¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ QuickDiag | g3n-h@ckm@n | 2_04.04.2016.1 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ¤¤¤¤¤ XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ¤¤¤¤¤ - Start 16/04/2016 11:20:30 Updated 04/04/2016 | 18.05 by g3n-h@ckm@n Contact : http://www.sosvirus.net/ [magali (Administrator)] - [MAGALI-PC] SID = S-1-5-21-1125036280-3562319748-3601731155-1000 System : Windows 7 Home Premium (64 bits) HomePremium Service Pack 1 PC : SAMSUNG ELECTRONICS CO., LTD. - R530/R730/P530 - Processor : X64 - 1995 Mhz - Intel(R) Pentium(R) CPU P6100 @ 2.00GHz Bios : Phoenix Technologies Ltd. - 06/21/2010 - V.04KQ.M007.20100621.KSJ CoreTemp : 51° C - Max : 89° C Boot: Normal boot ----------> Quick Memory RAM = Total (MB) : 4052 | Free (MB) : 1630 Pagefile = Total (MB) : 8101 | Free (MB) : 5270 Virtual = Total (MB) : 4194 | Free (MB) : 4054 ¤¤¤¤¤¤¤¤¤¤ | Drives D:\ -> [Fixed] | [] | Total : 266.66 Go | Free : 135.16 Go -> NTFS [ATA] C:\ -> [Fixed] | [] | Total : 179 Go | Free : 91.1 Go -> NTFS [ATA] ¤¤¤¤¤¤¤¤¤¤ | Windows updates Last detection : 2016-04-15 19:11:01 Downloaded last ones : 2016-04-15 19:54:21 Installed last ones : 2016-04-15 19:56:27 Next search : 2016-04-16 14:06:26 Microsoft : + ¤¤¤¤¤¤¤¤¤¤ | Browsers IE : 11.0.9600.18283 (© Microsoft Corporation. Tous droits réservés.) GC : 49.0.2623.112 (Copyright 2015 Google Inc.) Default : "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" ¤¤¤¤¤¤¤¤¤¤ | FlashPlayer FlashPlayer ActiveX : 21.0.0.213 FlashPlayer Plugin : 21.0.0.213 ¤¤¤¤¤¤¤¤¤¤ | Security AV : AS : Windows Defender Enabled AM : Malwarebytes' Anti-Malware ( 2.3.173.0) [Update : 08/12/2014 18:01:34] FW : WINDOWS Firewall WMI : OK WU: Windows Update Service [Auto(2)] = Running AS: Windows Defender [Auto(2)] = Running WMI: Windows Management Instrumentation [Auto(2)] = Running ¤¤¤¤¤¤¤¤¤¤ | Running processes 300 | [Owner : Système | Parent : 4(System) | ?????] - (.Microsoft Corporation - Gestionnaire de sessions Windows.) - (6.1.7601.23392) = C:\Windows\System32\smss.exe 508 | [Owner : | Parent : 444() | ?????] - (.Microsoft Corporation - Application de démarrage de Windows.) - (6.1.7600.16385) = C:\Windows\System32\wininit.exe 568 | [Owner : | Parent : 508(wininit.exe) | ?????] - (.Microsoft Corporation - Applications Services et Contrôleur.) - (6.1.7601.18829) = C:\Windows\System32\services.exe 584 | [Owner : | Parent : 508(wininit.exe) | ?????] - (.Microsoft Corporation - Local Security Authority Process.) - (6.1.7601.23392) = C:\Windows\System32\lsass.exe 592 | [Owner : | Parent : 508(wininit.exe) | ?????] - (.Microsoft Corporation - Service du gestionnaire de session locale.) - (6.1.7601.17514) = C:\Windows\System32\lsm.exe 652 | [Owner : | Parent : 500() | ?????] - (.Microsoft Corporation - Application d’ouverture de session Windows.) - (6.1.7601.18540) = C:\Windows\System32\winlogon.exe 732 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 800 | [Owner : | Parent : 568(services.exe) | ?????] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 189.11.) - (8.16.11.8911) = C:\Windows\System32\nvvsvc.exe 832 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 936 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 976 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 1004 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 320 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 688 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 1084 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 1192 | [Owner : | Parent : 800(nvvsvc.exe) | ?????] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 189.11.) - (8.16.11.8911) = C:\Windows\System32\nvvsvc.exe 1296 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Application sous-système spouleur.) - (6.1.7601.17777) = C:\Windows\System32\spoolsv.exe 1340 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 1440 | [Owner : | Parent : 568(services.exe) | ?????] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - (1.824.16.6751) = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 1584 | [Owner : | Parent : 568(services.exe) | ?????] - (.Devguru Co., Ltd. - Device Error Recovery SDK(x64).) - (1.3.950.0) = C:\Windows\System32\dgdersvc.exe 1612 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 1676 | [Owner : | Parent : 568(services.exe) | ?????] - (.LeapFrog Enterprises, Inc. - CommandService Application.) - (6.1.1.0) = C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe 1724 | [Owner : magali | Parent : 976(svchost.exe) | 34.39 Mo] - (.Microsoft Corporation - Gestionnaire de fenêtres du Bureau.) - (6.1.7600.16385) = C:\Windows\System32\dwm.exe 1780 | [Owner : magali | Parent : 1716() | 51.21 Mo] - (.Microsoft Corporation - Explorateur Windows.) - (6.1.7601.19135) = C:\Windows\explorer.exe 1888 | [Owner : | Parent : 568(services.exe) | ?????] - (.Malwarebytes - Malwarebytes Anti-Malware.) - (3.1.7.0) = C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe 460 | [Owner : | Parent : 568(services.exe) | ?????] - (.Malwarebytes - Malwarebytes Anti-Malware.) - (3.2.21.0) = C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe 1696 | [Owner : magali | Parent : 1888(mbamscheduler.exe) | 72.78 Mo] - (.Malwarebytes - Malwarebytes Anti-Malware.) - (2.3.173.0) = C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 2004 | [Owner : | Parent : 568(services.exe) | ?????] - (.-.) - (500.2001.208.2009) = C:\Windows\SysWOW64\Rezip.exe 1492 | [Owner : | Parent : 568(services.exe) | ?????] - (.- RichVideo Module.) - (2.0.0.3027) = C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2072 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corp. - Microsoft® Windows Live ID Service.) - (7.250.4232.0) = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 2184 | [Owner : | Parent : 2072(WLIDSVC.EXE) | ?????] - (.Microsoft Corp. - Microsoft® Windows Live ID Service Monitor.) - (7.250.4232.0) = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE 2520 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 2904 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - (7.0.7601.17610) = C:\Windows\System32\SearchIndexer.exe 5072 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 1144 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) = C:\Windows\System32\svchost.exe 3092 | [Owner : | Parent : 568(services.exe) | ?????] - (.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) - (12.0.7601.17514) = C:\Program Files\Windows Media Player\wmpnetwk.exe 3368 | [Owner : magali | Parent : 1780(explorer.exe) | 10.74 Mo] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) - (1.0.0.984) = C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe 3296 | [Owner : magali | Parent : 1780(explorer.exe) | 13.32 Mo] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) - (15.0.22.0) = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 2564 | [Owner : magali | Parent : 1780(explorer.exe) | 7.27 Mo] - (.Samsung Electronics Co., Ltd. - Kies TrayAgent Application.) - (1.5.0.80) = C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe 4476 | [Owner : magali | Parent : 1780(explorer.exe) | 20.17 Mo] - (.- Updater.) - (1.0.0.7) = C:\Program Files (x86)\Rentabiliweb\Mailorama pour internet explorer\MailoramaUpdater.exe 4932 | [Owner : magali | Parent : 1780(explorer.exe) | 89.07 Mo] - (.Spotify Ltd - Spotify.) - (1.0.26.132) = C:\Users\magali\AppData\Roaming\Spotify\Spotify.exe 4876 | [Owner : magali | Parent : 1780(explorer.exe) | 13.48 Mo] - (.Hewlett-Packard Development Company, LP - ScanToPCActivationApp.) - (32.3.198.49673) = C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe 3764 | [Owner : magali | Parent : 1780(explorer.exe) | 6.54 Mo] - (.Spotify Ltd - SpotifyWebHelper.) - (1.0.26.132) = C:\Users\magali\AppData\Roaming\Spotify\SpotifyWebHelper.exe 2724 | [Owner : magali | Parent : 732(svchost.exe) | 9.59 Mo] - (.Hewlett-Packard Development Company, LP - HPNetworkCommunicatorCom.) - (32.3.198.49673) = C:\Program Files\HP\HP ENVY 4500 series\Bin\HPNetworkCommunicatorCom.exe 4912 | [Owner : magali | Parent : 1780(explorer.exe) | 3.63 Mo] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) - (3.8.130.0) = C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe 3596 | [Owner : magali | Parent : 732(svchost.exe) | 15.11 Mo] - (.Microsoft Corporation - COM Surrogate.) - (6.1.7600.16385) = C:\Windows\System32\dllhost.exe 4524 | [Owner : magali | Parent : 3520() | 8.6 Mo] - (.CyberLink - CyberLink MediaLibray Service.) - (2.1.1803.0) = C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe 3080 | [Owner : magali | Parent : 1780(explorer.exe) | 5.49 Mo] - (.Sony Corporation - Media Check Tool.) - (1.2.0.13170) = C:\Program Files (x86)\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe 5016 | [Owner : magali | Parent : 3520() | 5.36 Mo] - (.CyberLink Corp. - PowerDVD RC Service.) - (7.0.2314.0) = C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe 1928 | [Owner : magali | Parent : 3520() | 3.76 Mo] - (.Hewlett-Packard - hpwuSchd Application.) - (80.1.1.0) = C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe 2852 | [Owner : magali | Parent : 3520() | 11.22 Mo] - (.LeapFrog Enterprises, Inc. - Monitor Application.) - (6.1.1.0) = C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe 2824 | [Owner : magali | Parent : 3296(SynTPEnh.exe) | 3.5 Mo] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) - (15.0.22.0) = C:\Program Files\Synaptics\SynTP\SynTPHelper.exe 3812 | [Owner : magali | Parent : 4932(Spotify.exe) | 5.16 Mo] - (.Spotify Ltd - SpotifyCrashService.) - (1.0.26.132) = C:\Users\magali\AppData\Roaming\Spotify\SpotifyCrashService.exe 4180 | [Owner : magali | Parent : 4932(Spotify.exe) | 44.74 Mo] - (.Spotify Ltd - Spotify.) - (1.0.26.132) = C:\Users\magali\AppData\Roaming\Spotify\Spotify.exe 1900 | [Owner : magali | Parent : 4932(Spotify.exe) | 120.43 Mo] - (.Spotify Ltd - Spotify.) - (1.0.26.132) = C:\Users\magali\AppData\Roaming\Spotify\Spotify.exe 3604 | [Owner : magali | Parent : 1780(explorer.exe) | 61.51 Mo] - (.Microsoft Corporation - Internet Explorer.) - (11.0.9600.18283) = C:\Program Files\Internet Explorer\iexplore.exe 4244 | [Owner : magali | Parent : 3604(iexplore.exe) | 434 Mo] - (.Microsoft Corporation - Internet Explorer.) - (11.0.9600.18283) = C:\Program Files (x86)\Internet Explorer\iexplore.exe 1424 | [Owner : magali | Parent : 3604(iexplore.exe) | 11.77 Mo] - (.Google Inc. - Google Toolbar Broker.) - (7.5.5111.1712) = C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe 1568 | [Owner : magali | Parent : 732(svchost.exe) | 10.98 Mo] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller 21.0 r0.) - (21.0.0.213) = C:\Windows\System32\Macromed\Flash\FlashUtil64_21_0_0_213_ActiveX.exe 1356 | [Owner : magali | Parent : 3604(iexplore.exe) | 319.66 Mo] - (.Microsoft Corporation - Internet Explorer.) - (11.0.9600.18283) = C:\Program Files (x86)\Internet Explorer\iexplore.exe 3464 | [Owner : magali | Parent : 2904(SearchIndexer.exe) | 7.31 Mo] - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) - (7.0.7601.17610) = C:\Windows\System32\SearchProtocolHost.exe 168 | [Owner : | Parent : 936(svchost.exe) | ?????] - (.Microsoft Corporation - Isolation graphique de périphérique audio Windows.) - (6.1.7601.18741) = C:\Windows\System32\audiodg.exe 4780 | [Owner : magali | Parent : 3604(iexplore.exe) | 15.79 Mo] - (.SosVirus - QuickDiag.) - (4.4.2016.1) = C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3AZXULE2\QuickDiag.exe ¤¤¤¤¤¤¤¤¤¤ | MD5 [MD5.9D77CC4A36FEEA644D002CFB9B2D42C0] - [10/02/2016 14:29:58] - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [3155.5 Ko] - (6.1.7601.19135) : C:\windows\Explorer.exe [MD5.5746BD7E255DD6A8AFA06F7C42C1BA41] - [02/10/2012 22:06:51] - (.© Microsoft Corporation. Tous droits réservés. - Interpréteur de commandes Windows.) - [337 Ko] - (6.1.7601.17514) : C:\windows\System32\cmd.exe [MD5.60C2862B4BF0FD9F582EF344C2B1EC72] - [14/07/2009 01:19:49] - (.© Microsoft Corporation. Tous droits réservés. - Processus d’exécution client-serveur.) - [7.5 Ko] - (6.1.7600.16385) : C:\windows\System32\csrss.exe [MD5.A8EDB86FC2A4D6D1285E4C70384AC35A] - [14/07/2009 01:59:17] - (.© Microsoft Corporation. - COM Surrogate.) - [9.5 Ko] - (6.1.7600.16385) : C:\windows\System32\dllhost.exe [MD5.B46D03BABD31B23E6FCB226CB22D4D6B] - [13/04/2016 11:30:26] - (.© Microsoft Corporation. Tous droits réservés. - DLL du client API BASE Windows NT.) - [1136 Ko] - (6.1.7601.23392) : C:\windows\System32\Kernel32.dll [MD5.626BE7CD27F44185AA4DCD3603830312] - [13/04/2016 11:30:25] - (.© Microsoft Corporation. - Local Security Authority Process.) - [30 Ko] - (6.1.7601.23392) : C:\windows\System32\lsass.exe [MD5.5C627D1B1138676C0A7AB2C2C190D123] - [02/10/2012 22:07:10] - (.© Microsoft Corporation. - Distributed COM Services.) - [500 Ko] - (6.1.7601.17514) : C:\windows\System32\rpcss.dll [MD5.DD81D91FF3B0763C392422865C9AC12E] - [14/07/2009 01:57:20] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte Windows (Rundll32).) - [44.5 Ko] - (6.1.7600.16385) : C:\windows\System32\rundll32.exe [MD5.71C85477DF9347FE8E7BC55768473FCA] - [13/05/2015 09:49:59] - (.© Microsoft Corporation. Tous droits réservés. - Applications Services et Contrôleur.) - [321 Ko] - (6.1.7601.18829) : C:\windows\System32\services.exe [MD5.C78655BC80301D76ED4FEF1C1EA40A7D] - [14/07/2009 01:31:13] - (.© Microsoft Corporation. Tous droits réservés. - Processus hôte pour les services Windows.) - [26.5 Ko] - (6.1.7600.16385) : C:\windows\System32\svchost.exe [MD5.06BF84D26A05D400F6B3FB3D3DE0B03A] - [11/12/2015 12:02:14] - (.© Microsoft Corporation. Tous droits réservés. - DLL client de l’API uilisateur de Windows multi-utilisateurs.) - [985 Ko] - (6.1.7601.19061) : C:\windows\System32\user32.dll [MD5.BAFE84E637BF7388C96EF48D4D3FDD53] - [02/10/2012 22:05:22] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Userinit.) - [30 Ko] - (6.1.7601.17514) : C:\windows\System32\userinit.exe [MD5.94355C28C1970635A31B3FE52EB7CEBA] - [14/07/2009 01:52:37] - (.© Microsoft Corporation. Tous droits réservés. - Application de démarrage de Windows.) - [126 Ko] - (6.1.7600.16385) : C:\windows\System32\Wininit.exe [MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - [16/10/2014 14:54:12] - (.© Microsoft Corporation. Tous droits réservés. - Application d’ouverture de session Windows.) - [444.5 Ko] - (6.1.7601.18540) : C:\windows\System32\Winlogon.exe [MD5.9A4A1EEE802BF2F878EE8EAB407B21B7] - [11/11/2015 13:23:04] - (.© Microsoft Corporation. Tous droits réservés. - Ancillary Function Driver for WinSock.) - [486 Ko] - (6.1.7601.19031) : C:\windows\System32\Drivers\afd.sys [MD5.02062C0B390B7729EDC9E69C680A6F3C] - [14/07/2009 01:19:47] - (.© Microsoft Corporation. - ATAPI IDE Miniport Driver.) - [23.56 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\atapi.sys [MD5.059F00DEF82BF41E433B7ED465847726] - [11/09/2013 16:13:51] - (.© Microsoft Corporation. - ATAPI Driver Extension.) - [151.94 Ko] - (6.1.7601.18231) : C:\windows\System32\Drivers\ataport.sys [MD5.B8BD2BB284668C84865658C77574381A] - [14/07/2009 01:19:47] - (.© Microsoft Corporation. - CD-ROM File System Driver.) - [90 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\cdfs.sys [MD5.F036CE71586E93D94DAB220D7BDF4416] - [02/10/2012 22:04:08] - (.© Microsoft Corporation. - SCSI CD-ROM Driver.) - [144 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\cdrom.sys [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - [02/10/2012 22:04:24] - (.© Microsoft Corporation. - DFS Namespace Client Driver.) - [100 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\dfsc.sys [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - [02/10/2012 22:04:07] - (.© Microsoft Corporation. - High Definition Audio Bus Driver.) - [119.5 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\hdaudbus.sys [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - [14/07/2009 01:19:58] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port i8042.) - [103 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\i8042prt.sys [MD5.A5F72BB0D024E7E463344105BE613AE4] - [25/10/2010 08:20:10] - (.Copyright(C) Intel Corporation 1994-2010 - Intel Rapid Storage Technology driver - x64.) - [528.02 Ko] - (9.6.3.1001) : C:\windows\System32\Drivers\iastor.sys [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - [14/07/2009 02:10:03] - (.© Microsoft Corporation. - IP Network Address Translator.) - [113.5 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\ipnat.sys [MD5.ACEC16415275E1AD6F7983EF472810E3] - [13/04/2016 11:30:27] - (.© Microsoft Corporation. - Windows NT SMB Minirdr.) - [156 Ko] - (6.1.7601.23392) : C:\windows\System32\Drivers\mrxsmb.sys [MD5.F7309F42555F8AAB7144A51A1F2585B0] - [11/11/2015 13:22:45] - (.© Microsoft Corporation. Tous droits réservés. - Pilote NDIS 6.20.) - [928.44 Ko] - (6.1.7601.19030) : C:\windows\System32\Drivers\ndis.sys [MD5.09594D1089C523423B32A4229263F068] - [02/10/2012 22:07:04] - (.© Microsoft Corporation. - MBT Transport driver.) - [255.5 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\netbt.sys [MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - [09/04/2014 16:04:35] - (.© Microsoft Corporation. Tous droits réservés. - Pilote du système de fichiers NT.) - [1645.44 Ko] - (6.1.7601.18378) : C:\windows\System32\Drivers\ntfs.sys [MD5.0086431C29C35BE1DBC43F52CC273887] - [14/07/2009 02:00:41] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de port parallèle.) - [95 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\parport.sys [MD5.471815800AE33E6F1C32FB1B97C490CA] - [02/10/2012 22:06:18] - (.© Microsoft Corporation. - RAS L2TP mini-port/call-manager driver.) - [126.5 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\rasl2tp.sys [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - [14/07/2009 02:09:09] - (.© Microsoft Corporation. - SMB Transport driver.) - [91 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\smb.sys [MD5.04ADD18EE5CC9FBEDAEC1DD1CD0CB45E] - [11/06/2014 07:53:32] - (.© Microsoft Corporation. Tous droits réservés. - Pilote TCP/IP.) - [1858.94 Ko] - (6.1.7601.18438) : C:\windows\System32\Drivers\tcpip.sys [MD5.AA77EB517D2F07A947294F260E3ACA83] - [11/11/2015 13:23:04] - (.© Microsoft Corporation. - TDI Translation Driver.) - [115.5 Ko] - (6.1.7601.19031) : C:\windows\System32\Drivers\tdx.sys [MD5.0D08D2F3B3FF84E433346669B5E0F639] - [02/10/2012 22:06:38] - (.© Microsoft Corporation. Tous droits réservés. - Pilote de cliché instantané du volume.) - [288.88 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\volsnap.sys ¤¤¤¤¤¤¤¤¤¤ | Locked Applications ¤¤¤¤¤¤¤¤¤¤ | Explorer.exe component call (Microsoft Files Whitelisted) ¤¤¤¤¤¤¤¤¤¤ | Svchost.exe component call (Microsoft Files Whitelisted) (.Realtek Semiconductor Corp..-.Realtek(r) LFX/GFX DSP component.) - (11.0.6000.470) -- C:\windows\system32\RltkAPO64.dll ¤¤¤¤¤¤¤¤¤¤ | ZeroAccess Check [HKLM\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll [HKLM\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\shell32.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll [HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll ¤¤¤¤¤¤¤¤¤¤ | Startings up [HKU\S-1-5-18\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\CurrentVersion\Run] "KiesTrayAgent"=C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [09/09/2010 10:34:22] "Facebook Update"="C:\Users\magali\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver "GoogleChromeAutoLaunch_DDA2A9FF4F7EFF593E1640A1EEB8B50F"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window "MailoramaUpdater.exe"=C:\Program Files (x86)\Rentabiliweb\Mailorama pour internet explorer\MailoramaUpdater.exe [08/07/2013 18:08:52] "Spotify"="C:\Users\magali\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized "HP ENVY 4500 series (NET)"="C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN46N122JY060F:NW" -scfn "HP ENVY 4500 series (NET)" -AutoStart 1 "Spotify Web Helper"="C:\Users\magali\AppData\Roaming\Spotify\SpotifyWebHelper.exe" "Flvto YouTube Downloader"="C:\Users\magali\AppData\Local\Flvto YouTube Downloader\FlvtoYoutubeDownloader.exe" /minimize [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"=C:\Windows\System32\mctadmin.exe [14/07/2009 01:54:49] [HKU\S-1-5-20\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"=C:\Windows\System32\mctadmin.exe [14/07/2009 01:54:49] [HKU\S-1-5-19\Software\Microsoft\Command Processor] "CompletionChar"=9 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=9 [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s "SynTPEnh"=%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [HKLM\Software\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] "UpdateLBPShortCut"="C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" "CLMLServer"="C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" "UpdateP2GoShortCut"="C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" "UpdatePDRShortCut"="C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0" "RemoteControl8"="C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" "PDVD8LanguageShortcut"="C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe" "UpdatePPShortCut"="C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0" "UpdatePSTShortCut"="C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" "Microsoft Default Manager"="C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume "UCam_Menu"="C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0" "tuto4pc_fr_30"= "HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [30/05/2013 14:50:10] ""= "Monitor"="C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe" [HKLM\Software\WOW6432Node\Microsoft\Command Processor] "CompletionChar"=64 "DefaultColor"=0 "EnableExtensions"=1 "PathCompletionChar"=64 ¤¤¤¤¤¤¤¤¤¤ | Startings up registry ¦ Folder ¤¤¤¤¤¤¤¤¤¤ | Other keys [HKLM\System\CurrentControlSet\Control\SecurityProviders] "SecurityProviders"=credssp.dll [HKLM\System\CurrentControlSet\Control\Terminal Server] "RCDependentServices"=CertPropSvc SessionEnv "NotificationTimeOut"=0 "SnapshotMonitors"=1 "ProductVersion"=5.1 "AllowRemoteRPC"=0 "DelayConMgrTimeout"=0 "fDenyTSConnections"=1 "StartRCM"=0 "TSAdvertise"=0 "DeleteTempDirsOnExit"=1 "fSingleSessionPerUser"=1 "PerSessionTempDir"=0 "TSUserEnabled"=0 "InstanceID"=5be01650-b005-43e6-813c-782d76d "fCredentialLessLogonSupported"=1 "fCredentialLessLogonSupportedTSS"=1 "fCredentialLessLogonSupportedKMRDP"=1 [HKLM\System\CurrentControlSet\Control\Session Manager] "CriticalSectionTimeout"=2592000 "GlobalFlag"=0 "HeapDeCommitFreeBlockThreshold"=0 "HeapDeCommitTotalFreeThreshold"=0 "HeapSegmentCommit"=0 "HeapSegmentReserve"=0 "ProcessorControl"=2 "ResourceTimeoutCount"=648000 "BootExecute"=autocheck autochk * "ExcludeFromKnownDlls"= "ObjectDirectories"=\Windows \RPC Control "ProtectionMode"=1 "NumberOfInitialSessions"=2 "SetupExecute"= "PendingFileRenameOperations"=\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\cleanup.old \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.old [HKLM\System\CurrentControlSet\Control] "PreshutdownOrder"=wuauserv gpsvc trustedinstaller "WaitToKillServiceTimeout"=12000 "CurrentUser"=USERNAME "BootDriverFlags"=0 "ServiceControlManagerExtension"=%systemroot%\system32\scext.dll "SystemStartOptions"= NOEXECUTE=OPTIN "SystemBootDevice"=multi(0)disk(0)rdisk(0)partition(3) "FirmwareBootDevice"=multi(0)disk(0)rdisk(0)partition(2) [HKLM\System\CurrentControlSet\Control\lsa] "auditbaseobjects"=0 "auditbasedirectories"=0 "crashonauditfail"=0 "fullprivilegeauditing"=0x00 "Bounds"=0x0030000000200000 "LimitBlankPasswordUse"=1 "NoLmHash"=1 "Notification Packages"=scecli "Security Packages"=kerberos msv1_0 schannel wdigest tspkg pku2u livessp "Authentication Packages"=msv1_0 "LsaPid"=584 "SecureBoot"=1 "ProductType"=3 "disabledomaincreds"=0 "everyoneincludesanonymous"=0 "forceguest"=0 "restrictanonymous"=0 "restrictanonymoussam"=1 ¤¤¤¤¤¤¤¤¤¤ | .LNK C:\Users\magali\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk (--remote-debugging-port=9223) C:\Users\magali\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk (--remote-debugging-port=9223) C:\Users\magali\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk (/SendTo) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk (/name Microsoft.EaseOfAccessCenter) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\Désinstaller CyberLink DVD Suite.lnk (/z-uninstall) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\Enregistrement en ligne.lnk (/LANG:FRA) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\Power2Go\Enregistrement en ligne.lnk (/LANG:FRA) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\PowerDirector\Désinstallez PowerDirector.lnk (-l0x00040C /z-uninstall) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\PowerDirector\Enregistrement en ligne.lnk (/LANG:Fra) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\PowerDVD 8\Désinstallez PowerDVD 8.lnk (/z-uninstall) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\PowerDVD 8\Inscription en ligne.lnk (/LANG:Fra) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\PowerProducer\Désinstaller PowerProducer.lnk (/z-uninstall) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\PowerProducer\Enregistrement en ligne.lnk (/LANG:FRA) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\Enregistrement en ligne.lnk (/LANG:FRA) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\Help.lnk (/help) C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Outil de détection de support Picture Motion Browser.lnk (/nobaloononstart) VolumeWatcherr2E16k SPUVOL~1.EXEV��>|@�>|@*�I SPUVolumeW C:\Users\Public\Desktop\HP ENVY 4500 series.lnk (-Start UDCDevicePage) C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk (/name Microsoft.DefaultPrograms) C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk (startmenu) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Default Manager.lnk (-settings) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk (/showgadgets) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk (/prefetch:1) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk (/open) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk (%SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk (-SpeechUX) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk (/res) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk (/s) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk (-NoExit -ImportSystemModules) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP490 series\MP Drivers - Programme de désinstallation.lnk (/U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP ENVY 4500 series\Désinstallation.lnk (/qb /x {9A9B64A8-A9E8-4588-B924-D1898D3E6355}) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP ENVY 4500 series\HP ENVY 4500 series.lnk (-Start UDCDevicePage) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP ENVY 4500 series\Mettre à jour l'adresse IP.lnk (/changeip "") C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP ENVY 4500 series\Programme d'amélioration des produits HP.lnk (/changesettings /UA 12.5 /DDV 0x0b00) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk (/name Microsoft.BackupAndRestore) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus\Désinstaller.lnk (C:\Program Files\McAfee Security Scan\3.8.130\McAfee.ico) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus\McAfee Security Scan Plus.lnk (SecurityScanner.dll) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Kies\Uninstall Kies.lnk (/removeonly) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk () 86EB9~1.130<�QC��QC��*�� 3.8.130h2��&C� SSSCHE~1.EXEL�&C�QC��*NQ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk (--reset-config --reset-plugins-cache vlc://quit) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk (-Iskins) ¤¤¤¤¤¤¤¤¤¤ | AppCertDlls | AppInit_DLLs [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_Dlls"=c:\progra~2\suptab\search~1.dll c:\progra~3\winspeed\winspeed.dll ¤¤¤¤¤¤¤¤¤¤ | Dnsapi.dll C:\windows\System32\dnsapi.dll -> OK : \drivers\etc\hosts C:\windows\SysWOW64\dnsapi.dll -> OK : \drivers\etc\hosts ¤¤¤¤¤¤¤¤¤¤ | Policies | Registry [HKU\S-1-5-18\Control Panel\Desktop] "DragFullWindows"=1 "FontSmoothing"=2 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "UserPreferencesMask"=0x9E3E038012000000 [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Control Panel\Desktop] "ScreenSaveActive"=1 "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "PaintDesktopVersion"=0 "RightOverlapChars"=3 "SnapSizing"=1 "TileWallpaper"=0 "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 "UserPreferencesMask"=0x9E3E078012000000 "Wallpaper"=C:\Users\magali\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg [25/02/2011 22:56:54] "LogPixels"=120 "Pattern Upgrade"=TRUE [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\CurrentVersion\Explorer] "ExplorerStartupTraceRecorded"=1 "ShellState"=0x240000003828000000000000000000000000000001000000120000000000000022000000 "CleanShutdown"=0 "link"=0x1E000000 "Browse For Folder Width"=404 "Browse For Folder Height"=354 [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 "ServerAdminUI"=0 "Hidden"=2 "ShowCompColor"=1 "HideFileExt"=1 "DontPrettyPath"=0 "ShowInfoTip"=1 "HideIcons"=0 "MapNetDrvBtn"=0 "WebView"=1 "Filter"=0 "SuperHidden"=0 "SeparateProcess"=0 "AutoCheckSelect"=0 "IconsOnly"=0 "ShowTypeOverlay"=1 "ListviewAlphaSelect"=0 "ListviewShadow"=1 "TaskbarAnimations"=0 "StartMenuInit"=4 "DisablePreviewDesktop"=0 "TaskbarSizeMove"=1 "TaskbarSmallIcons"=0 "TaskbarGlomLevel"=0 "ExtendedUIHoverTime"=0 "DesktopLivePreviewHoverTime"=0 ""=0 [HKU\S-1-5-20\Control Panel\Desktop] "ScreenSaveActive"=1 "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "PaintDesktopVersion"=0 "Pattern"=0 "RightOverlapChars"=3 "SnapSizing"=1 "TileWallpaper"=0 "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 [HKU\S-1-5-19\Control Panel\Desktop] "ScreenSaveActive"=1 "ActiveWndTrackTimeout"=0 "BlockSendInputResets"=0 "CaretWidth"=1 "ClickLockTime"=1200 "CoolSwitchColumns"=7 "CoolSwitchRows"=3 "CursorBlinkRate"=530 "DockMoving"=1 "DragFromMaximize"=1 "DragFullWindows"=1 "DragHeight"=4 "DragWidth"=4 "FocusBorderHeight"=1 "FocusBorderWidth"=1 "FontSmoothing"=2 "FontSmoothingGamma"=0 "FontSmoothingOrientation"=1 "FontSmoothingType"=2 "ForegroundFlashCount"=7 "ForegroundLockTimeout"=200000 "LeftOverlapChars"=3 "MenuShowDelay"=400 "PaintDesktopVersion"=0 "Pattern"=0 "RightOverlapChars"=3 "SnapSizing"=1 "TileWallpaper"=0 "WallpaperOriginX"=0 "WallpaperOriginY"=0 "WallpaperStyle"=10 "WheelScrollChars"=3 "WheelScrollLines"=3 "WindowArrangementActive"=1 [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Start_SearchFiles"=2 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "ValidateAdminCodeSignatures"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "FilterAdministratorToken"=0 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "CheckedValue"=1 "ValueName"=Hidden "DefaultValue"=2 "HKeyRoot"=2147483649 "HelpID"=shell.hlp#51105 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer] "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "BrowserCFCreator"={57f8510b-a5e2-41da-a8f0-8a5ae85dfffd} "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "IconUnderline"=2 "GlobalAssocChangedCounter"=23 "Max Cached Icons"=2000 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "TaskbarSizeMove"=0 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableInstallerDetection"=1 "EnableLUA"=1 "EnableSecureUIAPaths"=1 "EnableUIADesktopToggle"=0 "EnableVirtualization"=1 "PromptOnSecureDesktop"=1 "ValidateAdminCodeSignatures"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "scforceoption"=0 "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "FilterAdministratorToken"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop] "NoAddingComponents"=1 "NoComponents"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1 "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1 "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1 "{871C5380-42A0-1069-A2EA-08002B30309D}"=1 "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1 "{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1 "{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1 "{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] "{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0 "{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Text"=@shell32.dll,-30500 "Type"=radio "CheckedValue"=1 "ValueName"=Hidden "DefaultValue"=2 "HKeyRoot"=2147483649 "HelpID"=shell.hlp#51105 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer] "ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed} "BrowserCFCreator"={57f8510b-a5e2-41da-a8f0-8a5ae85dfffd} "GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} "FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} "IconUnderline"=2 "GlobalAssocChangedCounter"=466 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "TaskbarSizeMove"=0 [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] "Application"=http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s ¤¤¤¤¤¤¤¤¤¤ | Winlogon [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin "BuildNumber"=7601 "FirstLogon"=0 "ParseAutoexec"=1 [HKU\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin [HKU\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ReportBootOk"=1 "Shell"=explorer.exe "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "Userinit"=C:\Windows\system32\userinit.exe, "VMApplet"=SystemPropertiesPerformance.exe /pagefile "AutoRestartShell"=1 "Background"=0 0 0 "CachedLogonsCount"=10 "DebugServerCommand"=no "ForceUnlockLogon"=0 "LegalNoticeCaption"= "LegalNoticeText"= "PasswordExpiryWarning"=5 "PowerdownAfterShutdown"=0 "ShutdownWithoutLogon"=0 "WinStationsDisabled"=0 "DisableCAD"=1 "scremoveoption"=0 "ShutdownFlags"=43 "AutoAdminLogon"=0 "DefaultUserName"=magali [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] "ReportBootOk"=1 "Shell"=explorer.exe "PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16} "DefaultDomainName"= "DefaultUserName"= "Userinit"=userinit.exe, "VMApplet"=SystemPropertiesPerformance.exe /pagefile "allocatecdroms"=0 ¤¤¤¤¤¤¤¤¤¤ | Associations [HKLM\Software\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\Classes\.com] ""=comfile [HKLM\Software\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.reg] ""=regfile [HKLM\Software\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\Classes\.scr] ""=scrfile [HKLM\Software\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\Classes\.bat] ""=batfile [HKLM\Software\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.cmd] ""=cmdfile [HKLM\Software\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.pif] ""=piffile [HKLM\Software\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\Classes\.inf] ""=inffile [HKLM\Software\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\Classes\.url] ""=InternetShortcut [HKLM\Software\Classes\.lnk] ""=lnkfile [HKLM\Software\Classes\InternetShortcut] "NeverShowExt"= "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "EditFlags"=2 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "FriendlyTypeName"=@C:\windows\system32\ieframe.dll,-10046 "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\Classes\Application.Manifest] ""=Application Manifest "EditFlags"=65536 "BrowserFlags"=4096 "FriendlyTypeName"=@dfshim.dll,-200 [HKLM\Software\Classes\Application.Reference] "NeverShowExt"= ""=Application Reference "IsShortcut"= "EditFlags"=131072 "FriendlyTypeName"=@dfshim.dll,-201 [HKLM\Software\Classes\Folder] "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeLayoutPatternForSearch"=alpha "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay ""=Folder "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.ItemTypeText [HKLM\Software\WOW6432Node\Classes\.exe] ""=exefile "Content Type"=application/x-msdownload [HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command] ""="%1" %* "IsolatedCommand"="%1" %* [HKLM\Software\WOW6432Node\Classes\.com] ""=comfile [HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.reg] ""=regfile [HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command] ""=regedit.exe "%1" [HKLM\Software\WOW6432Node\Classes\.scr] ""=scrfile [HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command] ""="%1" /S [HKLM\Software\WOW6432Node\Classes\.bat] ""=batfile [HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.cmd] ""=cmdfile [HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.pif] ""=piffile [HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command] ""="%1" %* [HKLM\Software\WOW6432Node\Classes\.inf] ""=inffile [HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command] ""=%SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\Software\WOW6432Node\Classes\.url] ""=InternetShortcut [HKLM\Software\WOW6432Node\Classes\.lnk] ""=lnkfile [HKLM\Software\WOW6432Node\Classes\InternetShortcut] "NeverShowExt"= "InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "EditFlags"=2 "FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment "IsShortcut"= "FriendlyTypeName"=@C:\windows\system32\ieframe.dll,-10046 "PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment ""=Raccourci Internet [HKLM\Software\WOW6432Node\Classes\Application.Manifest] ""=Application Manifest "EditFlags"=65536 "BrowserFlags"=4096 "FriendlyTypeName"=@dfshim.dll,-200 [HKLM\Software\WOW6432Node\Classes\Application.Reference] "NeverShowExt"= ""=Application Reference "IsShortcut"= "EditFlags"=131072 "FriendlyTypeName"=@dfshim.dll,-201 [HKLM\Software\WOW6432Node\Classes\Folder] "ContentViewModeLayoutPatternForBrowse"=delta "ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified "ContentViewModeLayoutPatternForSearch"=alpha "ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay ""=Folder "EditFlags"=0xD2030000 "FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size "NoRecentDocs"= "ThumbnailCutoff"=0 "TileInfo"=prop:System.Title;System.ItemTypeText [HKLM\Software\Clients\StartMenuInternet\Chromium.YXL5XVQ2FQYBYWW53U3VSNC53E\Shell\open\Command] ""="C:\Users\magali\AppData\Local\Chromium\Application\chrome.exe" [HKLM\Software\Clients\StartMenuInternet\Chromium.YXL5XVQ2FQYBYWW53U3VSNC53E\InstallInfo] "ReinstallCommand"="C:\Users\magali\AppData\Local\Chromium\Application\chrome.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=iexplore.exe [HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Chromium.YXL5XVQ2FQYBYWW53U3VSNC53E\Shell\open\Command] ""="C:\Users\magali\AppData\Local\Chromium\Application\chrome.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Chromium.YXL5XVQ2FQYBYWW53U3VSNC53E\InstallInfo] "ReinstallCommand"="C:\Users\magali\AppData\Local\Chromium\Application\chrome.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\Shell\open\Command] ""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\InstallInfo] "ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command] ""=iexplore.exe [HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo] "ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall ¤¤¤¤¤¤¤¤¤¤ | AppcompatFlags [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted] "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5CQ2HH33\Installation_Messenger2011[1].exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBAUVLHO\avast_free6_01Net[1].exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7JJ5F1VB\wlsetup-web[1].exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5CQ2HH33\wlsetup-web[1].exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBAUVLHO\messenger-plus-live_messenger_plus_live_5.00.702_francais_11159[1].exe"=1 "SIGN.MEDIA=A828A3 Install.exe"=1 "C:\Program Files (x86)\Samsung\Kies\MyFreeCodecPack.exe"=1 "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe"=512 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7JJ5F1VB\bitcomet_setup[1].exe"=1 "SIGN.MEDIA=5E1688 Install.exe"=1 "SIGN.MEDIA=2740100 KODAK_Software_Downloader.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RDJA8NI3\install_flashplayer11x32ax_gtbp_mssa_aih[1].exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBAUVLHO\FacebookMessengerSetup_v1.2.205.0[1].exe"=1 "SIGN.MEDIA=232D72A installer.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CO6DUPJS\googleupdatesetup.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WHKWIB1\setup_gigatribe_v3.04.009.6238.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOYGGR6Z\Windows Live Messenger.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOYGGR6Z\MSN Messenger.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TYKR72L9\FlashPlayer.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOYGGR6Z\SkypeSetup.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TYKR72L9\FlashPlayer (1).exe"=1 "C:\windows\System32\msiexec.exe"=1 "SIGN.MEDIA=12F724 Microsoft Office Professionel 2007 [FR] + Sérial\Microsoft Office 2007 Professionel\SETUP.EXE"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1SYK55M\vlc-2.1.3-win32.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GSPNLJEA\shareaza.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9Q7YN0IU\iTunes.exe"=1 "C:\Users\magali\Desktop\iTunesSetup.exe"=1 "SIGN.MEDIA=5CAF1E40 Setup.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GSPNLJEA\install_flashplayer16x32ax_chrd_dn_awa_aih.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1SYK55M\install_flashplayer16x32_mssd_aaa_aih.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TYKR72L9\Adobe Reader.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOYGGR6Z\FYDLoad_flvto_2.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1SYK55M\mailoramaSetup.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TYKR72L9\install_flashplayer16x32ax_gtba_chra_dy_aaa_aih.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TYKR72L9\install_flashplayer17x32ax_chra_dy_awa_aih.exe"=1 "C:\Program Files (x86)\HP\Diagnostics\PSDR\HPPSDr.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GSPNLJEA\Telecharger_Drivers_V3.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9Q7YN0IU\readerdc_fr_db_install.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RCEADL6C\HPSupportSolutionsFramework-12.0.30.81.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TYKR72L9\DriverEasy_Setup-4-9-4-622.exe"=1 "C:\Program Files (x86)\HP Photo Creations\PhotoProduct.exe"=2 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O3WQIJYT\MyScrapNook.62227ffea06b4a2f87e843dd0a305f16.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1SYK55M\LeapFrogConnectSetup_LeapPadExplorer.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RCEADL6C\hppc-hpcom.18332.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RCEADL6C\driver_booster_setup.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JIX18H0D\Phylo_college_complet_setup_2012.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JIX18H0D\ProductivityBoss.a2121dbec83f457aa20400c5bec6437b.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JIX18H0D\SetupCVitaeV5.exe"=1 "C:\Program Files (x86)\DriverUpdate\DriverUpdate.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2GUJ79PS\FYDLoad_inflvto_13.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YWIF96YK\FreeStudio.exe"=1 "C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25EKXB2X\FYDLoad_inflvto_13.exe"=1 "C:\Program Files\AVAST Software\Avast\aswRunDll.exe"=32 ¤¤¤¤¤¤¤¤¤¤ | IFEO ¤¤¤¤¤¤¤¤¤¤ | Mountpoints2 [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{130150a3-7ff7-11e5-bdad-860413a7a451}] : F:\.\Driver\DriverInstaller.exe -eject (AutoRun) [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{690f1835-4775-11e1-9fe1-c9e5ddad3052}] : F:\KODAK_Software_Downloader.exe (AutoRun) ¤¤¤¤¤¤¤¤¤¤ | Windows [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "SwapMouseButtons"=#USR:Control Panel\Mouse "Beep"=#USR:Control Panel\Sound "DoubleClickSpeed"=#USR:Control Panel\Mouse "CoolSwitch"=USR:Control Panel\Desktop "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse ""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows "Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows] "MouseSpeed"=#USR:Control Panel\Mouse "MouseThreshold1"=#USR:Control Panel\Mouse "MouseThreshold2"=#USR:Control Panel\Mouse "SwapMouseButtons"=#USR:Control Panel\Mouse "Beep"=#USR:Control Panel\Sound "DoubleClickSpeed"=#USR:Control Panel\Mouse "CoolSwitch"=USR:Control Panel\Desktop "DoubleClickHeight"=#USR:Control Panel\Mouse "DoubleClickWidth"=#USR:Control Panel\Mouse "DragFullWindows"=USR:Control Panel\Desktop "InitialKeyboardIndicators"=USR:Control Panel\Keyboard "LowPowerActive"=#USR:Control Panel\Desktop "LowPowerTimeOut"=#USR:Control Panel\Desktop "PowerOffActive"=#USR:Control Panel\Desktop "PowerOffTimeOut"=#USR:Control Panel\Desktop "ScreenSaveActive"=#USR:Control Panel\Desktop "ScreenSaveTimeOut"=#USR:Control Panel\Desktop "SnapToDefaultButton"=#USR:Control Panel\Mouse "TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW "APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS "SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot] ""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot "ScreenSaverActive"=USR:Control Panel\Desktop "ScreenSaverIsSecure"=USR:Control Panel\Desktop "SCRNSAVE.EXE"=USR:Control Panel\Desktop "Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] "windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 ¤¤¤¤¤¤¤¤¤¤ | Security center [HKLM\SOFTWARE\Microsoft\Security Center] "cval"=1 [HKLM\SOFTWARE\Microsoft\Security Center\svc] "VistaSp1"=128920218544262440 "AntiVirusOverride"=0 "AntiSpywareOverride"=0 "FirewallOverride"=0 [HKLM\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=0 "DisableRoutinelyTakingAction"=0 "ProductStatus"=0 "InstallTime"=0x678184329274CB01 [HKLM\Software\WOW6432Node\Microsoft\Windows Defender] "DisableAntiSpyware"=0 "DisableRoutinelyTakingAction"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=1 "DefaultInboundAction"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=1 [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall"=1 ¤¤¤¤¤¤¤¤¤¤ | Safeboot [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vga.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vgasave.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfSvc] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] ¤¤¤¤¤¤¤¤¤¤ | Winsock (Whitelist) ¤¤¤¤¤¤¤¤¤¤ | Hosts ¤¤¤¤¤¤¤¤¤¤ | @ [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main] "Use Search Asst"= "Search Page"= "Search Bar"= "SearchAssistant"= "Isolation"=MPIL [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet settings] "EnableNegotiate"=1 "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "IE5_UA_Backup_Flag"=5.0 "ZonesSecurityUpgrade"=0xB6A118893F04CA01 "SecureProtocols"=40 "AutoConfigProxy"=wininet.dll "MigrateProxy"=1 "ProxyOverride"=<-loopback> [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000_Classes\Software\Microsoft\Windows\CurrentVersion\Internet settings] "ProxyEnable"=0 [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Internet Explorer\Main] "Disable Script Debugger"=yes "Anchor Underline"=yes "Cache_Update_Frequency"=Once_Per_Session "Display Inline Images"=yes "Do404Search"=0x01000000 "Local Page"=C:\windows\system32\blank.htm "Save_Session_History_On_Exit"=no "Show_FullURL"=no "Show_StatusBar"=yes "Show_ToolBar"=yes "Show_URLinStatusBar"=yes "Show_URLToolBar"=yes "Use_DlgBox_Colors"=yes "Search Page"=http://www.google.com "XMLHTTP"=1 "NoUpdateCheck"=1 "Enable Browser Extensions"=yes "Play_Background_Sounds"=yes "Play_Animations"=yes "Use Search Asst"=yes "AlwaysShowMenus"=0 "Search Bar"=http://www.google.com "StatusBarWeb"=1 "ForceGDIPlus"=0 "SuppressScriptDebuggerDialog"=0 "CSS_Compat"=doctype "Expand Alt Text"=no "Display Inline Videos"=1 "Print_Background"=no "Use Stylesheets"=1 "SmoothScroll"=1 "Show image placeholders"=0 "DisableScriptDebuggerIE"=yes "Move System Caret"=no "Enable AutoImageResize"=yes "UseThemes"=1 "UseHR"=0 "Q300829"=0 "Cleanup HTCs"=0 "XDomainRequest"=1 "DOMStorage"=1 "FrameTabWindow"=1 "AdminTabProcs"=1 "SessionMerging"=1 "FrameMerging"=1 "TabShutdownDelay"=60000 "FrameShutdownDelay"=0 "Start Page Redirect Cache AcceptLangs"=fr-FR "NotifyDownloadComplete"=yes "IconCache"=0jhswy2 "DownloadWindowPlacement"=0x2C0000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF370100005300000057040000AB020000 "Check_Associations"=no "EnableAlternativeCodec"=yes "GotoIntranetSiteForSingleWordEntry"=0 "Friendly http errors"=yes "Error Dlg Displayed On Every Error"=no "NscSingleExpand"=0 "IE10RunOncePerInstallCompleted"=1 "IE10RunOnceCompletionTime"=0xC6B0BD788FB0CF01 "DefSpellLang"=fr-FR "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "ImageStoreRandomFolder"=2xwk6ej "IE10RunOnceLastShown"=0 "DoNotTrack"=0 "ScriptDebugger_EnableHiddenTabs"=0 "ShutdownWaitForOnUnload"=0 "DNSPreresolution"=8 "SpellChecking"=1 "LangToolsBroker"={5bbd58bb-993e-4c17-8af6-3af8e908fca8} "DisablePasswordReveal"=0 "DisableRequiresActiveXPrompt"= "AutoSearch"=1 "PredictedViewExpansion"=100 "PredictedViewChangeThreshold"=10 "PredictedViewChangeThresholdPaint"=10 "ContentLayerCacheExpansion"=300 "RenderingLoopMaxTime"=250 "Disable Diagnostics Mode"=no "JScriptProfileCacheEventDelay"=5000 "CrossfadeMinTimeoutInMS"=30000 "CrossfadeMaxTimeoutInMS"=30000 "CrossfadeCurrentTimeoutInMS"=30000 "ScrollTimeoutInMS"=6000 "IE10TourNoShow"=0 "IE10TourShown"=1 "IE10RecommendedSettingsNo"=0 "HangRecovery"=1 "DesktopTransparentCoverWindowTime"=8 "TSEnable"=1 "Isolation"=PMIL "Isolation64Bit"=0 "IsolationImmersive"=PMEM "MinIEEnabled"=1 "FormSuggest Passwords"=yes "FormSuggest PW Ask"=yes "RefcountTracker"=0 "TabDragOnSingleProc"=0 "ForceBFCacheCandidacyPass"=0 "Fasterback"=1 "BackForwardInstrumentation"=0 "IE10TourShownTime"=0xD892C2788FB0CF01 "Start Page"=http://www.google.fr/ "OperationalData"=5 "CompatibilityFlags"=0 "FullScreen"=no "Window_Placement"=0x2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF960000009600000096040000FA000000 "Default_Page_URL"=about:blank "Start Default_Page_URL"=about:newtab "Default_Search_URL"=http://www.google.com "NoProtectedModeBanner"=1 "AutoHide"=yes "PlaySounds"=0 "UseSWRender"=0 "MixedContentBlockImages"=0 "Start Page_TIMESTAMP"=0x37E6D964BD97D101 "SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy"= [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"=http://www.google.com/ "SearchAssistant"=http://www.bing.com/search?q={searchTerms} "Start Page"=about:newtab "Start Default_Page_URL"=about:newtab "Search Page"=www.google.com [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Internet Explorer\SearchURL] "Default"=http://www.bing.com/search?q={searchTerms} "(Default)"=www.google.com/ ""=www.google.com/ [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Internet Explorer\AboutURLs] "Tabs"=about:newtab [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\CurrentVersion\Internet settings] "IE5_UA_Backup_Flag"=5.0 "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "EmailName"=IEUser@ "PrivDiscUiShown"=1 "EnableHttp1_1"=1 "WarnOnIntranet"=0 "MimeExclusionListForCache"=multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "AutoConfigProxy"=wininet.dll "UseSchannelDirectly"=0x01000000 "EnableNegotiate"=1 "MigrateProxy"=1 "WarnOnPost"=0x01000000 "UrlEncoding"=0 "SecureProtocols"=2720 "PrivacyAdvanced"=0 "ZonesSecurityUpgrade"=0x4D11390EDFE2CE01 "DisableCachingOfSSLPages"=0 "WarnonZoneCrossing"=0 "CertificateRevocation"=1 "EnableAutodial"=0 "NoNetAutodial"=0 "ProxyHttp1.1"=1 "EnablePunycode"=1 "ShowPunycode"=0 "CreateUriCacheSize"=80 "CoInternetCombineIUriCacheSize"=80 "SecurityIdIUriCacheSize"=30 "SpecialFoldersCacheSize"=8 "DisableIDNPrompt"=0 "WarnOnPostRedirect"=1 "WarnonBadCertRecving"=1 "EnableSPDY3_0"=0 "BackgroundConnections"=1 "SyncMode5"=4 "EnforceP3PValidity"=0 "ProxyEnable"=0 [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main] "Disable Script Debugger"=yes [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet settings] "IE5_UA_Backup_Flag"=5.0 "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "EmailName"=User@ "PrivDiscUiShown"=1 "EnableHttp1_1"=1 "WarnOnIntranet"=1 "MimeExclusionListForCache"=multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "AutoConfigProxy"=wininet.dll "UseSchannelDirectly"=0x01000000 "EnableNegotiate"=1 "ProxyEnable"=0 [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main] "Disable Script Debugger"=yes [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet settings] "IE5_UA_Backup_Flag"=5.0 "User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32) "EmailName"=User@ "PrivDiscUiShown"=1 "EnableHttp1_1"=1 "WarnOnIntranet"=1 "MimeExclusionListForCache"=multipart/mixed multipart/x-mixed-replace multipart/x-byteranges "AutoConfigProxy"=wininet.dll "UseSchannelDirectly"=0x01000000 "EnableNegotiate"=1 "ProxyEnable"=0 [HKLM\Software\Microsoft\Internet Explorer\Main] "AutoHide"=yes "Security Risk Page"=about:SecurityRisk "Extensions Off Page"=about:NoAdd-ons "Default_Search_URL"=www.google.com "Default_Page_URL"=about:blank "Anchor_Visitation_Horizon"=0x01000000 "Cache_Percent_of_Disk"=0x0A000000 "Placeholder_Width"=0x1A000000 "Placeholder_Height"=0x1A000000 "Default_Secondary_Page_URL"= "Use_Async_DNS"=yes "Start Page"=about:blank "Local Page"=C:\Windows\System32\blank.htm "Search Page"=www.google.com "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "TabProcGrowth"=Medium "Print_Background"=0 "AlwaysShowMenus"=0 "StatusBarWeb"=1 "Check_Associations"=yes "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [HKLM\Software\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "InPrivate"=res://ieframe.dll/inprivate_win7.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "Home"=270 "PostNotCached"=res://ieframe.dll/repost.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm "newtab"=www.google.com [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes] "mosaic"=http:// "www"=http:// "home"=http:// "ftp"=ftp:// [HKLM\Software\Microsoft\Windows\CurrentVersion\Internet settings] "EnablePunycode"=1 "CodeBaseSearchPath"=CODEBASE "WarnOnIntranet"=1 "MinorVersion"=0 "ActiveXCache"=C:\Windows\Downloaded Program Files [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main] "AutoHide"=yes "Security Risk Page"=about:SecurityRisk "Extensions Off Page"=about:NoAdd-ons "Default_Search_URL"=http://www.google.com "Default_Page_URL"=about:blank "Anchor_Visitation_Horizon"=0x01000000 "Cache_Percent_of_Disk"=0x0A000000 "Placeholder_Width"=0x1A000000 "Placeholder_Height"=0x1A000000 "Default_Secondary_Page_URL"= "Use_Async_DNS"=yes "Start Page"=about:newtab "Local Page"=C:\Windows\SysWOW64\blank.htm "Search Page"=http://www.google.com "Delete_Temp_Files_On_Exit"=yes "Enable_Disk_Cache"=yes "TabProcGrowth"=Medium "Print_Background"=0 "AlwaysShowMenus"=0 "StatusBarWeb"=1 "Enable Browser Extensions"=yes "Use Search Asst"=no "Check_Associations"=yes "ApplicationTileImmersiveActivation"=1 "AssociationActivationMode"=0 "x86AppPath"=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE "Start Default_Page_URL"=about:newtab "Search Bar"=http://www.google.com "AutoSearch"=1 [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Search] "Start Page"=about:newtab "Start Default_Page_URL"=about:newtab "Default_Search_URL"=http://www.google.com/ "Search Page"=www.google.com [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\SearchURL] "Default"=http://www.bing.com/search?q={searchTerms} [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs] "blank"=res://mshtml.dll/blank.htm "NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm "InPrivate"=res://ieframe.dll/inprivate_win7.htm "NavigationFailure"=res://ieframe.dll/navcancl.htm "NoAdd-ons"=res://ieframe.dll/noaddon.htm "Home"=270 "PostNotCached"=res://ieframe.dll/repost.htm "DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm "NavigationCanceled"=res://ieframe.dll/navcancl.htm "SecurityRisk"=res://ieframe.dll/securityatrisk.htm "Tabs"=about:newtab "newtab"=www.google.com [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] ""=http:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes] "mosaic"=http:// "www"=http:// "home"=http:// "ftp"=ftp:// [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings] "EnablePunycode"=1 "CodeBaseSearchPath"=CODEBASE "WarnOnIntranet"=1 "MinorVersion"=0 "ActiveXCache"=C:\Windows\Downloaded Program Files ¤¤¤¤¤¤¤¤¤¤ | reparsepoint ¤¤¤¤¤¤¤¤¤¤ | Detection of offsets ¤¤¤¤¤¤¤¤¤¤ | Notify ¤¤¤¤¤¤¤¤¤¤ | SSODL | SEH | URLSH | STS ¤¤¤¤¤¤¤¤¤¤ | Toolbar [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "Locked"=1 "ShowDiscussionButton"=Yes [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser] "ITBar7Layout"=0x1300000000000000000000002000000010000A006400000001000000000700006D01000007000000010100000000000009000000010100000000000008000000090100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000E2CC0C4F05317343AEDE7D5E2ADC83CEF79D72EAA8FE3C448781327FA3AB7529B1C218236549D4119B18009027A5CD4F0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 "ITBar7Height"=100 "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=0xB1C218236549D4119B18009027A5CD4F "{3D4D238C-9C48-47CD-A95C-53259ACF9E56}"=0x8C234D3D489CCD47A95C53259ACF9E56 "{9E96C0CD-A901-4032-9236-0E4A264AEEE4}"=0xCDC0969E01A9324092360E4A264AEEE4 "ITBar7Height64"=0 "ITBar7Layout64"=0x13000000000000000000000004000000100007000000000001000000000000005E0100000600000001010000000000000700000000010000000000000800000001010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000EC62AA5BF22EC42B60FEB7F41164C87B1C218236549D4119B18009027A5CD4FE2CC0C4F05317343AEDE7D5E2ADC83CE000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={6A1806CD-94D4-4689-BA73-E35EA1EA9990} "UpgradeTime"=0x628581CC99EFCF01 "ShowSearchSuggestionsInAddressGlobal"=1 "TopResult"=1 "ShowSearchSuggestionsGlobal"=1 "Version"=4 "DoNotAskAgain"=sweet-page.com bing.com "KnownProvidersUpgradeTime"=0xD20084CA99EFCF01 "DefaultPackCorrection"=1 "DefaultPackNTCorrection"=1 [HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "Locked"=0 "{4f0ccce2-3105-4373-aede-7d5e2adc83ce}"=Mailorama.IEModule "{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=0x00 [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={6A1806CD-94D4-4689-BA73-E35EA1EA9990} [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Toolbar] "Locked"=0 "{4f0ccce2-3105-4373-aede-7d5e2adc83ce}"=Mailorama.IEModule "{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=0x00 [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"={afdbddaa-5d3f-42ee-b79c-185a7020515b} ¤¤¤¤¤¤¤¤¤¤ | Extensions [HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{22CC3EBD-C286-43aa-B8E6-06B115F74162}] : (HP Smart Print) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{0000036B-C524-4050-81A0-243669A86B9F}] : () - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}] : (@C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{22CC3EBD-C286-43aa-B8E6-06B115F74162}] : (HP Smart Print) - [] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}] : () - [] ¤¤¤¤¤¤¤¤¤¤ | SearchScopes [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}] - () - : [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}] - (Bing) - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 : [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{68e3123d-3b5b-436f-879e-a24c3e348a77}] - (SearchTheWeb) - : [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1 : [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}] - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}] - () - : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}] - () - : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] - (Bing) - http://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}] - (Google) - http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 : ¤¤¤¤¤¤¤¤¤¤ | Browser Helper Objects [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{284da1e2-dbf1-4bde-a83d-e5b513ca1315}] -> () : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32dd8546-7b81-4ad0-87d9-f05f3ffad7de}] -> () : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{513fed4e-2a5d-47cd-ad4e-5369300483dc}] -> (Mailorama) : C:\Program Files (x86)\Rentabiliweb\Mailorama pour internet explorer\adxloader.dll [08/07/2013 18:08:52] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77ada2de-9e77-4f6a-a551-e3ca5f241567}] -> () : [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] -> (Programme d'aide de l'Assistant de connexion Windows Live ID) : C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [28/03/2011 20:35:06] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] -> (Google Toolbar Helper) : C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [16/10/2014 15:03:50] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC3A664C-4E5E-46ED-9A87-86416D099754}] -> () : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}] -> (MSS+ Identifier) : C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll [06/09/2013 18:29:34] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{284da1e2-dbf1-4bde-a83d-e5b513ca1315}] -> () : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32dd8546-7b81-4ad0-87d9-f05f3ffad7de}] -> () : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{513fed4e-2a5d-47cd-ad4e-5369300483dc}] -> (Mailorama) : C:\Program Files (x86)\Rentabiliweb\Mailorama pour internet explorer\adxloader.dll [08/07/2013 18:08:52] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77ada2de-9e77-4f6a-a551-e3ca5f241567}] -> () : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] -> (Programme d'aide de l'Assistant de connexion Windows Live ID) : C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [28/03/2011 20:35:06] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}] -> (Windows Live Messenger Companion Helper) : C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [08/03/2012 18:14:38] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] -> (Google Toolbar Helper) : C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [16/10/2014 15:03:50] [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EB168AD8-C87D-32F0-F125-02138D263E99}] -> () : [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC3A664C-4E5E-46ED-9A87-86416D099754}] -> () : ¤¤¤¤¤¤¤¤¤¤ | Chrome [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda] [HKLM\Software\WOW6432Node\Google\Chrome\Extensions\joefdjpocengkmjmcnheijdogjafdbha] ¤¤¤¤¤¤¤¤¤¤ | Opera ¤¤¤¤¤¤¤¤¤¤ | Firefox [HKLM\Software\WOW6432Node\mozilla\Firefox\Extensions] "{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5] - (A component of your photo software powered by RocketLife) : C:\Users\magali\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\MozillaPlugins\facebook.com/fbDesktopPlugin] - () : C:\Users\magali\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll [HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 21.0.0.213 Plugin) : C:\windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE] - () : disabled [HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 21.0.0.213 Plugin) : C:\windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@mcafee.com/McAfeeMssPlugin] - (McAfee Mss Plugin) : C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/GENUINE] - () : disabled [HKLM\Software\WOW6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [HKLM\Software\WOW6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3] - (VLC Multimedia Plugin) : C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKLM\Software\WOW6432Node\MozillaPlugins\Adobe Reader] - (Handles PDFs in-place in Firefox) : C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll ¤¤¤¤¤¤¤¤¤¤ | Active Connections TCP 192.168.0.11:1068 HPE7B603:8080 ESTABLISHED 2724 TCP 192.168.0.11:1085 lon3-accesspoint-a40.lon3.spotify.com:4070 ESTABLISHED 4932 TCP 192.168.0.11:1177 ec2-50-19-123-43.compute-1.amazonaws.com:https CLOSE_WAIT 1696 TCP 192.168.0.11:1207 ec2-107-21-242-251.compute-1.amazonaws.com:https CLOSE_WAIT 1696 TCP 192.168.0.11:1208 ec2-107-21-242-251.compute-1.amazonaws.com:https CLOSE_WAIT 1696 TCP 192.168.0.11:7472 mailorama.fr:http CLOSE_WAIT 1356 ¤¤¤¤¤¤¤¤¤¤ | DNS [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters] "DhcpNameServer"=212.27.40.240 212.27.40.241 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters] "NameServer"=8.8.8.8,8.8.8.4 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{3FF85018-09C6-49E4-A9F4-50D2B4C220C6}] "DhcpNameServer"=82.163.143.171 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{4E2B02A8-BA4B-4AB0-8229-AEAA37AB63EC}] "DhcpNameServer"=192.168.0.1 [HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{F0E29484-C9DB-4352-B7B4-9F3F04D9C2CB}] "DhcpNameServer"=212.27.40.240 212.27.40.241 [HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{3FF85018-09C6-49E4-A9F4-50D2B4C220C6}] "DhcpNameServer"=82.163.143.171 [HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{4E2B02A8-BA4B-4AB0-8229-AEAA37AB63EC}] "DhcpNameServer"=192.168.0.1 [HKLM\SYSTEM\ControlSet002\services\Tcpip\Parameters\Interfaces\{F0E29484-C9DB-4352-B7B4-9F3F04D9C2CB}] "DhcpNameServer"=212.27.40.240 212.27.40.241 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3FF85018-09C6-49E4-A9F4-50D2B4C220C6}] "DhcpNameServer"=82.163.143.171 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{4E2B02A8-BA4B-4AB0-8229-AEAA37AB63EC}] "DhcpNameServer"=192.168.0.1 [HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{F0E29484-C9DB-4352-B7B4-9F3F04D9C2CB}] "DhcpNameServer"=212.27.40.240 212.27.40.241 ¤¤¤¤¤¤¤¤¤¤ | Applications [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Classes\Applications\msnmsgr.exe] : "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\ehshell.exe] : "C:\Windows\eHome\ehshell.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\iexplore.exe" %1 [HKLM\SOFTWARE\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1" [HKLM\SOFTWARE\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\Classes\Applications\ois.exe] : C:\PROGRA~2\MICROS~1\Office12\OIS.EXE /shellOpen "%1" [HKLM\SOFTWARE\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\Classes\Applications\vlc.exe] : "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file "%1" [HKLM\SOFTWARE\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1" [HKLM\SOFTWARE\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\ehshell.exe] : "C:\Windows\eHome\ehshell.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iexplore.exe] : "C:\Program Files\Internet Explorer\iexplore.exe" %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\ois.exe] : C:\PROGRA~2\MICROS~1\Office12\OIS.EXE /shellOpen "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1 [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\vlc.exe] : "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L" [HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1" ¤¤¤¤¤¤¤¤¤¤ | Svchost - Netsvcs (Whitelisted) Term - : ¤¤¤¤¤¤¤¤¤¤ | Software [HKU\S-1-5-18\Software\53688dfe538be12] [HKU\S-1-5-18\Software\AppDataLow] [HKU\S-1-5-18\Software\Avast Software] [HKU\S-1-5-18\Software\CyberLink] [HKU\S-1-5-18\Software\Google] [HKU\S-1-5-18\Software\Hewlett-Packard] [HKU\S-1-5-18\Software\McAfee] [HKU\S-1-5-18\Software\Microsoft] [HKU\S-1-5-18\Software\mozilla] [HKU\S-1-5-18\Software\Netscape] [HKU\S-1-5-18\Software\Nico Mak Computing] [HKU\S-1-5-18\Software\NVIDIA Corporation] [HKU\S-1-5-18\Software\Opera Software] [HKU\S-1-5-18\Software\Policies] [HKU\S-1-5-18\Software\SiteAdvisor] [HKU\S-1-5-18\Software\Skype] [HKU\S-1-5-18\Software\WinZip Computing] [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-18\Software\Microsoft\Windows\DWM] [HKU\S-1-5-18\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000_Classes\Software\Microsoft] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000_Classes\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\(null)] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\3a6ad4c5-127f-4668-888b-e8e7a31031c2] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Adobe] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\APN PIP] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\AppDataLow] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\AVAST Software] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\AVG] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Binary Noise] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\BitComet] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\BrowserCompanion] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Canneverbe Limited] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Chromium] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Clients] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Conduit] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\CyberLink] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Facebook] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\FlvtoConverter] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\ForumerIT] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\FreeTime] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\g3n-h@ckm@n] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Gabest] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\globalUpdate] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\GNU] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Google] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Haali] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Hewlett-Packard] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\HookNetwork] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Hoolapp] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\hotger] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\HP] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\HP Photo Creations] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\IM Providers] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\INRP] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\InstalledBrowserExtensions] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\JavaSoft] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\JEDI-VCL] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Kodak] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Lake] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Licenses] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Macromedia] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Magnet] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\MCAFEE] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\mozilla] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\MozillaPlugins] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\MultiStageTrayAgent] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\MyFree Codec] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\NCH Software] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\NCH Swift Sound] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Netscape] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Nico Mak Computing] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\nuevos-programas.com] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\NVIDIA Corporation] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Oberon Media] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\ODBC] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Opera Software] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\PIP] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Policies] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\ProPCCleanerConfig] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Realtek] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Rentabiliweb] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\RocketLife] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\RocketLifeNetwork] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Samsung] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Semantis] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\SimplyTech] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Skype] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\SlimWare Utilities Inc] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Software] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Sony Corporation] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Spotify] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Store] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Synaptics] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\sysinternals] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\systweak] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\TeleCharger] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Trolltech] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Tutorials] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Visan] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Wow6432Node] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\yahooprovidedsearch] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Yuna Software] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\로컬 응용 프로그램 마법사에서 생성된 응용 프로그램] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\AppDataLow\Software\findlyrics] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\AppDataLow\Software\HappyLyrics] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\AppDataLow\Software\MarkAny] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\AppDataLow\Software\Microsoft] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\AppDataLow\Software\Simplytech] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\AppDataLow\Software\SmartBar] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\DWM] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\Shell] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\ShellNoRoam] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\Software\Microsoft\Windows NT\CurrentVersion] [HKU\S-1-5-20\Software\AppDataLow] [HKU\S-1-5-20\Software\Google] [HKU\S-1-5-20\Software\Microsoft] [HKU\S-1-5-20\Software\Policies] [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-20\Software\Microsoft\Windows\DWM] [HKU\S-1-5-20\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-20\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion] [HKU\S-1-5-19\Software\AppDataLow] [HKU\S-1-5-19\Software\Google] [HKU\S-1-5-19\Software\Microsoft] [HKU\S-1-5-19\Software\Policies] [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion] [HKU\S-1-5-19\Software\Microsoft\Windows\DWM] [HKU\S-1-5-19\Software\Microsoft\Windows\TabletPC] [HKU\S-1-5-19\Software\Microsoft\Windows\Windows Error Reporting] [HKU\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\ASK] [HKLM\Software\ATI Technologies] [HKLM\Software\AVG] [HKLM\Software\BrowserChoice] [HKLM\Software\bullguard ltd.] [HKLM\Software\Canon] [HKLM\Software\Clients] [HKLM\Software\Dolby] [HKLM\Software\DTS] [HKLM\Software\DtsEncodeTools] [HKLM\Software\Fortemedia] [HKLM\Software\g3n-h@ckm@n] [HKLM\Software\Google] [HKLM\Software\Hewlett-Packard] [HKLM\Software\HP] [HKLM\Software\InstalledBrowserExtensions] [HKLM\Software\InstalledOptions] [HKLM\Software\Intel] [HKLM\Software\Khronos] [HKLM\Software\Knowles] [HKLM\Software\Macromedia] [HKLM\Software\McAfee] [HKLM\Software\MCCI] [HKLM\Software\Microsoft] [HKLM\Software\MozillaPlugins] [HKLM\Software\Nuance] [HKLM\Software\NVIDIA Corporation] [HKLM\Software\ODBC] [HKLM\Software\Policies] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\Samsung] [HKLM\Software\SiteAdvisor] [HKLM\Software\Sonic] [HKLM\Software\SonicFocus] [HKLM\Software\SRS Labs] [HKLM\Software\Synaptics] [HKLM\Software\sysinternals] [HKLM\Software\Tarma Installer] [HKLM\Software\Waves Audio] [HKLM\Software\Wow6432Node] [HKLM\Software\Microsoft\Windows\CurrentVersion] [HKLM\Software\Microsoft\Windows\DWM] [HKLM\Software\Microsoft\Windows\HTML Help] [HKLM\Software\Microsoft\Windows\ITStorage] [HKLM\Software\Microsoft\Windows\ScheduledDiagnostics] [HKLM\Software\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\Microsoft\Windows\Tablet PC] [HKLM\Software\Microsoft\Windows\TabletPC] [HKLM\Software\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\Microsoft\Windows\Windows Search] [HKLM\Software\Microsoft\Windows NT\CurrentVersion] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\AxInstSVGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\defragsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\GPSvcGroup] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\SDRSVC] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\swprv] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\utcsvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wcssvc] [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wercplsupport] [HKLM\Software\WOW6432Node\1ce9893f-1968-4d6e-9c6b-b6f7c632d96b] [HKLM\Software\WOW6432Node\53688dfe538be12] [HKLM\Software\WOW6432Node\75b45f97-48e5-4f25-9b0c-a8a31695dfa8] [HKLM\Software\WOW6432Node\7c8de147-5fc2-4bfb-91c2-a464237d94b8] [HKLM\Software\WOW6432Node\8517c34f-f73e-4a33-a73c-88193759468c] [HKLM\Software\WOW6432Node\Adobe] [HKLM\Software\WOW6432Node\America Online] [HKLM\Software\WOW6432Node\Atheros] [HKLM\Software\WOW6432Node\AVAST Software] [HKLM\Software\WOW6432Node\AVG] [HKLM\Software\WOW6432Node\AviSynth] [HKLM\Software\WOW6432Node\Babylon] [HKLM\Software\WOW6432Node\Canneverbe Limited] [HKLM\Software\WOW6432Node\Canon] [HKLM\Software\WOW6432Node\CDDB] [HKLM\Software\WOW6432Node\cf057e2d-79b6-4d86-a815-16035ed16a1a] [HKLM\Software\WOW6432Node\CHECKINSTALLER] [HKLM\Software\WOW6432Node\Conduit] [HKLM\Software\WOW6432Node\CyberLink] [HKLM\Software\WOW6432Node\dotNetInstaller] [HKLM\Software\WOW6432Node\f3fcbf35-2597-4c7d-be9a-30262715ed43] [HKLM\Software\WOW6432Node\GlobalUpdate] [HKLM\Software\WOW6432Node\GNU] [HKLM\Software\WOW6432Node\Google] [HKLM\Software\WOW6432Node\HaaliMkx] [HKLM\Software\WOW6432Node\Hewlett-Packard] [HKLM\Software\WOW6432Node\HP] [HKLM\Software\WOW6432Node\INRP] [HKLM\Software\WOW6432Node\InstalledBrowserExtensions] [HKLM\Software\WOW6432Node\InstallShield] [HKLM\Software\WOW6432Node\Intel] [HKLM\Software\WOW6432Node\IObit] [HKLM\Software\WOW6432Node\Khronos] [HKLM\Software\WOW6432Node\Kodak] [HKLM\Software\WOW6432Node\Lake] [HKLM\Software\WOW6432Node\LeapFrog] [HKLM\Software\WOW6432Node\Licenses] [HKLM\Software\WOW6432Node\Loader] [HKLM\Software\WOW6432Node\Macromedia] [HKLM\Software\WOW6432Node\Malwarebytes' Anti-Malware] [HKLM\Software\WOW6432Node\Marvell] [HKLM\Software\WOW6432Node\McAfee] [HKLM\Software\WOW6432Node\McAfee.com] [HKLM\Software\WOW6432Node\McAfeeInstaller] [HKLM\Software\WOW6432Node\mcafeeupdater] [HKLM\Software\WOW6432Node\Microsoft] [HKLM\Software\WOW6432Node\Mozilla] [HKLM\Software\WOW6432Node\MozillaPlugins] [HKLM\Software\WOW6432Node\Myfree Codec] [HKLM\Software\WOW6432Node\Name of your company] [HKLM\Software\WOW6432Node\NCH Software] [HKLM\Software\WOW6432Node\NCH Swift Sound] [HKLM\Software\WOW6432Node\Nico Mak Computing] [HKLM\Software\WOW6432Node\Nuance] [HKLM\Software\WOW6432Node\Oberon Media] [HKLM\Software\WOW6432Node\ODBC] [HKLM\Software\WOW6432Node\Opera Software] [HKLM\Software\WOW6432Node\PIP] [HKLM\Software\WOW6432Node\Realtek] [HKLM\Software\WOW6432Node\Realtek Semiconductor Corp.] [HKLM\Software\WOW6432Node\RtWLan] [HKLM\Software\WOW6432Node\Samsung] [HKLM\Software\WOW6432Node\Samsung Electronics Co., Ltd.] [HKLM\Software\WOW6432Node\Skype] [HKLM\Software\WOW6432Node\SlimWare Utilities Inc] [HKLM\Software\WOW6432Node\SlimWare Utilities, Inc.] [HKLM\Software\WOW6432Node\Software] [HKLM\Software\WOW6432Node\Sonic] [HKLM\Software\WOW6432Node\Sony Corporation] [HKLM\Software\WOW6432Node\SONY PVC] [HKLM\Software\WOW6432Node\SRS Labs] [HKLM\Software\WOW6432Node\Systweak] [HKLM\Software\WOW6432Node\VideoLAN] [HKLM\Software\WOW6432Node\Visan] [HKLM\Software\WOW6432Node\Volatile] [HKLM\Software\WOW6432Node\Wpm] [HKLM\Software\WOW6432Node\Yuna Software] [HKLM\Software\WOW6432Node\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}] [HKLM\Software\WOW6432Node\{5F189DF5-2D05-472B-9091-84D9848AE48B}] [HKLM\Software\WOW6432Node\{77D46E27-0E41-4478-87A6-AABE6FBCF252}] [HKLM\Software\WOW6432Node\Clients] [HKLM\Software\WOW6432Node\Policies] [HKLM\Software\WOW6432Node\RegisteredApplications] [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows\Help] [HKLM\Software\WOW6432Node\Microsoft\Windows\HTML Help] [HKLM\Software\WOW6432Node\Microsoft\Windows\ITStorage] [HKLM\Software\WOW6432Node\Microsoft\Windows\ScriptedDiagnosticsProvider] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Error Reporting] [HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Search] [HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs] [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\wcssvc] ¤¤¤¤¤¤¤¤¤¤ | Drives D: ¤¤¤¤¤¤¤¤¤¤ | C: [14/07/2009 05:18:56] - |SHD| - [5889080] - C:\$Recycle.Bin [30/09/2015 22:33:28] - |HD| - [60779559] - C:\$Windows.~BT [MD5.1667A0F0E7161176DB6AB4ECACF4E307] - [17/05/2011 18:29:37] - (.-.) - [2006] - (0.0.0.0) - C:\aqua_bitmap.cpp [05/08/2014 14:34:53] - |D| - [0] - C:\components [14/07/2009 07:08:56] - |SHD| - [0] - C:\Documents and Settings [14/07/2011 17:42:25] - |D| - [0] - C:\Downloads [28/07/2011 10:08:20] - |D| - [425966] - C:\Drivers [MD5.D41D8CD98F00B204E9800998ECF8427E] - [05/04/2013 10:11:13] - (.-.) - [0] - (0.0.0.0) - C:\END [14/07/2011 17:54:56] - |D| - [5990363] - C:\extensions [MD5.D41D8CD98F00B204E9800998ECF8427E] - [26/10/2010 00:13:11] - (.-.) - [4148744192] - (0.0.0.0) - C:\hiberfil.sys [01/02/2016 18:15:28] - |D| - [65866633] - C:\INRP [25/10/2010 08:19:39] - |D| - [404582] - C:\Intel [23/05/2014 13:58:39] - |RHD| - [529670008] - C:\MSOCache [MD5.D41D8CD98F00B204E9800998ECF8427E] - [26/10/2010 04:45:57] - (.-.) - [4148744192] - (0.0.0.0) - C:\pagefile.sys [14/07/2009 05:20:08] - |D| - [0] - C:\PerfLogs [14/07/2009 05:20:08] - |RD| - [1440701720] - C:\Program Files [14/07/2009 05:20:08] - |RD| - [5100767114] - C:\Program Files (x86) [14/07/2009 05:20:08] - |HD| - [6651956369] - C:\ProgramData [16/04/2016 11:20:23] - |D| - [262056] - C:\QuickDiag [MD5.EB26DF5D39FEB6AFCA6E6AF84ECD1367] - [16/04/2016 11:20:30] - (.-.) - [128462] - (0.0.0.0) - C:\QuickDiag.txt [25/02/2011 22:35:42] - |SHD| - [171561145] - C:\Recovery [MD5.CE90341516EA16622BE7AF625871FAF0] - [25/10/2010 08:24:13] - (.-.) - [2162] - (0.0.0.0) - C:\RHDSetup.log [MD5.484FE9B3066CDEFE5E9224387B48ADDF] - [25/10/2010 08:23:31] - (.-.) - [191] - (0.0.0.0) - C:\Setup.log [26/10/2010 01:12:15] - |SHD| - [0] - C:\System Volume Information [03/04/2013 23:23:21] - |D| - [0] - C:\Temp [14/07/2009 05:20:08] - |RD| - [26373900005] - C:\Users [14/07/2009 05:20:08] - |D| - [49281834123] - C:\Windows ¤¤¤¤¤¤¤¤¤¤ | C:\windows [MD5.065919847CF1C1C0A1C5F63C488EB54B] - [25/02/2011 22:44:32] - (.-.) - [33] - (0.0.0.0) - C:\windows\0 [14/07/2009 07:32:38] - |D| - [802] - C:\windows\addins [14/07/2009 05:20:08] - |D| - [21047980] - C:\windows\AppCompat [14/07/2009 05:20:08] - |D| - [11035914] - C:\windows\AppPatch [14/07/2009 05:20:08] - |RSD| - [1480670681] - C:\windows\assembly [MD5.317CD1CE327B6520BF4EE007BCD39E61] - [02/10/2012 22:04:45] - (.© Microsoft Corporation. Tous droits réservés. - Utilitaire de service de fichier de démarrage.) - [71168] - (6.1.7601.17514) - C:\windows\bfsvc.exe [14/07/2009 05:20:09] - |D| - [29062678] - C:\windows\Boot [MD5.4F1E9CC96000F2B5F0BBD5794DE9FEDB] - [14/07/2009 07:38:36] - (.-.) - [67584] - (0.0.0.0) - C:\windows\bootstat.dat [14/07/2009 05:20:09] - |D| - [3233280] - C:\windows\Branding [25/10/2010 09:13:12] - |D| - [371873666] - C:\windows\CheckSur [MD5.89D05E2A481778FF843B6A540506B336] - [25/10/2010 08:29:17] - (.-.) - [19480587] - (0.0.0.0) - C:\windows\Crystal Delight.scr [MD5.517F564ECDCED2C56C4B32F0FDB44513] - [25/10/2010 10:00:03] - (.-.) - [10] - (0.0.0.0) - C:\windows\Csup.txt [14/07/2009 05:20:09] - |D| - [2113488] - C:\windows\Cursors [26/10/2010 00:55:57] - |D| - [0] - C:\windows\de-DE [14/07/2009 06:45:54] - |D| - [4114] - C:\windows\debug [MD5.67FC5B9D0957C4FBB37376DE49A2B170] - [12/06/2015 14:22:10] - (.-.) - [1890] - (0.0.0.0) - C:\windows\diagerr.xml [14/07/2009 07:32:38] - |D| - [3044378] - C:\windows\diagnostics [MD5.67FC5B9D0957C4FBB37376DE49A2B170] - [12/06/2015 14:22:10] - (.-.) - [1890] - (0.0.0.0) - C:\windows\diagwrn.xml [14/07/2009 07:37:46] - |D| - [0] - C:\windows\DigitalLocker [14/07/2009 07:32:38] - |D| - [283] - C:\windows\Downloaded Program Files [MD5.F9F4905664C5B42B49E78EFA12D1A6B6] - [25/10/2010 09:53:05] - (.-.) - [20] - (0.0.0.0) - C:\windows\DóÑ [26/10/2010 00:49:31] - |D| - [118090913] - C:\windows\ehome [14/07/2009 07:37:46] - |D| - [0] - C:\windows\en-US [MD5.9D77CC4A36FEEA644D002CFB9B2D42C0] - [10/02/2016 14:29:58] - (.© Microsoft Corporation. Tous droits réservés. - Explorateur Windows.) - [3231232] - (6.1.7601.19135) - C:\windows\explorer.exe [14/07/2009 05:20:09] - |RSD| - [407909063] - C:\windows\Fonts [25/06/2012 21:33:33] - |D| - [107376] - C:\windows\fr [26/10/2010 01:01:57] - |D| - [142848] - C:\windows\fr-FR [18/11/2012 11:50:29] - |SHD| - [0] - C:\windows\ftpcache [MD5.92BB2E9AA28542C685C59EFCBAC2490B] - [14/07/2009 01:22:13] - (.© Microsoft Corporation. Tous droits réservés. - Utilitaire de service de chiffrement de lecteur BitLocker.) - [15360] - (6.1.7600.16385) - C:\windows\fveupdate.exe [14/07/2009 05:20:09] - |D| - [45300575] - C:\windows\Globalization [14/07/2009 05:20:09] - |D| - [56410160] - C:\windows\Help [MD5.CD47548A52B02D254BF6D7F7A5F2BFD3] - [14/07/2009 02:29:53] - (.© Microsoft Corporation. Tous droits réservés. - Aide et support Microsoft.) - [733696] - (6.1.7600.16385) - C:\windows\HelpPane.exe [MD5.3D0B9EA79BF1F828324447D84AA9DCE2] - [14/07/2009 02:29:03] - (.© Microsoft Corporation. Tous droits réservés. - Exécutable de l’aide HTML Microsoft®.) - [16896] - (6.1.7600.16385) - C:\windows\hh.exe [MD5.0D776C3A36F2B6E657939BB96096E070] - [14/07/2009 09:44:57] - (.-.) - [48223] - (0.0.0.0) - C:\windows\HomeBasic.xml [MD5.1AEB4967A760D6EC21A3270F1B004AC1] - [26/10/2010 00:50:01] - (.-.) - [48265] - (0.0.0.0) - C:\windows\HomePremium.xml [MD5.D90E2928CACF5B3CBFFC3A9DFEEA4BF8] - [25/10/2010 09:11:40] - (.(c) Samsung Electronics. - HotfixChecker.) - [406528] - (1.0.0.2) - C:\windows\HotfixChecker.exe [MD5.00DFF7872973F026711625BDBE3546D7] - [25/10/2010 08:55:15] - (.-.) - [1238] - (0.0.0.0) - C:\windows\HotFixList.ini [14/07/2009 05:20:09] - |D| - [143547244] - C:\windows\IME [14/07/2009 05:20:10] - |D| - [157186878] - C:\windows\inf [25/10/2010 08:23:51] - |SHD| - [4447611988] - C:\windows\Installer [26/10/2010 01:07:57] - |D| - [0] - C:\windows\it-IT [14/07/2009 05:20:10] - |D| - [48371] - C:\windows\L2Schemas [MD5.5D00985A9108FBC518499A63766BB1D1] - [05/08/2014 12:42:25] - (.Copyright © 2012 - Toolbar_Exe_Launcher_Form.) - [34368] - (1.0.0.0) - C:\windows\Launcher.exe [14/07/2009 05:20:10] - |D| - [62600699] - C:\windows\LiveKernelReports [14/07/2009 05:20:10] - |D| - [96689252] - C:\windows\Logs [14/07/2009 05:20:10] - |RSD| - [13358214] - C:\windows\Media [MD5.F5B0E7E75D10B3DD68F21F4980AEF81C] - [07/10/2013 17:26:17] - (.-.) - [580976399] - (0.0.0.0) - C:\windows\MEMORY.DMP [MD5.23AF90D2355D8C83AA4567EF1763B467] - [14/07/2009 02:10:29] - (.-.) - [43131] - (0.0.0.0) - C:\windows\mib.bin [14/07/2009 05:20:10] - |D| - [1206028227] - C:\windows\Microsoft.NET [26/02/2014 11:11:39] - |D| - [4376] - C:\windows\Migration [07/10/2013 17:26:26] - |D| - [3225016] - C:\windows\Minidump [14/07/2009 05:20:10] - |D| - [0] - C:\windows\ModemLogs [MD5.B9FB94A8DA62711C6955825DEFB25C5A] - [14/07/2009 04:35:42] - (.-.) - [1405] - (0.0.0.0) - C:\windows\msdfmap.ini [26/10/2010 00:47:41] - |D| - [56694961] - C:\windows\MSetup [MD5.B32189BDFF6E577A92BAA61AD49264E6] - [16/08/2015 22:33:31] - (.© Microsoft Corporation. Tous droits réservés. - Bloc-notes.) - [193536] - (6.1.7601.18917) - C:\windows\notepad.exe [14/07/2009 07:32:38] - |D| - [65] - C:\windows\Offline Web Pages [02/08/2009 04:27:40] - |D| - [0] - C:\windows\Panther [25/10/2010 09:47:57] - |D| - [0] - C:\windows\PCHEALTH [14/07/2009 07:32:38] - |D| - [62204359] - C:\windows\Performance [MD5.56381B51A728004307B633FCFA6FAEA7] - [24/02/2016 17:41:26] - (.-.) - [440400] - (0.0.0.0) - C:\windows\PFRO.log [14/07/2009 05:20:10] - |D| - [1132015] - C:\windows\PLA [14/07/2009 05:20:10] - |D| - [2972554] - C:\windows\PolicyDefinitions [02/08/2009 03:28:40] - |D| - [45280206] - C:\windows\Prefetch [MD5.DB4C1752B0C964BD96E4B7D089CE7CA8] - [20/11/2009 19:17:38] - (.-.) - [480056] - (0.0.0.0) - C:\windows\R-series.bmp [MD5.F2F7CD17E0C3A9F846522DB9A3CB484F] - [20/11/2009 18:39:46] - (.-.) - [673] - (0.0.0.0) - C:\windows\R-series.c1 [MD5.F2F7CD17E0C3A9F846522DB9A3CB484F] - [20/11/2009 18:39:46] - (.-.) - [673] - (0.0.0.0) - C:\windows\R-series.c3 [MD5.5D741A9F2F66C6C1EB8E5AA6D84452D8] - [24/10/2006 18:06:36] - (.-.) - [639] - (0.0.0.0) - C:\windows\R-series.c4 [MD5.1CB939EA60BE00BAAB8F30A86024A841] - [20/02/2008 17:49:00] - (.Copyright © 2004-2008 Jan Kolarik & Ondrej Vaverka - Screensaver created with InstantStorm.) - [495104] - (1.5.3.0) - C:\windows\R-series.exe [MD5.235C926EC408B65B509D6D3E6F13DD5F] - [20/11/2009 18:39:14] - (.-.) - [10446] - (0.0.0.0) - C:\windows\R-series.ico [MD5.D41D8CD98F00B204E9800998ECF8427E] - [08/10/2006 20:33:54] - (.-.) - [0] - (0.0.0.0) - C:\windows\R-series.ini [MD5.7234FEA58FE972E8D1B3D96DEC67FBC5] - [20/02/2008 17:50:28] - (.Copyright © 2004-2008 Jan Kolarik & Ondrej Vaverka - Screensaver created with InstantStorm.) - [903680] - (1.5.3.0) - C:\windows\R-series.scr [MD5.EF903A7916BA7FB9CC891A5F85B4104E] - [20/11/2009 14:56:12] - (.-.) - [10478708] - (0.0.0.0) - C:\windows\R-series.swf [MD5.2E2C937846A0B8789E5E91739284D17A] - [14/07/2009 01:27:10] - (.© Microsoft Corporation. Tous droits réservés. - Éditeur du Registre.) - [427008] - (6.1.7600.16385) - C:\windows\regedit.exe [14/07/2009 05:20:10] - |D| - [22588] - C:\windows\Registration [MD5.51414CB4A0BE4703A1ACB4E50518BD5C] - [25/10/2010 10:04:51] - (.-.) - [47584] - (0.0.0.0) - C:\windows\Report.htm [14/07/2009 05:20:10] - |D| - [7087452] - C:\windows\rescache [MD5.B543F54C0E5C551066129C389CA3BF26] - [08/01/2011 08:46:48] - (.TODO: (c) . - TODO: .) - [423936] - (1.0.0.1) - C:\windows\Reseal64.exe [14/07/2009 05:20:10] - |D| - [1676954] - C:\windows\Resources [MD5.C0E078A1C4ADA282131D141EA5154510] - [25/10/2010 08:24:13] - (.Realtek Semiconductor Corp. Copyright (C) 2009 - RtlExUpd DLL for setup utility function.) - [838176] - (1.0.1.8) - C:\windows\RtlExUpd.dll [MD5.F53B03707C7ED9A9D69393FD84E5B6CD] - [25/10/2010 08:29:20] - (.-.) - [16018] - (0.0.0.0) - C:\windows\Samsung.png [14/07/2009 05:20:10] - |D| - [0] - C:\windows\SchCache [14/07/2009 05:20:10] - |D| - [58021] - C:\windows\schemas [02/08/2009 04:27:11] - |D| - [2311612] - C:\windows\Sec [14/07/2009 05:20:10] - |D| - [1056998] - C:\windows\security [14/07/2009 06:45:47] - |D| - [128141604] - C:\windows\ServiceProfiles [14/07/2009 05:20:10] - |D| - [197472105] - C:\windows\servicing [MD5.2226109C5FCC0BD014F40D50432DE3EA] - [25/10/2010 09:59:18] - (.Copyright (C) 2005 - SetDisplayResolution MFC Program.) - [307200] - (1.2.0.8) - C:\windows\SetDisplayResolution.exe [MD5.99781C9D6344FB1D65D93B962B508942] - [25/10/2010 09:59:18] - (.-.) - [3282] - (0.0.0.0) - C:\windows\SetDisplayResolutionDT.xml [MD5.201FDD2F8231EF33C1D9210577624F4D] - [25/10/2010 09:59:18] - (.-.) - [3282] - (0.0.0.0) - C:\windows\SetDisplayResolutionNP.xml [MD5.4673C94AEE1AD9C4BEAE58ECC3DBC2B8] - [25/10/2010 09:11:44] - (.Samsung Electronics Co., Ltd. - SetLCDStretchMode.) - [345600] - (1.0.2.1) - C:\windows\SetLCDStretchMode.exe [14/07/2009 06:45:50] - |D| - [13802] - C:\windows\Setup [MD5.D8D8664B157A7C3F2DFF0765DE74316A] - [24/02/2016 17:41:37] - (.-.) - [3360] - (0.0.0.0) - C:\windows\setupact.log [MD5.D41D8CD98F00B204E9800998ECF8427E] - [24/02/2016 17:41:37] - (.-.) - [0] - (0.0.0.0) - C:\windows\setuperr.log [26/10/2010 00:49:31] - |D| - [101851] - C:\windows\ShellNew [26/10/2010 00:18:12] - |D| - [4674442279] - C:\windows\SoftwareDistribution [14/07/2009 05:20:10] - |D| - [70579144] - C:\windows\Speech [MD5.127AA81343A7C6F665C22CB1293B0A90] - [02/10/2012 10:26:20] - (.© Microsoft Corporation. - Print driver host for 32bit applications.) - [67072] - (6.1.7601.17777) - C:\windows\splwow64.exe [MD5.9060C3C745E7B2D8E1A81DD061021546] - [14/07/2009 07:28:38] - (.-.) - [48201] - (0.0.0.0) - C:\windows\Starter.xml [MD5.BC4133E8F2311394FF990DE5A8F2F7D9] - [25/02/2011 22:56:28] - (.-.) - [562718] - (0.0.0.0) - C:\windows\surbey.ico [14/07/2009 05:20:10] - |D| - [0] - C:\windows\system [MD5.286A9EDB379DC3423A528B0864A0F111] - [14/07/2009 04:34:57] - (.-.) - [219] - (0.0.0.0) - C:\windows\system.ini [14/07/2009 05:20:10] - |D| - [5136098963] - C:\windows\System32 [14/07/2009 05:20:14] - |D| - [1305991103] - C:\windows\SysWOW64 [14/07/2009 05:20:14] - |D| - [15] - C:\windows\TAPI [14/07/2009 05:20:14] - |D| - [38666] - C:\windows\Tasks [14/07/2009 05:20:14] - |D| - [172870981] - C:\windows\Temp [14/07/2009 05:20:14] - |D| - [0] - C:\windows\tracing [MD5.0BEA3F79A36B1F67B2CE0F595524C77C] - [10/06/2009 23:41:17] - (.- Twain Source Manager (Image Acquisition Interface).) - [94784] - (1.7.0.0) - C:\windows\twain.dll [14/07/2009 07:32:38] - |D| - [18629983] - C:\windows\twain_32 [MD5.163A95975E1D8819E653AA3E961371CA] - [02/10/2012 22:04:51] - (.- Gestionnaire de sources Twain_32 (Image Acquisition Interface).) - [51200] - (1.7.1.3) - C:\windows\twain_32.dll [MD5.F36A271706EDD23C94956AFB56981184] - [14/07/2009 00:47:26] - (.- Twain_32.dll Client's 16-Bit Thunking Server.) - [49680] - (1.7.0.0) - C:\windows\twunk_16.exe [MD5.0BD6E68F3EA0DD62CD86283D86895381] - [14/07/2009 02:14:40] - (.- Twain.dll Client's 32-Bit Thunking Server.) - [31232] - (1.7.1.0) - C:\windows\twunk_32.exe [14/07/2009 05:20:14] - |D| - [12420] - C:\windows\Vss [14/07/2009 05:20:14] - |D| - [46452220] - C:\windows\Web [MD5.C667A0A4D08227ED19D7720FAF7E2D54] - [14/07/2009 04:34:57] - (.-.) - [510] - (0.0.0.0) - C:\windows\win.ini [MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - [14/07/2009 06:54:24] - (.-.) - [749] - (0.0.0.0) - C:\windows\WindowsShell.Manifest [MD5.3630F4C4272DABF099F19CBC0AE52A23] - [26/10/2010 00:18:08] - (.-.) - [1611475] - (0.0.0.0) - C:\windows\WindowsUpdate.log [MD5.1D420D66250BCAAAED05724FB34008CF] - [14/07/2009 02:12:29] - (.© Microsoft Corporation. Tous droits réservés. - Relais Windows Winhlp32.) - [9728] - (6.1.7600.16385) - C:\windows\winhlp32.exe [14/07/2009 05:20:14] - |D| - [28046024256] - C:\windows\winsxs [MD5.4860944ABF2F8EAB74039A3A132B9995] - [08/03/2012 18:37:20] - (.© 2010 Microsoft Corporation. Tous droits réservés. - Écran de veille photos Windows Live.) - [302448] - (15.4.3555.308) - C:\windows\WLXPGSS.SCR [MD5.1EE445899AD3878ED0668E7DFDAC11F7] - [11/12/2002 13:11:50] - (.-.) - [19492] - (0.0.0.0) - C:\windows\WMPrfChs.prx [MD5.33B38F0A45AF240B8168615F32626FE6] - [11/12/2002 13:11:50] - (.-.) - [18804] - (0.0.0.0) - C:\windows\WMPrfCht.prx [MD5.35326EACBBEDFE3320128AA4D9E3CE26] - [11/12/2002 13:11:50] - (.-.) - [33820] - (0.0.0.0) - C:\windows\WMPrfDeu.prx [MD5.646F7663ACFE045FD8AA7E716FDB25E9] - [11/12/2002 13:11:50] - (.-.) - [35590] - (0.0.0.0) - C:\windows\WMPrfEsp.prx [MD5.2449E01AA5EFCA4A6862B6D8B040A97C] - [11/12/2002 13:11:50] - (.-.) - [37916] - (0.0.0.0) - C:\windows\WMPrfFra.prx [MD5.FCB1C196D3E0C21BE5FD9C06DCA2CF06] - [11/12/2002 13:11:50] - (.-.) - [35680] - (0.0.0.0) - C:\windows\WMPrfIta.prx [MD5.4956D92DCDCBDEBD7C90D86916CA4D77] - [11/12/2002 13:11:50] - (.-.) - [23304] - (0.0.0.0) - C:\windows\WMPrfJpn.prx [MD5.F8757A5EB20A041122FB87DF5C89EDD7] - [11/12/2002 13:11:50] - (.-.) - [22338] - (0.0.0.0) - C:\windows\WMPrfKor.prx [MD5.F0F7F6E1B8827380BEEA280448FCB023] - [11/12/2002 13:11:50] - (.-.) - [32964] - (0.0.0.0) - C:\windows\WMPrfNld.prx [MD5.0063D7FBBB1C2864BD475A2B70AD4C69] - [11/12/2002 13:11:50] - (.-.) - [35822] - (0.0.0.0) - C:\windows\WMPrfPlk.prx [MD5.89F0EE2791CC6BB0AA0E17A6C5415257] - [11/12/2002 13:11:50] - (.-.) - [35306] - (0.0.0.0) - C:\windows\WMPrfRus.prx [MD5.A6F5D676F3780F31A30D9917C0F7152A] - [11/12/2002 13:11:50] - (.-.) - [32022] - (0.0.0.0) - C:\windows\WMPrfTrk.prx [MD5.DC17DD0189B0C36D863B4DD0A036C10F] - [10/06/2009 22:52:44] - (.-.) - [316640] - (0.0.0.0) - C:\windows\WMSysPr9.prx [MD5.F8ED3B4B209E2CB49028E36CF06CA851] - [14/07/2009 01:56:28] - (.© Microsoft Corporation. - Windows Write.) - [10240] - (6.1.7600.16385) - C:\windows\write.exe ¤¤¤¤¤¤¤¤¤¤ | Systemroot\System ¤¤¤¤¤¤¤¤¤¤ | Systemroot\Installer [16/10/2014 15:03:51] - C:\windows\Installer\17697e.msi : (Google Toolbar for Internet Explorer - Google Inc.) [03/06/2010 20:03:08] - C:\windows\Installer\18767.msi : (Blank Project Template - CyberLink Corp.) [21/11/2009 04:31:48] - C:\windows\Installer\1876d.msi : (Samsung R-Series - Samsung Electronics) [08/03/2016 18:43:45] - C:\windows\Installer\26c76.msi : (Looks for updates for your computer's software and drivers to improve performance. - Slimware Utilities Holdings, Inc.) [25/12/2015 22:23:56] - C:\windows\Installer\27ca36.msi : (LeapFrog Connect - LeapFrog Enterprises, Inc.) [25/12/2015 22:11:18] - C:\windows\Installer\27ca3c.msi : (LeapFrog LeapPad Explorer Plugin Installer - LeapFrog) [25/01/2012 19:48:16] - C:\windows\Installer\2fd5b0.msi : (Blank Project Template - Macrovision Corporation) [03/02/2016 23:21:42] - C:\windows\Installer\35a08a.msi : (Google Update Helper - Google Inc.) [17/03/2015 10:41:29] - C:\windows\Installer\39fd78.msi : ( - Adobe Systems Incorporated) [02/10/2015 10:29:49] - C:\windows\Installer\3d7ce0.msi : (HP Support Solutions Framework - Hewlett-Packard Company) [22/07/2014 03:26:52] - C:\windows\Installer\3d7e3d.msi : (HP ENVY 4500 series Basic Device Software - Hewlett-Packard Co.) [22/07/2014 03:26:55] - C:\windows\Installer\3d7e4c.msi : (Product Improvement Study for HP ENVY 4500 series - Hewlett-Packard Co.) [15/06/2010 11:16:22] - C:\windows\Installer\50614.msi : (Intel(R) WiFi - Intel Corporation) [14/08/2009 00:25:16] - C:\windows\Installer\50619.msi : (Blank Project Template - CyberLink Corp.) [22/07/2009 01:45:16] - C:\windows\Installer\5061f.msi : (Blank Project Template - CyberLink Corp.) [21/07/2009 21:31:36] - C:\windows\Installer\50625.msi : (Blank Project Template - CyberLink Corp.) [20/08/2009 02:59:24] - C:\windows\Installer\5062b.msi : (Blank Project Template - CyberLink Corp.) [14/08/2009 00:36:44] - C:\windows\Installer\50638.msi : (Blank Project Template - CyberLink Corp.) [20/08/2009 03:06:02] - C:\windows\Installer\5063e.msi : (Blank Project Template - CyberLink Corp.) [21/07/2009 21:39:32] - C:\windows\Installer\50649.msi : (Blank Project Template - CyberLink Corp.) [01/06/2010 21:53:28] - C:\windows\Installer\50653.msi : ( - Samsung Electronics. Co. Ltd.) [21/05/2010 18:06:18] - C:\windows\Installer\5065b.msi : ( - Samsung) [07/05/2010 01:50:12] - C:\windows\Installer\50662.msi : ( - Samsung Electronics Co. Ltd.) [12/09/2010 15:03:11] - C:\windows\Installer\515eac.msi : (Blank Project Template - Samsung Electronics) [01/01/2010 02:00:00] - C:\windows\Installer\653db2.msi : (Facebook Messenger 2.1.4814.0 - Facebook) [08/07/2013 18:09:26] - C:\windows\Installer\7a0227.msi : ( - Rentabiliweb) [27/08/2010 04:36:50] - C:\windows\Installer\7e0cc3.msi : ( - Samsung) [05/07/2013 10:58:06] - C:\windows\Installer\911b1.msi : (HP FWUpdateEDO2 - Hewlett-Packard) [05/06/2013 21:29:12] - C:\windows\Installer\c704e5.msi : (HP Update - Hewlett-Packard) [09/01/2013 08:25:19] - C:\windows\Installer\c704ec.msi : (HP ENVY 4500 series Get product specific help to easily troubleshoot and fix problems. - Hewlett Packard) [09/03/2016 17:21:34] - C:\windows\Installer\d3c5c5.msi : (Visual Studio 2012 x64 Redistributables - AVG Technologies) [09/03/2016 17:21:55] - C:\windows\Installer\d3c5c9.msi : (Visual Studio 2012 x86 Redistributables - AVG Technologies CZ, s.r.o.) [14/01/2016 13:31:28] - C:\windows\Installer\e1a6f.msi : (Adobe ARM Installer - Adobe Systems Incorporated) ¤¤¤¤¤¤¤¤¤¤ | %System%\*.in* [14/07/2009 06:57:09] - [73] - C:\windows\System32\desktop.ini [15/04/2015 09:29:11] - [16303] - C:\windows\System32\ieuinit.inf [14/07/2009 07:13:15] - [1669584] - C:\windows\System32\PerfStringBackup.INI [10/06/2009 23:01:25] - [60124] - C:\windows\System32\tcpmon.ini [15/04/2015 09:29:15] - [16303] - C:\windows\Syswow64\ieuinit.inf [03/04/2013 22:38:18] - [685] - C:\windows\Syswow64\InstallUtil.InstallLog [14/07/2009 06:55:01] - [535] - C:\windows\Syswow64\mapisvc.inf [05/05/2013 21:45:06] - [1644652] - C:\windows\Syswow64\PerfStringBackup.INI ¤¤¤¤¤¤¤¤¤¤ | [magali] [25/02/2011 22:37:23] - |HD| - [7582446631] - C:\Users\magali\AppData [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\Application Data [25/02/2011 22:56:57] - |RD| - [68787] - C:\Users\magali\Contacts [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\Cookies [16/09/2011 15:36:56] - |D| - [0] - C:\Users\magali\CyberLink [25/02/2011 22:37:23] - |RD| - [111992579] - C:\Users\magali\Desktop [25/02/2011 22:52:22] - |A| - [148] - C:\Users\magali\DiskScrP.txt [25/02/2011 22:37:23] - |RD| - [183043152] - C:\Users\magali\Documents [25/02/2011 22:37:23] - |RD| - [398775000] - C:\Users\magali\Downloads [25/02/2011 22:37:23] - |RD| - [30235] - C:\Users\magali\Favorites [25/02/2011 22:37:23] - |RD| - [3186] - C:\Users\magali\Links [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\Local Settings [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\Menu Démarrer [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\Mes documents [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\Modèles [25/02/2011 22:37:23] - |RD| - [3479] - C:\Users\magali\Music [25/02/2011 22:37:23] - |ASH| - [30408704] - C:\Users\magali\NTUSER.DAT [25/02/2011 22:37:24] - |ASH| - [262144] - C:\Users\magali\ntuser.dat.LOG1 [25/02/2011 22:37:24] - |ASH| - [0] - C:\Users\magali\ntuser.dat.LOG2 [25/02/2011 22:37:24] - |ASH| - [65536] - C:\Users\magali\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [25/02/2011 22:37:24] - |ASH| - [524288] - C:\Users\magali\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [25/02/2011 22:37:24] - |ASH| - [524288] - C:\Users\magali\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [25/02/2011 22:37:24] - |SH| - [20] - C:\Users\magali\ntuser.ini [25/02/2011 22:37:23] - |RD| - [11343241097] - C:\Users\magali\Pictures [16/09/2011 15:36:42] - |HD| - [0] - C:\Users\magali\PP_ROTATE_SLIDE.TMP [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\Recent [25/02/2011 22:37:23] - |RD| - [282] - C:\Users\magali\Saved Games [25/02/2011 22:57:16] - |RD| - [1020] - C:\Users\magali\Searches [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\SendTo [10/03/2011 10:07:35] - |D| - [0] - C:\Users\magali\Tracing [25/02/2011 22:37:23] - |RD| - [504] - C:\Users\magali\Videos [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\Voisinage d'impression [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\Voisinage réseau [25/02/2011 22:38:34] - |D| - [42791570] - C:\Users\magali\AppData\Local\Adobe [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\AppData\Local\Application Data [21/01/2013 18:50:39] - |D| - [1632663] - C:\Users\magali\AppData\Local\Apps [28/10/2012 00:37:26] - |A| - [112044] - C:\Users\magali\AppData\Local\ars.cache [10/03/2016 10:57:31] - |D| - [19569350] - C:\Users\magali\AppData\Local\Avg [09/03/2016 17:15:50] - |D| - [22607542] - C:\Users\magali\AppData\Local\AvgSetupLog [06/08/2015 11:03:14] - |D| - [0] - C:\Users\magali\AppData\Local\CEF [28/10/2012 00:38:22] - |A| - [830603] - C:\Users\magali\AppData\Local\census.cache [13/11/2015 11:32:08] - |D| - [388249595] - C:\Users\magali\AppData\Local\Chromium [18/06/2014 19:47:08] - |A| - [5120] - C:\Users\magali\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [21/01/2013 18:50:39] - |D| - [0] - C:\Users\magali\AppData\Local\Deployment [09/03/2011 22:44:45] - |D| - [3596511] - C:\Users\magali\AppData\Local\Diagnostics [05/05/2013 21:17:22] - |D| - [0] - C:\Users\magali\AppData\Local\Downloaded Installations [03/11/2015 16:22:20] - |D| - [53575680] - C:\Users\magali\AppData\Local\Downloaded Installers [13/12/2012 23:00:22] - |D| - [0] - C:\Users\magali\AppData\Local\ElevatedDiagnostics [14/11/2014 18:54:47] - |SHD| - [0] - C:\Users\magali\AppData\Local\EmieBrowserModeList [20/05/2014 14:58:59] - |SHD| - [0] - C:\Users\magali\AppData\Local\EmieSiteList [20/05/2014 14:58:59] - |SHD| - [0] - C:\Users\magali\AppData\Local\EmieUserList [01/10/2012 16:58:35] - |D| - [79452397] - C:\Users\magali\AppData\Local\Facebook [10/03/2016 10:56:18] - |D| - [0] - C:\Users\magali\AppData\Local\Flvto YouTube Downloader [28/02/2011 00:05:45] - |A| - [115512] - C:\Users\magali\AppData\Local\GDIPFONTCACHEV1.DAT [29/07/2014 12:34:52] - |D| - [0] - C:\Users\magali\AppData\Local\globalUpdate [12/03/2011 00:29:25] - |D| - [493844431] - C:\Users\magali\AppData\Local\Google [02/10/2015 10:31:27] - |D| - [2788] - C:\Users\magali\AppData\Local\Hewlett-Packard [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\AppData\Local\Historique [18/02/2015 19:48:19] - |D| - [8373] - C:\Users\magali\AppData\Local\Hotger [28/10/2012 00:06:21] - |A| - [36] - C:\Users\magali\AppData\Local\housecall.guid.cache [16/10/2014 15:00:11] - |D| - [319912] - C:\Users\magali\AppData\Local\HP [23/02/2016 22:57:44] - |AH| - [4848935] - C:\Users\magali\AppData\Local\IconCache.db [25/02/2011 22:37:23] - |D| - [1422340775] - C:\Users\magali\AppData\Local\Microsoft [23/05/2014 14:00:34] - |D| - [106180] - C:\Users\magali\AppData\Local\Microsoft Help [01/12/2013 16:40:47] - |D| - [0] - C:\Users\magali\AppData\Local\NativeMessaging [09/03/2016 17:33:06] - |D| - [0] - C:\Users\magali\AppData\Local\Opera Software [25/02/2011 22:57:54] - |D| - [72704] - C:\Users\magali\AppData\Local\Power2Go [02/05/2013 18:01:22] - |D| - [0] - C:\Users\magali\AppData\Local\Programs [19/02/2016 19:23:48] - |D| - [304] - C:\Users\magali\AppData\Local\Semantis [05/04/2013 20:33:45] - |D| - [6562] - C:\Users\magali\AppData\Local\Shalsoft [18/06/2014 15:40:38] - |D| - [704602919] - C:\Users\magali\AppData\Local\Shareaza [07/03/2014 23:02:13] - |D| - [4887808] - C:\Users\magali\AppData\Local\Skype [02/05/2013 16:17:50] - |D| - [0] - C:\Users\magali\AppData\Local\Software [13/12/2013 12:03:28] - |D| - [3049306334] - C:\Users\magali\AppData\Local\Spotify [25/02/2011 22:37:23] - |D| - [123403706] - C:\Users\magali\AppData\Local\Temp [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\AppData\Local\Temporary Internet Files [25/02/2011 22:56:52] - |D| - [741128225] - C:\Users\magali\AppData\Local\VirtualStore [01/12/2013 16:39:41] - |D| - [194848] - C:\Users\magali\AppData\Local\WhiteListing [09/03/2011 23:24:14] - |D| - [139264] - C:\Users\magali\AppData\Local\Windows Live [13/03/2011 19:34:10] - |D| - [648363] - C:\Users\magali\AppData\Local\Windows Live Writer [25/06/2011 10:16:40] - |D| - [0] - C:\Users\magali\AppData\Local\{00A60A0B-CB8F-4118-BA7C-1AA7106F7AD1} [13/03/2012 15:57:15] - |D| - [0] - C:\Users\magali\AppData\Local\{0113B529-E5D8-4391-BEB4-38415CDEF98F} [26/01/2012 09:57:01] - |D| - [0] - C:\Users\magali\AppData\Local\{0165BE24-2EDD-474C-9616-9DC35DD8851D} [06/03/2012 19:50:09] - |D| - [0] - C:\Users\magali\AppData\Local\{01DDA2B6-75A1-416C-B803-FC2DB6B1F95A} [25/04/2014 16:28:12] - |A| - [0] - C:\Users\magali\AppData\Local\{025DCCEE-1EEC-4666-9B47-A6E47DC8CAF0} [10/02/2013 09:44:17] - |D| - [0] - C:\Users\magali\AppData\Local\{02B95BAB-25DE-443C-9D0F-46026748D8AB} [14/03/2011 09:57:12] - |D| - [0] - C:\Users\magali\AppData\Local\{0384A31A-64EA-463F-A768-2130930F3B5F} [28/01/2012 21:00:17] - |D| - [0] - C:\Users\magali\AppData\Local\{03861F98-54C1-4145-910F-AC094FEBA41F} [12/07/2011 15:39:22] - |D| - [0] - C:\Users\magali\AppData\Local\{03AB90F1-31B3-4FD2-AED9-033477E7D2FF} [03/03/2013 10:58:21] - |D| - [0] - C:\Users\magali\AppData\Local\{03EEDF27-CA96-414C-80D7-024FA90F72D6} [12/09/2012 09:16:57] - |D| - [0] - C:\Users\magali\AppData\Local\{04054A3E-BB07-479C-8338-A8F6D66BD7DA} [03/10/2011 21:47:16] - |D| - [0] - C:\Users\magali\AppData\Local\{0578EB69-DC86-490E-84C3-7E2B76F34941} [20/01/2013 10:43:20] - |D| - [0] - C:\Users\magali\AppData\Local\{05C37887-9917-4C0D-B7B0-2C29011E84FA} [02/11/2011 22:12:30] - |D| - [0] - C:\Users\magali\AppData\Local\{0601C399-96A1-47FC-A4C9-736E53F9DD38} [04/07/2011 23:03:06] - |D| - [0] - C:\Users\magali\AppData\Local\{060CEE30-AB95-428F-921C-988FE26986B3} [30/11/2014 23:19:19] - |D| - [0] - C:\Users\magali\AppData\Local\{0658C6EA-C2AF-442A-9F31-587950024B84} [19/01/2013 10:42:25] - |D| - [0] - C:\Users\magali\AppData\Local\{0684F838-E715-4A5C-83B5-3556CDB0C94B} [15/07/2011 01:15:46] - |D| - [0] - C:\Users\magali\AppData\Local\{06BF703D-89F8-4C6C-8464-5642BADEDF21} [16/04/2013 22:13:02] - |D| - [0] - C:\Users\magali\AppData\Local\{06D68EB7-523D-4859-A637-C5543C9759C7} [22/10/2012 15:31:47] - |D| - [0] - C:\Users\magali\AppData\Local\{06F19802-6FB1-4C12-B612-AA395A8407E3} [23/05/2012 16:41:41] - |D| - [0] - C:\Users\magali\AppData\Local\{06F32F4F-0AFF-48DC-AF51-E6C2E5539E9A} [17/04/2013 22:51:54] - |D| - [0] - C:\Users\magali\AppData\Local\{08255991-A108-43CD-B47E-D892F1D57445} [15/07/2012 18:48:53] - |D| - [0] - C:\Users\magali\AppData\Local\{089BE76B-92F9-4BEE-A723-4F5766769738} [29/03/2013 22:58:28] - |D| - [0] - C:\Users\magali\AppData\Local\{0976268B-39D0-4E11-822D-04630DD78130} [10/08/2012 19:09:47] - |D| - [0] - C:\Users\magali\AppData\Local\{098CD7D5-01AB-4733-850A-D77226364F83} [15/02/2012 10:53:06] - |D| - [0] - C:\Users\magali\AppData\Local\{09E2D730-F720-4763-9F24-AA3D559A8333} [02/02/2012 15:42:09] - |D| - [0] - C:\Users\magali\AppData\Local\{0AA48A11-83B9-468E-A5BF-E740DE6D422E} [24/06/2011 22:13:46] - |D| - [0] - C:\Users\magali\AppData\Local\{0AAF92E1-A8FB-4BB1-AB27-CB939FFFA4EE} [15/05/2012 14:27:10] - |D| - [0] - C:\Users\magali\AppData\Local\{0B038BFF-F1AA-4508-807A-FF40735C1BDC} [18/04/2012 21:55:28] - |D| - [0] - C:\Users\magali\AppData\Local\{0B646371-B2C2-4341-99F4-FC3D47C2014E} [18/03/2012 22:37:11] - |D| - [0] - C:\Users\magali\AppData\Local\{0C356A3F-2615-4A7D-B79E-581D8780098F} [05/03/2013 09:54:05] - |D| - [0] - C:\Users\magali\AppData\Local\{0C405500-76A7-4A15-BB59-254F34AA0123} [09/10/2012 10:04:04] - |D| - [0] - C:\Users\magali\AppData\Local\{0C6D349F-8057-439C-819C-5C22F11DA5C8} [26/10/2012 10:35:58] - |D| - [0] - C:\Users\magali\AppData\Local\{0D93E3AA-EFA5-44E3-AF9C-6C8890628FF2} [16/03/2011 11:06:58] - |D| - [0] - C:\Users\magali\AppData\Local\{0E39FBB2-6882-4B56-A668-FC6D7598C64E} [26/07/2011 21:12:09] - |D| - [0] - C:\Users\magali\AppData\Local\{0F24CAE2-1CD2-4339-869E-100BD8D7C160} [30/08/2012 16:34:56] - |D| - [0] - C:\Users\magali\AppData\Local\{0F5AA810-17CD-4CCD-AEEB-65CF975E8D2A} [25/06/2012 21:07:44] - |D| - [0] - C:\Users\magali\AppData\Local\{0FA68464-FAEC-4DFF-808F-277AD1D482B3} [18/02/2013 09:55:45] - |D| - [0] - C:\Users\magali\AppData\Local\{1033DC74-EE12-4392-AE7A-11E0D3838DA5} [29/07/2012 09:57:11] - |D| - [0] - C:\Users\magali\AppData\Local\{103921C2-A75F-4DE4-A49D-9EA794E553A2} [17/11/2015 15:30:48] - |D| - [1309358] - C:\Users\magali\AppData\Local\{10682634-34C0-4A8C-5958-6F647D3093FC} [05/05/2011 14:35:12] - |D| - [0] - C:\Users\magali\AppData\Local\{10D3D5FC-1009-416C-B147-D628E47BF008} [08/04/2013 15:19:40] - |D| - [0] - C:\Users\magali\AppData\Local\{10F9CE9C-7747-4EE3-A4F4-67A5E305C0C3} [18/04/2012 16:52:02] - |D| - [0] - C:\Users\magali\AppData\Local\{11089EE4-95BC-4655-9166-05E6DB76A437} [18/02/2013 21:56:20] - |D| - [0] - C:\Users\magali\AppData\Local\{111053B6-7704-4506-9568-DB2F98CA5F08} [14/04/2013 18:51:39] - |D| - [0] - C:\Users\magali\AppData\Local\{11412BD6-D42D-4617-96C4-A7FEE4144B6B} [30/11/2014 23:33:11] - |D| - [0] - C:\Users\magali\AppData\Local\{11DAEE94-1343-460B-BE05-14CA632A1434} [19/03/2013 23:19:22] - |D| - [0] - C:\Users\magali\AppData\Local\{123975B7-8DA5-4188-A3E9-4A05C1E6E1AA} [13/02/2012 10:43:18] - |D| - [0] - C:\Users\magali\AppData\Local\{12BF82B6-F68A-4849-B1EE-824007066FCE} [08/08/2012 20:58:03] - |D| - [0] - C:\Users\magali\AppData\Local\{12CDB1D8-F758-49BB-87C4-206BC0C39A72} [04/09/2011 16:08:02] - |D| - [0] - C:\Users\magali\AppData\Local\{12E9B2A6-1354-4E37-BCFC-932DF46549FE} [24/07/2012 09:00:45] - |D| - [0] - C:\Users\magali\AppData\Local\{133E8708-02D9-4CBF-BB95-2E05C312400B} [14/09/2012 09:29:19] - |D| - [0] - C:\Users\magali\AppData\Local\{1377526A-782E-4E69-8567-5FE608233963} [18/07/2011 23:24:00] - |D| - [0] - C:\Users\magali\AppData\Local\{139CD459-FFDE-4FBE-849C-B4628618BE59} [09/07/2012 15:29:33] - |D| - [0] - C:\Users\magali\AppData\Local\{13B3E80E-354E-485B-AC46-DCB17E01C0B6} [26/02/2012 20:01:03] - |D| - [0] - C:\Users\magali\AppData\Local\{13D1A130-C51E-432C-AB88-B39E4FF9B28F} [12/11/2012 09:35:22] - |D| - [0] - C:\Users\magali\AppData\Local\{14648282-FE15-4D16-AEC9-571DD31D20A1} [25/08/2012 19:29:29] - |D| - [0] - C:\Users\magali\AppData\Local\{14876AE8-C171-48DE-9B34-F047ABD966A6} [07/09/2011 21:41:15] - |D| - [0] - C:\Users\magali\AppData\Local\{1496E2BE-3732-4103-BB79-4B1691FAB513} [29/01/2012 15:50:45] - |D| - [0] - C:\Users\magali\AppData\Local\{14B6D2E6-7E0B-49F6-8F51-B5224830AF35} [24/10/2011 21:38:47] - |D| - [0] - C:\Users\magali\AppData\Local\{150E4A5D-50D0-4D4D-ABD4-53A867B8CBA5} [09/06/2011 10:28:39] - |D| - [0] - C:\Users\magali\AppData\Local\{150EB813-7D07-4ADF-A2B7-7FC9F25831A7} [03/02/2012 22:45:30] - |D| - [0] - C:\Users\magali\AppData\Local\{1517400F-CD2C-4F32-A5C9-FB306ED46F82} [08/08/2012 20:58:54] - |D| - [0] - C:\Users\magali\AppData\Local\{15B2AC8D-EF99-426C-A4EA-6BA002B4BDB3} [21/09/2011 09:57:13] - |D| - [0] - C:\Users\magali\AppData\Local\{15F79A82-81D2-4FFB-A773-AB229ED8D545} [11/04/2012 16:22:27] - |D| - [0] - C:\Users\magali\AppData\Local\{16351769-3B69-41B6-BE4E-3911C5804912} [06/05/2012 21:11:10] - |D| - [0] - C:\Users\magali\AppData\Local\{166DFA8D-B12D-4004-835F-E3516D7EF0FD} [24/01/2012 22:08:36] - |D| - [0] - C:\Users\magali\AppData\Local\{167C92DA-8572-42BA-ACE8-749669933346} [08/10/2012 21:14:18] - |D| - [0] - C:\Users\magali\AppData\Local\{173F6EAD-BEF7-4097-AAF1-25E531849592} [01/05/2011 22:21:46] - |D| - [0] - C:\Users\magali\AppData\Local\{179144B6-C3C4-4635-B363-FC405B1CC986} [17/10/2012 10:16:56] - |D| - [0] - C:\Users\magali\AppData\Local\{182278AB-E452-4D2D-B7AF-E2D6DDD21BFF} [20/06/2011 22:44:42] - |D| - [0] - C:\Users\magali\AppData\Local\{1829485A-0D82-465B-B78D-A86670A99FA1} [01/06/2012 15:04:59] - |D| - [0] - C:\Users\magali\AppData\Local\{1842A9E5-A73D-4882-BDA8-151A7E644A58} [04/11/2012 15:50:56] - |D| - [0] - C:\Users\magali\AppData\Local\{188BA512-E916-4E14-8867-B027CC18768D} [11/04/2013 10:51:56] - |D| - [0] - C:\Users\magali\AppData\Local\{18C68BBD-6A02-4FF7-B8CB-36B772A6B0DC} [13/07/2011 14:42:34] - |D| - [0] - C:\Users\magali\AppData\Local\{18CA5E61-6840-435A-B792-061ADF5AE9A9} [30/01/2013 16:21:33] - |D| - [0] - C:\Users\magali\AppData\Local\{1953E367-46DA-49DE-BF2D-9C81F6C8BD84} [12/02/2012 11:10:46] - |D| - [0] - C:\Users\magali\AppData\Local\{1A146B4A-190B-4240-8386-6E92CD374EF9} [15/03/2012 15:35:13] - |D| - [0] - C:\Users\magali\AppData\Local\{1A5C10CD-180E-4050-9413-18C5987140FD} [08/02/2012 13:41:12] - |D| - [0] - C:\Users\magali\AppData\Local\{1A8175D8-8165-471C-AF79-A03A52E5E2D7} [21/03/2013 23:01:57] - |D| - [0] - C:\Users\magali\AppData\Local\{1AF1CCF3-E219-41BE-97F2-DB5F84B57821} [06/07/2011 16:36:21] - |D| - [0] - C:\Users\magali\AppData\Local\{1B0013B0-C8D3-4C24-A916-EE53A690C9C1} [31/01/2012 18:55:38] - |D| - [0] - C:\Users\magali\AppData\Local\{1B319759-AD75-4D28-9AE7-AFAD29BE4F82} [28/10/2011 15:46:25] - |D| - [0] - C:\Users\magali\AppData\Local\{1B7EEEC9-CC46-420C-AB68-D283163E0C7E} [17/02/2012 11:02:30] - |D| - [0] - C:\Users\magali\AppData\Local\{1BFD5218-28D8-49E7-80B5-A3B6913C64A8} [21/09/2012 18:57:29] - |D| - [0] - C:\Users\magali\AppData\Local\{1C10E4A4-1C4D-488C-BB12-BB032A97A785} [05/04/2011 22:05:49] - |D| - [0] - C:\Users\magali\AppData\Local\{1C1BDABC-F668-47F3-8A5F-263C599AF297} [06/10/2012 10:54:44] - |D| - [0] - C:\Users\magali\AppData\Local\{1C536C3C-83D4-4D6C-8C2C-B68B585FB91F} [17/08/2011 22:37:06] - |D| - [0] - C:\Users\magali\AppData\Local\{1CA733EA-D785-4DD8-8B77-C834F76E879B} [31/01/2013 22:24:48] - |D| - [0] - C:\Users\magali\AppData\Local\{1F901983-A44D-41D9-8493-2D56ECADE160} [08/02/2012 13:41:48] - |D| - [0] - C:\Users\magali\AppData\Local\{1FC1D01C-E6E4-4266-B3A2-F140C20A8D35} [20/10/2012 18:05:06] - |D| - [0] - C:\Users\magali\AppData\Local\{1FF6C1E2-1216-43B8-89F6-3075403B7881} [17/05/2011 17:40:38] - |D| - [0] - C:\Users\magali\AppData\Local\{20180436-51C1-41C0-82EC-11A381DB9962} [18/06/2011 11:50:05] - |D| - [0] - C:\Users\magali\AppData\Local\{2038D8DB-EB9F-46F2-9324-904172B79F7B} [10/08/2012 19:10:31] - |D| - [0] - C:\Users\magali\AppData\Local\{2051811D-8615-4522-814B-9294CD85CC43} [23/02/2012 10:15:17] - |D| - [0] - C:\Users\magali\AppData\Local\{206BED9C-742B-454D-8B65-E9DB60CC585E} [21/08/2011 11:18:36] - |D| - [0] - C:\Users\magali\AppData\Local\{207798DC-E53C-4085-8192-1D9C2020F733} [04/04/2013 09:37:51] - |D| - [0] - C:\Users\magali\AppData\Local\{209F479F-75AA-4628-8A75-97B2E70BC46C} [18/10/2012 10:03:28] - |D| - [0] - C:\Users\magali\AppData\Local\{20A1DA52-BF33-45B4-AB35-7274033E727F} [04/07/2011 08:48:16] - |D| - [0] - C:\Users\magali\AppData\Local\{210E4F9E-5006-4CE8-A950-3071204AEB76} [19/11/2012 11:59:47] - |D| - [0] - C:\Users\magali\AppData\Local\{2134D5D1-9E26-4CE1-AD1F-87D6D433F0A7} [09/07/2011 11:32:30] - |D| - [0] - C:\Users\magali\AppData\Local\{21BE1E3C-B53A-4C07-8321-5AA8BFB6D922} [31/08/2011 10:01:53] - |D| - [0] - C:\Users\magali\AppData\Local\{22C3B3EA-A7E8-4B96-ACC5-3EEC7096F70E} [27/03/2013 17:32:23] - |D| - [0] - C:\Users\magali\AppData\Local\{22D5110E-F156-466E-8A78-ABFD4811B474} [08/09/2011 21:13:07] - |D| - [0] - C:\Users\magali\AppData\Local\{22F333CE-2A7A-40DD-A63D-51379CF73BA4} [01/02/2012 10:22:44] - |D| - [0] - C:\Users\magali\AppData\Local\{230F1B0B-0405-4576-8705-AF984DFC0479} [18/04/2011 23:43:42] - |D| - [0] - C:\Users\magali\AppData\Local\{2358C93B-A63F-4C9B-9634-F98ED138D4D1} [15/03/2012 15:35:57] - |D| - [0] - C:\Users\magali\AppData\Local\{238F420C-2EC1-4716-99A2-939FE2C47A51} [25/04/2011 20:34:10] - |D| - [0] - C:\Users\magali\AppData\Local\{23B3093F-46D3-4453-BDB7-E85C863EBC22} [12/12/2012 17:39:26] - |D| - [0] - C:\Users\magali\AppData\Local\{241044BF-D62C-4C2C-AA27-C2CF22A0C35E} [30/03/2011 21:37:24] - |D| - [0] - C:\Users\magali\AppData\Local\{24644DC0-928E-4549-A1E6-EB782D2D3F29} [06/11/2012 11:38:56] - |D| - [0] - C:\Users\magali\AppData\Local\{24E850ED-E51E-4059-978C-D9CB3C543412} [14/02/2012 15:24:28] - |D| - [0] - C:\Users\magali\AppData\Local\{250F3FEB-19E0-4C06-8203-1EACDE132EAB} [18/08/2012 22:15:33] - |D| - [0] - C:\Users\magali\AppData\Local\{254DAA03-9590-48C9-9481-3FC9E7AA8468} [21/07/2012 22:55:05] - |D| - [0] - C:\Users\magali\AppData\Local\{25552AC5-8349-4A02-A052-7E06CEF07C54} [25/04/2013 14:47:53] - |D| - [0] - C:\Users\magali\AppData\Local\{2761F822-3C10-4B91-B728-E501CCFDEFA9} [21/08/2011 11:17:35] - |D| - [0] - C:\Users\magali\AppData\Local\{276FB17B-7DBE-4935-89F6-4C59C4DB19EE} [17/10/2012 14:55:29] - |D| - [0] - C:\Users\magali\AppData\Local\{279B8EF1-68AA-44C6-B34C-81BD5050F2D8} [08/09/2011 21:16:55] - |D| - [0] - C:\Users\magali\AppData\Local\{28002D2E-173B-4CDC-8117-387F625F9CD2} [21/02/2012 10:28:44] - |D| - [0] - C:\Users\magali\AppData\Local\{282F0225-01BD-403C-A07C-A94ACBFFB1FE} [28/07/2011 22:02:20] - |D| - [0] - C:\Users\magali\AppData\Local\{289B6BC4-2147-4FB4-976A-4FCAD2816BAE} [22/02/2012 11:31:05] - |D| - [0] - C:\Users\magali\AppData\Local\{29473CF4-9373-491C-A29B-1400B4E936AA} [05/07/2011 11:04:00] - |D| - [0] - C:\Users\magali\AppData\Local\{2A31A53A-B07C-4759-B51F-EE90BDC4FFF7} [15/05/2011 03:34:35] - |D| - [0] - C:\Users\magali\AppData\Local\{2AD1B007-A71F-4E35-859E-62D1AA5F6C24} [12/10/2012 14:19:42] - |D| - [0] - C:\Users\magali\AppData\Local\{2AF54DE1-6D5E-4106-B3B1-D6412EE23415} [06/02/2013 14:57:26] - |D| - [0] - C:\Users\magali\AppData\Local\{2B09DF4E-CF94-47F3-A814-6BDB40244335} [01/08/2012 19:49:14] - |D| - [0] - C:\Users\magali\AppData\Local\{2B1D6C1C-8399-4C08-9E10-24191FC2F2F8} [10/03/2016 10:16:28] - |D| - [0] - C:\Users\magali\AppData\Local\{2BB3541F-3B48-4D7E-9B1B-DFC8B4C854A7} [15/06/2011 22:19:17] - |D| - [0] - C:\Users\magali\AppData\Local\{2BBC2597-EF8D-49D8-953D-9BA49E726AE1} [04/02/2016 12:01:26] - |D| - [0] - C:\Users\magali\AppData\Local\{2C65B66B-4DF0-46A8-8E38-1C536070A02C} [10/07/2012 22:15:05] - |D| - [0] - C:\Users\magali\AppData\Local\{2CF219F1-5474-410A-9440-5EE39FCE79D6} [24/02/2012 15:11:59] - |D| - [0] - C:\Users\magali\AppData\Local\{2CF66712-FE8A-43B9-A878-4F4B47C989B9} [19/02/2012 23:58:02] - |D| - [0] - C:\Users\magali\AppData\Local\{2D3754E3-DAD2-47CC-A8B9-C4FBA78B0901} [18/04/2012 21:55:50] - |D| - [0] - C:\Users\magali\AppData\Local\{2D9448B0-2185-4F6C-A7CA-9605EFE87FD3} [15/06/2011 10:18:51] - |D| - [0] - C:\Users\magali\AppData\Local\{2E8236DC-C044-4192-8FA7-02496934F328} [14/11/2012 11:23:30] - |D| - [0] - C:\Users\magali\AppData\Local\{2F60C960-F19B-4084-8903-67BC8DAA71B9} [19/03/2013 11:19:01] - |D| - [0] - C:\Users\magali\AppData\Local\{2FFA4DBF-37FA-4E9C-AB7B-13F8B79DCFB7} [26/05/2012 11:03:11] - |D| - [0] - C:\Users\magali\AppData\Local\{30641707-8C74-4CAC-9913-6D27EECC776B} [04/07/2012 10:41:49] - |D| - [0] - C:\Users\magali\AppData\Local\{3070CE9E-6A5C-466C-A8DD-819E78675ED3} [27/07/2011 11:26:04] - |A| - [0] - C:\Users\magali\AppData\Local\{30B198F3-D1E9-4F6A-83F2-45CC2F5D97D1} [07/12/2012 11:08:38] - |D| - [0] - C:\Users\magali\AppData\Local\{311D53D0-B1DD-4C16-AC02-60790BCA0A7A} [29/05/2011 22:53:45] - |D| - [0] - C:\Users\magali\AppData\Local\{31464915-FC2F-4756-9551-DD90EA950D2B} [10/03/2013 18:31:47] - |D| - [0] - C:\Users\magali\AppData\Local\{31794343-45BF-4F83-8E2E-ED622970AE10} [28/01/2013 21:55:18] - |D| - [0] - C:\Users\magali\AppData\Local\{31E8C0E5-4A05-4FD5-B10E-F975DA218F96} [31/05/2011 09:41:01] - |D| - [0] - C:\Users\magali\AppData\Local\{3238662D-0AF3-45B4-AD2C-1D4A045BB4D0} [14/08/2012 21:32:59] - |D| - [0] - C:\Users\magali\AppData\Local\{32EE195F-73DD-4128-BD33-052E56A4CB35} [15/02/2013 14:59:11] - |D| - [0] - C:\Users\magali\AppData\Local\{334D1A52-C020-48DE-9877-D14334EA0635} [05/11/2012 23:07:10] - |D| - [0] - C:\Users\magali\AppData\Local\{33928076-A5B5-44CF-869A-E27F492A5BE9} [16/04/2011 20:37:58] - |D| - [0] - C:\Users\magali\AppData\Local\{34599BC7-EBDF-4F32-82D5-FA56397CEFC9} [15/11/2012 14:11:11] - |D| - [0] - C:\Users\magali\AppData\Local\{34D30158-044A-407F-8105-6F43B019FEEB} [03/02/2012 09:46:24] - |D| - [0] - C:\Users\magali\AppData\Local\{34FECDBB-07B3-4062-AABD-7C9391575BC9} [13/10/2011 17:14:14] - |D| - [0] - C:\Users\magali\AppData\Local\{352E9502-7C02-48EE-9F7A-63CD6729C37C} [08/05/2013 21:35:13] - |D| - [0] - C:\Users\magali\AppData\Local\{359AB072-0056-4E91-BEFA-023096D46D28} [07/06/2011 21:14:40] - |D| - [0] - C:\Users\magali\AppData\Local\{3651EB29-BE4C-403C-96D8-004C9C5D63F3} [30/11/2014 23:31:40] - |D| - [0] - C:\Users\magali\AppData\Local\{3696DCEA-961C-4A64-95B8-580A3DC62150} [24/03/2011 23:00:03] - |D| - [0] - C:\Users\magali\AppData\Local\{3777DADE-61FD-4FA6-9992-16CB9F015F4A} [27/02/2013 19:58:22] - |D| - [0] - C:\Users\magali\AppData\Local\{37B2BB5D-BF7D-4853-86FF-472995E4FBDE} [26/06/2011 22:36:11] - |D| - [0] - C:\Users\magali\AppData\Local\{37D46D9F-74C5-4D51-A78C-5C696B30D54F} [31/08/2011 10:02:40] - |D| - [0] - C:\Users\magali\AppData\Local\{384674B7-DF56-4FE2-B06C-5871C821C804} [28/09/2012 22:46:39] - |D| - [0] - C:\Users\magali\AppData\Local\{38B26F7E-DB90-43AB-A9CA-B827BF886371} [23/10/2012 09:48:22] - |D| - [0] - C:\Users\magali\AppData\Local\{392B818B-FCEA-4235-9994-CA18D869D0E7} [16/01/2013 10:26:39] - |D| - [0] - C:\Users\magali\AppData\Local\{3A1E9EE8-7EB9-40CE-8695-EA5D65852470} [05/10/2012 09:28:53] - |D| - [0] - C:\Users\magali\AppData\Local\{3A52A5CB-EE78-42C2-9AD3-4997DD846FE1} [12/07/2012 21:26:18] - |D| - [0] - C:\Users\magali\AppData\Local\{3A80AD46-2C24-464F-81E0-B6B723CA74AE} [16/09/2011 10:06:16] - |D| - [0] - C:\Users\magali\AppData\Local\{3AC460D7-3CB5-4CAA-81E7-58BB7FE3F176} [22/05/2012 17:19:45] - |D| - [0] - C:\Users\magali\AppData\Local\{3AF17C01-D45A-4EC6-A630-1E5B480B364C} [20/01/2013 22:43:47] - |D| - [0] - C:\Users\magali\AppData\Local\{3BE6501B-2ABC-48E1-B290-17564A581968} [14/06/2011 09:49:55] - |D| - [0] - C:\Users\magali\AppData\Local\{3C229C5B-D8A6-429B-9528-D684B75E41BF} [03/05/2011 22:28:25] - |D| - [0] - C:\Users\magali\AppData\Local\{3C23EC5A-A228-40A0-97E5-8AFFC4326470} [22/01/2013 11:25:02] - |D| - [0] - C:\Users\magali\AppData\Local\{3C6F14BE-C38B-44C5-BC73-C3E5A6FBD6F5} [08/09/2011 16:06:41] - |D| - [0] - C:\Users\magali\AppData\Local\{3D02E7C9-17BC-49D4-8E4F-6C7DD46CF3B8} [07/06/2011 09:14:01] - |D| - [0] - C:\Users\magali\AppData\Local\{3E0AD3E8-9843-44FA-8FD8-B68FC5CA6FDB} [15/07/2011 00:14:32] - |D| - [0] - C:\Users\magali\AppData\Local\{3E35822A-DB31-49A0-8BF2-1E28621BDD49} [25/06/2012 21:07:28] - |D| - [0] - C:\Users\magali\AppData\Local\{3ED76DA3-8500-4003-987A-37D1B00D8E81} [22/10/2011 21:45:04] - |D| - [0] - C:\Users\magali\AppData\Local\{3F961240-24DD-42AB-A073-04B76CC0FABB} [16/04/2011 08:37:19] - |D| - [0] - C:\Users\magali\AppData\Local\{40145BD6-8572-44B1-841A-CBAF01A678AF} [04/06/2011 13:23:09] - |D| - [0] - C:\Users\magali\AppData\Local\{40C91396-42E8-460C-83EF-95C32D406336} [28/07/2011 09:58:15] - |D| - [0] - C:\Users\magali\AppData\Local\{41342698-855A-4AF7-9785-2096F251EBC0} [03/09/2012 21:46:05] - |D| - [0] - C:\Users\magali\AppData\Local\{41D75236-17B8-4A63-9088-9D76BCED12F8} [17/07/2011 23:11:04] - |D| - [0] - C:\Users\magali\AppData\Local\{425890A4-13A7-4FA8-BE85-21C8E575398E} [13/03/2012 15:57:00] - |D| - [0] - C:\Users\magali\AppData\Local\{425BECC9-5570-44FA-9224-D214A985A66B} [26/03/2011 23:27:57] - |D| - [0] - C:\Users\magali\AppData\Local\{428039CA-5A9F-45E4-AF00-CD872955EE2A} [30/05/2011 21:40:18] - |D| - [0] - C:\Users\magali\AppData\Local\{428E4D8B-FE12-4F1E-8F2C-F3E78F653012} [05/01/2013 11:56:34] - |D| - [0] - C:\Users\magali\AppData\Local\{429DB330-1BA5-4B1D-8D9B-811BEB767350} [30/10/2012 09:55:55] - |D| - [0] - C:\Users\magali\AppData\Local\{42B5EB82-F477-4EE0-9DCA-198B69832BE2} [29/03/2013 09:47:22] - |D| - [0] - C:\Users\magali\AppData\Local\{42B9EFF2-B6F1-4509-AF01-76E6D3BF9963} [28/04/2011 22:16:17] - |D| - [0] - C:\Users\magali\AppData\Local\{43C25B59-F232-440E-B498-CFCAA35A0DC1} [26/01/2013 11:39:34] - |D| - [0] - C:\Users\magali\AppData\Local\{43E92A08-768B-4495-9BB9-6AFF53167579} [15/10/2012 22:31:18] - |D| - [0] - C:\Users\magali\AppData\Local\{440E26FE-CBD9-4180-A322-3785852AB62B} [31/03/2013 21:18:40] - |D| - [0] - C:\Users\magali\AppData\Local\{443A0BA0-A93F-4F84-B094-903A62403E84} [07/03/2013 15:19:26] - |D| - [0] - C:\Users\magali\AppData\Local\{444ECFDF-9496-45CE-804E-A5C9A03ABA22} [17/07/2011 23:22:52] - |D| - [0] - C:\Users\magali\AppData\Local\{4463B00C-678A-4FDF-8EDA-5E1C56A03107} [23/01/2012 22:21:10] - |D| - [0] - C:\Users\magali\AppData\Local\{467CDC2C-7839-4EB7-BEE2-DFF64B61E3E2} [19/02/2012 11:57:02] - |D| - [0] - C:\Users\magali\AppData\Local\{49992E13-6930-48C7-A2D9-6412E4D04AA0} [23/01/2013 10:50:27] - |D| - [0] - C:\Users\magali\AppData\Local\{4A0C3780-C89C-416B-8D78-8154FD7D35E9} [23/08/2012 21:39:38] - |D| - [0] - C:\Users\magali\AppData\Local\{4A220A0E-C0A1-46A2-8AD2-F6301EFE815C} [18/05/2011 21:10:33] - |D| - [0] - C:\Users\magali\AppData\Local\{4A7BDC59-5B9A-408D-BE57-FC17FF9AFC66} [06/06/2011 12:10:58] - |D| - [0] - C:\Users\magali\AppData\Local\{4ADD2527-3023-414B-A962-E5388E406D26} [07/02/2013 13:39:44] - |D| - [0] - C:\Users\magali\AppData\Local\{4B7D6B1D-0EAF-4763-BEBA-EAC1436F781E} [20/04/2011 09:34:46] - |D| - [0] - C:\Users\magali\AppData\Local\{4BD8B31D-12D7-46EF-803A-BF9A635DBD2D} [10/02/2012 10:11:37] - |D| - [0] - C:\Users\magali\AppData\Local\{4BDB7EF0-03F0-45C1-AA3F-1A0B9E06CAD1} [13/11/2015 11:26:02] - |D| - [1305803] - C:\Users\magali\AppData\Local\{4C037A5F-68AB-16E7-0533-330F215BCF97} [11/07/2011 11:20:00] - |D| - [0] - C:\Users\magali\AppData\Local\{4C4C597A-A6A3-415F-8D19-1CE6A8C38960} [04/10/2012 09:27:51] - |D| - [0] - C:\Users\magali\AppData\Local\{4C68F39E-CC16-4CD7-8DAB-299F30BFC37E} [20/03/2011 21:29:29] - |D| - [0] - C:\Users\magali\AppData\Local\{4CB2916A-BA1F-44B2-ABC0-ACC975B156D9} [04/08/2012 17:44:10] - |D| - [0] - C:\Users\magali\AppData\Local\{4CC82764-DA26-4D18-A5C7-B7A1F890DB76} [23/08/2011 10:44:18] - |D| - [0] - C:\Users\magali\AppData\Local\{4DFDEC7F-4169-48B9-9250-9B226BCB2EDA} [03/05/2011 22:32:31] - |D| - [0] - C:\Users\magali\AppData\Local\{4E4ACD9D-389F-43EC-A242-60644D274A57} [09/07/2012 15:28:52] - |D| - [0] - C:\Users\magali\AppData\Local\{4EF401A6-ACD6-4A8B-97A7-FEE0EC132552} [03/04/2011 22:02:14] - |D| - [0] - C:\Users\magali\AppData\Local\{4FD58832-D0D9-4F8D-B8CE-AC5A79CF9665} [23/03/2011 22:35:25] - |D| - [0] - C:\Users\magali\AppData\Local\{4FE02BEC-8A26-4573-ACC0-26AAC7AF06B0} [12/02/2012 11:11:40] - |D| - [0] - C:\Users\magali\AppData\Local\{502EDC42-F24A-47C0-96D7-2696A6369517} [19/03/2012 18:56:18] - |D| - [0] - C:\Users\magali\AppData\Local\{503451D5-6D86-4E32-9B6D-7243ACD5664A} [19/06/2011 22:33:48] - |D| - [0] - C:\Users\magali\AppData\Local\{507A5B95-C246-4E7D-837E-D5E44F6F7003} [10/10/2012 10:04:59] - |D| - [0] - C:\Users\magali\AppData\Local\{5087F856-4ED2-4084-9534-AA86A6176355} [23/10/2012 09:27:52] - |D| - [0] - C:\Users\magali\AppData\Local\{50C43552-7F98-4677-9345-0BA2587950FC} [16/11/2012 11:54:49] - |D| - [0] - C:\Users\magali\AppData\Local\{5106A04F-ECD8-4836-A9FA-F818B4DD7CCF} [13/10/2011 17:14:33] - |D| - [0] - C:\Users\magali\AppData\Local\{51094F1D-244B-4956-B9C7-13D9BBDF7C8C} [14/05/2012 21:21:12] - |D| - [0] - C:\Users\magali\AppData\Local\{5177D9CD-D1E4-4FAC-9BD8-3CFE3E708402} [21/08/2011 22:01:01] - |D| - [0] - C:\Users\magali\AppData\Local\{51AF0087-588E-49E1-BA07-5A7D228ECB14} [05/08/2012 17:28:37] - |D| - [0] - C:\Users\magali\AppData\Local\{51FB6297-7FC8-43F8-B215-2601DEF43283} [21/01/2013 23:24:35] - |D| - [0] - C:\Users\magali\AppData\Local\{521323B4-02B5-4A3A-B487-63E10D7DA78F} [25/06/2012 21:38:48] - |D| - [0] - C:\Users\magali\AppData\Local\{5260078C-E1C4-4403-BD7B-DDAF823D0D83} [05/04/2013 09:04:32] - |D| - [0] - C:\Users\magali\AppData\Local\{5270E5F3-B91A-4B5E-8C4F-F7820211B111} [04/02/2012 10:56:10] - |D| - [0] - C:\Users\magali\AppData\Local\{52CBE1B5-2408-4445-B5C1-2F1446F7C829} [11/04/2011 18:05:39] - |D| - [0] - C:\Users\magali\AppData\Local\{52DCA8AA-3C36-43D5-8F95-484382E8B638} [21/12/2011 19:16:59] - |D| - [0] - C:\Users\magali\AppData\Local\{5364D26E-5C14-481E-A7DE-F5B318FB4477} [10/09/2011 21:20:08] - |D| - [0] - C:\Users\magali\AppData\Local\{53AB247E-DC11-4F95-9241-ECC6D8842AD8} [04/01/2013 16:22:36] - |D| - [0] - C:\Users\magali\AppData\Local\{54A3BA0F-A9E4-475F-8F02-A2CF8B061D50} [19/06/2011 02:08:02] - |D| - [0] - C:\Users\magali\AppData\Local\{55093519-873A-4346-B175-2D4F3F017954} [24/10/2011 21:38:18] - |D| - [0] - C:\Users\magali\AppData\Local\{554D347D-5696-4896-BEBF-2EB96230476C} [17/11/2012 23:33:43] - |D| - [0] - C:\Users\magali\AppData\Local\{559A6E6C-20EE-46BE-8FC0-CC7ED3174278} [30/11/2014 23:33:57] - |D| - [0] - C:\Users\magali\AppData\Local\{55B00738-0BE7-4A9C-8C91-CF5005814C3C} [21/02/2012 10:27:24] - |D| - [0] - C:\Users\magali\AppData\Local\{56510A37-2C69-460C-AA52-7A0ED150E7BF} [02/05/2011 10:22:23] - |D| - [0] - C:\Users\magali\AppData\Local\{5672914F-95A0-4F0D-BBF2-0E0953348679} [21/05/2011 22:44:07] - |D| - [0] - C:\Users\magali\AppData\Local\{56DAB988-204F-45FA-BAB3-F161E01D3088} [22/05/2012 18:48:40] - |D| - [0] - C:\Users\magali\AppData\Local\{56E6CF39-645D-43A6-A545-ABBCB1867B48} [24/01/2012 22:08:59] - |D| - [0] - C:\Users\magali\AppData\Local\{58195E2D-B6BF-4AE3-91DB-14A33F5C92FD} [17/02/2012 11:01:43] - |D| - [0] - C:\Users\magali\AppData\Local\{5867854B-4759-450C-841B-D7BD18450258} [26/05/2012 11:02:54] - |D| - [0] - C:\Users\magali\AppData\Local\{5A6D5D17-EB4C-404E-BCB7-6CFD05290E1B} [11/07/2011 23:20:27] - |D| - [0] - C:\Users\magali\AppData\Local\{5B7CFD37-FCE9-4F22-AA6D-80EE8BB7859F} [02/04/2013 10:26:24] - |D| - [0] - C:\Users\magali\AppData\Local\{5C0DB6A5-449E-45CB-85FC-F97252AA8FDF} [20/09/2011 14:56:26] - |D| - [0] - C:\Users\magali\AppData\Local\{5E16A59A-695D-410F-8D30-9710355A3C7E} [05/08/2012 17:29:21] - |D| - [0] - C:\Users\magali\AppData\Local\{5E39C727-57CA-405E-8122-BFE3C15F1CBD} [06/03/2012 19:49:28] - |D| - [0] - C:\Users\magali\AppData\Local\{5E4AFDB6-E597-4537-AF0D-0658465ACC57} [13/04/2011 10:41:51] - |D| - [0] - C:\Users\magali\AppData\Local\{5E8D3207-2BD2-42B7-9B47-8CBC137FBAB8} [02/07/2012 21:15:27] - |D| - [0] - C:\Users\magali\AppData\Local\{5EE0E148-A122-4781-B7DA-CEF5C500CCFA} [27/11/2011 23:57:19] - |D| - [0] - C:\Users\magali\AppData\Local\{5EE3F323-2F1D-49E4-B93F-8AF285033443} [06/01/2013 11:43:27] - |D| - [0] - C:\Users\magali\AppData\Local\{6023C1D4-ED79-4692-B6A4-A683C9C884F3} [01/10/2012 16:19:10] - |D| - [0] - C:\Users\magali\AppData\Local\{613E10D5-5FF4-4453-9EBA-2B6B5F6CB934} [15/10/2011 20:38:27] - |D| - [0] - C:\Users\magali\AppData\Local\{6210C515-FD69-4113-8D59-1790EACB2B7E} [21/08/2011 22:00:45] - |D| - [0] - C:\Users\magali\AppData\Local\{6216FF8B-C6AE-44D9-92E2-5929B45B0FD9} [04/03/2013 10:11:42] - |D| - [0] - C:\Users\magali\AppData\Local\{622AA7C3-903D-49C9-BF2C-8227A62A53CD} [03/11/2013 23:55:24] - |D| - [0] - C:\Users\magali\AppData\Local\{62785534-D137-45EF-A169-62C67CF15F7A} [01/03/2013 17:33:33] - |D| - [0] - C:\Users\magali\AppData\Local\{629A4228-1A94-4121-BE69-BFF40A9D6D90} [19/08/2011 18:46:00] - |D| - [0] - C:\Users\magali\AppData\Local\{630821EE-848E-451C-9E19-D80C808B7AC1} [12/04/2013 15:12:05] - |D| - [0] - C:\Users\magali\AppData\Local\{634D5B6E-C05D-4B40-BE33-B7C6B1C41C7F} [10/04/2012 14:53:23] - |D| - [0] - C:\Users\magali\AppData\Local\{635D484F-69E3-433E-B49E-5B70BF6D63DA} [22/10/2011 21:46:01] - |D| - [0] - C:\Users\magali\AppData\Local\{63F3F8F8-164E-4B44-AA00-9D88274FE7EE} [29/11/2011 11:45:35] - |D| - [0] - C:\Users\magali\AppData\Local\{64713701-86AA-4652-AADE-FF7E50006B1D} [30/03/2011 21:38:41] - |D| - [0] - C:\Users\magali\AppData\Local\{64F8ADE1-33AD-4004-9A1E-246D5A388270} [21/10/2011 21:10:26] - |D| - [0] - C:\Users\magali\AppData\Local\{652B3D9A-3FAA-42B1-879E-448C928A9D25} [04/02/2012 10:55:13] - |D| - [0] - C:\Users\magali\AppData\Local\{652EAFF6-24E2-4686-86E9-93D911D151FB} [13/10/2012 09:08:21] - |D| - [0] - C:\Users\magali\AppData\Local\{656935BE-5E6C-4603-A047-9E242E2D9340} [12/03/2013 21:59:15] - |D| - [0] - C:\Users\magali\AppData\Local\{6640BEBB-2F80-4175-AAE2-5E154BDD374A} [25/06/2012 21:39:09] - |D| - [0] - C:\Users\magali\AppData\Local\{664A7EDD-7FAF-4018-8300-BFAFA1C9CA49} [16/09/2011 10:06:40] - |D| - [0] - C:\Users\magali\AppData\Local\{6676FC37-EFF5-4BE7-BB51-7B36DFFD7C89} [12/06/2012 15:54:26] - |D| - [0] - C:\Users\magali\AppData\Local\{66B3F0DA-F44A-405D-9639-A8C3DA617A9B} [16/04/2012 21:24:00] - |D| - [0] - C:\Users\magali\AppData\Local\{67A27119-E432-45DE-8E04-77492DFC9E96} [30/03/2013 16:31:30] - |D| - [0] - C:\Users\magali\AppData\Local\{680B8844-1587-4D74-A06A-4B9621832AF6} [19/02/2013 11:02:03] - |D| - [0] - C:\Users\magali\AppData\Local\{682A05FB-6F43-4F9A-9811-F40E7D56DA17} [18/05/2012 09:10:47] - |D| - [0] - C:\Users\magali\AppData\Local\{68A35D60-6E40-49B2-B20D-101B8A860639} [12/04/2011 08:41:37] - |D| - [0] - C:\Users\magali\AppData\Local\{68B9949B-BE17-457F-A31D-81EBC08D124B} [04/07/2012 10:42:31] - |D| - [0] - C:\Users\magali\AppData\Local\{696947CA-BD63-4E36-B3E9-0E6F7C0B61F4} [29/01/2012 15:49:48] - |D| - [0] - C:\Users\magali\AppData\Local\{69FDFE06-42C5-41D8-89E2-43F796A8DA59} [02/02/2013 15:53:11] - |D| - [0] - C:\Users\magali\AppData\Local\{6A12A2FA-3DFF-41E3-A690-CF221F9106BC} [15/05/2012 14:27:43] - |D| - [0] - C:\Users\magali\AppData\Local\{6A6CB963-3E2D-48CC-8469-DEB4579CC26D} [02/04/2012 21:50:08] - |D| - [0] - C:\Users\magali\AppData\Local\{6A9C344A-1EAF-47A5-A3DE-31D0D246D85A} [01/11/2012 22:57:59] - |D| - [0] - C:\Users\magali\AppData\Local\{6B4B3FB9-F308-49BB-84C9-17FAB4F2C23A} [06/09/2011 21:25:49] - |D| - [0] - C:\Users\magali\AppData\Local\{6C5903D4-4791-4884-AB9A-0F1C5C99A84B} [30/04/2013 17:43:41] - |D| - [0] - C:\Users\magali\AppData\Local\{6C5B16F7-72D1-49D5-9B2B-B7D40E8A15FC} [19/03/2012 18:56:48] - |D| - [0] - C:\Users\magali\AppData\Local\{6CBC028A-9ADD-4D74-B50E-4F151360F36A} [12/04/2012 21:45:34] - |D| - [0] - C:\Users\magali\AppData\Local\{6CDB90E3-A59C-40A5-8651-3F9DCE6D11EA} [29/09/2015 09:30:52] - |D| - [0] - C:\Users\magali\AppData\Local\{6D1F47F0-FAE5-4692-8090-E603EF9E15AB} [09/10/2012 22:04:32] - |D| - [0] - C:\Users\magali\AppData\Local\{6D26D7D3-2DB0-49D3-8B30-A6ADAA7EB258} [01/02/2013 10:25:14] - |D| - [0] - C:\Users\magali\AppData\Local\{6D4FACE3-10F1-4934-A0CE-B587BAD3EB5F} [14/02/2013 15:20:01] - |D| - [0] - C:\Users\magali\AppData\Local\{6D4FF803-2A05-4E3A-B774-DB816E4FE7B8} [22/12/2015 12:26:00] - |D| - [0] - C:\Users\magali\AppData\Local\{6DD012BB-696F-42C0-A132-F739533785A0} [09/06/2011 22:29:17] - |D| - [0] - C:\Users\magali\AppData\Local\{6DD4B318-45B2-4621-BFFE-437740F508CE} [02/02/2012 15:43:06] - |D| - [0] - C:\Users\magali\AppData\Local\{6E0C7F2C-52B9-40F8-AC9F-B1729C581F67} [21/12/2011 19:16:33] - |D| - [0] - C:\Users\magali\AppData\Local\{6E6FC17A-7852-4B02-8D06-64C1E9085D75} [26/03/2013 10:59:57] - |D| - [0] - C:\Users\magali\AppData\Local\{6F4411F0-B279-44B3-BA38-B0C8FFD531AE} [27/01/2012 22:16:58] - |D| - [0] - C:\Users\magali\AppData\Local\{6FC736A8-36FA-4CDD-B05B-42E21FDAD7DA} [30/11/2012 11:19:16] - |D| - [0] - C:\Users\magali\AppData\Local\{6FF6B3E2-BA6F-4105-B20B-B808764A24D7} [08/10/2011 20:21:08] - |D| - [0] - C:\Users\magali\AppData\Local\{70035A4D-CD49-4941-9679-19DEBAC75EC0} [19/12/2012 16:23:27] - |D| - [0] - C:\Users\magali\AppData\Local\{702F78A5-2CB9-49F1-BAFE-3F9444759998} [15/09/2011 22:05:43] - |D| - [0] - C:\Users\magali\AppData\Local\{70DEACB1-09D9-4173-9671-780AA13E0A91} [07/07/2012 17:46:39] - |D| - [0] - C:\Users\magali\AppData\Local\{714D5DC9-F175-47C5-85B9-F4D963DF92B8} [16/02/2012 09:42:53] - |D| - [0] - C:\Users\magali\AppData\Local\{71605D3A-C993-47D7-BB9D-D1385C7B69A3} [24/07/2012 09:00:03] - |D| - [0] - C:\Users\magali\AppData\Local\{718A6A4A-748E-4C2E-A27E-6D0428B24328} [19/10/2012 21:44:43] - |D| - [0] - C:\Users\magali\AppData\Local\{7252968C-330F-4A95-B700-C5938B16D4C4} [19/02/2012 23:58:55] - |D| - [0] - C:\Users\magali\AppData\Local\{72AA8413-680A-4B18-9318-4F32BCC62CCE} [13/06/2011 21:49:25] - |D| - [0] - C:\Users\magali\AppData\Local\{748BFAEE-2CF1-47EE-B3ED-B0B8DA689A53} [15/07/2011 22:02:19] - |D| - [0] - C:\Users\magali\AppData\Local\{75571850-BF29-4EB3-BBDB-FF4AE0C65BBC} [22/05/2012 18:49:03] - |D| - [0] - C:\Users\magali\AppData\Local\{75FD7565-B420-4042-8F04-8CE281BEE5AC} [26/02/2012 20:01:44] - |D| - [0] - C:\Users\magali\AppData\Local\{75FF79F2-A47B-4C01-A43C-DA61AC677873} [15/10/2011 20:39:07] - |D| - [0] - C:\Users\magali\AppData\Local\{7669ECA0-3341-4040-BC02-6AC0F1F2F7B0} [18/02/2012 11:37:39] - |D| - [0] - C:\Users\magali\AppData\Local\{76D2CFB1-EAF0-42AD-A7B0-04B625BE1A8C} [18/02/2012 11:38:34] - |D| - [0] - C:\Users\magali\AppData\Local\{777634E9-9625-4882-BAD9-587301C12C78} [24/02/2013 17:43:04] - |D| - [0] - C:\Users\magali\AppData\Local\{777A190E-1553-4C5B-B161-329D5C4A73DE} [29/06/2011 09:53:58] - |D| - [0] - C:\Users\magali\AppData\Local\{77E0E7D4-9F88-47A0-96B7-5C20F2B45AC1} [11/02/2012 10:44:26] - |D| - [0] - C:\Users\magali\AppData\Local\{77F117D6-276D-43B4-B85E-A3A0B4FA2559} [06/04/2011 22:09:57] - |D| - [0] - C:\Users\magali\AppData\Local\{77F1511D-8C42-40DB-A66C-B371091135CE} [09/03/2013 16:20:52] - |D| - [0] - C:\Users\magali\AppData\Local\{7822A9A0-0552-4C9F-B14A-FFF14D252946} [10/06/2011 10:29:54] - |D| - [0] - C:\Users\magali\AppData\Local\{796BC62E-F1C1-419C-BC05-D3942B79A8EE} [04/08/2012 17:44:44] - |D| - [0] - C:\Users\magali\AppData\Local\{79EEB26D-FEF9-4B0E-AC76-BE1F7A90560F} [15/10/2012 10:31:01] - |D| - [0] - C:\Users\magali\AppData\Local\{7A37CB17-3750-4AA2-9918-ACA8BF84F98A} [19/07/2011 23:25:15] - |D| - [0] - C:\Users\magali\AppData\Local\{7A5531FD-DFEE-430F-9565-43A751F560FE} [20/07/2011 11:25:41] - |D| - [0] - C:\Users\magali\AppData\Local\{7A92A75A-DC29-40A2-A1C4-45AD449A5CBD} [27/10/2012 10:35:37] - |D| - [0] - C:\Users\magali\AppData\Local\{7AD1896E-2973-425E-A51C-1C20DE61BF67} [27/02/2012 16:56:20] - |D| - [0] - C:\Users\magali\AppData\Local\{7B40B785-9403-4A94-9D11-7AD0C7747C06} [30/11/2014 23:11:07] - |D| - [0] - C:\Users\magali\AppData\Local\{7B55C51A-6D42-42FD-9DC3-3FC9F253570A} [28/10/2011 15:45:49] - |D| - [0] - C:\Users\magali\AppData\Local\{7B604C47-4AC4-40D8-83FB-6748F0EB7287} [15/02/2012 10:35:49] - |D| - [0] - C:\Users\magali\AppData\Local\{7C48BB46-1F13-4B72-B36F-34D5D1BCFFF9} [25/04/2012 08:35:59] - |D| - [0] - C:\Users\magali\AppData\Local\{7D3430C5-93C5-4AEB-BE88-6C5846F02422} [21/09/2011 09:58:19] - |D| - [0] - C:\Users\magali\AppData\Local\{7D70029B-3A25-46A9-83EB-16B61E08B388} [13/11/2012 09:30:32] - |D| - [0] - C:\Users\magali\AppData\Local\{7D8CB0C7-7A90-4921-BE39-7AF7F8120AD1} [20/08/2011 22:27:56] - |D| - [0] - C:\Users\magali\AppData\Local\{7F690C91-0E06-4897-9231-A1E7CE01EEAC} [03/02/2012 22:46:26] - |D| - [0] - C:\Users\magali\AppData\Local\{7FC1F29E-C44C-46B6-A6ED-B8876CB9EE6D} [21/02/2013 10:06:45] - |D| - [0] - C:\Users\magali\AppData\Local\{7FC2DF5F-84CB-4272-AAC6-E8B442A1898E} [16/02/2012 09:41:50] - |D| - [0] - C:\Users\magali\AppData\Local\{8084E248-F264-4059-AD1B-149B07FA485B} [16/07/2011 11:07:14] - |D| - [0] - C:\Users\magali\AppData\Local\{80D8D894-9AD0-4C6C-B158-FD4F0BE37312} [07/02/2012 15:38:02] - |D| - [0] - C:\Users\magali\AppData\Local\{8117D548-78BD-43D5-8D72-CFC0BAEA8834} [16/06/2011 10:19:54] - |D| - [0] - C:\Users\magali\AppData\Local\{81672478-850B-46FC-B41D-FE4F308E78AA} [22/02/2012 11:30:05] - |D| - [0] - C:\Users\magali\AppData\Local\{8191C566-8AE3-46D3-9D26-F28CCEF10646} [02/07/2012 21:16:01] - |D| - [0] - C:\Users\magali\AppData\Local\{81F5DE6C-AFEF-4DEC-A2C2-6AEF4C0716AE} [26/04/2012 22:50:52] - |D| - [0] - C:\Users\magali\AppData\Local\{824972C8-F773-4D05-9ABD-BEECD3A65514} [01/06/2011 22:29:11] - |D| - [0] - C:\Users\magali\AppData\Local\{82649C83-F1AE-4AEA-A0C5-F84690BE5F21} [11/10/2012 21:34:13] - |D| - [0] - C:\Users\magali\AppData\Local\{82CE2A5E-B314-47BF-B7F4-0AD137563861} [21/11/2012 13:11:33] - |D| - [0] - C:\Users\magali\AppData\Local\{83805FC3-9B0A-4531-9B25-72625E46BFEF} [13/06/2011 21:45:52] - |D| - [0] - C:\Users\magali\AppData\Local\{83B9703B-6A97-426B-B30D-676037A7AF34} [05/11/2011 11:08:27] - |D| - [0] - C:\Users\magali\AppData\Local\{844CD846-CE2A-4C5A-84EE-E42CCE36ADC8} [24/01/2013 13:00:52] - |D| - [0] - C:\Users\magali\AppData\Local\{849FE5E9-7007-4452-A760-70192396CC8F} [27/11/2012 16:12:59] - |D| - [0] - C:\Users\magali\AppData\Local\{84B20C75-B999-41BB-B9F2-1EFD7AE3F2F7} [30/11/2014 23:37:07] - |D| - [0] - C:\Users\magali\AppData\Local\{85930A28-FA24-40E5-AE4C-EEC783F412E0} [09/10/2011 17:13:59] - |D| - [0] - C:\Users\magali\AppData\Local\{859695C6-2288-4336-8DDA-A518F4005598} [15/02/2012 10:54:26] - |D| - [0] - C:\Users\magali\AppData\Local\{86C130D8-32B8-4E67-A88C-A1360044C145} [15/06/2011 10:17:23] - |D| - [0] - C:\Users\magali\AppData\Local\{880EB705-E43E-4A83-826E-A0DECD86AC22} [01/02/2012 22:24:36] - |D| - [0] - C:\Users\magali\AppData\Local\{88832DBC-B073-4FC9-993F-263054FC7865} [29/07/2012 09:57:52] - |D| - [0] - C:\Users\magali\AppData\Local\{888AAEAB-93CE-443C-8A7D-B977B8C87E16} [04/05/2012 21:36:11] - |D| - [0] - C:\Users\magali\AppData\Local\{88CDC6CE-2A70-43C2-8FD5-35E02002B673} [12/03/2012 18:18:14] - |D| - [0] - C:\Users\magali\AppData\Local\{88F89B24-DB20-4B73-9E97-244C77974554} [08/06/2011 22:28:02] - |D| - [0] - C:\Users\magali\AppData\Local\{89EE5738-08EA-4080-A2C8-9372C8D14A48} [08/08/2012 21:15:34] - |D| - [0] - C:\Users\magali\AppData\Local\{8A2C3A58-8001-4C12-BE97-5145999912EE} [22/06/2011 10:26:26] - |D| - [0] - C:\Users\magali\AppData\Local\{8A53FC31-E77C-4728-9115-5070577C542D} [09/02/2012 15:24:59] - |D| - [0] - C:\Users\magali\AppData\Local\{8A53FED9-C339-4A92-B41E-BEAD184F3834} [18/07/2011 11:23:24] - |D| - [0] - C:\Users\magali\AppData\Local\{8AC9B376-80C3-4396-AF5B-FDBFB47F6BD1} [11/11/2012 16:40:55] - |D| - [0] - C:\Users\magali\AppData\Local\{8B845C76-7416-4CEE-8D46-36F76DE1D594} [15/03/2011 15:30:28] - |D| - [0] - C:\Users\magali\AppData\Local\{8C2CD38F-2F9E-47B8-9F90-C2E523C1E97B} [25/05/2011 22:15:57] - |D| - [0] - C:\Users\magali\AppData\Local\{8CAD31C6-D5BF-4AF3-A50F-C20DC663C6FA} [08/11/2012 15:37:15] - |D| - [0] - C:\Users\magali\AppData\Local\{8CBB8B6A-D9B8-4098-8C1A-3721717667C8} [08/08/2012 21:15:52] - |D| - [0] - C:\Users\magali\AppData\Local\{8CF4D262-28AB-4491-B9F1-5B3B5A7E80DE} [21/10/2011 21:08:29] - |D| - [0] - C:\Users\magali\AppData\Local\{8D528036-F4FA-4C3A-8957-534FC2294274} [02/10/2012 21:51:41] - |D| - [0] - C:\Users\magali\AppData\Local\{8D53041A-6C15-4E71-95DC-82571E2E292E} [05/12/2012 22:29:22] - |D| - [0] - C:\Users\magali\AppData\Local\{8DAEEBBE-49A7-44FC-B87A-ADFE86E6CF6B} [16/06/2011 22:20:31] - |D| - [0] - C:\Users\magali\AppData\Local\{8DB19614-1FD0-4597-B90F-1A77188B7A8B} [26/06/2011 10:32:35] - |D| - [0] - C:\Users\magali\AppData\Local\{8E2949FB-7F47-46F7-8347-34827A155DC0} [12/03/2013 09:37:42] - |D| - [0] - C:\Users\magali\AppData\Local\{8E5D4372-F178-40CC-B40C-B10603645395} [15/09/2011 22:05:04] - |D| - [0] - C:\Users\magali\AppData\Local\{8EBFAF6D-AFA8-49D9-8808-EC06E67E8A8D} [11/06/2011 09:53:29] - |D| - [0] - C:\Users\magali\AppData\Local\{8F14CA84-3EA7-4E83-B3AB-9CBBA194594D} [21/06/2011 10:45:11] - |D| - [0] - C:\Users\magali\AppData\Local\{8F2CC97B-131C-451A-99C8-20699296ECEC} [11/08/2014 11:54:15] - |D| - [0] - C:\Users\magali\AppData\Local\{8F3AE919-106C-47E5-8C19-8F683391980C} [21/02/2012 23:27:36] - |D| - [0] - C:\Users\magali\AppData\Local\{8F6C4231-1E9A-4C0D-8866-AF84B733E9FE} [20/06/2012 21:51:02] - |D| - [0] - C:\Users\magali\AppData\Local\{8F8FC1BA-CA5C-42CE-AECE-F1769E3B429D} [19/12/2011 19:16:00] - |D| - [0] - C:\Users\magali\AppData\Local\{8FA05143-779B-4434-8021-445B8869E8B2} [07/07/2011 11:12:19] - |D| - [0] - C:\Users\magali\AppData\Local\{8FBE0CA6-CF94-4887-A946-1E5A10D68B7D} [18/06/2012 21:18:25] - |D| - [0] - C:\Users\magali\AppData\Local\{8FD58166-3B8C-4818-B00E-382AE247C7B9} [01/06/2012 15:30:11] - |D| - [0] - C:\Users\magali\AppData\Local\{915F8E5E-D9D1-4C67-AF0E-A44BBC6A5C8E} [20/03/2011 21:29:43] - |D| - [0] - C:\Users\magali\AppData\Local\{916C623D-E964-479B-8AAF-829396AA2042} [03/10/2012 09:52:10] - |D| - [0] - C:\Users\magali\AppData\Local\{91DA1894-9810-4B8B-9C5D-DC05EE5E0CF9} [27/01/2013 12:21:43] - |D| - [0] - C:\Users\magali\AppData\Local\{9210E535-AE59-4BC6-B131-BF018F4DC7EE} [13/10/2012 21:21:00] - |D| - [0] - C:\Users\magali\AppData\Local\{92DD5705-97E5-4401-83AE-9D84555C3AB9} [20/03/2013 11:19:52] - |D| - [0] - C:\Users\magali\AppData\Local\{9338ADB5-C418-407E-A599-C6BB92D24731} [26/04/2011 22:28:48] - |D| - [0] - C:\Users\magali\AppData\Local\{93A28824-83B4-4947-9F6D-589787F93954} [01/08/2012 19:29:34] - |D| - [0] - C:\Users\magali\AppData\Local\{93D7706A-B49D-48FA-A894-239545BA51BC} [11/02/2012 22:47:05] - |D| - [0] - C:\Users\magali\AppData\Local\{94442CC8-0E6F-46C7-81C9-A1FE1CA4D55C} [13/03/2011 18:39:26] - |D| - [0] - C:\Users\magali\AppData\Local\{944FF015-C479-4F2C-AE87-6077A16A2477} [18/11/2012 11:51:13] - |D| - [0] - C:\Users\magali\AppData\Local\{94868ADA-36A0-49EA-95EE-2D3BA83ADC57} [03/02/2013 21:52:32] - |D| - [0] - C:\Users\magali\AppData\Local\{951E2103-778E-496E-AF51-EEDB99888082} [14/08/2012 21:33:42] - |D| - [0] - C:\Users\magali\AppData\Local\{952A1C49-3562-4750-90D0-450F50DF69D5} [02/11/2011 22:13:19] - |D| - [0] - C:\Users\magali\AppData\Local\{952EADC2-E70A-45CB-9163-62F95B698668} [01/04/2013 21:01:17] - |D| - [0] - C:\Users\magali\AppData\Local\{9547BBC2-1F22-4343-B33C-01160C49675D} [13/07/2011 14:38:06] - |D| - [0] - C:\Users\magali\AppData\Local\{957629D2-E1F7-473A-9398-DDA83AF61BB7} [11/10/2012 08:57:40] - |D| - [0] - C:\Users\magali\AppData\Local\{95952A82-42D0-4F70-848A-37150A6025CE} [24/02/2012 15:12:29] - |D| - [0] - C:\Users\magali\AppData\Local\{959A89BF-C808-4047-8B5A-0507D66CD12B} [12/03/2012 18:18:30] - |D| - [0] - C:\Users\magali\AppData\Local\{960D9F6E-D432-404B-AFD6-71B07F0BA891} [23/08/2011 10:45:51] - |D| - [0] - C:\Users\magali\AppData\Local\{96CA7E97-EFE3-4181-9629-4B72F65842AE} [10/07/2012 22:14:35] - |D| - [0] - C:\Users\magali\AppData\Local\{96F2217C-6C2A-4554-9874-A22B006E855A} [11/12/2012 09:54:03] - |D| - [0] - C:\Users\magali\AppData\Local\{973A9FF5-B33F-46D4-8B42-6D8DFAEFBDCC} [20/12/2011 16:33:07] - |D| - [0] - C:\Users\magali\AppData\Local\{978CE28D-2882-41DB-A615-1D3D1AD3B863} [14/06/2011 21:50:31] - |D| - [0] - C:\Users\magali\AppData\Local\{979398D9-F471-4E79-913F-2C3F959C9083} [04/05/2012 21:19:24] - |D| - [0] - C:\Users\magali\AppData\Local\{98290F5C-9BDA-4BA6-A31C-77EB81DB7925} [23/01/2012 22:20:42] - |D| - [0] - C:\Users\magali\AppData\Local\{9847F666-472B-424D-A8D4-2FF35F449E1D} [18/08/2012 22:16:27] - |D| - [0] - C:\Users\magali\AppData\Local\{9A2DE427-251B-4A47-942C-0998276A9B92} [27/05/2011 21:47:29] - |D| - [0] - C:\Users\magali\AppData\Local\{9AB1D669-8AC2-4772-9ADB-68B054271C52} [18/03/2012 22:36:11] - |D| - [0] - C:\Users\magali\AppData\Local\{9AC29048-D9F1-4B40-8509-89381EF9FD8C} [17/11/2015 18:08:37] - |D| - [0] - C:\Users\magali\AppData\Local\{9B2F095D-D955-48DF-9FFD-9A6254B9EDBD} [29/04/2011 21:37:50] - |D| - [0] - C:\Users\magali\AppData\Local\{9B78716F-8F46-4C46-9001-C757CA26A67C} [14/11/2011 21:37:55] - |D| - [0] - C:\Users\magali\AppData\Local\{9B9C6CD6-995F-4A12-A620-6AB7CF96AED2} [10/04/2013 21:48:41] - |D| - [0] - C:\Users\magali\AppData\Local\{9BD7C8B4-E81D-46FD-8B2D-DC6FDA7C6E15} [06/09/2011 21:26:45] - |D| - [0] - C:\Users\magali\AppData\Local\{9BE3FB0B-8A89-43C3-A043-B6436EB6F746} [22/02/2013 10:01:02] - |D| - [0] - C:\Users\magali\AppData\Local\{9C9CC6EC-3191-4039-87C4-E6D9877559C0} [23/02/2013 03:38:33] - |D| - [0] - C:\Users\magali\AppData\Local\{9DA52BE5-43EE-4C95-BBA0-C9843F16DE5C} [14/04/2011 21:01:25] - |D| - [0] - C:\Users\magali\AppData\Local\{9DED8628-D963-4D7B-AF64-113A06DDE1F0} [15/04/2011 09:01:50] - |D| - [0] - C:\Users\magali\AppData\Local\{9ED77462-9704-4E98-9C55-8EF332F4AF23} [03/04/2013 02:47:59] - |D| - [0] - C:\Users\magali\AppData\Local\{9EEE5DF3-F044-4FF5-B454-1156ED752D2B} [27/01/2012 09:52:41] - |D| - [0] - C:\Users\magali\AppData\Local\{9FF9893D-60A2-42E9-B73C-CB50654C3F69} [27/01/2012 22:16:12] - |D| - [0] - C:\Users\magali\AppData\Local\{A077ED88-0EFE-4F0A-BE11-D875EDFAD4FF} [10/09/2011 21:19:28] - |D| - [0] - C:\Users\magali\AppData\Local\{A11637EF-B97F-484B-9B75-AC451D4461B7} [31/01/2012 18:54:48] - |D| - [0] - C:\Users\magali\AppData\Local\{A1B922E3-8D55-42E8-B180-F927FEFA895F} [01/11/2015 19:40:36] - |D| - [0] - C:\Users\magali\AppData\Local\{A25B7D14-FB24-49B7-A210-9FA5C63C092D} [09/10/2011 17:13:32] - |D| - [0] - C:\Users\magali\AppData\Local\{A308B5DB-8697-4ED5-A1C4-700A0131BC6A} [07/11/2012 18:08:57] - |D| - [0] - C:\Users\magali\AppData\Local\{A363F59F-E3B4-4309-8EC0-AC5E33437062} [23/05/2012 16:42:03] - |D| - [0] - C:\Users\magali\AppData\Local\{A3888B5E-730C-47D4-AF86-8D5BF1875EA1} [16/12/2012 23:13:42] - |D| - [0] - C:\Users\magali\AppData\Local\{A39C4BBC-8259-450B-B1AD-19F60BAFBD5A} [29/04/2013 09:58:10] - |D| - [0] - C:\Users\magali\AppData\Local\{A4E54E55-68D2-4872-8507-BB6E74EB0051} [06/03/2012 15:22:50] - |D| - [0] - C:\Users\magali\AppData\Local\{A5411401-AFFC-43C9-AD31-01F14B4991EF} [19/04/2013 08:32:48] - |D| - [0] - C:\Users\magali\AppData\Local\{A5F175B1-AE3A-48B9-B45F-1B2F524E5B23} [05/09/2011 21:15:15] - |D| - [0] - C:\Users\magali\AppData\Local\{A75C70B8-2C46-41C8-ABD9-05F4E1C4F20D} [10/07/2011 10:49:42] - |D| - [0] - C:\Users\magali\AppData\Local\{A7AAE54F-472E-41FF-9625-7B1EE430F78B} [31/08/2011 10:27:47] - |D| - [0] - C:\Users\magali\AppData\Local\{A7B8F0EF-EA18-4530-8BCF-2EA5431D1A27} [27/07/2011 10:20:11] - |D| - [0] - C:\Users\magali\AppData\Local\{A90C00EE-C73F-4F92-ADA5-D85B083A1530} [17/05/2012 15:27:08] - |D| - [0] - C:\Users\magali\AppData\Local\{A9167A9B-7B96-4AC1-BD94-1F664F3B7C5F} [28/10/2012 18:57:12] - |D| - [0] - C:\Users\magali\AppData\Local\{A992D8B7-CEF8-4CD3-81C6-0A61ED4D8E49} [09/12/2012 22:54:17] - |D| - [0] - C:\Users\magali\AppData\Local\{AA727497-6DBD-49EF-8264-3A7C93112384} [09/02/2013 16:11:07] - |D| - [0] - C:\Users\magali\AppData\Local\{AA94FDBE-A975-4E02-9B89-D545A7C9CF21} [06/11/2011 16:50:36] - |D| - [0] - C:\Users\magali\AppData\Local\{AA9E324E-18DF-4AF5-8778-9E3C04E99AE0} [25/02/2013 11:50:27] - |D| - [0] - C:\Users\magali\AppData\Local\{AAB96886-0717-4202-928B-7AED1166189B} [06/05/2012 21:11:39] - |D| - [0] - C:\Users\magali\AppData\Local\{AABBEEC6-0A46-466E-9112-5E05E54C03F4} [05/06/2011 20:15:34] - |D| - [0] - C:\Users\magali\AppData\Local\{AB6B5BEF-A39A-4069-8258-D282ED3BCFF6} [30/09/2012 21:42:55] - |D| - [0] - C:\Users\magali\AppData\Local\{AB73F99B-9739-474D-8759-9119D62C3670} [04/05/2012 21:35:39] - |D| - [0] - C:\Users\magali\AppData\Local\{AB91961A-2DA3-4527-A1F6-562F355FC2CD} [01/07/2011 10:01:50] - |D| - [0] - C:\Users\magali\AppData\Local\{AB9DCDB4-A659-4807-B1A1-FA252A512F30} [24/10/2012 15:35:54] - |D| - [0] - C:\Users\magali\AppData\Local\{ABB7B240-973D-44F1-85F3-76BDEFBC4C6B} [14/05/2012 21:21:49] - |D| - [0] - C:\Users\magali\AppData\Local\{ABDDAC6B-9C24-4FE4-8095-04EEA66EC8CF} [13/12/2012 13:33:12] - |D| - [0] - C:\Users\magali\AppData\Local\{AC9A7728-9021-4BDD-9FFC-614B6ECE7561} [29/01/2013 10:55:29] - |D| - [0] - C:\Users\magali\AppData\Local\{ACA2BF34-6FCC-40AA-98C6-52844B0C9428} [04/10/2011 15:03:41] - |D| - [0] - C:\Users\magali\AppData\Local\{ACC093A3-8D8F-47CB-AC17-9C7E2BC284DA} [23/06/2011 22:07:36] - |D| - [0] - C:\Users\magali\AppData\Local\{ACD67631-E44F-4CDC-8DCD-AB7060C72B70} [21/05/2012 21:12:55] - |D| - [0] - C:\Users\magali\AppData\Local\{AD129033-354B-458C-AF90-B9B2AD411CAB} [04/05/2012 21:19:56] - |D| - [0] - C:\Users\magali\AppData\Local\{AD4306B2-23AB-4466-95A3-C333E7453B30} [03/07/2012 14:38:18] - |D| - [0] - C:\Users\magali\AppData\Local\{AD93FC32-DE6C-4A69-BA6B-F8A0D74FFEEF} [07/02/2012 15:39:14] - |D| - [0] - C:\Users\magali\AppData\Local\{AE1F32FB-97A3-46EE-916D-6FB6FFC0B512} [04/05/2011 10:32:59] - |D| - [0] - C:\Users\magali\AppData\Local\{AE524C87-8C80-48C5-A508-1B728A9C40DD} [27/03/2011 22:21:00] - |D| - [0] - C:\Users\magali\AppData\Local\{AE57F864-9AC9-4739-978E-0046BF3D9342} [28/05/2011 10:25:12] - |D| - [0] - C:\Users\magali\AppData\Local\{AEE1A17B-1EE6-4149-AB48-AE96281CA7ED} [18/01/2013 22:41:58] - |D| - [0] - C:\Users\magali\AppData\Local\{B0836BA3-EA84-4A11-80B2-230BC0F19A19} [18/05/2012 18:39:32] - |D| - [0] - C:\Users\magali\AppData\Local\{B08F0E6D-789C-4978-948E-DC3FBC233F4F} [18/05/2012 18:40:07] - |D| - [0] - C:\Users\magali\AppData\Local\{B1A37A94-4953-45CE-8C9B-96D83BA23C57} [25/03/2016 09:57:06] - |D| - [0] - C:\Users\magali\AppData\Local\{B4BA75D1-8522-45F2-A20C-F84E1796FC60} [01/10/2013 16:40:45] - |D| - [0] - C:\Users\magali\AppData\Local\{B5DAD62C-640D-400B-9711-F1CBAE009092} [14/10/2012 21:19:56] - |D| - [0] - C:\Users\magali\AppData\Local\{B695FEFD-079F-43BA-BAC9-9ACAE1A2291B} [19/01/2013 22:42:51] - |D| - [0] - C:\Users\magali\AppData\Local\{B755B4F1-6E65-478F-890D-EF6AD9438DA9} [26/02/2013 10:51:28] - |D| - [0] - C:\Users\magali\AppData\Local\{B76551EF-C8BF-4429-A1D7-FFAD06CE2D9E} [11/02/2012 10:45:13] - |D| - [0] - C:\Users\magali\AppData\Local\{B77F56AF-DAD8-41EB-A468-B4F8FB04BE84} [05/09/2011 21:13:34] - |D| - [0] - C:\Users\magali\AppData\Local\{B86074A8-3361-41B9-A835-6295F0EF7A2A} [03/02/2012 09:45:34] - |D| - [0] - C:\Users\magali\AppData\Local\{B8DF464A-3502-47F0-9722-2059F0222500} [02/01/2012 21:59:17] - |D| - [0] - C:\Users\magali\AppData\Local\{B9D6289B-7BC8-4A59-8936-DF0E8F2DD08B} [04/09/2011 16:09:03] - |D| - [0] - C:\Users\magali\AppData\Local\{BAB20626-DCEA-422B-999C-C5A5DB5AE909} [18/05/2012 09:10:16] - |D| - [0] - C:\Users\magali\AppData\Local\{BAC070B6-29DB-459E-BE27-0A5F1F15C5E8} [02/10/2012 09:09:09] - |D| - [0] - C:\Users\magali\AppData\Local\{BB27C6E2-8C44-4FB7-9574-3F96F9FE2585} [14/02/2012 15:25:32] - |D| - [0] - C:\Users\magali\AppData\Local\{BBB3A63D-4948-4680-A337-4E2D3E276344} [09/02/2012 15:25:48] - |D| - [0] - C:\Users\magali\AppData\Local\{BBE6D330-07C6-47A7-B40E-4935A0781DCD} [16/04/2012 21:18:57] - |D| - [0] - C:\Users\magali\AppData\Local\{BC0F130E-2B7A-4A60-8670-36253143ADA2} [11/02/2012 22:46:12] - |D| - [0] - C:\Users\magali\AppData\Local\{BC127CBB-F4C0-48AD-B003-228518CD2B4B} [25/03/2013 22:47:13] - |D| - [0] - C:\Users\magali\AppData\Local\{BC233563-D71B-4125-9A53-EAE16487FE72} [15/04/2013 10:05:16] - |D| - [0] - C:\Users\magali\AppData\Local\{BC397B66-B480-4058-93CF-C50263765348} [19/07/2011 11:24:37] - |D| - [0] - C:\Users\magali\AppData\Local\{BC587B59-964B-4F53-A1C6-CF732941472D} [22/06/2011 22:31:15] - |D| - [0] - C:\Users\magali\AppData\Local\{BD357B09-D749-483E-BBFC-1D66A33BA032} [16/05/2011 21:12:18] - |D| - [0] - C:\Users\magali\AppData\Local\{BD9BAFE2-D86A-4A6F-B372-D0A24F947AFA} [02/05/2011 22:23:00] - |D| - [0] - C:\Users\magali\AppData\Local\{BDB2013C-135B-4D7F-B484-F7F5E8DFD562} [04/10/2011 15:05:04] - |D| - [0] - C:\Users\magali\AppData\Local\{BE3A9CC8-CF52-43C9-B52F-507DC7121E92} [20/11/2012 14:47:54] - |D| - [0] - C:\Users\magali\AppData\Local\{BEF4E01E-DBB5-47FC-A017-35D86E7E3B14} [08/07/2011 10:23:24] - |D| - [0] - C:\Users\magali\AppData\Local\{BF736D18-1E03-496D-8469-A93FF6416C1C} [02/01/2012 21:58:45] - |D| - [0] - C:\Users\magali\AppData\Local\{BFCD2BEB-A0B8-4C5F-88D4-8F939C52917B} [24/11/2011 22:39:54] - |D| - [0] - C:\Users\magali\AppData\Local\{C005CCF3-3FC5-4959-93FE-7B42DA5931D1} [15/01/2013 21:46:05] - |D| - [0] - C:\Users\magali\AppData\Local\{C054F55E-8CA7-43F4-95B1-0AD29FE5563D} [27/01/2012 09:51:56] - |D| - [0] - C:\Users\magali\AppData\Local\{C09887DB-97B6-42CC-B514-F44F9D35A473} [12/06/2012 15:53:59] - |D| - [0] - C:\Users\magali\AppData\Local\{C0F713B4-C5AF-4039-86C4-D95F3AC2DE8E} [15/07/2012 18:44:04] - |D| - [0] - C:\Users\magali\AppData\Local\{C0FE62F4-FC82-41EF-9F6D-C2E1562FED47} [15/07/2012 18:48:33] - |D| - [0] - C:\Users\magali\AppData\Local\{C109FE56-09E9-435F-9773-D4671447BCFE} [08/09/2011 21:17:54] - |D| - [0] - C:\Users\magali\AppData\Local\{C14409B3-C01D-4AA5-9886-333436D1507D} [29/11/2011 11:46:28] - |D| - [0] - C:\Users\magali\AppData\Local\{C15E94A7-45A9-41E3-BD61-54950BF025E8} [05/02/2013 09:54:25] - |D| - [0] - C:\Users\magali\AppData\Local\{C29BFD98-7A16-4623-8808-CB253F290474} [19/06/2011 22:35:36] - |D| - [0] - C:\Users\magali\AppData\Local\{C2DDE186-DA39-4191-AEB8-D6A881E094F1} [15/11/2011 15:33:58] - |D| - [0] - C:\Users\magali\AppData\Local\{C3D7669D-7D7B-447E-9340-BA638D034FAF} [24/11/2011 22:41:14] - |D| - [0] - C:\Users\magali\AppData\Local\{C4484963-8D94-4E85-9D8D-96F7AEC41A02} [02/12/2013 16:59:32] - |D| - [0] - C:\Users\magali\AppData\Local\{C4548E86-4DA4-4463-A31C-5A4764DFEB57} [02/03/2013 11:09:25] - |D| - [0] - C:\Users\magali\AppData\Local\{C507C9BB-61C1-41AB-8D97-8AC890BA3C55} [06/02/2012 09:54:15] - |D| - [0] - C:\Users\magali\AppData\Local\{C5263403-2A84-445C-AA79-6F3A26E62391} [13/09/2012 11:10:14] - |D| - [0] - C:\Users\magali\AppData\Local\{C55ED753-9FB6-435C-AAA4-D61A6AE4E446} [10/02/2012 10:12:53] - |D| - [0] - C:\Users\magali\AppData\Local\{C5BF1B97-9BA4-45E9-89F7-ED934E7345DB} [19/02/2012 11:56:07] - |D| - [0] - C:\Users\magali\AppData\Local\{C67A3A7F-EBE0-4DD7-A1E3-10F524C1E8B6} [26/01/2012 09:58:01] - |D| - [0] - C:\Users\magali\AppData\Local\{C70D58A4-3B62-451C-98D5-21AC187993F9} [08/09/2011 21:18:40] - |D| - [0] - C:\Users\magali\AppData\Local\{C72CB643-5F09-45DE-8DDB-5077A0C4F604} [17/06/2011 22:21:46] - |D| - [0] - C:\Users\magali\AppData\Local\{C73B153F-1DAE-4827-8846-306744D15127} [20/08/2011 22:28:23] - |D| - [0] - C:\Users\magali\AppData\Local\{C7AE0F06-A39D-4DB5-B3E2-FEF2143BE31A} [01/06/2012 15:30:26] - |D| - [0] - C:\Users\magali\AppData\Local\{C8AF4FAC-E3AC-4567-8328-29CA5E2B8138} [06/11/2011 16:49:54] - |D| - [0] - C:\Users\magali\AppData\Local\{C95BF922-9028-40FA-83F7-D65C6C5C5E34} [16/04/2012 21:22:33] - |D| - [0] - C:\Users\magali\AppData\Local\{C97391AC-A85D-4D33-AC6A-A72E9C27DEF5} [12/06/2011 12:02:37] - |D| - [0] - C:\Users\magali\AppData\Local\{C984B37F-1D3A-4D09-99B4-D8A4E2DB0ADC} [04/10/2012 21:28:22] - |D| - [0] - C:\Users\magali\AppData\Local\{CA3E6438-6FEB-4A87-9CC9-5AC07ED9021D} [13/02/2012 22:45:03] - |D| - [0] - C:\Users\magali\AppData\Local\{CB01A65C-1993-48B6-AF79-A95D9A05EE81} [18/04/2013 10:56:47] - |D| - [0] - C:\Users\magali\AppData\Local\{CBC19127-D6A8-4F64-A51F-CC3A54AAF491} [28/03/2011 23:10:38] - |D| - [0] - C:\Users\magali\AppData\Local\{CBC1F48C-1403-44FE-BA0D-134A5FFE79F0} [11/09/2012 10:00:35] - |D| - [0] - C:\Users\magali\AppData\Local\{CC2542DA-DB12-4C88-B381-346D9257A33C} [01/08/2012 19:49:01] - |D| - [0] - C:\Users\magali\AppData\Local\{CD0D1639-AEA1-4294-B8EC-6B2569E13580} [16/10/2012 14:08:56] - |D| - [0] - C:\Users\magali\AppData\Local\{CD609D76-915C-44F5-AA69-5D0A66BEC761} [15/07/2012 18:44:20] - |D| - [0] - C:\Users\magali\AppData\Local\{CDE97DFE-5797-454A-8E3B-14B5407DA280} [21/10/2012 09:29:07] - |D| - [0] - C:\Users\magali\AppData\Local\{CDF0B4A1-B1F1-489E-B4F1-00DE0589DFCC} [19/10/2012 09:05:54] - |D| - [0] - C:\Users\magali\AppData\Local\{CE063FCC-28FF-40E7-82F1-3C43230C521E} [18/04/2012 16:42:46] - |D| - [0] - C:\Users\magali\AppData\Local\{CE19B645-60FB-400D-A58C-118B3B26E9A7} [21/02/2012 23:28:45] - |D| - [0] - C:\Users\magali\AppData\Local\{CE5C044A-283F-4786-A6B6-58D514603957} [25/10/2012 14:46:43] - |D| - [0] - C:\Users\magali\AppData\Local\{CEB10665-0012-4E44-89AB-DBD9B6E42AEE} [06/02/2012 21:56:09] - |D| - [0] - C:\Users\magali\AppData\Local\{CECEE39B-EA2E-4CB1-9FA9-410A214394C3} [17/05/2012 15:26:51] - |D| - [0] - C:\Users\magali\AppData\Local\{CFFACFD4-6D98-4D77-938D-DCCED1697392} [17/03/2011 09:43:49] - |D| - [0] - C:\Users\magali\AppData\Local\{D0436F04-B444-4868-9D4A-22A04214543A} [09/09/2012 12:22:51] - |D| - [0] - C:\Users\magali\AppData\Local\{D04C07F5-DAA6-4F5F-B9FE-8C43EB2324D4} [08/09/2011 16:08:26] - |D| - [0] - C:\Users\magali\AppData\Local\{D10CF364-6E85-485C-9698-71511D080637} [03/07/2012 14:37:43] - |D| - [0] - C:\Users\magali\AppData\Local\{D1116A02-97C5-4E22-A1E1-16FA4A7A8E52} [29/03/2011 21:28:18] - |D| - [0] - C:\Users\magali\AppData\Local\{D1B61DA9-E043-4C46-A434-240ADBB86783} [25/06/2012 21:26:16] - |D| - [0] - C:\Users\magali\AppData\Local\{D1FC98BF-923B-4B9C-A6C6-051C4B3A4E33} [10/07/2011 22:51:04] - |D| - [0] - C:\Users\magali\AppData\Local\{D2545148-0368-44DF-ACF4-503516CEBDE8} [30/11/2014 23:26:34] - |D| - [0] - C:\Users\magali\AppData\Local\{D2BD3D17-00CB-4AD6-B43C-D7A0678924A0} [09/03/2016 14:14:23] - |D| - [0] - C:\Users\magali\AppData\Local\{D304DFCE-4B21-4528-A778-C9FBC66A49FE} [16/02/2013 10:16:23] - |D| - [0] - C:\Users\magali\AppData\Local\{D38FDAB4-93A7-4FDE-9A2A-C3D572D14FBA} [02/03/2016 00:03:41] - |D| - [0] - C:\Users\magali\AppData\Local\{D472CBEC-9E7C-4F48-B11B-64484137D1CA} [27/06/2011 10:36:40] - |D| - [0] - C:\Users\magali\AppData\Local\{D4D0E515-8B3A-47BD-9C52-C1A7F5FAA0E2} [15/11/2011 15:33:32] - |D| - [0] - C:\Users\magali\AppData\Local\{D4F547F1-10ED-4FB2-A8A3-F7508A5BF3D3} [04/04/2011 21:12:55] - |D| - [0] - C:\Users\magali\AppData\Local\{D54B8E59-3E41-4009-9705-66ADE459B811} [25/01/2013 15:22:41] - |D| - [0] - C:\Users\magali\AppData\Local\{D59A4DE8-B252-4B87-821B-E711F8E272CD} [28/06/2011 10:37:52] - |D| - [0] - C:\Users\magali\AppData\Local\{D6AE830D-8D34-4A73-9751-39DFBC0CA4B8} [22/05/2012 17:20:17] - |D| - [0] - C:\Users\magali\AppData\Local\{D75DE8E2-9948-492D-99B4-BCB929639B8E} [13/02/2012 10:42:24] - |D| - [0] - C:\Users\magali\AppData\Local\{D7F28D90-6B45-4562-A1DD-6D0CF0B10646} [28/01/2013 09:54:50] - |D| - [0] - C:\Users\magali\AppData\Local\{D8759968-4405-48B4-9466-FE7184134D4C} [12/07/2012 21:25:36] - |D| - [0] - C:\Users\magali\AppData\Local\{D9C8DDEF-09A7-42CA-A8A1-DF77DF45E830} [22/04/2013 22:45:51] - |D| - [0] - C:\Users\magali\AppData\Local\{DA06908B-4357-4CF4-AE80-99723D2B22C7} [01/04/2011 20:35:38] - |D| - [0] - C:\Users\magali\AppData\Local\{DA1475C4-23EE-4EDF-B363-4694A4CA8D85} [24/06/2011 10:08:22] - |D| - [0] - C:\Users\magali\AppData\Local\{DA514344-AE52-4547-A458-CF21EA1F3CD4} [14/04/2011 08:45:46] - |D| - [0] - C:\Users\magali\AppData\Local\{DAA840C7-4F33-42A8-9470-327540E5104F} [29/01/2013 22:55:55] - |D| - [0] - C:\Users\magali\AppData\Local\{DB0F08CB-9A4A-4D5E-97F1-EAD624C9D8C2} [01/05/2013 18:09:08] - |D| - [0] - C:\Users\magali\AppData\Local\{DB521A79-B041-4EC7-8E19-4EC2E8AA9015} [26/11/2012 15:58:57] - |D| - [0] - C:\Users\magali\AppData\Local\{DB5CCF39-252B-4C8C-92BA-4AE53E092AF0} [29/03/2013 09:54:21] - |D| - [0] - C:\Users\magali\AppData\Local\{DB984525-F757-4094-8D00-5235E5C814AC} [20/09/2011 14:57:15] - |D| - [0] - C:\Users\magali\AppData\Local\{DBA71889-1EB6-404B-BCB6-3CDFF8EC2695} [17/03/2013 17:42:36] - |D| - [0] - C:\Users\magali\AppData\Local\{DBB369D8-399B-4ACC-A3D0-110FE2266D4F} [24/03/2013 16:06:16] - |D| - [0] - C:\Users\magali\AppData\Local\{DC25EAEC-C53C-4F3C-86D9-0C664128C501} [20/09/2013 18:50:04] - |D| - [0] - C:\Users\magali\AppData\Local\{DCEE6E00-12A2-46A0-BF49-B942E5696099} [26/04/2012 22:50:15] - |D| - [0] - C:\Users\magali\AppData\Local\{DD34AED0-9F61-4D68-9B5D-6BD4DF9811CF} [16/01/2013 23:02:45] - |D| - [0] - C:\Users\magali\AppData\Local\{DD4FCD44-9380-4399-92BB-195FE76B3CF5} [12/05/2011 21:38:35] - |D| - [0] - C:\Users\magali\AppData\Local\{DD6168AA-4DC4-4892-85A8-9B9C3F9AF188} [22/05/2011 23:24:09] - |D| - [0] - C:\Users\magali\AppData\Local\{DD78B3C6-9555-4E6B-A840-47A4BAD6614E} [15/04/2013 22:34:35] - |D| - [0] - C:\Users\magali\AppData\Local\{DDB1B5A6-462C-41D5-BEAD-F54C0A5FA12D} [20/06/2012 21:51:58] - |D| - [0] - C:\Users\magali\AppData\Local\{DDFD5E1F-431A-4395-B48E-56391FC66C05} [25/04/2012 08:36:36] - |D| - [0] - C:\Users\magali\AppData\Local\{DE08BC17-33D9-4B5A-B174-F1C33B05D542} [07/10/2012 09:34:38] - |D| - [0] - C:\Users\magali\AppData\Local\{DE264F16-8199-4BD5-AD06-DFC47DFD521D} [08/09/2012 20:02:21] - |D| - [0] - C:\Users\magali\AppData\Local\{DED77FD0-888D-464F-93C2-1149E41A8816} [04/10/2011 15:05:54] - |D| - [0] - C:\Users\magali\AppData\Local\{DEF7125D-26F2-491B-B280-389C05612B30} [19/07/2015 19:02:44] - |D| - [0] - C:\Users\magali\AppData\Local\{DFC226A7-A00C-444E-B141-BDDE0ADFC6A2} [25/03/2011 16:08:01] - |D| - [0] - C:\Users\magali\AppData\Local\{E05448F9-8E85-4935-894B-811E1A83E680} [28/05/2011 23:59:59] - |D| - [0] - C:\Users\magali\AppData\Local\{E0F7A3ED-A9F1-4CBF-8B02-98941205BAA4} [18/01/2013 10:41:25] - |D| - [0] - C:\Users\magali\AppData\Local\{E122E913-94D9-40F0-A67F-6B0C424688B7} [16/03/2013 10:33:40] - |D| - [0] - C:\Users\magali\AppData\Local\{E13B9D91-A01D-41AE-B69A-1AB9BD4314AF} [17/01/2013 11:03:15] - |D| - [0] - C:\Users\magali\AppData\Local\{E3CAAFD5-7460-445F-AFD7-285A083F5385} [21/03/2012 22:26:06] - |D| - [0] - C:\Users\magali\AppData\Local\{E4E3D50B-E88A-4CA3-BA6E-069468385BD6} [10/04/2011 22:54:06] - |D| - [0] - C:\Users\magali\AppData\Local\{E57EA7E4-AB3F-4A0C-865D-4475696B9B17} [14/11/2011 21:37:39] - |D| - [0] - C:\Users\magali\AppData\Local\{E61F1709-81B4-45E5-91F3-EB19ACFDAB9E} [07/01/2013 22:27:25] - |D| - [0] - C:\Users\magali\AppData\Local\{E68DD5C5-2FB7-4CFE-91E1-029562FE5ED5} [12/03/2011 12:33:13] - |D| - [0] - C:\Users\magali\AppData\Local\{E6BA6E6B-54E4-4D44-BE2E-799A9B1F7FFA} [31/01/2013 10:24:26] - |D| - [0] - C:\Users\magali\AppData\Local\{E81AF139-1F71-4A10-A7D5-3E587EC4A3A2} [09/04/2011 19:32:00] - |D| - [0] - C:\Users\magali\AppData\Local\{E822323B-1D97-4E49-83CD-D70F08F6B33E} [02/04/2012 21:47:04] - |D| - [0] - C:\Users\magali\AppData\Local\{E848933D-0A41-41E4-98A6-556FDC04C6C7} [13/03/2013 18:41:22] - |D| - [0] - C:\Users\magali\AppData\Local\{E8E89524-7DDA-4002-922D-58F7B26E41F1} [25/06/2012 21:25:28] - |D| - [0] - C:\Users\magali\AppData\Local\{E931333A-9BA7-4CED-A3C3-1E87B8E11D7C} [01/06/2012 15:05:41] - |D| - [0] - C:\Users\magali\AppData\Local\{E96DD6FC-653D-49DB-A239-A8885D32EF9D} [20/12/2011 16:33:52] - |D| - [0] - C:\Users\magali\AppData\Local\{E9A392CD-1744-4584-8DAA-4692E424A187} [01/02/2012 22:25:27] - |D| - [0] - C:\Users\magali\AppData\Local\{EA320D69-9FD9-4040-AD25-61FA12F174CA} [21/07/2012 22:54:18] - |D| - [0] - C:\Users\magali\AppData\Local\{EAB6F45C-6275-486D-8206-300513D9AF05} [02/06/2011 10:35:16] - |D| - [0] - C:\Users\magali\AppData\Local\{EB128D12-479B-4625-B86A-023D453C1879} [05/02/2012 11:03:26] - |D| - [0] - C:\Users\magali\AppData\Local\{EBE13FAF-FD4D-4837-A279-FA6A507562CF} [21/10/2011 21:10:57] - |D| - [0] - C:\Users\magali\AppData\Local\{ED1807DC-0C59-4C96-8499-798BB1B14098} [26/05/2011 15:28:33] - |D| - [0] - C:\Users\magali\AppData\Local\{ED3DD625-10F8-4083-BCCB-ECB2E9C3491B} [15/08/2012 15:39:03] - |D| - [0] - C:\Users\magali\AppData\Local\{ED45A9BF-0DEB-4214-A97B-CDBBAC81AAD8} [15/08/2012 15:38:27] - |D| - [0] - C:\Users\magali\AppData\Local\{EDFD5CE7-7A9B-4CDA-9563-01CE8485C853} [08/10/2011 20:19:55] - |D| - [0] - C:\Users\magali\AppData\Local\{EE7C4ACB-BC2D-4FF1-B3CC-5C88A570AD87} [27/04/2013 09:03:24] - |D| - [0] - C:\Users\magali\AppData\Local\{EEBE71C4-441F-417E-8B6D-ECF7C5280B6E} [15/05/2011 20:55:26] - |D| - [0] - C:\Users\magali\AppData\Local\{EEFDE9D1-8E7F-4289-BF79-881E6B9825E3} [28/01/2012 20:59:34] - |D| - [0] - C:\Users\magali\AppData\Local\{EF255362-D2F0-474C-84D0-D5314A4E776B} [20/02/2013 11:46:15] - |D| - [0] - C:\Users\magali\AppData\Local\{EF9CCCD2-27D4-479F-B6F0-6857968218FF} [30/06/2011 22:00:39] - |D| - [0] - C:\Users\magali\AppData\Local\{EFEB93FF-9D2E-43B5-AD67-CE6CEAFA5CA8} [07/10/2014 21:10:38] - |D| - [0] - C:\Users\magali\AppData\Local\{F0573BD7-C959-42B5-9BD5-504A4B68C972} [08/07/2011 23:31:58] - |D| - [0] - C:\Users\magali\AppData\Local\{F14F0A91-152C-49A8-8124-7CC31F572CCF} [06/02/2012 09:53:16] - |D| - [0] - C:\Users\magali\AppData\Local\{F186FD1A-1B89-444A-83E1-12466A49637F} [19/05/2011 21:36:41] - |D| - [0] - C:\Users\magali\AppData\Local\{F24CD34E-3BF8-4595-9D3A-073286B54410} [04/02/2013 16:20:21] - |D| - [0] - C:\Users\magali\AppData\Local\{F298C837-1B89-4E8A-B3A4-7C3F86B45D24} [22/08/2012 19:43:50] - |D| - [0] - C:\Users\magali\AppData\Local\{F39C97BF-82C0-4FE2-96C0-589E313F8A15} [08/06/2011 10:27:20] - |D| - [0] - C:\Users\magali\AppData\Local\{F3FF8E3B-1293-4B33-A669-CFCA0695F854} [07/09/2011 21:42:15] - |D| - [0] - C:\Users\magali\AppData\Local\{F401E019-5375-4958-A708-A9F606646631} [02/05/2013 15:45:47] - |D| - [0] - C:\Users\magali\AppData\Local\{F4596869-5FB4-47A8-8A59-4D69265AC1A0} [23/02/2012 10:15:51] - |D| - [0] - C:\Users\magali\AppData\Local\{F493EF3F-9D5C-4D98-B36C-2548F22AD0B8} [26/07/2015 23:01:11] - |D| - [0] - C:\Users\magali\AppData\Local\{F66B6FAD-9B1E-4FBD-A59A-9D9956F304A6} [31/08/2011 10:28:00] - |D| - [0] - C:\Users\magali\AppData\Local\{F6D65D50-ABC4-43ED-B7DA-75FE55CD0171} [07/12/2012 23:09:05] - |D| - [0] - C:\Users\magali\AppData\Local\{F76AC6D1-B698-4FC8-9CC9-997803410C2B} [09/03/2013 00:09:24] - |D| - [0] - C:\Users\magali\AppData\Local\{F7811C00-3BF8-4AE5-B3AF-6BE7931D7FD3} [07/07/2012 17:45:49] - |D| - [0] - C:\Users\magali\AppData\Local\{F8188FD9-A39E-42CB-BAA5-8DBE35786232} [20/11/2012 00:00:02] - |D| - [0] - C:\Users\magali\AppData\Local\{F85DEF76-C6A0-4568-81B1-06916DF9B185} [02/07/2011 10:06:54] - |D| - [0] - C:\Users\magali\AppData\Local\{F896C7C8-8881-42A1-B0B9-A8EC085040DC} [27/02/2012 16:55:38] - |D| - [0] - C:\Users\magali\AppData\Local\{F8B62973-DD03-4406-BA8B-E9B41C4A7A15} [01/02/2012 10:23:33] - |D| - [0] - C:\Users\magali\AppData\Local\{F8C0A6A7-7673-4FDF-B35B-4C5CBE6E4EB0} [17/02/2013 14:48:16] - |D| - [0] - C:\Users\magali\AppData\Local\{F92C11D0-443A-43F9-A846-9BA543F3A795} [23/01/2012 22:23:09] - |D| - [0] - C:\Users\magali\AppData\Local\{FA168CBC-F001-408E-8875-991362ACCC40} [03/10/2011 21:46:31] - |D| - [0] - C:\Users\magali\AppData\Local\{FA43C3A8-2DB4-450D-B219-54B5990EC0F1} [08/05/2011 21:39:01] - |D| - [0] - C:\Users\magali\AppData\Local\{FA475AF6-34C2-4D81-BA2A-7319A6F2C905} [09/11/2012 15:32:36] - |D| - [0] - C:\Users\magali\AppData\Local\{FC0E07D3-D06A-4593-B2EA-70E721C8E1CD} [27/11/2011 23:58:16] - |D| - [0] - C:\Users\magali\AppData\Local\{FC409EC7-F800-458E-8538-01D38F92D939} [14/10/2013 18:10:08] - |D| - [0] - C:\Users\magali\AppData\Local\{FC61C562-CFBC-4F63-8324-59C1056D63C4} [23/01/2012 22:24:28] - |D| - [0] - C:\Users\magali\AppData\Local\{FCAB595D-2148-46B7-B123-52135EC533DD} [05/02/2012 11:04:19] - |D| - [0] - C:\Users\magali\AppData\Local\{FCFBEF2E-1FBA-4940-8CAB-5C0E545200CD} [27/06/2011 22:37:16] - |D| - [0] - C:\Users\magali\AppData\Local\{FD36B945-283A-4FE8-9715-E05FD78F9DE7} [28/02/2013 10:12:24] - |D| - [0] - C:\Users\magali\AppData\Local\{FD9155CE-EF6F-4BA0-ADCC-FA608E3DD9A2} [21/01/2013 11:24:03] - |D| - [0] - C:\Users\magali\AppData\Local\{FE66798A-4DAF-4055-98AE-00D16FD066E5} [28/04/2013 20:49:35] - |D| - [0] - C:\Users\magali\AppData\Local\{FE7A7067-D708-4AD8-B7AB-35C8E43FDF29} [17/06/2011 10:21:09] - |D| - [0] - C:\Users\magali\AppData\Local\{FEC14766-64CD-4BDE-AD55-EF4E3AEE8C3A} [16/09/2012 21:22:58] - |D| - [0] - C:\Users\magali\AppData\Local\{FF1CE64D-8F4C-4784-9D5D-B8E4D93F5AF9} [14/07/2011 12:04:44] - |D| - [0] - C:\Users\magali\AppData\Local\{FF5809A6-4A77-4882-B025-38EA0C74A9DB} [21/05/2012 21:13:21] - |D| - [0] - C:\Users\magali\AppData\Local\{FFF3468B-3CFE-4008-83A6-87F6288D3633} [25/02/2011 22:57:16] - |ASH| - [174] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini [25/02/2011 22:37:24] - |SHD| - [0] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes [25/02/2011 22:37:23] - |RD| - [77428] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [25/02/2011 22:37:23] - |RD| - [14549] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [25/02/2011 22:57:16] - |RD| - [174] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [25/02/2011 22:37:23] - |D| - [42147] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite [25/02/2011 22:46:51] - |D| - [5147] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam [25/02/2011 22:57:16] - |ASH| - [476] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini [09/03/2013 18:08:12] - |D| - [1338] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook [03/04/2013 22:38:28] - |D| - [4380] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory [08/01/2016 20:45:37] - |D| - [2942] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP [25/02/2011 22:57:27] - |A| - [1357] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [25/02/2011 22:37:23] - |RD| - [580] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [13/12/2013 12:03:26] - |A| - [1758] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk [25/02/2011 22:57:16] - |RD| - [2580] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [25/02/2011 22:57:16] - |ASH| - [174] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini [28/07/2011 10:07:44] - |A| - [2406] - C:\Users\magali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Outil de détection de support Picture Motion Browser.lnk ¤¤¤¤¤¤¤¤¤¤ | [Public] [28/02/2011 00:09:42] - |D| - [428] - C:\Users\Public\CyberLink [14/07/2009 05:20:08] - |RHD| - [30172] - C:\Users\Public\Desktop [14/07/2009 06:54:24] - |ASH| - [174] - C:\Users\Public\desktop.ini [14/07/2009 05:20:08] - |RD| - [26945743] - C:\Users\Public\Documents [14/07/2009 05:20:08] - |RD| - [174] - C:\Users\Public\Downloads [14/07/2009 05:20:08] - |RHD| - [0] - C:\Users\Public\Favorites [14/07/2009 05:20:08] - |RHD| - [3970] - C:\Users\Public\Libraries [14/07/2009 05:20:08] - |RD| - [97915] - C:\Users\Public\Music [14/07/2009 05:20:08] - |RD| - [5838651] - C:\Users\Public\Pictures [26/10/2010 00:49:30] - |RD| - [9699579] - C:\Users\Public\Recorded TV [14/07/2009 05:20:08] - |RD| - [26246732] - C:\Users\Public\Videos ¤¤¤¤¤¤¤¤¤¤ | C:\ProgramData [31/03/2016 10:09:36] - |D| - [0] - C:\ProgramData\30e85ae1 [21/08/2014 12:04:44] - |D| - [7613] - C:\ProgramData\99c6ee7aa56007dc [25/02/2011 22:38:25] - |D| - [1304319607] - C:\ProgramData\Adobe [16/10/2014 15:01:08] - |A| - [57] - C:\ProgramData\Ament.ini [14/07/2009 07:08:56] - |SHD| - [76178110432] - C:\ProgramData\Application Data [12/03/2011 00:28:15] - |D| - [0] - C:\ProgramData\AVAST Software [10/03/2016 11:08:06] - |D| - [486570] - C:\ProgramData\Avg [02/05/2013 16:17:41] - |D| - [0] - C:\ProgramData\Babylon [22/02/2012 18:19:29] - |D| - [0] - C:\ProgramData\Canneverbe Limited [23/04/2015 16:17:20] - |HD| - [21474066] - C:\ProgramData\CanonBJ [09/03/2016 17:19:40] - |HD| - [96] - C:\ProgramData\Common Files [25/10/2010 08:30:22] - |D| - [118636] - C:\ProgramData\CyberLink [14/07/2009 07:08:56] - |SHD| - [30172] - C:\ProgramData\Desktop [14/07/2009 07:08:56] - |SHD| - [26945743] - C:\ProgramData\Documents [22/01/2016 10:04:58] - |AH| - [0] - C:\ProgramData\DP45977C.lfl [21/08/2014 12:04:26] - |D| - [669352] - C:\ProgramData\Easytoshhop [14/07/2009 07:08:56] - |SHD| - [0] - C:\ProgramData\Favorites [25/02/2011 22:38:59] - |A| - [131368] - C:\ProgramData\FullRemove.exe [28/03/2011 09:07:07] - |D| - [545034] - C:\ProgramData\Google [15/03/2011 16:57:50] - |D| - [148200] - C:\ProgramData\Hewlett-Packard [16/10/2014 15:02:27] - |D| - [10544013] - C:\ProgramData\HP [15/01/2016 19:04:31] - |D| - [309762438] - C:\ProgramData\IObit [05/05/2011 14:53:24] - |A| - [0] - C:\ProgramData\LauncherAccess.dt [25/12/2015 22:06:49] - |D| - [426349526] - C:\ProgramData\Leapfrog [08/12/2014 18:01:31] - |D| - [621374278] - C:\ProgramData\Malwarebytes [25/10/2010 08:40:41] - |D| - [60153] - C:\ProgramData\McAfee [03/07/2012 15:47:34] - |D| - [959] - C:\ProgramData\McAfee Security Scan [28/04/2011 23:00:46] - |D| - [2729602] - C:\ProgramData\Messenger Plus! [14/07/2009 05:20:08] - |SD| - [3742649726] - C:\ProgramData\Microsoft [23/05/2014 14:00:12] - |D| - [63520] - C:\ProgramData\Microsoft Help [19/02/2016 19:23:11] - |A| - [86] - C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc [20/09/2011 16:49:28] - |D| - [6069] - C:\ProgramData\NCH Software [20/09/2011 16:49:57] - |D| - [0] - C:\ProgramData\NCH Swift Sound [09/03/2016 16:45:10] - |D| - [0] - C:\ProgramData\Nico Mak Computing [13/11/2015 11:26:07] - |RASH| - [290] - C:\ProgramData\ntuser.pol [25/10/2010 10:00:37] - |D| - [104] - C:\ProgramData\NVIDIA [15/01/2016 20:20:10] - |D| - [2482423] - C:\ProgramData\NVIDIA Corporation [25/02/2011 22:44:13] - |D| - [32714813] - C:\ProgramData\OberonGameConsole [15/01/2016 19:05:28] - |D| - [286] - C:\ProgramData\ProductData [24/09/2014 10:54:50] - |D| - [7345] - C:\ProgramData\saferwweb [25/10/2010 08:37:55] - |D| - [9742184] - C:\ProgramData\SAMSUNG [05/09/2014 17:02:17] - |D| - [644245] - C:\ProgramData\shopnnddraop [25/10/2010 08:54:16] - |D| - [36] - C:\ProgramData\SiteAdvisor [25/02/2011 22:37:53] - |D| - [128170312] - C:\ProgramData\Skype [28/07/2011 10:02:03] - |D| - [192] - C:\ProgramData\Sony Corporation [14/07/2009 07:08:56] - |SHD| - [259808] - C:\ProgramData\Start Menu [25/10/2010 08:30:21] - |AD| - [360732] - C:\ProgramData\Temp [14/07/2009 07:08:56] - |SHD| - [4121368] - C:\ProgramData\Templates [16/10/2014 15:03:31] - |D| - [95268] - C:\ProgramData\Visan [25/10/2010 08:38:50] - |D| - [17135851] - C:\ProgramData\WinClon [21/08/2014 11:44:08] - |D| - [0] - C:\ProgramData\WinSpeed [21/09/2011 11:10:55] - |D| - [96] - C:\ProgramData\WinZip [25/10/2010 08:36:06] - |A| - [109] - C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log [25/10/2010 08:34:13] - |A| - [106] - C:\ProgramData\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}.log [25/10/2010 08:30:58] - |A| - [105] - C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log [25/01/2012 19:48:16] - |D| - [19160576] - C:\ProgramData\{A0559A84-0A11-425F-BFFC-532378694B25} [25/10/2010 08:35:13] - |A| - [110] - C:\ProgramData\{B7A0CE06-068E-11D6-97FD-0050BACBF861}.log [25/10/2010 08:30:35] - |A| - [107] - C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log [25/10/2010 08:31:59] - |A| - [110] - C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log [15/01/2016 19:12:01] - |D| - [0] - C:\ProgramData\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98} ¤¤¤¤¤¤¤¤¤¤ | C:\ProgramData\Microsoft\Windows\Start Menu [14/07/2009 07:01:14] - |A| - [1282] - C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk [14/07/2009 06:49:40] - |ASH| - [442] - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini [14/07/2009 05:20:08] - |RD| - [256818] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs [14/07/2009 06:49:40] - |A| - [1266] - C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk ¤¤¤¤¤¤¤¤¤¤ | C:\ProgramData\Microsoft\Windows\Start Menu\Programs [14/07/2009 05:20:08] - |RD| - [45972] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories [06/08/2015 11:00:55] - |A| - [2441] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk [14/07/2009 07:32:38] - |RD| - [18363] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [23/04/2015 16:17:54] - |D| - [1495] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP490 series [22/02/2012 18:17:57] - |A| - [1903] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk [14/07/2009 06:54:23] - |ASH| - [1748] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini [02/10/2015 14:23:23] - |D| - [1960] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverEasy [25/02/2011 22:38:59] - |D| - [29632] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Pack [14/07/2009 07:32:38] - |RD| - [6112] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games [13/03/2013 19:08:59] - |A| - [2193] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [12/06/2015 12:50:15] - |D| - [18227] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP [25/12/2015 22:24:11] - |D| - [2141] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LeapFrog Connect [14/07/2009 05:20:08] - |RD| - [4370] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance [08/12/2014 18:01:38] - |D| - [3691] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware [17/10/2013 21:28:37] - |D| - [2970] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus [26/10/2010 00:17:42] - |A| - [1345] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk [25/10/2010 09:59:01] - |A| - [1380] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Default Manager.lnk [23/05/2014 14:11:17] - |D| - [29609] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office [25/10/2010 09:28:27] - |A| - [2435] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk [16/03/2013 13:18:27] - |D| - [2265] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [07/06/2011 18:21:03] - |D| - [998] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec [25/10/2010 08:28:44] - |D| - [24961] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung [14/07/2009 06:57:08] - |A| - [1330] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk [28/07/2011 10:03:32] - |D| - [21348] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony Picture Utility [14/07/2009 05:20:08] - |RD| - [2105] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [01/02/2016 18:15:50] - |D| - [856] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SVT_INRP [26/10/2010 00:49:30] - |RHD| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC [31/05/2014 13:47:54] - |D| - [6774] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [14/07/2009 06:57:09] - |A| - [1352] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk [26/10/2010 00:17:42] - |A| - [1326] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk [14/07/2009 06:54:59] - |A| - [1210] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk [12/03/2011 11:31:42] - |RD| - [7356] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live [12/03/2011 11:38:45] - |A| - [1478] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk [12/03/2011 11:51:20] - |A| - [1305] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk [12/03/2011 11:46:03] - |A| - [1374] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk [14/07/2009 06:57:06] - |A| - [1547] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk [14/07/2009 06:57:08] - |A| - [1246] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk ¤¤¤¤¤¤¤¤¤¤ | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [14/07/2009 06:54:23] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini [03/07/2012 15:47:32] - |A| - [1931] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ¤¤¤¤¤¤¤¤¤¤ | C:\Program Files (x86) [06/08/2015 10:59:59] - |D| - [204855149] - C:\Program Files (x86)\Adobe [25/10/2010 08:27:05] - |D| - [1078] - C:\Program Files (x86)\Atheros Client Installation Program [09/03/2016 17:19:41] - |D| - [0] - C:\Program Files (x86)\AVG [14/07/2011 17:40:31] - |D| - [0] - C:\Program Files (x86)\BitComet [22/02/2012 18:17:46] - |D| - [18810137] - C:\Program Files (x86)\CDBurnerXP [14/07/2009 05:20:08] - |D| - [667590660] - C:\Program Files (x86)\Common Files [25/10/2010 08:30:26] - |D| - [1187946521] - C:\Program Files (x86)\CyberLink [14/07/2009 06:54:24] - |ASH| - [174] - C:\Program Files (x86)\desktop.ini [03/04/2013 22:37:58] - |D| - [142342301] - C:\Program Files (x86)\FreeTime [25/02/2011 22:38:40] - |D| - [143538947] - C:\Program Files (x86)\Game Pack [12/03/2011 00:29:25] - |D| - [529980180] - C:\Program Files (x86)\Google [13/11/2014 23:33:43] - |D| - [0] - C:\Program Files (x86)\GUM8842.tmp [06/08/2015 11:15:25] - |D| - [0] - C:\Program Files (x86)\GUM9F2B.tmp [06/08/2015 11:03:56] - |D| - [0] - C:\Program Files (x86)\GUMF151.tmp [16/10/2014 15:04:04] - |D| - [7661110] - C:\Program Files (x86)\Hewlett-Packard [16/10/2014 15:02:27] - |D| - [21306775] - C:\Program Files (x86)\HP [25/10/2010 08:20:10] - |HD| - [184656852] - C:\Program Files (x86)\InstallShield Installation Information [25/10/2010 08:19:44] - |D| - [5083321] - C:\Program Files (x86)\Intel [14/07/2009 05:20:08] - |D| - [10533113] - C:\Program Files (x86)\Internet Explorer [15/01/2016 19:04:21] - |D| - [35915764] - C:\Program Files (x86)\IObit [25/01/2012 19:50:05] - |D| - [29003447] - C:\Program Files (x86)\Kodak [25/12/2015 22:06:50] - |D| - [122913047] - C:\Program Files (x86)\LeapFrog [08/12/2014 18:01:31] - |D| - [59752207] - C:\Program Files (x86)\Malwarebytes Anti-Malware [17/05/2011 18:29:41] - |D| - [2530872] - C:\Program Files (x86)\MarkAny [25/10/2010 08:24:51] - |D| - [3407947] - C:\Program Files (x86)\Marvell [25/10/2010 08:40:44] - |D| - [0] - C:\Program Files (x86)\McAfee [25/10/2010 09:58:24] - |D| - [1591607] - C:\Program Files (x86)\Microsoft [25/10/2010 09:28:27] - |D| - [515719014] - C:\Program Files (x86)\Microsoft Office [16/03/2013 13:16:06] - |D| - [42884494] - C:\Program Files (x86)\Microsoft Silverlight [12/03/2011 11:42:52] - |D| - [1829877] - C:\Program Files (x86)\Microsoft SQL Server Compact Edition [23/05/2014 14:08:12] - |D| - [14904] - C:\Program Files (x86)\Microsoft Visual Studio [23/05/2014 14:03:40] - |D| - [1387249] - C:\Program Files (x86)\Microsoft Visual Studio 8 [23/05/2014 14:08:43] - |D| - [3726168] - C:\Program Files (x86)\Microsoft Works [04/10/2012 09:30:47] - |D| - [8175999] - C:\Program Files (x86)\Microsoft.NET [02/05/2013 16:19:34] - |D| - [0] - C:\Program Files (x86)\Mozilla Firefox [14/07/2009 07:32:38] - |D| - [26521] - C:\Program Files (x86)\MSBuild [07/06/2011 18:21:02] - |D| - [11033350] - C:\Program Files (x86)\MyFree Codec [20/09/2011 16:49:20] - |D| - [10796642] - C:\Program Files (x86)\NCH Software [09/03/2016 17:25:58] - |D| - [986] - C:\Program Files (x86)\Opera [17/05/2011 18:32:41] - |D| - [31060] - C:\Program Files (x86)\PC Connectivity Solution [25/10/2010 08:24:14] - |D| - [3358313] - C:\Program Files (x86)\Realtek [25/10/2010 08:27:26] - |D| - [5760794] - C:\Program Files (x86)\REALTEK Wireless LAN Software [14/07/2009 07:32:38] - |D| - [39175425] - C:\Program Files (x86)\Reference Assemblies [04/03/2015 19:43:32] - |D| - [12019578] - C:\Program Files (x86)\Rentabiliweb [25/10/2010 08:29:52] - |D| - [493297564] - C:\Program Files (x86)\Samsung [02/05/2013 16:17:50] - |D| - [0] - C:\Program Files (x86)\Software [28/07/2011 10:03:32] - |D| - [176619271] - C:\Program Files (x86)\Sony [25/10/2010 08:24:14] - |HD| - [0] - C:\Program Files (x86)\Temp [14/07/2009 06:57:06] - |HD| - [0] - C:\Program Files (x86)\Uninstall Information [31/05/2014 13:47:33] - |D| - [100325589] - C:\Program Files (x86)\VideoLAN [14/07/2009 07:32:38] - |D| - [524800] - C:\Program Files (x86)\Windows Defender [25/10/2010 09:48:54] - |D| - [236404283] - C:\Program Files (x86)\Windows Live [14/07/2009 05:20:08] - |D| - [6181376] - C:\Program Files (x86)\Windows Mail [14/07/2009 07:32:38] - |D| - [5024017] - C:\Program Files (x86)\Windows Media Player [14/07/2009 05:20:08] - |D| - [12197556] - C:\Program Files (x86)\Windows NT [14/07/2009 07:32:38] - |D| - [4417800] - C:\Program Files (x86)\Windows Photo Viewer [14/07/2009 07:32:38] - |D| - [189952] - C:\Program Files (x86)\Windows Portable Devices [14/07/2009 07:32:38] - |D| - [6302189] - C:\Program Files (x86)\Windows Sidebar [28/04/2011 22:57:45] - |D| - [23921134] - C:\Program Files (x86)\Yuna Software ¤¤¤¤¤¤¤¤¤¤ | C:\Program Files [29/07/2014 12:15:02] - |D| - [0] - C:\Program Files\005 [12/03/2011 00:28:15] - |D| - [0] - C:\Program Files\AVAST Software [14/07/2009 05:20:08] - |D| - [78561919] - C:\Program Files\Common Files [14/07/2009 06:54:24] - |ASH| - [174] - C:\Program Files\desktop.ini [25/01/2012 19:50:16] - |D| - [1605624] - C:\Program Files\DIFX [05/05/2013 21:10:54] - |D| - [42695] - C:\Program Files\DomaIQ Uninstaller [14/07/2009 07:32:38] - |D| - [90256916] - C:\Program Files\DVD Maker [02/10/2015 14:23:16] - |D| - [8233225] - C:\Program Files\Easeware [28/03/2011 09:07:24] - |D| - [1290016] - C:\Program Files\Google [12/06/2015 12:49:38] - |D| - [146965677] - C:\Program Files\HP [25/10/2010 08:25:20] - |D| - [22198796] - C:\Program Files\Intel [14/07/2009 05:20:08] - |D| - [30570876] - C:\Program Files\Internet Explorer [17/10/2013 21:28:27] - |D| - [16486127] - C:\Program Files\McAfee Security Scan [14/07/2009 07:32:38] - |D| - [149237810] - C:\Program Files\Microsoft Games [23/05/2014 14:04:04] - |D| - [593814] - C:\Program Files\Microsoft Office [16/03/2013 13:16:06] - |D| - [55714702] - C:\Program Files\Microsoft Silverlight [14/07/2009 07:32:38] - |D| - [25757] - C:\Program Files\MSBuild [13/09/2013 13:45:09] - |D| - [327984803] - C:\Program Files\NVIDIA Corporation [25/10/2010 08:24:24] - |D| - [39440680] - C:\Program Files\Realtek [14/07/2009 07:32:38] - |D| - [36834473] - C:\Program Files\Reference Assemblies [25/10/2010 08:28:15] - |D| - [336205838] - C:\Program Files\Samsung [25/10/2010 08:27:56] - |D| - [33126644] - C:\Program Files\Synaptics [14/07/2009 07:09:26] - |HD| - [0] - C:\Program Files\Uninstall Information [14/07/2009 07:32:38] - |D| - [4039680] - C:\Program Files\Windows Defender [26/10/2010 00:49:31] - |D| - [9241208] - C:\Program Files\Windows Journal [12/03/2011 01:05:06] - |D| - [7987385] - C:\Program Files\Windows Live [14/07/2009 05:20:08] - |D| - [6667776] - C:\Program Files\Windows Mail [14/07/2009 07:32:38] - |D| - [7687085] - C:\Program Files\Windows Media Player [14/07/2009 05:20:08] - |D| - [12627636] - C:\Program Files\Windows NT [14/07/2009 07:32:38] - |D| - [5516056] - C:\Program Files\Windows Photo Viewer [14/07/2009 07:32:38] - |D| - [244736] - C:\Program Files\Windows Portable Devices [14/07/2009 07:32:38] - |D| - [11313592] - C:\Program Files\Windows Sidebar ¤¤¤¤¤¤¤¤¤¤ | C:\Program Files (x86)\Common Files [28/03/2011 09:30:00] - |D| - [9281179] - C:\Program Files (x86)\Common Files\Adobe [25/10/2010 08:34:58] - |D| - [128512] - C:\Program Files (x86)\Common Files\CyberLink [04/01/2013 19:40:07] - |D| - [745624] - C:\Program Files (x86)\Common Files\DESIGNER [25/10/2010 08:24:12] - |D| - [7156114] - C:\Program Files (x86)\Common Files\InstallShield [15/01/2016 19:11:51] - |D| - [0] - C:\Program Files (x86)\Common Files\IObit [25/01/2012 19:50:05] - |D| - [1668667] - C:\Program Files (x86)\Common Files\Kodak [25/10/2010 08:42:21] - |D| - [820488] - C:\Program Files (x86)\Common Files\McAfee [14/07/2009 05:20:08] - |D| - [238037701] - C:\Program Files (x86)\Common Files\microsoft shared [25/02/2011 22:38:57] - |D| - [354896] - C:\Program Files (x86)\Common Files\Oberon Media [25/10/2010 08:38:45] - |D| - [54293042] - C:\Program Files (x86)\Common Files\Samsung [14/07/2009 05:20:08] - |D| - [2702] - C:\Program Files (x86)\Common Files\Services [14/07/2009 05:20:08] - |D| - [41103783] - C:\Program Files (x86)\Common Files\SpeechEngines [14/07/2009 05:20:08] - |D| - [44310223] - C:\Program Files (x86)\Common Files\System [03/04/2013 22:37:51] - |D| - [0] - C:\Program Files (x86)\Common Files\Umbrella [25/10/2010 09:39:17] - |D| - [269687729] - C:\Program Files (x86)\Common Files\Windows Live ¤¤¤¤¤¤¤¤¤¤ | C:\Program Files\Common files [14/07/2009 05:20:08] - |D| - [65760254] - C:\Program Files\Common files\Microsoft Shared [14/07/2009 05:20:08] - |D| - [2702] - C:\Program Files\Common files\Services [14/07/2009 05:20:08] - |D| - [608768] - C:\Program Files\Common files\SpeechEngines [14/07/2009 05:20:08] - |D| - [12190195] - C:\Program Files\Common files\System ¤¤¤¤¤¤¤¤¤¤ | Tasks [MD5.E2644841764B2CAE769882D6D88A6B15] - [12/03/2015 18:31:32] - |A| - [1002] - C:\windows\Tasks\Adobe Flash Player Updater.job [MD5.4F40FD697C31ADB5B213A113192358C5] - [02/10/2015 14:23:28] - |A| - [408] - C:\windows\Tasks\DriverEasy Scheduled Scan.job [MD5.2C6F585A7B7151C4D2EBE335E08FD328] - [01/10/2012 16:58:38] - |A| - [910] - C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1125036280-3562319748-3601731155-1000Core.job [MD5.9DFC30F246B79F80F32C5B2919EBF36C] - [01/10/2012 16:58:39] - |A| - [932] - C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1125036280-3562319748-3601731155-1000UA.job [MD5.AA5B56FF09F67F2760B375B4586DEE41] - [13/03/2013 18:59:47] - |A| - [1066] - C:\windows\Tasks\GoogleUpdateTaskMachineCore.job [MD5.76440F3ED7724BF4F83886788B44B019] - [13/03/2013 18:59:48] - |A| - [1070] - C:\windows\Tasks\GoogleUpdateTaskMachineUA.job [MD5.125F0A0654BB5252B47F41746C7BC973] - [08/01/2016 20:46:47] - |A| - [408] - C:\windows\Tasks\HP Photo Creations Communicator.job [MD5.00000000000000000000000000000000] - [15/01/2016 19:05:28] - |D| - [0] - C:\windows\Tasks\ImCleanDisabled [MD5.F1A6CD5ADAAB953A6764EA364E17BFB8] - [14/07/2009 07:08:49] - |AH| - [6] - C:\windows\Tasks\SA.DAT [MD5.D14C8B16062899052284E74D3B53D1CA] - [14/07/2009 07:08:49] - |A| - [32496] - C:\windows\Tasks\SCHEDLGU.TXT [MD5.2AE5BA2AD0DD6D6D187E421B9735E000] - [09/03/2016 13:38:55] - |A| - [368] - C:\windows\Tasks\SlimCleaner Plus (Scheduled Scan - magali).job [MD5.B63AD96D5AB77552EFDB7D2277C3B0CB] - [06/08/2015 11:01:28] - |A| - [3886] - C:\windows\System32\Tasks\Adobe Acrobat Update Task : C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [MD5.EE781505DDE0CA80AEC49EC7CC790BDF] - [12/03/2015 18:31:32] - |A| - [3940] - C:\windows\System32\Tasks\Adobe Flash Player Updater : C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [MD5.CD76994A7C7712CC0B5B2C486E787102] - [25/10/2010 08:39:22] - |A| - [3306] - C:\windows\System32\Tasks\advSRS4 : "C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe" [MD5.6A72F09797DC65C098E2F41AA73E801F] - [09/03/2016 19:52:23] - |A| - [2760] - C:\windows\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance : C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe [MD5.862F067E7F0E0E0DAC62F8FFE463588C] - [25/10/2010 08:37:14] - |A| - [3100] - C:\windows\System32\Tasks\BatteryLifeExtender : C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [MD5.8243F34B556B517268A5BDEBB602E23B] - [10/03/2011 10:33:33] - |A| - [3540] - C:\windows\System32\Tasks\CreateChoiceProcessTask : C:\Windows\System32\browserchoice.exe [MD5.DAB758CB992572636A6A7BA17D1D56D7] - [15/01/2016 19:04:33] - |A| - [2878] - C:\windows\System32\Tasks\Driver Booster SkipUAC (magali) : C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [MD5.BD5CE11240533E4D54C35369D24378E5] - [02/10/2015 14:23:28] - |A| - [3814] - C:\windows\System32\Tasks\DriverEasy Scheduled Scan : C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [MD5.C6EFFC924E1E3FC006E14FF0E03F929E] - [25/10/2010 08:37:32] - |A| - [3294] - C:\windows\System32\Tasks\EasyBatteryManager : "%ProgramFiles(x86)%\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe" [MD5.CE75171162882119BE23577A6484EC50] - [25/10/2010 08:37:54] - |A| - [3168] - C:\windows\System32\Tasks\EasyDisplayMgr : "C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe" [MD5.D03B4BF4041704915321A3D8876EC7A3] - [25/10/2010 08:36:49] - |A| - [3286] - C:\windows\System32\Tasks\EasySpeedUpManager : "%programfiles(x86)%\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe" [MD5.F3847300081E71007844049BC707CB34] - [01/10/2012 16:58:39] - |A| - [3542] - C:\windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1125036280-3562319748-3601731155-1000Core : C:\Users\magali\AppData\Local\Facebook\Update\FacebookUpdate.exe [MD5.87E3DBE42BF7A2BA4958534D4BDA0630] - [01/10/2012 16:58:39] - |A| - [3910] - C:\windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1125036280-3562319748-3601731155-1000UA : C:\Users\magali\AppData\Local\Facebook\Update\FacebookUpdate.exe [MD5.CDB7E58233167FB6103A2EE30378F97D] - [13/03/2013 18:59:47] - |A| - [3814] - C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.0B5C2F5E37F9A4FB1A4DF2AC65FE06EE] - [13/03/2013 18:59:48] - |A| - [4066] - C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.00000000000000000000000000000000] - [02/10/2015 10:31:35] - |D| - [12676] - C:\windows\System32\Tasks\Hewlett-Packard [MD5.63CD60BD9BA4031BB7CC45462E742F28] - [05/05/2013 21:02:09] - |A| - [3516] - C:\windows\System32\Tasks\Hoolapp For Android : C:\Users\magali\AppData\Roaming\HOOLAP~1\UPDATE~1\UPDATE~1.EXE [MD5.18CB435B2531BE0830D929C855B0939E] - [05/05/2013 21:02:11] - |A| - [3314] - C:\windows\System32\Tasks\Hoolapp Init : C:\Users\magali\AppData\Roaming\HOOLAP~1\Hoolapp.exe [MD5.24DE25F0F4DD44910147F970F01E8F2D] - [08/01/2016 20:46:47] - |A| - [3414] - C:\windows\System32\Tasks\HP Photo Creations Communicator : C:\Users\magali\AppData\Roaming\HP Photo Creations\Communicator.exe [MD5.9FC3DA50EFAFA8E6FF9642D09A3E041F] - [12/06/2015 12:50:31] - |A| - [3614] - C:\windows\System32\Tasks\HPCustParticipation HP ENVY 4500 series : "C:\Program Files\HP\HP ENVY 4500 series\Bin\HPCustPartic.exe" [MD5.00000000000000000000000000000000] - [14/07/2009 05:20:13] - |D| - [285372] - C:\windows\System32\Tasks\Microsoft [MD5.00000000000000000000000000000000] - [20/09/2011 16:49:28] - |D| - [0] - C:\windows\System32\Tasks\NCH Software [MD5.00000000000000000000000000000000] - [20/09/2011 16:49:49] - |D| - [0] - C:\windows\System32\Tasks\NCH Swift Sound [MD5.E946B2EC038ECB85A3127FEF12985E03] - [25/10/2010 08:38:42] - |A| - [3266] - C:\windows\System32\Tasks\SamsungSupportCenter : %programfiles(x86)%\Samsung\Samsung Support Center\SSCKbdHk.exe [MD5.6D186858C58A598EF600714E1351F4F0] - [09/03/2016 13:39:58] - |A| - [3032] - C:\windows\System32\Tasks\SlimCleaner Plus (Scheduled Scan - magali) : C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe [MD5.4D3D0D7BD9B0BF28D91E3BF7867AEB17] - [25/10/2010 08:29:55] - |A| - [3158] - C:\windows\System32\Tasks\SUPBackground : "%ProgramFiles%\Samsung\Samsung Update Plus\SUPBackground.exe" [MD5.C8281F0C3DAD564BA2DAA21690709350] - [17/01/2013 00:16:49] - |A| - [3944] - C:\windows\System32\Tasks\User_Feed_Synchronization-{60F508E2-143A-4D68-9237-C7F52CF5C0F5} : C:\windows\system32\msfeedssync.exe [MD5.00000000000000000000000000000000] - [14/07/2009 07:09:57] - |D| - [4482] - C:\windows\System32\Tasks\WPD [MD5.B6AF2B32A471D96F6F75BE5B34864DBF] - [05/08/2014 14:52:57] - |A| - [3222] - C:\windows\System32\Tasks\{02A2ED98-CC95-4695-9252-CB87DDDF5DCE} : C:\windows\system32\pcalua.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 15:42:57] - |A| - [2986] - C:\windows\System32\Tasks\{247E49CC-6347-4935-A0AA-9FEF6302A610} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 16:24:25] - |A| - [2986] - C:\windows\System32\Tasks\{2B9BCD07-F719-40CF-BDD8-D9F6A8A3581F} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 16:24:32] - |A| - [2986] - C:\windows\System32\Tasks\{317E5F60-B9BD-4FAF-AF96-C4DEEF9DA89F} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 16:25:00] - |A| - [2986] - C:\windows\System32\Tasks\{3836A68E-C1CC-4458-A1ED-6BE220EDC363} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 16:24:39] - |A| - [2986] - C:\windows\System32\Tasks\{6BB85316-7E49-4775-81B6-AE7765C0F16C} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 16:24:54] - |A| - [2986] - C:\windows\System32\Tasks\{7C6BDDD9-BB0F-4070-A0D6-9C4795812C98} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 15:42:19] - |A| - [2986] - C:\windows\System32\Tasks\{7CBD8FF0-BC4C-4806-BA6B-D16A61A287D6} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 15:46:47] - |A| - [2986] - C:\windows\System32\Tasks\{8743580A-E797-4ADE-91FC-FE43757F0BB0} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 16:24:23] - |A| - [2986] - C:\windows\System32\Tasks\{8833BD5D-6209-4625-B312-9F1732055E76} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 16:29:25] - |A| - [2986] - C:\windows\System32\Tasks\{8C1DD00A-0E9B-43D4-9D73-CF0724DCCEA4} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 15:42:45] - |A| - [2986] - C:\windows\System32\Tasks\{8F853D28-F657-4FE5-B81D-79A7E04DCE5C} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.F133273742CF60C8EB1883B19759D3CB] - [05/08/2014 14:35:13] - |A| - [3122] - C:\windows\System32\Tasks\{A504159C-86B7-4F1D-871A-A748561539B6} : C:\windows\system32\pcalua.exe [MD5.B7A7617FAF91DFFE3EC99469E5E63BE8] - [31/03/2016 10:10:12] - |A| - [3730] - C:\windows\System32\Tasks\{A915FE5C-7EA8-C248-B529-70C9F5A6B579} : C:\windows\system32\regsvr32.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 16:24:14] - |A| - [2986] - C:\windows\System32\Tasks\{B06D3D14-CEF4-42E5-8D1C-363781476F10} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 15:45:55] - |A| - [2986] - C:\windows\System32\Tasks\{B33A6CC8-882F-45BA-B0F8-CC6C91ED1A67} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 16:29:51] - |A| - [2986] - C:\windows\System32\Tasks\{B81B071B-ABB3-4943-A607-27B941526326} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 16:29:15] - |A| - [2986] - C:\windows\System32\Tasks\{BAB0CD74-9AEF-4FD6-AD43-DE800D500060} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 15:41:52] - |A| - [2986] - C:\windows\System32\Tasks\{F33F428E-CFBE-4315-ABE2-8450357CE743} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.1A8D0E031792423F9869AB7C77E218ED] - [02/03/2014 15:39:35] - |A| - [2986] - C:\windows\System32\Tasks\{F7700C70-F052-470C-A3E7-8B97E179841A} : C:\Program Files (x86)\Game Pack\GameConsole\GamePack.exe [MD5.BABC4702B8645E7B2E36AF6B8EB97717] - [02/05/2013 15:58:14] - |A| - [3098] - C:\windows\System32\Tasks\{FC1C4D3F-99A6-4D05-B95C-74AAF956DD44} : "c:\program files (x86)\google\chrome\application\chrome.exe" [MD5.00000000000000000000000000000000] - [14/07/2009 05:20:14] - |D| - [0] - C:\windows\Syswow64\Tasks\Microsoft ¤¤¤¤¤¤¤¤¤¤ | Firewall [HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules] "Netlogon-NamedPipe-In"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=445|App=System|Name=@netlogon.dll,-1003|Desc=@netlogon.dll,-1006|EmbedCtxt=@netlogon.dll,-1010| "{B9B162EC-FD9E-41C6-BCB7-71ED04025558}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE|Name=CyberLink PowerDirector|Desc=CyberLink PowerDirector| "{603A756A-E1D8-47AB-B27D-6727609D338F}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\CyberLink\PowerDVD8\PowerDVD8.EXE|Name=CyberLink PowerDVD 8.0|Desc=CyberLink PowerDVD 8.0| "{892411EE-4DDF-4643-AB2E-DE4FBB3CE124}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Profile=Domain|Profile=Private|Profile=Public|App=C:\Program Files (x86)\Common Files\Mcafee\MNA\McNaSvc.exe|Name=McAfee Network Agent|Desc=McAfee Network Agent| "{0620A053-4AED-46E6-B714-E477DB6EB115}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe|Name=Windows Live Communications Platform|Edge=TRUE| "{98232BA7-579B-46E9-99AE-29B7779289BD}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=2869|RA4=LocalSubnet|RA6=LocalSubnet|Name=Windows Live Communications Platform (UPnP)| "{6480EF59-FF68-4F7A-ACF8-A677C81EA933}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=1900|RA4=LocalSubnet|RA6=LocalSubnet|Name=Windows Live Communications Platform (SSDP)| "{6C8BAAD6-D47F-446D-9249-CF14C220B9E9}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe|Name=Windows Live Messenger|Edge=TRUE| "{378D6D7C-C95E-481A-9EF0-B516476EC084}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Windows Live\Mesh\MOE.exe|Name=Windows Live Mesh|Edge=TRUE| "{14604895-221D-403B-8FB6-52EAB3722DA5}"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=808|App=C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe|Svc=NetTcpActivator|Name=@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelEvents.dll,-2000|Desc=@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelEvents.dll,-2001|EmbedCtxt=@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelEvents.dll,-2002| "TCP Query User{A1346196-75E7-4CE6-AA37-465F48B5015F}C:\users\magali\appdata\roaming\spotify\spotify.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\magali\appdata\roaming\spotify\spotify.exe|Name=spotify.exe|Desc=spotify.exe|Defer=User| "UDP Query User{D7CFE603-5DA5-4A7E-8E92-63E45145685A}C:\users\magali\appdata\roaming\spotify\spotify.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\magali\appdata\roaming\spotify\spotify.exe|Name=spotify.exe|Desc=spotify.exe|Defer=User| "{D321C24C-09A7-4109-9F88-931954A19153}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\SoloApp\WebDriver.dll|Name=WebDriver.dll| "{E8443416-17F2-4376-A2CA-CE83FE3027F9}"=v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\SoloApp\WebDriver.dll|Name=WebDriver.dll| "{74AFEE00-6EBA-4AEA-A3C4-AD4054F8EEAF}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\SoloApp\WebDriver.dll|Name=WebDriver.dll| "{BA5DBC59-9663-47E9-9CD5-8C5A157E7DB4}"=v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\SoloApp\WebDriver.dll|Name=WebDriver.dll| "{D80DE0FA-67E5-4599-A58C-3A59766E364B}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\SoloApp\WebDriver.dll|Name=WebDriver.dll| "{577F64AB-7B42-4BE8-9F4A-6F2D2A461F47}"=v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\SoloApp\WebDriver.dll|Name=WebDriver.dll| "{F0D953D9-E4C5-4085-9DEC-DCD290936272}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\SoloApp\WebDriver.dll|Name=WebDriver.dll| "{6EC0952A-25B5-49FE-A101-3676507B96DE}"=v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\SoloApp\WebDriver.dll|Name=WebDriver.dll| "{8C11766F-BE77-4531-977D-A2EA327D41F1}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\SoloApp\WebDriver.dll|Name=WebDriver.dll| "{63B87497-E952-4E25-8C9F-DFB4150B2471}"=v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\SoloApp\WebDriver.dll|Name=WebDriver.dll| "TCP Query User{3C75DB8F-97C8-4713-B9EE-E8B0E3BB4D4C}C:\users\magali\appdata\local\microsoft\windows\temporary internet files\content.ie5\rceadl6c\runtime\jre-x64\1.8.0_25\bin\javaw.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\magali\appdata\local\microsoft\windows\temporary internet files\content.ie5\rceadl6c\runtime\jre-x64\1.8.0_25\bin\javaw.exe|Name=javaw.exe|Desc=javaw.exe| "UDP Query User{78914E5D-889A-4750-BB49-B9DD9FE5EA89}C:\users\magali\appdata\local\microsoft\windows\temporary internet files\content.ie5\rceadl6c\runtime\jre-x64\1.8.0_25\bin\javaw.exe"=v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\magali\appdata\local\microsoft\windows\temporary internet files\content.ie5\rceadl6c\runtime\jre-x64\1.8.0_25\bin\javaw.exe|Name=javaw.exe|Desc=javaw.exe| "{564A3F01-35E3-40D3-90B1-C98C39D18BA5}"=v2.10|Action=Allow|Active=TRUE|Dir=In|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\Program Files\HP\HP ENVY 4500 series\Bin\DeviceSetup.exe|Name=Configuration du périphérique HP (HP ENVY 4500 series)|Edge=TRUE| "{FF95B045-7C61-4AB1-93CB-8C3282831949}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|LPort=5357|Name=Port TCP WS-Eventing 5357| "{BD0FC3B1-3989-422B-A9B8-3D4A177F3471}"=v2.10|Action=Allow|Active=TRUE|Dir=In|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\Program Files\HP\HP ENVY 4500 series\Bin\HPNetworkCommunicatorCom.exe|Name=Communicateur réseau COM HP (HP ENVY 4500 series)|Edge=TRUE| "{55D67599-FA62-48E7-960C-02B0F465A33F}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Users\magali\AppData\Local\Chromium\Application\chrome.exe|Name=Chromium (mDNS-In)|Desc=Règle de trafic entrant pour Chromium autorisant le trafic mDNS|EmbedCtxt=Chromium| "{D45FCE91-7932-406B-86D9-395B66DFE386}"=v2.10|Action=Allow|Active=TRUE|Dir=In|RA4=169.254.0.0/255.255.0.0|RA4=244.0.0.251|App=C:\Program Files (x86)\LeapFrog\LeapFrog Connect\LeapfrogConnect.exe|Name=LeapFrog Connect| "{832A8F92-F03A-4452-87F8-A09464127E04}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Windows\SysWOW64\muzapp.exe|Name=MUZ AOD APP player| "{EE000481-A5A4-44F8-9316-2B6A3BAE001A}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Windows\SysWOW64\muzapp.exe|Name=MUZ AOD APP player| "{C7AF5667-9BF7-4352-BB9C-4C04987B1F27}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe|Name=Driver Booster| "{1030C72F-3766-4CB1-B78D-8D0A95E3A0B0}"=v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe|Name=Driver Booster| "{562F7180-469A-4B02-83AC-13CBAD7B0017}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe|Name=Driver Booster| "{D5229D01-C983-43F4-B635-00E1B77B713B}"=v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe|Name=Driver Booster| "{6E095F67-9FB8-4D18-B13A-50FEE45A0C8D}"=v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe|Name=Driver Booster| "{CC74B5EA-08EC-423B-A0E0-27870994CFFB}"=v2.10|Action=Allow|Active=TRUE|Dir=Out|App=C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe|Name=Driver Booster| "{1DAAFE87-7B03-49A2-910A-8363B4A4E685}"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe|Name=Google Chrome (mDNS-In)|Desc=Règle de trafic entrant pour Google Chrome autorisant le trafic mDNS|EmbedCtxt=Google Chrome| "TCP Query User{A80137C5-6CBA-412B-A1EC-D72343F79773}C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3AZXULE2\QuickDiag.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3AZXULE2\QuickDiag.exe|Name=QuickDiag|Desc=QuickDiag|Defer=User| "UDP Query User{8086F52E-78FA-489A-B2C4-2168ADE624EB}C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3AZXULE2\QuickDiag.exe"=v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Users\magali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3AZXULE2\QuickDiag.exe|Name=QuickDiag|Desc=QuickDiag|Defer=User| ¤¤¤¤¤¤¤¤¤¤ | Control\Class [HKLM\SYSTEM\CurrentControlSet\Control\Class\{03F52937-1FD6-44FB-82C6-FE988F1B1D61}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{0475BB51-5A02-4EE0-B36C-29040FAD2650}] : (igfx) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{04A83FC2-2AE2-4C99-B45F-E9707B377636}] : (aswEmHWID2) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{1264760F-A5C8-4BFE-B314-D56A7B44A362}] : (DXGKrnl) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{14B62F50-3F15-11DD-AE16-0800200C9A66}] : (DigitalMediaDevices) [] -> @digitalmediadevice.inf,%ClassName%;Appareils multimédias numériques [HKLM\SYSTEM\CurrentControlSet\Control\Class\{25DBCE51-6C8F-4A72-8A6D-B54C2B4FC835}] : (WCEUSBS) [] -> @%SystemRoot%\System32\SysClass.Dll,-3026 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{36FC9E60-C465-11CF-8056-444553540000}] : (USB) [] -> @%SystemRoot%\System32\SysClass.Dll,-3025 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4116F60B-25B3-4662-B732-99A6111EDC0B}] : (IPMIDRV) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{43675D81-502A-4A82-9F84-B75F418C5DEA}] : (Media Center Extender) [] -> @%SystemRoot%\system32\McxDriv.dll,-100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4658EE7E-F050-11D1-B6BD-00C04FA372A7}] : (PnpPrinters) [] -> @%systemroot%\system32\ntprint.dll,-1300 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{48721B56-6795-11D2-B1A8-0080C72E74A2}] : (Dot4) [] -> @%SystemRoot%\system32\sysclass.dll,-3023 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{49CE6AC8-6F86-11D2-B1E5-0080C72E74A2}] : (Dot4Print) [] -> @%SystemRoot%\system32\sysclass.dll,-3024 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}] : (CDROM) [] -> @%SystemRoot%\System32\StorProp.dll,-17001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E966-E325-11CE-BFC1-08002BE10318}] : (Computer) [] -> @%SystemRoot%\System32\SysClass.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}] : (DiskDrive) [] -> @%SystemRoot%\System32\StorProp.dll,-17000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}] : (Display) [] -> @DispCI.dll,-3100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}] : (fdc) [] -> @%SystemRoot%\System32\SysClass.Dll,-3013 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}] : (hdc) [] -> @%SystemRoot%\System32\SysClass.Dll,-3001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}] : (Keyboard) [] -> @%SystemRoot%\System32\SysClass.Dll,-3002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96C-E325-11CE-BFC1-08002BE10318}] : (MEDIA) [] -> @mmci.dll,-3000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}] : (Modem) [] -> @%SystemRoot%\System32\mdminst.dll,-14100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}] : (Monitor) [] -> @Montr_CI.dll,-3100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96F-E325-11CE-BFC1-08002BE10318}] : (Mouse) [] -> @%SystemRoot%\System32\SysClass.Dll,-3004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E970-E325-11CE-BFC1-08002BE10318}] : (MTD) [] -> @SysClass.Dll,-3021 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E971-E325-11CE-BFC1-08002BE10318}] : (MultiFunction) [] -> @%SystemRoot%\System32\SysClass.Dll,-3014 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}] : (Net) [] -> @NetCfgx.dll,-1502 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E973-E325-11CE-BFC1-08002BE10318}] : (NetClient) [] -> @NetCfgx.dll,-1504 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E974-E325-11CE-BFC1-08002BE10318}] : (NetService) [] -> @NetCfgx.dll,-1505 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E975-E325-11CE-BFC1-08002BE10318}] : (NetTrans) [] -> @NetCfgx.dll,-1503 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E977-E325-11CE-BFC1-08002BE10318}] : (PCMCIA) [] -> @%SystemRoot%\System32\SysClass.Dll,-3010 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E978-E325-11CE-BFC1-08002BE10318}] : (Ports) [] -> @%SystemRoot%\System32\msports.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E979-E325-11CE-BFC1-08002BE10318}] : (Printer) [] -> @%systemroot%\system32\ntprint.dll,-1004 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}] : (SCSIAdapter) [] -> @%SystemRoot%\System32\SysClass.Dll,-3005 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E97D-E325-11CE-BFC1-08002BE10318}] : (System) [] -> @%SystemRoot%\System32\SysClass.Dll,-3008 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E97E-E325-11CE-BFC1-08002BE10318}] : (Unknown) [] -> @%SystemRoot%\System32\SysClass.Dll,-3009 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}] : (FloppyDisk) [] -> @%SystemRoot%\System32\SysClass.Dll,-3015 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50127DC3-0F36-415E-A6CC-4CB3BE910B65}] : (Processor) [] -> @%SystemRoot%\system32\procinst.dll,-100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50906CB8-BA12-11D1-BF5D-0000F805F530}] : (MultiPortSerial) [] -> @%SystemRoot%\system32\sysclass.dll,-3022 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5099944A-F6B9-4057-A056-8C550228544C}] : (Memory) [] -> @%SystemRoot%\System32\SysClass.Dll,-3018 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] : (SmartCardReader) [] -> @StorProp.dll,-17002 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{5175D334-C371-4806-B3BA-71FD53C9258D}] : (Sensor) [] -> @%systemroot%\system32\SensorsCpl.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{522119B9-1B9A-498A-AC52-148B533EFD50}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] : (VolumeSnapshot) [] -> @%SystemRoot%\System32\SysClass.Dll,-3011 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{53D29EF7-377C-4D14-864B-EB3A85769359}] : (BiometricDevice) [] -> @%SystemRoot%\System32\SysClass.DLL,-3028 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] : (1394) [] -> @%SystemRoot%\System32\SysClass.Dll,-3016 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC5-810F-11D0-BEC7-08002BE2092F}] : (Infrared) [] -> @NetCfgx.dll,-1501 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC6-810F-11D0-BEC7-08002BE2092F}] : (Image) [] -> @%systemroot%\system32\sti_ci.dll,-52 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6D807884-7D21-11CF-801C-08002BE10318}] : (TapeDrive) [] -> @%SystemRoot%\System32\SysClass.Dll,-3006 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{6FAE73B7-B735-4B50-A0DA-0DC2484B1F1A}] : (igfx) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] : (Volume) [] -> @%SystemRoot%\System32\SysClass.Dll,-3007 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{72631E54-78A4-11D0-BCF7-00AA00B7B32A}] : (Battery) [] -> @%SystemRoot%\system32\batt.dll,-100 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] : (HIDClass) [] -> @hid.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{7EBEFBC0-3200-11D2-B4C2-00A0C9697D07}] : (61883) [] -> @%SystemRoot%\System32\SysClass.Dll,-3019 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{87C077B2-3D3B-4156-938A-EA51B451D6C6}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{8ECC055D-047F-11D1-A537-0000F8753ED1}] : (LegacyDriver) [] -> @%SystemRoot%\System32\SysClass.Dll,-3003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{990A2BD7-E738-46C7-B26F-1CF8FB9F1391}] : (SmartCard) [] -> @sccls.dll,-300 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{997B5D8D-C442-4F2E-BAF3-9C8E671E9E21}] : (SideShow) [] -> @%systemroot%\system32\AuxiliaryDisplayClassInstaller.dll,-10000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] : (SDHost) [] -> @%SystemRoot%\System32\SysClass.Dll,-3012 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{A73C93F1-9727-4D1D-ACE1-0E333BA4E7DB}] : (nvlddmkm) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{AB4964A5-4361-4899-BA0A-180305F2BF92}] : (aswTdi) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{BC103702-DD72-406F-9B28-95C868337B59}] : (Transfer Cable) [] -> @%SystemRoot%\System32\migwiz\migres.dll,-20 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{C06FF265-AE09-48F0-812C-16753D7CBA83}] : (AVC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3027 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{C4A06E97-ED42-47B9-83E1-F12299B286A5}] : (aswRdr) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Class\{CE5939AE-EBDE-11D0-B181-0000F8753EC4}] : (MediumChanger) [] -> @%SystemRoot%\System32\StorProp.dll,-17003 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] : (SBP2) [] -> @%SystemRoot%\System32\SysClass.Dll,-3017 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{D61CA365-5AF4-4486-998B-9DB4734C6CA3}] : (XnaComposite) [] -> @%SystemRoot%\system32\XInput9_1_0.dll,-1000 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] : (SecurityDevices) [] -> @%SystemRoot%\System32\SysClass.Dll,-3020 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{DB4F6DDD-9C0E-45E4-9597-78DBBAD0F412}] : (SmartCardFilter) [] -> @sccls.dll,-301 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{E0CBF06C-CD8B-4647-BB8A-263B43F0F974}] : (Bluetooth) [] -> @%SystemRoot%\system32\bthci.dll,-4001 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}] : (WPD) [] -> @wpd_ci.dll,-101 [HKLM\SYSTEM\CurrentControlSet\Control\Class\{FB58BE68-EA9E-4803-847F-2CE814E7B159}] : (aswSP) [] -> [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}] : (Script Detection) [@elscore.dll,-2] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}] : (Transliteration) [@elscore.dll,-5] -> elstrans.dll (Copyright (c) Microsoft Corporation.) [HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}] : (Language Detection) [@elscore.dll,-1] -> ElsLad.dll (Copyright (c) Microsoft Corporation.) ¤¤¤¤¤¤¤¤¤¤ | Loaded modules (Microsoft Files whitelisted) [// ::] - (0.0.0.0) - ( -) - C:\windows\System32\drivers\wtkblyo.sys [25/10/2010 08:20:10] - (9.6.3.1001) - (Intel Corporation - Intel Rapid Storage Technology driver - x64) - C:\windows\system32\DRIVERS\iaStor.sys [02/10/2012 10:09:23] - (1.1.2.5) - (Advanced Micro Devices - Storage Filter Driver) - C:\windows\system32\drivers\amdxata.sys [25/10/2010 08:36:52] - (1.0.0.0) - (SAMSUNG ELECTRONICS - SAMSUNG Kernel Driver) - C:\windows\system32\Drivers\SABI.sys [15/01/2016 19:04:31] - (8.98.0.0) - (REALiX(tm) - HWiNFO AMD64 Kernel Driver) - C:\windows\SysWOW64\drivers\HWiNFO64A.SYS [15/01/2016 20:18:31] - (9.18.13.4192) - (NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 341.92) - C:\windows\system32\DRIVERS\nvlddmkm.sys [13/12/2011 03:32:22] - (9.2.0.470) - (Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driver) - C:\windows\system32\DRIVERS\athrx.sys [28/09/2009 11:22:00] - (11.22.3.3) - ( -) - C:\windows\system32\DRIVERS\yk62x64.sys [26/10/2010 00:37:58] - (15.0.22.0) - (Synaptics Incorporated - Synaptics Touchpad Driver) - C:\windows\system32\DRIVERS\SynTP.sys [15/01/2016 19:19:19] - (18.1.37.4) - (Synaptics Incorporated - Synaptics SMBus Driver) - C:\windows\system32\DRIVERS\Smb_driver_Intel.sys [15/01/2016 20:16:34] - (1.3.30.1) - (NVIDIA Corporation - NVIDIA HDMI Audio Driver) - C:\windows\system32\drivers\nvhda64v.sys [16/02/2016 11:28:43] - (6.0.1.7673) - (Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver) - C:\windows\system32\drivers\RTKVHD64.sys [09/03/2016 17:56:20] - (5.1.2.247) - (Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver) - C:\windows\System32\ATMFD.DLL [08/12/2014 18:01:31] - (0.1.16.0) - (Malwarebytes - Malwarebytes Anti-Malware) - C:\windows\system32\drivers\mbam.sys [09/09/2010 09:46:08] - (1.3.950.0) - (Devguru Co., Ltd - Device Error Recovery SDK(x64)) - C:\windows\System32\drivers\dgderdrv.sys [08/12/2014 18:02:13] - (0.3.0.4) - (Malwarebytes - Malwarebytes Anti-Malware) - C:\windows\system32\drivers\MBAMSwissArmy.sys [08/12/2014 18:01:31] - (1.0.6.0) - (Malwarebytes Corporation - Malwarebytes Web Access Control) - C:\windows\system32\drivers\mwac.sys ¤¤¤¤¤¤¤¤¤¤ | Services | 0 : Starting up | 1 : System | 2 : Automatic | 3 : Manual | 4 : Disabled | R : Running service | S : Stopped service R0 - ACPI (Pilote ACPI Microsoft) -> system32\drivers\ACPI.sys R0 - amdxata () -> system32\drivers\amdxata.sys R0 - atapi (Canal IDE) -> system32\drivers\atapi.sys R0 - CLFS (@%SystemRoot%\system32\clfs.sys,-100) -> System32\CLFS.sys R0 - CNG () -> System32\Drivers\cng.sys R0 - Compbatt (Microsoft Composite Battery Driver) -> system32\DRIVERS\compbatt.sys R0 - Disk (Pilote de disque) -> system32\DRIVERS\disk.sys R0 - FileInfo (@%SystemRoot%\system32\drivers\fileinfo.sys,-100) -> system32\drivers\fileinfo.sys R0 - FltMgr (@%SystemRoot%\system32\drivers\fltmgr.sys,-10001) -> system32\drivers\fltmgr.sys S0 - Fs_Rec () -> (?) R0 - fvevol (@%SystemRoot%\system32\drivers\fvevol.sys,-100) -> System32\DRIVERS\fvevol.sys R0 - hwpolicy (@%systemroot%\system32\drivers\hwpolicy.sys,-101) -> System32\drivers\hwpolicy.sys R0 - iaStor (Intel AHCI Controller) -> system32\DRIVERS\iaStor.sys R0 - KSecDD () -> System32\Drivers\ksecdd.sys R0 - KSecPkg () -> System32\Drivers\ksecpkg.sys R0 - mountmgr (@%SystemRoot%\system32\drivers\mountmgr.sys,-100) -> System32\drivers\mountmgr.sys R0 - msahci () -> system32\drivers\msahci.sys R0 - msisadrv () -> system32\drivers\msisadrv.sys R0 - Mup (@%systemroot%\system32\drivers\mup.sys,-101) -> System32\Drivers\mup.sys R0 - NDIS (@%SystemRoot%\system32\drivers\ndis.sys,-200) -> system32\drivers\ndis.sys R0 - partmgr (@%SystemRoot%\system32\drivers\partmgr.sys,-100) -> System32\drivers\partmgr.sys R0 - pci (Pilote de bus PCI) -> system32\drivers\pci.sys R0 - pcw (Performance Counters for Windows Driver) -> System32\drivers\pcw.sys S0 - PxHelp20 (PxHelp20) -> system32\Drivers\PxHelp20.sys R0 - rdyboost (ReadyBoost) -> System32\drivers\rdyboost.sys R0 - spldr (Security Processor Loader Driver) -> (?) R0 - Tcpip (@%SystemRoot%\system32\tcpipcfg.dll,-50003) -> System32\drivers\tcpip.sys R0 - vdrvroot (Pilote d’énumérateur de lecteur virtuel Microsoft) -> system32\drivers\vdrvroot.sys R0 - volmgr (Pilote du Gestionnaire de volume) -> system32\drivers\volmgr.sys R0 - volmgrx (@%SystemRoot%\system32\drivers\volmgrx.sys,-100) -> System32\drivers\volmgrx.sys R0 - volsnap (Volumes de stockage) -> system32\drivers\volsnap.sys R0 - Wdf01000 (@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000) -> system32\drivers\Wdf01000.sys R1 - AFD (@%systemroot%\system32\drivers\afd.sys,-1000) -> \SystemRoot\system32\drivers\afd.sys R1 - Beep (Beep) -> (?) R1 - blbdrive () -> system32\DRIVERS\blbdrive.sys R1 - cdrom (Pilote de CD-ROM) -> system32\DRIVERS\cdrom.sys R1 - DfsC (@%systemroot%\system32\drivers\dfsc.sys,-101) -> System32\Drivers\dfsc.sys R1 - discache (@%systemroot%\system32\drivers\discache.sys,-102) -> System32\drivers\discache.sys R1 - HWiNFO32 (HWiNFO32/64 Kernel Driver) -> \??\C:\windows\SysWOW64\drivers\HWiNFO64A.SYS R1 - Msfs () -> (?) R1 - mssmbios (Pilote BIOS de gestion de systèmes Microsoft) -> \SystemRoot\system32\drivers\mssmbios.sys R1 - NetBIOS (NetBIOS Interface) -> system32\DRIVERS\netbios.sys R1 - NetBT (NetBT) -> System32\DRIVERS\netbt.sys R1 - Npfs () -> (?) R1 - nsiproxy (@%SystemRoot%\system32\drivers\nsiproxy.sys,-2) -> system32\drivers\nsiproxy.sys R1 - Null () -> (?) R1 - Psched (@%SystemRoot%\System32\drivers\pacer.sys,-101) -> system32\DRIVERS\pacer.sys R1 - rdbss (@%systemroot%\system32\wkssvc.dll,-1000) -> system32\DRIVERS\rdbss.sys R1 - RDPCDD (@%systemroot%\system32\DRIVERS\RDPCDD.sys,-100) -> System32\DRIVERS\RDPCDD.sys R1 - RDPENCDD (@%systemroot%\system32\drivers\RDPENCDD.sys,-101) -> system32\drivers\rdpencdd.sys R1 - RDPREFMP (@%systemroot%\system32\drivers\RdpRefMp.sys,-101) -> system32\drivers\rdprefmp.sys R1 - SABI (SAMSUNG Kernel Driver For Windows 7) -> \??\C:\windows\system32\Drivers\SABI.sys S1 - StarOpen () -> (?) R1 - tdx (@%SystemRoot%\system32\tcpipcfg.dll,-50004) -> system32\DRIVERS\tdx.sys R1 - TermDD (Pilote de périphérique terminal) -> \SystemRoot\system32\drivers\termdd.sys R1 - VgaSave () -> \SystemRoot\System32\drivers\vga.sys R1 - vwififlt (Virtual WiFi Filter Driver) -> system32\DRIVERS\vwififlt.sys R1 - Wanarpv6 (@%systemroot%\system32\rascfg.dll,-32012) -> system32\DRIVERS\wanarp.sys R1 - WfpLwf (WFP Lightweight Filter) -> system32\DRIVERS\wfplwf.sys R2 - AdobeARMservice (Adobe Acrobat Update Service) -> "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" R2 - AudioEndpointBuilder (@%SystemRoot%\system32\audiosrv.dll,-204) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R2 - AudioSrv (@%SystemRoot%\system32\audiosrv.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted R2 - BFE (@%SystemRoot%\system32\bfe.dll,-1001) -> %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork R2 - BITS (@%SystemRoot%\system32\qmgr.dll,-1000) -> %SystemRoot%\System32\svchost.exe -k netsvcs S2 - clr_optimization_v4.0.30319_32 (Microsoft .NET Framework NGEN v4.0.30319_X86) -> C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe S2 - clr_optimization_v4.0.30319_64 (Microsoft .NET Framework NGEN v4.0.30319_X64) -> C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe R2 - CryptSvc (@%SystemRoot%\system32\cryptsvc.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k NetworkService R2 - DcomLaunch (@oleres.dll,-5012) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch R2 - dgdersvc (Device Error Recovery Service) -> C:\windows\system32\dgdersvc.exe R2 - Dhcp (@%SystemRoot%\system32\dhcpcore.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted R2 - DiagTrack (@%SystemRoot%\system32\UtcResources.dll,-3001) -> %SystemRoot%\System32\svchost.exe -k utcsvc R2 - Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101) -> %SystemRoot%\system32\svchost.exe -k NetworkService R2 - DPS (@%systemroot%\system32\dps.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork R2 - eventlog (@%SystemRoot%\system32\wevtsvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted R2 - EventSystem (@comres.dll,-2450) -> %SystemRoot%\system32\svchost.exe -k LocalService R2 - FontCache (@%systemroot%\system32\FntCache.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService R2 - gpsvc (@gpapi.dll,-112) -> %windir%\system32\svchost.exe -k GPSvcGroup S2 - gupdate (Service Google Update (gupdate)) -> "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc S2 - HPSupportSolutionsFrameworkService (HP Support Solutions Framework Service) -> "C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe" R2 - IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501) -> %systemroot%\system32\svchost.exe -k netsvcs R2 - IPBusEnum (@%systemroot%\system32\IPBusEnum.dll,-102) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted R2 - iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500) -> %SystemRoot%\System32\svchost.exe -k NetSvcs R2 - LanmanServer (@%systemroot%\system32\srvsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs R2 - LanmanWorkstation (@%systemroot%\system32\wkssvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k NetworkService R2 - LeapFrog Connect Device Service (LeapFrog Connect Device Service) -> "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe" S2 - LiveUpdateSvc (LiveUpdate) -> C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe R2 - lltdio (Link-Layer Topology Discovery Mapper I/O Driver) -> system32\DRIVERS\lltdio.sys R2 - lmhosts (@%SystemRoot%\system32\lmhsvc.dll,-101) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted R2 - luafv (@%systemroot%\system32\drivers\luafv.sys,-100) -> \SystemRoot\system32\drivers\luafv.sys R2 - MBAMScheduler () -> "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe" R2 - MBAMService () -> "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe" S2 - MMCSS (@%systemroot%\system32\mmcss.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs R2 - MpsSvc (@%SystemRoot%\system32\FirewallAPI.dll,-23090) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork R2 - NlaSvc (@%SystemRoot%\System32\nlasvc.dll,-1) -> %SystemRoot%\System32\svchost.exe -k NetworkService R2 - nsi (@%SystemRoot%\system32\nsisvc.dll,-200) -> %systemroot%\system32\svchost.exe -k LocalService R2 - nvsvc (NVIDIA Display Driver Service) -> C:\windows\system32\nvvsvc.exe R2 - PcaSvc (@%SystemRoot%\system32\pcasvc.dll,-1) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted R2 - PEAUTH (PEAUTH) -> system32\drivers\peauth.sys R2 - PlugPlay (@%SystemRoot%\system32\umpnpmgr.dll,-100) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch R2 - Power (@%SystemRoot%\system32\umpo.dll,-100) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch R2 - ProfSvc (@%systemroot%\system32\profsvc.dll,-300) -> %systemroot%\system32\svchost.exe -k netsvcs R2 - Rezip (Rezip) -> C:\windows\SysWOW64\Rezip.exe R2 - RichVideo (Cyberlink RichVideo Service(CRVS)) -> "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" R2 - RpcEptMapper (@%windir%\system32\RpcEpMap.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k RPCSS R2 - RpcSs (@oleres.dll,-5010) -> %SystemRoot%\system32\svchost.exe -k rpcss R2 - rspndr (Link-Layer Topology Discovery Responder) -> system32\DRIVERS\rspndr.sys R2 - SamSs (@%SystemRoot%\system32\samsrv.dll,-1) -> %SystemRoot%\system32\lsass.exe R2 - Schedule (@%SystemRoot%\system32\schedsvc.dll,-100) -> %systemroot%\system32\svchost.exe -k netsvcs R2 - SENS (@%SystemRoot%\system32\Sens.dll,-200) -> %SystemRoot%\system32\svchost.exe -k netsvcs R2 - ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288) -> %SystemRoot%\System32\svchost.exe -k netsvcs R2 - Spooler (Spouleur d’impression) -> %SystemRoot%\System32\spoolsv.exe S2 - sppsvc (@%SystemRoot%\system32\sppsvc.exe,-101) -> %SystemRoot%\system32\sppsvc.exe S2 - stisvc (@%SystemRoot%\system32\wiaservc.dll,-9) -> %SystemRoot%\system32\svchost.exe -k imgsvc R2 - SysMain (@%SystemRoot%\system32\sysmain.dll,-1000) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted R2 - tcpipreg (TCP/IP Registry Compatibility) -> System32\drivers\tcpipreg.sys R2 - Themes (@%SystemRoot%\System32\themeservice.dll,-8192) -> %SystemRoot%\System32\svchost.exe -k netsvcs R2 - TrkWks (@%SystemRoot%\system32\trkwks.dll,-1) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R2 - UxSms (@%SystemRoot%\system32\dwm.exe,-2000) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted R2 - WinDefend (@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103) -> %SystemRoot%\System32\svchost.exe -k secsvcs R2 - Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205) -> %systemroot%\system32\svchost.exe -k netsvcs R2 - Wlansvc (@%SystemRoot%\System32\wlansvc.dll,-257) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted R2 - wlidsvc (Windows Live ID Sign-in Assistant) -> "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" R2 - WMPNetworkSvc (@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101) -> "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe" R2 - wscsvc (@%SystemRoot%\System32\wscsvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted R2 - WSearch (@%systemroot%\system32\SearchIndexer.exe,-103) -> %systemroot%\system32\SearchIndexer.exe /Embedding R2 - wuauserv (@%systemroot%\system32\wuaueng.dll,-105) -> %systemroot%\system32\svchost.exe -k netsvcs ¤¤¤¤¤¤¤¤¤¤ | System files (Microsoft Files whitelisted) [MD5.8F22037D3F5A6BB676525D825A1388B9] - [30/07/2015 19:48:22] - (.© Malwarebytes Corporation. - Malwarebytes Anti-Malware.) - [111.21 Ko] - (0.2.22.0) - C:\windows\System32\Drivers\087E2B90.sys [MD5.8F22037D3F5A6BB676525D825A1388B9] - [19/09/2015 17:46:37] - (.© Malwarebytes Corporation. - Malwarebytes Anti-Malware.) - [111.21 Ko] - (0.2.22.0) - C:\windows\System32\Drivers\55FA5F29.sys [MD5.8F22037D3F5A6BB676525D825A1388B9] - [17/09/2015 08:57:08] - (.© Malwarebytes Corporation. - Malwarebytes Anti-Malware.) - [111.21 Ko] - (0.2.22.0) - C:\windows\System32\Drivers\73A02DA5.sys [MD5.2F6B34B83843F0C5118B63AC634F5BF4] - [10/06/2009 22:36:24] - (.Copyright © 2006 Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) - [479.58 Ko] - (1.6.6.4) - C:\windows\System32\Drivers\adp94xx.sys [MD5.597F78224EE9224EA1A13D6350CED962] - [13/07/2009 23:59:32] - (.Copyright © 2006 Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) - [331.58 Ko] - (1.6.6.1) - C:\windows\System32\Drivers\adpahci.sys [MD5.E109549C90F62FB570B9540C4B148E54] - [13/07/2009 23:59:33] - (.Copyright © 2003 Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) - [178.58 Ko] - (7.2.0.0) - C:\windows\System32\Drivers\adpu320.sys [MD5.5812713A477A3AD7363C7438CA2EE038] - [14/07/2009 01:19:47] - (.Copyright (C) Acer Laboratories Inc. 2000 - ALi mini IDE Driver.) - [15.08 Ko] - (1.2.0.0) - C:\windows\System32\Drivers\aliide.sys [MD5.1FF8B4431C353CE385C875F194924C0C] - [14/07/2009 01:19:49] - (.Copyright (C) AMD 2003 - Pilote IDE AMD.) - [15.08 Ko] - (6.1.7600.16385) - C:\windows\System32\Drivers\amdide.sys [MD5.D4121AE6D0C0E7E13AA221AA57EF2D49] - [02/10/2012 10:09:24] - (.Copyright © 2008-2010 AMD, Inc. - AHCI 1.2 Device Driver.) - [105.38 Ko] - (1.1.2.5) - C:\windows\System32\Drivers\amdsata.sys [MD5.F67F933E79241ED32FF46A4F29B5120B] - [10/06/2009 22:37:35] - (.2008 Advanced Micro Devices, Inc. - AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform.) - [189.58 Ko] - (3.6.1540.127) - C:\windows\System32\Drivers\amdsbs.sys [MD5.540DAF1CEA6094886D72126FD7C33048] - [02/10/2012 10:09:23] - (.Copyright © 2008-2010 AMD, Inc. - Storage Filter Driver.) - [26.38 Ko] - (1.1.2.5) - C:\windows\System32\Drivers\amdxata.sys [MD5.C484F8CEB1717C540242531DB7845C4E] - [13/07/2009 23:59:33] - (.Copyright 2007 Adaptec, Inc. - Adaptec RAID Storport Driver.) - [85.58 Ko] - (5.2.0.10384) - C:\windows\System32\Drivers\arc.sys [MD5.019AF6924AEFE7839F61C830227FE79C] - [13/07/2009 23:59:33] - (.Copyright 2008 Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) - [95.56 Ko] - (5.2.0.16119) - C:\windows\System32\Drivers\arcsas.sys [MD5.3D68A1EEF77307142636AF5127990BCB] - [13/12/2011 03:32:22] - (.Copyright (C) 2001-2010 Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driver.) - [2731.5 Ko] - (9.2.0.470) - C:\windows\System32\Drivers\athrx.sys [MD5.B5ACE6968304A3900EEB1EBFD9622DF2] - [10/06/2009 22:34:23] - (.Copyright 2000-2008, Broadcom Corporation. - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) - [264.5 Ko] - (10.100.4.0) - C:\windows\System32\Drivers\b57nd60a.sys [MD5.F09EEE9EDC320B5E1501F749FDE686C8] - [14/07/2009 03:19:59] - (.Copyright (C) Brother Industries, Ltd. 2001-2003 - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) - [18 Ko] - (1.10.0.2) - C:\windows\System32\Drivers\BrFiltLo.sys [MD5.B114D3098E9BDB8BEA8B053685831BE6] - [14/07/2009 03:20:21] - (.Copyright (C) Brother Industries, Ltd. 2001 - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) - [8.5 Ko] - (1.4.0.1) - C:\windows\System32\Drivers\BrFiltUp.sys [MD5.43BEA8D483BF1870F018E2D02E06A5BD] - [14/07/2009 03:19:06] - (.Copyright (C) Brother Industries Ltd.1997-2006 - Pilote Brother Série I/F (WDM).) - [280 Ko] - (1.0.1.6) - C:\windows\System32\Drivers\BrSerId.sys [MD5.A6ECA2151B08A09CACECA35C07F05B42] - [14/07/2009 03:20:11] - (.Copyright (C) Brother Industries Ltd.1997-2003 - Brother Serial driver (WDM version).) - [46 Ko] - (1.0.0.20) - C:\windows\System32\Drivers\BrSerWdm.sys [MD5.B79968002C277E869CF38BD22CD61524] - [14/07/2009 03:20:26] - (.Copyright(C)Brother Industries Ltd.1997-2006 - Brother USB MDM Driver.) - [14.63 Ko] - (1.0.0.12) - C:\windows\System32\Drivers\BrUsbMdm.sys [MD5.A87528880231C54E75EA7A44943B38BF] - [14/07/2009 03:20:15] - (.Copyright(C)Brother Industries Ltd.1997-2006 - Brother USB Serial Driver.) - [14.38 Ko] - (1.0.1.3) - C:\windows\System32\Drivers\BrUsbSer.sys [MD5.3E5B191307609F7514148C6832BB0842] - [10/06/2009 22:34:28] - (.(c) COPYRIGHT 2001-2008 Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) - [457.5 Ko] - (4.8.2.0) - C:\windows\System32\Drivers\bxvbda.sys [MD5.E19D3F095812725D88F9001985B94EDD] - [14/07/2009 01:19:48] - (.Copyright (C) CMD Technology, Inc. 1999-2000 - CMD PCI IDE Bus Driver.) - [17.08 Ko] - (2.0.7.0) - C:\windows\System32\Drivers\cmdide.sys [MD5.DEF365F0F6E017888C4B869D3BA4B8E0] - [09/09/2010 09:46:08] - (.Devguru Co., Ltd. - Device Error Recovery SDK(x64).) - [20.07 Ko] - (1.3.950.0) - C:\windows\System32\Drivers\dgderdrv.sys [MD5.0E5DA5369A0FCAEA12456DD852545184] - [10/06/2009 22:36:49] - (.Copyright © 2003-2009 Emulex - Storport Miniport Driver for LightPulse HBAs.) - [518.06 Ko] - (7.2.10.211) - C:\windows\System32\Drivers\elxstor.sys [MD5.DC5D737F51BE844D8C82C695EB17372F] - [10/06/2009 22:34:33] - (.(c) COPYRIGHT 2001-2008 Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) - [3209 Ko] - (4.8.13.0) - C:\windows\System32\Drivers\evbda.sys [MD5.F2523EF6460FC42405B12248338AB2F0] - [14/07/2009 00:53:43] - (.Copyright ©2007-2009 Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) - [30.5 Ko] - (1.31.27127.0) - C:\windows\System32\Drivers\hcw85cir.sys [MD5.39D2ABCD392F3D8A6DCE7B60AE7B8EFC] - [02/10/2012 22:06:09] - (.Copyright (c) 2004-2010 Hewlett-Packard Development Company, L.P. - Smart Array SAS/SATA Controller Media Driver.) - [76.88 Ko] - (6.12.6.64) - C:\windows\System32\Drivers\HpSAMD.sys [MD5.A5F72BB0D024E7E463344105BE613AE4] - [25/10/2010 08:20:10] - (.Copyright(C) Intel Corporation 1994-2010 - Intel Rapid Storage Technology driver - x64.) - [528.02 Ko] - (9.6.3.1001) - C:\windows\System32\Drivers\iaStor.sys [MD5.AAAF44DB3BD0B9D1FB6969B23ECC8366] - [02/10/2012 10:09:23] - (.Copyright(C) Intel Corporation 1994-2008 - Intel Matrix Storage Manager driver - x64.) - [400.88 Ko] - (8.6.2.1014) - C:\windows\System32\Drivers\iaStorV.sys [MD5.A87261EF1546325B559374F5689CF5BC] - [10/06/2009 22:37:05] - (.Copyright (c) 1998-2006 Intel Corporation. - Intel Graphics Kernel Mode Driver.) - [5965.25 Ko] - (8.15.10.1749) - C:\windows\System32\Drivers\igdkmd64.sys [MD5.5C18831C61933628F5BB0EA2675B9D21] - [13/07/2009 23:59:33] - (.Copyright © 2002-05 Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) - [43.08 Ko] - (5.4.22.0) - C:\windows\System32\Drivers\iirsp.sys [MD5.DD587A55390ED2295BCE6D36AD567DA9] - [26/10/2010 00:37:28] - (.Copyright(C) 2008 Intel Corporation - Intel(R) Turbo Boost Technology Driver.) - [155.25 Ko] - (1.2.0.1002) - C:\windows\System32\Drivers\Impcd.sys [MD5.1A93E54EB0ECE102495A51266DCDB6A6] - [13/07/2009 23:59:34] - (.Copyright © LSI Corporation 2008 - LSI Fusion-MPT FC Driver (StorPort).) - [112.06 Ko] - (1.28.3.52) - C:\windows\System32\Drivers\lsi_fc.sys [MD5.1047184A9FDC8BDBFF857175875EE810] - [13/07/2009 23:59:33] - (.Copyright © LSI Corporation 2008 - LSI Fusion-MPT SAS Driver (StorPort).) - [104.06 Ko] - (1.28.3.52) - C:\windows\System32\Drivers\lsi_sas.sys [MD5.30F5C0DE1EE8B5BC9306C1F0E4A75F93] - [13/07/2009 23:59:34] - (.Copyright © LSI Corporation 2009 - LSI SAS Gen2 Driver (StorPort).) - [64.06 Ko] - (2.0.2.71) - C:\windows\System32\Drivers\lsi_sas2.sys [MD5.0504EACAFF0D3C8AED161C4B0D369D4A] - [13/07/2009 23:59:33] - (.Copyright © LSI Corporation 2008 - LSI Fusion-MPT SCSI Driver (StorPort).) - [113.06 Ko] - (1.28.3.67) - C:\windows\System32\Drivers\lsi_scsi.sys [MD5.78BFF5425E044086E74E78650A359FBB] - [08/12/2014 18:01:31] - (.© Malwarebytes. - Malwarebytes Anti-Malware.) - [26.38 Ko] - (0.1.16.0) - C:\windows\System32\Drivers\mbam.sys [MD5.1239597BAB7EED2BB16D035AF87E65D9] - [08/12/2014 18:01:31] - (.© Malwarebytes. - Malwarebytes Chameleon Protection Driver.) - [137.38 Ko] - (1.1.22.0) - C:\windows\System32\Drivers\mbamchameleon.sys [MD5.78488AF2AB2111D67B3C4044707A519B] - [08/12/2014 18:02:13] - (.© Malwarebytes. - Malwarebytes Anti-Malware.) - [187.71 Ko] - (0.3.0.4) - C:\windows\System32\Drivers\MBAMSwissArmy.sys [MD5.A55805F747C6EDB6A9080D7C633BD0F4] - [10/06/2009 22:37:14] - (.Copyright © LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for x64.) - [34.56 Ko] - (4.5.1.64) - C:\windows\System32\Drivers\megasas.sys [MD5.BAF74CE0072480C3B6B7C13B2A94D6B3] - [13/07/2009 23:59:33] - (.Copyright (C) 2007 LSI Corporation. - LSI MegaRAID Software RAID Driver.) - [278.06 Ko] - (13.5.409.2009) - C:\windows\System32\Drivers\MegaSR.sys [MD5.452ACB7A9914398D9E18CCCFFCF92208] - [08/12/2014 18:01:31] - (.© Malwarebytes Corporation. - Malwarebytes Web Access Control.) - [63.38 Ko] - (1.0.6.0) - C:\windows\System32\Drivers\mwac.sys [MD5.77889813BE4D166CDAB78DDBA990DA92] - [13/07/2009 23:59:33] - (.(C) Copyright IBM Corp. 1994, 2002. - IBM ServeRAID Controller Driver.) - [50.06 Ko] - (7.10.0.0) - C:\windows\System32\Drivers\nfrd960.sys [MD5.E366A5681C50785D4ED04FCFD65C3415] - [15/01/2016 20:16:34] - (.(C) NVIDIA Corporation. - NVIDIA HDMI Audio Driver.) - [192.78 Ko] - (1.3.30.1) - C:\windows\System32\Drivers\nvhda64v.sys [MD5.AB443152695F1B606EFD3E3728D5F362] - [15/01/2016 20:18:31] - (.(C) 2015 NVIDIA Corporation. - NVIDIA Windows Kernel Mode Driver, Version 341.92.) - [12596.67 Ko] - (9.18.13.4192) - C:\windows\System32\Drivers\nvlddmkm.sys [MD5.0A92CB65770442ED0DC44834632F66AD] - [02/10/2012 10:09:24] - (.Copyright(C) 2001-2010 NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) - [144.88 Ko] - (10.6.0.18) - C:\windows\System32\Drivers\nvraid.sys [MD5.DAB0E87525C10052BF65F06152F37E4A] - [02/10/2012 10:09:24] - (.Copyright(C) 2001-2010 NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) - [162.38 Ko] - (10.6.0.18) - C:\windows\System32\Drivers\nvstor.sys [MD5.A53A15A11EBFD21077463EE2C7AFEEF0] - [10/06/2009 22:37:36] - (.Copyright © QLogic Corporation 1996-2009 - QLogic Fibre Channel Stor Miniport Driver.) - [1489.08 Ko] - (9.1.8.6) - C:\windows\System32\Drivers\ql2300.sys [MD5.4F6D12B51DE1AAEFF7DC58C4D75423C8] - [13/07/2009 23:59:34] - (.© QLogic Corporation. - QLogic iSCSI Storport Miniport Driver.) - [125.58 Ko] - (2.1.3.20) - C:\windows\System32\Drivers\ql40xx.sys [MD5.BAEFEE35D27A5440D35092CE10267BEC] - [10/06/2009 22:35:42] - (.Copyright (C) 2008 Realtek Corporation. This product is covered by one or more of the following patents:US5,307,459, US5,434,872, US5,732,094, US6,570,884, US6,115,776, and US6,327,625. - Realtek 8101E/8168/8169 NDIS 6.20 64-bit Driver .) - [183 Ko] - (7.2.1125.2008) - C:\windows\System32\Drivers\Rt64win7.sys [MD5.93E07E34AC803B37CD196662FDBA38F8] - [16/02/2016 11:28:43] - (.Copyright (c) Realtek Semiconductor Corp.1998-2013 - Realtek(r) High Definition Audio Function Driver.) - [4576.75 Ko] - (6.0.1.7673) - C:\windows\System32\Drivers\RTKVHD64.sys [MD5.2362226743449C713E1CD3210595F9AB] - [25/10/2010 08:27:26] - (.Copyright (C) 2006 Realtek Semiconductor Corporation - Realtek RTL819xP NDIS Driverr.) - [608.03 Ko] - (2000.4.201.2010) - C:\windows\System32\Drivers\rtl819xp.sys [MD5.62DB6CC4B0818F1B5F3441241B098F12] - [25/10/2010 08:36:52] - (.Copyright (C) 2009 SAMSUNG ELECTRONICS - SAMSUNG Kernel Driver.) - [13.5 Ko] - (1.0.0.0) - C:\windows\System32\Drivers\SABI.sys [MD5.3EA8A16169C26AFBEB544E0E48421186] - [14/07/2009 04:36:07] - (.© 2006 Macrovision Corporation - Macrovision SECURITY Driver.) - [22.5 Ko] - (4.3.86.0) - C:\windows\System32\Drivers\secdrv.sys [MD5.843CAF1E5FDE1FFD5FF768F23A51E2E1] - [10/06/2009 22:37:40] - (.Copyright (c) SiS Corp. 2000-2010 - SiS RAID Stor Miniport Driver.) - [42.56 Ko] - (5.1.1039.2600) - C:\windows\System32\Drivers\sisraid2.sys [MD5.6A6C106D42E9FFFF8B9FCB4F754F6DA4] - [13/07/2009 23:59:33] - (.Copyright (c) SiS Corp. 2007-2013 - SiS AHCI Stor-Miniport Driver.) - [78.58 Ko] - (5.1.1039.3600) - C:\windows\System32\Drivers\sisraid4.sys [MD5.C10B629AD8BD36BF8D376243D509AECA] - [15/01/2016 19:19:19] - (.Copyright (C) Synaptics Incorporated 1996-2015 - Synaptics SMBus Driver.) - [32.16 Ko] - (18.1.37.4) - C:\windows\System32\Drivers\Smb_driver_Intel.sys [MD5.73BDD44A6088916964945886F9025409] - [22/01/2014 09:52:10] - (.Copyright (c) DEVGURU 2002-2008.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ver.3).) - [106.25 Ko] - (2.11.7.0) - C:\windows\System32\Drivers\ssudbus.sys [MD5.5252D7BC56E5E0ED715AEA8FE173A455] - [22/01/2014 09:52:10] - (.Copyright (c) DEVGURU 2002-2008. (www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ver.3).) - [201.25 Ko] - (2.11.7.0) - C:\windows\System32\Drivers\ssudmdm.sys [MD5.EF806D212D34B0E173BAEB3564D53E37] - [17/05/2011 18:35:53] - (.Copyright (c) 1997-2009 MCCI - SAMSUNG USB Mobile Device.) - [124.5 Ko] - (5.0.0.0) - C:\windows\System32\Drivers\ss_bbus.sys [MD5.946684DEF391FA17A830091EA84E74FE] - [17/05/2011 18:35:53] - (.Copyright (c) 1997-2009 MCCI Corporation - Windows 2000/XP support functions.) - [15 Ko] - (5.0.0.0) - C:\windows\System32\Drivers\ss_bcm.sys [MD5.946684DEF391FA17A830091EA84E74FE] - [17/05/2011 18:35:53] - (.Copyright (c) 1997-2009 MCCI Corporation - Windows 2000/XP support functions.) - [15 Ko] - (5.0.0.0) - C:\windows\System32\Drivers\ss_bcmnt.sys [MD5.08B1B34ABEBEB6AC2DEA06900C56411E] - [17/05/2011 18:35:53] - (.Copyright (c) 1997-2009 MCCI Corporation - SAMSUNG USB Mobile Modem Filter.) - [18.5 Ko] - (5.0.0.0) - C:\windows\System32\Drivers\ss_bmdfl.sys [MD5.71A9DA6BEAA4CB54DFB827FB78600A5D] - [17/05/2011 18:35:53] - (.Copyright (c) 1997-2009 MCCI Corporation - SAMSUNG USB Mobile Modem.) - [157.5 Ko] - (5.0.0.0) - C:\windows\System32\Drivers\ss_bmdm.sys [MD5.677CDC98F8363ACCAAE783FDE1599C2A] - [17/05/2011 18:35:53] - (.Copyright (c) 1997-2009 MCCI Corporation - SAMSUNG USB Mobile Logging Device Driver.) - [125 Ko] - (5.0.0.0) - C:\windows\System32\Drivers\ss_bserd.sys [MD5.CC98D196AFAD3580E454DDED14BDAC7A] - [17/05/2011 18:35:54] - (.Copyright (c) 1997-2009 MCCI Corporation - SAMSUNG USB Mobile Device (Windows 2000/XP support functions).) - [15.5 Ko] - (5.0.0.0) - C:\windows\System32\Drivers\ss_bwh.sys [MD5.CC98D196AFAD3580E454DDED14BDAC7A] - [17/05/2011 18:35:54] - (.Copyright (c) 1997-2009 MCCI Corporation - SAMSUNG USB Mobile Device (Windows 2000/XP support functions).) - [15.5 Ko] - (5.0.0.0) - C:\windows\System32\Drivers\ss_bwhnt.sys [MD5.F3817967ED533D08327DC73BC4D5542A] - [13/07/2009 23:59:33] - (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) - [24.08 Ko] - (5.0.1.1) - C:\windows\System32\Drivers\stexstor.sys [MD5.04CF20310145DEC63D5387BEAFF77D9A] - [19/02/2016 19:22:40] - (.-.) - [13.59 Ko] - (0.0.0.0) - C:\windows\System32\Drivers\SWDUMon.sys [MD5.14FEB5052837D9277520088DCE549036] - [26/10/2010 00:37:58] - (.Copyright (C) Synaptics Incorporated 1996-2010 - Synaptics Touchpad Driver.) - [1345.55 Ko] - (15.0.22.0) - C:\windows\System32\Drivers\SynTP.sys [MD5.CE4B6956E4E12492715A53076E58761F] - [17/05/2011 18:34:51] - (.Teruten Inc - File System Mini Filter Drvier.) - [16.01 Ko] - (1.0.0.1) - C:\windows\System32\Drivers\TFsExDisk.sys [MD5.E5689D93FFE4E5D66C0178761240DD54] - [14/07/2009 01:19:50] - (.Copyright (C) VIA Technologies, Inc. 2000-2007 - VIA Generic PCI IDE Bus Driver.) - [17.08 Ko] - (6.0.6000.170) - C:\windows\System32\Drivers\viaide.sys [MD5.5E2016EA6EBACA03C04FEAC5F330D997] - [10/06/2009 22:37:58] - (.Copyright (C) VIA Technologies 1992-2007 - VIA RAID DRIVER FOR AMD-X86-64.) - [158.08 Ko] - (6.0.6000.6210) - C:\windows\System32\Drivers\vsmraid.sys [MD5.64F88AF327AA74E03658AE32B48CCB8B] - [28/09/2009 11:22:00] - (.©Copyright 2002-2009 Marvell®. -.) - [386 Ko] - (11.22.3.3) - C:\windows\System32\Drivers\yk62x64.sys [MD5.BF79E659C506674C0497CC9C61F1A165] - [28/07/2011 10:07:59] - (.Copyright (c) 1994-2005 Sonic Solutions - CDR4 CD and DVD Place Holder Driver (see PxHelp).) - [2.38 Ko] - (8.0.0.212) - C:\windows\Syswow64\Drivers\cdr4_2k.sys [MD5.BF79E659C506674C0497CC9C61F1A165] - [28/07/2011 10:07:59] - (.Copyright (c) 1994-2005 Sonic Solutions - CDR4 CD and DVD Place Holder Driver (see PxHelp).) - [2.38 Ko] - (8.0.0.212) - C:\windows\Syswow64\Drivers\cdr4_xp.sys [MD5.2C41CD49D82D5FD85C72D57B6CA25471] - [28/07/2011 10:07:59] - (.Copyright (c) 1994-2005 Sonic Solutions - CDRAL Place Holder Driver (see PxHelp).) - [2.5 Ko] - (8.0.0.212) - C:\windows\Syswow64\Drivers\cdralw2k.sys [MD5.3BE1651C63954067940E7F473498AD70] - [09/09/2010 09:44:50] - (.Devguru Co., Ltd. - Device Error Recovery SDK(x86).) - [17.7 Ko] - (1.3.950.0) - C:\windows\Syswow64\Drivers\dgderdrv.sys [MD5.E5805896A55D4166C20F216249F40FA3] - [15/01/2016 19:04:31] - (.Copyright (c)1999-2014 Martin Malík - REALiX - HWiNFO AMD64 Kernel Driver.) - [25.91 Ko] - (8.98.0.0) - C:\windows\Syswow64\Drivers\HWiNFO64A.SYS [MD5.1962166E0CEB740704F30FA55AD3D509] - [28/07/2011 10:07:59] - (.Copyright © Sonic Solutions - Px Engine Device Driver for Windows 2000/XP.) - [35.77 Ko] - (3.0.43.9) - C:\windows\Syswow64\Drivers\pxhelp20.sys [MD5.E78CD3BB53A208DFAB8FC826384307E0] - [28/07/2011 10:08:20] - (.Copyright (C) Sony Corporation 2001 - sonyhcb.sys.) - [5.95 Ko] - (1.0.0.53) - C:\windows\Syswow64\Drivers\sonyhcb.sys [MD5.55E48017295F26BA266F935DA49C59A4] - [28/07/2011 10:08:20] - (.Copyright (C) Sony Corporation 2001 - sonyhcc.sys.) - [37.83 Ko] - (1.0.0.53) - C:\windows\Syswow64\Drivers\sonyhcc.sys [MD5.610F515FCD95D37F3252E1C250EF8C61] - [28/07/2011 10:08:22] - (.Copyright (C) Sony Corporation 2001 - sonyhcs.sys.) - [292.89 Ko] - (1.0.0.53) - C:\windows\Syswow64\Drivers\sonyhcs.sys [MD5.DFADFC2C86662F40759BF02ADD27D569] - [28/07/2011 10:08:20] - (.Copyright 2002 Sony Corp. - Sony Digital Imaging.) - [99.82 Ko] - (1.1.1.14) - C:\windows\Syswow64\Drivers\sonypvs1.sys [MD5.306521935042FC0A6988D528643619B3] - [05/05/2011 14:50:31] - (.-.) - [5.5 Ko] - (0.0.0.0) - C:\windows\Syswow64\Drivers\StarOpen.sys [MD5.CE4B6956E4E12492715A53076E58761F] - [17/05/2011 18:34:51] - (.Teruten Inc - File System Mini Filter Drvier.) - [16.01 Ko] - (1.0.0.1) - C:\windows\Syswow64\Drivers\TFsExDisk.Sys ¤¤¤¤¤¤¤¤¤¤ | Uninstall [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\58ac1b367c70ef79107456ffbc31d966] : (.-.) -> [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Chromium] : (Chromium.-.Chromium) -> "C:\Users\magali\AppData\Local\{4C037A5F-68AB-16E7-0533-330F215BCF97}\uninstall.exe" /Uninstall /s /noun [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\HP Photo Creations] : (HP Photo Creations.-.HP) -> "C:\Users\magali\AppData\Roaming\HP Photo Creations\remove.exe" [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MyFreeCodec] : (MyFreeCodec.-.) -> C:\Program Files (x86)\MyFree Codec\1.0b beta\uninstall.exe [HKU\S-1-5-21-1125036280-3562319748-3601731155-1000\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Spotify] : (Spotify.-.Spotify AB) -> "C:\Users\magali\AppData\Roaming\Spotify\Spotify.exe" /uninstall [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\3D970B9F930E7AAE23C06D39A1AC98548C90B442] : (Package de pilotes Windows - Eastman Kodak KODAK Digital Camera (01/29/2010 1.4.1.0).-.Eastman Kodak) -> C:\PROGRA~1\DIFX\9C0EB5A087EF219F\Dpinst.exe /u C:\windows\System32\DriverStore\FileRepository\ggcam.inf_amd64_neutral_e474c8acc61493df\ggcam.inf [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D] : (Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012).-.Leapfrog) -> C:\PROGRA~1\DIFX\B60D1297D6D5E54C\DPInst64.exe /u C:\windows\System32\DriverStore\FileRepository\leapfrog-02-03-05-012-1373324.inf_amd64_neutral_8d32ba055a076abd\leapfrog-02-03-05-012-1373324.inf [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DriverEasy_is1] : (DriverEasy 4.9.5.-.Easeware) -> "C:\Program Files\Easeware\DriverEasy\unins000.exe" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\McAfee Security Scan] : (McAfee Security Scan Plus.-.McAfee, Inc.) -> "C:\Program Files\McAfee Security Scan\uninstall.exe" [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\NVIDIA Drivers] : (NVIDIA Drivers.-.NVIDIA Corporation) -> C:\windows\system32\nvuninst.exe UninstallGUI [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\ProInst] : (Intel PROSet Wireless.-.) -> Intel PROSet Wireless [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SAMSUNG Mobile Composite Device] : (SAMSUNG Mobile Composite Device Software.-.) -> C:\windows\SysWOW64\Samsung_USB_Drivers\6\SSBCUninstall.exe [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Samsung Mobile phone USB driver Drive] : (Samsung Mobile phone USB driver Drive Software.-.) -> C:\windows\SysWOW64\Samsung_USB_Drivers\5\SSSDUninstall.exe [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SynTPDeinstKey] : (Synaptics Pointing Device Driver.-.Synaptics Incorporated) -> rundll32.exe "%ProgramFiles%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series] : (Canon MP490 series MP Drivers.-.) -> "C:\windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series\DelDrv64.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}] : (Visual Studio 2012 x64 Redistributables.-.AVG Technologies) -> MsiExec.exe /I{8C775E70-A791-4DA8-BCC3-6AB7136F4484} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{9A9B64A8-A9E8-4588-B924-D1898D3E6355}] : (Logiciel de base du périphérique HP ENVY 4500 series.-.Hewlett-Packard Co.) -> MsiExec.exe /I{9A9B64A8-A9E8-4588-B924-D1898D3E6355} [{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer] : (NVIDIA Install Application.-.NVIDIA Corporation) -> [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{CBCCA175-DA19-424B-9D9F-5343140C884F}] : (Étude pour l'amélioration du produit HP ENVY 4500 series.-.Hewlett-Packard Co.) -> MsiExec.exe /I{CBCCA175-DA19-424B-9D9F-5343140C884F} [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}] : (SAMSUNG USB Driver for Mobile Phones.-.SAMSUNG Electronics Co., Ltd.) -> C:\Program Files (x86)\Samsung\USB Drivers\Uninstall.exe [HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{D16A2127-B927-4379-B153-3DEC091E4EEB}] : (Intel(R) PROSet/Wireless WiFi Software.-.Intel Corporation) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\11598763487076930564] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\4b5293c8d65b750b] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\79b5a6f5c97029b5] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX] : (Adobe Flash Player 21 ActiveX.-.Adobe Systems Incorporated) -> C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_213_ActiveX.exe -maintain activex [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI] : (Adobe Flash Player 21 NPAPI.-.Adobe Systems Incorporated) -> C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_213_Plugin.exe -maintain plugin [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Conduit Engine] : (.-.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DomaIQ Uninstaller] : (DomaIQ.-.Tuguu SLU) -> "C:\Program Files\DomaIQ Uninstaller\DomaIQUninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\FormatFactory] : (FormatFactory 3.0.1.-.Free Time) -> C:\Program Files (x86)\FreeTime\FormatFactory\uninst.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Google Chrome] : (Google Chrome.-.Google Inc.) -> "C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\Installer\setup.exe" --uninstall --multi-install --chrome --system-level [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield Uninstall Information] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}] : (CyberLink YouCam.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}] : (CyberLink DVD Suite.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}] : (CyberLink PowerDVD 8.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}] : (CyberLink Power2Go.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}] : (CyberLink PowerProducer.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}] : (CyberLink LabelPrint.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}] : (CyberLink PowerDirector.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}] : (Kies.-.Nom de votre société) -> "C:\Program Files (x86)\InstallShield Installation Information\{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}\setup.exe" -runfromtemp -l0x040c -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\LeapPadExplorerPlugin] : (Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapPad Explorer Plugin).-.LeapFrog) -> MsiExec.exe /X{7036DB59-1B09-411F-8588-2A16838371DA} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Malwarebytes Anti-Malware_is1] : (Malwarebytes Anti-Malware version 2.2.1.1043.-.Malwarebytes) -> "C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Marvell Miniport Driver] : (Marvell Miniport Driver.-.Marvell) -> C:\Program Files (x86)\Marvell\Miniport Driver\Uninst.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\McAfee Security Scan] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Messenger Plus!] : (Messenger Plus! 5.-.Yuna Software) -> "C:\Program Files (x86)\Yuna Software\Messenger Plus!\Uninstall.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MyFreeCodec] : (MyFreeCodec.-.) -> C:\Program Files (x86)\MyFree Codec\1.0b beta\uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Phylogène collège_is1] : (Phylogene V2.7.6.1.-.) -> "C:\INRP\Phylogene\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SearchTheWebARP] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\UPCShell] : (LeapFrog Connect (French).-.LeapFrog) -> C:\Program Files (x86)\LeapFrog\LeapFrog Connect\uninst.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\VLC media player] : (VLC media player 2.1.3.-.VideoLAN) -> C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\YahooProvidedSearch] : (Search Provided by Yahoo.-.) -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{01FB4998-33C4-4431-85ED-079E3EEFE75D}] : (CyberLink YouCam.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{0F796312-289C-40CA-856C-9FBCF5E83342}] : (REALTEK Wireless LAN Software.-.REALTEK Semiconductor Corp.) -> C:\Program Files (x86)\InstallShield Installation Information\{0F796312-289C-40CA-856C-9FBCF5E83342}\Install.exe -uninst -l0x9 [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}] : (Samsung Recovery Solution 4.-.Samsung) -> "C:\Program Files (x86)\InstallShield Installation Information\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}\setup.exe" -runfromtemp -l0x0009 -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{17283B95-21A8-4996-97DA-547A48DB266F}] : (Easy Display Manager.-.Samsung Electronics Co., Ltd.) -> "C:\Program Files (x86)\InstallShield Installation Information\{17283B95-21A8-4996-97DA-547A48DB266F}\setup.exe" -runfromtemp -l0x0009 -removeonly [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}] : (Google Toolbar for Internet Explorer.-.Google Inc.) -> MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{19F1A99A-196F-4D18-BC36-C1DAD6ABCCF3}] : (Application du bouton Share KODAK.-.Eastman Kodak Company) -> MsiExec.exe /I{19F1A99A-196F-4D18-BC36-C1DAD6ABCCF3} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1C52B8B6-FFA2-12F6-0A5A-E8301F96A568}] : (downloaditkeep.-."") -> [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}] : (CyberLink DVD Suite.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}] : (Google Toolbar for Internet Explorer.-.Google Inc.) -> "C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_A6282D74FF5C38C8.exe" /uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{23B82977-C816-92D2-66E7-BE67DD1E7786}] : (tperfectcoupon.-."") -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{28B97CAB-828F-49D8-A30A-675476F9BA92}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{28B97CAB-828F-49D8-A30A-675476F9BA92}\setup.exe" -l0x40c /cont -removeonly [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}] : (CyberLink PowerDVD 8.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}] : (Intel(R) Rapid Storage Technology.-.Intel Corporation) -> C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\Uninstall\setup.exe -uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3EED7541-55F8-4DC6-B9CD-28762D71310E}] : (Samsung R-Series.-.Samsung) -> MsiExec.exe /X{3EED7541-55F8-4DC6-B9CD-28762D71310E} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{40BF1E83-20EB-11D8-97C5-0009C5020658}] : (CyberLink Power2Go.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}] : (HP FWUpdateEDO2.-.Hewlett-Packard) -> MsiExec.exe /I{415FA9AD-DA10-4ABE-97B6-5051D4795C90} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4A331D24-A9E8-484F-835E-1BA7B139689C}] : (EasyBatteryManager.-.Samsung) -> "C:\Program Files (x86)\InstallShield Installation Information\{4A331D24-A9E8-484F-835E-1BA7B139689C}\setup.exe" -runfromtemp -l0x0009 -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4E7DC12A-3597-4A94-9429-F6C6987361B1}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{4E7DC12A-3597-4A94-9429-F6C6987361B1}\setup.exe" -l0x40c -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{532970A2-464B-73CB-BBC4-F209EAD3EEBE}] : (easytoshop.-."") -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5B4383F2-37EE-4E97-AD81-F5FF76F286DA}] : (OutlookAddInNet3Setup.-.Samsung) -> MsiExec.exe /I{5B4383F2-37EE-4E97-AD81-F5FF76F286DA} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}] : (Sony USB Driver.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}\setup.exe" -l0x40c UNINSTALL -removeonly [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}] : (Google Update Helper.-.Google Inc.) -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6813C983-427E-4511-8456-E98FCAA1A125}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{6813C983-427E-4511-8456-E98FCAA1A125}\setup.exe" -l0x40c -removeonly [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7036DB59-1B09-411F-8588-2A16838371DA}] : (LeapFrog LeapPad Explorer Plugin.-.LeapFrog) -> MsiExec.exe /I{7036DB59-1B09-411F-8588-2A16838371DA} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7204BDEE-1A48-4D95-A964-44A9250B439E}] : (Facebook Messenger 2.1.4814.0.-.Facebook) -> MsiExec.exe /X{7204BDEE-1A48-4D95-A964-44A9250B439E} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{730C1F02-ABB6-7601-60ED-659A59700742}] : (realdeal.-.realdeal) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{74A579FB-EB06-497D-B194-01590D6FE51A}] : (BatteryLifeExtender.-.Samsung) -> MsiExec.exe /I{74A579FB-EB06-497D-B194-01590D6FE51A} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7DADB304-AF20-48C3-A780-4B4133A08817}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{7DADB304-AF20-48C3-A780-4B4133A08817}\setup.exe" -l0x40c -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1] : (CDBurnerXP.-.CDBurnerXP) -> "C:\Program Files (x86)\CDBurnerXP\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7E7FAE3D-3358-D280-8DBF-E8E2D94326D1}] : (shopnnddraop.-.sshoppndrop) -> [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{800F7DAC-E4DE-4B60-9FC6-02A101E79333}] : (Mailorama pour internet explorer.-.Rentabiliweb) -> MsiExec.exe /I{800F7DAC-E4DE-4B60-9FC6-02A101E79333} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110109903}] : (Flip Words.-.Oberon Media) -> "C:\Program Files (x86)\Game Pack\Flip Words\Uninstall.exe" "C:\Program Files (x86)\Game Pack\Flip Words\install.log" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110245793}] : (Insaniquarium Deluxe.-.Oberon Media) -> "C:\Program Files (x86)\Game Pack\Insaniquarium Deluxe\Uninstall.exe" "C:\Program Files (x86)\Game Pack\Insaniquarium Deluxe\install.log" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110521483}] : (Gem Shop.-.Oberon Media) -> "C:\Program Files (x86)\Game Pack\Gem Shop\Uninstall.exe" "C:\Program Files (x86)\Game Pack\Gem Shop\install.log" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}] : (Mahjong Escape Ancient China.-.Oberon Media) -> "C:\Program Files (x86)\Game Pack\Mahjong Escape Ancient China\Uninstall.exe" "C:\Program Files (x86)\Game Pack\Mahjong Escape Ancient China\install.log" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}] : (Galapago.-.Oberon Media) -> "C:\Program Files (x86)\Game Pack\Galapago\Uninstall.exe" "C:\Program Files (x86)\Game Pack\Galapago\install.log" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113128447}] : (Daycare Nightmare.-.Oberon Media) -> "C:\Program Files (x86)\Game Pack\Daycare Nightmare\Uninstall.exe" "C:\Program Files (x86)\Game Pack\Daycare Nightmare\install.log" [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{89B5DFCA-81E0-4EA4-8A0A-4F4087A1DD00}] : (Iminent.-.Iminent) -> MsiExec.exe /X{89B5DFCA-81E0-4EA4-8A0A-4F4087A1DD00} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}] : (HP Update.-.Hewlett-Packard) -> MsiExec.exe /X{912D30CF-F39E-4B31-AD9A-123C6B794EE2} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9225EABF-4457-403B-A82B-91614C9DDDF7}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{9225EABF-4457-403B-A82B-91614C9DDDF7}\setup.exe" -l0x40c -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}] : (Visual Studio 2012 x86 Redistributables.-.AVG Technologies CZ, s.r.o.) -> MsiExec.exe /I{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9C423CF6-2DAA-4A37-94B8-59D7ECC7DB13}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{9C423CF6-2DAA-4A37-94B8-59D7ECC7DB13}\setup.exe" -l0x40c -removeonly [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824166751}] : (Adobe Refresh Manager.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AC76BA86-0804-1033-1959-001824166751} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}] : (Adobe Acrobat Reader DC - Français.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-AC0F074E4100} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ACE66099-E18E-4037-83C8-9D182E5B9FA8}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{ACE66099-E18E-4037-83C8-9D182E5B9FA8}\setup.exe" -l0x40c -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B34B6E67-FCDD-4E03-8742-B5701427FAFB}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{B34B6E67-FCDD-4E03-8742-B5701427FAFB}\setup.exe" -l0x40c -removeonly [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B7A0CE06-068E-11D6-97FD-0050BACBF861}] : (CyberLink PowerProducer.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BA23A9FD-F612-4779-81DD-88BD56647356}] : (DriverUpdate.-.Slimware Utilities Holdings, Inc.) -> MsiExec.exe /X{BA23A9FD-F612-4779-81DD-88BD56647356} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BA9EAF4E-04E2-4BF6-8B6D-3AC72F61DB98}] : (LeapFrog Connect.-.LeapFrog) -> MsiExec.exe /X{BA9EAF4E-04E2-4BF6-8B6D-3AC72F61DB98} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}] : (User Guide.-.) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}\setup.exe" -l0x9 Remove [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{BAF28CCD-121D-4C6C-B29D-4F7B51B2D1B4}] : (HP ENVY 4500 series Aide.-.Hewlett Packard) -> MsiExec.exe /I{BAF28CCD-121D-4C6C-B29D-4F7B51B2D1B4} [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C59C179C-668D-49A9-B6EA-0121CCFC1243}] : (CyberLink LabelPrint.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C9EFF51A-C925-4F1A-9DEB-DB5F970DE983}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{C9EFF51A-C925-4F1A-9DEB-DB5F970DE983}\setup.exe" -l0x40c -removeonly [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}] : (CyberLink PowerDirector.-.CyberLink Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D1434266-0486-4469-B338-A60082CC04E1}] : (Atheros Client Installation Program.-.Atheros) -> "C:\Program Files (x86)\InstallShield Installation Information\{D1434266-0486-4469-B338-A60082CC04E1}\setup.exe" -runfromtemp -l0x0009 -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D1F6FBBB-B204-459A-9BF8-D06FFAB96CCC}_is1] : (Game Pack.-.Oberon Media, Inc.) -> "C:\Program Files (x86)\Game Pack\GameConsole\unins000.exe" [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}] : (Samsung Update Plus.-.Samsung Electronics Co., Ltd.) -> "C:\Program Files (x86)\InstallShield Installation Information\{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}\setup.exe" -runfromtemp -l0x0009 -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D5068583-D569-468B-9755-5FBF5848F46F}] : (Sony Picture Utility.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{D5068583-D569-468B-9755-5FBF5848F46F}\setup.exe" -l0x40c /removeonly uninstall -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}] : (Intel(R) Turbo Boost Technology Driver.-.Intel Corporation) -> C:\Program Files (x86)\Intel\Intel(R) Turbo Boost Technology Driver\Uninstall\setup.exe -uninstall -iips [{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}] : (Kies.-.Nom de votre société) -> MsiExec.exe /X{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E4B931AF-C59A-4D92-8767-8E2D5F53144E}] : (HP Support Solutions Framework.-.Hewlett-Packard Company) -> MsiExec.exe /X{E4B931AF-C59A-4D92-8767-8E2D5F53144E} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E9CCEA28-3608-4078-8A07-997646E1A357}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{E9CCEA28-3608-4078-8A07-997646E1A357}\setup.exe" -l0x40c -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{EF367AA4-070B-493C-9575-85BE59D789C9}] : (Easy SpeedUp Manager.-.Samsung Electronics Co.,Ltd.) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{EF367AA4-070B-493C-9575-85BE59D789C9}\setup.exe" -l0x9 Remove [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}] : (Realtek High Definition Audio Driver.-.Realtek Semiconductor Corp.) -> C:\Program Files\Realtek\Audio\HDA\RtlUpd64.exe -r -m -nrg2709 [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F687E657-F636-44DF-8125-9FEEA2C362F5}] : (Samsung Support Center.-.Samsung) -> MsiExec.exe /I{F687E657-F636-44DF-8125-9FEEA2C362F5} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F9557866-B4C8-4CE5-8508-0E386BDC20B2}] : (Easy Network Manager.-.Samsung) -> MsiExec.exe /I{F9557866-B4C8-4CE5-8508-0E386BDC20B2} [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FA6CC4B4-7741-4F8D-8E81-15C4BAB9869B}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{FA6CC4B4-7741-4F8D-8E81-15C4BAB9869B}\setup.exe" -l0x40c -removeonly [HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{FD7FF74D-0AB5-48D6-929C-7E93A5162521}] : (.-.Sony Corporation) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{FD7FF74D-0AB5-48D6-929C-7E93A5162521}\setup.exe" -l0x40c -removeonly ¤¤¤¤¤¤¤¤¤¤ | Installer [HKCR\Installer\Products\07E577C8197A8AD4CB3CA67B31F64448] : Visual Studio 2012 x64 Redistributables [HKCR\Installer\Products\098990BCF5D15D11E99A0005AB3E711E] : PowerDirector -> C:\windows\Installer\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\ARPPRODUCTICON.exe [HKCR\Installer\Products\1457DEE38F556CD49BDC8267D21713E0] : Samsung R-Series -> C:\windows\Installer\{3EED7541-55F8-4DC6-B9CD-28762D71310E}\ARPPRODUCTICON.exe [HKCR\Installer\Products\17EBDE16E3D57BA4DA595EF3AE6FC871] : Bing Rewards Client Installer [HKCR\Installer\Products\18555481990E8AB4CBB63FB4F26006C0] : Google Toolbar for Internet Explorer [HKCR\Installer\Products\1C4235E6CF4867F4A9A36CE5708FE06E] : Complément Messenger -> C:\windows\Installer\{6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}\CompanionIcon [HKCR\Installer\Products\38E1FB04BE028D11795C00905C206085] : Power2Go -> C:\windows\Installer\{40BF1E83-20EB-11D8-97C5-0009C5020658}\ARPPRODUCTICON.exe [HKCR\Installer\Products\42C6FBF1DF1C10144AB2C065F4E9E897] : PowerStarter -> C:\windows\Installer\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\ARPPRODUCTICON.exe [HKCR\Installer\Products\52744B0D6663D294EB6F85A741DBB99D] : MSVCRT_amd64 [HKCR\Installer\Products\571ACCBC91ADB424D9F9353441C088F4] : Étude pour l'amélioration du produit HP ENVY 4500 series -> C:\windows\Installer\{CBCCA175-DA19-424B-9D9F-5343140C884F}\ARP_Icon [HKCR\Installer\Products\60EC0A7BE8606D1179DF0005ABBC8F16] : PowerProducer -> C:\windows\Installer\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\ARPPRODUCTICON.exe [HKCR\Installer\Products\6116D6C8427B0184F8D20D746E7B6DE8] : Mesh Runtime [HKCR\Installer\Products\6687559F8C4B5EC45880E083B6CD022B] : Easy Network Manager -> C:\windows\Installer\{F9557866-B4C8-4CE5-8508-0E386BDC20B2}\_6FEFF9B68218417F98F549.exe [HKCR\Installer\Products\68AB67CA408033019195008142617615] : Adobe Refresh Manager -> C:\windows\Installer\{AC76BA86-0804-1033-1959-001824166751}\ARPPRODUCTICON.exe [HKCR\Installer\Products\68AB67CA7DA76301B744CAF070E41400] : Adobe Acrobat Reader DC - Français -> C:\windows\Installer\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}\SC_Reader.ico [HKCR\Installer\Products\7212A61D729B97341B35D3CE90E1E4BE] : Intel(R) PROSet/Wireless WiFi Software -> C:\windows\Installer\{D16A2127-B927-4379-B153-3DEC091E4EEB}\ARPPRODUCTICON.exe [HKCR\Installer\Products\756E786F636FFD441852F9EE2A3C265F] : Samsung Support Center -> C:\windows\Installer\{F687E657-F636-44DF-8125-9FEEA2C362F5}\_6FEFF9B68218417F98F549.exe [HKCR\Installer\Products\7BD4C90EC03660F46A13E87A329932FA] : D3DX10 [HKCR\Installer\Products\7E0BA6F1DDC839B4A832AAE92BEFCF4E] : Junk Mail filter update [HKCR\Installer\Products\8994BF104C33134458DE70E9E3FE7ED5] : YouCam -> C:\windows\Installer\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\ARPPRODUCTICON.exe [HKCR\Installer\Products\8A46B9A98E9A88549B421D98D8E33655] : Logiciel de base du périphérique HP ENVY 4500 series -> C:\windows\Installer\{9A9B64A8-A9E8-4588-B924-D1898D3E6355}\ARP_Icon [HKCR\Installer\Products\95BD630790B1F1145888A261383817AD] : LeapFrog LeapPad Explorer Plugin [HKCR\Installer\Products\A089CE062ADB6BC44A720BA745894BAC] : Google Update Helper [HKCR\Installer\Products\A6C64DD86500CEF47BA082BB611A1FF1] : MSVCRT [HKCR\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F] : Visual Studio 2012 x86 Redistributables [HKCR\Installer\Products\A99A1F91F69181D4CB631CAD6DBACC3F] : Application du bouton Share KODAK -> C:\windows\Installer\{19F1A99A-196F-4D18-BC36-C1DAD6ABCCF3}\ARPPRODUCTICON.exe [HKCR\Installer\Products\ACFD5B980E184AE4A8A0F404781ADD00] : Iminent -> C:\windows\Installer\{89B5DFCA-81E0-4EA4-8A0A-4F4087A1DD00}\imbooster.ico [HKCR\Installer\Products\BF975A4760BED7941B491095D0F65EA1] : BatteryLifeExtender -> C:\windows\Installer\{74A579FB-EB06-497D-B194-01590D6FE51A}\_6FEFF9B68218417F98F549.exe [HKCR\Installer\Products\C971C95CD8669A946BAE1012CCCF2134] : LabelPrint -> C:\windows\Installer\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\ARPPRODUCTICON.exe [HKCR\Installer\Products\CAD7F008ED4E06B4F96C201A107E3933] : Mailorama pour internet explorer [HKCR\Installer\Products\DCC82FABD121C6C42BD9F4B7152B1D4B] : HP ENVY 4500 series Aide -> C:\windows\Installer\{BAF28CCD-121D-4C6C-B29D-4F7B51B2D1B4}\ARP_Icon [HKCR\Installer\Products\DF62DC6DF7DC68C4693AEEFBBA5EEF74] : Kies -> C:\windows\Installer\{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}\ARPPRODUCTICON.exe [HKCR\Installer\Products\DF9A32AB216F977418DD88DB65463765] : DriverUpdate -> C:\windows\Installer\{BA23A9FD-F612-4779-81DD-88BD56647356}\Icon.exe [HKCR\Installer\Products\E4FAE9AB2E406FB4B8D6A37CF216BD89] : LeapFrog Connect [HKCR\Installer\Products\F13E2FB2BB8B7A046B05892DE8F0D774] : PowerDVD -> C:\windows\Installer\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\ARPPRODUCTICON.exe [HKCR\Installer\Products\FA139B4EA95C29D47876E8D2F53541E4] : HP Support Solutions Framework -> C:\windows\Installer\{E4B931AF-C59A-4D92-8767-8E2D5F53144E}\icon.ico [HKCR\Installer\Products\FC03D219E93F13B4DAA921C3B697E42E] : HP Update -> C:\windows\Installer\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}\ARPPRODUCTICON.exe ¤¤¤¤¤¤¤¤¤¤ | ADS @C:\ProgramData\Temp:268F887D @C:\ProgramData\Temp:373E1720 ¤¤¤¤¤¤¤¤¤¤ | Drives Disk: 0 Size=477G Pos MBRndx Type/Name Size Active Hide Start Sector Sectors --- ------ ---------- ---- ------ ---- ------------ ------------ 0 0 27-UNKNWN 20G No No 2,048 41,943,040 1 1 07-NTFS 100M Yes No 41,945,088 204,800 2 2 07-NTFS 183G No No 42,149,888 375,390,208 3 3 0F-EXTEND 273G No No 417,540,096 559,230,976 ¤¤¤¤¤¤¤¤¤¤ | MBR Windows Version: Windows 7 Home Premium Edition Windows Information: Service Pack 1 (build 7601), 64-bit Base Board Manufacturer: SAMSUNG ELECTRONICS CO., LTD. BIOS Manufacturer: Phoenix Technologies Ltd. System Manufacturer: SAMSUNG ELECTRONICS CO., LTD. System Product Name: R530/R730/P530 Logical Drives Mask: 0x0000001c Analysis of file "C:\QuickDiag\MBR.bin": Unknown MBR code 64 bits not supported by MBR.exe, Dump : C:\QuickDiag\MBR.Bin ¤¤¤¤¤¤¤¤¤¤( EOF)¤¤¤¤¤¤¤¤¤¤ - 4053 | 11:32:13