE|LUOwn=S-1-5-18|AppPkgId=S-1-15-2-1430448594-2639229838-973813799-439329657-1197984847-4069167804-1277922394|EmbedCtxt=windows_ie_ac_001|Platform=2:6:2|Platform2=GTEQ| "{4249D5FB-1979-41A1-998C-F8B180BAE665}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Check Point VPN|Desc=Check Point VPN|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-3676279713-3632409675-756843784-3388909659-2454753834-4233625902-1413163418|EmbedCtxt=Check Point VPN|Platform=2:6:2|Platform2=GTEQ| "{39DB202F-73FD-4A45-A0D7-0C9F4784198B}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Check Point VPN|Desc=Check Point VPN|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-3676279713-3632409675-756843784-3388909659-2454753834-4233625902-1413163418|EmbedCtxt=Check Point VPN|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{483782A6-B136-4872-8831-841569A476F1}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=F5 VPN|Desc=F5 VPN|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-3873129616-3864902477-3117653462-838095904-2337665935-1018217662-2152729480|EmbedCtxt=F5 VPN|Platform=2:6:2|Platform2=GTEQ| "{4810556F-EEBE-48B4-BB5A-41A540F41E83}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=F5 VPN|Desc=F5 VPN|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-3873129616-3864902477-3117653462-838095904-2337665935-1018217662-2152729480|EmbedCtxt=F5 VPN|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{CFC12AF4-1958-4C28-B737-B552CB9E28AD}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Juniper Networks Junos Pulse|Desc=Juniper Networks Junos Pulse|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-413786399-3497379642-531169432-1175633435-3083429259-2317590812-1892764672|EmbedCtxt=Juniper Networks Junos Pulse|Platform=2:6:2|Platform2=GTEQ| "{6C54FFBF-D1CA-4A39-BAEB-5CA7DCCD3F6D}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Juniper Networks Junos Pulse|Desc=Juniper Networks Junos Pulse|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-413786399-3497379642-531169432-1175633435-3083429259-2317590812-1892764672|EmbedCtxt=Juniper Networks Junos Pulse|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{A3A6F2C1-72FB-4ABB-8127-186245FA7CBE}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=SonicWALL Mobile Connect|Desc=SonicWALL Mobile Connect|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-1141404472-3582312691-3771565717-2155153689-4284170330-1053580937-782359393|EmbedCtxt=SonicWALL Mobile Connect|Platform=2:6:2|Platform2=GTEQ| "{19935821-3B1E-448E-889C-CBB3E2A8EEB3}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=SonicWALL Mobile Connect|Desc=SonicWALL Mobile Connect|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-1141404472-3582312691-3771565717-2155153689-4284170330-1053580937-782359393|EmbedCtxt=SonicWALL Mobile Connect|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{23AC89DE-944B-447E-A4CF-C1285A5F92F0}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\Thomas\AppData\Roaming\uTorrent\uTorrent.exe|Name=µTorrent (TCP-In)|Desc=Allow µTorrent network traffic with Edge Traversal|Edge=TRUE| "{77EE5801-B989-40D9-BAC3-F42C093A014A}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\Thomas\AppData\Roaming\uTorrent\uTorrent.exe|Name=µTorrent (UDP-In)|Desc=Allow µTorrent network traffic with Edge Traversal|Edge=TRUE| "{F35B860F-DFF3-4192-8CD4-54A8093CEBAC}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe|Name=Ubisoft Game Launcher| "{0F562D9E-9D3A-419B-B625-13489C32530A}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe|Name=Ubisoft Game Launcher| "{2BEABC52-9BF7-4A2F-A6FA-97CC90D171DF}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Program Files (x86)\Just Cause 2\JustCause2.exe|Name=Just Cause 2| "{DC77BE9A-2517-4361-8745-4B7BC38FD575}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Program Files (x86)\Just Cause 2\JustCause2.exe|Name=Just Cause 2| "{B35ED9EF-6555-4F27-B3D0-6073378E789A}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Google Search|Desc=Google Search|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-952914762-3925684122-2884453516-746264338-106963559-873903280-1628321774|EmbedCtxt=Google Search|Platform=2:6:2|Platform2=GTEQ| "{D9A8A749-E20C-446A-90B5-DDE64D3F21FC}"=v2.22|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\LINE\LINE.exe|Name=LineApp| "{FDBC6380-66D0-470C-A5B2-B11821B872C0}"=v2.22|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\LINE\LINE.exe|Name=LineApp| "{59460E51-C5CF-43E2-B8DA-C0B4A1D9492A}"=v2.22|Action=Allow|Active=TRUE|Dir=In|App=D:\Program Files (x86)\GlassWire\GWCtlSrv.exe|Svc=GlassWire|Name=GlassWire Service|Desc=|EmbedCtxt=| "{8CA8EA81-5253-4573-A624-4149765BEEC4}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|App=D:\Program Files (x86)\GlassWire\GWCtlSrv.exe|Svc=GlassWire|Name=GlassWire Service|Desc=|EmbedCtxt=| "{6317CA2C-56EC-441A-8BF2-339F91662DDE}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\Cities Skyline\Cities Skyline\Cities.exe|Name=Cities.exe| "{3226B2F8-E6EE-43CD-90B0-73C18EDADE9B}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\Cities Skyline\Cities Skyline\Cities.exe|Name=Cities.exe| "{487D1BAF-36CA-464D-98AB-B1E75EB3ADB6}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\Program Files (x86)\SimCity\SimCity\SimCity.exe|Name=SimCity| "{F48765D8-6806-4A83-B2F3-0231995BAD07}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\Program Files (x86)\SimCity\SimCity\SimCity.exe|Name=SimCity| "{9A3A030F-256D-45A4-9AA9-F96EA4AC9013}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe|Name=avast! NG front end| "{97E31980-5108-470D-87D4-81D15C47D260}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe|Name=avast! NG front end| "{91EA1A8C-9F4E-4395-B3A8-5B8D9079B454}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2010\pes2010.exe|Name=Pro Evolution Soccer 2010| "{04F4721C-1FAA-4D3E-8758-71C42B3D965E}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2010\pes2010.exe|Name=Pro Evolution Soccer 2010| "{3E58AEFD-9DCB-4CB3-83C0-C33F1015E8AC}"=v2.22|Action=Block|Active=TRUE|Dir=In|App=c:\windows\system32\dashost.exe|Name=@{Glasswire.application_15304421843262773972}|Desc=GlassWire|EmbedCtxt=GlassWire| "{5E20CAE5-1072-42CF-8974-DD938F10B748}"=v2.22|Action=Block|Active=TRUE|Dir=Out|App=c:\windows\system32\dashost.exe|Name=@{Glasswire.application_15304421843262773972}|Desc=GlassWire|EmbedCtxt=GlassWire| "{6BD480C1-487B-44B1-8C74-72CBD963572A}"=v2.22|Action=Block|Active=TRUE|Dir=In|App=c:\windows\winstore\wshost.exe|Name=@{Glasswire.application_4518689245302436877}|Desc=GlassWire|EmbedCtxt=GlassWire| "{2C372546-9B1A-491A-AF8C-D3F2C077C578}"=v2.22|Action=Block|Active=TRUE|Dir=Out|App=c:\windows\winstore\wshost.exe|Name=@{Glasswire.application_4518689245302436877}|Desc=GlassWire|EmbedCtxt=GlassWire| "{962A3FDC-3AF3-4443-8367-61FE37C54627}"=v2.22|Action=Block|Active=TRUE|Dir=In|App=c:\program files (x86)\skillbrains\updater\1.7.2.5\updater.exe|Name=@{Glasswire.application_10201233518736522724}|Desc=GlassWire|EmbedCtxt=GlassWire| "{99542CAE-A4F1-464B-B8A6-551DA9BF7137}"=v2.22|Action=Block|Active=TRUE|Dir=Out|App=c:\program files (x86)\skillbrains\updater\1.7.2.5\updater.exe|Name=@{Glasswire.application_10201233518736522724}|Desc=GlassWire|EmbedCtxt=GlassWire| "{548D34D0-1C48-4B6D-A8C9-CD31CF9D5724}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort2_10=6881-6889|App=D:\Program Files (x86)\GameforgeLive\gfl_client.exe|Name=Gameforge Live (P2P Inbound)|EmbedCtxt=Gameforge Live|Edge=TRUE|Defer=App| "{EF57096D-9CBE-4EAD-8437-6029BA26A18A}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Program Files (x86)\GameforgeLive\Games\FRA_fra\S.K.I.L.L\Binaries\Win32\sf2.exe|Name=Special Force 2| "{B385A418-7699-4B3B-8140-4B999A71319A}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Program Files (x86)\GameforgeLive\Games\FRA_fra\S.K.I.L.L\Binaries\Win32\sf2.exe|Name=Special Force 2| "{2F210EF7-9525-4C9A-A001-0B305AA85BA4}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe|Name=STAR WARS™ Battlefront™ (x64)| "{F07C1388-FA93-4414-A119-6F483795360B}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe|Name=STAR WARS™ Battlefront™ (x64)| "{C5199598-D23D-4501-81C3-E530766AEE6B}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\Blacklist_Launcher.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ Launcher| "{FD9FD224-3253-456B-AC3B-0EAD6660952C}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\Blacklist_Launcher.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ Launcher| "{249552E1-9EAD-4E6C-8E40-616F9954C7D1}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_game.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ DX9| "{617AC41E-44DA-4AAB-BB83-2958B3857F22}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_game.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ DX9| "{7ED040FF-829E-41DD-A648-FD957026F347}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_DX11_game.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ DX11| "{66665ADE-ACC3-4661-8A5D-81AEAD0AA521}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_DX11_game.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ DX11| "{1FAAFAB2-6913-4179-81C5-B8708709AFBE}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\gu.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ GameUpdate| "{5E02F528-C8D1-4C24-8498-7BE61299A87B}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\gu.exe|Name=Tom Clancy's Splinter Cell® Blacklist™ GameUpdate| "{3072EB04-63CC-4029-973C-48B23B807CDC}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Windows\SysWOW64\PnkBstrA.exe|Name=PnkBstrA| "{157E28B2-BC2F-4A7A-82A7-59C240682BE6}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Windows\SysWOW64\PnkBstrA.exe|Name=PnkBstrA| "{E07DB8AE-74C1-400F-8AF1-18A902AE0513}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Windows\SysWOW64\PnkBstrB.exe|Name=PnkBstrB| "{767A25BE-FF17-4A79-B016-6EE1CB169597}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Windows\SysWOW64\PnkBstrB.exe|Name=PnkBstrB| "{96927247-B4B7-47F8-B5E2-3613E097E670}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ| "{7B18FF63-76BB-403F-8096-61B2CDBD7717}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=OneNote|Desc=OneNote|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-3445883232-1224167743-206467785-1580939083-2750001491-3097792036-3019341970|EmbedCtxt=OneNote|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{96912910-7F2F-4F36-9581-93F12D113426}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=HP All-in-One Printer Remote|Desc=HP All-in-One Printer Remote|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-744533573-2444454674-265863901-3215465728-4115286053-1341080355-789689510|EmbedCtxt=HP All-in-One Printer Remote|Platform=2:6:2|Platform2=GTEQ| "{6406A4D3-4388-4205-A85E-169981D7185E}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=HP All-in-One Printer Remote|Desc=HP All-in-One Printer Remote|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-744533573-2444454674-265863901-3215465728-4115286053-1341080355-789689510|EmbedCtxt=HP All-in-One Printer Remote|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| "{09A28855-D9F8-41D7-B1F4-78D092140521}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe|Name=STAR WARS™ Battlefront™ (x64)| "{995BC751-CDE1-42C3-B37A-704226D7EE6E}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\Program Files (x86)\Origin Games\STAR WARS Battlefront\starwarsbattlefront.exe|Name=STAR WARS™ Battlefront™ (x64)| "{47E2549E-87AE-42A5-82AB-2B571AE20312}"=v2.22|Action=Allow|Active=TRUE|Dir=In|App=D:\Program Files (x86)\Droid4X\Droid4X\Droid4X.exe|Name=Droid4X.exe|Desc=| "{AD250C1F-B525-4586-BB75-9F5CE72A3955}"=v2.22|Action=Allow|Active=TRUE|Dir=In|App=D:\Program Files (x86)\Droid4X\Droid4X\download\MiniThunderPlatform.exe|Name=MiniThunderPlatform.exe|Desc=| "{89475DBD-8BA2-453D-B771-00E563C8490F}"=v2.22|Action=Allow|Active=TRUE|Dir=In|App=D:\Program Files (x86)\Droid4X\Droid4X\download\MiniThunderPlatform.exe|Name=MultiMgr.exe|Desc=| "{BF0F7C0A-C7E6-4E02-9A9A-FA21A700990B}"=v2.22|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files\Oracle\VirtualBox\vboxheadless.exe|Name=vboxheadless.exe|Desc=| "{C0D24F11-B15F-463B-B479-CC928355601D}"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files\java\jre1.8.0_31\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary| "{3B746E0C-BF85-4DD7-B009-6ADA63DA85B0}"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files\java\jre1.8.0_31\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary| "{59F4EE8F-A8B2-4587-98E2-316C4DFCED2F}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary|Defer=User| "{BF139A52-35AF-43B4-9A2A-1110D56DD88C}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary|Defer=User| "{04615669-984A-43E9-843F-5096A93F49E7}"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary| "{55336886-77D0-4299-A1A8-F3FC6B1499F9}"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe|Name=Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary| "{4C8AEABE-6521-40EC-B5E8-727F784B3718}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\thomas\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe|Name=javaw|Desc=javaw| "{D7476141-7E6F-4A53-88B2-C78B81148DBF}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\thomas\desktop\runtime\jre-x64\1.8.0_25\bin\javaw.exe|Name=javaw|Desc=javaw| "{0E208986-BE23-418E-92BC-26105C7F94BB}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\Thomas\AppData\Local\Chromatic\Application\chromatic.exe|Name=Chromatic| "{BB8877B6-8B24-47BD-9668-54310A38BB86}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\Thomas\AppData\Local\Chromatic\Application\chromatic.exe|Name=Chromatic| "{9FD067F7-8843-42D9-97FB-D41949AF8AFE}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\Thomas\AppData\Local\Chromatic\Utils\Updater.exe|Name=ChromaticUpdater| "{3C10DF61-2869-461C-B659-1557C24CF50C}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\Thomas\AppData\Local\Chromatic\Utils\Updater.exe|Name=ChromaticUpdater| "{82E98F9E-E170-45F9-8747-8097A437625F}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\Thomas\AppData\Local\wd\wd.exe|Name=WatchDog| "{20E6D129-3093-45FD-9988-61919DC1ADD1}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\Thomas\AppData\Local\wd\wd.exe|Name=WatchDog| "{CB953536-4F6C-4A53-BAC3-4351FD92E685}"=v2.22|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\Thomas\AppData\Local\LINE\bin\4.7.0.1027\LINE.exe|Name=LineApp| "{7B9F006E-A2CE-4B61-A57E-D93381E1338E}"=v2.22|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\Thomas\AppData\Local\LINE\bin\4.7.0.1027\LINE.exe|Name=LineApp| "{49EA96D1-44D4-4850-8A6D-63075E3E266B}"=v2.22|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\Thomas\AppData\Local\LINE\bin\4.7.0.1027\LineUpdater.exe|Name=LineUpdater| "{06FADF22-5819-4B90-B332-1143C65A9461}"=v2.22|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\Thomas\AppData\Local\LINE\bin\4.7.0.1027\LineUpdater.exe|Name=LineUpdater| "{B505426D-9BD0-47C7-BE07-CC15DA135FCA}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=LINE|Desc=LINE|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-3154901008-2849271269-1294263849-4111868753-1430083361-3789501531-791294240|EmbedCtxt=LINE|Platform=2:6:2|Platform2=GTEQ| "{8FE0CCC7-45A7-46BA-B097-6997A8CFBE3E}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=D:\Program Files (x86)\Origin Games\Star Wars Battlefront\STAR WARS Battlefront\starwarsbattlefront.exe|Name=STAR WARS™ Battlefront™ (x64)| "{EC38AD87-F0CF-4FEF-BF37-0F19E950E346}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=D:\Program Files (x86)\Origin Games\Star Wars Battlefront\STAR WARS Battlefront\starwarsbattlefront.exe|Name=STAR WARS™ Battlefront™ (x64)| "{379E4190-FA53-4872-A7DD-040D3785E8FC}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=D:\Games\Grand Theft Auto V\GTA5.exe|Name=GTA V| "{ABF6526E-6FBC-49DC-9FDB-73D27F4718B3}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=D:\Games\Grand Theft Auto V\GTA5.exe|Name=GTA V| "{AE8BF422-CE0C-4A45-B9D5-3925791A383F}"=v2.22|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\BlueStacks\HD-Plus-Service.exe|Name=BlueStacks Service| "{F9367366-EBAB-4AE7-BA6A-C7996778D69A}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=D:\Program Files\AVAST Software\SZBrowser\4.58.2552.909\SZBrowser.exe|Name=Opera Internet Browser (mDNS-In)|Desc=Inbound rule to allow mDNS traffic.|EmbedCtxt=Opera Internet Browser| "{86B6D198-3977-41BB-826D-29E1FF1A6DE0}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=D:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe|Name=Opera Internet Browser (mDNS-In)|Desc=Inbound rule to allow mDNS traffic.|EmbedCtxt=Opera Internet Browser| "{208C5E8F-641B-4237-94A5-F0A44A8EADF9}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe|Name=Google Chrome (mDNS-In)|Desc=Règle de trafic entrant pour Google Chrome autorisant le trafic mDNS|EmbedCtxt=Google Chrome| "{98AD7422-D32A-4C04-9D02-DA8EE985250C}"=v2.22|Action=Allow|Active=TRUE|Dir=Out|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox One SmartGlass|Desc=Xbox One SmartGlass|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-2214089197-971179125-4124359169-283697964-1336710732-3555069067-437187921|EmbedCtxt=Xbox One SmartGlass|Platform=2:6:2|Platform2=GTEQ| "{5C3E2253-6815-4345-9CBD-ADB6E448586D}"=v2.22|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|Name=Xbox One SmartGlass|Desc=Xbox One SmartGlass|LUOwn=S-1-5-21-1200667838-2990588833-2439126145-1001|AppPkgId=S-1-15-2-2214089197-971179125-4124359169-283697964-1336710732-3555069067-437187921|EmbedCtxt=Xbox One SmartGlass|Platform=2:6:2|Platform2=GTEQ|Edge=TRUE| ---------- | Control\Class [HKLM\SYSTEM\CurrentControlSet\Control\Class\{03F52937-1FD6-44FB-82C6-FE988F1B1D61}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{04A83FC2-2AE2-4C88-B45F-E9707B377636}] : (aswHwid) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{091BC97E-2352-4362-A539-10A6D8FF7596}] : (RDPDR) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1264760F-A5C8-4BFE-B314-D56A7B44A362}] : (DXGKrnl) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{14b62f50-3f15-11dd-ae16-0800200c9a66}] : (DigitalMediaDevices) [] -> @digitalmediadevice.inf,%ClassName%;Digital Media Devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}] : (PrintQueue) [] -> @PrintQueue.inf,%ClassName%;Print queues [HKLM\SYSTEM\CurrentControlSet\Control\Class\{24A0C840-2C3D-4410-8236-8B40816C7B90}] : (aswVmm) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{25dbce51-6c8f-4a72-8a6d-b54c2b4fc835}] : (WCEUSBS) [] -> @%SystemRoot%\System32\SysClass.Dll,-3026 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{268c95a1-edfe-11d3-95c3-0010dc4050a5}] : (Security Accelerator) [] -> @c_sslaccel.inf,%SECURITYACCELERATORCLASSNAME%;Security Accelerator [HKLM\SYSTEM\CurrentControlSet\Control\Class\{2a9fe532-0cdc-44f9-9827-76192f2ca2fb}] : (HidMsr) [] -> @idtsec.inf,%ClassName%;POS HID Magnetic Stripe Reader [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B648}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3163C566-D381-4467-87BC-A65A18D5B649}] : (fvevol) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{36fc9e60-c465-11cf-8056-444553540000}] : (USB) [] -> @%SystemRoot%\System32\SysClass.Dll,-3025 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{39EB4865-658B-4410-AFA3-378D8517461C}] : (ngvss) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{3f966bd9-fa04-4ec5-991c-d326973b5128}] : (AndroidUsbDeviceClass) [] -> @oem13.inf,%ClassName%;Android Phone [HKLM\SYSTEM\CurrentControlSet\Control\Class\{43675d81-502a-4a82-9f84-b75f418c5dea}] : (Media Center Extender) [] -> @%SystemRoot%\system32\McxDriv.dll,-100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4658ee7e-f050-11d1-b6bd-00c04fa372a7}] : (PnpPrinters) [] -> @%systemroot%\system32\ntprint.dll,-1300 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48721b56-6795-11d2-b1a8-0080c72e74a2}] : (Dot4) [] -> @%SystemRoot%\system32\sysclass.dll,-3023 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{49ce6ac8-6f86-11d2-b1e5-0080c72e74a2}] : (Dot4Print) [] -> @%SystemRoot%\system32\sysclass.dll,-3024 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e965-e325-11ce-bfc1-08002be10318}] : (CDROM) [] -> @%SystemRoot%\System32\StorProp.dll,-17001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e966-e325-11ce-bfc1-08002be10318}] : (Computer) [] -> @%SystemRoot%\System32\SysClass.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318}] : (DiskDrive) [] -> @%SystemRoot%\System32\StorProp.dll,-17000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}] : (Display) [] -> @%SystemRoot%\System32\DispCI.dll,-3100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e969-e325-11ce-bfc1-08002be10318}] : (fdc) [] -> @%SystemRoot%\System32\SysClass.Dll,-3013 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96a-e325-11ce-bfc1-08002be10318}] : (hdc) [] -> @%SystemRoot%\System32\SysClass.Dll,-3001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96b-e325-11ce-bfc1-08002be10318}] : (Keyboard) [] -> @%SystemRoot%\System32\SysClass.Dll,-3002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96c-e325-11ce-bfc1-08002be10318}] : (MEDIA) [] -> @%SystemRoot%\System32\mmci.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}] : (Modem) [] -> @%SystemRoot%\System32\mdminst.dll,-14100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}] : (Monitor) [] -> @%SystemRoot%\System32\Montr_CI.dll,-3100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e96f-e325-11ce-bfc1-08002be10318}] : (Mouse) [] -> @%SystemRoot%\System32\SysClass.Dll,-3004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e970-e325-11ce-bfc1-08002be10318}] : (MTD) [] -> @%SystemRoot%\System32\SysClass.Dll,-3021 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e971-e325-11ce-bfc1-08002be10318}] : (MultiFunction) [] -> @%SystemRoot%\System32\SysClass.Dll,-3014 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}] : (Net) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1502 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e973-e325-11ce-bfc1-08002be10318}] : (NetClient) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1504 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e974-e325-11ce-bfc1-08002be10318}] : (NetService) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1505 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e975-e325-11ce-bfc1-08002be10318}] : (NetTrans) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1503 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e977-e325-11ce-bfc1-08002be10318}] : (PCMCIA) [] -> @%SystemRoot%\System32\SysClass.Dll,-3010 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e978-e325-11ce-bfc1-08002be10318}] : (Ports) [] -> @%SystemRoot%\System32\msports.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e979-e325-11ce-bfc1-08002be10318}] : (Printer) [] -> @%systemroot%\system32\ntprint.dll,-1004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}] : (SCSIAdapter) [] -> @%SystemRoot%\System32\SysClass.Dll,-3005 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97d-e325-11ce-bfc1-08002be10318}] : (System) [] -> @%SystemRoot%\System32\SysClass.Dll,-3008 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e97e-e325-11ce-bfc1-08002be10318}] : (Unknown) [] -> @%SystemRoot%\System32\SysClass.Dll,-3009 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e980-e325-11ce-bfc1-08002be10318}] : (FloppyDisk) [] -> @%SystemRoot%\System32\SysClass.Dll,-3015 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50127dc3-0f36-415e-a6cc-4cb3be910b65}] : (Processor) [] -> @%SystemRoot%\system32\procinst.dll,-100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50906cb8-ba12-11d1-bf5d-0000f805f530}] : (MultiPortSerial) [] -> @%SystemRoot%\system32\sysclass.dll,-3022 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5099944a-f6b9-4057-a056-8c550228544c}] : (Memory) [] -> @%SystemRoot%\System32\SysClass.Dll,-3018 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50dd5230-ba8a-11d1-bf5d-0000f805f530}] : (SmartCardReader) [] -> @%SystemRoot%\System32\StorProp.dll,-17002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5175d334-c371-4806-b3ba-71fd53c9258d}] : (Sensor) [] -> @%systemroot%\system32\SensorsCpl.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{522119B9-1B9A-498A-AC52-148B533EFD50}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{533c5b84-ec70-11d2-9505-00c04f79deaf}] : (VolumeSnapshot) [] -> @%SystemRoot%\System32\SysClass.Dll,-3011 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53d29ef7-377c-4d14-864b-eb3a85769359}] : (Biometric) [] -> @%SystemRoot%\System32\SysClass.DLL,-3028 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5630831c-06c9-4856-b327-f5d32586e060}] : (Proximity) [] -> @c_proximity.inf,%ClassDesc%;Proximity devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{62f9c741-b25a-46ce-b54c-9bccce08b6f2}] : (SoftwareDevice) [] -> @c_swdevice.inf,%ClassDesc%;Software devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc1-810f-11d0-bec7-08002be2092f}] : (1394) [] -> @%SystemRoot%\System32\SysClass.Dll,-3016 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc5-810f-11d0-bec7-08002be2092f}] : (Infrared) [] -> @%SystemRoot%\System32\NetCfgx.dll,-1501 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc6-810f-11d0-bec7-08002be2092f}] : (Image) [] -> @%systemroot%\system32\sti_ci.dll,-52 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6d807884-7d21-11cf-801c-08002be10318}] : (TapeDrive) [] -> @%SystemRoot%\System32\SysClass.Dll,-3006 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6FAE73B7-B735-4B50-A0DA-0DC2484B1F1A}] : (BasicDisplay) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f}] : (Volume) [] -> @%SystemRoot%\System32\SysClass.Dll,-3007 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{72631e54-78a4-11d0-bcf7-00aa00b7b32a}] : (Battery) [] -> @%SystemRoot%\system32\powrprof.dll,-611 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{745a17a0-74d3-11d0-b6fe-00a0c90f57da}] : (HIDClass) [] -> @%SystemRoot%\System32\hid.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{7ebefbc0-3200-11d2-b4c2-00a0c9697d07}] : (61883) [] -> @%SystemRoot%\System32\SysClass.Dll,-3019 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{81C87465-DE07-4EFC-9D93-61E891D52FD2}] : (RdpVideoMiniport) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{87C077B2-3D3B-4156-938A-EA51B451D6C6}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88a1c342-4539-11d3-b88d-00c04fad5171}] : (TS_Generic) [] -> @ts_generic.inf,%TSClassName%;Generic Remote Desktop devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{88bae032-5a81-49f0-bc3d-a4ff138216d6}] : (USBDevice) [] -> @%SystemRoot%\System32\SysClass.Dll,-3029 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8AE85550-832C-4A9B-81BB-2A49DBEE72B4}] : (aswRvrt) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8c78b96c-9120-4da4-a144-ff427f2cf132}] : (BarcodeScanner) [] -> @hidscanner.inf,%ClassName%;POS HID Barcode scanners [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8ecc055d-047f-11d1-a537-0000f8753ed1}] : (LegacyDriver) [] -> @%SystemRoot%\System32\SysClass.Dll,-3003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}] : (SmartCard) [] -> @%SystemRoot%\System32\sccls.dll,-300 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}] : (dtsoftbus01) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9d6d66a6-0b0c-4563-9077-a0e9a7955ae4}] : (Ramdisk) [] -> @ramdisk.inf,%ClassName%;RAM Disk drives [HKLM\SYSTEM\CurrentControlSet\Control\Class\{9da2b80f-f89f-4a49-a5c2-511b085b9e8a}] : (EhStorSilo) [] -> @rawsilo.inf,%ClassName%;IEEE 1667 silo and control devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{a0a588a4-c46f-4b37-b7ea-c82fe89870c6}] : (SDHost) [] -> @%SystemRoot%\System32\SysClass.Dll,-3012 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A3E32DBA-BA89-4F17-8386-2D0127FBD4CC}] : (rdpbus) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A73C93F1-9727-4D1D-ACE1-0E333BA4E7DB}] : (nvlddmkm) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{B95B836B-234E-4857-A1F8-D0D9A9BEC1C5}] : (vmbus) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c06ff265-ae09-48f0-812c-16753d7cba83}] : (AVC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3027 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c166523c-fe0c-4a94-a586-f1a80cfbbf3e}] : (AudioEndpoint) [] -> @AudioEndpoint.inf,%ClassName%;Audio inputs and outputs [HKLM\SYSTEM\CurrentControlSet\Control\Class\{c30ecea0-11ef-4ef9-b02e-6af81e6e65c0}] : (WSDPrintDevice) [] -> @WSDPrint.Inf,%ClassName%;WSD Print Provider [HKLM\SYSTEM\CurrentControlSet\Control\Class\{C4A06E97-ED42-47B9-83E1-F12299B286A5}] : (aswRdr) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{C777C165-D422-426D-8EBF-6EAF3FB83ADF}] : (aswNdisFlt) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{CC41EBA2-AB57-4F4E-8C3D-1BC33B1E74E3}] : (RDPDR) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{ce5939ae-ebde-11d0-b181-0000f8753ec4}] : (MediumChanger) [] -> @%SystemRoot%\System32\StorProp.dll,-17003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d421b08e-6d16-41ca-9c4d-9147e5ac98e0}] : (Miracast) [] -> @miradisp.inf,%ClassName%;Miracast display devices [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d48179be-ec20-11d1-b6b8-00c04fa372a7}] : (SBP2) [] -> @%SystemRoot%\System32\SysClass.Dll,-3017 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d61ca365-5af4-4486-998b-9db4734c6ca3}] : (XnaComposite) [] -> @xusb22.inf,%XUSB22.ClassName%;Xbox 360 Peripherals [HKLM\SYSTEM\CurrentControlSet\Control\Class\{d94ee5d8-d189-4994-83d2-f68d7d41b0e6}] : (SecurityDevices) [] -> @%SystemRoot%\System32\SysClass.Dll,-3020 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{db4f6ddd-9c0e-45e4-9597-78dbbad0f412}] : (SmartCardFilter) [] -> @%SystemRoot%\System32\sccls.dll,-301 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e0cbf06c-cd8b-4647-bb8a-263b43f0f974}] : (Bluetooth) [] -> @%SystemRoot%\system32\bthci.dll,-4001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{e2f84ce7-8efa-411c-aa69-97454ca4cb57}] : (Extension) [] -> @c_extension.inf,%ClassDesc%;Extensions [HKLM\SYSTEM\CurrentControlSet\Control\Class\{eec5ad98-8080-425f-922a-dabf3de3f69a}] : (WPD) [] -> @%SystemRoot%\System32\wpd_ci.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{f2e7dd72-6468-4e36-b6f1-6488f42c1b52}] : (Firmware) [] -> @c_firmware.inf,%ClassDesc%;Firmware [HKLM\SYSTEM\CurrentControlSet\Control\Class\{FB58BE68-EA9E-4803-847F-2CE814E7B159}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}] : (Script Detection) [@elscore.dll,-2] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}] : (Transliteration) [@elscore.dll,-5] -> elstrans.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}] : (Language Detection) [@elscore.dll,-1] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) ---------- | Loaded modules (whitelist) [24/03/2016 21:55:40] - (4.3.12.0) - (Oracle Corporation - VirtualBox Support Driver) - C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [08/03/2017 20:26:34] - (21.21.13.7866) - (NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 378.66) - C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [22/12/2014 22:23:05] - (2.1.0.21) - (Qualcomm Atheros Co., Ltd. - Qualcomm Atheros Ar81xx series PCI-E Gigabit Ethernet Controller) - C:\WINDOWS\system32\DRIVERS\L1C62x64.sys [27/07/2017 18:35:53] - (3.90.1.0) - (NVIDIA Corporation - NVIDIA Virtual Audio Driver) - C:\WINDOWS\system32\drivers\nvvad64v.sys [14/04/2017 18:44:26] - (202.0.0.0) - (NVIDIA Corporation - Virtual USB Host Controller driver) - C:\WINDOWS\System32\drivers\nvvhci.sys [02/06/2017 04:44:06] - (1.1.4.1) - (SteelSeries ApS - SteelSeries Device Factory Driver) - C:\WINDOWS\System32\drivers\ssdevfactory.sys [03/06/2015 07:09:36] - (4.1.0.0) - (Sysprogs OU - WinCDEmu virtual CDROM bus) - C:\WINDOWS\System32\drivers\BazisVirtualCDBus.sys [18/10/2015 23:27:45] - (4.10.0.2964) - (Eugene V. Muzychenko - Kernel-mode WDM driver) - C:\WINDOWS\system32\DRIVERS\vrtaucbl.sys [08/03/2017 20:26:35] - (1.3.34.21) - (NVIDIA Corporation - NVIDIA HDMI Audio Driver) - C:\WINDOWS\system32\drivers\nvhda64v.sys [30/06/2017 21:21:56] - (2.4.1.2) - (SteelSeries ApS - SteelSeries HID Driver) - C:\WINDOWS\System32\drivers\sshid.sys [18/07/2017 11:59:51] - (5.1.2.252) - (Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver) - C:\WINDOWS\System32\ATMFD.DLL [29/06/2017 12:24:50] - (8.1.4.1) - (LogMeIn Inc. - LogMeIn Hamachi Virtual Miniport Driver) - C:\WINDOWS\system32\DRIVERS\Hamdrv.sys ---------- | Services | 0 : Starting up | 1 : System | 2 : Automatic | 3 : Manual | 4 : Disabled | R : Running service | S : Stopped service S0 - [Kernel Driver] - 3ware () -> System32\drivers\3ware.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - ACPI (@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver) -> System32\drivers\ACPI.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - acpiex (Microsoft ACPIEx Driver) -> System32\Drivers\acpiex.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - ADP80XX () -> System32\drivers\ADP80XX.SYS - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - agp440 (@machine.inf,%agp440_svcdesc%;Intel AGP Bus Filter) -> System32\drivers\agp440.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdsata () -> System32\drivers\amdsata.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdsbs () -> System32\drivers\amdsbs.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - amdxata () -> System32\drivers\amdxata.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - arcsas (@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Storport's Miniport Driver) -> System32\drivers\arcsas.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - atapi (@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel) -> System32\drivers\atapi.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - b06bdrv (@netbvbda.inf,%vbd_srv_desc%;Broadcom NetXtreme II VBD) -> System32\drivers\bxvbda.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - CLFS (@%SystemRoot%\system32\drivers\clfs.sys,-100) -> System32\drivers\CLFS.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - CNG () -> System32\Drivers\cng.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - disk (@disk.inf,%disk_ServiceDesc%;Disk Driver) -> System32\drivers\disk.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - ebdrv (@netevbda.inf,%vbd_srv_desc%;Broadcom NetXtreme II 10 GigE VBD) -> System32\drivers\evbda.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - EhStorClass (@%SystemRoot%\system32\drivers\EhStorClass.sys,-100) -> System32\drivers\EhStorClass.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - EhStorTcgDrv (@ehstortcgdrv.inf,%EhStorTcgDrv.Desc%;Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols) -> System32\drivers\EhStorTcgDrv.sys - AcceptPause: False - AcceptStop: False R0 - [File System Driver] - FileInfo (@%SystemRoot%\system32\drivers\fileinfo.sys,-100) -> System32\drivers\fileinfo.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - FltMgr (@%SystemRoot%\system32\drivers\fltmgr.sys,-10001) -> system32\drivers\fltmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - fvevol (@%SystemRoot%\system32\drivers\fvevol.sys,-100) -> System32\DRIVERS\fvevol.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - gagp30kx (@machine.inf,%gagp30kx_svcdesc%;Filtre AGP version 3.0 générique Microsoft pour plates-formes à base de processeur K8) -> System32\drivers\gagp30kx.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - HpSAMD () -> System32\drivers\HpSAMD.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - hwpolicy (@%systemroot%\system32\drivers\hwpolicy.sys,-101) -> System32\drivers\hwpolicy.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - iaStorAV (@iastorav.inf,%iaStorAV.DeviceDesc%;Intel(R) SATA RAID Controller Windows) -> System32\drivers\iaStorAV.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - iaStorV (@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7) -> System32\drivers\iaStorV.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - intelide () -> System32\drivers\intelide.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - intelpep (@intelpep.inf,%INTELPEP.SVCDESC%;Intel(R) Power Engine Plug-in Driver) -> System32\drivers\intelpep.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - isapnp () -> System32\drivers\isapnp.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - KSecDD () -> System32\Drivers\ksecdd.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - KSecPkg () -> System32\Drivers\ksecpkg.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - LSI_SAS () -> System32\drivers\lsi_sas.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SAS2 () -> System32\drivers\lsi_sas2.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SAS3 () -> System32\drivers\lsi_sas3.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - LSI_SSS () -> System32\drivers\lsi_sss.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasas () -> System32\drivers\megasas.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - megasr () -> System32\drivers\megasr.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - mountmgr (@%SystemRoot%\system32\drivers\mountmgr.sys,-100) -> System32\drivers\mountmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - msisadrv () -> System32\drivers\msisadrv.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - Mup (@%systemroot%\system32\drivers\mup.sys,-101) -> System32\Drivers\mup.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - mvumis () -> System32\drivers\mvumis.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - NDIS (@%SystemRoot%\system32\drivers\ndis.sys,-200) -> system32\drivers\ndis.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - nvraid () -> System32\drivers\nvraid.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - nvstor () -> System32\drivers\nvstor.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - nv_agp (@machine.inf,%agpnvidia_svcdesc%;NVIDIA nForce AGP Bus Filter) -> System32\drivers\nv_agp.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - partmgr (@%SystemRoot%\system32\drivers\partmgr.sys,-100) -> System32\drivers\partmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - pci (@machine.inf,%pci_svcdesc%;Pilote de bus PCI) -> System32\drivers\pci.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - pciide () -> System32\drivers\pciide.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - pcmcia () -> System32\drivers\pcmcia.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - pcw (Performance Counters for Windows Driver) -> System32\drivers\pcw.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - pdc (@%SystemRoot%\system32\drivers\pdc.sys,-100) -> system32\drivers\pdc.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - rdyboost (ReadyBoost) -> System32\drivers\rdyboost.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - sbp2port (@sbp2.inf,%sbp2_ServiceDesc%;SBP-2 Transport/Protocol Bus Driver) -> System32\drivers\sbp2port.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - SiSRaid2 () -> System32\drivers\SiSRaid2.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - SiSRaid4 () -> System32\drivers\sisraid4.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - spaceport (@spaceport.inf,%Spaceport_ServiceDesc%;Storage Spaces Driver) -> System32\drivers\spaceport.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - stexstor () -> System32\drivers\stexstor.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - storahci (@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver) -> System32\drivers\storahci.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - storflt (@%SystemRoot%\system32\vmstorfltres.dll,-1000) -> System32\drivers\vmstorfl.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - stornvme (@stornvme.inf,%StorNVMe_ServiceDesc%;Microsoft Standard NVM Express Driver) -> System32\drivers\stornvme.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - storvsc () -> System32\drivers\storvsc.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - Tcpip (@%SystemRoot%\system32\tcpipcfg.dll,-50003) -> System32\drivers\tcpip.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - uagp35 (@machine.inf,%uagp35_svcdesc%;Filtre AGP version 3.5 Microsoft) -> System32\drivers\uagp35.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - uliagpkx (@machine.inf,%uliagpkx_svcdesc%;Uli AGP Bus Filter) -> System32\drivers\uliagpkx.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - vdrvroot (@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator) -> System32\drivers\vdrvroot.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - viaide () -> System32\drivers\viaide.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - vmbus (@%SystemRoot%\system32\vmbusres.dll,-1000) -> System32\drivers\vmbus.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - volmgr (@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver) -> System32\drivers\volmgr.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - volmgrx (@%SystemRoot%\system32\drivers\volmgrx.sys,-100) -> System32\drivers\volmgrx.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - volsnap (@volume.inf,%VolumeClassName%;Storage volumes) -> System32\drivers\volsnap.sys - AcceptPause: False - AcceptStop: True S0 - [Kernel Driver] - vsmraid () -> System32\drivers\vsmraid.sys - AcceptPause: False - AcceptStop: False S0 - [Kernel Driver] - VSTXRAID (@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage RAID Controller Windows Driver) -> System32\drivers\vstxraid.sys - AcceptPause: False - AcceptStop: False R0 - [Kernel Driver] - Wdf01000 (@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000) -> system32\drivers\Wdf01000.sys - AcceptPause: False - AcceptStop: True R0 - [Kernel Driver] - WFPLWFS (@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000) -> system32\DRIVERS\wfplwfs.sys - AcceptPause: False - AcceptStop: True R0 - [File System Driver] - Wof (Windows Overlay File System Filter Driver) -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - AFD (@%systemroot%\system32\drivers\afd.sys,-1000) -> \SystemRoot\system32\drivers\afd.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - ahcache (@%systemroot%\system32\drivers\ahcache.sys,-102) -> system32\DRIVERS\ahcache.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - aswbidsdriver (aswbidsdriver) -> \SystemRoot\system32\drivers\aswbidsdrivera.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - aswKbd (aswKbd) -> \SystemRoot\system32\drivers\aswKbd.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - aswNetSec (aswNetSec) -> \SystemRoot\system32\drivers\aswNetSec.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - aswRdr (aswRdr) -> \SystemRoot\system32\drivers\aswRdr2.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - aswSnx (aswSnx) -> \SystemRoot\system32\drivers\aswSnx.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - aswSP (aswSP) -> \SystemRoot\system32\drivers\aswSP.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - BasicDisplay () -> \SystemRoot\System32\drivers\BasicDisplay.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - BasicRender () -> \SystemRoot\System32\drivers\BasicRender.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Beep (Beep) -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - cdrom (@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver) -> \SystemRoot\System32\drivers\cdrom.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - CSC (@%systemroot%\system32\cscsvc.dll,-202) -> system32\drivers\csc.sys - AcceptPause: False - AcceptStop: True S1 - [Kernel Driver] - dam (@%SystemRoot%\system32\drivers\dam.sys,-100) -> system32\drivers\dam.sys - AcceptPause: False - AcceptStop: False R1 - [File System Driver] - Dfsc (@%systemroot%\system32\wkssvc.dll,-1008) -> System32\Drivers\dfsc.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - Msfs () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - mssmbios (@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver) -> \SystemRoot\System32\drivers\mssmbios.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - NetBIOS (@netnb.inf,%NetBIOS_Desc%;NetBIOS Interface) -> system32\DRIVERS\netbios.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - NetBT (@%SystemRoot%\system32\drivers\netbt.sys,-2) -> System32\DRIVERS\netbt.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - Npfs () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - npsvctrig (@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider) -> \SystemRoot\System32\drivers\npsvctrig.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - nsiproxy (@%SystemRoot%\system32\drivers\nsiproxy.sys,-2) -> system32\drivers\nsiproxy.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Null () -> (?) - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - Psched (@%SystemRoot%\System32\drivers\pacer.sys,-101) -> \SystemRoot\system32\DRIVERS\pacer.sys - AcceptPause: False - AcceptStop: True R1 - [File System Driver] - rdbss (@%systemroot%\system32\wkssvc.dll,-1000) -> system32\DRIVERS\rdbss.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - tdx (@%SystemRoot%\system32\tcpipcfg.dll,-50004) -> \SystemRoot\system32\DRIVERS\tdx.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - VBoxDrv (VirtualBox Service) -> \SystemRoot\system32\DRIVERS\VBoxDrv.sys - AcceptPause: False - AcceptStop: True R1 - [Kernel Driver] - ws2ifsl (Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0) -> \SystemRoot\system32\drivers\ws2ifsl.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - aswMonFlt (aswMonFlt) -> \SystemRoot\system32\drivers\aswMonFlt.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - aswStm (aswStm) -> \SystemRoot\system32\drivers\aswStm.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - lltdio (@%SystemRoot%\system32\lltdres.dll,-6) -> \SystemRoot\system32\DRIVERS\lltdio.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - luafv (@%systemroot%\system32\drivers\luafv.sys,-100) -> \SystemRoot\system32\drivers\luafv.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - mrxsmb10 (@%systemroot%\system32\wkssvc.dll,-1004) -> system32\DRIVERS\mrxsmb10.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - Ndu (@%SystemRoot%\system32\drivers\Ndu.sys,-10001) -> system32\drivers\Ndu.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - PEAUTH (PEAUTH) -> system32\drivers\peauth.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - rspndr (@%SystemRoot%\system32\lltdres.dll,-5) -> \SystemRoot\system32\DRIVERS\rspndr.sys - AcceptPause: False - AcceptStop: True R2 - [File System Driver] - srv (@%systemroot%\system32\srvsvc.dll,-102) -> System32\DRIVERS\srv.sys - AcceptPause: False - AcceptStop: True R2 - [Kernel Driver] - tcpipreg (TCP/IP Registry Compatibility) -> System32\drivers\tcpipreg.sys - AcceptPause: False - AcceptStop: True ---------- | System files (Microsoft|Avast|Atheros|Adaptec|Brother|Intel Files whitelisted) [MD5.4AC51459805264AFFD5F6FDFB9D9235F] - [16/09/2016 20:53:32] - (.Copyright (c) GEAR Software Inc. 2006 - CD/DVD Class Filter Driver.) - [15.3 Ko] - (2.0.6.1) - C:\WINDOWS\Syswow64\Drivers\GEARAspiWDM.sys [MD5.890CADA2AB7ACF53A5F9CCE7515522A2] - [11/11/2015 17:21:42] - (.Copyright (c) 1998-2002 Macrovision Corp. - Macrovision SECURITY Driver.) - [12.17 Ko] - (3.17.0.0) - C:\WINDOWS\Syswow64\Drivers\SECDRV.SYS ---------- | Uninstall (Whitelist) [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\5e513792988f949e] : (.-.) -> [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\642972f0658b42f1] : (.-.) -> [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\8f21e4e6a99f15de] : (.-.) -> [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\a1ef42432e75f3e1] : (.-.) -> [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\b3e7bec5a96728d4] : (.-.) -> [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\bc14b2953fd524cd] : (.-.) -> [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\be22d2a0a86c5cda] : (.-.) -> [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\c34dcdf9e28bda87] : (.-.) -> [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\da2f89cf06de4f58] : (.-.) -> [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\f9db7d139899bfb8] : (.-.) -> [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\fba24b2b2622db] : (.-.) -> [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\GoldenEye Setup Editor 3.0] : (GoldenEye Setup Editor 3.0.-.) -> D:\GEEdit3\Uninstall.exe [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\LINE] : (LINE.-.LINE Corporation) -> C:\Users\Thomas\AppData\Local\LINE\bin\LineUnInst.exe [HKU\S-1-5-21-1200667838-2990588833-2439126145-1001\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\UnityWebPlayer] : (Unity Web Player.-.Unity Technologies ApS) -> C:\Users\Thomas\AppData\Local\Unity\WebPlayer\Uninstall.exe /CurrentUser [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Andy OS] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DAEMON Tools Lite] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\GIMP-2_is1] : (GIMP 2.8.16.-.The GIMP Team) -> "D:\Program Files (x86)\GIMP 2\uninst\unins000.exe" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\gpuminer] : (.-.Open Source) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Virtual Audio Cable 4.10] : (Virtual Audio Cable 4.10.-.) -> D:\Program Files\Virtual Audio Cable\setup64.exe -u [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F64180121F0}] : (Java 8 Update 121 (64-bit).-.Oracle Corporation) -> MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F64180121F0} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F64180131F0}] : (Java 8 Update 131 (64-bit).-.Oracle Corporation) -> MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F64180131F0} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{66C5838F-B854-4A55-89E6-A6138747A4DF}] : (Epic Games Launcher Prerequisites (x64).-.Epic Games, Inc.) -> MsiExec.exe /X{66C5838F-B854-4A55-89E6-A6138747A4DF} ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel] : (Ansel.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel] : (Panneau de configuration NVIDIA 378.66.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update] : (Mises à jour NVIDIA 28.0.0.0.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv] : (NVIDIA SHIELD Streaming.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer] : (NVIDIA Install Application.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend] : (NVIDIA Backend.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer] : (NVIDIA Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.ContainerTelemetryApiHelper] : (NVIDIA TelemetryApi helper for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem] : (NVIDIA LocalSystem Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus] : (NVIDIA Message Bus for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NetworkService] : (NVIDIA NetworkService Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.Session] : (NVIDIA Session Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User] : (NVIDIA User Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer] : (NVIDIA Display Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS] : (NVIDIA Display Container LS.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs] : (NVIDIA NodeJS.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog] : (NVIDIA Watchdog Plugin for NvContainer.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry] : (NVIDIA Telemetry Client.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetryContainer] : (NVIDIA Telemetry Container.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci] : (NVIDIA Virtual Host Controller.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC] : (Nvidia Share.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay] : (NVIDIA ShadowPlay 3.9.0.61.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController] : (NVIDIA SHIELD Wireless Controller Driver.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core] : (NVIDIA Update Core.-.NVIDIA Corporation) -> ----------[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver] : (NVIDIA Virtual Audio 3.90.1.-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}] : (Oracle VM VirtualBox 4.3.12_ZZZZ.-.Oracle Corporation) -> MsiExec.exe /I{B5121457-0126-4E62-BCBF-6DC7C73D9E4A} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{DADC2AF6-DC9F-4BCF-BFCE-DCEC16EF507C}] : (paint.net.-.dotPDN LLC) -> MsiExec.exe /X{DADC2AF6-DC9F-4BCF-BFCE-DCEC16EF507C} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\1421404701_is1] : (STAR WARS® - Battlefront® II.-.GOG.com) -> "D:\Program Files (x86)\Star Wars - Battlefront 2\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\1963513391_is1] : (Cuphead.-.GOG.com) -> "D:\Program Files (x86)\Cuphead\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI] : (Adobe Flash Player 27 NPAPI.-.Adobe Systems Incorporated) -> C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_159_Plugin.exe -maintain plugin [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\American Truck Simulator - Heavy Cargo Pack_is1] : (American Truck Simulator - Heavy Cargo Pack version 1.0.-.SCS Software) -> "D:\Program Files (x86)\American Truck Simulator\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\com.adobe.downloadassistant.AdobeDownloadAssistant] : (Adobe Download Assistant.-.Adobe Systems Incorporated) -> msiexec /qb /x {B8B7838E-449E-B187-57E1-1AA686F225DC} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\GlassWire 1.1] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield Uninstall Information] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IObitUninstall] : (IObit Uninstaller.-.IObit) -> "C:\Program Files (x86)\IObit\IObit Uninstaller\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\LogMeIn Hamachi] : (LogMeIn Hamachi.-.LogMeIn, Inc.) -> C:\WINDOWS\SysWOW64\\msiexec.exe /i {BE82D2D7-6CA2-43B3-8C22-CCF6405806E7} REMOVE=ALL [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Magic Set Editor 2_is1] : (Magic Set Editor 2.0.0.-.) -> "D:\Program Files (x86)\Magic Set Editor 2\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MCreator 1.7.1 Installer] : (MCreator 1.7.1.-.Pylo) -> D:\Program Files (x86)\MCreator171\Uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MCreator 1.7.1 Installer}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MCreator 1.7.5 Installer}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Outlast_is1] : (Outlast.-.) -> "D:\Program Files (x86)\Outlast\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\PerfectGold] : (GoldenEye Setup Editor 3.0.-.) -> "D:\GEEdit3\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Songbird-release-2453] : (Songbird 2.2.0 (Build 2453).-.) -> "D:\Program Files (x86)\Songbird\Songbird-Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SU] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\The Sims 4_is1] : (The Sims 4.-.) -> "D:\Games\The Sims 4\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\TmUnitedForever_is1] : (TmUnitedForever Update 2010-03-15.-.Nadeo) -> "C:\Program Files (x86)\TmUnitedForever\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Unity] : (Unity.-.Unity Technologies ApS) -> D:\Program Files (x86)\Unity Web Player\Editor\Uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\VTFEdit_is1] : (VTFEdit 1.2.5.-.Neil Jedrzejewski & Ryan Gregg) -> "D:\Program Files (x86)\VTFEdit\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{08D2E121-7F6A-43EB-97FD-629B44903403}] : (Microsoft_VC90_CRT_x86.-.Adobe) -> MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{0D566ABB-889B-AF39-7B6A-23D4C5D54542}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{14974B3E-1954-4BAC-A618-91F1121497F8}] : (TrackMania Unlimiter.-.TrackMania Unlimiter) -> MsiExec.exe /I{14974B3E-1954-4BAC-A618-91F1121497F8} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}] : (Minecraft.-.Mojang) -> MsiExec.exe /X{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{214E251B-BF42-BF18-588C-42DA92658DB4}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{23B82977-C816-92D2-66E7-BE67DD1E7786}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{25A344BB-378D-4E51-9A39-780755012B2D}] : (RealWorld Cursor Editor.-.RealWorld Graphics) -> MsiExec.exe /I{25A344BB-378D-4E51-9A39-780755012B2D} ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{25A60C59-0FDC-4D73-81F4-D4A6D4E0CB92}] : (Adobe AIR.-.Adobe Systems Incorporated) -> MsiExec.exe /I{25A60C59-0FDC-4D73-81F4-D4A6D4E0CB92} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{274E3C5C-178E-EAE2-A52F-2863C0EECD46}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1] : (Lightshot-5.3.0.0.-.Skillbrains) -> "C:\Program Files (x86)\Skillbrains\lightshot\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{35E0D123-1F22-9AE6-F973-B7ECA46E8BFE}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}] : (Skype™ 7.40.-.Skype Technologies S.A.) -> MsiExec.exe /X{3B7E914A-93D5-4A29-92BB-AF8C3F66C431} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3E1679DA-5081-44AA-B4C2-BF8EE7E107E0}] : (OpenOffice 4.1.3.-.Apache Software Foundation) -> MsiExec.exe /I{3E1679DA-5081-44AA-B4C2-BF8EE7E107E0} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3F7D597C-7512-F73C-B0F3-5D711BC91948}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{47B2010D-2F1B-7A72-E485-51BA1F6D5901}] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}] : (Java Auto Updater.-.Oracle Corporation) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{51417852-174C-88D4-34A0-D0FE7858BE47}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5D37C779-D659-4A32-B1D2-7331926D0ED9}_is1] : (FunCraft (Launcher Minecraft Premium) version 1.0.-.ASCENTIA SAS) -> "D:\Program Files (x86)\FunCraft Premium\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{604B50C8-59DF-C3D0-EC52-CD17D7D40A30}] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}] : (Google Update Helper.-.Google Inc.) -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6A08B379-76FB-B4CF-0C70-CAFCD3635A77}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6B8D3A67-346D-410E-81D2-3BFE228D263D}] : (VirtualDJ 8.-.Atomix Productions) -> MsiExec.exe /I{6B8D3A67-346D-410E-81D2-3BFE228D263D} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1] : (Gyazo 3.3.2.-.Nota Inc.) -> "C:\Program Files (x86)\Gyazo\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7223EDAC-E091-B3C1-BD91-B66CE557800F}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{730C1F02-ABB6-7601-60ED-659A59700742}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7BCAC0EB-3993-2416-0531-848C39DF8B65}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{886E86E6-6673-4EAD-A4FF-6E087A661F4E}] : (Epic Games Launcher.-.Epic Games, Inc.) -> MsiExec.exe /X{886E86E6-6673-4EAD-A4FF-6E087A661F4E} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8E8C2E2D-7F21-2CF5-0ADB-64935121ECF0}] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}] : (Microsoft_VC80_CRT_x86.-.Adobe) -> MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9777123F-5BF8-6C86-217E-7EB783C2E885}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9BCF5203-72BB-4425-A391-83BF298EF376}] : (Mumble 1.2.19.-.Thorvald Natvig) -> MsiExec.exe /I{9BCF5203-72BB-4425-A391-83BF298EF376} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9D9BEFAE-9499-F52B-6CC4-94818CCC2AB5}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AA67D612-0BE5-44D6-9A91-592958F754A1}] : (Intel(R) C++ Redistributables on Intel(R) 64.-.Intel Corporation) -> MsiExec.exe /X{AA67D612-0BE5-44D6-9A91-592958F754A1} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B0EC0808-6922-8705-C255-F9C79C315BD5}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B138259A-351E-33FA-2726-8D71704F1DA9}] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B8B7838E-449E-B187-57E1-1AA686F225DC}] : (Adobe Download Assistant.-.Adobe Systems Incorporated) -> MsiExec.exe /I{B8B7838E-449E-B187-57E1-1AA686F225DC} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BE360B8B-0F10-CA89-FC84-A5EAB71A6AF8}] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BE82D2D7-6CA2-43B3-8C22-CCF6405806E7}] : (LogMeIn Hamachi.-.LogMeIn, Inc.) -> MsiExec.exe /I{BE82D2D7-6CA2-43B3-8C22-CCF6405806E7} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BEB5FB69-4080-466F-96C4-F15DF271718B}_is1] : (Project 64 version 2.2.0.3.-.) -> "D:\Program Files (x86)\Project64 2.2\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C5CA8928-4AC0-DA84-6864-59CFC9F6212C}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CA8C94BE-9F47-1B2E-90F8-D8C07119BD96}] : (.-.) -> ----------[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D596980D-17BE-4425-B8F0-5640719AADE9}] : (LEGO® Star Wars™: The Complete Saga.-.LucasArts) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D8BC877A-DD41-4488-BA72-E9CA0B65D809}] : (Pokémon Trading Card Game Online.-.The Pokémon Company International) -> MsiExec.exe /I{D8BC877A-DD41-4488-BA72-E9CA0B65D809} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D8FA85EA-181E-7C3E-EDC7-4961E965FE61}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E9AD2F38-EF9C-B9DA-048A-A92FBC17701E}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ECF2E224-42F5-4E50-B58E-94CA70E85697}] : (Google Earth Pro.-.Google) -> MsiExec.exe /I{ECF2E224-42F5-4E50-B58E-94CA70E85697} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F5853CDF-2C63-6D1D-B286-CBB1CD5DFD62}] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F7F74F7F-C458-4B7C-A6F4-80A28ED7AF0B}] : (Scrolls.-.Mojang) -> MsiExec.exe /X{F7F74F7F-C458-4B7C-A6F4-80A28ED7AF0B} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FC4C8FDD-384C-471F-9E9A-C25B57ABE7A8}] : (NBTExplorer.-.Justin Aquadro) -> MsiExec.exe /X{FC4C8FDD-384C-471F-9E9A-C25B57ABE7A8} ---------- | Ports ---------- | Installer [HKCR\Installer\Products\216D76AA5EB06D44A9199592857F451A] : Intel(R) C++ Redistributables on Intel(R) 64 [HKCR\Installer\Products\3025FCB9BB2752443A1938FB92E83F67] : Mumble 1.2.19 -> C:\WINDOWS\Installer\{9BCF5203-72BB-4425-A391-83BF298EF376}\mumble.ico [HKCR\Installer\Products\3ACB61C11CBE6F946832F8FB9BCC8C27] : Minecraft -> C:\WINDOWS\Installer\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}\minecraft.ico [HKCR\Installer\Products\422E2FCE5F2405E45BE849AC078E6579] : Google Earth Pro -> C:\WINDOWS\Installer\{ECF2E224-42F5-4E50-B58E-94CA70E85697}\MainIcon.ico [HKCR\Installer\Products\4EA42A62D9304AC4784BF2468110120F] : Java 8 Update 121 (64-bit) -> C:\Program Files\Java\jre1.8.0_121\\bin\javaws.exe [HKCR\Installer\Products\4EA42A62D9304AC4784BF2468110130F] : Java 8 Update 131 (64-bit) -> C:\Program Files\Java\jre1.8.0_131\\bin\javaws.exe [HKCR\Installer\Products\6E68E6883766DAE44AFFE680A766F1E4] : Epic Games Launcher -> C:\WINDOWS\Installer\{886E86E6-6673-4EAD-A4FF-6E087A661F4E}\Installer.ico [HKCR\Installer\Products\6FA2CDADF9CDFCB4FBECCDCE61FE05C7] : paint.net -> C:\WINDOWS\Installer\{DADC2AF6-DC9F-4BCF-BFCE-DCEC16EF507C}\_853F67D554F05449430E7E.exe [HKCR\Installer\Products\7541215B621026E4CBFBD67C7CD3E9A4] : Oracle VM VirtualBox 4.3.12_ZZZZ -> C:\WINDOWS\Installer\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}\IconVirtualBox [HKCR\Installer\Products\7D2D28EB2AC63B34C822CC6F0485607E] : LogMeIn Hamachi [HKCR\Installer\Products\8E5775848BEADB6429B24282970ED35D] : Age of Empires III -> C:\Windows\Installer\{485775E8-AEB8-46BD-922B-242879E03DD5}\ARPPRODUCTICON.exe [HKCR\Installer\Products\95C06A52CDF037D4184F4D6A4D0EBC29] : Adobe AIR [HKCR\Installer\Products\A089CE062ADB6BC44A720BA745894BAC] : Google Update Helper [HKCR\Installer\Products\A419E7B35D3992A429BBFAC8F3664C13] : Skype™ 7.40 -> C:\WINDOWS\Installer\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}\SkypeIcon.exe [HKCR\Installer\Products\AD9761E31805AA444B2CFBE87E1E700E] : OpenOffice 4.1.3 -> C:\WINDOWS\Installer\{3E1679DA-5081-44AA-B4C2-BF8EE7E107E0}\soffice.ico [HKCR\Installer\Products\D089695DEB7152448B0F650417A9DA9E] : LEGO® Star Wars™: The Complete Saga -> C:\WINDOWS\Installer\{D596980D-17BE-4425-B8F0-5640719AADE9}\ARPPRODUCTICON.exe [HKCR\Installer\Products\D139E7FE48CDB174D86B8A3385904547] : [HKCR\Installer\Products\DDF8C4CFC483F174E9A92CB575BA7E8A] : NBTExplorer -> C:\WINDOWS\Installer\{FC4C8FDD-384C-471F-9E9A-C25B57ABE7A8}\I.MainIcon [HKCR\Installer\Products\E3B479414591CAB46A81191F2141798F] : TrackMania Unlimiter -> C:\WINDOWS\Installer\{14974B3E-1954-4BAC-A618-91F1121497F8}\ARPPRODUCTICON.exe [HKCR\Installer\Products\E8387B8BE944781B751EA16A682F52CD] : Adobe Download Assistant [HKCR\Installer\Products\F45FAD3B52BD6854E91F692DB41B0488] : Windows Movie Maker 2.6 [HKCR\Installer\Products\F60730A4A66673047777F5728467D401] : Java Auto Updater [HKCR\Installer\Products\F7F47F7F854CC7B46A4F082AE87DFAB0] : Scrolls -> C:\Windows\Installer\{F7F74F7F-C458-4B7C-A6F4-80A28ED7AF0B}\scrolls.ico [HKCR\Installer\Products\F8385C66458B55A4986E6A3178744AFD] : Epic Games Launcher Prerequisites (x64) -> C:\WINDOWS\Installer\{66C5838F-B854-4A55-89E6-A6138747A4DF}\UnrealEngineLauncher.ico ---------- | ADS ---------- | Drives ---------- | MBR 64 bits not supported by MBR.exe, Dump : C:\QuickDiag\MBR.Bin ---------- | 20 LastEventLog Échec de la planification du redémarrage du service de protection logicielle à 2117-09-24T10:25:40Z. Code d’erreur : 0x80071A2D. ------------ Échec de la planification du redémarrage du service de protection logicielle à 2117-09-24T10:25:09Z. Code d’erreur : 0x80070070. ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ svchost (1492) SRUJet: Un lien de page incorrect (erreur -338) a été détecté dans le B-Tree (ObjectId : 13, PgnoRoot : 55) de la base de données C:\WINDOWS\system32\SRU\SRUDB.dat (1051 => 1594, 1593). ------------ ----------( EOF)---------- - 5265 | 18:59:04