1. ========================= SEAF 1.0.1.0 - C_XX 2. 3. Commencé à: 15:20:26 le 13/03/2016 4. 5. Valeur(s) recherchée(s): 6. AppData 7. 8. Légende: TC => Date de création, TM => Date de modification, DA => Dernier accès 9. 10. (!) --- Calcul du Hash "MD5" 11. (!) --- Informations supplémentaires 12. (!) --- Affichage des ADS 13. (!) --- Affichage des dossiers 14. (!) --- Recherche registre 15. 16. ====== Fichier(s) ====== 17. 18. 19. "C:\MFT 563\Centrale\AppData" [ DIRECTORY ] 20. TC: 17/01/2015,11:07:26 | TM: 17/01/2015,11:15:33 | DA: 17/01/2015,11:15:33 21. 22. ========================= 23. 24. 25. "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\localization_appdata.exe" [ ARCHIVE | 419 Ko ] 26. TC: 03/09/2014,07:41:48 | TM: 03/09/2014,07:41:48 | DA: 03/09/2014,07:41:48 27. 28. Hash MD5: 4C86038EB9AEED372E3C6DFDD3EDC21B 29. 30. 31. ========================= 32. 33. 34. "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\localization_appdata.exe.md5" [ ARCHIVE | 32 o ] 35. TC: 03/09/2014,07:41:48 | TM: 03/09/2014,07:41:48 | DA: 03/09/2014,07:41:48 36. 37. Hash MD5: 69D2A15D25626CB056E86460BCFBAEF8 38. 39. 40. ========================= 41. 42. 43. "C:\ProgramData\Avg\AWL\appdata.dat" [ NOT_CONTENT_INDEXED|ARCHIVE | 2 Ko ] 44. TC: 13/02/2016,09:50:57 | TM: 28/02/2016,09:02:00 | DA: 13/02/2016,09:50:57 45. 46. Hash MD5: C670967B2084C65798179DFDEA438B4F 47. 48. 49. ========================= 50. 51. 52. "C:\Qoobox\BackEnv\AppData.folder.dat" [ ARCHIVE | 126 o ] 53. TC: 02/01/2016,09:29:26 | TM: 19/02/2016,11:23:43 | DA: 02/01/2016,09:29:26 54. 55. Hash MD5: 4743521A29D923808F829C453B50CA0D 56. 57. 58. ========================= 59. 60. 61. "C:\Qoobox\BackEnv\LocalAppData.folder.dat" [ ARCHIVE | 102 o ] 62. TC: 02/01/2016,09:29:26 | TM: 19/02/2016,11:23:43 | DA: 02/01/2016,09:29:26 63. 64. Hash MD5: 2805558F714CF6FDB4A9BE1D7C084EE9 65. 66. 67. ========================= 68. 69. 70. "C:\Users\All Users\Avg\AWL\appdata.dat" [ NOT_CONTENT_INDEXED|ARCHIVE | 2 Ko ] 71. TC: 13/02/2016,09:50:57 | TM: 28/02/2016,09:02:00 | DA: 13/02/2016,09:50:57 72. 73. Hash MD5: C670967B2084C65798179DFDEA438B4F 74. 75. 76. ========================= 77. 78. 79. "C:\Users\Centrale\AppData" [ NOT_CONTENT_INDEXED|DIRECTORY|HIDDEN ] 80. TC: 02/09/2014,20:26:51 | TM: 27/09/2014,10:07:34 | DA: 27/09/2014,10:07:34 81. 82. ========================= 83. 84. 85. "C:\Users\Default\AppData" [ NOT_CONTENT_INDEXED|DIRECTORY|HIDDEN ] 86. TC: 02/11/2006,14:33:54 | TM: 02/11/2006,14:33:54 | DA: 02/11/2006,14:33:54 87. 88. ========================= 89. 90. 91. "C:\Windows\ServiceProfiles\LocalService\AppData" [ NOT_CONTENT_INDEXED|DIRECTORY|HIDDEN ] 92. TC: 02/11/2006,16:22:02 | TM: 02/11/2006,14:33:54 | DA: 02/11/2006,16:22:02 93. 94. ========================= 95. 96. 97. "C:\Windows\ServiceProfiles\NetworkService\AppData" [ NOT_CONTENT_INDEXED|DIRECTORY|HIDDEN ] 98. TC: 02/11/2006,16:22:01 | TM: 15/11/2015,15:09:39 | DA: 15/11/2015,15:09:39 99. 100. ========================= 101. 102. 103. "C:\Windows\System32\config\systemprofile\AppData" [ DIRECTORY ] 104. TC: 02/11/2006,16:30:39 | TM: 21/01/2008,04:04:20 | DA: 21/01/2008,04:04:20 105. 106. ========================= 107. 108. 109. "C:\Windows\SysWOW64\config\systemprofile\AppData" [ DIRECTORY ] 110. TC: 02/11/2006,16:30:39 | TM: 21/01/2008,04:04:20 | DA: 21/01/2008,04:04:20 111. 112. ========================= 113. 114. 115. "C:\Windows\winsxs\amd64_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6000.16386_none_5389feac7bf65d11" [ DIRECTORY ] 116. TC: 02/11/2006,14:34:25 | TM: 02/11/2006,14:34:25 | DA: 02/11/2006,14:34:25 117. 118. ========================= 119. 120. 121. "C:\Windows\winsxs\amd64_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6000.16720_none_538485107bfb2c85" [ DIRECTORY ] 122. TC: 02/09/2014,22:56:03 | TM: 02/09/2014,22:56:03 | DA: 02/09/2014,22:56:03 123. 124. ========================= 125. 126. 127. "C:\Windows\winsxs\amd64_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6000.20883_none_3cbc9bb4959d7178" [ DIRECTORY ] 128. TC: 02/09/2014,22:56:03 | TM: 02/09/2014,22:56:03 | DA: 02/09/2014,22:56:03 129. 130. ========================= 131. 132. 133. "C:\Windows\winsxs\amd64_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6001.18111_none_535f69c67c4d3926" [ DIRECTORY ] 134. TC: 02/09/2014,22:55:09 | TM: 02/09/2014,22:55:09 | DA: 02/09/2014,22:55:09 135. 136. ========================= 137. 138. 139. "C:\Windows\winsxs\amd64_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6001.22230_none_3c93da6295f2b239" [ DIRECTORY ] 140. TC: 02/09/2014,22:55:08 | TM: 02/09/2014,22:55:08 | DA: 02/09/2014,22:55:08 141. 142. ========================= 143. 144. 145. "C:\Windows\winsxs\FileMaps\users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 146. TC: 02/11/2006,16:07:25 | TM: 02/11/2006,16:06:37 | DA: 02/11/2006,16:06:37 147. 148. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 149. 150. 151. ========================= 152. 153. 154. "C:\Windows\winsxs\FileMaps\users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 155. TC: 02/11/2006,14:08:19 | TM: 02/11/2006,14:06:33 | DA: 02/11/2006,14:06:33 156. 157. Hash MD5: 558090AF7DA064E4FD7884D416620D60 158. 159. 160. ========================= 161. 162. 163. "C:\Windows\winsxs\Manifests\amd64_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6000.16386_none_5389feac7bf65d11.manifest" [ ARCHIVE | 2 Ko ] 164. TC: 02/11/2006,13:31:47 | TM: 02/11/2006,13:20:55 | DA: 02/11/2006,14:09:03 165. 166. Hash MD5: 2A1FD4F67F4340AFAD4EBC354B6C2CC9 167. 168. 169. ========================= 170. 171. 172. "C:\Windows\winsxs\Manifests\amd64_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6000.16720_none_538485107bfb2c85.manifest" [ NORMAL | 2 Ko ] 173. TC: 02/09/2014,22:52:02 | TM: 28/07/2008,00:37:56 | DA: 02/09/2014,22:52:02 174. 175. Hash MD5: EA28F9F32CD95934CE20EE053ADFD978 176. 177. 178. ========================= 179. 180. 181. "C:\Windows\winsxs\Manifests\amd64_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6000.20883_none_3cbc9bb4959d7178.manifest" [ NORMAL | 2 Ko ] 182. TC: 02/09/2014,22:52:02 | TM: 28/07/2008,00:37:13 | DA: 02/09/2014,22:52:02 183. 184. Hash MD5: 35FB59AF52E2A1DAABBCFB3352AEAC47 185. 186. 187. ========================= 188. 189. 190. "C:\Windows\winsxs\Manifests\amd64_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6001.18111_none_535f69c67c4d3926.manifest" [ NORMAL | 2 Ko ] 191. TC: 02/09/2014,22:52:02 | TM: 28/07/2008,00:55:13 | DA: 02/09/2014,22:52:02 192. 193. Hash MD5: 7E1067F535DBA88039A880EB317F0585 194. 195. 196. ========================= 197. 198. 199. "C:\Windows\winsxs\Manifests\amd64_netfx-aspnet_appdata_b03f5f7f11d50a3a_6.0.6001.22230_none_3c93da6295f2b239.manifest" [ NORMAL | 2 Ko ] 200. TC: 02/09/2014,22:52:02 | TM: 28/07/2008,01:08:57 | DA: 02/09/2014,22:52:02 201. 202. Hash MD5: 6696C4951E9499A49AB30AE637D5C10E 203. 204. 205. ========================= 206. 207. 208. "C:\Windows\winsxs\Temp\PendingRenames\00f742361749d101421200000c118013.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 209. TC: 07/01/2016,07:47:01 | TM: 07/01/2016,07:47:01 | DA: 07/01/2016,07:47:01 210. 211. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 212. 213. 214. ========================= 215. 216. 217. "C:\Windows\winsxs\Temp\PendingRenames\092be8d93736d101421200002c10ec10.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 218. TC: 14/12/2015,07:22:47 | TM: 14/12/2015,07:22:47 | DA: 14/12/2015,07:22:47 219. 220. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 221. 222. 223. ========================= 224. 225. 226. "C:\Windows\winsxs\Temp\PendingRenames\09a771973836d101671f00002c10ec10.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 227. TC: 14/12/2015,07:28:05 | TM: 14/12/2015,07:28:05 | DA: 14/12/2015,07:28:05 228. 229. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 230. 231. 232. ========================= 233. 234. 235. "C:\Windows\winsxs\Temp\PendingRenames\1f2eb6c1fd20d101f81e0000c80f4417.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 236. TC: 17/11/2015,07:04:01 | TM: 17/11/2015,07:04:01 | DA: 17/11/2015,07:04:01 237. 238. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 239. 240. 241. ========================= 242. 243. 244. "C:\Windows\winsxs\Temp\PendingRenames\1f4e6c0afd20d101b5110000c80f4417.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 245. TC: 17/11/2015,06:58:54 | TM: 17/11/2015,06:58:54 | DA: 17/11/2015,06:58:54 246. 247. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 248. 249. 250. ========================= 251. 252. 253. "C:\Windows\winsxs\Temp\PendingRenames\200fc35aff45d101421200001c106810.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 254. TC: 03/01/2016,09:18:41 | TM: 03/01/2016,09:18:41 | DA: 03/01/2016,09:18:41 255. 256. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 257. 258. 259. ========================= 260. 261. 262. "C:\Windows\winsxs\Temp\PendingRenames\20a9767f1849d101c12a00000c118013.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 263. TC: 07/01/2016,07:56:13 | TM: 07/01/2016,07:56:13 | DA: 07/01/2016,07:56:13 264. 265. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 266. 267. 268. ========================= 269. 270. 271. "C:\Windows\winsxs\Temp\PendingRenames\2134d569056ed101dd1f0000dc0c5810.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 272. TC: 23/02/2016,07:42:49 | TM: 23/02/2016,07:42:49 | DA: 23/02/2016,07:42:49 273. 274. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 275. 276. 277. ========================= 278. 279. 280. "C:\Windows\winsxs\Temp\PendingRenames\214274da056ed1013e2b0000dc0c5810.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 281. TC: 23/02/2016,07:45:58 | TM: 23/02/2016,07:45:58 | DA: 23/02/2016,07:45:58 282. 283. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 284. 285. 286. ========================= 287. 288. 289. "C:\Windows\winsxs\Temp\PendingRenames\23d26852615ad1015f1f0000840b9012.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 290. TC: 29/01/2016,07:50:21 | TM: 29/01/2016,07:50:21 | DA: 29/01/2016,07:50:21 291. 292. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 293. 294. 295. ========================= 296. 297. 298. "C:\Windows\winsxs\Temp\PendingRenames\23dba247b93bd101421200007c0e9807.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 299. TC: 21/12/2015,07:31:52 | TM: 21/12/2015,07:31:52 | DA: 21/12/2015,07:31:52 300. 301. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 302. 303. 304. ========================= 305. 306. 307. "C:\Windows\winsxs\Temp\PendingRenames\242cbbc1135fd101191200002c05800e.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 308. TC: 04/02/2016,07:17:42 | TM: 04/02/2016,07:17:42 | DA: 04/02/2016,07:17:42 309. 310. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 311. 312. 313. ========================= 314. 315. 316. "C:\Windows\winsxs\Temp\PendingRenames\32df93921433d101c12a0000f4139004.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 317. TC: 10/12/2015,07:32:42 | TM: 10/12/2015,07:32:42 | DA: 10/12/2015,07:32:42 318. 319. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 320. 321. 322. ========================= 323. 324. 325. "C:\Windows\winsxs\Temp\PendingRenames\335cf707b967d101dd1f0000b00a7c0f.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 326. TC: 15/02/2016,07:20:57 | TM: 15/02/2016,07:20:57 | DA: 15/02/2016,07:20:57 327. 328. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 329. 330. 331. ========================= 332. 333. 334. "C:\Windows\winsxs\Temp\PendingRenames\4035a822010fd101e22900005c11b410.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 335. TC: 25/10/2015,09:42:52 | TM: 25/10/2015,09:42:52 | DA: 25/10/2015,09:42:52 336. 337. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 338. 339. 340. ========================= 341. 342. 343. "C:\Windows\winsxs\Temp\PendingRenames\413e773ddd1dd101f81e00003c13a410.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 344. TC: 13/11/2015,07:33:42 | TM: 13/11/2015,07:33:42 | DA: 13/11/2015,07:33:42 345. 346. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 347. 348. 349. ========================= 350. 351. 352. "C:\Windows\winsxs\Temp\PendingRenames\47383ac93b0ed101021f0000ec0c0817.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 353. TC: 24/10/2015,10:10:11 | TM: 24/10/2015,10:10:11 | DA: 24/10/2015,10:10:11 354. 355. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 356. 357. 358. ========================= 359. 360. 361. "C:\Windows\winsxs\Temp\PendingRenames\4eaa6976986fd1013e2b0000880e3c0e.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 362. TC: 25/02/2016,07:47:58 | TM: 25/02/2016,07:47:58 | DA: 25/02/2016,07:47:58 363. 364. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 365. 366. 367. ========================= 368. 369. 370. "C:\Windows\winsxs\Temp\PendingRenames\538baecf2b6ad1013e2b0000ac059005.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 371. TC: 18/02/2016,10:07:37 | TM: 18/02/2016,10:07:37 | DA: 18/02/2016,10:07:37 372. 373. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 374. 375. 376. ========================= 377. 378. 379. "C:\Windows\winsxs\Temp\PendingRenames\5487c283145fd1015f1f00002c05800e.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 380. TC: 04/02/2016,07:23:08 | TM: 04/02/2016,07:23:08 | DA: 04/02/2016,07:23:08 381. 382. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 383. 384. 385. ========================= 386. 387. 388. "C:\Windows\winsxs\Temp\PendingRenames\609b67043720d101b5110000b806d412.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 389. TC: 16/11/2015,07:21:23 | TM: 16/11/2015,07:21:23 | DA: 16/11/2015,07:21:23 390. 391. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 392. 393. 394. ========================= 395. 396. 397. "C:\Windows\winsxs\Temp\PendingRenames\64a41c15155fd101b62a00002c05800e.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 398. TC: 04/02/2016,07:27:12 | TM: 04/02/2016,07:27:12 | DA: 04/02/2016,07:27:12 399. 400. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 401. 402. 403. ========================= 404. 405. 406. "C:\Windows\winsxs\Temp\PendingRenames\70423d30d307d101de1100006014c416.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 407. TC: 16/10/2015,06:26:19 | TM: 16/10/2015,06:26:19 | DA: 16/10/2015,06:26:19 408. 409. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 410. 411. 412. ========================= 413. 414. 415. "C:\Windows\winsxs\Temp\PendingRenames\73c7dd212b6ad101dd1f0000ac059005.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 416. TC: 18/02/2016,10:02:45 | TM: 18/02/2016,10:02:45 | DA: 18/02/2016,10:02:45 417. 418. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 419. 420. 421. ========================= 422. 423. 424. "C:\Windows\winsxs\Temp\PendingRenames\801894aa000fd101021f00005c11b410.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 425. TC: 25/10/2015,09:39:30 | TM: 25/10/2015,09:39:30 | DA: 25/10/2015,09:39:30 426. 427. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 428. 429. 430. ========================= 431. 432. 433. "C:\Windows\winsxs\Temp\PendingRenames\87e1ed4e3c0ed101e2290000ec0c0817.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 434. TC: 24/10/2015,10:13:55 | TM: 24/10/2015,10:13:55 | DA: 24/10/2015,10:13:55 435. 436. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 437. 438. 439. ========================= 440. 441. 442. "C:\Windows\winsxs\Temp\PendingRenames\90cb9cea1749d101671f00000c118013.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 443. TC: 07/01/2016,07:52:03 | TM: 07/01/2016,07:52:03 | DA: 07/01/2016,07:52:03 444. 445. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 446. 447. 448. ========================= 449. 450. 451. "C:\Windows\winsxs\Temp\PendingRenames\932ce2f4615ad101b62a0000840b9012.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 452. TC: 29/01/2016,07:54:53 | TM: 29/01/2016,07:54:53 | DA: 29/01/2016,07:54:53 453. 454. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 455. 456. 457. ========================= 458. 459. 460. "C:\Windows\winsxs\Temp\PendingRenames\934c936d2a6ad1017e120000ac059005.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 461. TC: 18/02/2016,09:57:42 | TM: 18/02/2016,09:57:43 | DA: 18/02/2016,09:57:42 462. 463. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 464. 465. 466. ========================= 467. 468. 469. "C:\Windows\winsxs\Temp\PendingRenames\a0028ae70046d101c12a00001c106810.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 470. TC: 03/01/2016,09:29:46 | TM: 03/01/2016,09:29:46 | DA: 03/01/2016,09:29:46 471. 472. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 473. 474. 475. ========================= 476. 477. 478. "C:\Windows\winsxs\Temp\PendingRenames\a0a467180046d101671f00001c106810.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 479. TC: 03/01/2016,09:23:59 | TM: 03/01/2016,09:23:59 | DA: 03/01/2016,09:23:59 480. 481. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 482. 483. 484. ========================= 485. 486. 487. "C:\Windows\winsxs\Temp\PendingRenames\a4f05d038073d1017e1200004c0d2413.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 488. TC: 01/03/2016,07:03:01 | TM: 01/03/2016,07:03:01 | DA: 01/03/2016,07:03:01 489. 490. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 491. 492. 493. ========================= 494. 495. 496. "C:\Windows\winsxs\Temp\PendingRenames\ae9ac96c976fd1017e120000880e3c0e.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 497. TC: 25/02/2016,07:40:32 | TM: 25/02/2016,07:40:32 | DA: 25/02/2016,07:40:32 498. 499. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 500. 501. 502. ========================= 503. 504. 505. "C:\Windows\winsxs\Temp\PendingRenames\aece3607986fd101dd1f0000880e3c0e.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 506. TC: 25/02/2016,07:44:51 | TM: 25/02/2016,07:44:51 | DA: 25/02/2016,07:44:51 507. 508. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 509. 510. 511. ========================= 512. 513. 514. "C:\Windows\winsxs\Temp\PendingRenames\b0b819abff0ed101de1100005c11b410.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 515. TC: 25/10/2015,09:32:22 | TM: 25/10/2015,09:32:22 | DA: 25/10/2015,09:32:22 516. 517. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 518. 519. 520. ========================= 521. 522. 523. "C:\Windows\winsxs\Temp\PendingRenames\b0fa38d83720d101f81e0000b806d412.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 524. TC: 16/11/2015,07:27:19 | TM: 16/11/2015,07:27:19 | DA: 16/11/2015,07:27:19 525. 526. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 527. 528. 529. ========================= 530. 531. 532. "C:\Windows\winsxs\Temp\PendingRenames\b2b05d691333d10142120000f4139004.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 533. TC: 10/12/2015,07:24:23 | TM: 10/12/2015,07:24:23 | DA: 10/12/2015,07:24:23 534. 535. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 536. 537. 538. ========================= 539. 540. 541. "C:\Windows\winsxs\Temp\PendingRenames\b3d27b90ba3bd101671f00007c0e9807.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 542. TC: 21/12/2015,07:41:04 | TM: 21/12/2015,07:41:04 | DA: 21/12/2015,07:41:04 543. 544. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 545. 546. 547. ========================= 548. 549. 550. "C:\Windows\winsxs\Temp\PendingRenames\bf0e2336126bd1017e120000cc09240e.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 551. TC: 19/02/2016,13:36:53 | TM: 19/02/2016,13:36:53 | DA: 19/02/2016,13:36:53 552. 553. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 554. 555. 556. ========================= 557. 558. 559. "C:\Windows\winsxs\Temp\PendingRenames\c44c892d8173d1013e2b00004c0d2413.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 560. TC: 01/03/2016,07:11:22 | TM: 01/03/2016,07:11:22 | DA: 01/03/2016,07:11:22 561. 562. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 563. 564. 565. ========================= 566. 567. 568. "C:\Windows\winsxs\Temp\PendingRenames\c46d75a88073d101dd1f00004c0d2413.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 569. TC: 01/03/2016,07:07:38 | TM: 01/03/2016,07:07:38 | DA: 01/03/2016,07:07:38 570. 571. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 572. 573. 574. ========================= 575. 576. 577. "C:\Windows\winsxs\Temp\PendingRenames\c96b623a3936d101c12a00002c10ec10.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 578. TC: 14/12/2015,07:32:39 | TM: 14/12/2015,07:32:39 | DA: 14/12/2015,07:32:39 579. 580. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 581. 582. 583. ========================= 584. 585. 586. "C:\Windows\winsxs\Temp\PendingRenames\cf8718f8126bd101dd1f0000cc09240e.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 587. TC: 19/02/2016,13:42:18 | TM: 19/02/2016,13:42:18 | DA: 19/02/2016,13:42:18 588. 589. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 590. 591. 592. ========================= 593. 594. 595. "C:\Windows\winsxs\Temp\PendingRenames\cff94c4ffe20d101512a0000c80f4417.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 596. TC: 17/11/2015,07:07:59 | TM: 17/11/2015,07:07:59 | DA: 17/11/2015,07:07:59 597. 598. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 599. 600. 601. ========================= 602. 603. 604. "C:\Windows\winsxs\Temp\PendingRenames\d092fbded307d101021f00006014c416.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 605. TC: 16/10/2015,06:31:13 | TM: 16/10/2015,06:31:13 | DA: 16/10/2015,06:31:13 606. 607. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 608. 609. 610. ========================= 611. 612. 613. "C:\Windows\winsxs\Temp\PendingRenames\d0b26c6bd407d101e22900006014c416.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 614. TC: 16/10/2015,06:35:08 | TM: 16/10/2015,06:35:08 | DA: 16/10/2015,06:35:08 615. 616. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 617. 618. 619. ========================= 620. 621. 622. "C:\Windows\winsxs\Temp\PendingRenames\d3870489b967d1013e2b0000b00a7c0f.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 623. TC: 15/02/2016,07:24:33 | TM: 15/02/2016,07:24:33 | DA: 15/02/2016,07:24:33 624. 625. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 626. 627. 628. ========================= 629. 630. 631. "C:\Windows\winsxs\Temp\PendingRenames\d3db3525bb3bd101c12a00007c0e9807.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 632. TC: 21/12/2015,07:45:13 | TM: 21/12/2015,07:45:13 | DA: 21/12/2015,07:45:13 633. 634. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 635. 636. 637. ========================= 638. 639. 640. "C:\Windows\winsxs\Temp\PendingRenames\d3ef7e5cb867d1017e120000b00a7c0f.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 641. TC: 15/02/2016,07:16:09 | TM: 15/02/2016,07:16:09 | DA: 15/02/2016,07:16:09 642. 643. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 644. 645. 646. ========================= 647. 648. 649. "C:\Windows\winsxs\Temp\PendingRenames\e19ee9d0046ed1017e120000dc0c5810.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 650. TC: 23/02/2016,07:38:33 | TM: 23/02/2016,07:38:33 | DA: 23/02/2016,07:38:33 651. 652. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 653. 654. 655. ========================= 656. 657. 658. "C:\Windows\winsxs\Temp\PendingRenames\e345458e605ad10119120000840b9012.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 659. TC: 29/01/2016,07:44:52 | TM: 29/01/2016,07:44:52 | DA: 29/01/2016,07:44:52 660. 661. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 662. 663. 664. ========================= 665. 666. 667. "C:\Windows\winsxs\Temp\PendingRenames\f08646763820d101512a0000b806d412.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 668. TC: 16/11/2015,07:31:44 | TM: 16/11/2015,07:31:44 | DA: 16/11/2015,07:31:44 669. 670. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 671. 672. 673. ========================= 674. 675. 676. "C:\Windows\winsxs\Temp\PendingRenames\f118dedcdd1dd101512a00003c13a410.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 677. TC: 13/11/2015,07:38:10 | TM: 13/11/2015,07:38:10 | DA: 13/11/2015,07:38:10 678. 679. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 680. 681. 682. ========================= 683. 684. 685. "C:\Windows\winsxs\Temp\PendingRenames\f1a60d76dc1dd101b51100003c13a410.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 686. TC: 13/11/2015,07:28:08 | TM: 13/11/2015,07:28:08 | DA: 13/11/2015,07:28:08 687. 688. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 689. 690. 691. ========================= 692. 693. 694. "C:\Windows\winsxs\Temp\PendingRenames\f2287a0c1433d101671f0000f4139004.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 695. TC: 10/12/2015,07:28:57 | TM: 10/12/2015,07:28:57 | DA: 10/12/2015,07:28:57 696. 697. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 698. 699. 700. ========================= 701. 702. 703. "C:\Windows\winsxs\Temp\PendingRenames\f77f53b93a0ed101de110000ec0c0817.users_default_appdata_roaming_media_center_programs_b8fc97cb3886dd3f.cdf-ms" [ ARCHIVE | 704 o ] 704. TC: 24/10/2015,10:02:35 | TM: 24/10/2015,10:02:35 | DA: 24/10/2015,10:02:35 705. 706. Hash MD5: CF6B5243EFF4B9ABE19F39E4148B2745 707. 708. 709. ========================= 710. 711. 712. "C:\Windows\winsxs\Temp\PendingRenames\fff1818a136bd1013e2b0000cc09240e.users_default_appdata_roaming_microsoft_windows_sendto_cc2b2363b7303311.cdf-ms" [ ARCHIVE | 1 Ko ] 713. TC: 19/02/2016,13:46:24 | TM: 19/02/2016,13:46:24 | DA: 19/02/2016,13:46:24 714. 715. Hash MD5: 86DC4F2F3A8DD11423DC1272B1F62B02 716. 717. 718. ========================= 719. 720. 721. 722. ====== Entrée(s) du registre ====== 723. 724. 725. [HKLM\Software\Auslogics\ATToolsStd\1.x\Settings] 726. "Prioritization.OptimizedCPUItems"="C:\Users\Centrale\AppData\Local\Temp\_iu14D2N.tmp 727. C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revouninstaller.exe 728. C:\Windows\explorer.exe" (REG_MULTI_SZ) 729. 730. [HKLM\Software\Classes\Interface\{413DAFB0-BCF4-11D1-861D-0080C729264D}] 731. ""="IReceiveAppData" (REG_SZ) 732. 733. [HKLM\Software\Classes\Interface\{B60040E0-BCF3-11D1-861D-0080C729264D}] 734. ""="IGetAppData" (REG_SZ) 735. 736. [HKLM\Software\Classes\SOFTWARE\RealNetworks\Update\6.0\Preferences\Rename\File17] 737. ""="C:\Users\Centrale\AppData\Roaming\Real\RealPlayer\Favorites" (REG_SZ) 738. 739. [HKLM\Software\DVDVideoSoft\NetLogger] 740. "LogFilePath"="C:\Users\Centrale\AppData\Roaming\DVDVideoSoft\logs\FreeYouTubeToMP3Converter_install_ext2.txt" (REG_SZ) 741. 742. [HKLM\Software\DVDVideoSoft\NetLogger] 743. "SearchNetLoggerDir"="C:\Users\Centrale\AppData\Local\Temp\is-JA8QJ.tmp" (REG_SZ) 744. 745. [HKLM\Software\IObit\RegistryDefragBoot\FileList] 746. "\Registry\User\S-1-5-21-2605355984-3802085725-3497844330-1000_Classes"="\??\C:\Users\Centrale\AppData\Local\Microsoft\Windows\UsrClass.dat" (REG_SZ) 747. 748. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}] 749. "Name"="AppData" (REG_SZ) 750. 751. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}] 752. "RelativePath"="AppData\Roaming" (REG_SZ) 753. 754. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}] 755. "Name"="Common AppData" (REG_SZ) 756. 757. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}] 758. "Name"="LocalAppDataLow" (REG_SZ) 759. 760. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}] 761. "RelativePath"="AppData\LocalLow" (REG_SZ) 762. 763. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}] 764. "Name"="Local AppData" (REG_SZ) 765. 766. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}] 767. "RelativePath"="AppData\Local" (REG_SZ) 768. 769. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\OpenContainingFolderHiddenList] 770. "Windows Mail"="%LOCALAPPDATA%\Microsoft\Windows Mail" (REG_EXPAND_SZ) 771. 772. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 773. "Common AppData"="C:\ProgramData" (REG_SZ) 774. 775. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 776. "Common AppData"="%ProgramData%" (REG_EXPAND_SZ) 777. 778. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Windows Error Reporting Archive Files] 779. "Folder"="%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportArchive" (REG_EXPAND_SZ) 780. 781. [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Windows Error Reporting Queue Files] 782. "Folder"="%USERPROFILE%\AppData\Local\Microsoft\Windows\WER\ReportQueue" (REG_EXPAND_SZ) 783. 784. [HKLM\Software\Microsoft\Windows NT\CurrentVersion\APITracing] 785. "LogFileDirectory"="%USERPROFILE%\AppData\Local\Microsoft\APITracing" (REG_EXPAND_SZ) 786. 787. [HKLM\Software\Microsoft\Windows NT\CurrentVersion\SeCEdit] 788. "EnvironmentVariables"="%AppData% 789. %UserProfile% 790. %AllUsersProfile% 791. %ProgramFiles% 792. %SystemRoot% 793. %SystemDrive% 794. %Temp% 795. %Tmp" (REG_MULTI_SZ) 796. 797. [HKLM\System\ControlSet001\Control\BackupRestore\FilesNotToSnapshot] 798. "OutlookOST"="$UserProfile$\AppData\Local\Microsoft\Outlook\*.ost" (REG_MULTI_SZ) 799. 800. [HKLM\System\ControlSet001\Control\hivelist] 801. "\Registry\User\S-1-5-21-2605355984-3802085725-3497844330-1000_Classes"="\Device\HarddiskVolume2\Users\Centrale\AppData\Local\Microsoft\Windows\UsrClass.dat" (REG_SZ) 802. 803. [HKLM\System\ControlSet001\Services\cpuz137] 804. "ImagePath"="\??\C:\Users\Centrale\AppData\Local\Temp\cpuz137\cpuz137_x64.sys" (REG_EXPAND_SZ) 805. 806. [HKLM\System\ControlSet002\Services\cpuz137] 807. "ImagePath"="\??\C:\Users\Centrale\AppData\Local\Temp\cpuz137\cpuz137_x64.sys" (REG_EXPAND_SZ) 808. 809. [HKLM\System\ControlSet003\Services\cpuz137] 810. "ImagePath"="\??\C:\Users\Centrale\AppData\Local\Temp\cpuz137\cpuz137_x64.sys" (REG_EXPAND_SZ) 811. 812. [HKLM\System\ControlSet004\Services\cpuz137] 813. "ImagePath"="\??\C:\Users\Centrale\AppData\Local\Temp\cpuz137\cpuz137_x64.sys" (REG_EXPAND_SZ) 814. 815. [HKLM\System\ControlSet005\Services\cpuz137] 816. "ImagePath"="\??\C:\Users\Centrale\AppData\Local\Temp\cpuz137\cpuz137_x64.sys" (REG_EXPAND_SZ) 817. 818. [HKLM\System\ControlSet006\Services\cpuz137] 819. "ImagePath"="\??\C:\Users\Centrale\AppData\Local\Temp\cpuz137\cpuz137_x64.sys" (REG_EXPAND_SZ) 820. 821. [HKLM\System\ControlSet007\Services\cpuz137] 822. "ImagePath"="\??\C:\Users\Centrale\AppData\Local\Temp\cpuz137\cpuz137_x64.sys" (REG_EXPAND_SZ) 823. 824. [HKLM\System\ControlSet008\Control\BackupRestore\FilesNotToSnapshot] 825. "OutlookOST"="$UserProfile$\AppData\Local\Microsoft\Outlook\*.ost" (REG_MULTI_SZ) 826. 827. [HKLM\System\ControlSet008\Services\cpuz137] 828. "ImagePath"="\??\C:\Users\Centrale\AppData\Local\Temp\cpuz137\cpuz137_x64.sys" (REG_EXPAND_SZ) 829. 830. [HKLM\System\CurrentControlSet\Control\BackupRestore\FilesNotToSnapshot] 831. "OutlookOST"="$UserProfile$\AppData\Local\Microsoft\Outlook\*.ost" (REG_MULTI_SZ) 832. 833. [HKLM\System\CurrentControlSet\Control\hivelist] 834. "\Registry\User\S-1-5-21-2605355984-3802085725-3497844330-1000_Classes"="\Device\HarddiskVolume2\Users\Centrale\AppData\Local\Microsoft\Windows\UsrClass.dat" (REG_SZ) 835. 836. [HKLM\System\CurrentControlSet\Services\cpuz137] 837. "ImagePath"="\??\C:\Users\Centrale\AppData\Local\Temp\cpuz137\cpuz137_x64.sys" (REG_EXPAND_SZ) 838. 839. [HKU\.DEFAULT\Environment] 840. "TEMP"="%USERPROFILE%\AppData\Local\Temp" (REG_EXPAND_SZ) 841. 842. [HKU\.DEFAULT\Environment] 843. "TMP"="%USERPROFILE%\AppData\Local\Temp" (REG_EXPAND_SZ) 844. 845. [HKU\.DEFAULT\Software\AppDataLow] 846. DA: 13/03/2016 01:45:39 847. 848. [HKU\.DEFAULT\Software\Microsoft\GDIPlus] 849. "FontCachePath"="C:\Users\Centrale\AppData\Local" (REG_SZ) 850. 851. [HKU\.DEFAULT\Software\Microsoft\MediaPlayer\Preferences] 852. "ObfuscatedSyncPlaylistsPath"="C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\fr-FR\0006CB4A" (REG_SZ) 853. 854. [HKU\.DEFAULT\Software\Microsoft\MediaPlayer\Setup\CreatedLinks] 855. "Shortcut0"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk" (REG_SZ) 856. 857. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo\Volume{501d2792-32d5-11e4-9ec6-806e6f6e6963}] 858. "StagingPath"="C:\Users\Default\AppData\Local\Microsoft\Windows\Burn\Burn" (REG_SZ) 859. 860. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 861. "Local AppData"="C:\Users\Default\AppData\Local" (REG_SZ) 862. 863. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 864. "AppData"="C:\Users\Default\AppData\Roaming" (REG_SZ) 865. 866. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 867. "History"="C:\Users\Default\AppData\Local\Microsoft\Windows\History" (REG_SZ) 868. 869. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 870. "NetHood"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts" (REG_SZ) 871. 872. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 873. "Cookies"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies" (REG_SZ) 874. 875. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 876. "SendTo"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo" (REG_SZ) 877. 878. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 879. "Start Menu"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu" (REG_SZ) 880. 881. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 882. "Programs"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" (REG_SZ) 883. 884. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 885. "Recent"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent" (REG_SZ) 886. 887. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 888. "CD Burning"="C:\Users\Default\AppData\Local\Microsoft\Windows\Burn\Burn" (REG_SZ) 889. 890. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 891. "PrintHood"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" (REG_SZ) 892. 893. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 894. "Startup"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" (REG_SZ) 895. 896. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 897. "Administrative Tools"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools" (REG_SZ) 898. 899. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 900. "Cache"="C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files" (REG_SZ) 901. 902. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 903. "Templates"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates" (REG_SZ) 904. 905. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 906. "AppData"="%USERPROFILE%\AppData\Roaming" (REG_EXPAND_SZ) 907. 908. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 909. "NetHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts" (REG_EXPAND_SZ) 910. 911. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 912. "PrintHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" (REG_EXPAND_SZ) 913. 914. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 915. "Programs"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" (REG_EXPAND_SZ) 916. 917. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 918. "Recent"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent" (REG_EXPAND_SZ) 919. 920. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 921. "SendTo"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo" (REG_EXPAND_SZ) 922. 923. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 924. "Start Menu"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu" (REG_EXPAND_SZ) 925. 926. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 927. "Startup"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" (REG_EXPAND_SZ) 928. 929. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 930. "Templates"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates" (REG_EXPAND_SZ) 931. 932. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 933. "Cookies"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies" (REG_EXPAND_SZ) 934. 935. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 936. "Local AppData"="%USERPROFILE%\AppData\Local" (REG_EXPAND_SZ) 937. 938. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 939. "Cache"="%USERPROFILE%\AppData\Local\Microsoft\Windows\Temporary Internet Files" (REG_EXPAND_SZ) 940. 941. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 942. "History"="%USERPROFILE%\AppData\Local\Microsoft\Windows\History" (REG_EXPAND_SZ) 943. 944. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat] 945. "CachePath"="%USERPROFILE%\AppData\Local\Microsoft\Feeds Cache" (REG_EXPAND_SZ) 946. 947. [HKU\.DEFAULT\Software\Microsoft\Windows Mail] 948. "Store Root"="%USERPROFILE%\AppData\Local\Microsoft\Windows Mail\" (REG_EXPAND_SZ) 949. 950. [HKU\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\Namespace] 951. "LocalBase"="C:\Users\Default\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNS.XML" (REG_SZ) 952. 953. [HKU\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\Namespace] 954. "DTDFile"="C:\Users\Default\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNS.DTD" (REG_SZ) 955. 956. [HKU\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\Namespace] 957. "LocalDelta"="C:\Users\Default\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNSD.XML" (REG_SZ) 958. 959. [HKU\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\Namespace] 960. "RemoteDelta"="C:\Users\Default\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNSR.XML" (REG_SZ) 961. 962. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 963. "AppData"="%USERPROFILE%\AppData\Roaming" (REG_EXPAND_SZ) 964. 965. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 966. "NetHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts" (REG_EXPAND_SZ) 967. 968. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 969. "PrintHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" (REG_EXPAND_SZ) 970. 971. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 972. "Programs"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" (REG_EXPAND_SZ) 973. 974. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 975. "Recent"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent" (REG_EXPAND_SZ) 976. 977. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 978. "SendTo"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo" (REG_EXPAND_SZ) 979. 980. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 981. "Start Menu"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu" (REG_EXPAND_SZ) 982. 983. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 984. "Startup"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" (REG_EXPAND_SZ) 985. 986. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 987. "Templates"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates" (REG_EXPAND_SZ) 988. 989. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 990. "Cookies"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies" (REG_EXPAND_SZ) 991. 992. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 993. "Local AppData"="%USERPROFILE%\AppData\Local" (REG_EXPAND_SZ) 994. 995. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 996. "Cache"="%USERPROFILE%\AppData\Local\Microsoft\Windows\Temporary Internet Files" (REG_EXPAND_SZ) 997. 998. [HKU\.DEFAULT\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 999. "History"="%USERPROFILE%\AppData\Local\Microsoft\Windows\History" (REG_EXPAND_SZ) 1000. 1001. [HKU\S-1-5-19\Environment] 1002. "TEMP"="%USERPROFILE%\AppData\Local\Temp" (REG_EXPAND_SZ) 1003. 1004. [HKU\S-1-5-19\Environment] 1005. "TMP"="%USERPROFILE%\AppData\Local\Temp" (REG_EXPAND_SZ) 1006. 1007. [HKU\S-1-5-19\Software\AppDataLow] 1008. DA: 05/03/2016 02:12:12 1009. 1010. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1011. "AppData"="%USERPROFILE%\AppData\Roaming" (REG_EXPAND_SZ) 1012. 1013. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1014. "Cache"="%USERPROFILE%\AppData\Local\Microsoft\Windows\Temporary Internet Files" (REG_EXPAND_SZ) 1015. 1016. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1017. "Cookies"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies" (REG_EXPAND_SZ) 1018. 1019. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1020. "History"="%USERPROFILE%\AppData\Local\Microsoft\Windows\History" (REG_EXPAND_SZ) 1021. 1022. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1023. "Local AppData"="%USERPROFILE%\AppData\Local" (REG_EXPAND_SZ) 1024. 1025. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1026. "NetHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts" (REG_EXPAND_SZ) 1027. 1028. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1029. "PrintHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" (REG_EXPAND_SZ) 1030. 1031. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1032. "Programs"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" (REG_EXPAND_SZ) 1033. 1034. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1035. "Recent"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent" (REG_EXPAND_SZ) 1036. 1037. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1038. "SendTo"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo" (REG_EXPAND_SZ) 1039. 1040. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1041. "Startup"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" (REG_EXPAND_SZ) 1042. 1043. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1044. "Start Menu"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu" (REG_EXPAND_SZ) 1045. 1046. [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1047. "Templates"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates" (REG_EXPAND_SZ) 1048. 1049. [HKU\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 1050. "ExcludeProfileDirs"="AppData\Local;AppData\LocalLow;$Recycle.Bin" (REG_SZ) 1051. 1052. [HKU\S-1-5-20\Environment] 1053. "TEMP"="%USERPROFILE%\AppData\Local\Temp" (REG_EXPAND_SZ) 1054. 1055. [HKU\S-1-5-20\Environment] 1056. "TMP"="%USERPROFILE%\AppData\Local\Temp" (REG_EXPAND_SZ) 1057. 1058. [HKU\S-1-5-20\Software\AppDataLow] 1059. DA: 05/03/2016 02:12:12 1060. 1061. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1062. "AppData"="%USERPROFILE%\AppData\Roaming" (REG_EXPAND_SZ) 1063. 1064. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1065. "Cache"="%USERPROFILE%\AppData\Local\Microsoft\Windows\Temporary Internet Files" (REG_EXPAND_SZ) 1066. 1067. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1068. "Cookies"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies" (REG_EXPAND_SZ) 1069. 1070. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1071. "History"="%USERPROFILE%\AppData\Local\Microsoft\Windows\History" (REG_EXPAND_SZ) 1072. 1073. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1074. "Local AppData"="%USERPROFILE%\AppData\Local" (REG_EXPAND_SZ) 1075. 1076. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1077. "NetHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts" (REG_EXPAND_SZ) 1078. 1079. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1080. "PrintHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" (REG_EXPAND_SZ) 1081. 1082. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1083. "Programs"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" (REG_EXPAND_SZ) 1084. 1085. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1086. "Recent"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent" (REG_EXPAND_SZ) 1087. 1088. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1089. "SendTo"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo" (REG_EXPAND_SZ) 1090. 1091. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1092. "Startup"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" (REG_EXPAND_SZ) 1093. 1094. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1095. "Start Menu"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu" (REG_EXPAND_SZ) 1096. 1097. [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1098. "Templates"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates" (REG_EXPAND_SZ) 1099. 1100. [HKU\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 1101. "ExcludeProfileDirs"="AppData\Local;AppData\LocalLow;$Recycle.Bin" (REG_SZ) 1102. 1103. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Environment] 1104. "TEMP"="%USERPROFILE%\AppData\Local\Temp" (REG_EXPAND_SZ) 1105. 1106. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Environment] 1107. "TMP"="%USERPROFILE%\AppData\Local\Temp" (REG_EXPAND_SZ) 1108. 1109. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\AdblockPlus] 1110. "AppDataFolder"="C:\Program Files\Adblock Plus for IE\" (REG_SZ) 1111. 1112. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\AppDataLow] 1113. DA: 13/03/2016 01:59:22 1114. 1115. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Apple Computer, Inc.\QuickTime\LocalUserPreferences] 1116. "FolderPath"="C:\Users\Centrale\AppData\LocalLow\Apple Computer\QuickTime\" (REG_SZ) 1117. 1118. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\GDIPlus] 1119. "FontCachePath"="C:\Users\Centrale\AppData\Local" (REG_SZ) 1120. 1121. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths] 1122. "C:\Users\Centrale\AppData\LocalLow"="" () 1123. 1124. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths] 1125. "C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\Cookies"="" () 1126. 1127. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths] 1128. "C:\Users\Centrale\AppData\Local\Microsoft\Windows\History"="" () 1129. 1130. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths] 1131. "C:\Users\Centrale\AppData\Local\Microsoft\Windows\Temporary Internet Files"="" () 1132. 1133. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths] 1134. "C:\Users\Centrale\AppData\Local\Microsoft\Feeds"="" () 1135. 1136. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths] 1137. "C:\Users\Centrale\AppData\Local\Temp\Low"="" () 1138. 1139. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths] 1140. "C:\Users\Centrale\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized"="" () 1141. 1142. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] 1143. "FaviconPath"="C:\Users\Centrale\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico" (REG_SZ) 1144. 1145. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\MediaPlayer\Preferences] 1146. "ObfuscatedSyncPlaylistsPath"="C:\Users\Centrale\AppData\Local\Microsoft\Media Player\Sync Playlists\fr-FR\00048333" (REG_SZ) 1147. 1148. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\MediaPlayer\Services\MusicType1VirginMegaFr] 1149. "CachedLargeLogoPath"="C:\Users\Centrale\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ZNGWMO\ServiceLargeURL11[1].png" (REG_SZ) 1150. 1151. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\MediaPlayer\Services\MusicType1VirginMegaFr] 1152. "CachedSmallLogoPath"="C:\Users\Centrale\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\76YFQ89A\ServiceSmallURL[1].png" (REG_SZ) 1153. 1154. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\MediaPlayer\Services\MusicType1VirginMegaFr] 1155. "CachedIconPath"="C:\Users\Centrale\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30ZNGWMO\MenuURLMusic[1].png" (REG_SZ) 1156. 1157. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\MediaPlayer\Setup\CreatedLinks] 1158. "Shortcut0"="C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk" (REG_SZ) 1159. 1160. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\MediaPlayer\Setup\CreatedLinks] 1161. "Shortcut1"="C:\Users\Centrale\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk" (REG_SZ) 1162. 1163. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo\Volume{501d2792-32d5-11e4-9ec6-806e6f6e6963}] 1164. "StagingPath"="C:\Users\Centrale\AppData\Local\Microsoft\Windows\Burn\Burn" (REG_SZ) 1165. 1166. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1167. "Local AppData"="C:\Users\Centrale\AppData\Local" (REG_SZ) 1168. 1169. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1170. "AppData"="C:\Users\Centrale\AppData\Roaming" (REG_SZ) 1171. 1172. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1173. "History"="C:\Users\Centrale\AppData\Local\Microsoft\Windows\History" (REG_SZ) 1174. 1175. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1176. "NetHood"="C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\Network Shortcuts" (REG_SZ) 1177. 1178. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1179. "Cookies"="C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\Cookies" (REG_SZ) 1180. 1181. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1182. "SendTo"="C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\SendTo" (REG_SZ) 1183. 1184. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1185. "Start Menu"="C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\Start Menu" (REG_SZ) 1186. 1187. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1188. "Programs"="C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" (REG_SZ) 1189. 1190. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1191. "Recent"="C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\Recent" (REG_SZ) 1192. 1193. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1194. "CD Burning"="C:\Users\Centrale\AppData\Local\Microsoft\Windows\Burn\Burn" (REG_SZ) 1195. 1196. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1197. "PrintHood"="C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" (REG_SZ) 1198. 1199. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1200. "Startup"="C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" (REG_SZ) 1201. 1202. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1203. "Administrative Tools"="C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools" (REG_SZ) 1204. 1205. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1206. "Cache"="C:\Users\Centrale\AppData\Local\Microsoft\Windows\Temporary Internet Files" (REG_SZ) 1207. 1208. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1209. "Templates"="C:\Users\Centrale\AppData\Roaming\Microsoft\Windows\Templates" (REG_SZ) 1210. 1211. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1212. "AppData"="%USERPROFILE%\AppData\Roaming" (REG_EXPAND_SZ) 1213. 1214. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1215. "Cache"="%USERPROFILE%\AppData\Local\Microsoft\Windows\Temporary Internet Files" (REG_EXPAND_SZ) 1216. 1217. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1218. "Cookies"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies" (REG_EXPAND_SZ) 1219. 1220. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1221. "History"="%USERPROFILE%\AppData\Local\Microsoft\Windows\History" (REG_EXPAND_SZ) 1222. 1223. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1224. "Local AppData"="%USERPROFILE%\AppData\Local" (REG_EXPAND_SZ) 1225. 1226. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1227. "NetHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts" (REG_EXPAND_SZ) 1228. 1229. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1230. "PrintHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" (REG_EXPAND_SZ) 1231. 1232. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1233. "Programs"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" (REG_EXPAND_SZ) 1234. 1235. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1236. "Recent"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent" (REG_EXPAND_SZ) 1237. 1238. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1239. "SendTo"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo" (REG_EXPAND_SZ) 1240. 1241. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1242. "Startup"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" (REG_EXPAND_SZ) 1243. 1244. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1245. "Start Menu"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu" (REG_EXPAND_SZ) 1246. 1247. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1248. "Templates"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates" (REG_EXPAND_SZ) 1249. 1250. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat] 1251. "CachePath"="%USERPROFILE%\AppData\Local\Microsoft\Feeds Cache" (REG_EXPAND_SZ) 1252. 1253. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat] 1254. "CachePath"="%APPDATA%\Microsoft\Windows\IECompatCache" (REG_EXPAND_SZ) 1255. 1256. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iedownload] 1257. "CachePath"="%APPDATA%\Microsoft\Windows\IEDownloadHistory" (REG_EXPAND_SZ) 1258. 1259. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld] 1260. "CachePath"="%APPDATA%\Microsoft\Windows\IETldCache" (REG_EXPAND_SZ) 1261. 1262. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:] 1263. "CachePath"="%APPDATA%\Microsoft\Windows\PrivacIE" (REG_EXPAND_SZ) 1264. 1265. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\DOMStore] 1266. "CachePath"="%USERPROFILE%\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore" (REG_EXPAND_SZ) 1267. 1268. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\feedplat] 1269. "CachePath"="%USERPROFILE%\AppData\Local\Microsoft\Feeds Cache" (REG_EXPAND_SZ) 1270. 1271. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\iecompat] 1272. "CachePath"="%APPDATA%\Microsoft\Windows\IECompatCache\Low" (REG_EXPAND_SZ) 1273. 1274. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\iedownload] 1275. "CachePath"="%APPDATA%\Microsoft\Windows\IEDownloadHistory" (REG_EXPAND_SZ) 1276. 1277. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\ietld] 1278. "CachePath"="%APPDATA%\Microsoft\Windows\IETldCache\Low" (REG_EXPAND_SZ) 1279. 1280. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\PrivacIE:] 1281. "CachePath"="%APPDATA%\Microsoft\Windows\PrivacIE\Low" (REG_EXPAND_SZ) 1282. 1283. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows Mail] 1284. "Store Root"="%USERPROFILE%\AppData\Local\Microsoft\Windows Mail\" (REG_EXPAND_SZ) 1285. 1286. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows Media\WMSDK\Namespace] 1287. "LocalBase"="C:\Users\Centrale\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNS.XML" (REG_SZ) 1288. 1289. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows Media\WMSDK\Namespace] 1290. "DTDFile"="C:\Users\Centrale\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNS.DTD" (REG_SZ) 1291. 1292. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows Media\WMSDK\Namespace] 1293. "LocalDelta"="C:\Users\Centrale\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNSD.XML" (REG_SZ) 1294. 1295. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows Media\WMSDK\Namespace] 1296. "RemoteDelta"="C:\Users\Centrale\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNSR.XML" (REG_SZ) 1297. 1298. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 1299. "ExcludeProfileDirs"="AppData\Local;AppData\LocalLow;$Recycle.Bin" (REG_SZ) 1300. 1301. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] 1302. "C:\Users\Centrale\AppData\Local\Temp\is-GMNAQ.tmp\is-KC2IF.tmp"="Setup/Uninstall" (REG_SZ) 1303. 1304. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Volatile Environment] 1305. "APPDATA"="C:\Users\Centrale\AppData\Roaming" (REG_SZ) 1306. 1307. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000\Volatile Environment] 1308. "LOCALAPPDATA"="C:\Users\Centrale\AppData\Local" (REG_SZ) 1309. 1310. [HKU\S-1-5-21-2605355984-3802085725-3497844330-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] 1311. "C:\Users\Centrale\AppData\Local\Temp\is-GMNAQ.tmp\is-KC2IF.tmp"="Setup/Uninstall" (REG_SZ) 1312. 1313. [HKU\S-1-5-18\Environment] 1314. "TEMP"="%USERPROFILE%\AppData\Local\Temp" (REG_EXPAND_SZ) 1315. 1316. [HKU\S-1-5-18\Environment] 1317. "TMP"="%USERPROFILE%\AppData\Local\Temp" (REG_EXPAND_SZ) 1318. 1319. [HKU\S-1-5-18\Software\AppDataLow] 1320. DA: 13/03/2016 01:45:39 1321. 1322. [HKU\S-1-5-18\Software\Microsoft\GDIPlus] 1323. "FontCachePath"="C:\Users\Centrale\AppData\Local" (REG_SZ) 1324. 1325. [HKU\S-1-5-18\Software\Microsoft\MediaPlayer\Preferences] 1326. "ObfuscatedSyncPlaylistsPath"="C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\fr-FR\0006CB4A" (REG_SZ) 1327. 1328. [HKU\S-1-5-18\Software\Microsoft\MediaPlayer\Setup\CreatedLinks] 1329. "Shortcut0"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk" (REG_SZ) 1330. 1331. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo\Volume{501d2792-32d5-11e4-9ec6-806e6f6e6963}] 1332. "StagingPath"="C:\Users\Default\AppData\Local\Microsoft\Windows\Burn\Burn" (REG_SZ) 1333. 1334. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1335. "Local AppData"="C:\Users\Default\AppData\Local" (REG_SZ) 1336. 1337. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1338. "AppData"="C:\Users\Default\AppData\Roaming" (REG_SZ) 1339. 1340. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1341. "History"="C:\Users\Default\AppData\Local\Microsoft\Windows\History" (REG_SZ) 1342. 1343. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1344. "NetHood"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts" (REG_SZ) 1345. 1346. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1347. "Cookies"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies" (REG_SZ) 1348. 1349. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1350. "SendTo"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo" (REG_SZ) 1351. 1352. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1353. "Start Menu"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu" (REG_SZ) 1354. 1355. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1356. "Programs"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" (REG_SZ) 1357. 1358. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1359. "Recent"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent" (REG_SZ) 1360. 1361. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1362. "CD Burning"="C:\Users\Default\AppData\Local\Microsoft\Windows\Burn\Burn" (REG_SZ) 1363. 1364. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1365. "PrintHood"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" (REG_SZ) 1366. 1367. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1368. "Startup"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" (REG_SZ) 1369. 1370. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1371. "Administrative Tools"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools" (REG_SZ) 1372. 1373. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1374. "Cache"="C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files" (REG_SZ) 1375. 1376. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] 1377. "Templates"="C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates" (REG_SZ) 1378. 1379. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1380. "AppData"="%USERPROFILE%\AppData\Roaming" (REG_EXPAND_SZ) 1381. 1382. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1383. "NetHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts" (REG_EXPAND_SZ) 1384. 1385. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1386. "PrintHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" (REG_EXPAND_SZ) 1387. 1388. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1389. "Programs"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" (REG_EXPAND_SZ) 1390. 1391. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1392. "Recent"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent" (REG_EXPAND_SZ) 1393. 1394. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1395. "SendTo"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo" (REG_EXPAND_SZ) 1396. 1397. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1398. "Start Menu"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu" (REG_EXPAND_SZ) 1399. 1400. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1401. "Startup"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" (REG_EXPAND_SZ) 1402. 1403. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1404. "Templates"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates" (REG_EXPAND_SZ) 1405. 1406. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1407. "Cookies"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies" (REG_EXPAND_SZ) 1408. 1409. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1410. "Local AppData"="%USERPROFILE%\AppData\Local" (REG_EXPAND_SZ) 1411. 1412. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1413. "Cache"="%USERPROFILE%\AppData\Local\Microsoft\Windows\Temporary Internet Files" (REG_EXPAND_SZ) 1414. 1415. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1416. "History"="%USERPROFILE%\AppData\Local\Microsoft\Windows\History" (REG_EXPAND_SZ) 1417. 1418. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat] 1419. "CachePath"="%USERPROFILE%\AppData\Local\Microsoft\Feeds Cache" (REG_EXPAND_SZ) 1420. 1421. [HKU\S-1-5-18\Software\Microsoft\Windows Mail] 1422. "Store Root"="%USERPROFILE%\AppData\Local\Microsoft\Windows Mail\" (REG_EXPAND_SZ) 1423. 1424. [HKU\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\Namespace] 1425. "LocalBase"="C:\Users\Default\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNS.XML" (REG_SZ) 1426. 1427. [HKU\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\Namespace] 1428. "DTDFile"="C:\Users\Default\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNS.DTD" (REG_SZ) 1429. 1430. [HKU\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\Namespace] 1431. "LocalDelta"="C:\Users\Default\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNSD.XML" (REG_SZ) 1432. 1433. [HKU\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\Namespace] 1434. "RemoteDelta"="C:\Users\Default\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNSR.XML" (REG_SZ) 1435. 1436. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1437. "AppData"="%USERPROFILE%\AppData\Roaming" (REG_EXPAND_SZ) 1438. 1439. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1440. "NetHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts" (REG_EXPAND_SZ) 1441. 1442. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1443. "PrintHood"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts" (REG_EXPAND_SZ) 1444. 1445. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1446. "Programs"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs" (REG_EXPAND_SZ) 1447. 1448. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1449. "Recent"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent" (REG_EXPAND_SZ) 1450. 1451. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1452. "SendTo"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo" (REG_EXPAND_SZ) 1453. 1454. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1455. "Start Menu"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu" (REG_EXPAND_SZ) 1456. 1457. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1458. "Startup"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" (REG_EXPAND_SZ) 1459. 1460. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1461. "Templates"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates" (REG_EXPAND_SZ) 1462. 1463. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1464. "Cookies"="%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies" (REG_EXPAND_SZ) 1465. 1466. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1467. "Local AppData"="%USERPROFILE%\AppData\Local" (REG_EXPAND_SZ) 1468. 1469. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1470. "Cache"="%USERPROFILE%\AppData\Local\Microsoft\Windows\Temporary Internet Files" (REG_EXPAND_SZ) 1471. 1472. [HKU\S-1-5-18\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] 1473. "History"="%USERPROFILE%\AppData\Local\Microsoft\Windows\History" (REG_EXPAND_SZ) 1474. 1475. ========================= 1476. 1477. Fin à: 15:22:48 le 13/03/2016 1478. 315558 Éléments analysés 1479. 1480. ========================= 1481. E.O.F